[SOLVED] Microsoft Safety Scanner and Windows Defender Logs

Status
Not open for further replies.
I’ll try to do it later today or tomorrow, if possible.
i just need to figure out how to not have things auto update before I post the logs.
 
I’ll try to do it later today or tomorrow, if possible.
i just need to figure out how to not have things auto update before I post the logs.

OK. I'll be here.
 
I decided to just do it now if that's okay:
Also don't know if i should close the browser in case it accidently updates
Edit: Somethings automatically updated as I booted up the computer
 

Attachments

I also just remembered that I took logs when I was paranoid about this on the 30th, so I can supply them too if needed.
 
Your computer is clean, and I don't see anything that explains your concerns.

Just a bit maintenance:

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Code:
Start::
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
Task: {F38BA347-4025-4160-BD79-9D3FCB173015} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(1): %windir%\system32\compattelrunner.exe -> -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc
Task: {F38BA347-4025-4160-BD79-9D3FCB173015} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(2): %windir%\system32\compattelrunner.exe -> -m:appraiser.dll -f:DoScheduledTelemetryRun
Task: {F38BA347-4025-4160-BD79-9D3FCB173015} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(3): %windir%\system32\compattelrunner.exe -> -m:aemarebackup.dll -f:BackupMareData
CMD: DISM /Online /Cleanup-Image /RestoreHealth
CMD: SFC /scannow
EmptyTemp:
End::
  • Right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.[/*]
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Post the log in your next reply.
 
There was an existing fixlog in my downloads folder, since I ran a fix last month. I think this new fixlog overwrote that though so hopefully that never created any problems.
I was also signed out on another site, which I imagine is normal when you run this fix. Do you reckon it's good to update now?
 

Attachments

Please move the FRST tool on to your Desktop.

Start in Safe mode:
  • Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
  • Choose Update and Security.
  • From the menu at the left, choose Recovery.
  • Under the title Advanced startup at the right, choose Restart now.
  • From the window that will appear choose Troubleshoot and then Advanced options.
  • Choose Startup Settings and then Restart.
  • Press number 5, for choosing Safe mode with networking.
  • You will know that you are in Safe mode, if the background is black and Safe mode is written at the four corners of the screen.

After that:

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Code:
Start::
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
End::
  • Right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.[/*]
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Post the log in your next reply.
 
Isn’t that restriction normal because of some sort of policy, or am I misunderstanding something here?
Also, don’t you need to login to safe mode with the password, as I don’t remember the password for my local account and have been using the pin to sign in.
sorry if it seems like I’m being difficult
 
OK, I forgot you don't remember your password.

  • Press Windows icon key on your keyboard, together with the letter R.
  • Type cmd, and press Ctrl + Shift + Enter to run Command Prompt as administrator.
  • Copy and paste the following command and press Enter to execute it:
Code:
net user administrator /active:yes
  • Restart the computer in Safe mode, as instructed above, and choose this account (Administrator).


After sign in with the Administrator account in Safe mode, run the fix I gave you here.
 
Ok, I think I messed something up and I’m really scared. I clicked the admin account and there’s nothing on the desktop. How do I exit safe mode from here?
it acted like it was setting up a new local account and I don’t know if it’s supposed to do that
 

Attachments

  • IMG_0108.jpeg
    IMG_0108.jpeg
    54.8 KB · Views: 3
There is nothing on the Desktop, because it is an account used for the first time.

So you are now signed in with the Admin account in Safe mode. Is that correct?

If yes,

Open a File explorer, choose This PC, and then navigate to this path: C:\Users\DR M\Desktop (of course you won't find DR M, but your user account name). Find FRST tool, copy it and paste it on the Desktop of the Admin account your signed in now. You will need it to run the fix.
 
Good!

Now, sign in with the Administrator account but in normal mode this time (not Safe mode). We are going to set a new password for your local account.
 
Ok, thank you.
How do I get off safe mode, by the way?
Would I have to power off and on, or restart?
The restart button on my case doesn’t work, but it never bothered me, since I always restarted via the windows option
 
Just Restart the computer and choose the Administrator account.

After that, type Control Panel in the Search area and hit Enter to go to Control Panel. Select User Accounts and then Change account type. Choose your User account. Then, Change password. Type a new password and confirm. Restart, choosing your User account.
 
Ah, I don’t know how to restart from here
i clicked on the windows icon, but nothing happens, so I don’t know what to do
Can I just power it off and on with the power button, or does it have to be a restart?
 
Do whatever you do to shut down and then start the computer.
 
Ok, I successfully changed it now.
For some reason, it’d force me into the admin account when it restarted though, so I had to choose my account from the start menu.
Maybe it’s because the Admin account doesn’t have a password?
Also, I had to click through a bunch of stuff for the admin account like stuff for edge when I loaded safe mode (It wouldn’t even let me close the window without clicking through the options which was really annoying), and location services and stuff when booting into normal mode, so I don’t know if we’re going to do something to delete those preferences next?
Sorry if I seem scatterbrained and panicky. Ive never done anything like this before
 
Last edited:
Also, I’m sitting on my local account now, and I’m at the desktop, but I’ve not done anything yet.
I moved the FRST tool back to my desktop along with the fixlog that was created when I ran that last Fix
 
Status
Not open for further replies.

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top