Bootkit or other problems – Virus, Trojan, Spyware, and Malware Removal Help – BleepingComputer

What's wrong with my computer?Please help me up to fix it. Thank you for yor help.

AVGVirus Remover for Bootkits

*** Analyzing boot areas ***

----------------------------

Reading MBR from PhysicalDrive0: nError = 00000000

Boot partition: 0

VBR offset: 00000000-00080000

Reading VBR from PhysicalDrive0: nError = 00000000

NTFS volume detected. Reading IPL: nError = 00000000

*** Analyzing disk drivers ***

------------------------------

Driver: disk.sys

DeviceObject: FFFFA906-65D8E080

DriverObject: FFFFA906-65D0AD10

Driver Start: FFFFF805-50580000

Driver Path: C:Windowssystem32driversdisk.sys

DrvUnhookDriver(disk.sys) failed. nError = E0010057

===========================================================

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-07-2021

Ran by HELLO (administrator) on ABC-PLAY (02-08-2021 20:56:39)

Running from C:UsersHELLODesktop

Loaded Profiles: HELLO

Platform: Windows 10 Pro Version 21H1 19043.1151 (X64) Language: Chinese (Traditional, Taiwan) -> English (United States)

Default browser: Chrome

Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Google LLC -> Google LLC) C:Program FilesGoogleChromeApplicationchrome.exe <12>

(Kaspersky Lab JSC -> AO Kaspersky Lab) C:Program Files (x86)Kaspersky LabKaspersky Internet Security 21.3avp.exe

(Kaspersky Lab JSC -> AO Kaspersky Lab) C:Program Files (x86)Kaspersky LabKaspersky Internet Security 21.3avpui.exe

(Kaspersky Lab JSC -> AO Kaspersky Lab) C:Program Files (x86)Kaspersky LabKaspersky Internet Security 21.3plugins_nms.exe

(Microsoft Corporation -> Microsoft Corporation) C:Program Files (x86)MicrosoftEdgeUpdateMicrosoftEdgeUpdate.exe

(Microsoft Windows -> Microsoft Corporation) C:UsersHELLOAppDataLocalTempA71F5651-0AA4-4AD1-AA5D-F99054F0D088DismHost.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsHelpPane.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsImmersiveControlPanelSystemSettings.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsSystem32cmd.exe <2>

(Microsoft Windows -> Microsoft Corporation) C:WindowsSystem32Dism.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsSystem32dllhost.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsSystem32drvinst.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsSystem32MoUsoCoreWorker.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsSystem32oobeUserOOBEBroker.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsSystem32smartscreen.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsSysWOW64wbemWmiPrvSE.exe

(Microsoft Windows -> Microsoft Corporation) C:WindowsWinSxSamd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1145_none_7e2e1aee7c75684dTiWorker.exe

(NVIDIA Corporation -> NVIDIA Corporation) C:Program FilesNVIDIA CorporationDisplay.NvContainerNVDisplay.Container.exe <2>

(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:Program FilesSUPERAntiSpywareSASCore64.exe

(Support.com Inc -> SUPERAntiSpyware) C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe

(SurfRight B.V. -> SurfRight B.V.) C:Program Files (x86)HitmanPro.Alerthmpalert.exe <2>

(SurfRight B.V. -> SurfRight B.V.) C:Program FilesHitmanProhmpsched.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKUS-1-5-21-2296713964-2084279076-2192899481-1001...Run: [SUPERAntiSpyware] => C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe [11223920 2021-06-29] (Support.com Inc -> SUPERAntiSpyware)

HKLMSoftwareMicrosoftActive SetupInstalled Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:Program FilesGoogleChromeApplication92.0.4515.107Installerchrmstp.exe [2021-07-26] (Google LLC -> Google LLC)

GroupPolicy: Restriction ? <==== ATTENTION

GroupPolicyUser: Restriction ? <==== ATTENTION

Policies: C:ProgramDataNTUSER.pol: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {15C05B90-3497-4843-9478-C8668582F30F} - System32TasksSUPERAntiSpyware Scheduled Task fb453ecb-e60b-4aac-a8e9-841ce6f05bcd => C:Program FilesSUPERAntiSpywareSASTask.exe [49944 2021-01-09] (SUPERAntiSpyware.com -> SUPERAdBlocker.com) -> "C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe" /TASK:fb453ecb-e60b-4aac-a8e9-841ce6f05bcd

Task: {20B49EDC-7119-4398-AC88-9CAEB4FA1501} - System32TasksGoogleUpdateTaskMachineUA => C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [154520 2021-07-18] (Google LLC -> Google LLC)

Task: {299D4BE4-1944-475E-AE7C-867AE8597492} - System32TasksCCleanerSkipUAC => D:ccsetup572CCleaner.exe

Task: {3BBF80C4-379B-4D52-8A9F-D0DA66FD7E5D} - System32TasksKaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:Program FilesCommon FilesAVKaspersky Labupgrade_launcher.exe [743488 2021-07-18] (Kaspersky Lab JSC -> AO Kaspersky Lab)

Task: {741BAE46-959E-483A-B8F1-D9A9C6208335} - System32TasksGoogleUpdateTaskMachineCore => C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [154520 2021-07-18] (Google LLC -> Google LLC)

Task: {9F622D2D-7198-4EEF-A3AB-60F257B373DA} - System32TasksSUPERAntiSpyware Scheduled Task db27122d-6c13-4f16-a918-4d45b5575121 => C:Program FilesSUPERAntiSpywareSASTask.exe [49944 2021-01-09] (SUPERAntiSpyware.com -> SUPERAdBlocker.com) -> "C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe" /TASK:db27122d-6c13-4f16-a918-4d45b5575121

Task: {A4A579BD-E186-45E4-9DA0-A16FB77042BC} - System32TasksOneDrive Standalone Update Task-S-1-5-21-2296713964-2084279076-2192899481-1001 => C:UsersHELLOAppDataLocalMicrosoftOneDriveOneDriveStandaloneUpdater.exe

Task: {BAD2AF23-F242-444B-9BEB-2A82A3DB9677} - System32TasksCreateExplorerShellUnelevatedTask => C:Windowsexplorer.exe /NoUACCheck

Task: {E2C84504-337F-483C-8B81-A6DA2D117F5D} - System32TasksTweaking.com - Windows Repair Tray Icon => C:Program Files (x86)Tweaking.comWindows Repair (All in One)WR_Tray_Icon.exe [220816 2019-10-01] (Tweaking LLC -> Tweaking.com)

Task: {E887E880-52F8-4433-8C2C-76A05AFD8379} - System32TasksCCleaner Update => D:ccsetup572CCUpdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:WindowsTasksCreateExplorerShellUnelevatedTask.job => C:Windowsexplorer.exe

Task: C:WindowsTasksSUPERAntiSpyware Scheduled Task db27122d-6c13-4f16-a918-4d45b5575121.job => C:Program FilesSUPERAntiSpywareSASTask.exe C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe

Task: C:WindowsTasksSUPERAntiSpyware Scheduled Task fb453ecb-e60b-4aac-a8e9-841ce6f05bcd.job => C:Program FilesSUPERAntiSpywareSASTask.exe C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

TcpipParameters: [DhcpNameServer] 192.168.1.1

Tcpip..Interfaces{c4d0c6eb-8a15-4b23-b491-052f46abc172}: [DhcpNameServer] 192.168.1.1

Edge:

=======

Edge DefaultProfile: Default

Edge Profile: C:UsersHELLOAppDataLocalMicrosoftEdgeUser DataDefault [2021-08-02]

Edge HKUS-1-5-21-2296713964-2084279076-2192899481-1001SOFTWAREMicrosoftEdgeExtensions...EdgeExtension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]

FireFox:

Continued here:
Bootkit or other problems - Virus, Trojan, Spyware, and Malware Removal Help - BleepingComputer

Related Posts

Comments are closed.