Hi,
I would like request for a quick help here.
The issue happened at my workstation where all the browsers had been hijacked. I had attempted some fixes before but no aid.
The logs are provided here.
Any help is really appreciated.
Thank you!
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-08-2020 Ran by Administrator (administrator) on CAPS-Q3DEMO-A (27-08-2020 15:48:42) Running from C:\Users\Administrator\Downloads Loaded Profiles: Administrator Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] C:\Program Files (x86)\D-Link\DWA-125 revA\ANIWConnService.exe () [File not signed] C:\Users\Administrator\Desktop\baretail.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe <2> (CodeSigning for The Apache Software Foundation -> Apache Software Foundation) C:\OraclePaymentInterface\v19.1\Services\ConfigService\OPIConfigService.exe (CodeSigning for The Apache Software Foundation -> Apache Software Foundation) C:\OraclePaymentInterface\v19.1\Services\OPI\bin\OPIService.exe (CodeSigning for The Apache Software Foundation -> Apache Software Foundation) C:\OraclePaymentInterface\v19.1\Services\OPI\bin\UtilityService.exe (DigitalPersona, Inc. -> DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Pro Workstation\Bin\DpHostW.exe (D-LINK CORPORATION -> D-Link Corp.) [File not signed] C:\Program Files (x86)\D-Link\DWA-125 revA\AirNCFG.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxTray.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Oracle America, Inc. -> MICROS Systems Inc.) C:\Program Files (x86)\MICROS\McrsCAL\McrsCal.exe (Oracle America, Inc. -> MICROS Systems Inc.) C:\Program Files (x86)\MICROS\McrsCAL\WIN7CALStart.exe (Oracle America, Inc. -> Oracle) C:\Micros\Simphony\WebServer\ServiceHost.exe <2> (philandro Software GmbH -> philandro Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe <3> (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-12] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [DpTsClnt] => Regsvr32.exe /s "C:\Program Files\DigitalPersona\Pro Workstation\Bin\DpTsClnt.dll" HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [156808 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-03-06] (Intel Corporation - Software and Firmware Products -> Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587800 2017-12-19] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Run: [MAKEN OPEN DRAWER] => D:\POS SYSTEM\????(??)\DrawTest.exe start HKLM-x32\...\Run: [D-Link D-Link DWA-125] => C:\Program Files (x86)\D-Link\DWA-125 revA\AirNCFG.exe [1095984 2014-03-18] (D-LINK CORPORATION -> D-Link Corp.) [File not signed] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2019-08-21] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1DB5DA09-C167-4D0F-AD68-F51CBD502750} - System32\Tasks\Microsoft POS for .NET SQM Uploader => C:\Program Files (x86)\Microsoft Point Of Service\SqmUploader.exe [147704 2017-08-08] (Microsoft Corporation -> ) Task: {4576D400-3CFD-4748-832C-04BAE9CBE76D} - System32\Tasks\{1B0F8D77-A354-4DDA-8E75-ABE69A60EDF1} => C:\Windows\system32\pcalua.exe -a "D:\POS SYSTEM\KPOS_Printer_DriverInstall_Graph(附安装说明)(3)(1)\KPOS_Printer_DriverInstall_Graphú¿╕╜░▓╫░╦╡├≈ú⌐\KPOS_Printer_DriverInstall_Graph_20190426\POS104Install.exe" -d "D:\POS SYSTEM\KPOS_Printer_DriverInstall_Graph(附安装说明)(3)(1)\KPOS_Printer_DriverInstall_Graphú¿╕╜░▓╫░╦╡├≈ú⌐\KPOS_Printer_Driv (the data entry has 25 more characters). Task: {E6EAD99D-BDCA-457E-83E7-EFC7AB6AABC8} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [3858056 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) Task: {FFD2951F-2AD3-4B0D-8401-D3C98AFE7A47} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1792136 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.6 192.168.1.5 8.8.4.4 8.8.8.8 Tcpip\..\Interfaces\{49D3160E-9769-4443-8845-529949E72514}: [DhcpNameServer] 192.168.1.6 192.168.1.5 8.8.4.4 8.8.8.8 Tcpip\..\Interfaces\{F26F6D75-F8F7-413A-A510-67DF5E6A3839}: [DhcpNameServer] 192.168.1.6 192.168.1.5 8.8.4.4 8.8.8.8 Internet Explorer: ================== BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll [2020-03-31] (Oracle America, Inc. -> Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll [2020-03-31] (Oracle America, Inc. -> Oracle Corporation) FireFox: ======== FF DefaultProfile: 5c5wbps2.default FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\5c5wbps2.default [2020-08-27] FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\mpwzd1gz.default-release-1598513963193 [2020-08-27] FF Plugin: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2020-03-31] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2020-03-31] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] Chrome: ======= StartMenuInternet: Google Chrome.6Y2LFEZ7UHFRSQMVKOHQNSWZNY - C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) "{74712200-2132-494a-BD2F-D9CFE8900378}" => service could not be unlocked. <==== ATTENTION HKLM\SYSTEM\ControlSet001\Services\{74712200-2132-494a-BD2F-D9CFE8900378} => C:\Windows\System32\drivers\zokng.sys [11470256 2019-07-25] () [File not signed] <==== ATTENTION (Rootkit!/Locked Service) R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [3668944 2020-08-08] (philandro Software GmbH -> philandro Software GmbH) R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [354272 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [7823296 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R2 DpHost; C:\Program Files\DigitalPersona\Pro Workstation\Bin\DpHostW.exe [473424 2014-12-15] (DigitalPersona, Inc. -> DigitalPersona, Inc.) R2 D_Link_DWA-125_WPS; C:\Program Files (x86)\D-Link\DWA-125 revA\ANIWConnService.exe [53248 2010-07-12] () [File not signed] R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7138296 2020-08-25] (Malwarebytes Inc -> Malwarebytes) R2 MICROS CAL Client; C:\Program Files (x86)\Micros\McrsCAL\McrsCal.exe [76624 2019-09-02] (Oracle America, Inc. -> MICROS Systems Inc.) R2 MSSQL$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [163008 2017-08-15] (Microsoft Corporation -> Microsoft Corporation) R2 OPIConfigService; C:\OraclePaymentInterface\v19.1\Services\ConfigService\OPIConfigService.exe [109696 2019-02-12] (CodeSigning for The Apache Software Foundation -> Apache Software Foundation) R2 OPIService; C:\OraclePaymentInterface\v19.1\Services\OPI\bin\OPIService.exe [109696 2019-02-12] (CodeSigning for The Apache Software Foundation -> Apache Software Foundation) R2 Oracle Hospitality Simphony Service Host; C:\Micros\Simphony\WebServer\ServiceHost.exe [18440 2020-01-09] (Oracle America, Inc. -> Oracle) S4 POSPerformanceCounters; C:\Program Files (x86)\Microsoft Point Of Service\Microsoft.PointOfService.Service.exe [37624 2017-08-08] (Microsoft Corporation -> ) S4 SQLAgent$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [448704 2017-08-15] (Microsoft Corporation -> Microsoft Corporation) R2 UtilityService; C:\OraclePaymentInterface\v19.1\Services\OPI\bin\UtilityService.exe [109696 2019-02-12] (CodeSigning for The Apache Software Foundation -> Apache Software Foundation) S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwfx.sys [15872 2010-05-29] (Microsoft Windows Hardware Compatibility Publisher -> ) R0 avgArDisk; C:\Windows\System32\drivers\avgArDisk.sys [37208 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgArPot; C:\Windows\System32\drivers\avgArPot.sys [205952 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgbidsdriver; C:\Windows\System32\drivers\avgbidsdriver.sys [235656 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R0 avgbidsh; C:\Windows\System32\drivers\avgbidsh.sys [195720 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R0 avgbuniv; C:\Windows\System32\drivers\avgbuniv.sys [61064 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgKbd; C:\Windows\System32\drivers\avgKbd.sys [42840 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R2 avgMonFlt; C:\Windows\System32\drivers\avgMonFlt.sys [175264 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgNetHub; C:\Windows\System32\drivers\avgNetHub.sys [515600 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R3 avgNetNd6; C:\Windows\System32\DRIVERS\avgNetNd6.sys [29944 2020-08-25] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.) R1 avgRdr; C:\Windows\System32\drivers\avgRdr2.sys [109336 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R0 avgRvrt; C:\Windows\System32\drivers\avgRvrt.sys [84912 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgSnx; C:\Windows\System32\drivers\avgSnx.sys [851664 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgSP; C:\Windows\System32\drivers\avgSP.sys [466816 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R2 avgStm; C:\Windows\System32\drivers\avgStm.sys [217392 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R0 avgVmm; C:\Windows\System32\drivers\avgVmm.sys [323848 2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R0 bhound7; C:\Windows\System32\DRIVERS\bhound7.sys [68064 2009-03-02] (Perisoft -> Perisoft) S3 CYUSB; C:\Windows\System32\Drivers\CYUSB.sys [48648 2011-06-22] (Cypress -> Cypress Semiconductor) S3 CYUSB3; C:\Windows\System32\Drivers\CYUSB3.sys [71904 2017-07-05] (Cypress Semiconductor Technology India Pvt Ltd. -> Cypress Semiconductor) S3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [65408 2013-07-17] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc) S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [39296 2013-06-04] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc) S3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [94208 2013-07-17] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc) R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [217088 2020-08-27] (Malwarebytes Inc -> Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-08-25] (Malwarebytes Inc -> Malwarebytes) S3 netr28ux; C:\Windows\System32\DRIVERS\Dnetr28ux.sys [2225808 2014-12-08] (MEDIATEK INC. -> MediaTek Inc.) S3 rusb3hub; C:\Windows\system32\DRIVERS\rusb3hub.sys [114568 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation) S3 rusb3xhc; C:\Windows\system32\DRIVERS\rusb3xhc.sys [230280 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation) R3 Ser2pl; C:\Windows\System32\DRIVERS\ser2pl64.sys [89600 2007-02-13] (Microsoft Windows Hardware Compatibility Publisher -> Prolific Technology Inc.) S3 VUSB3HUB; C:\Windows\system32\DRIVERS\ViaHub3.sys [221696 2016-02-03] (Microsoft Windows Hardware Compatibility Publisher -> VIA Technologies, Inc.) S3 xhcdrv; C:\Windows\system32\DRIVERS\xhcdrv.sys [294912 2016-02-03] (Microsoft Windows Hardware Compatibility Publisher -> VIA Technologies, Inc.) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-08-27 15:47 - 2020-08-27 15:48 - 000000000 ____D C:\Users\Administrator\Downloads\FRST-OlderVersion 2020-08-27 15:47 - 2020-08-27 15:47 - 000000000 ___HD C:\$AV_AVG 2020-08-27 15:39 - 2020-08-27 15:39 - 000000000 ____D C:\Users\Administrator\Desktop\Old Firefox Data 2020-08-27 15:38 - 2020-08-27 15:41 - 000000000 ____D C:\Program Files\Mozilla Firefox 2020-08-27 15:38 - 2020-08-27 15:40 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-08-27 15:38 - 2020-08-27 15:38 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2020-08-27 15:38 - 2020-08-27 15:38 - 000000924 _____ C:\Users\Public\Desktop\Firefox.lnk 2020-08-27 15:38 - 2020-08-27 15:38 - 000000924 _____ C:\ProgramData\Desktop\Firefox.lnk 2020-08-27 15:32 - 2020-08-27 15:32 - 000217088 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2020-08-27 15:30 - 2020-08-27 15:30 - 020447232 ____N C:\Windows\system32\config\SYSTEM 2020-08-25 18:00 - 2020-08-27 15:30 - 000000000 ____D C:\Windows\system32\Tasks\AVAST Software 2020-08-25 17:42 - 2020-08-25 17:42 - 000046177 _____ C:\Users\Administrator\Downloads\Shortcut.txt 2020-08-25 17:17 - 2020-08-25 17:17 - 008414384 _____ (Malwarebytes) C:\Users\Administrator\Downloads\adwcleaner_8.0.7.exe 2020-08-25 17:14 - 2020-08-25 17:19 - 000000000 ____D C:\AdwCleaner 2020-08-25 17:08 - 2020-08-25 17:55 - 000001105 _____ C:\Users\Administrator\Downloads\Fixlog.txt 2020-08-25 15:56 - 2020-08-25 17:42 - 000031971 _____ C:\Users\Administrator\Downloads\Addition.txt 2020-08-25 15:49 - 2020-08-27 15:50 - 000016556 _____ C:\Users\Administrator\Downloads\FRST.txt 2020-08-25 15:49 - 2020-08-27 15:49 - 000000000 ____D C:\FRST 2020-08-25 15:49 - 2020-08-27 15:47 - 002298368 _____ (Farbar) C:\Users\Administrator\Downloads\FRST64.exe 2020-08-25 15:27 - 2020-08-25 15:27 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\AVG 2020-08-25 15:27 - 2020-08-25 15:27 - 000000000 ____D C:\Users\Administrator\AppData\Local\CEF 2020-08-25 15:27 - 2020-08-25 15:27 - 000000000 ____D C:\Users\Administrator\AppData\Local\Avg 2020-08-25 15:27 - 2020-08-25 15:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2020-08-25 15:25 - 2020-08-25 15:25 - 000000000 ____D C:\Windows\system32\Tasks\AVG 2020-08-25 15:24 - 2020-08-27 15:30 - 000003904 _____ C:\Windows\system32\Tasks\Antivirus Emergency Update 2020-08-25 15:24 - 2020-08-25 15:24 - 000851664 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSnx.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000515600 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgNetHub.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000466816 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000336520 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe 2020-08-25 15:24 - 2020-08-25 15:24 - 000323848 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgVmm.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000235656 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdriver.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000217392 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgStm.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000205952 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgArPot.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000195720 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsh.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000175264 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgMonFlt.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000109336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000084912 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000061064 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniv.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000042840 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgKbd.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000037208 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgArDisk.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000029944 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgNetNd6.sys 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____D C:\Program Files\Common Files\AVG 2020-08-25 15:23 - 2020-08-27 15:42 - 000000000 ____D C:\ProgramData\AVG 2020-08-25 15:23 - 2020-08-25 15:23 - 000271696 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Administrator\Downloads\avg_antivirus_free_setup.exe 2020-08-25 15:23 - 2020-08-25 15:23 - 000000000 ____D C:\Program Files\AVG 2020-08-25 15:21 - 2020-08-25 15:21 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2020-08-24 16:03 - 2020-08-24 16:43 - 000710356 _____ C:\Windows\ntbtlog.txt 2020-08-24 15:42 - 2020-08-24 16:16 - 000000000 ____D C:\Windows\pss 2020-08-24 15:40 - 2020-08-27 15:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\CrashDumps 2020-08-24 14:57 - 2020-08-24 14:58 - 006455520 _____ (EnigmaSoft Limited) C:\Users\Administrator\Downloads\SpyHunter-Installer.exe 2020-08-24 14:51 - 2020-08-24 14:51 - 000000000 ____D C:\Users\Administrator\Downloads\chc 2020-08-24 14:50 - 2020-08-24 14:50 - 009047080 _____ C:\Users\Administrator\Downloads\chc.zip 2020-08-24 11:48 - 2020-08-25 15:22 - 000001960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2020-08-24 11:48 - 2020-08-25 15:22 - 000001948 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2020-08-24 11:48 - 2020-08-25 15:22 - 000001948 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2020-08-24 11:48 - 2020-08-24 11:48 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbam 2020-08-24 11:47 - 2020-08-25 15:21 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys 2020-08-24 11:47 - 2020-08-24 11:47 - 000000000 ____D C:\ProgramData\Malwarebytes 2020-08-24 11:47 - 2020-08-24 11:47 - 000000000 ____D C:\Program Files\Malwarebytes 2020-08-24 11:45 - 2020-08-24 11:45 - 002040904 _____ (Malwarebytes) C:\Users\Administrator\Downloads\MBSetup.exe 2020-08-24 11:45 - 2020-08-24 11:45 - 000388608 _____ (Trend Micro Inc.) C:\Users\Administrator\Downloads\HijackThis.exe 2020-08-17 16:18 - 2020-08-27 15:30 - 000000000 ___HD C:\Windows\msdownld.tmp 2020-08-17 16:13 - 2020-08-25 17:14 - 000000000 ____D C:\Users\Administrator\AppData\Local\Google 2020-08-17 16:12 - 2020-08-25 17:15 - 000000000 ____D C:\Program Files (x86)\Google ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-08-27 15:49 - 2019-07-25 07:15 - 020709376 _____ C:\Windows\system32\C_32770.NLS 2020-08-27 15:41 - 2019-08-13 17:27 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Mozilla 2020-08-27 15:37 - 2009-07-14 13:13 - 000910410 _____ C:\Windows\system32\PerfStringBackup.INI 2020-08-27 15:37 - 2009-07-14 11:20 - 000000000 ____D C:\Windows\inf 2020-08-27 15:32 - 2009-07-14 12:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2020-08-27 15:32 - 2009-07-14 12:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2020-08-27 15:31 - 2009-07-14 13:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-08-27 04:20 - 2019-08-13 18:36 - 000000000 ____D C:\Windows\system32\MRT 2020-08-27 04:15 - 2019-08-13 18:35 - 120636720 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-08-26 20:07 - 2019-08-20 10:00 - 001509224 _____ C:\Journal.txt 2020-08-08 18:24 - 2019-08-21 11:53 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2020-08-05 10:17 - 2019-08-21 11:33 - 000001102 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk 2020-08-05 10:17 - 2019-08-21 11:33 - 000001090 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2020-08-05 10:17 - 2019-08-21 11:33 - 000001090 _____ C:\ProgramData\Desktop\TeamViewer 8.lnk ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2020-08-25 00:56 ==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-08-2020 Ran by Administrator (27-08-2020 15:52:43) Running from C:\Users\Administrator\Downloads Windows 7 Professional Service Pack 1 (X64) (2019-07-24 22:55:26) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= admin (S-1-5-21-2582853694-2877760415-371799054-1000 - Administrator - Disabled) => C:\Users\admin Administrator (S-1-5-21-2582853694-2877760415-371799054-500 - Administrator - Enabled) => C:\Users\Administrator Guest (S-1-5-21-2582853694-2877760415-371799054-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411} AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: AVG Antivirus (Enabled - Up to date) {A3C8941D-8036-3856-D9BB-709D4A2A7EAC} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 6.0.7 - philandro Software GmbH) AVG AntiVirus FREE (HKLM-x32\...\AVG Antivirus) (Version: 20.6.3135 - AVG Technologies) Bus Hound (HKLM-x32\...\{7A19AACA-48DD-43E1-92BE-B12D78466C89}) (Version: 6.1.0 - Perisoft) DigitalPersona TouchChip Device Add-On for U.are.U SDK (HKLM\...\{20CB814D-73D5-422B-9E61-BE3F68E280DD}) (Version: 1.0.1.767 - DigitalPersona, Inc.) DigitalPersona U.are.U RTE (HKLM\...\{3FE5B696-9DA2-41AA-8414-58E3936169A6}) (Version: 2.3.1.767 - DigitalPersona, Inc.) D-Link DWA-125 (HKLM-x32\...\{E45CACFE-0576-4375-A84F-C34B99A7B652}) (Version: - D-Link Corporation) Intel(R) Chipset Device Software (HKLM-x32\...\{f3e3c5dd-edd0-406b-8aa2-ce5acb93660e}) (Version: 10.0.14 - Intel(R) Corporation) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation) Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.19 - Intel Corporation) Java 8 Update 161 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180161F0}) (Version: 8.0.1610.12 - Oracle Corporation) Malwarebytes version 4.2.0.82 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.0.82 - Malwarebytes) Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.8 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.8.03761 - Microsoft Corporation) Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{A106FA6F-E94C-44C9-8A0F-C34BD82C9FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft POS for .NET 1.14.1 (HKLM-x32\...\{9352A741-7648-46DA-806F-44ED64890BA4}) (Version: 1.14.1708.8001 - Microsoft Corporation) Microsoft Report Viewer 2014 Runtime (HKLM-x32\...\{327E9C0D-1687-414F-923E-F5979E549548}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}) (Version: 10.51.2500.0 - Microsoft Corporation) Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{6292D514-17A4-403F-98F9-E150F10C043D}) (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 Setup Support Files (HKLM-x32\...\{D441BD04-E548-4F8E-97A4-1B66135BAAA8}) (Version: 10.1.2731.0 - Microsoft Corporation) Microsoft SQL Server 2012 (HKLM-x32\...\Microsoft SQL Server SQLServer2012) (Version: - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{B9274744-8BAE-4874-8E59-2610919CD419}) (Version: 11.4.7001.0 - Microsoft Corporation) Microsoft SQL Server 2012 Setup (English) (HKLM-x32\...\{5B2CB8F5-3151-4B85-8EC7-E7BF1CFC8646}) (Version: 11.4.7001.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{18F346D2-4CE0-45C4-BCD9-BA054FE7CB91}) (Version: 11.4.7001.0 - Microsoft Corporation) Microsoft SQL Server 2014 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2014) (Version: - Microsoft Corporation) Microsoft SQL Server 2014 Policies (HKLM-x32\...\{1C30FE7E-8A8C-4492-89D6-10CB20C3B0EB}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Setup (English) (HKLM\...\{0EEBDCCA-EF5D-4896-9FEA-D7D410A57E8A}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL Compiler Service (HKLM\...\{59DE4D1C-690E-4397-8A44-B684934E863C}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}) (Version: 10.51.2500.0 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{8C06D6DB-A391-4686-B050-99CC522A7843}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (HKLM-x32\...\{49697869-be8e-427d-81a0-c334d1d14950}) (Version: 14.21.27702.2 - Microsoft Corporation) Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\...\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft VSS Writer for SQL Server 2012 (HKLM\...\{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E}) (Version: 11.4.7001.0 - Microsoft Corporation) Mozilla Firefox 72.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 72.0.2 (x64 en-US)) (Version: 72.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 67.0 - Mozilla) Oracle Payment Interface (HKLM-x32\...\{FDFB3AFE-1D8F-4145-BE5F-9466F5984455}) (Version: 19.1.0.0 - Oracle) Hidden Oracle Payment Interface (HKLM-x32\...\InstallShield_{FDFB3AFE-1D8F-4145-BE5F-9466F5984455}) (Version: 19.1.0.0 - Oracle) Printer Driver Setup v2.0 (HKLM-x32\...\{DEFC2352-70A5-433C-841D-5EC6527E2EA9}) (Version: 2.0 - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.) Service Pack 4 for SQL Server 2012 (KB4018073) (HKLM-x32\...\KB4018073) (Version: 11.4.7001.0 - Microsoft Corporation) SQL Server 2012 Common Files (HKLM-x32\...\{124D51A1-F3C2-45AE-B812-D3CA71247093}) (Version: 11.4.7001.0 - Microsoft Corporation) Hidden SQL Server 2012 Common Files (HKLM-x32\...\{7D29ED63-84F9-4EC7-B49F-994A3A3195B2}) (Version: 11.4.7001.0 - Microsoft Corporation) Hidden SQL Server 2012 Database Engine Services (HKLM-x32\...\{87D50333-E534-493A-8E98-0A49BC28F64B}) (Version: 11.4.7001.0 - Microsoft Corporation) Hidden SQL Server 2012 Database Engine Services (HKLM-x32\...\{C22613C2-C7A4-4761-A906-116ECD4E7477}) (Version: 11.4.7001.0 - Microsoft Corporation) Hidden SQL Server 2012 Database Engine Shared (HKLM-x32\...\{54F84805-0116-467F-8713-899DFC472235}) (Version: 11.4.7001.0 - Microsoft Corporation) Hidden SQL Server 2012 Database Engine Shared (HKLM-x32\...\{D0F44C37-A22B-4733-BBA7-86C9F4988725}) (Version: 11.4.7001.0 - Microsoft Corporation) Hidden SQL Server 2014 Client Tools (HKLM\...\{2BA1811B-44C0-4C50-8C5A-CE68AB25ED71}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Client Tools (HKLM\...\{B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Common Files (HKLM\...\{BD1CD96B-FE4B-4EAE-83D4-6EF55AB5779C}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Common Files (HKLM\...\{F7012F84-80F5-4C25-852E-B1BA03276FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Management Studio (HKLM\...\{75A54138-3B98-4705-92E4-F619825B121F}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Management Studio (HKLM\...\{839EF29A-3055-43DC-ADCE-8E84893798D5}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server Browser for SQL Server 2012 (HKLM-x32\...\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}) (Version: 11.4.7001.0 - Microsoft Corporation) Sql Server Customer Experience Improvement Program (HKLM-x32\...\{30CA21F2-901A-44DB-A43F-FC31CD0F2493}) (Version: 11.4.7001.0 - Microsoft Corporation) Hidden TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.258861 - TeamViewer) Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation) WIN32 CAL Client (HKLM-x32\...\{0B64324E-75FA-4A9C-8997-9C21F8777110}) (Version: 3.1.4.146 - ORACLE | Micros) Hidden WIN32 CAL Client (HKLM-x32\...\InstallShield_{0B64324E-75FA-4A9C-8997-9C21F8777110}) (Version: 3.1.4.146 - ORACLE | Micros) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2582853694-2877760415-371799054-500_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-08-24] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2014-03-08] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\Windows\system32\igfxOSP.dll [2014-03-08] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-08-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-08-24] (Malwarebytes Corporation -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Administrator\Desktop\LaunchConfiguration - Shortcut.lnk -> C:\OraclePaymentInterface\v19.1\Config\LaunchConfiguration.bat () ==================== Loaded Modules (Whitelisted) ============= 2019-08-27 10:32 - 2019-08-27 10:32 - 000315392 _____ () [File not signed] C:\Program Files (x86)\D-Link\DWA-125 revA\ANPDApi.dll 2019-08-27 10:32 - 2012-12-05 10:40 - 000303104 _____ () [File not signed] C:\Program Files (x86)\D-Link\DWA-125 revA\WlanApp.dll 2019-07-25 07:19 - 2014-03-06 10:08 - 000074240 ____R (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.dll 2020-08-27 15:32 - 2020-08-27 15:32 - 000198144 ____N (Java(TM) Native Access (JNA)) [File not signed] C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\jna-1840106495\jna1208285878972502543.dll 2020-08-27 15:31 - 2020-08-27 15:31 - 000198144 ____N (Java(TM) Native Access (JNA)) [File not signed] C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\jna-1840106495\jna7570238549666890663.dll 2019-08-27 10:32 - 2010-07-12 14:39 - 000413696 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\D-Link\DWA-125 revA\MSVCP60.dll 2019-03-27 23:48 - 2019-03-27 23:48 - 000115200 _____ (Microsoft Corporation) [File not signed] C:\Windows\Microsoft.Net\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll 2020-01-09 14:16 - 2020-01-09 14:16 - 000796672 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808\MSVCR80.dll 2019-08-14 09:37 - 2019-08-14 09:37 - 000626688 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\MSVCR80.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-core-file-l1-2-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-core-file-l2-1-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-core-localization-l1-2-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-core-processthreads-l1-1-1.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-core-synch-l1-2-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-core-timezone-l1-1-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-crt-convert-l1-1-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-crt-heap-l1-1-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-crt-runtime-l1-1-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-crt-stdio-l1-1-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\api-ms-win-crt-string-l1-1-0.dll 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\ucrtbase.DLL 2020-08-25 15:24 - 2020-08-25 15:24 - 000000000 ____L (Microsoft Corporation) C:\Program Files\AVG\Antivirus\1033\avg.local_vc142.crt\VCRUNTIME140.dll 2019-08-27 10:32 - 2012-09-04 15:31 - 000278528 _____ (Wireless Service) [File not signed] C:\Program Files (x86)\D-Link\DWA-125 revA\wnicapi.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 10:34 - 2020-08-17 18:05 - 000000152 _____ C:\Windows\system32\drivers\etc\hosts 192.168.1.15 simapp.q3aurelia.com 175.143.55.113 simapp.q3aurelia.com 192.168.1.18 simrpt.q3aurelia.com 175.143.55.113 simrpt.q3aurelia.com ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\TXE Components\TCS\;C:\Program Files\Intel\TXE Components\TCS\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\ HKU\S-1-5-21-2582853694-2877760415-371799054-500\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.6 - 192.168.1.5 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) C:\Windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) C:\Windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{B231DE16-40B6-4ABD-B7E2-A79168D1CD06}] => (Allow) C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc -> Google Inc.) FirewallRules: [{7E18DC82-0E7C-46A4-BE84-13ABEF854B2F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe => No File FirewallRules: [{A082D422-7099-44B3-BA13-5D1C5C84E61B}] => (Allow) C:\Users\Administrator\Desktop\AnyDesk.exe => No File FirewallRules: [{318DDDE5-0B27-4FA2-9BCD-C8E8D562DBAA}] => (Allow) C:\Users\Administrator\Desktop\AnyDesk.exe => No File FirewallRules: [{1D90D57C-843A-44E4-9932-0BD875DBED81}] => (Allow) C:\Users\Administrator\Desktop\AnyDesk.exe => No File FirewallRules: [{4FD3B272-07A7-4539-8DB5-BACC4ABCFFE6}] => (Allow) C:\Users\Administrator\Desktop\AnyDesk.exe => No File FirewallRules: [{B68F8AA1-E8E5-44AE-824B-74B79F04DD14}] => (Allow) C:\Users\Administrator\Desktop\AnyDesk.exe => No File FirewallRules: [{F689A6C3-0E21-4EE8-8607-077A65EFFEB7}] => (Allow) C:\Users\Administrator\Desktop\AnyDesk.exe => No File FirewallRules: [{7FE72AE8-5290-4DC8-B243-D71F70533A13}] => (Allow) C:\Micros\Simphony\WebServer\ServiceHost.exe (Oracle America, Inc. -> Oracle) FirewallRules: [{77257AAC-8EA2-41F0-B4ED-4965A0778AC0}] => (Allow) C:\Micros\Simphony\WebServer\ServiceHost.exe (Oracle America, Inc. -> Oracle) FirewallRules: [{1F60E561-F666-4D24-9C4B-DADD02FF3979}] => (Allow) LPort=1434 FirewallRules: [{536DE056-6B5D-459D-A4E2-38EF087B4D66}] => (Allow) LPort=1433 FirewallRules: [{962F0249-DDF1-4453-817A-9C764D673680}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) FirewallRules: [{0D11B8B2-84B8-4F04-ABA3-F15773ED857A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) FirewallRules: [{646583CE-020D-4F64-B165-63ADF393A69B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) FirewallRules: [{69800F2C-A6BA-44E8-BD2F-7F708E40684C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer GmbH) FirewallRules: [{6AA4549C-4F38-4781-97B1-FF900EB68A1F}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{E413EAC6-1445-43B0-AF2E-FE1F4B8FD7D6}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{E344BD32-9B67-4C2C-BC2A-3A120B8873C2}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{BBC7A038-649C-40DB-B85A-C92E70685A01}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{A1DC380A-3E8E-4494-8E18-B0B5522F085C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{CC0ED5A7-CBD0-41D8-A475-3AF70DAC09A5}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{E8628A48-8619-4500-9F37-865EA71241F9}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{8DE820D2-D58D-4469-AC66-E4FFA0EE34D8}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) ==================== Restore Points ========================= 25-08-2020 15:24:53 Device Driver Package Install: AVG Technologies Network Service 25-08-2020 18:06:55 Windows Modules Installer 25-08-2020 18:11:45 Windows Modules Installer 25-08-2020 18:24:23 Windows Modules Installer 25-08-2020 18:29:09 Windows Modules Installer 27-08-2020 04:14:18 Windows Update ==================== Faulty Device Manager Devices ============ Name: Standard PS/2 Keyboard Description: Standard PS/2 Keyboard Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard keyboards) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: PS/2 Compatible Mouse Description: PS/2 Compatible Mouse Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ======================== Application errors: ================== Error: (08/27/2020 03:36:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0x37c Faulting application start time: 0x01d67c44c8d787bb Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 08433df0-e838-11ea-b1bb-68eda42b384e Error: (08/27/2020 03:36:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0x142c Faulting application start time: 0x01d67c44bfa4338e Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: ff8a4bae-e837-11ea-b1bb-68eda42b384e Error: (08/27/2020 03:36:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0x434 Faulting application start time: 0x01d67c44be96420a Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: fe835f24-e837-11ea-b1bb-68eda42b384e Error: (08/27/2020 03:36:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0xe0 Faulting application start time: 0x01d67c44b75aa68d Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: fb4fed84-e837-11ea-b1bb-68eda42b384e Error: (08/27/2020 03:29:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0x1108 Faulting application start time: 0x01d67c43ba7081e6 Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: fbb62f2c-e836-11ea-aad5-68eda42b384e Error: (08/27/2020 03:07:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0x1a30 Faulting application start time: 0x01d67c40bc3a383c Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: fbca3fd9-e833-11ea-aad5-68eda42b384e Error: (08/27/2020 03:07:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0x19f4 Faulting application start time: 0x01d67c40baa190e0 Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: fa2f7595-e833-11ea-aad5-68eda42b384e Error: (08/27/2020 03:06:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iexplore.exe, version: 11.0.9600.19597, time stamp: 0x5df81503 Faulting module name: ntdll.dll, version: 6.1.7601.24545, time stamp: 0x5e0eb67f Exception code: 0xc0000005 Fault offset: 0x0000000000027a6d Faulting process id: 0xd08 Faulting application start time: 0x01d67c408c5d2b42 Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: cbf1519e-e833-11ea-aad5-68eda42b384e System errors: ============= Error: (08/27/2020 03:32:12 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (08/26/2020 07:41:32 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Oracle Hospitality Simphony Service Host service terminated unexpectedly. It has done this 1 time(s). Error: (08/25/2020 06:20:43 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (08/25/2020 05:57:55 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (08/25/2020 05:21:57 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (08/25/2020 05:20:07 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: The server {752073A1-23F2-4396-85F0-8FDB879ED0ED} did not register with DCOM within the required timeout. Error: (08/25/2020 05:19:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The OPI Utility Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error: (08/25/2020 05:19:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The SQL Server (SQLEXPRESS) service terminated unexpectedly. It has done this 1 time(s). ==================== Memory info =========================== BIOS: American Megatrends Inc. 5.6.5 05/07/2019 Motherboard: AMI Corporation Aptio CRB Processor: Intel(R) Celeron(R) CPU J1900 @ 1.99GHz Percentage of memory in use: 90% Total physical RAM: 1938.64 MB Available physical RAM: 191.08 MB Total Virtual: 5235.96 MB Available Virtual: 409.11 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:59.62 GB) (Free:8.9 GB) NTFS ==>[drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 59.6 GB) (Disk ID: 33217C0D) Partition 1: (Active) - (Size=59.6 GB) - (Type=07 NTFS) ==================== End of Addition.txt =======================