Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-11-2017
Ran by Administrator (administrator) on NEWUSER-PC (29-11-2017 10:40:07)
Running from C:\Users\Administrator\Downloads
Loaded Profiles: Administrator (Available Profiles: New User & Administrator)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Users\Administrator\Downloads\FRST (1).exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-29] (AVAST Software)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [267064 2017-03-22] (Apple Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-914808374-759592663-328091246-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6667992 2016-03-11] (Piriform Ltd)
GroupPolicy\User: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{73748022-E818-48DB-AB21-06430F24F6E5}: [NameServer] 76.73.7.75,107.6.133.7
Tcpip\..\Interfaces\{73748022-E818-48DB-AB21-06430F24F6E5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{94E21882-9300-4201-AB49-B77C93CC0691}: [DhcpNameServer] 172.20.10.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131189595039368748&GUID=FF7E1EFE-CF2D-49A9-BDC9-5BF3665BC833
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131189595039680749&GUID=FF7E1EFE-CF2D-49A9-BDC9-5BF3665BC833
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131189595039680749&GUID=FF7E1EFE-CF2D-49A9-BDC9-5BF3665BC833
HKU\S-1-5-21-914808374-759592663-328091246-500\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-914808374-759592663-328091246-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://outlook.live.com/owa/?path=/mail/AQMkADAwATIwMTAwAC0wMTI3LWNiNjItMDACLTAwCgAuAAADVVwnRb%2F%2ByUSv%2B010boFkFQEADTaWMq31aES4Uomoz7M4IAAAAgFUAAAA
HKU\S-1-5-21-914808374-759592663-328091246-500\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.google.com/?gws_rd=ssl#q=how+to+make+my+email+page+my+homepage+internet+explorer
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-914808374-759592663-328091246-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U218DF&PC=U218&q={searchTerms}&src=IE-SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-15] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-01-07] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-15] (Google Inc.)
Toolbar: HKU\S-1-5-21-914808374-759592663-328091246-500 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-15] (Google Inc.)
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
FireFox:
========
FF DefaultProfile: se9kv7zw.default
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default [2017-11-29]
FF Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\extensions\toolbar11367@freshy.com.xpi [not found]
FF Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\extensions\TidyNetwork@TidyNetwork [not found]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\searchplugins\bing-avast.xml [2015-05-08]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\searchplugins\Yahoo powered search.xml [2016-10-20]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\searchplugins\yahoo-avast.xml [2015-03-09]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [2011-09-29] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2011-09-16] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-01-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll [No File]
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-01-07] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2017-03-23]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default [2017-11-29]
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-08]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-08]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-20]
CHR Extension: (Google Search) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-08]
CHR Extension: (Bookmark Manager) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-08]
CHR Extension: (avast! Online Security) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-08]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-20]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-08]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-08]
CHR HKLM\...\Chrome\Extension: [anacbkknplojdncnpbhfkkmecdjlmleg] - C:\Program Files\OApps\chrome-sl.crx
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
StartMenuInternet: Google Chrome.HW4BWTSX2CCN2Y5XYLY67PDS3M - C:\Users\New User\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5904136 2017-11-29] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-29] (AVAST Software)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4563920 2017-11-01] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
S4 SCManager; C:\Program Files\SafeConnect\scManager.sys [176520 2012-11-19] (Impulse Point, LLC)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [157176 2017-11-29] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriverx.sys [255616 2017-11-29] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidshx.sys [157408 2017-11-29] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\System32\drivers\aswblogx.sys [276728 2017-11-29] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\System32\drivers\aswbunivx.sys [50376 2017-11-29] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [65344 2017-01-17] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [42848 2017-11-29] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [35096 2016-09-26] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [124952 2017-11-29] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [99560 2017-11-29] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [70864 2017-11-29] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [783136 2017-11-29] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [388760 2017-11-29] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [150848 2017-11-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [298360 2017-11-29] (AVAST Software)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-12] (AVG Technologies)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [59896 2017-11-01] ()
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [167352 2017-11-29] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [91576 2017-11-29] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [40376 2017-11-29] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [221112 2017-11-29] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [65824 2017-11-29] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
S1 afdivuwu; \??\C:\Windows\system32\drivers\afdivuwu.sys [X]
S1 agbgyfat; \??\C:\Windows\system32\drivers\agbgyfat.sys [X]
S1 anspeouj; \??\C:\Windows\system32\drivers\anspeouj.sys [X]
S1 aojjsesl; \??\C:\Windows\system32\drivers\aojjsesl.sys [X]
S1 aonnczhl; \??\C:\Windows\system32\drivers\aonnczhl.sys [X]
S1 aoscdxio; \??\C:\Windows\system32\drivers\aoscdxio.sys [X]
S1 arxuykmj; \??\C:\Windows\system32\drivers\arxuykmj.sys [X]
S1 asmewgdv; \??\C:\Windows\system32\drivers\asmewgdv.sys [X]
S1 auraxxir; \??\C:\Windows\system32\drivers\auraxxir.sys [X]
S1 avafugts; \??\C:\Windows\system32\drivers\avafugts.sys [X]
S1 avsibhjp; \??\C:\Windows\system32\drivers\avsibhjp.sys [X]
S1 axnurzoh; \??\C:\Windows\system32\drivers\axnurzoh.sys [X]
S1 bfobislo; \??\C:\Windows\system32\drivers\bfobislo.sys [X]
S1 bgbooorc; \??\C:\Windows\system32\drivers\bgbooorc.sys [X]
S1 bjccjqpt; \??\C:\Windows\system32\drivers\bjccjqpt.sys [X]
S1 bjvodcyt; \??\C:\Windows\system32\drivers\bjvodcyt.sys [X]
S1 bqjgpqxt; \??\C:\Windows\system32\drivers\bqjgpqxt.sys [X]
S1 brsjhlwy; \??\C:\Windows\system32\drivers\brsjhlwy.sys [X]
S1 btpfgaqv; \??\C:\Windows\system32\drivers\btpfgaqv.sys [X]
S1 btwrjxme; \??\C:\Windows\system32\drivers\btwrjxme.sys [X]
S1 bvechhvl; \??\C:\Windows\system32\drivers\bvechhvl.sys [X]
S1 bxuxpvgn; \??\C:\Windows\system32\drivers\bxuxpvgn.sys [X]
S3 catchme; \??\C:\Users\ADMINI~1\AppData\Local\Temp\catchme.sys [X]
S1 cczgmozq; \??\C:\Windows\system32\drivers\cczgmozq.sys [X]
S1 cehcdifo; \??\C:\Windows\system32\drivers\cehcdifo.sys [X]
S1 cifofbyc; \??\C:\Windows\system32\drivers\cifofbyc.sys [X]
S1 circuygo; \??\C:\Windows\system32\drivers\circuygo.sys [X]
S1 cmxpfewc; \??\C:\Windows\system32\drivers\cmxpfewc.sys [X]
S1 cnvgnbky; \??\C:\Windows\system32\drivers\cnvgnbky.sys [X]
S1 cqvjmugj; \??\C:\Windows\system32\drivers\cqvjmugj.sys [X]
S1 cscgzzpq; \??\C:\Windows\system32\drivers\cscgzzpq.sys [X]
S1 cynslgqb; \??\C:\Windows\system32\drivers\cynslgqb.sys [X]
S1 dhktjafl; \??\C:\Windows\system32\drivers\dhktjafl.sys [X]
S1 diqsddfa; \??\C:\Windows\system32\drivers\diqsddfa.sys [X]
S1 dnaojagy; \??\C:\Windows\system32\drivers\dnaojagy.sys [X]
S1 dswjbcdh; \??\C:\Windows\system32\drivers\dswjbcdh.sys [X]
S1 dubridng; \??\C:\Windows\system32\drivers\dubridng.sys [X]
S1 ebmoqtri; \??\C:\Windows\system32\drivers\ebmoqtri.sys [X]
S1 ehlnzlyf; \??\C:\Windows\system32\drivers\ehlnzlyf.sys [X]
S1 emieplht; \??\C:\Windows\system32\drivers\emieplht.sys [X]
S1 ewnmtgzh; \??\C:\Windows\system32\drivers\ewnmtgzh.sys [X]
S1 ewvsiclk; \??\C:\Windows\system32\drivers\ewvsiclk.sys [X]
S1 fcbqkbes; \??\C:\Windows\system32\drivers\fcbqkbes.sys [X]
S1 fcegngzu; \??\C:\Windows\system32\drivers\fcegngzu.sys [X]
S1 fcfxcjxx; \??\C:\Windows\system32\drivers\fcfxcjxx.sys [X]
S1 fdlkbcuf; \??\C:\Windows\system32\drivers\fdlkbcuf.sys [X]
S1 fdwrshnk; \??\C:\Windows\system32\drivers\fdwrshnk.sys [X]
S1 ffontlzk; \??\C:\Windows\system32\drivers\ffontlzk.sys [X]
S1 ffqkjdol; \??\C:\Windows\system32\drivers\ffqkjdol.sys [X]
S1 fivxdpjk; \??\C:\Windows\system32\drivers\fivxdpjk.sys [X]
S1 flmfpbha; \??\C:\Windows\system32\drivers\flmfpbha.sys [X]
S1 fsflywfn; \??\C:\Windows\system32\drivers\fsflywfn.sys [X]
S1 gbsslhhy; \??\C:\Windows\system32\drivers\gbsslhhy.sys [X]
S1 gfjpcymu; \??\C:\Windows\system32\drivers\gfjpcymu.sys [X]
S1 ggtqidoi; \??\C:\Windows\system32\drivers\ggtqidoi.sys [X]
S1 ggyferpt; \??\C:\Windows\system32\drivers\ggyferpt.sys [X]
S1 gpockzrf; \??\C:\Windows\system32\drivers\gpockzrf.sys [X]
S1 gtqdpbaq; \??\C:\Windows\system32\drivers\gtqdpbaq.sys [X]
S1 gwuqhdpc; \??\C:\Windows\system32\drivers\gwuqhdpc.sys [X]
S1 hgzhzuuz; \??\C:\Windows\system32\drivers\hgzhzuuz.sys [X]
S1 hljgnucy; \??\C:\Windows\system32\drivers\hljgnucy.sys [X]
S1 hqmxqedq; \??\C:\Windows\system32\drivers\hqmxqedq.sys [X]
S1 idbsxlcs; \??\C:\Windows\system32\drivers\idbsxlcs.sys [X]
S1 iddwqvds; \??\C:\Windows\system32\drivers\iddwqvds.sys [X]
S1 ikzofkiq; \??\C:\Windows\system32\drivers\ikzofkiq.sys [X]
S1 ilsgsotq; \??\C:\Windows\system32\drivers\ilsgsotq.sys [X]
S1 irjrnkof; \??\C:\Windows\system32\drivers\irjrnkof.sys [X]
S1 itgqetir; \??\C:\Windows\system32\drivers\itgqetir.sys [X]
S1 iuaglmsv; \??\C:\Windows\system32\drivers\iuaglmsv.sys [X]
S1 ixushmeh; \??\C:\Windows\system32\drivers\ixushmeh.sys [X]
S1 janjmyrx; \??\C:\Windows\system32\drivers\janjmyrx.sys [X]
S1 jbhanhwq; \??\C:\Windows\system32\drivers\jbhanhwq.sys [X]
S1 jcrrchbm; \??\C:\Windows\system32\drivers\jcrrchbm.sys [X]
S1 jgrkyfrw; \??\C:\Windows\system32\drivers\jgrkyfrw.sys [X]
S1 jiqakcef; \??\C:\Windows\system32\drivers\jiqakcef.sys [X]
S1 jkhamied; \??\C:\Windows\system32\drivers\jkhamied.sys [X]
S1 jobyazcp; \??\C:\Windows\system32\drivers\jobyazcp.sys [X]
S1 jpitlgyr; \??\C:\Windows\system32\drivers\jpitlgyr.sys [X]
S1 jsozmxag; \??\C:\Windows\system32\drivers\jsozmxag.sys [X]
S1 kewgjmvr; \??\C:\Windows\system32\drivers\kewgjmvr.sys [X]
S1 kgjgxgfc; \??\C:\Windows\system32\drivers\kgjgxgfc.sys [X]
S1 kkrizifb; \??\C:\Windows\system32\drivers\kkrizifb.sys [X]
S1 kpcfnajf; \??\C:\Windows\system32\drivers\kpcfnajf.sys [X]
S1 kseupdmb; \??\C:\Windows\system32\drivers\kseupdmb.sys [X]
S1 kwnyscxx; \??\C:\Windows\system32\drivers\kwnyscxx.sys [X]
S1 kyguvgwn; \??\C:\Windows\system32\drivers\kyguvgwn.sys [X]
S1 lcudrefu; \??\C:\Windows\system32\drivers\lcudrefu.sys [X]
S1 lfikjbby; \??\C:\Windows\system32\drivers\lfikjbby.sys [X]
S1 lfodztlv; \??\C:\Windows\system32\drivers\lfodztlv.sys [X]
S1 lhuctkuw; \??\C:\Windows\system32\drivers\lhuctkuw.sys [X]
S1 lirpssca; \??\C:\Windows\system32\drivers\lirpssca.sys [X]
S1 loacqulo; \??\C:\Windows\system32\drivers\loacqulo.sys [X]
S1 lrkiqzpn; \??\C:\Windows\system32\drivers\lrkiqzpn.sys [X]
S1 lzcuyhqp; \??\C:\Windows\system32\drivers\lzcuyhqp.sys [X]
S1 lzhthtle; \??\C:\Windows\system32\drivers\lzhthtle.sys [X]
S1 mbchseag; \??\C:\Windows\system32\drivers\mbchseag.sys [X]
S1 mghdxudt; \??\C:\Windows\system32\drivers\mghdxudt.sys [X]
S1 mnaptwlo; \??\C:\Windows\system32\drivers\mnaptwlo.sys [X]
S1 mxytqmmp; \??\C:\Windows\system32\drivers\mxytqmmp.sys [X]
S1 mxzzbipw; \??\C:\Windows\system32\drivers\mxzzbipw.sys [X]
S1 mzgxmryv; \??\C:\Windows\system32\drivers\mzgxmryv.sys [X]
S1 ndzjaugg; \??\C:\Windows\system32\drivers\ndzjaugg.sys [X]
S1 neucxbpc; \??\C:\Windows\system32\drivers\neucxbpc.sys [X]
S1 nfyysmew; \??\C:\Windows\system32\drivers\nfyysmew.sys [X]
S1 ngralood; \??\C:\Windows\system32\drivers\ngralood.sys [X]
S1 ngrlzwrd; \??\C:\Windows\system32\drivers\ngrlzwrd.sys [X]
S1 nkgbdpyw; \??\C:\Windows\system32\drivers\nkgbdpyw.sys [X]
S1 nkjjcisc; \??\C:\Windows\system32\drivers\nkjjcisc.sys [X]
S1 noyomhol; \??\C:\Windows\system32\drivers\noyomhol.sys [X]
S1 nricvzas; \??\C:\Windows\system32\drivers\nricvzas.sys [X]
S1 ntckxetg; \??\C:\Windows\system32\drivers\ntckxetg.sys [X]
S1 ntcyzgnw; \??\C:\Windows\system32\drivers\ntcyzgnw.sys [X]
S1 nzagpeuk; \??\C:\Windows\system32\drivers\nzagpeuk.sys [X]
S1 obsdpjrz; \??\C:\Windows\system32\drivers\obsdpjrz.sys [X]
S1 obtqdeyu; \??\C:\Windows\system32\drivers\obtqdeyu.sys [X]
S1 obztevfy; \??\C:\Windows\system32\drivers\obztevfy.sys [X]
S1 ongdukcq; \??\C:\Windows\system32\drivers\ongdukcq.sys [X]
S1 ookfmgwl; \??\C:\Windows\system32\drivers\ookfmgwl.sys [X]
S1 oqoxyegi; \??\C:\Windows\system32\drivers\oqoxyegi.sys [X]
S1 owtngtiz; \??\C:\Windows\system32\drivers\owtngtiz.sys [X]
S1 oxvkjyyd; \??\C:\Windows\system32\drivers\oxvkjyyd.sys [X]
S1 pewmadkg; \??\C:\Windows\system32\drivers\pewmadkg.sys [X]
S1 phxtnroa; \??\C:\Windows\system32\drivers\phxtnroa.sys [X]
S1 pypbmsyc; \??\C:\Windows\system32\drivers\pypbmsyc.sys [X]
S1 pzlofker; \??\C:\Windows\system32\drivers\pzlofker.sys [X]
S1 qaxmljko; \??\C:\Windows\system32\drivers\qaxmljko.sys [X]
S1 qcezrzaw; \??\C:\Windows\system32\drivers\qcezrzaw.sys [X]
S1 qchkgadm; \??\C:\Windows\system32\drivers\qchkgadm.sys [X]
S1 qfhilepk; \??\C:\Windows\system32\drivers\qfhilepk.sys [X]
S1 qftfhebo; \??\C:\Windows\system32\drivers\qftfhebo.sys [X]
S1 qhknkfqk; \??\C:\Windows\system32\drivers\qhknkfqk.sys [X]
S1 qtvotjnt; \??\C:\Windows\system32\drivers\qtvotjnt.sys [X]
S1 quwhqura; \??\C:\Windows\system32\drivers\quwhqura.sys [X]
S1 rkferrej; \??\C:\Windows\system32\drivers\rkferrej.sys [X]
S1 rkgxfoov; \??\C:\Windows\system32\drivers\rkgxfoov.sys [X]
S1 rkuxirpn; \??\C:\Windows\system32\drivers\rkuxirpn.sys [X]
S1 rmndjgmd; \??\C:\Windows\system32\drivers\rmndjgmd.sys [X]
S1 rogknzxp; \??\C:\Windows\system32\drivers\rogknzxp.sys [X]
S1 rpqbhdbn; \??\C:\Windows\system32\drivers\rpqbhdbn.sys [X]
S1 rqdepymj; \??\C:\Windows\system32\drivers\rqdepymj.sys [X]
S1 rvolhsih; \??\C:\Windows\system32\drivers\rvolhsih.sys [X]
S1 rvraysee; \??\C:\Windows\system32\drivers\rvraysee.sys [X]
S1 sgghfzer; \??\C:\Windows\system32\drivers\sgghfzer.sys [X]
S1 sltfisdi; \??\C:\Windows\system32\drivers\sltfisdi.sys [X]
S1 spbigqyn; \??\C:\Windows\system32\drivers\spbigqyn.sys [X]
S1 srsbmlzi; \??\C:\Windows\system32\drivers\srsbmlzi.sys [X]
S1 stbasfjy; \??\C:\Windows\system32\drivers\stbasfjy.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S1 tdnibiod; \??\C:\Windows\system32\drivers\tdnibiod.sys [X]
S1 thadkseq; \??\C:\Windows\system32\drivers\thadkseq.sys [X]
S1 thccjafx; \??\C:\Windows\system32\drivers\thccjafx.sys [X]
S1 tihmnqrf; \??\C:\Windows\system32\drivers\tihmnqrf.sys [X]
S1 tjxuyiha; \??\C:\Windows\system32\drivers\tjxuyiha.sys [X]
S1 toayjwnz; \??\C:\Windows\system32\drivers\toayjwnz.sys [X]
S1 tqnnagnl; \??\C:\Windows\system32\drivers\tqnnagnl.sys [X]
S1 tqpnjocd; \??\C:\Windows\system32\drivers\tqpnjocd.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S1 tzkzotja; \??\C:\Windows\system32\drivers\tzkzotja.sys [X]
S1 uclztmzh; \??\C:\Windows\system32\drivers\uclztmzh.sys [X]
S1 uidtdlbi; \??\C:\Windows\system32\drivers\uidtdlbi.sys [X]
S1 ujsppubm; \??\C:\Windows\system32\drivers\ujsppubm.sys [X]
S1 ukjbhzjs; \??\C:\Windows\system32\drivers\ukjbhzjs.sys [X]
S1 ushbmqhg; \??\C:\Windows\system32\drivers\ushbmqhg.sys [X]
S1 uwddgrpe; \??\C:\Windows\system32\drivers\uwddgrpe.sys [X]
S1 vaqrqnfr; \??\C:\Windows\system32\drivers\vaqrqnfr.sys [X]
S1 vervcinv; \??\C:\Windows\system32\drivers\vervcinv.sys [X]
S1 vfpluzdv; \??\C:\Windows\system32\drivers\vfpluzdv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 viybnrep; \??\C:\Windows\system32\drivers\viybnrep.sys [X]
S1 vngnmwur; \??\C:\Windows\system32\drivers\vngnmwur.sys [X]
S1 vnhsblqk; \??\C:\Windows\system32\drivers\vnhsblqk.sys [X]
S1 vpkjvrjb; \??\C:\Windows\system32\drivers\vpkjvrjb.sys [X]
S1 vupbwzhm; \??\C:\Windows\system32\drivers\vupbwzhm.sys [X]
S1 vuukbrru; \??\C:\Windows\system32\drivers\vuukbrru.sys [X]
S1 vuzmzvru; \??\C:\Windows\system32\drivers\vuzmzvru.sys [X]
S1 vwfpfvmo; \??\C:\Windows\system32\drivers\vwfpfvmo.sys [X]
S1 wbrapvjc; \??\C:\Windows\system32\drivers\wbrapvjc.sys [X]
S0 wfkeuy; System32\drivers\colxvtng.sys [X]
S1 wkmcbxsn; \??\C:\Windows\system32\drivers\wkmcbxsn.sys [X]
S1 wlcbottc; \??\C:\Windows\system32\drivers\wlcbottc.sys [X]
S1 wmtlgjvs; \??\C:\Windows\system32\drivers\wmtlgjvs.sys [X]
S1 wqwtxpaa; \??\C:\Windows\system32\drivers\wqwtxpaa.sys [X]
S1 wrhnrtrs; \??\C:\Windows\system32\drivers\wrhnrtrs.sys [X]
S1 wxllmhbq; \??\C:\Windows\system32\drivers\wxllmhbq.sys [X]
S1 xakbgcce; \??\C:\Windows\system32\drivers\xakbgcce.sys [X]
S1 xcvaytpk; \??\C:\Windows\system32\drivers\xcvaytpk.sys [X]
S1 xgvusuym; \??\C:\Windows\system32\drivers\xgvusuym.sys [X]
S1 xhcclinj; \??\C:\Windows\system32\drivers\xhcclinj.sys [X]
S1 xjrdofpg; \??\C:\Windows\system32\drivers\xjrdofpg.sys [X]
S1 xkdxpobt; \??\C:\Windows\system32\drivers\xkdxpobt.sys [X]
S1 xrbakghj; \??\C:\Windows\system32\drivers\xrbakghj.sys [X]
S1 xtfsoaxo; \??\C:\Windows\system32\drivers\xtfsoaxo.sys [X]
S1 yausplos; \??\C:\Windows\system32\drivers\yausplos.sys [X]
S1 yiudaent; \??\C:\Windows\system32\drivers\yiudaent.sys [X]
S1 yivzfage; \??\C:\Windows\system32\drivers\yivzfage.sys [X]
S1 yshprhfd; \??\C:\Windows\system32\drivers\yshprhfd.sys [X]
S1 yudvilad; \??\C:\Windows\system32\drivers\yudvilad.sys [X]
S1 zazuzpwo; \??\C:\Windows\system32\drivers\zazuzpwo.sys [X]
S1 zbplivgr; \??\C:\Windows\system32\drivers\zbplivgr.sys [X]
S1 zeomwijg; \??\C:\Windows\system32\drivers\zeomwijg.sys [X]
S1 zmhowvdu; \??\C:\Windows\system32\drivers\zmhowvdu.sys [X]
S1 zsjufcuf; \??\C:\Windows\system32\drivers\zsjufcuf.sys [X]
S1 zwwlgjka; \??\C:\Windows\system32\drivers\zwwlgjka.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-29 10:40 - 2017-11-29 10:43 - 000027568 _____ C:\Users\Administrator\Downloads\FRST.txt
2017-11-29 10:39 - 2017-11-29 10:40 - 000000000 ____D C:\FRST
2017-11-29 10:39 - 2017-11-29 10:39 - 001752064 _____ (Farbar) C:\Users\Administrator\Downloads\FRST (1).exe
2017-11-29 10:37 - 2017-11-29 10:38 - 001752064 _____ (Farbar) C:\Users\Administrator\Downloads\FRST.exe
2017-11-29 10:30 - 2017-11-29 10:30 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-11-29 10:13 - 2017-11-29 10:14 - 008261584 _____ (Malwarebytes) C:\Users\Administrator\Downloads\AdwCleaner (1).exe
2017-11-29 09:46 - 2017-11-29 09:45 - 000157176 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000276728 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswblogx.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000255616 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000157408 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidshx.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000050376 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbunivx.sys
2017-11-29 09:45 - 2017-11-29 09:44 - 000305328 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-11-29 08:52 - 2017-11-29 10:29 - 000091576 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-11-29 08:52 - 2017-11-29 10:29 - 000065824 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-11-29 08:52 - 2017-11-29 08:52 - 000167352 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2017-11-29 08:51 - 2017-11-29 10:29 - 000040376 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-11-29 08:51 - 2017-11-29 08:51 - 000221112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2017-11-29 08:51 - 2017-11-29 08:51 - 000001976 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-11-29 08:51 - 2017-11-29 08:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-29 08:51 - 2017-11-29 08:51 - 000000000 ____D C:\Program Files\Malwarebytes
2017-11-29 08:51 - 2017-11-01 08:54 - 000059896 _____ C:\Windows\system32\Drivers\mbae.sys
2017-11-29 08:50 - 2017-11-29 08:50 - 000000000 ____D C:\ProgramData\MB2Migration
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-29 10:42 - 2009-07-13 23:34 - 000020880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-29 10:42 - 2009-07-13 23:34 - 000020880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-29 10:29 - 2015-05-08 10:04 - 000000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2017-11-29 10:29 - 2012-10-14 13:29 - 000109864 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2017-11-29 10:27 - 2009-07-13 23:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-29 10:24 - 2009-07-13 23:33 - 000411664 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-29 10:18 - 2015-01-04 13:58 - 000000000 ____D C:\AdwCleaner
2017-11-29 10:08 - 2013-06-10 18:39 - 000000000 ____D C:\Windows\system32\appmgmt
2017-11-29 10:05 - 2012-08-14 07:55 - 000000000 ____D C:\Program Files\Google
2017-11-29 09:56 - 2011-09-29 16:50 - 000414506 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-29 09:56 - 2009-07-13 21:37 - 000000000 ____D C:\Windows\inf
2017-11-29 09:47 - 2011-09-29 17:20 - 000388760 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-11-29 09:45 - 2014-09-15 08:21 - 000150848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-11-29 09:45 - 2014-09-15 08:21 - 000042848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-11-29 09:45 - 2013-08-10 14:43 - 000298360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-11-29 09:45 - 2013-08-10 14:43 - 000070864 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-11-29 09:45 - 2012-08-14 07:52 - 000099560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-11-29 09:45 - 2011-09-29 17:20 - 000124952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-11-29 09:45 - 2011-09-29 17:19 - 000000000 ____D C:\ProgramData\AVAST Software
2017-11-29 09:44 - 2011-09-29 17:20 - 000783136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-11-29 09:27 - 2014-09-21 11:02 - 000000920 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-914808374-759592663-328091246-1000UA.job
2017-11-29 09:05 - 2016-09-21 12:32 - 000000000 _____ C:\Windows\system32\last.dump
2017-11-29 09:01 - 2009-07-13 23:53 - 000032698 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-11-29 08:51 - 2014-09-14 22:59 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-11-29 08:33 - 2017-01-06 18:54 - 000216584 _____ C:\Windows\ntbtlog.txt
2017-11-25 10:16 - 2009-07-13 21:37 - 000000000 ____D C:\Windows\system32\NDF
Some files in TEMP:
====================
2016-12-15 01:06 - 2016-12-15 01:06 - 002458672 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Administrator\AppData\Local\temp\libeay32.dll
2016-12-15 01:06 - 2016-12-15 01:06 - 000970912 _____ (Microsoft Corporation) C:\Users\Administrator\AppData\Local\temp\msvcr120.dll
2016-12-15 01:06 - 2016-12-15 01:06 - 000772672 _____ () C:\Users\Administrator\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-13 11:19
==================== End of FRST.txt ============================
Ran by Administrator (administrator) on NEWUSER-PC (29-11-2017 10:40:07)
Running from C:\Users\Administrator\Downloads
Loaded Profiles: Administrator (Available Profiles: New User & Administrator)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Users\Administrator\Downloads\FRST (1).exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-29] (AVAST Software)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [267064 2017-03-22] (Apple Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-914808374-759592663-328091246-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6667992 2016-03-11] (Piriform Ltd)
GroupPolicy\User: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{73748022-E818-48DB-AB21-06430F24F6E5}: [NameServer] 76.73.7.75,107.6.133.7
Tcpip\..\Interfaces\{73748022-E818-48DB-AB21-06430F24F6E5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{94E21882-9300-4201-AB49-B77C93CC0691}: [DhcpNameServer] 172.20.10.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131189595039368748&GUID=FF7E1EFE-CF2D-49A9-BDC9-5BF3665BC833
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131189595039680749&GUID=FF7E1EFE-CF2D-49A9-BDC9-5BF3665BC833
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131189595039680749&GUID=FF7E1EFE-CF2D-49A9-BDC9-5BF3665BC833
HKU\S-1-5-21-914808374-759592663-328091246-500\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-914808374-759592663-328091246-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://outlook.live.com/owa/?path=/mail/AQMkADAwATIwMTAwAC0wMTI3LWNiNjItMDACLTAwCgAuAAADVVwnRb%2F%2ByUSv%2B010boFkFQEADTaWMq31aES4Uomoz7M4IAAAAgFUAAAA
HKU\S-1-5-21-914808374-759592663-328091246-500\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.google.com/?gws_rd=ssl#q=how+to+make+my+email+page+my+homepage+internet+explorer
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-914808374-759592663-328091246-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U218DF&PC=U218&q={searchTerms}&src=IE-SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-15] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-01-07] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-15] (Google Inc.)
Toolbar: HKU\S-1-5-21-914808374-759592663-328091246-500 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-15] (Google Inc.)
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
FireFox:
========
FF DefaultProfile: se9kv7zw.default
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default [2017-11-29]
FF Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\extensions\toolbar11367@freshy.com.xpi [not found]
FF Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\extensions\TidyNetwork@TidyNetwork [not found]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\searchplugins\bing-avast.xml [2015-05-08]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\searchplugins\Yahoo powered search.xml [2016-10-20]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\se9kv7zw.default\searchplugins\yahoo-avast.xml [2015-03-09]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [2011-09-29] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2011-09-16] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-01-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll [No File]
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-01-07] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2017-03-23]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default [2017-11-29]
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-08]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-08]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-20]
CHR Extension: (Google Search) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-08]
CHR Extension: (Bookmark Manager) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-08]
CHR Extension: (avast! Online Security) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-08]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-20]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-08]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-08]
CHR HKLM\...\Chrome\Extension: [anacbkknplojdncnpbhfkkmecdjlmleg] - C:\Program Files\OApps\chrome-sl.crx
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
StartMenuInternet: Google Chrome.HW4BWTSX2CCN2Y5XYLY67PDS3M - C:\Users\New User\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5904136 2017-11-29] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-29] (AVAST Software)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4563920 2017-11-01] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
S4 SCManager; C:\Program Files\SafeConnect\scManager.sys [176520 2012-11-19] (Impulse Point, LLC)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [157176 2017-11-29] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriverx.sys [255616 2017-11-29] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidshx.sys [157408 2017-11-29] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\System32\drivers\aswblogx.sys [276728 2017-11-29] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\System32\drivers\aswbunivx.sys [50376 2017-11-29] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [65344 2017-01-17] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [42848 2017-11-29] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [35096 2016-09-26] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [124952 2017-11-29] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [99560 2017-11-29] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [70864 2017-11-29] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [783136 2017-11-29] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [388760 2017-11-29] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [150848 2017-11-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [298360 2017-11-29] (AVAST Software)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-12] (AVG Technologies)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [59896 2017-11-01] ()
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [167352 2017-11-29] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [91576 2017-11-29] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [40376 2017-11-29] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [221112 2017-11-29] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [65824 2017-11-29] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
S1 afdivuwu; \??\C:\Windows\system32\drivers\afdivuwu.sys [X]
S1 agbgyfat; \??\C:\Windows\system32\drivers\agbgyfat.sys [X]
S1 anspeouj; \??\C:\Windows\system32\drivers\anspeouj.sys [X]
S1 aojjsesl; \??\C:\Windows\system32\drivers\aojjsesl.sys [X]
S1 aonnczhl; \??\C:\Windows\system32\drivers\aonnczhl.sys [X]
S1 aoscdxio; \??\C:\Windows\system32\drivers\aoscdxio.sys [X]
S1 arxuykmj; \??\C:\Windows\system32\drivers\arxuykmj.sys [X]
S1 asmewgdv; \??\C:\Windows\system32\drivers\asmewgdv.sys [X]
S1 auraxxir; \??\C:\Windows\system32\drivers\auraxxir.sys [X]
S1 avafugts; \??\C:\Windows\system32\drivers\avafugts.sys [X]
S1 avsibhjp; \??\C:\Windows\system32\drivers\avsibhjp.sys [X]
S1 axnurzoh; \??\C:\Windows\system32\drivers\axnurzoh.sys [X]
S1 bfobislo; \??\C:\Windows\system32\drivers\bfobislo.sys [X]
S1 bgbooorc; \??\C:\Windows\system32\drivers\bgbooorc.sys [X]
S1 bjccjqpt; \??\C:\Windows\system32\drivers\bjccjqpt.sys [X]
S1 bjvodcyt; \??\C:\Windows\system32\drivers\bjvodcyt.sys [X]
S1 bqjgpqxt; \??\C:\Windows\system32\drivers\bqjgpqxt.sys [X]
S1 brsjhlwy; \??\C:\Windows\system32\drivers\brsjhlwy.sys [X]
S1 btpfgaqv; \??\C:\Windows\system32\drivers\btpfgaqv.sys [X]
S1 btwrjxme; \??\C:\Windows\system32\drivers\btwrjxme.sys [X]
S1 bvechhvl; \??\C:\Windows\system32\drivers\bvechhvl.sys [X]
S1 bxuxpvgn; \??\C:\Windows\system32\drivers\bxuxpvgn.sys [X]
S3 catchme; \??\C:\Users\ADMINI~1\AppData\Local\Temp\catchme.sys [X]
S1 cczgmozq; \??\C:\Windows\system32\drivers\cczgmozq.sys [X]
S1 cehcdifo; \??\C:\Windows\system32\drivers\cehcdifo.sys [X]
S1 cifofbyc; \??\C:\Windows\system32\drivers\cifofbyc.sys [X]
S1 circuygo; \??\C:\Windows\system32\drivers\circuygo.sys [X]
S1 cmxpfewc; \??\C:\Windows\system32\drivers\cmxpfewc.sys [X]
S1 cnvgnbky; \??\C:\Windows\system32\drivers\cnvgnbky.sys [X]
S1 cqvjmugj; \??\C:\Windows\system32\drivers\cqvjmugj.sys [X]
S1 cscgzzpq; \??\C:\Windows\system32\drivers\cscgzzpq.sys [X]
S1 cynslgqb; \??\C:\Windows\system32\drivers\cynslgqb.sys [X]
S1 dhktjafl; \??\C:\Windows\system32\drivers\dhktjafl.sys [X]
S1 diqsddfa; \??\C:\Windows\system32\drivers\diqsddfa.sys [X]
S1 dnaojagy; \??\C:\Windows\system32\drivers\dnaojagy.sys [X]
S1 dswjbcdh; \??\C:\Windows\system32\drivers\dswjbcdh.sys [X]
S1 dubridng; \??\C:\Windows\system32\drivers\dubridng.sys [X]
S1 ebmoqtri; \??\C:\Windows\system32\drivers\ebmoqtri.sys [X]
S1 ehlnzlyf; \??\C:\Windows\system32\drivers\ehlnzlyf.sys [X]
S1 emieplht; \??\C:\Windows\system32\drivers\emieplht.sys [X]
S1 ewnmtgzh; \??\C:\Windows\system32\drivers\ewnmtgzh.sys [X]
S1 ewvsiclk; \??\C:\Windows\system32\drivers\ewvsiclk.sys [X]
S1 fcbqkbes; \??\C:\Windows\system32\drivers\fcbqkbes.sys [X]
S1 fcegngzu; \??\C:\Windows\system32\drivers\fcegngzu.sys [X]
S1 fcfxcjxx; \??\C:\Windows\system32\drivers\fcfxcjxx.sys [X]
S1 fdlkbcuf; \??\C:\Windows\system32\drivers\fdlkbcuf.sys [X]
S1 fdwrshnk; \??\C:\Windows\system32\drivers\fdwrshnk.sys [X]
S1 ffontlzk; \??\C:\Windows\system32\drivers\ffontlzk.sys [X]
S1 ffqkjdol; \??\C:\Windows\system32\drivers\ffqkjdol.sys [X]
S1 fivxdpjk; \??\C:\Windows\system32\drivers\fivxdpjk.sys [X]
S1 flmfpbha; \??\C:\Windows\system32\drivers\flmfpbha.sys [X]
S1 fsflywfn; \??\C:\Windows\system32\drivers\fsflywfn.sys [X]
S1 gbsslhhy; \??\C:\Windows\system32\drivers\gbsslhhy.sys [X]
S1 gfjpcymu; \??\C:\Windows\system32\drivers\gfjpcymu.sys [X]
S1 ggtqidoi; \??\C:\Windows\system32\drivers\ggtqidoi.sys [X]
S1 ggyferpt; \??\C:\Windows\system32\drivers\ggyferpt.sys [X]
S1 gpockzrf; \??\C:\Windows\system32\drivers\gpockzrf.sys [X]
S1 gtqdpbaq; \??\C:\Windows\system32\drivers\gtqdpbaq.sys [X]
S1 gwuqhdpc; \??\C:\Windows\system32\drivers\gwuqhdpc.sys [X]
S1 hgzhzuuz; \??\C:\Windows\system32\drivers\hgzhzuuz.sys [X]
S1 hljgnucy; \??\C:\Windows\system32\drivers\hljgnucy.sys [X]
S1 hqmxqedq; \??\C:\Windows\system32\drivers\hqmxqedq.sys [X]
S1 idbsxlcs; \??\C:\Windows\system32\drivers\idbsxlcs.sys [X]
S1 iddwqvds; \??\C:\Windows\system32\drivers\iddwqvds.sys [X]
S1 ikzofkiq; \??\C:\Windows\system32\drivers\ikzofkiq.sys [X]
S1 ilsgsotq; \??\C:\Windows\system32\drivers\ilsgsotq.sys [X]
S1 irjrnkof; \??\C:\Windows\system32\drivers\irjrnkof.sys [X]
S1 itgqetir; \??\C:\Windows\system32\drivers\itgqetir.sys [X]
S1 iuaglmsv; \??\C:\Windows\system32\drivers\iuaglmsv.sys [X]
S1 ixushmeh; \??\C:\Windows\system32\drivers\ixushmeh.sys [X]
S1 janjmyrx; \??\C:\Windows\system32\drivers\janjmyrx.sys [X]
S1 jbhanhwq; \??\C:\Windows\system32\drivers\jbhanhwq.sys [X]
S1 jcrrchbm; \??\C:\Windows\system32\drivers\jcrrchbm.sys [X]
S1 jgrkyfrw; \??\C:\Windows\system32\drivers\jgrkyfrw.sys [X]
S1 jiqakcef; \??\C:\Windows\system32\drivers\jiqakcef.sys [X]
S1 jkhamied; \??\C:\Windows\system32\drivers\jkhamied.sys [X]
S1 jobyazcp; \??\C:\Windows\system32\drivers\jobyazcp.sys [X]
S1 jpitlgyr; \??\C:\Windows\system32\drivers\jpitlgyr.sys [X]
S1 jsozmxag; \??\C:\Windows\system32\drivers\jsozmxag.sys [X]
S1 kewgjmvr; \??\C:\Windows\system32\drivers\kewgjmvr.sys [X]
S1 kgjgxgfc; \??\C:\Windows\system32\drivers\kgjgxgfc.sys [X]
S1 kkrizifb; \??\C:\Windows\system32\drivers\kkrizifb.sys [X]
S1 kpcfnajf; \??\C:\Windows\system32\drivers\kpcfnajf.sys [X]
S1 kseupdmb; \??\C:\Windows\system32\drivers\kseupdmb.sys [X]
S1 kwnyscxx; \??\C:\Windows\system32\drivers\kwnyscxx.sys [X]
S1 kyguvgwn; \??\C:\Windows\system32\drivers\kyguvgwn.sys [X]
S1 lcudrefu; \??\C:\Windows\system32\drivers\lcudrefu.sys [X]
S1 lfikjbby; \??\C:\Windows\system32\drivers\lfikjbby.sys [X]
S1 lfodztlv; \??\C:\Windows\system32\drivers\lfodztlv.sys [X]
S1 lhuctkuw; \??\C:\Windows\system32\drivers\lhuctkuw.sys [X]
S1 lirpssca; \??\C:\Windows\system32\drivers\lirpssca.sys [X]
S1 loacqulo; \??\C:\Windows\system32\drivers\loacqulo.sys [X]
S1 lrkiqzpn; \??\C:\Windows\system32\drivers\lrkiqzpn.sys [X]
S1 lzcuyhqp; \??\C:\Windows\system32\drivers\lzcuyhqp.sys [X]
S1 lzhthtle; \??\C:\Windows\system32\drivers\lzhthtle.sys [X]
S1 mbchseag; \??\C:\Windows\system32\drivers\mbchseag.sys [X]
S1 mghdxudt; \??\C:\Windows\system32\drivers\mghdxudt.sys [X]
S1 mnaptwlo; \??\C:\Windows\system32\drivers\mnaptwlo.sys [X]
S1 mxytqmmp; \??\C:\Windows\system32\drivers\mxytqmmp.sys [X]
S1 mxzzbipw; \??\C:\Windows\system32\drivers\mxzzbipw.sys [X]
S1 mzgxmryv; \??\C:\Windows\system32\drivers\mzgxmryv.sys [X]
S1 ndzjaugg; \??\C:\Windows\system32\drivers\ndzjaugg.sys [X]
S1 neucxbpc; \??\C:\Windows\system32\drivers\neucxbpc.sys [X]
S1 nfyysmew; \??\C:\Windows\system32\drivers\nfyysmew.sys [X]
S1 ngralood; \??\C:\Windows\system32\drivers\ngralood.sys [X]
S1 ngrlzwrd; \??\C:\Windows\system32\drivers\ngrlzwrd.sys [X]
S1 nkgbdpyw; \??\C:\Windows\system32\drivers\nkgbdpyw.sys [X]
S1 nkjjcisc; \??\C:\Windows\system32\drivers\nkjjcisc.sys [X]
S1 noyomhol; \??\C:\Windows\system32\drivers\noyomhol.sys [X]
S1 nricvzas; \??\C:\Windows\system32\drivers\nricvzas.sys [X]
S1 ntckxetg; \??\C:\Windows\system32\drivers\ntckxetg.sys [X]
S1 ntcyzgnw; \??\C:\Windows\system32\drivers\ntcyzgnw.sys [X]
S1 nzagpeuk; \??\C:\Windows\system32\drivers\nzagpeuk.sys [X]
S1 obsdpjrz; \??\C:\Windows\system32\drivers\obsdpjrz.sys [X]
S1 obtqdeyu; \??\C:\Windows\system32\drivers\obtqdeyu.sys [X]
S1 obztevfy; \??\C:\Windows\system32\drivers\obztevfy.sys [X]
S1 ongdukcq; \??\C:\Windows\system32\drivers\ongdukcq.sys [X]
S1 ookfmgwl; \??\C:\Windows\system32\drivers\ookfmgwl.sys [X]
S1 oqoxyegi; \??\C:\Windows\system32\drivers\oqoxyegi.sys [X]
S1 owtngtiz; \??\C:\Windows\system32\drivers\owtngtiz.sys [X]
S1 oxvkjyyd; \??\C:\Windows\system32\drivers\oxvkjyyd.sys [X]
S1 pewmadkg; \??\C:\Windows\system32\drivers\pewmadkg.sys [X]
S1 phxtnroa; \??\C:\Windows\system32\drivers\phxtnroa.sys [X]
S1 pypbmsyc; \??\C:\Windows\system32\drivers\pypbmsyc.sys [X]
S1 pzlofker; \??\C:\Windows\system32\drivers\pzlofker.sys [X]
S1 qaxmljko; \??\C:\Windows\system32\drivers\qaxmljko.sys [X]
S1 qcezrzaw; \??\C:\Windows\system32\drivers\qcezrzaw.sys [X]
S1 qchkgadm; \??\C:\Windows\system32\drivers\qchkgadm.sys [X]
S1 qfhilepk; \??\C:\Windows\system32\drivers\qfhilepk.sys [X]
S1 qftfhebo; \??\C:\Windows\system32\drivers\qftfhebo.sys [X]
S1 qhknkfqk; \??\C:\Windows\system32\drivers\qhknkfqk.sys [X]
S1 qtvotjnt; \??\C:\Windows\system32\drivers\qtvotjnt.sys [X]
S1 quwhqura; \??\C:\Windows\system32\drivers\quwhqura.sys [X]
S1 rkferrej; \??\C:\Windows\system32\drivers\rkferrej.sys [X]
S1 rkgxfoov; \??\C:\Windows\system32\drivers\rkgxfoov.sys [X]
S1 rkuxirpn; \??\C:\Windows\system32\drivers\rkuxirpn.sys [X]
S1 rmndjgmd; \??\C:\Windows\system32\drivers\rmndjgmd.sys [X]
S1 rogknzxp; \??\C:\Windows\system32\drivers\rogknzxp.sys [X]
S1 rpqbhdbn; \??\C:\Windows\system32\drivers\rpqbhdbn.sys [X]
S1 rqdepymj; \??\C:\Windows\system32\drivers\rqdepymj.sys [X]
S1 rvolhsih; \??\C:\Windows\system32\drivers\rvolhsih.sys [X]
S1 rvraysee; \??\C:\Windows\system32\drivers\rvraysee.sys [X]
S1 sgghfzer; \??\C:\Windows\system32\drivers\sgghfzer.sys [X]
S1 sltfisdi; \??\C:\Windows\system32\drivers\sltfisdi.sys [X]
S1 spbigqyn; \??\C:\Windows\system32\drivers\spbigqyn.sys [X]
S1 srsbmlzi; \??\C:\Windows\system32\drivers\srsbmlzi.sys [X]
S1 stbasfjy; \??\C:\Windows\system32\drivers\stbasfjy.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S1 tdnibiod; \??\C:\Windows\system32\drivers\tdnibiod.sys [X]
S1 thadkseq; \??\C:\Windows\system32\drivers\thadkseq.sys [X]
S1 thccjafx; \??\C:\Windows\system32\drivers\thccjafx.sys [X]
S1 tihmnqrf; \??\C:\Windows\system32\drivers\tihmnqrf.sys [X]
S1 tjxuyiha; \??\C:\Windows\system32\drivers\tjxuyiha.sys [X]
S1 toayjwnz; \??\C:\Windows\system32\drivers\toayjwnz.sys [X]
S1 tqnnagnl; \??\C:\Windows\system32\drivers\tqnnagnl.sys [X]
S1 tqpnjocd; \??\C:\Windows\system32\drivers\tqpnjocd.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S1 tzkzotja; \??\C:\Windows\system32\drivers\tzkzotja.sys [X]
S1 uclztmzh; \??\C:\Windows\system32\drivers\uclztmzh.sys [X]
S1 uidtdlbi; \??\C:\Windows\system32\drivers\uidtdlbi.sys [X]
S1 ujsppubm; \??\C:\Windows\system32\drivers\ujsppubm.sys [X]
S1 ukjbhzjs; \??\C:\Windows\system32\drivers\ukjbhzjs.sys [X]
S1 ushbmqhg; \??\C:\Windows\system32\drivers\ushbmqhg.sys [X]
S1 uwddgrpe; \??\C:\Windows\system32\drivers\uwddgrpe.sys [X]
S1 vaqrqnfr; \??\C:\Windows\system32\drivers\vaqrqnfr.sys [X]
S1 vervcinv; \??\C:\Windows\system32\drivers\vervcinv.sys [X]
S1 vfpluzdv; \??\C:\Windows\system32\drivers\vfpluzdv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 viybnrep; \??\C:\Windows\system32\drivers\viybnrep.sys [X]
S1 vngnmwur; \??\C:\Windows\system32\drivers\vngnmwur.sys [X]
S1 vnhsblqk; \??\C:\Windows\system32\drivers\vnhsblqk.sys [X]
S1 vpkjvrjb; \??\C:\Windows\system32\drivers\vpkjvrjb.sys [X]
S1 vupbwzhm; \??\C:\Windows\system32\drivers\vupbwzhm.sys [X]
S1 vuukbrru; \??\C:\Windows\system32\drivers\vuukbrru.sys [X]
S1 vuzmzvru; \??\C:\Windows\system32\drivers\vuzmzvru.sys [X]
S1 vwfpfvmo; \??\C:\Windows\system32\drivers\vwfpfvmo.sys [X]
S1 wbrapvjc; \??\C:\Windows\system32\drivers\wbrapvjc.sys [X]
S0 wfkeuy; System32\drivers\colxvtng.sys [X]
S1 wkmcbxsn; \??\C:\Windows\system32\drivers\wkmcbxsn.sys [X]
S1 wlcbottc; \??\C:\Windows\system32\drivers\wlcbottc.sys [X]
S1 wmtlgjvs; \??\C:\Windows\system32\drivers\wmtlgjvs.sys [X]
S1 wqwtxpaa; \??\C:\Windows\system32\drivers\wqwtxpaa.sys [X]
S1 wrhnrtrs; \??\C:\Windows\system32\drivers\wrhnrtrs.sys [X]
S1 wxllmhbq; \??\C:\Windows\system32\drivers\wxllmhbq.sys [X]
S1 xakbgcce; \??\C:\Windows\system32\drivers\xakbgcce.sys [X]
S1 xcvaytpk; \??\C:\Windows\system32\drivers\xcvaytpk.sys [X]
S1 xgvusuym; \??\C:\Windows\system32\drivers\xgvusuym.sys [X]
S1 xhcclinj; \??\C:\Windows\system32\drivers\xhcclinj.sys [X]
S1 xjrdofpg; \??\C:\Windows\system32\drivers\xjrdofpg.sys [X]
S1 xkdxpobt; \??\C:\Windows\system32\drivers\xkdxpobt.sys [X]
S1 xrbakghj; \??\C:\Windows\system32\drivers\xrbakghj.sys [X]
S1 xtfsoaxo; \??\C:\Windows\system32\drivers\xtfsoaxo.sys [X]
S1 yausplos; \??\C:\Windows\system32\drivers\yausplos.sys [X]
S1 yiudaent; \??\C:\Windows\system32\drivers\yiudaent.sys [X]
S1 yivzfage; \??\C:\Windows\system32\drivers\yivzfage.sys [X]
S1 yshprhfd; \??\C:\Windows\system32\drivers\yshprhfd.sys [X]
S1 yudvilad; \??\C:\Windows\system32\drivers\yudvilad.sys [X]
S1 zazuzpwo; \??\C:\Windows\system32\drivers\zazuzpwo.sys [X]
S1 zbplivgr; \??\C:\Windows\system32\drivers\zbplivgr.sys [X]
S1 zeomwijg; \??\C:\Windows\system32\drivers\zeomwijg.sys [X]
S1 zmhowvdu; \??\C:\Windows\system32\drivers\zmhowvdu.sys [X]
S1 zsjufcuf; \??\C:\Windows\system32\drivers\zsjufcuf.sys [X]
S1 zwwlgjka; \??\C:\Windows\system32\drivers\zwwlgjka.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-29 10:40 - 2017-11-29 10:43 - 000027568 _____ C:\Users\Administrator\Downloads\FRST.txt
2017-11-29 10:39 - 2017-11-29 10:40 - 000000000 ____D C:\FRST
2017-11-29 10:39 - 2017-11-29 10:39 - 001752064 _____ (Farbar) C:\Users\Administrator\Downloads\FRST (1).exe
2017-11-29 10:37 - 2017-11-29 10:38 - 001752064 _____ (Farbar) C:\Users\Administrator\Downloads\FRST.exe
2017-11-29 10:30 - 2017-11-29 10:30 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-11-29 10:13 - 2017-11-29 10:14 - 008261584 _____ (Malwarebytes) C:\Users\Administrator\Downloads\AdwCleaner (1).exe
2017-11-29 09:46 - 2017-11-29 09:45 - 000157176 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000276728 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswblogx.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000255616 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000157408 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidshx.sys
2017-11-29 09:46 - 2017-11-29 09:44 - 000050376 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbunivx.sys
2017-11-29 09:45 - 2017-11-29 09:44 - 000305328 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-11-29 08:52 - 2017-11-29 10:29 - 000091576 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-11-29 08:52 - 2017-11-29 10:29 - 000065824 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-11-29 08:52 - 2017-11-29 08:52 - 000167352 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2017-11-29 08:51 - 2017-11-29 10:29 - 000040376 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-11-29 08:51 - 2017-11-29 08:51 - 000221112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2017-11-29 08:51 - 2017-11-29 08:51 - 000001976 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-11-29 08:51 - 2017-11-29 08:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-29 08:51 - 2017-11-29 08:51 - 000000000 ____D C:\Program Files\Malwarebytes
2017-11-29 08:51 - 2017-11-01 08:54 - 000059896 _____ C:\Windows\system32\Drivers\mbae.sys
2017-11-29 08:50 - 2017-11-29 08:50 - 000000000 ____D C:\ProgramData\MB2Migration
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-29 10:42 - 2009-07-13 23:34 - 000020880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-29 10:42 - 2009-07-13 23:34 - 000020880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-29 10:29 - 2015-05-08 10:04 - 000000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2017-11-29 10:29 - 2012-10-14 13:29 - 000109864 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2017-11-29 10:27 - 2009-07-13 23:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-29 10:24 - 2009-07-13 23:33 - 000411664 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-29 10:18 - 2015-01-04 13:58 - 000000000 ____D C:\AdwCleaner
2017-11-29 10:08 - 2013-06-10 18:39 - 000000000 ____D C:\Windows\system32\appmgmt
2017-11-29 10:05 - 2012-08-14 07:55 - 000000000 ____D C:\Program Files\Google
2017-11-29 09:56 - 2011-09-29 16:50 - 000414506 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-29 09:56 - 2009-07-13 21:37 - 000000000 ____D C:\Windows\inf
2017-11-29 09:47 - 2011-09-29 17:20 - 000388760 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-11-29 09:45 - 2014-09-15 08:21 - 000150848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-11-29 09:45 - 2014-09-15 08:21 - 000042848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-11-29 09:45 - 2013-08-10 14:43 - 000298360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-11-29 09:45 - 2013-08-10 14:43 - 000070864 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-11-29 09:45 - 2012-08-14 07:52 - 000099560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-11-29 09:45 - 2011-09-29 17:20 - 000124952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-11-29 09:45 - 2011-09-29 17:19 - 000000000 ____D C:\ProgramData\AVAST Software
2017-11-29 09:44 - 2011-09-29 17:20 - 000783136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-11-29 09:27 - 2014-09-21 11:02 - 000000920 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-914808374-759592663-328091246-1000UA.job
2017-11-29 09:05 - 2016-09-21 12:32 - 000000000 _____ C:\Windows\system32\last.dump
2017-11-29 09:01 - 2009-07-13 23:53 - 000032698 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-11-29 08:51 - 2014-09-14 22:59 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-11-29 08:33 - 2017-01-06 18:54 - 000216584 _____ C:\Windows\ntbtlog.txt
2017-11-25 10:16 - 2009-07-13 21:37 - 000000000 ____D C:\Windows\system32\NDF
Some files in TEMP:
====================
2016-12-15 01:06 - 2016-12-15 01:06 - 002458672 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Administrator\AppData\Local\temp\libeay32.dll
2016-12-15 01:06 - 2016-12-15 01:06 - 000970912 _____ (Microsoft Corporation) C:\Users\Administrator\AppData\Local\temp\msvcr120.dll
2016-12-15 01:06 - 2016-12-15 01:06 - 000772672 _____ () C:\Users\Administrator\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-13 11:19
==================== End of FRST.txt ============================