Hello, Welcome to BleepingComputer.
I’m nasdaq and will be helping you.
If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===
Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
start Comment: All processes will be force closed, System Protection will be enabled Comment: New Restore Point will be created, All network proxies will be removed CloseProcesses: SystemRestore: On CreateRestorePoint: RemoveProxy: Comment: Items from the FRST.TXT log that will be removed from the Registry. Task: {008A3035-9BEB-4F82-BBF0-04690BE73C3D} - System32TasksOneDrive Standalone Update Task-S-1-5-21-2336844648-3213177803-2782347618-500 => C:Usersilu-pAppDataLocalMicrosoftOneDriveOneDriveStandaloneUpdater.exe (No File) Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsHostExtensionsAutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsBookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsHostExtensionsLearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsHostExtensionsPinJSAPI [not found] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.cpdf -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File] Comment: Items from the Addition.txt log that will be removed. CustomCLSID: HKUS-1-5-21-2336844648-3213177803-2782347618-1001_ClassesCLSID{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}InprocServer32 -> C:Usersilu-pAppDataLocalMicrosoftTeamsMeetingAddin1.0.20244.4x64Microsoft.Teams.AddinLoader.dll => No File CustomCLSID: HKUS-1-5-21-2336844648-3213177803-2782347618-1001_ClassesCLSID{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}localserver32 -> "C:Usersilu-pAppDataLocalMicrosoftTeamscurrentTeams.exe" --toast => No File FirewallRules: [{D9812375-7BC9-4473-B15E-6AE8B6304BF4}] => (Allow) C:Program FilesIntelWiFibinPanDhcpDns.exe => No File FirewallRules: [{1317FF1F-6F73-4018-816D-1CEF3E97038E}] => (Allow) C:Program Files (x86)Steambincefcef.win7steamwebhelper.exe => No File FirewallRules: [{A09A1C24-462A-4CDF-9490-BE3291376496}] => (Allow) C:Program Files (x86)Steambincefcef.win7steamwebhelper.exe => No File FirewallRules: [{B2368FE2-5D44-4CE3-8FBE-51751C2E527E}] => (Allow) C:Program Files (x86)SteamsteamappscommonRealm of the Mad GodRealm of the Mad God.exe => No File FirewallRules: [{045BB8E4-8691-4FBE-B987-3F2CFCEC19D1}] => (Allow) C:Program Files (x86)SteamsteamappscommonRealm of the Mad GodRealm of the Mad God.exe => No File Comment: Resetting of services and maintenance. cmd: ECHO Y|CHKDSK C: /F cmd: pushdwindowssystem32 cmd: net stop bits cmd: net stop cryptSvc cmd: net stop wuauserv cmd: net stop msiserver cmd: del /s /q C:WindowsSoftwareDistributiondownload*.* cmd: net start cryptSvc cmd: net start bits cmd: net start wuauserv cmd: net start msiserver cmd: sfc /scannow cmd: DISM.exe /Online /Cleanup-image /Restorehealth cmd: sfc /scannow StartBatch: del /s /q "%userprofile%AppDataLocalGoogleChromeUser DataDefaultCache*.*" del /s /q "%userprofile%AppDataLocalMicrosoftEdgeUser DataDefaultCache*.*" "%WINDIR%SYSTEM32lodctr.exe" /R "%WINDIR%SysWOW64lodctr.exe" /R "%WINDIR%SYSTEM32lodctr.exe" /R "%WINDIR%SysWOW64lodctr.exe" /R NETSH winsock reset catalog NETSH int ipv4 reset reset.log NETSH int ipv6 reset reset.log netsh interface IP delete arpcache ipconfig /release ipconfig /renew ipconfig /flushdns ipconfig /registerdns net start sdrsvc net start vss net start rpcss net start eventsystem net start mpsdrv net start bfe net start MpsSvc net start winmgmt netsh winhttp reset proxy Endbatch: cmd: Bitsadmin /Reset /Allusers cmd: winmgmt /verifyrepository cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state ON Comment: Use Farbar routine to delete temp files C:WindowsTemp*.* C:WINDOWSsystem32*.tmp C:WINDOWSsyswow64*.tmp Comment: The system will restart. Reboot: End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.
Run FRST and click Fix only once and wait.
The tool will create a log (Fixlog.txt) please post it to your reply.
===
Please post the Fixlog.txt and let me know what problem persists.
Source: https://www.bleepingcomputer.com/forums/t/771068/urgent-help-needed/