Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2022
Ran by John (administrator) on SARAH-PC (Compaq-Presario GX618AA-ABA SR5350F) (14-12-2022 09:17:58)
Running from C:\Users\John\Downloads
Loaded Profiles: John
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\AVAST Software\Avast\AvastSvc.exe ->) (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(explorer.exe ->) (AOL Inc. -> AOL Inc.) C:\Program Files\AIM\aim.exe
(explorer.exe ->) (Google Inc -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe <15>
(explorer.exe ->) (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(explorer.exe ->) (Hewlett-Packard Company) [File not signed] C:\hp\support\hpsysdrv.exe
(explorer.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(explorer.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(explorer.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <2>
(explorer.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(explorer.exe ->) (OsdMaestro) [File not signed] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
(explorer.exe ->) (Yahoo! Inc. -> Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
(services.exe ->) (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(services.exe ->) (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(services.exe ->) (Hewlett-Packard Company) [File not signed] C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(svchost.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\igfxsrvc.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) [File not signed]
HKLM\...\Run: [OsdMaestro] => C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro) [File not signed]
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4874240 2008-01-15] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM\...\Run: [SunJavaUpdateReg] => C:\Windows\system32\jureg.exe [54680 2009-03-08] (Sun Microsystems, Inc. -> Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2153472 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2153472 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [Messenger (Yahoo!)] => C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [4363504 2009-01-08] (Yahoo! Inc. -> Yahoo! Inc.)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [Aim] => C:\Program Files\AIM\aim.exe [4156312 2017-02-23] (AOL Inc. -> AOL Inc.)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [AvastBrowserIsDefault] => "C:\Program Files\AVAST Software\Browser\Application\AvastBrowserProtector.exe" --force-protect (No File)
HKLM\...\Windows NT x86\Print Processors\winprint: localspl.dll (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe [2022-03-23] (Google Inc -> Google Inc.)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {33047591-8B4F-4E15-A0CF-4B4A30556B90} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /c (No File)
Task: {6F5E79BC-5451-4BE4-8858-F7F7B4B1B754} - System32\Tasks\JavaUpdateAdministrator => C:\Windows\system32\jusched.exe (No File)
Task: {7AF197DA-602F-486C-BD9B-8328544A7E5C} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-08] (Adobe Inc. -> Adobe) [File not signed]
Task: {7C040E69-E581-4AC7-8EB4-91071E0C4223} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [153168 2017-08-09] (Google Inc -> Google Inc.)
Task: {82D27DDD-CDE9-4646-8F0E-62E5BACA334D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [153168 2017-08-09] (Google Inc -> Google Inc.)
Task: {9AE06C97-3310-4680-BE3B-FEE61B6440FB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe) [File not signed]
Task: {A0364B18-9C67-4642-A27D-19F8E1364E9D} - System32\Tasks\PC-Doctor\Scheduled Maintanence => C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe [73728 2007-06-25] (PC-Doctor, Inc.) [File not signed]
Task: {C33B7959-E56A-475B-BCD0-562348DC4289} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1630008 2018-05-31] (AVAST Software s.r.o. -> AVAST Software)
Task: {E2A93A77-9013-4FB4-9718-72BBA2998F23} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2762968 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
Task: {EC2DD444-24FC-414F-B116-674077F8029E} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => Command(1): C:\Windows\servicing\vsp1ceip.exe [175104 [2008-01-19]] (Microsoft Windows -> Microsoft Corporation)
Task: {F0C37474-8AF1-4947-8556-6C4C06128A88} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /ua /installsource scheduler (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\User_Feed_Synchronization-{2216E477-7DEF-4482-AD03-D42193D074E7}.job => C:\Windows\system32\msfeedssync.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{73B646CC-8C74-4151-84F9-23E4B03FD810}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
FireFox:
========
FF ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\su7k0ty2.default-1670861870862 [2022-12-14]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-15] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-08] (Adobe Inc. -> ) [File not signed]
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2009-01-08] (Yahoo! Inc. -> Yahoo! Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\John\AppData\Local\Google\Chrome\User Data\Default [2022-12-14]
CHR Notifications: Default -> hxxps://www.facebook.com; hxxps://www.facebook.com
CHR Extension: (Slides) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
CHR Extension: (YouTube) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-09]
CHR Extension: (Sheets) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Google Docs Offline) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-01]
CHR Extension: (Gmail) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-25]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe) [File not signed]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6799632 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [324000 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
S2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2009-03-17] (Hewlett-Packard Company) [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
R2 XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [386560 2007-10-18] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
S2 avast; "C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /svc [X]
S3 avastm; "C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /medsvc [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [167480 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriverx.sys [188976 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidshx.sys [165384 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswblogx.sys [284256 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbunivx.sys [57904 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [183176 2018-11-26] (AVAST Software s.r.o. -> AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [42736 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [40688 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [135200 2019-01-18] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr.sys [70640 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [72800 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [784552 2019-05-23] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [397984 2019-05-23] (AVAST Software s.r.o. -> AVAST Software)
R3 aswStmXP; C:\Windows\System32\drivers\aswStmXP.sys [146584 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [310200 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R3 HSF_DP; C:\Windows\System32\DRIVERS\HSX_DP.sys [980992 2008-05-08] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
R3 HSXHWBS2; C:\Windows\System32\DRIVERS\HSXHWBS2.sys [266752 2008-05-08] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
S4 iteatapi; C:\Windows\system32\drivers\iteatapi.sys [35944 2006-11-02] (Microsoft Windows -> Integrated Technology Express, Inc.)
S4 iteraid; C:\Windows\system32\drivers\iteraid.sys [35944 2006-11-02] (Microsoft Windows -> Integrated Technology Express, Inc.)
R2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [12672 2006-06-19] (Microsoft Windows Hardware Compatibility Publisher -> Conexant)
S4 Mraid35x; C:\Windows\system32\drivers\mraid35x.sys [33384 2006-11-02] (Microsoft Windows -> LSI Logic Corporation)
S4 ntrigdigi; C:\Windows\system32\drivers\ntrigdigi.sys [20608 2006-11-02] (Microsoft Windows -> N-trig Innovative Technologies)
R3 RTL8169; C:\Windows\System32\DRIVERS\Rtlh86.sys [91648 2007-08-03] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Corporation)
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2009-01-23] (Acronis, Inc -> Acronis)
S4 uliahci; C:\Windows\system32\drivers\uliahci.sys [235112 2006-11-02] (Microsoft Windows -> ULi Electronics Inc.)
S4 UlSata; C:\Windows\system32\drivers\ulsata.sys [98408 2006-11-02] (Microsoft Windows -> Promise Technology, Inc.)
S4 ulsata2; C:\Windows\system32\drivers\ulsata2.sys [115816 2006-11-02] (Microsoft Windows -> Promise Technology, Inc.)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-01] (Microsoft Windows Hardware Compatibility Publisher -> America Online, Inc.)
R3 winachsf; C:\Windows\System32\DRIVERS\HSX_CNXT.sys [661504 2008-05-08] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
R2 XAudio; C:\Windows\System32\DRIVERS\xaudio.sys [8704 2007-10-18] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
S3 謌챊젳২精诿ﱊ젳│靖룿栨旟૩ﯦ쳿쳌쳌䶋菰Ӂ䗩诿솃郊↓咋ࠤ䊍謌젳짨靖룿桤旟퓩ﯥ쳿쳌쳌쳌쳌쳌쳌쳌⡪䖋僤靖菿ࣄ诃觩诿삃倌䖋僠秨菿ࣄ诃༁಄HdsKe; C:\Windows\system32\drivers\謌챊젳২精诿ﱊ젳│靖룿栨旟૩ﯦ쳿쳌쳌䶋菰Ӂ䗩诿솃郊↓咋ࠤ䊍謌젳짨靖룿桤旟퓩ﯥ쳿쳌쳌쳌쳌쳌쳌쳌⡪䖋僤靖菿ࣄ诃觩诿삃倌䖋僠秨菿ࣄ诃༁಄HdsKe.sys [84928 2017-09-07] (AVAST Software) [File not signed]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-12-14 09:17 - 2022-12-14 09:17 - 002078720 _____ (Farbar) C:\Users\John\Downloads\FRST(2).exe
2022-12-14 08:53 - 2022-12-14 08:56 - 000009280 _____ C:\Users\John\Downloads\Addition.txt
2022-12-14 08:49 - 2022-12-14 09:20 - 000018312 _____ C:\Users\John\Downloads\FRST.txt
2022-12-14 08:49 - 2022-12-14 08:49 - 002078720 _____ (Farbar) C:\Users\John\Downloads\FRST(1).exe
2022-12-14 08:48 - 2022-12-14 08:48 - 002375680 _____ (Farbar) C:\Users\John\Downloads\FRST64.exe
2022-12-14 08:46 - 2022-12-14 09:19 - 000000000 ____D C:\FRST
2022-12-14 08:46 - 2022-12-14 08:46 - 002078720 _____ (Farbar) C:\Users\John\Downloads\FRST.exe
2022-12-14 08:36 - 2022-12-14 08:36 - 008791352 _____ (Malwarebytes) C:\Users\John\Downloads\adwcleaner.exe
2022-12-14 08:30 - 2022-12-14 08:30 - 002821616 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(5).exe
2022-12-14 08:29 - 2022-12-14 08:29 - 002821640 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(4).exe
2022-12-14 08:03 - 2022-12-14 08:03 - 002821616 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(3).exe
2022-12-14 08:02 - 2022-12-14 08:02 - 002821640 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(2).exe
2022-12-14 07:37 - 2022-12-14 07:38 - 002821952 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(1).exe
2022-12-13 16:32 - 2022-12-13 16:32 - 002821976 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup.exe
2022-12-12 11:18 - 2022-12-12 11:18 - 000000000 ____D C:\Users\John\Desktop\Old Firefox Data
2022-12-12 02:15 - 2022-12-12 02:15 - 000145216 _____ C:\Windows\Minidump\Mini121222-01.dmp
2022-12-04 08:25 - 2022-12-04 08:25 - 000145216 _____ C:\Windows\Minidump\Mini120422-01.dmp
2022-12-01 18:40 - 2022-12-01 18:40 - 000145216 _____ C:\Windows\Minidump\Mini120122-01.dmp
2022-12-01 08:33 - 2018-11-21 04:46 - 000323288 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2022-11-27 20:43 - 2022-11-27 20:43 - 000145216 _____ C:\Windows\Minidump\Mini112722-01.dmp
2022-11-25 15:46 - 2022-11-25 15:46 - 000145216 _____ C:\Windows\Minidump\Mini112522-01.dmp
2022-11-24 13:53 - 2022-11-24 13:53 - 000145216 _____ C:\Windows\Minidump\Mini112422-01.dmp
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-12-14 09:15 - 2016-11-16 18:21 - 000000000 ____D C:\Users\John\AppData\LocalLow\Mozilla
2022-12-14 08:30 - 2006-11-02 07:47 - 000003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2022-12-14 08:30 - 2006-11-02 07:47 - 000003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2022-12-14 08:28 - 2015-02-18 02:48 - 000000000 ____D C:\Program Files\Google
2022-12-14 07:39 - 2015-09-30 15:49 - 000098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2022-12-14 05:42 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\inf
2022-12-13 08:36 - 2017-02-01 19:12 - 000000000 ___SD C:\Users\John\AppData\LocalLow\Temp
2022-12-13 07:43 - 2018-06-21 06:20 - 000000000 ____D C:\Users\John\AppData\Local\AVAST Software
2022-12-12 10:30 - 2006-11-02 08:01 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-12-12 10:29 - 2006-11-02 08:01 - 000032560 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2022-12-12 02:15 - 2008-08-01 14:35 - 000000000 ____D C:\Windows\Minidump
2022-12-12 02:14 - 2019-01-01 18:18 - 230307517 _____ C:\Windows\MEMORY.DMP
2022-12-10 21:11 - 2017-12-06 09:06 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2022-12-10 21:11 - 2017-08-09 22:31 - 000003322 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2022-12-10 21:11 - 2017-08-09 22:31 - 000003194 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2022-12-09 13:56 - 2011-05-14 04:56 - 000000000 ____D C:\Users\John\AppData\Roaming\HpUpdate
2022-12-08 18:41 - 2017-03-01 13:20 - 000004168 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2022-12-01 08:36 - 2017-01-31 18:26 - 000001835 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2022-11-30 23:31 - 2008-05-28 14:26 - 000000000 ____D C:\Users\John
2022-11-30 23:31 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\system32\spool
2022-11-30 23:31 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\system32\Msdtc
2022-11-30 23:31 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\registration
2022-11-30 23:31 - 2006-11-02 05:22 - 033554432 _____ C:\Windows\system32\config\software_previous
2022-11-30 23:31 - 2006-11-02 05:22 - 028573696 _____ C:\Windows\system32\config\system_previous
2022-11-30 23:26 - 2006-11-02 05:22 - 039583744 _____ C:\Windows\system32\config\components_previous
2022-11-30 23:26 - 2006-11-02 05:22 - 000053248 _____ C:\Windows\system32\config\sam_previous
2022-11-30 20:22 - 2006-11-02 05:22 - 000524288 _____ C:\Windows\system32\config\default_previous
2022-11-30 20:22 - 2006-11-02 05:22 - 000020480 _____ C:\Windows\system32\config\security_previous
==================== Files in the root of some directories ========
2010-10-18 11:59 - 2014-07-15 08:03 - 000003688 _____ () C:\Users\John\AppData\Roaming\wklnhst.dat
2010-04-11 20:10 - 2010-04-11 20:16 - 000010032 ___SH () C:\Users\John\AppData\Local\0CMR8yFmkXh
2011-07-05 19:55 - 2011-07-05 19:55 - 000001558 ___SH () C:\Users\John\AppData\Local\1hu4i5i6c1wx6ngdh3brb4vh33mo74i8k66043
2008-05-28 14:59 - 2022-05-31 09:00 - 000005892 _____ () C:\Users\John\AppData\Local\d3d9caps.dat
2009-01-23 18:47 - 2014-08-28 23:05 - 000007680 _____ () C:\Users\John\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-05-29 14:09 - 2011-05-29 14:17 - 000011864 ___SH () C:\Users\John\AppData\Local\e32lig0acfqskqq
2012-01-11 21:35 - 2012-01-11 21:41 - 000008642 ___SH () C:\Users\John\AppData\Local\q3k132b461d0vlmjgwe3423qks888wt4i067x
2010-02-11 07:57 - 2010-02-11 08:06 - 000007446 ___SH () C:\Users\John\AppData\Local\R4AlO7HdsW5
2021-10-21 05:01 - 2021-10-21 05:01 - 000000000 _____ () C:\Users\John\AppData\Local\{BF478C30-F17C-40D8-8397-984D790151A8}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-12-13 22:56
==================== End of FRST.txt ========================
Ran by John (administrator) on SARAH-PC (Compaq-Presario GX618AA-ABA SR5350F) (14-12-2022 09:17:58)
Running from C:\Users\John\Downloads
Loaded Profiles: John
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\AVAST Software\Avast\AvastSvc.exe ->) (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(explorer.exe ->) (AOL Inc. -> AOL Inc.) C:\Program Files\AIM\aim.exe
(explorer.exe ->) (Google Inc -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe <15>
(explorer.exe ->) (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(explorer.exe ->) (Hewlett-Packard Company) [File not signed] C:\hp\support\hpsysdrv.exe
(explorer.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(explorer.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(explorer.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <2>
(explorer.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(explorer.exe ->) (OsdMaestro) [File not signed] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
(explorer.exe ->) (Yahoo! Inc. -> Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
(services.exe ->) (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(services.exe ->) (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(services.exe ->) (Hewlett-Packard Company) [File not signed] C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(svchost.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\igfxsrvc.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) [File not signed]
HKLM\...\Run: [OsdMaestro] => C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro) [File not signed]
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4874240 2008-01-15] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM\...\Run: [SunJavaUpdateReg] => C:\Windows\system32\jureg.exe [54680 2009-03-08] (Sun Microsystems, Inc. -> Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2153472 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2153472 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [Messenger (Yahoo!)] => C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [4363504 2009-01-08] (Yahoo! Inc. -> Yahoo! Inc.)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [Aim] => C:\Program Files\AIM\aim.exe [4156312 2017-02-23] (AOL Inc. -> AOL Inc.)
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\...\Run: [AvastBrowserIsDefault] => "C:\Program Files\AVAST Software\Browser\Application\AvastBrowserProtector.exe" --force-protect (No File)
HKLM\...\Windows NT x86\Print Processors\winprint: localspl.dll (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe [2022-03-23] (Google Inc -> Google Inc.)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {33047591-8B4F-4E15-A0CF-4B4A30556B90} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /c (No File)
Task: {6F5E79BC-5451-4BE4-8858-F7F7B4B1B754} - System32\Tasks\JavaUpdateAdministrator => C:\Windows\system32\jusched.exe (No File)
Task: {7AF197DA-602F-486C-BD9B-8328544A7E5C} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-08] (Adobe Inc. -> Adobe) [File not signed]
Task: {7C040E69-E581-4AC7-8EB4-91071E0C4223} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [153168 2017-08-09] (Google Inc -> Google Inc.)
Task: {82D27DDD-CDE9-4646-8F0E-62E5BACA334D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [153168 2017-08-09] (Google Inc -> Google Inc.)
Task: {9AE06C97-3310-4680-BE3B-FEE61B6440FB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe) [File not signed]
Task: {A0364B18-9C67-4642-A27D-19F8E1364E9D} - System32\Tasks\PC-Doctor\Scheduled Maintanence => C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe [73728 2007-06-25] (PC-Doctor, Inc.) [File not signed]
Task: {C33B7959-E56A-475B-BCD0-562348DC4289} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1630008 2018-05-31] (AVAST Software s.r.o. -> AVAST Software)
Task: {E2A93A77-9013-4FB4-9718-72BBA2998F23} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2762968 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
Task: {EC2DD444-24FC-414F-B116-674077F8029E} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => Command(1): C:\Windows\servicing\vsp1ceip.exe [175104 [2008-01-19]] (Microsoft Windows -> Microsoft Corporation)
Task: {F0C37474-8AF1-4947-8556-6C4C06128A88} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /ua /installsource scheduler (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\User_Feed_Synchronization-{2216E477-7DEF-4482-AD03-D42193D074E7}.job => C:\Windows\system32\msfeedssync.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{73B646CC-8C74-4151-84F9-23E4B03FD810}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
FireFox:
========
FF ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\su7k0ty2.default-1670861870862 [2022-12-14]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-15] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-08] (Adobe Inc. -> ) [File not signed]
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2009-01-08] (Yahoo! Inc. -> Yahoo! Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\John\AppData\Local\Google\Chrome\User Data\Default [2022-12-14]
CHR Notifications: Default -> hxxps://www.facebook.com; hxxps://www.facebook.com
CHR Extension: (Slides) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
CHR Extension: (YouTube) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-09]
CHR Extension: (Sheets) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Google Docs Offline) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-01]
CHR Extension: (Gmail) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-25]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe) [File not signed]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6799632 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [324000 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
S2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2009-03-17] (Hewlett-Packard Company) [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Windows -> Microsoft Corporation)
R2 XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [386560 2007-10-18] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
S2 avast; "C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /svc [X]
S3 avastm; "C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /medsvc [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [167480 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriverx.sys [188976 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidshx.sys [165384 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswblogx.sys [284256 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbunivx.sys [57904 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [183176 2018-11-26] (AVAST Software s.r.o. -> AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [42736 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [40688 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [135200 2019-01-18] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr.sys [70640 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [72800 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [784552 2019-05-23] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [397984 2019-05-23] (AVAST Software s.r.o. -> AVAST Software)
R3 aswStmXP; C:\Windows\System32\drivers\aswStmXP.sys [146584 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [310200 2018-11-21] (AVAST Software s.r.o. -> AVAST Software)
R3 HSF_DP; C:\Windows\System32\DRIVERS\HSX_DP.sys [980992 2008-05-08] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
R3 HSXHWBS2; C:\Windows\System32\DRIVERS\HSXHWBS2.sys [266752 2008-05-08] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
S4 iteatapi; C:\Windows\system32\drivers\iteatapi.sys [35944 2006-11-02] (Microsoft Windows -> Integrated Technology Express, Inc.)
S4 iteraid; C:\Windows\system32\drivers\iteraid.sys [35944 2006-11-02] (Microsoft Windows -> Integrated Technology Express, Inc.)
R2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [12672 2006-06-19] (Microsoft Windows Hardware Compatibility Publisher -> Conexant)
S4 Mraid35x; C:\Windows\system32\drivers\mraid35x.sys [33384 2006-11-02] (Microsoft Windows -> LSI Logic Corporation)
S4 ntrigdigi; C:\Windows\system32\drivers\ntrigdigi.sys [20608 2006-11-02] (Microsoft Windows -> N-trig Innovative Technologies)
R3 RTL8169; C:\Windows\System32\DRIVERS\Rtlh86.sys [91648 2007-08-03] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Corporation)
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2009-01-23] (Acronis, Inc -> Acronis)
S4 uliahci; C:\Windows\system32\drivers\uliahci.sys [235112 2006-11-02] (Microsoft Windows -> ULi Electronics Inc.)
S4 UlSata; C:\Windows\system32\drivers\ulsata.sys [98408 2006-11-02] (Microsoft Windows -> Promise Technology, Inc.)
S4 ulsata2; C:\Windows\system32\drivers\ulsata2.sys [115816 2006-11-02] (Microsoft Windows -> Promise Technology, Inc.)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-01] (Microsoft Windows Hardware Compatibility Publisher -> America Online, Inc.)
R3 winachsf; C:\Windows\System32\DRIVERS\HSX_CNXT.sys [661504 2008-05-08] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
R2 XAudio; C:\Windows\System32\DRIVERS\xaudio.sys [8704 2007-10-18] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
S3 謌챊젳২精诿ﱊ젳│靖룿栨旟૩ﯦ쳿쳌쳌䶋菰Ӂ䗩诿솃郊↓咋ࠤ䊍謌젳짨靖룿桤旟퓩ﯥ쳿쳌쳌쳌쳌쳌쳌쳌⡪䖋僤靖菿ࣄ诃觩诿삃倌䖋僠秨菿ࣄ诃༁಄HdsKe; C:\Windows\system32\drivers\謌챊젳২精诿ﱊ젳│靖룿栨旟૩ﯦ쳿쳌쳌䶋菰Ӂ䗩诿솃郊↓咋ࠤ䊍謌젳짨靖룿桤旟퓩ﯥ쳿쳌쳌쳌쳌쳌쳌쳌⡪䖋僤靖菿ࣄ诃觩诿삃倌䖋僠秨菿ࣄ诃༁಄HdsKe.sys [84928 2017-09-07] (AVAST Software) [File not signed]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-12-14 09:17 - 2022-12-14 09:17 - 002078720 _____ (Farbar) C:\Users\John\Downloads\FRST(2).exe
2022-12-14 08:53 - 2022-12-14 08:56 - 000009280 _____ C:\Users\John\Downloads\Addition.txt
2022-12-14 08:49 - 2022-12-14 09:20 - 000018312 _____ C:\Users\John\Downloads\FRST.txt
2022-12-14 08:49 - 2022-12-14 08:49 - 002078720 _____ (Farbar) C:\Users\John\Downloads\FRST(1).exe
2022-12-14 08:48 - 2022-12-14 08:48 - 002375680 _____ (Farbar) C:\Users\John\Downloads\FRST64.exe
2022-12-14 08:46 - 2022-12-14 09:19 - 000000000 ____D C:\FRST
2022-12-14 08:46 - 2022-12-14 08:46 - 002078720 _____ (Farbar) C:\Users\John\Downloads\FRST.exe
2022-12-14 08:36 - 2022-12-14 08:36 - 008791352 _____ (Malwarebytes) C:\Users\John\Downloads\adwcleaner.exe
2022-12-14 08:30 - 2022-12-14 08:30 - 002821616 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(5).exe
2022-12-14 08:29 - 2022-12-14 08:29 - 002821640 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(4).exe
2022-12-14 08:03 - 2022-12-14 08:03 - 002821616 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(3).exe
2022-12-14 08:02 - 2022-12-14 08:02 - 002821640 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(2).exe
2022-12-14 07:37 - 2022-12-14 07:38 - 002821952 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup(1).exe
2022-12-13 16:32 - 2022-12-13 16:32 - 002821976 _____ (Opera Software) C:\Users\John\Downloads\OperaSetup.exe
2022-12-12 11:18 - 2022-12-12 11:18 - 000000000 ____D C:\Users\John\Desktop\Old Firefox Data
2022-12-12 02:15 - 2022-12-12 02:15 - 000145216 _____ C:\Windows\Minidump\Mini121222-01.dmp
2022-12-04 08:25 - 2022-12-04 08:25 - 000145216 _____ C:\Windows\Minidump\Mini120422-01.dmp
2022-12-01 18:40 - 2022-12-01 18:40 - 000145216 _____ C:\Windows\Minidump\Mini120122-01.dmp
2022-12-01 08:33 - 2018-11-21 04:46 - 000323288 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2022-11-27 20:43 - 2022-11-27 20:43 - 000145216 _____ C:\Windows\Minidump\Mini112722-01.dmp
2022-11-25 15:46 - 2022-11-25 15:46 - 000145216 _____ C:\Windows\Minidump\Mini112522-01.dmp
2022-11-24 13:53 - 2022-11-24 13:53 - 000145216 _____ C:\Windows\Minidump\Mini112422-01.dmp
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-12-14 09:15 - 2016-11-16 18:21 - 000000000 ____D C:\Users\John\AppData\LocalLow\Mozilla
2022-12-14 08:30 - 2006-11-02 07:47 - 000003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2022-12-14 08:30 - 2006-11-02 07:47 - 000003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2022-12-14 08:28 - 2015-02-18 02:48 - 000000000 ____D C:\Program Files\Google
2022-12-14 07:39 - 2015-09-30 15:49 - 000098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2022-12-14 05:42 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\inf
2022-12-13 08:36 - 2017-02-01 19:12 - 000000000 ___SD C:\Users\John\AppData\LocalLow\Temp
2022-12-13 07:43 - 2018-06-21 06:20 - 000000000 ____D C:\Users\John\AppData\Local\AVAST Software
2022-12-12 10:30 - 2006-11-02 08:01 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-12-12 10:29 - 2006-11-02 08:01 - 000032560 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2022-12-12 02:15 - 2008-08-01 14:35 - 000000000 ____D C:\Windows\Minidump
2022-12-12 02:14 - 2019-01-01 18:18 - 230307517 _____ C:\Windows\MEMORY.DMP
2022-12-10 21:11 - 2017-12-06 09:06 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2022-12-10 21:11 - 2017-08-09 22:31 - 000003322 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2022-12-10 21:11 - 2017-08-09 22:31 - 000003194 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2022-12-09 13:56 - 2011-05-14 04:56 - 000000000 ____D C:\Users\John\AppData\Roaming\HpUpdate
2022-12-08 18:41 - 2017-03-01 13:20 - 000004168 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2022-12-01 08:36 - 2017-01-31 18:26 - 000001835 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2022-11-30 23:31 - 2008-05-28 14:26 - 000000000 ____D C:\Users\John
2022-11-30 23:31 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\system32\spool
2022-11-30 23:31 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\system32\Msdtc
2022-11-30 23:31 - 2006-11-02 06:18 - 000000000 ____D C:\Windows\registration
2022-11-30 23:31 - 2006-11-02 05:22 - 033554432 _____ C:\Windows\system32\config\software_previous
2022-11-30 23:31 - 2006-11-02 05:22 - 028573696 _____ C:\Windows\system32\config\system_previous
2022-11-30 23:26 - 2006-11-02 05:22 - 039583744 _____ C:\Windows\system32\config\components_previous
2022-11-30 23:26 - 2006-11-02 05:22 - 000053248 _____ C:\Windows\system32\config\sam_previous
2022-11-30 20:22 - 2006-11-02 05:22 - 000524288 _____ C:\Windows\system32\config\default_previous
2022-11-30 20:22 - 2006-11-02 05:22 - 000020480 _____ C:\Windows\system32\config\security_previous
==================== Files in the root of some directories ========
2010-10-18 11:59 - 2014-07-15 08:03 - 000003688 _____ () C:\Users\John\AppData\Roaming\wklnhst.dat
2010-04-11 20:10 - 2010-04-11 20:16 - 000010032 ___SH () C:\Users\John\AppData\Local\0CMR8yFmkXh
2011-07-05 19:55 - 2011-07-05 19:55 - 000001558 ___SH () C:\Users\John\AppData\Local\1hu4i5i6c1wx6ngdh3brb4vh33mo74i8k66043
2008-05-28 14:59 - 2022-05-31 09:00 - 000005892 _____ () C:\Users\John\AppData\Local\d3d9caps.dat
2009-01-23 18:47 - 2014-08-28 23:05 - 000007680 _____ () C:\Users\John\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-05-29 14:09 - 2011-05-29 14:17 - 000011864 ___SH () C:\Users\John\AppData\Local\e32lig0acfqskqq
2012-01-11 21:35 - 2012-01-11 21:41 - 000008642 ___SH () C:\Users\John\AppData\Local\q3k132b461d0vlmjgwe3423qks888wt4i067x
2010-02-11 07:57 - 2010-02-11 08:06 - 000007446 ___SH () C:\Users\John\AppData\Local\R4AlO7HdsW5
2021-10-21 05:01 - 2021-10-21 05:01 - 000000000 _____ () C:\Users\John\AppData\Local\{BF478C30-F17C-40D8-8397-984D790151A8}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-12-13 22:56
==================== End of FRST.txt ========================