Joined
·
1,049 Posts
You are using an outdated version of Java ...
Please uninstall ... Java 8 Update 91 ... reboot your computer to complete the uninstall.
Unless you have a specific need for Java, I recommend you do not use it at all. Java is not Javascript, which most websites use, it is entirely separate, and very few sites use it.
If you do need to have it, download and install the latest version ... https://java.com/en/download/
Next ...
With your computer booted as normal ...
... old Java versions are seriously insecure. Java is one of the most exploited programs there is (which is why it is updated so frequently), so it is critical that you always use the latest version.Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation)
Please uninstall ... Java 8 Update 91 ... reboot your computer to complete the uninstall.
Unless you have a specific need for Java, I recommend you do not use it at all. Java is not Javascript, which most websites use, it is entirely separate, and very few sites use it.
If you do need to have it, download and install the latest version ... https://java.com/en/download/
Next ...
With your computer booted as normal ...
- Start FRST in a similar manner to when you ran the scan earlier, but this time when it opens ....
- Press Ctrl+y (Ctrl and y keys at the same time)
- A blank randomly named .txt Notepad file will open.
- Copy and paste the following into it ....
Code:
VirusTotal: C:\Users\Perry\AppData\Local\Programs\Opera\assistant\browser_assistant.exe;C:\Windows\system32\scrnsave.scr;C:\Users\Perry\Desktop\stopandshop_flyer_0515_05222020.pdf;C:\Users\Perry\Desktop\stopandshop_flyer_0521_05282020.pdf
SearchScopes: HKU\S-1-5-21-1021941897-2095083384-3793157674-1001 -> {38E3C46F-AA59-491C-A8C6-B63EB2282FC0} URL =
SearchScopes: HKU\S-1-5-21-1021941897-2095083384-3793157674-1001 -> {B6150270-6ECB-42FA-BC45-4C6131964B6C} URL = hxxps://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
SearchScopes: HKU\S-1-5-21-1021941897-2095083384-3793157674-1001 -> {F94DBE5E-5FA7-4397-A1F6-8598A3210271} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-06-29] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-06-29] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKU\S-1-5-21-1021941897-2095083384-3793157674-1001 -> No Name - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - No File
Toolbar: HKU\S-1-5-21-1021941897-2095083384-3793157674-1001 -> No Name - {093F479D-712E-46CD-9E06-62E734A05F68} - No File
OPR Notifications: hxxps://togo.carrabbasonlineordering.com
S3 mfesapsn; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [X]
C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AERTFilters => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: Dell Customer Connect => 2
MSCONFIG\Services: Dell Foundation Services => 2
MSCONFIG\Services: DellDataVault => 2
MSCONFIG\Services: DellDataVaultWiz => 2
MSCONFIG\Services: DellDigitalDelivery => 2
MSCONFIG\Services: DellProdRegManager => 3
MSCONFIG\Services: DraftSight API Service => 2
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: ibtsiva => 2
MSCONFIG\Services: ICCS => 3
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: igfxCUIService2.0.0.0 => 2
MSCONFIG\Services: Intel(R) Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: IntelUSBoverIP => 2
MSCONFIG\Services: IntuitUpdateServiceV4 => 2
MSCONFIG\Services: iumsvc => 3
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: klvssbrigde64 => 3
MSCONFIG\Services: KSDE1.0.0 => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: NitroReaderDriverReadSpool3 => 2
MSCONFIG\Services: NitroReaderDriverReadSpool5 => 2
MSCONFIG\Services: RichVideo => 2
MSCONFIG\Services: RtkAudioService => 2
MSCONFIG\Services: SftService => 2
MSCONFIG\Services: SupportAssistAgent => 2
MSCONFIG\Services: TrueColorALS => 2
MSCONFIG\Services: WavesSysSvc => 2
HKLM\...\StartupApproved\StartupFolder: => "APC UPS Status.lnk"
HKLM\...\StartupApproved\Run: => "RTHDVCPL"
HKLM\...\StartupApproved\Run: => "RtHDVBg_MAXX6"
HKLM\...\StartupApproved\Run: => "WavesSvc"
HKLM\...\StartupApproved\Run: => "BTMTrayAgent"
HKLM\...\StartupApproved\Run: => "TrueColor UI"
HKLM\...\StartupApproved\Run: => "IAStorIcon"
HKLM\...\StartupApproved\Run: => "Classic Start Menu"
HKLM\...\StartupApproved\Run32: => "DropboxOEM"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "SolidWorks_CheckForUpdates"
HKLM\...\StartupApproved\Run32: => "Display"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "Avira System Speedup User Starter"
FirewallRules: [TCP Query User{D6128130-0166-43ED-A302-2C3D82DBB4BD}C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe => No File
FirewallRules: [UDP Query User{25A8383A-6844-4CA9-9754-F7270A9EDEA9}C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe => No File
FirewallRules: [TCP Query User{1B8AE6FC-E82A-40BE-8DBF-D3AD761BE7E1}C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Block) C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe => No File
FirewallRules: [UDP Query User{719A1FE3-1692-41CB-9F74-9DEAEE8D0FF4}C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Block) C:\users\perry\appdata\local\programs\opera\65.0.3467.78\opera.exe => No File
FirewallRules: [TCP Query User{177B8F47-546D-4976-A11C-17FDD34801F5}C:\users\perry\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\66.0.3515.44\opera.exe => No File
FirewallRules: [UDP Query User{6B88847B-FE25-4614-AA14-1DDD0C253D73}C:\users\perry\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\66.0.3515.44\opera.exe => No File
FirewallRules: [TCP Query User{644CE154-8622-400A-AE33-A786378E424E}C:\users\perry\appdata\local\programs\opera\66.0.3515.72\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\66.0.3515.72\opera.exe => No File
FirewallRules: [UDP Query User{28BA8541-E530-4656-8FB7-5422DAFDB661}C:\users\perry\appdata\local\programs\opera\66.0.3515.72\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\66.0.3515.72\opera.exe => No File
FirewallRules: [TCP Query User{D52A6DEC-B307-4B55-82A3-9BDC378B506E}C:\users\perry\appdata\local\programs\opera\66.0.3515.103\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\66.0.3515.103\opera.exe => No File
FirewallRules: [UDP Query User{9A797914-2F08-422A-B91A-30867781BF19}C:\users\perry\appdata\local\programs\opera\66.0.3515.103\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\66.0.3515.103\opera.exe => No File
FirewallRules: [TCP Query User{26971CB7-D74D-4ED6-9196-4CD951E32B1C}C:\users\perry\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Block) C:\users\perry\appdata\local\programs\opera\66.0.3515.115\opera.exe => No File
FirewallRules: [UDP Query User{A6195251-C89A-4CE9-B8C4-2977AE96E030}C:\users\perry\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Block) C:\users\perry\appdata\local\programs\opera\66.0.3515.115\opera.exe => No File
FirewallRules: [TCP Query User{EDF0A680-FAE9-4947-838D-8DB1F1C8D5C5}C:\users\perry\appdata\local\programs\opera\67.0.3575.53\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.53\opera.exe => No File
FirewallRules: [UDP Query User{8B099F78-6AEE-4FC5-A875-FBC2F8517F0B}C:\users\perry\appdata\local\programs\opera\67.0.3575.53\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.53\opera.exe => No File
FirewallRules: [TCP Query User{30F004F0-F6F3-4156-880C-A57493CEC785}C:\users\perry\appdata\local\programs\opera\67.0.3575.79\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.79\opera.exe => No File
FirewallRules: [UDP Query User{D318FF28-1366-4F65-A1D5-7123AD773E70}C:\users\perry\appdata\local\programs\opera\67.0.3575.79\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.79\opera.exe => No File
FirewallRules: [TCP Query User{CEFBDAB2-21A3-4F35-91EB-AAD8D4C131DC}C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File
FirewallRules: [UDP Query User{5DD32CD3-B1FF-437E-86BA-FBA6C39248C1}C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File
FirewallRules: [TCP Query User{5ED39571-8E69-4C1A-90ED-2FB2C769D0E7}C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File
FirewallRules: [UDP Query User{C30BC556-0CEA-4866-9BCC-F4E0E84C6512}C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File
FirewallRules: [TCP Query User{5EAB188D-C903-4495-A291-723E2EFCA6C3}C:\users\perry\appdata\local\programs\opera\67.0.3575.115\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.115\opera.exe => No File
FirewallRules: [UDP Query User{03FD3AFC-F656-4B44-B46E-533E7AF5BE42}C:\users\perry\appdata\local\programs\opera\67.0.3575.115\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.115\opera.exe => No File
FirewallRules: [TCP Query User{A5B3D830-1B72-4817-A536-6D5837989108}C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe => No File
FirewallRules: [UDP Query User{69559080-63F6-4FC6-9340-66D6ED8D0173}C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe => No File
FirewallRules: [TCP Query User{271390FD-885E-48D7-BDD9-959E8C607053}C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe] => (Block) C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe => No File
FirewallRules: [UDP Query User{A3E86EDD-B458-457A-975C-CCA9FA674F47}C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe] => (Block) C:\users\perry\appdata\local\programs\opera\67.0.3575.137\opera.exe => No File
FirewallRules: [TCP Query User{374B0C3C-1447-478C-893D-E6A7A8565C85}C:\users\perry\appdata\local\programs\opera\68.0.3618.63\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\68.0.3618.63\opera.exe => No File
FirewallRules: [UDP Query User{005CB3A9-EBFD-4C3A-9F23-DB1ADB0A6D93}C:\users\perry\appdata\local\programs\opera\68.0.3618.63\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\68.0.3618.63\opera.exe => No File
FirewallRules: [TCP Query User{7DA8C419-B362-4075-B772-80EB3FD7ECCE}C:\users\perry\appdata\local\programs\opera\68.0.3618.104\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\68.0.3618.104\opera.exe => No File
FirewallRules: [UDP Query User{7D6A0B82-E44B-4560-9011-79602A33874C}C:\users\perry\appdata\local\programs\opera\68.0.3618.104\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\68.0.3618.104\opera.exe => No File
FirewallRules: [TCP Query User{EFF3852E-CE5D-4025-8B8F-0A90D2568E28}C:\users\perry\appdata\local\programs\opera\68.0.3618.125\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\68.0.3618.125\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [UDP Query User{D0BB52AD-A263-4596-BE08-305C5BFCCB7E}C:\users\perry\appdata\local\programs\opera\68.0.3618.125\opera.exe] => (Allow) C:\users\perry\appdata\local\programs\opera\68.0.3618.125\opera.exe (Opera Software AS -> Opera Software)
EmptyTemp:
Hosts:
Cmd: ipconfig /flushdns
- Press Ctrl+s to save fixlist.txt
- Now press the Fix button once and wait.
- FRST will process fixlist.txt
- When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
- Please post me the log