Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click
Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.
Code:
start::
CreateRestorePoint:
HKU\S-1-5-21-2215749033-445842302-415398914-1001\...\Run: [MicrosoftEdgeAutoLaunch_46C0173F98CBD0BEB36BBC1DDC54FE9A] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4210216 2023-09-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2215749033-445842302-415398914-1001\...\Run: [GoogleChromeAutoLaunch_B364DB4262BB88E80B8C959641DD7ACE] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [3242272 2023-09-27] (Google LLC -> Google LLC)
S3 cpuz154; \??\C:\Windows\temp\cpuz154\cpuz154_x64.sys [X]
S3 AscFileFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [X]
S3 AscRegistryFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [X]
2023-10-01 18:51 - 2023-10-02 01:05 - 000000000 ____D C:\ProgramData\IObit
2023-10-01 18:51 - 2023-10-01 23:41 - 000000000 ____D C:\Users\justc\AppData\LocalLow\IObit
2023-10-01 18:50 - 2023-10-01 23:41 - 000000000 ____D C:\Program Files (x86)\IObit
2023-10-01 18:50 - 2023-10-01 19:13 - 000000000 ____D C:\Users\justc\AppData\Roaming\IObit
C:\ProgramData\{7D4F950D-61ED-482D-A05D-43620B49B610}
C:\ProgramData\ProductData
C:\ProgramData\360Quarant
C:\Program Files (x86)\360
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu64.dll -> No File
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu64.dll -> No File
ShortcutWithArgument: C:\Users\justc\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncm\Gmail.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=aghbiahbpaijignceidepookljebhfak
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=fhihpiojkbmbpdjeoajapmgkhlnakfjf
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=kefjledonklijopmnomlcbpllchaibag
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\188f5ec9d11ded56\Profile 2 - Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory="Profile 1"
AlternateDataStreams: C:\Users\justc\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\HijackThis (1).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\HijackThis.exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (1).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (2).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (3).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (4).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\SnookerQSetup-20230923-0.1.710 (1).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\SnookerQSetup-20230923-0.1.710.exe:BDU [0]
emptytemp:
Reboot:
End::
Again, no where to attach.
Fix result of Farbar Recovery Scan Tool (x64) Version: 25-09-2023
Ran by justc (03-10-2023 08:22:11) Run:1
Running from C:\Users\justc\Desktop
Loaded Profiles: justc
Boot Mode: Normal
==============================================
fixlist content:
*****************
start::
CreateRestorePoint:
HKU\S-1-5-21-2215749033-445842302-415398914-1001\...\Run: [MicrosoftEdgeAutoLaunch_46C0173F98CBD0BEB36BBC1DDC54FE9A] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4210216 2023-09-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2215749033-445842302-415398914-1001\...\Run: [GoogleChromeAutoLaunch_B364DB4262BB88E80B8C959641DD7ACE] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [3242272 2023-09-27] (Google LLC -> Google LLC)
S3 cpuz154; \??\C:\Windows\temp\cpuz154\cpuz154_x64.sys [X]
S3 AscFileFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [X]
S3 AscRegistryFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [X]
2023-10-01 18:51 - 2023-10-02 01:05 - 000000000 ____D C:\ProgramData\IObit
2023-10-01 18:51 - 2023-10-01 23:41 - 000000000 ____D C:\Users\justc\AppData\LocalLow\IObit
2023-10-01 18:50 - 2023-10-01 23:41 - 000000000 ____D C:\Program Files (x86)\IObit
2023-10-01 18:50 - 2023-10-01 19:13 - 000000000 ____D C:\Users\justc\AppData\Roaming\IObit
C:\ProgramData\{7D4F950D-61ED-482D-A05D-43620B49B610}
C:\ProgramData\ProductData
C:\ProgramData\360Quarant
C:\Program Files (x86)\360
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu64.dll -> No File
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu64.dll -> No File
ShortcutWithArgument: C:\Users\justc\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncm\Gmail.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=aghbiahbpaijignceidepookljebhfak
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=fhihpiojkbmbpdjeoajapmgkhlnakfjf
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=kefjledonklijopmnomlcbpllchaibag
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml
ShortcutWithArgument: C:\Users\justc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\188f5ec9d11ded56\Profile 2 - Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory="Profile 1"
AlternateDataStreams: C:\Users\justc\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\HijackThis (1).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\HijackThis.exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (1).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (2).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (3).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\mwav (4).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\SnookerQSetup-20230923-0.1.710 (1).exe:BDU [0]
AlternateDataStreams: C:\Users\justc\Downloads\SnookerQSetup-20230923-0.1.710.exe:BDU [0]
emptytemp:
Reboot:
End::
*****************
Restore point was successfully created.
"HKU\S-1-5-21-2215749033-445842302-415398914-1001\Software\Microsoft\Windows\CurrentVersion\Run\\MicrosoftEdgeAutoLaunch_46C0173F98CBD0BEB36BBC1DDC54FE9A" => removed successfully
"HKU\S-1-5-21-2215749033-445842302-415398914-1001\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_B364DB4262BB88E80B8C959641DD7ACE" => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz154 => removed successfully
cpuz154 => service removed successfully
HKLM\System\CurrentControlSet\Services\AscFileFilter => removed successfully
AscFileFilter => service removed successfully
HKLM\System\CurrentControlSet\Services\AscRegistryFilter => removed successfully
AscRegistryFilter => service removed successfully
"C:\ProgramData\IObit" folder move:
Could not move "C:\ProgramData\IObit" => Scheduled to move on reboot.
"C:\Users\justc\AppData\LocalLow\IObit" folder move:
Could not move "C:\Users\justc\AppData\LocalLow\IObit" => Scheduled to move on reboot.
"C:\Program Files (x86)\IObit" folder move:
Could not move "C:\Program Files (x86)\IObit" => Scheduled to move on reboot.
"C:\Users\justc\AppData\Roaming\IObit" folder move:
Could not move "C:\Users\justc\AppData\Roaming\IObit" => Scheduled to move on reboot.
"C:\ProgramData\{7D4F950D-61ED-482D-A05D-43620B49B610}" folder move:
Could not move "C:\ProgramData\{7D4F950D-61ED-482D-A05D-43620B49B610}" => Scheduled to move on reboot.
"C:\ProgramData\ProductData" folder move:
Could not move "C:\ProgramData\ProductData" => Scheduled to move on reboot.
"C:\ProgramData\360Quarant" folder move:
Could not move "C:\ProgramData\360Quarant" => Scheduled to move on reboot.
"C:\Program Files (x86)\360" folder move:
Could not move "C:\Program Files (x86)\360" => Scheduled to move on reboot.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\AIMP => removed successfully
HKLM\Software\Classes\CLSID\{1F77B17B-F531-44DB-ACA4-76ABB5010A28} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\AIMP => removed successfully
C:\Users\justc\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncm\Gmail.lnk => Shortcut argument removed successfully
C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk => Shortcut argument removed successfully
C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk => Shortcut argument removed successfully
C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk => Shortcut argument removed successfully
C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk => Shortcut argument removed successfully
C:\Users\justc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk => Shortcut argument removed successfully
C:\Users\justc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\188f5ec9d11ded56\Profile 2 - Edge.lnk => Shortcut argument removed successfully
"C:\Users\justc\Desktop\FRST64.exe" => ":BDU" ADS not found.
C:\Users\justc\Downloads\HijackThis (1).exe => ":BDU" ADS removed successfully
C:\Users\justc\Downloads\HijackThis.exe => ":BDU" ADS removed successfully
C:\Users\justc\Downloads\mwav (1).exe => ":BDU" ADS removed successfully
C:\Users\justc\Downloads\mwav (2).exe => ":BDU" ADS removed successfully
C:\Users\justc\Downloads\mwav (3).exe => ":BDU" ADS removed successfully
C:\Users\justc\Downloads\mwav (4).exe => ":BDU" ADS removed successfully
C:\Users\justc\Downloads\SnookerQSetup-20230923-0.1.710 (1).exe => ":BDU" ADS removed successfully
C:\Users\justc\Downloads\SnookerQSetup-20230923-0.1.710.exe => ":BDU" ADS removed successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8547112 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 2604868 B
Edge => 0 B
Chrome => 334229704 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 9648 B
NetworkService => 9648 B
justc => -3068634 B
RecycleBin => 753 B
EmptyTemp: => 329.4 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 03-10-2023 08:25:12)
C:\ProgramData\IObit => Is moved successfully
C:\Users\justc\AppData\LocalLow\IObit => Is moved successfully
C:\Program Files (x86)\IObit => Is moved successfully
C:\Users\justc\AppData\Roaming\IObit => Is moved successfully
C:\ProgramData\{7D4F950D-61ED-482D-A05D-43620B49B610} => Is moved successfully
C:\ProgramData\ProductData => Is moved successfully
C:\ProgramData\360Quarant => Is moved successfully
C:\Program Files (x86)\360 => Is moved successfully
==== End of Fixlog 08:25:12 ====