Hii, Thanks for the help so far.
1.
I won't touch the quarantine files as of now.
Note: My PC is still slow (slower than before the virus problem started)
I think there may be some virus or malware.
I did a malware scan with Quick Heal and it cleaned few malware but there could be more.)
2.
Update on those 'Hosts 0.0.0.0<websites>' things.
I have never opened them myself, but sometime when I click on any article, It opens multiple advertisement tabs.
It could be those.
Still,
could you tell me what they could be ? (bcoz they are bothering me)
Read 3. to 5. after reading the logs.
3.
Under installed programs, it show plantvszombie.
I may have played that years ago but I don't have it now.
So, why is it here ? How can I get rid of it?
4.
Under 'scheduled task' and 'FirewallRules' there are names like lost-planet, condition zero, DAVE , Kaspersky, real upgrade, ...
I remember playing DAVE and condition zero so they don't look suspicious.
(I don't remember playing rest of them but I could have had them so they too aren't suspicious as well)
But, I had uninstalled and deleted them years ago so why are they here?
I want to delete every non-academic thing and don't want any trail of them
so could you advise how to permanently get rid of them.
5.Rest looked clean.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-01-2019
Ran by HOME (administrator) on HOME-PC (06-01-2019 19:26:05)
Running from F:\
Loaded Profiles: HOME & UpdatusUser (Available Profiles: HOME & UpdatusUser)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ARWSRVC.EXE
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCSECSVC.EXE
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.33.23\GoogleCrashHandler.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ONLINENT.EXE
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\QHPISVR.EXE
() C:\Program Files\Google\Drive\googledrivesync.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\OPSSVC.EXE
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\BDSSVC.EXE
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\EMLPROXY.EXE
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\QUHLPSVC.EXE
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\REPRSVC.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
() C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Quick Heal Technologies Ltd.) C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCANWSCS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
HKLM\...\Run: [Quick Heal Core UI] => C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\strtupap.exe [192128 2017-06-15] (Quick Heal Technologies Ltd.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\...\Run: [mailruhomesearchvbm] => C:\Users\HOME\AppData\Local\Mail.ru\Sputnik\ptls\mailruhomesearchvbm.exe -ptls
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [42832888 2018-10-04] ()
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\...\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\...\Policies\Explorer: [NoRecentDocsMenu] 0
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\...\MountPoints2: {86975686-f4d2-11e1-8771-f46d04e4fe2b} - H:\unlock.exe autoplay=true
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-3774606966-3563777163-3817635589-1001\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKLM\...\Drivers32: [MSVideo8] => C:\Windows\system32\VfWWDM32.dll [56832 2010-11-20] (Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2018-12-18] (Google Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2009-08-18] (Microsoft Corporation)
IFEO\(प्रश्न.exe: [Debugger] M-NPAV
IFEO\अ.exe: [Debugger] M-NPAV
Lsa: [Notification Packages] scecli C:\Windows\system32\ScSecAuth.Dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2016-01-25]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
Startup: C:\Users\HOME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2012-10-11]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * nprootkt.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 27.123.216.3 27.123.216.154
Tcpip\..\Interfaces\{3EE56205-4A21-4BFB-A2D0-B5E0E1EEEA28}: [DhcpNameServer] 27.123.216.3 27.123.216.154
Tcpip\..\Interfaces\{42193D09-1751-4AC9-B56B-F3A2ACB37825}: [DhcpNameServer] 27.123.216.3 27.123.216.154
Tcpip\..\Interfaces\{5AA0052D-C59D-4297-A4B2-6DF2468302FA}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{E8F51D76-0420-4E03-813A-158B137F5CF7}: [DhcpNameServer] 27.123.216.3 27.123.216.154
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Google
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://in.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180316__yaie
HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
URLSearchHook: HKLM - (No Name) - {d432f2f5-1d8b-482b-8a49-9fadfabd8cd7} - No File
URLSearchHook: HKU\S-1-5-21-3774606966-3563777163-3817635589-1000 - (No Name) - {d432f2f5-1d8b-482b-8a49-9fadfabd8cd7} - No File
SearchScopes: HKU\S-1-5-21-3774606966-3563777163-3817635589-1000 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10440__180316__yaie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3774606966-3563777163-3817635589-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=IPGTDF&PC=IPGTDF&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3774606966-3563777163-3817635589-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-3774606966-3563777163-3817635589-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10440__180316__yaie&p={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll => No File
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-12] (Adobe Systems Incorporated)
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll => No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2018-10-27] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: No Name -> {d432f2f5-1d8b-482b-8a49-9fadfabd8cd7} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-10-27] (Oracle Corporation)
Toolbar: HKLM - StartNow Toolbar - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll No File
Toolbar: HKLM - No Name - {d432f2f5-1d8b-482b-8a49-9fadfabd8cd7} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_171-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-00171-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_171-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\HOME\AppData\Roaming\Mozilla\Firefox\Profiles\74qlkyog.default [2019-01-06]
FF Homepage: Mozilla\Firefox\Profiles\74qlkyog.default -> hxxps://in.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180316__yaff
FF NewTab: Mozilla\Firefox\Profiles\74qlkyog.default -> hxxps://in.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180316__yaff
FF Extension: (Miniclip ) - C:\Users\HOME\AppData\Roaming\Mozilla\Firefox\Profiles\74qlkyog.default\Extensions\{1c68c940-1b2f-46eb-bd8c-2e1612ff6a58} [2002-01-01] [Legacy] [not signed]
FF Extension: (No Name) - C:\Users\HOME\AppData\Roaming\Mozilla\Firefox\Profiles\74qlkyog.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7} [not found]
FF Extension: (No Name) - C:\Users\HOME\AppData\Roaming\Mozilla\Firefox\Profiles\74qlkyog.default\extensions\testpilot@labs.mozilla.com.xpi [not found]
FF HKLM\...\Firefox\Extensions: [{0153E448-190B-4987-BDE1-F256CADA672F}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext => not found
FF Plugin:
@Java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-10-27] (Oracle Corporation)
FF Plugin:
@Java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-10-27] (Oracle Corporation)
FF Plugin:
@microsoft.com/GENUINE -> disabled [No File]
FF Plugin:
@real.com/nppl3260;version=15.0.6.14 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [No File]
FF Plugin:
@real.com/nprjplug;version=15.0.6.14 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [No File]
FF Plugin:
@real.com/nprpchromebrowserrecordext;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [No File]
FF Plugin:
@real.com/nprphtml5videoshim;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [No File]
FF Plugin:
@real.com/nprpplugin;version=15.0.6.14 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [No File]
FF Plugin:
@tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc.)
FF Plugin:
@tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-3774606966-3563777163-3817635589-1000:
@unity3d.com/UnityPlayer,version=1.0 -> C:\Users\HOME\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-07-07] (Unity Technologies ApS)
Chrome:
=======
CHR HomePage: Default -> search.ask.com
CHR StartupUrls: Default -> "hxxp://www.google.co.in/"
CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}
CHR DefaultSearchKeyword: Default -> search.ask.com
CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms}
CHR Profile: C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default [2019-01-06]
CHR Extension: (Slides) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-19]
CHR Extension: (Docs) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-19]
CHR Extension: (Google Drive) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Cinema-Plus-1.7cV27.10) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpffalghigmkdghibgickgcnkbcaidch [2014-10-27]
CHR Extension: (todoist) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\coafbinhgifdjfmefnjdnhkeamocgink [2018-08-05]
CHR Extension: (Sheets) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-19]
CHR Extension: (Google Docs Offline) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-16]
CHR Extension: (Google Keep) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfcmgpnmpinpidjdgejehjchlbglpde [2018-08-05]
CHR Extension: () - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2014-09-19]
CHR Extension: (Todoist: To-Do list and Task Manager) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\jldhpllghnbhlbpcmnajkpdmadaolakh [2019-01-06]
CHR Extension: (Grammarly for Chrome) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-12-18]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-01-06]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2018-12-18]
CHR Extension: (Video Speed Controller) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffaoalbilbmmfgbnbgppjihopabppdk [2018-12-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Extension: (Chrome Media Router) - C:\Users\HOME\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-18]
CHR Profile: C:\Users\HOME\AppData\Local\Google\Chrome\User Data\System Profile [2018-01-06]
CHR HKLM\...\Chrome\Extension: [aaaadbhonifkcheeddllhmpapnhcpgia] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gnlaniokgfckpjblpafbfchhghecmifi] - C:\Users\HOME\AppData\Local\CRE\gnlaniokgfckpjblpafbfchhghecmifi.crx <not found>
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx <not found>
CHR HKLM\...\Chrome\Extension: [ppcdpabdaaenpfihggajpnehffdcbima] - C:\ProgramData\FlashPlayer\ext i ri_2.crx <not found>
CHR HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gnlaniokgfckpjblpafbfchhghecmifi] - C:\Users\HOME\AppData\Local\CRE\gnlaniokgfckpjblpafbfchhghecmifi.crx <not found>
CHR HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [incfcgceegpikennjoplhfghaaikdgei] - C:\Users\HOME\AppData\Roaming\StartNow Toolbar\CR\zcrx.crx <not found>
CHR HKU\S-1-5-21-3774606966-3563777163-3817635589-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 arwsrvc; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\arwsrvc.exe [68736 2018-06-18] (Quick Heal Technologies Ltd.)
R2 Behavior Detection System; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\bdssvc.exe [35456 2017-11-14] (Quick Heal Technologies Ltd.)
R2 Core Mail Protection; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\EMLPROXY.EXE [55424 2017-06-15] (Quick Heal Technologies Ltd.)
R2 Core Scanning Server; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE [280712 2018-08-07] (Quick Heal Technologies Ltd.)
S3 Core Scanning ServerEx; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SAPISSVC.EXE [280712 2018-08-07] (Quick Heal Technologies Ltd.)
S3 GoogleChromeElevationService; C:\Program Files\Google\Chrome\Application\71.0.3578.98\elevation_service.exe [375776 2018-12-12] (Google Inc.)
R2 Online Protection System; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\opssvc.exe [59520 2017-06-15] (Quick Heal Technologies Ltd.)
R2 Quick Update Service; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\quhlpsvc.exe [148608 2017-07-04] (Quick Heal Technologies Ltd.)
R2 RepairService; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\reprsvc.exe [38016 2017-06-15] (Quick Heal Technologies Ltd.)
R2 ScanWscS; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\SCANWSCS.EXE [306336 2017-12-22] (Quick Heal Technologies Ltd.)
R2 ScSecSvc; C:\Program Files\Quick Heal\Quick Heal AntiVirus Pro\ScSecSvc.exe [482944 2018-06-16] (Quick Heal Technologies Ltd.)
S3 uSHAREitSvc; C:\Program Files\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2017-09-11] (SHAREit Technologies Co.Ltd)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 FLEXnet Licensing Service; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [X]
S2 MovieMode; "C:\ProgramData\MovieMode\MovieModeService.exe" "C:\ProgramData\MovieMode\MovieMode.exe"
S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
S2 Updater Service for StartNow Toolbar; C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 arwflt; C:\Windows\System32\DRIVERS\arwflt.sys [91592 2018-06-13] (Quick Heal Technologies Ltd.)
R3 atkldrvr; C:\Windows\System32\DRIVERS\atkldrvr.sys [55480 2017-04-27] (Quick Heal Technologies Ltd.)
R1 bdsflt; C:\Windows\System32\DRIVERS\bdsflt.sys [290328 2018-07-20] (Quick Heal Technologies Ltd.)
R1 bdsnm; C:\Windows\System32\DRIVERS\bdsnm.sys [31816 2017-11-14] (Quick Heal Technologies Ltd.)
R3 bsfs; C:\Windows\System32\DRIVERS\bsfs.sys [87168 2017-05-08] (Quick Heal Technologies Ltd.)
R2 catflt; C:\Windows\System32\DRIVERS\catflt.sys [141032 2018-05-24] (Quick Heal Technologies Ltd.)
R2 EMLSS; C:\Windows\System32\drivers\emltdi.sys [43432 2017-04-21] (Quick Heal Technologies Ltd.)
R1 ggc; C:\Windows\System32\DRIVERS\ggc.sys [85456 2018-05-21] (Quick Heal Technologies Ltd.)
R3 kbfltr; C:\Windows\System32\DRIVERS\kbfltr.sys [37328 2017-04-27] (Quick Heal Technologies Ltd.)
S3 llio; C:\Windows\system32\DRIVERS\llio.sys [81816 2018-09-19] (Quick Heal Technologies Ltd.)
S0 mscank; C:\Windows\System32\DRIVERS\mscank.sys [57120 2018-03-09] (Quick Heal Technologies Ltd.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
R3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [1348240 2013-03-05] (Realtek Semiconductor Corporation )
S4 secdrv; C:\Windows\system32\Drivers\secdrv.sys [11376 2018-05-31] () [File not signed]
S3 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [171104 2017-09-13] (Oracle Corporation)
R0 webssx; C:\Windows\System32\drivers\webssx.sys [73504 2018-05-17] (Quick Heal Technologies Ltd.)
R1 wsnf; C:\Windows\System32\DRIVERS\wsnf.sys [52584 2016-04-12] (Quick Heal Technologies Ltd.)
S3 anvsnddrv; system32\drivers\anvsnddrv.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-01-06 19:25 - 2019-01-06 19:26 - 000000000 ____D C:\FRST
2019-01-06 19:10 - 2019-01-06 19:10 - 000000000 ___HD C:\Users\HOME\ScStore
2019-01-06 16:07 - 2019-01-06 16:07 - 000016247 _____ C:\Users\HOME\Desktop\attach.txt
2019-01-06 16:07 - 2019-01-06 16:07 - 000016079 _____ C:\Users\HOME\Desktop\dds.txt
2019-01-06 11:05 - 2019-01-06 15:05 - 000000460 _____ C:\Windows\Tasks\Quick Heal AntiMalware Scan.job
2019-01-06 11:05 - 2018-09-19 12:17 - 000081816 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\llio.sys
2019-01-06 11:05 - 2018-07-20 13:48 - 000290328 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\bdsflt.sys
2019-01-06 11:05 - 2018-03-09 09:02 - 000057120 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\mscank.sys
2019-01-06 11:05 - 2017-11-14 13:39 - 000031816 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\bdsnm.sys
2019-01-06 11:05 - 2017-04-21 12:50 - 000043432 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\EMLTDI.SYS
2019-01-06 11:05 - 2017-03-14 18:41 - 000113264 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\bdsaei32.dll
2019-01-06 11:04 - 2019-01-06 15:04 - 000000436 _____ C:\Windows\Tasks\Resume Quickup Download.job
2019-01-06 11:04 - 2019-01-06 11:04 - 000001184 _____ C:\Users\Public\Desktop\Quick Heal Secure Browse.lnk
2019-01-06 11:04 - 2018-05-17 19:33 - 000073504 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\webssx.sys
2019-01-06 11:04 - 2018-04-11 08:35 - 000110176 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\wsfilter.sys
2019-01-06 11:04 - 2017-09-21 17:09 - 000405104 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\ScDetour.Dll
2019-01-06 11:04 - 2016-07-23 16:29 - 000255616 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\ScSandboxApi.dll
2019-01-06 11:04 - 2016-07-23 16:29 - 000178304 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\ScSecAuth.Dll
2019-01-06 11:04 - 2016-04-12 13:32 - 000052584 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\wsnf.sys
2019-01-06 11:04 - 2016-01-21 20:57 - 000115840 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\atklshld32.dll
2019-01-06 11:03 - 2019-01-06 11:04 - 000000000 ____D C:\Program Files\Common Files\Quick Heal
2019-01-06 11:03 - 2019-01-06 11:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quick Heal AntiVirus Pro
2019-01-06 11:03 - 2019-01-06 11:03 - 000000000 ____D C:\Program Files\Quick Heal
2019-01-06 11:00 - 2019-01-06 11:04 - 000000000 ____D C:\Windows\system32\gprodat
2019-01-06 11:00 - 2018-05-21 20:36 - 000085456 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\ggc.sys
2019-01-06 10:48 - 2019-01-06 10:58 - 258731664 _____ (Quick Heal Technologies Ltd.) C:\Users\HOME\Desktop\QHAVFT32.EXE
2019-01-05 21:39 - 2019-01-05 21:39 - 000688992 ____R (Swearware) C:\Users\HOME\Desktop\dds.scr
2018-12-31 16:32 - 2018-12-31 16:32 - 000000000 ____D C:\Users\HOME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anaconda3 (32-bit)
2018-12-31 12:35 - 2018-12-31 12:35 - 000000018 _____ C:\Users\HOME\.condarc
2018-12-31 12:34 - 2018-12-31 12:34 - 000000000 ____D C:\Users\HOME\.conda
2018-12-31 12:34 - 2018-12-31 12:34 - 000000000 ____D C:\Users\HOME\.anaconda
2018-12-24 11:58 - 2018-12-24 11:58 - 000030359 _____ C:\Users\Public\Documents\Git Commit.pdf
2018-12-22 11:18 - 2018-12-22 18:54 - 000000000 ____D C:\Users\HOME\AppData\Roaming\jupyter
2018-12-22 11:17 - 2018-12-22 11:17 - 000000000 ____D C:\Users\HOME\AppData\Local\conda
2018-12-22 00:25 - 2018-12-22 00:25 - 000000000 ____D C:\Users\HOME\Documents\Python Scripts
2018-12-18 18:22 - 2018-12-18 18:22 - 000002211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-12-18 18:22 - 2018-12-18 18:22 - 000002170 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-12-18 14:32 - 2018-05-24 11:36 - 000141032 _____ (Quick Heal Technologies Ltd.) C:\Windows\system32\Drivers\catflt.sys
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-01-06 19:16 - 2009-07-14 10:04 - 000013424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-01-06 19:16 - 2009-07-14 10:04 - 000013424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-01-06 19:13 - 2013-07-28 22:16 - 000000000 ____D C:\Users\UpdatusUser
2019-01-06 19:12 - 2018-01-06 23:24 - 000000000 ___RD C:\Users\HOME\Google Drive
2019-01-06 19:10 - 2012-09-02 13:15 - 000000000 ____D C:\Users\HOME
2019-01-06 19:10 - 2009-07-14 10:23 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-01-06 15:59 - 2018-05-02 14:27 - 000000000 ____D C:\Users\HOME\Documents\My Games
2019-01-06 15:19 - 2009-07-14 07:34 - 000000024 _____ C:\AUTOEXEC.BAT
2019-01-06 15:14 - 2012-09-02 14:49 - 000000000 ____D C:\Users\HOME\AppData\Roaming\vlc
2019-01-06 14:30 - 2018-10-15 11:26 - 000000000 ____D C:\Users\HOME\AppData\Roaming\gavvdvch
2019-01-06 14:22 - 2009-07-14 08:07 - 000000000 ____D C:\Windows\system32\NDF
2019-01-06 12:14 - 2013-11-18 11:16 - 000000000 ____D C:\Users\HOME\AppData\Local\WhiteListing
2019-01-06 12:06 - 2014-11-18 20:11 - 000000000 ____D C:\Users\HOME\AppData\Local\IObit installer
2019-01-06 11:04 - 2009-07-14 08:07 - 000000000 ____D C:\Windows\inf
2018-12-31 11:24 - 2018-07-26 20:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Git
2018-12-31 11:24 - 2018-07-26 20:39 - 000000000 ____D C:\ProgramData\Git
2018-12-22 10:11 - 2009-07-14 10:23 - 000032650 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-12-19 02:19 - 2018-11-20 17:21 - 000000000 ____D C:\Users\HOME\AppData\Local\STUDY_AT_HOME
2018-12-19 02:19 - 2018-11-20 13:06 - 000000000 ____D C:\Program Files\STUDY_AT_HOME
2018-12-19 02:19 - 2009-07-14 08:07 - 000000000 ____D C:\Windows\registration
2018-12-18 18:22 - 2012-09-02 14:38 - 000000000 ____D C:\Program Files\Google
2018-12-18 12:55 - 2018-01-06 23:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
==================== Files in the root of some directories =======
2014-09-01 13:48 - 2015-06-16 10:45 - 000000935 _____ () C:\Users\HOME\AppData\Roaming\ODG
2016-01-19 18:46 - 2017-09-22 00:32 - 000007607 _____ () C:\Users\HOME\AppData\Local\resmon.resmoncfg
2018-11-26 15:16 - 2018-11-26 15:16 - 000000000 _____ () C:\Users\HOME\AppData\Local\{65D06EC3-D1EF-489D-AC4A-CF08E23E43D0}
Some files in TEMP:
====================
2018-12-04 11:31 - 2018-12-04 12:48 - 000176307 _____ () C:\Users\HOME\AppData\Local\Temp\hpnhykulbh.exe
2018-12-08 10:35 - 2018-12-08 10:40 - 000004016 _____ () C:\Users\HOME\AppData\Local\Temp\jhoqngifuu.exe
2018-10-27 11:03 - 2018-10-27 11:03 - 001892728 _____ (Oracle Corporation) C:\Users\HOME\AppData\Local\Temp\jre-8u191-windows-au.exe
2018-12-08 12:39 - 2018-12-08 14:43 - 000175836 _____ () C:\Users\HOME\AppData\Local\Temp\lpeoxfmmji.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-07-03 22:15
==================== End of FRST.txt ============================