Fix result of Farbar Recovery Scan Tool (x64) Version: 29-03-2020 Ran by [removed] (01-04-2020 16:17:33) Run:1 Running from C:\Users\[removed]\Downloads [removed] Boot Mode: Normal ============================================== fixlist content: ***************** SearchScopes: HKLM -> DefaultScope {13526EF3-1889-448B-AA0C-4CF7C0037058} URL = hxxp://www.bing.com/search?q={searchTerms}&form=PRNAM1&src=IE11TR&pc=NMTE SearchScopes: HKLM -> {13526EF3-1889-448B-AA0C-4CF7C0037058} URL = hxxp://www.bing.com/search?q={searchTerms}&form=PRNAM1&src=IE11TR&pc=NMTE SearchScopes: HKLM-x32 -> DefaultScope {13526EF3-1889-448B-AA0C-4CF7C0037058} URL = hxxp://www.bing.com/search?q={searchTerms}&form=PRNAM1&src=IE11TR&pc=NMTE SearchScopes: HKLM-x32 -> {13526EF3-1889-448B-AA0C-4CF7C0037058} URL = hxxp://www.bing.com/search?q={searchTerms}&form=PRNAM1&src=IE11TR&pc=NMTE SearchScopes: HKU\S-1-5-21-2825346925-3975081358-1914956935-1002 -> DefaultScope {13526EF3-1889-448B-AA0C-4CF7C0037058} URL = SearchScopes: HKU\S-1-5-21-2825346925-3975081358-1914956935-1002 -> {13526EF3-1889-448B-AA0C-4CF7C0037058} URL = SearchScopes: HKU\S-1-5-21-2825346925-3975081358-1914956935-1002 -> {1C438BC6-4F49-47DA-8B71-66AB89A3F83B} URL = hxxps://privatesearch.adaware.com/?gd=SY1001470&d=200321&q={searchTerms} BHO: No Name -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> No File FF Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\misfi\AppData\Roaming\Mozilla\Firefox\Profiles\64on43rx.default\Extensions\[removed] [2019-08-26] FF Extension: (Avast Online Security) - C:\Users\misfi\AppData\Roaming\Mozilla\Firefox\Profiles\64on43rx.default\Extensions\[removed] [2019-08-26] FF Notifications: Mozilla\Firefox\Profiles\oowq5ggu.default-release-1584804676275 -> hxxps://movieshdstreaming.com S3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [53904 2018-09-05] (AVAST Software s.r.o. -> The OpenVPN Project) C:\WINDOWS\System32\drivers\aswTap.sys S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2014-11-05] (OpenVPN Technologies, Inc. -> The OpenVPN Project) C:\WINDOWS\System32\drivers\tap0901.sys 2020-04-01 14:02 - 2019-09-13 00:09 - 000000000 ____D C:\Program Files\AVAST Software 2020-04-01 14:02 - 2019-08-26 20:13 - 000000000 ____D C:\ProgramData\AVAST Software ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File FirewallRules: [{5D67F1B3-6418-402D-B447-1DC89A3C89D3}] => (Allow) C:\Users\misfi\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{2D2F36FA-B23F-43C1-B847-449C2FDBD4F7}] => (Allow) C:\Users\misfi\AppData\Roaming\uTorrent\uTorrent.exe No File VirusTotal: C:\WINDOWS\System32\drivers\BthA2dp.sys;C:\windows\system32\rtvcvfw64.dll;C:\Windows\SysWOW64\rtvcvfw32.dll EmptyTemp: CMD: ipconfig /flushdns ***************** HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{13526EF3-1889-448B-AA0C-4CF7C0037058} => removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{13526EF3-1889-448B-AA0C-4CF7C0037058} => removed successfully "HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{13526EF3-1889-448B-AA0C-4CF7C0037058} => removed successfully HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1C438BC6-4F49-47DA-8B71-66AB89A3F83B} => removed successfully HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => removed successfully C:\Users\misfi\AppData\Roaming\Mozilla\Firefox\Profiles\64on43rx.default\Extensions\[removed] => moved successfully C:\Users\misfi\AppData\Roaming\Mozilla\Firefox\Profiles\64on43rx.default\Extensions\[removed] => moved successfully "FF Notifications:" => removed successfully HKLM\System\CurrentControlSet\Services\aswTap => removed successfully aswTap => service removed successfully C:\WINDOWS\System32\drivers\aswTap.sys => moved successfully HKLM\System\CurrentControlSet\Services\tap0901 => removed successfully tap0901 => service removed successfully C:\WINDOWS\System32\drivers\tap0901.sys => moved successfully C:\Program Files\AVAST Software => moved successfully C:\ProgramData\AVAST Software => moved successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\IObitUnstaler => removed successfully HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\IObitUnstaler => removed successfully HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\IObitUnstaler => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5D67F1B3-6418-402D-B447-1DC89A3C89D3}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2D2F36FA-B23F-43C1-B847-449C2FDBD4F7}" => removed successfully VirusTotal: C:\WINDOWS\System32\drivers\BthA2dp.sys => https://www.virustotal.com/file/8b0f65f411c463cbc68b8039d4795a3d3a356f6f18ff165f2c14439bd8fb569a/analysis/1585723642/ VirusTotal: C:\windows\system32\rtvcvfw64.dll => https://www.virustotal.com/file/a126f29f665ba1b94392165cdcc6ffa0fdbfc330f5dde12dcaecd4c371b22681/analysis/1585666694/ VirusTotal: C:\Windows\SysWOW64\rtvcvfw32.dll => https://www.virustotal.com/file/746f4ccfd2752bc9e741977772647e00e63c340c57599008d6e900a24e40ad50/analysis/1585666699/ ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 10510336 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 56271560 B Java, Flash, Steam htmlcache => 372596179 B Windows/system/drivers => 2600253 B Edge => 50819 B Chrome => 13610924 B Firefox => 1159076137 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 19000 B NetworkService => 50888 B misfi => 19053431 B RecycleBin => 0 B EmptyTemp: => 1.5 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 16:18:25 ====