Each time I restart or turn off the pc the sessions are closed.

Hi, I passed you the FRST tool and this is the fix I applied to you:

Code:
Fix result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019
Ran by User (04-04-2019 08:06:06) Run:1
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
CHR HKLM\...\Chrome\Extension: [fcbhdhpamoencpdogjnmnbjddipfkpad] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fcbhdhpamoencpdogjnmnbjddipfkpad] - hxxps://clients2.google.com/service/update2/crx
S1 UimBus; \SystemRoot\System32\drivers\uimbus.sys [X]
S1 Uim_DEVIM; \SystemRoot\System32\drivers\uimdevim.sys [X]
S1 amsdk; C:\WINDOWS\system32\drivers\amsdk.sys [232792 2019-03-02] (Zemana D.O.O. Sarajevo -> Copyright 2018.)
R2 libwamf; C:\WINDOWS\System32\DRIVERS\libwamf.sys [35400 2019-03-22] (Opswat Inc. -> OPSWAT, Inc.)
R2 libwasys; C:\WINDOWS\system32\DRIVERS\libwasys.sys [38472 2019-03-22] (Opswat Inc. -> OPSWAT, Inc.)
2019-04-02 07:05 - 2019-04-02 07:05 - 000000000 ____D C:\RusRoute
2019-04-02 19:04 - 2019-04-02 19:04 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-04-02 19:04 - 2019-04-02 19:04 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-04-02 19:04 - 2019-04-02 19:04 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-04-02 19:04 - 2019-04-02 19:04 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-04-02 19:04 - 2019-04-02 19:04 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-04-02 19:04 - 2019-04-02 19:04 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-04-02 19:04 - 2019-04-02 19:04 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-04-01 18:57 - 2019-04-01 18:58 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-04-01 16:59 - 2019-04-01 16:59 - 000000000 _____ C:\WINDOWS\System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}
2019-04-01 16:52 - 2019-04-01 18:56 - 000000000 ____D C:\WINDOWS\System32\Tasks\Doctor Web
2019-04-01 15:33 - 2019-04-01 15:45 - 000000000 ____D C:\Users\User\AppData\Roaming\Panda Security
2019-04-01 15:30 - 2019-04-01 15:46 - 000000000 ____D C:\ProgramData\Panda Security
2019-04-01 14:48 - 2019-04-01 14:51 - 000000000 ____D C:\ProgramData\HitmanPro
2019-03-31 12:36 - 2019-04-03 15:41 - 000000000 ____D C:\Program Files (x86)\BraveSoftware
2019-03-31 12:35 - 2019-03-31 12:37 - 000000000 ____D C:\Users\User\AppData\Local\BraveSoftware
2019-03-31 08:17 - 2019-03-31 08:17 - 000000000 ____D C:\Users\User\AppData\Local\Paragon
2019-03-31 08:17 - 2019-03-31 08:17 - 000000000 ____D C:\ProgramData\Paragon Software
2019-03-31 08:16 - 2019-04-03 15:41 - 000000000 ____D C:\Program Files\Paragon Software
2019-03-31 08:16 - 2019-03-31 08:16 - 000000000 ____D C:\ProgramData\Paragon
2019-03-30 11:57 - 2019-04-02 22:34 - 003629648 _____ (AhnLab, Inc.) C:\WINDOWS\system32\btscan.exe
2019-03-30 07:42 - 2019-03-30 07:42 - 000000000 ____D C:\AdwCleaner
2019-03-30 07:35 - 2019-03-30 07:35 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\113442DB.sys
2019-03-30 07:34 - 2019-03-30 07:43 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2019-03-30 07:32 - 2019-03-30 07:35 - 000316088 _____ C:\TDSSKiller.3.1.0.26_30.03.2019_07.32.22_log.txt
2019-03-30 05:22 - 2019-03-30 05:37 - 000000000 ____D C:\ProgramData\RogueKiller
2019-03-30 11:45 - 2019-03-30 11:46 - 000000000 ____D C:\ProgramData\AhnLab
2019-03-22 16:01 - 2019-04-02 09:15 - 000000016 _____ C:\WINDOWS\CyProtect.cache
2019-03-22 10:46 - 2019-03-22 11:11 - 000000000 ____D C:\Users\User\AppData\Roaming\Sun
2019-03-22 10:46 - 2019-03-22 11:11 - 000000000 ____D C:\Users\User\AppData\LocalLow\Sun
2019-03-22 10:45 - 2019-03-22 11:11 - 000000000 ____D C:\ProgramData\Oracle
2019-03-21 09:43 - 2019-03-22 04:00 - 000038472 _____ (OPSWAT, Inc.) C:\WINDOWS\system32\Drivers\libwasys.sys
2019-03-21 09:43 - 2019-03-22 04:00 - 000035400 _____ (OPSWAT, Inc.) C:\WINDOWS\system32\Drivers\libwamf.sys
2019-04-03 15:06 - 2019-02-15 13:01 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-04-01 17:13 - 2019-01-28 05:51 - 000000000 ____D C:\Users\User\Doctor Web
Metadefender Endpoint (HKLM-x32\...\{8AF70079-42E8-4194-A888-38711BD0F50E}) (Version: 7.6.51.0 - OPSWAT, Inc.) Hidden
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\AIDA64 Reports:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\Battlefield 4:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\Battlefield V:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\Diablo III:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\ezvid:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\FIFA 19:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\My Games:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\Reflect:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\User\OneDrive - 广厚设计学校\Documentos\SysnativeBSODCollectionApp:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]

*****************

"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\fcbhdhpamoencpdogjnmnbjddipfkpad => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fcbhdhpamoencpdogjnmnbjddipfkpad => removed successfully
HKLM\System\CurrentControlSet\Services\UimBus => removed successfully
UimBus => service removed successfully
HKLM\System\CurrentControlSet\Services\Uim_DEVIM => removed successfully
Uim_DEVIM => service removed successfully
HKLM\System\CurrentControlSet\Services\amsdk => removed successfully
amsdk => service removed successfully
libwamf => Unable to stop service.
HKLM\System\CurrentControlSet\Services\libwamf => removed successfully
libwamf => service removed successfully
libwasys => Unable to stop service.
HKLM\System\CurrentControlSet\Services\libwasys => removed successfully
libwasys => service removed successfully
C:\RusRoute => moved successfully
C:\WINDOWS\system32\DrtmAuth7.bin => moved successfully
C:\WINDOWS\system32\DrtmAuth6.bin => moved successfully
C:\WINDOWS\system32\DrtmAuth5.bin => moved successfully
C:\WINDOWS\system32\DrtmAuth4.bin => moved successfully
C:\WINDOWS\system32\DrtmAuth3.bin => moved successfully
C:\WINDOWS\system32\DrtmAuth2.bin => moved successfully
C:\WINDOWS\system32\DrtmAuth1.bin => moved successfully
C:\ProgramData\Kaspersky Lab Setup Files => moved successfully
C:\WINDOWS\System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82} => moved successfully
C:\WINDOWS\System32\Tasks\Doctor Web => moved successfully
C:\Users\User\AppData\Roaming\Panda Security => moved successfully
C:\ProgramData\Panda Security => moved successfully
C:\ProgramData\HitmanPro => moved successfully
C:\Program Files (x86)\BraveSoftware => moved successfully
C:\Users\User\AppData\Local\BraveSoftware => moved successfully
C:\Users\User\AppData\Local\Paragon => moved successfully
C:\ProgramData\Paragon Software => moved successfully
C:\Program Files\Paragon Software => moved successfully
C:\ProgramData\Paragon => moved successfully
C:\WINDOWS\system32\btscan.exe => moved successfully
C:\AdwCleaner => moved successfully
C:\WINDOWS\system32\Drivers\113442DB.sys => moved successfully
C:\ProgramData\Malwarebytes' Anti-Malware (portable) => moved successfully
C:\TDSSKiller.3.1.0.26_30.03.2019_07.32.22_log.txt => moved successfully
C:\ProgramData\RogueKiller => moved successfully
C:\ProgramData\AhnLab => moved successfully
C:\WINDOWS\CyProtect.cache => moved successfully
C:\Users\User\AppData\Roaming\Sun => moved successfully
C:\Users\User\AppData\LocalLow\Sun => moved successfully
C:\ProgramData\Oracle => moved successfully
C:\WINDOWS\system32\Drivers\libwasys.sys => moved successfully
C:\WINDOWS\system32\Drivers\libwamf.sys => moved successfully
C:\ProgramData\Malwarebytes => moved successfully
C:\Users\User\Doctor Web => moved successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8AF70079-42E8-4194-A888-38711BD0F50E}\\SystemComponent" => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\CLSID\{B298D29A-A6ED-11DE-BA8C-A68E55D89593} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\CLSID\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} => not found
C:\Users\User\OneDrive - 广厚设计学校\Documentos\AIDA64 Reports => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\Battlefield 4 => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\Battlefield V => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\Diablo III => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\ezvid => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\FIFA 19 => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\My Games => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\Reflect => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\User\OneDrive - 广厚设计学校\Documentos\SysnativeBSODCollectionApp => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully


The system needed a reboot.

==== End of Fixlog 08:06:28 ====


Still with the same problem. Regards.
 
I'm testing it and it looks like the problem was Glary Utilitis Pro. For now I have restarted several times and I am still connected in all sessions. Thank you very much. Regards.
 
FTR, I would never use or recommend the Glary Utilities program. Modern versions of Windows don't need it.

As a side note, you sure have a lot of security programs there. I see OPSWAT, Zemana, Malwarebytes, Kaspersky, Panda, HitmanPro, RogueKiller, AdwCleaner, TDSSKiller, AhnLab, CyProtect, Doctor Web - I might have missed some.

If me, I would uninstall all of them, reboot, then and start over with one good, real-time anti-malware scanner (I use Windows Defender on all my systems here) and have one additional scanner for "on-demand" scanning. I use Malwarebytes but many like Zemana for that. Even if all those are NOT running in real time, if nothing else, they are hogging disk space. But I suspect several at least have real-time components - perhaps to check for updates. They, at least, are using system resources.
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top