When you are ready:
The following tool will remove the tools we used as well as reset system restore points:
Download
KpRm by kernel-panik and save it to your desktop.
- Right-click kprm_(version).exe and select Run as Administrator.
- Read and accept the disclaimer.
- When the tool opens, ensure all boxes under Actions are checked.
- Under Delete Quarantines select Delete Now, then click Run.
- Once complete, click OK.
- A log will open in Notepad titled kprm-(date).txt.
- Please copy and paste its contents in your next reply.
Here's the log:
# Run at 30-Jul-22 10:15:01 AM
# KpRm (Kernel-panik) version 2.9.3
# Website
https://kernel-panik.me/tool/kprm/
# Run by Sandarpan from D:\Desktop
# Computer Name: SANDARPAN
# OS: Windows 10 X64 (19044)
# Number of passes: 1
- Checked options -
~ Registry Backup
~ Delete Tools
~ Restore System Settings
~ UAC Restore
~ Delete Restore Points
~ Create Restore Point
~ Delete Quarantines
- Create Registry Backup -
~ [OK] Hive C:\WINDOWS\System32\config\SOFTWARE backed up
~ [OK] Hive C:\Users\Sandarpan.PC2\NTUSER.dat backed up
[OK] Registry Backup: C:\KPRM\backup\2022-07-30-10-15-01
- Delete Tools -
## AdwCleaner
[OK] D:\Desktop\AdwCleaner.exe deleted
[OK] C:\AdwCleaner deleted
## ESET Online Scanner
[OK] D:\Desktop\ESET Online Scanner.lnk deleted
[OK] D:\Desktop\esetonlinescanner.exe deleted
[OK] C:\Users\Sandarpan.PC2\AppData\Local\ESET\ESETOnlineScanner deleted
## FRST
[OK] D:\Desktop\Addition.txt deleted
[OK] D:\Desktop\Fixlog.txt deleted
[OK] D:\Desktop\FRST-OlderVersion deleted
[OK] D:\Desktop\FRST.txt deleted
[OK] D:\Desktop\FRST64.exe deleted
[OK] C:\FRST deleted
## FSS
[OK] D:\Desktop\FSS.exe deleted
[OK] D:\Desktop\FSS.txt deleted
## Kaspersky Virus Removal Tool
[OK] C:\KVRT_Data deleted
- Restore System Settings -
[OK] Reset WinSock
[OK] FLUSHDNS
[OK] Hide Hidden file.
[OK] Show Extensions for known file types
[OK] Hide protected operating system files
- Restore UAC -
[OK] Set EnableLUA with default (1) value
[OK] Set ConsentPromptBehaviorAdmin with default (5) value
[OK] Set ConsentPromptBehaviorUser with default (3) value
[OK] Set EnableInstallerDetection with default (0) value
[OK] Set EnableSecureUIAPaths with default (1) value
[OK] Set EnableUIADesktopToggle with default (0) value
[OK] Set EnableVirtualization with default (1) value
[OK] Set FilterAdministratorToken with default (0) value
[OK] Set PromptOnSecureDesktop with default (1) value
[OK] Set ValidateAdminCodeSignatures with default (0) value
- Clear Restore Points -
~ [OK] RP named Windows Modules Installer created at 07/30/2022 03:23:13 deleted
[OK] All system restore points have been successfully deleted
- Create Restore Point -
[OK] System Restore Point created
- Display System Restore Point -
~
RP named KpRm created at 07/30/2022 04:46:34
-- KPRM finished in 173.43s --