Thanks Starbuck, I have un-installed searchtoolshub and PC HelpSoft Driver Updater.
I hope I have the rest ok
.
I am unsure of the malwarebytes report as I did what you said and exported it's report but to where? It just disappeared. There was nothing to be quarantined. But it's on the clip board some where.
Ok let's see if I can paste the two that you need, Fixlog.txt (from FRST)
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-08-2022 02
Ran by mijje (16-08-2022 23:53:37) Run:1
Running from C:\Users\mijje\OneDrive\Desktop
Loaded Profiles: mijje
Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-68675055-564967560-4285980964-1001\...\Run: [Avast Browser] => C:\Users\mijje\AppData\Local\AVAST Software\Browser\Update\1.8.1206.2\AvastBrowserUpdateCore.exe (No File)
Task: {07CEC5E7-DB3D-4233-B2A6-C0D543A66F90} - System32\Tasks\AdBlocker Ultimate Updater => C:\Program Files\AdBlocker Ultimate\AdBlockerUltimateUpdater.exe hidden (No File) <==== ATTENTION
Task: {5EDB39B5-4BA3-416C-B6E7-355C540C63AF} - System32\Tasks\AdBlocker Ultimate Sync => C:\Program Files\AdBlocker Ultimate\AdBlockerUltimateGUI.exe /verify (No File) <==== ATTENTION
Task: {6CBEF361-EE00-46F9-B3B8-D803788F07C8} - \Microsoft\Windows\Management\Provisioning\PostResetBoot -> No File <==== ATTENTION
Task: {92E2FA3E-D0B1-4381-BF8F-E0D7A2DFBC9D} - \HPAudioSwitch -> No File <==== ATTENTION
Task: {E718D044-8F6E-48E7-953D-85D8F0FF19E2} - \OneDrive Standalone Update Task-S-1-5-21-2024600284-1515572505-3624664209-500 -> No File <==== ATTENTION
Edge Notifications: Default -> hxxps://lifeindigo.com; hxxps://www.buzzfond.com
Edge DefaultSearchURL: Default -> hxxps://find.searchtoolshub.com?2ba4e03bfc98ed613d9d865d7b57a55c=H1xAXFNGX1hbVVQNEQQwBw9cQ1pRR1heXVRKXFVCWltcVFQJDB0LUyknNy4nNikoW1FCW1FCLlY4VTopLyxdIClXQF9TRFlaXSJKXCdAV1opVw%253D%253D&q={searchTerms}
Edge DefaultSearchKeyword: Default -> find.searchtoolshub.com
FF Plugin HKU\S-1-5-21-68675055-564967560-4285980964-1001: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Users\mijje\AppData\Local\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll [No File]
FF Plugin HKU\S-1-5-21-68675055-564967560-4285980964-1001: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Users\mijje\AppData\Local\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll [No File]
CustomCLSID: HKU\S-1-5-21-68675055-564967560-4285980964-1001_Classes\CLSID\{167FD956-39C3-374C-927A-1D3C47CB6663}\InprocServer32 -> C:\Users\mijje\AppData\Local\AVAST Software\Browser\Update\1.8.1206.2\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-68675055-564967560-4285980964-1001_Classes\CLSID\{77CB610F-0C15-4CA8-A839-79C3AD7A400E}\InprocServer32 -> C:\Users\mijje\AppData\Local\AVAST Software\Browser\Update\1.8.1206.2\psuser_64.dll => No File
C:\Users\mijje\AppData\Local\AVAST Software
FirewallRules: [{3EA96598-6173-4657-81C0-C82979DCE902}] => (Allow) C:\Program Files\AdBlocker Ultimate\AdblockerUltimateGUI.exe => No File
FirewallRules: [{9FE5078E-37E6-4931-B3BD-D0FFD8B52892}] => (Allow) C:\Program Files\AdBlocker Ultimate\AdBlockerUltimateService.exe => No File
FirewallRules: [{918F7027-5B9E-4ECF-974B-5C0B1D2DE5B3}] => (Allow) C:\Program Files\AdBlocker Ultimate\AdBlockerUltimateService.exe => No File
S2 ABUService; C:\Program Files\AdBlocker Ultimate\AdBlockerUltimateService.exe [X]
S1 adavoid; system32\drivers\adavoid.sys [X]
U3 aspnet_state; no ImagePath
2022-08-09 22:36 - 2022-08-09 22:36 - 000601088 _____ (OldTimer Tools) C:\Users\mijje\Downloads\OTL.exe
2022-08-09 22:59 - 2022-08-09 22:59 - 000469692 _____ C:\Users\mijje\Downloads\OTL.Txt
2022-08-09 23:00 - 2022-08-09 23:00 - 000120704 _____ C:\Users\mijje\Downloads\Extras.Txt
2022-08-05 20:08 - 2022-08-05 20:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC HelpSoft Driver Updater
*****************
Processes closed successfully.
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
"HKU\S-1-5-21-68675055-564967560-4285980964-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Avast Browser" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{07CEC5E7-DB3D-4233-B2A6-C0D543A66F90}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{07CEC5E7-DB3D-4233-B2A6-C0D543A66F90}" => removed successfully
C:\WINDOWS\System32\Tasks\AdBlocker Ultimate Updater => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdBlocker Ultimate Updater" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5EDB39B5-4BA3-416C-B6E7-355C540C63AF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EDB39B5-4BA3-416C-B6E7-355C540C63AF}" => removed successfully
C:\WINDOWS\System32\Tasks\AdBlocker Ultimate Sync => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdBlocker Ultimate Sync" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{6CBEF361-EE00-46F9-B3B8-D803788F07C8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6CBEF361-EE00-46F9-B3B8-D803788F07C8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Management\Provisioning\PostResetBoot" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{92E2FA3E-D0B1-4381-BF8F-E0D7A2DFBC9D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92E2FA3E-D0B1-4381-BF8F-E0D7A2DFBC9D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPAudioSwitch" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E718D044-8F6E-48E7-953D-85D8F0FF19E2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E718D044-8F6E-48E7-953D-85D8F0FF19E2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Standalone Update Task-S-1-5-21-2024600284-1515572505-3624664209-500" => removed successfully
"Edge Notifications" => removed successfully
"Edge DefaultSearchURL" => removed successfully
"Edge DefaultSearchKeyword" => removed successfully
HKU\S-1-5-21-68675055-564967560-4285980964-1001\Software\MozillaPlugins\@update.avastbrowser.com/Avast Browser;version=3 => removed successfully
"C:\Users\mijje\AppData\Local\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll" => not found
HKU\S-1-5-21-68675055-564967560-4285980964-1001\Software\MozillaPlugins\@update.avastbrowser.com/Avast Browser;version=9 => removed successfully
"C:\Users\mijje\AppData\Local\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll" => not found
HKU\S-1-5-21-68675055-564967560-4285980964-1001_Classes\CLSID\{167FD956-39C3-374C-927A-1D3C47CB6663} => removed successfully
HKU\S-1-5-21-68675055-564967560-4285980964-1001_Classes\CLSID\{77CB610F-0C15-4CA8-A839-79C3AD7A400E} => removed successfully
"C:\Users\mijje\AppData\Local\AVAST Software" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3EA96598-6173-4657-81C0-C82979DCE902}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9FE5078E-37E6-4931-B3BD-D0FFD8B52892}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{918F7027-5B9E-4ECF-974B-5C0B1D2DE5B3}" => removed successfully
HKLM\System\CurrentControlSet\Services\ABUService => removed successfully
ABUService => service removed successfully
HKLM\System\CurrentControlSet\Services\adavoid => removed successfully
adavoid => service removed successfully
HKLM\System\CurrentControlSet\Services\aspnet_state => removed successfully
aspnet_state => service removed successfully
C:\Users\mijje\Downloads\OTL.exe => moved successfully
C:\Users\mijje\Downloads\OTL.Txt => moved successfully
C:\Users\mijje\Downloads\Extras.Txt => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC HelpSoft Driver Updater => moved successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 44433870 B
Java, Discord, Steam htmlcache => 0 B
Windows/system/drivers => 6416926 B
Edge => 0 B
Chrome => 465339449 B
Brave => 514266280 B
Firefox => 27282854 B
Opera => 38581141 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 47186 B
NetworkService => 403436 B
mijje => 22270259 B
RecycleBin => 4634 B
EmptyTemp: => 1 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 23:54:29 ====