Trojan On Computer 2, Think I Need Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chaos Annihilator, Mar 10, 2026.

  1. Chaos Annihilator

    Chaos Annihilator Private First Class

    This is a long story involving both of my computers, I know I need a different post for each, so this one can be for Computer 2.

    After upgrading to Windows 11 in October 2025, I switched both computers from Avast to Windows Defender hoping it was a good idea, and thinking it would make my computer (#2) faster since it struggled with Windows 11 in the beginning. I regularly ran Full Scans weekly, but week before last I skipped.

    When I finally full scans in Windows Defender (on Saturday, I think), Computer 2 came back fine, but Computer 1 found a trojan, and put it in quarantine. Since it only discovered this trojan when I was running a scan, and not earlier, I wondered if Windows Defender was the best. I also became worried about computer 2. They are both laptops, and I only use them on my own wifi, so I'm not sure how easy it is for them to share viruses, but a few days before the scan I used a USB stick to transfer a Libre document from Computer 1 with the trojan to Computer 2 without.

    So I did everything I could think of (on both computers just in case, so this applies to Computer 2 which we are focusing on in this thread, and when I scanned computer 2 I also had my USB stick plugged in so it would scan as well):

    I cleared all my cookies and cache on both computers, emptied the recycle bin, then I ran a Windows smart scan, offline scan, and another full scan. I ran free Malwarebytes, Spybot, Spybot's rootkit scan. Nothing found anything. So I reinstalled Avast like I did before, and ran a smart scan, which showed nothing, and then a full scan.

    The avast full scan ran overnight last night. When I checked them earlier today, it seemed like there was some glitch in avast or something, because instead of showing the scan progress, the window was black (on both computers). When I returned to the Scans page, under Full scan it showed it was still going, but at 100%. I gave it a couple more hours. Computer 2 finally finished, and when I went to check the results, there was a trojan found on Computer 2 now as well! It put it in quarantine, but why are these getting through undetected? Is there something else lurking around that I haven't found yet?

    Computer 2 is the one I use for all my important things, so I figured it was time to enlist some help. The full Avast scan on Computer 1 is still running, so we'll see how that goes.

    FRST logs for computer 2 are attached. I'll start working on a post for computer 1 in a little bit after I give Avast some more time. I just realized that I did not have the USB in question plugged in when I ran FRST, should I have?

    Any help is appreciated. Thanks!
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome back to Major Geeks Malware Forum.

    We can check the USB later. Please allow me some time to review what you have posted.
     
  3. Chaos Annihilator

    Chaos Annihilator Private First Class

    Hi friend. Sure, thanks!
     
  4. Chaos Annihilator

    Chaos Annihilator Private First Class

    Here's a weird update that I'm not sure is relevant: While waiting for a reply, on this computer 2 I went to my email to see if I saw anything suspicious, and see if I could figure out how to scan my emails. There's a new section in Avast that says it uses AI and you can paste in links and it will check it for you. So, to test it all out, I dropped an email link in, and Avast said it thought it was safe.

    But then my computer made a strange loud buzzing noise that it had never made before - not the normal working sounds, not a fan's clogged up sound, but really loud strange electrical buzzing that was continuous. I thought maybe Avast was trying to make a bling noise and it freaked out, so I tried to mute my computer and see if it would quit, but I couldn't mute it. Then the task bar started flashing quickly, and my cursor started circling like it was trying to do something. I couldn't close windows, the noise wouldn't stop, the task bar kept flashing, so I turned the computer off, cleaned the vents, and turned it back on. Everything seems fine now.

    Reading back over what I typed, I think it sounds insane. I swear I'm not taking anything. I don't know if my computer just freaked out or if it is related to whatever else is going on, but I thought I'd let you know.
     
  5. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for the updated post. I am wondering if it might be related to the lack of memory as detailed below.

    We will work on one computer at a time.

    Please consider and do this.

    This is an insufficient amount of available memory to run your system.

    ===================================================

    Uninstalling Adobe Flash Player

    --------------------

    Note: Adobe Flash Player is no longer supported and is a security risk.
    • Download Adobe Flash Player Uninstaller and save it to your Desktop
    • Right click on the icon and select Run as administrator
    • Click Uninstall then Done to reboot your computer
    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a log on the desktop called Fixlog.txt
    • Copy and paste the contents of the report in your reply. If it is too large you can attach it or uploaded here
    • The tool will create a zipped folder on your Desktop with today's date, example: 02.17.2022_13.24.50.zip. Attach the report to your reply

    ===================================================

    Uninstalling Programs Using Revo Uninstaller Free Portable

    --------------------
    • Download Revo Uninstaller Free Portable and save it to your Desktop
    • Right click on the folder and select Extract All..., then click Extract
    • Double click on the RevoUninstaller-Portable folder
    • Right click on RevoUPort and select Run as administrator
    • Click OK on the License Agreement
    • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
    Code:
    Lenovo App Explorer
    Spybot - Search and Destroy
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Flash player uninstalled?
    • Fixlog
    • Attached file
    • Programs removed?
     

    Attached Files:

  6. Chaos Annihilator

    Chaos Annihilator Private First Class

    After my last post, I noticed my computer was trying to update. This always bogs it down so bad its pretty near unusable until it's done. I was going to pull up my task manager now and report that my memory was freed up since the update is complete, by my memory is still between 86% and 89%, so I don't know what to say about that.

    Flash player is uninstalled, the Fixlog and zip folder are attached.
    I could not find anything like Lenovo App Explorer, and I successfully removed Spybot.

    Thanks
     

    Attached Files:

  7. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the reply.

    Avast is not showing any detections, although the reports are for a very limited timeframe.

    Do you recognize this?

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Close any open programs or windows because your computer will automatically reboot after FRST64 is run
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    Zip: C:\ProgramData\rionix\NewYankee\_log.html
    Lenovo App Explorer (HKU\S-1-5-19\...\Host App Service) (Version: 0.273.2.343 - SweetLabs for Lenovo) <==== ATTENTION
    Lenovo App Explorer (HKU\S-1-5-20\...\Host App Service) (Version: 0.273.2.343 - SweetLabs for Lenovo) <==== ATTENTION
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    Emptytemp:
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • WARNING Regarding the Emptytemp: command, please see here before running the Fixlist.
    • The tool will create a zipped folder on the Desktop with today's date. Please attach it to your reply

    ===================================================

    Windows Defender Offline Scan

    --------------------
    • Click Start, type Security, then select Windows Security
    • Click Virus & threat protection
    • Click Scan options
    • Select Microsoft Defender Offline scan
    • Click Scan now
    • Click Scan after saving any work
    • Once completed your computer will reboot
    • Click Start, type Security then select Windows Security
    • Click Virus & threat protection
    • Click Protection history
    • Let me know if there are any listed threats identified around the time the offline scan was completed
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Recognize NewYankee?
    • Fixlog
    • Attached file
    • Offline scan result
     
  8. Chaos Annihilator

    Chaos Annihilator Private First Class

    Sorry, I'm working at this slowly but surely.

    When I go to the protection history in Avast I can see what it caught and put in quarantine. I tried to take a screenshot for you, but it won't let me. It calls it "INI:Shortcut-inf [Trj]" the infected file is "C:\Users\Mariah\Desktop\shortcuts\inhalers..." then it cuts it out and I can't read the rest now. There's probably a more limited timeframe because I just installed Avast the day before yesterday.

    I do recognize New Yankee, it's a game series I've been testing. rionix maybe the developer, I'm not sure about that.

    The fix log is attached and the zip file, and that's as far as I got so far. A different text file appeared that I don't recognize after I ran FRST, called "irybwgflubgwioajh.txt". I'm quite sure I have no idea what this is, and am afraid to open it or attach it for you. Should I do either?

    I'll report back once I finish the offline scan. I ran it a couple of days ago, and couldn't figure out how to see the results. Nothing showed up in the history then, but I'll give it a go and see what happens. Thanks!
     

    Attached Files:

  9. Chaos Annihilator

    Chaos Annihilator Private First Class

    Computer 2 was too slow to get to the offline scan, so I restarted and it's trying to update again. I should get it done soon.
     
  10. Chaos Annihilator

    Chaos Annihilator Private First Class

    Okay, I finished. The offline scan found no threats.
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks.

    The randomly named file was a temporary file name for Fixlog.txt. It should have automatically been deleted but sometimes it is not.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Close any open programs or windows because your computer will automatically reboot after FRST64 is run
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     
  12. Chaos Annihilator

    Chaos Annihilator Private First Class

    I'm glad the text file wasn't anything bad, sorry I freak out so easily.

    Here is the log, but it seems it quit because it took too long. Should I try it again?

    Are you seeing anything concerning with this computer so far, or can you tell yet?

    Thanks!

    Fix result of Farbar Recovery Scan Tool (x64) Version: 11-03-2026
    Ran by Mariah (11-03-2026 21:11:32) Run:3
    Running from C:\Users\Mariah\Desktop
    Loaded Profiles: Mariah
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    *****************


    ========= DISM /Online /Cleanup-Image /RestoreHealth =========


    Fixing is terminated due to reaching maximum fixing time of 60 minutes. <==== ATTENTION
     
  13. Chaos Annihilator

    Chaos Annihilator Private First Class

    My computer started being slow, but then it straightened up. I hadn't heard if I should try the fix again, but just in case my slow computer messed it up I went ahead and ran it again, but again it terminated because of how long it took. After that, I restarted, and now Computer 2 is stuck updating again. It's been trying for over an hour as of this post, and it has just a black screen with the normal "Windows is updating, don't turn off your computer" message, but giving no percent.

    Both of the computers updated quickly yesterday. Computer 1 has been working fine since, computer 2 has updated each time I restart after that. This morning, after an update, I checked to see if windows thought it was up to date now, and if an update was failing, but it all looked fine and up to date. I don't know why it would be stuck trying to update again, when it thought it was up to date just hours before.

    I'm not sure what to do now, or if it is related to whatever else has been going on with this computer, but since the screen thinks I shouldn't turn my computer off, I guess I won't, and we'll see if it figures itself out.
     
  14. Chaos Annihilator

    Chaos Annihilator Private First Class

    Consistent with my usual character, I freaked out prematurely. About 25 minutes after my last post, this computer 2 finished updating and is now working okay so far. I checked the update history for this one and also computer 1, and it looks pretty similar, so I still don't know why computer 2 has to update continually. But as of right now, it's working and thinks it is up to date, so we'll see.
     
  15. Oh My!

    Oh My! Malware Expert Staff Member

    The lack of sufficient available memory will affect your system in various ways. I suspect the Windows Update issue and the inability of FRST64 to complete the requested task via the Fixlist command may be because of that.

    Please do this.

    ===================================================

    CBS and DISM Zip Folders

    --------------------
    • Hit the Ctrl + E keys at the same time
    • Navigate to each of the below folders, right click on the folder, select Send to, then select Compressed (zipped) folder
    • The zipped folders will be placed on the desktop
    C:\Windows\Logs\CBS
    C:\Windows\Logs\DISM
    • Upload the zipped folders to GoFile or the file hosting site of your choice and post the download links in your reply

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST will do it for you
    Code:
    Start::
    Powershell: Get-WindowsUpdateLog
    End::
    
    • Click Fix
    • When completed he tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • The tool will also create a WindowsUpdate report on the desktop. Attach that file to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Download links
    • Fixlog
    • Attached WindowsUpdate report
     
  16. Chaos Annihilator

    Chaos Annihilator Private First Class

  17. Chaos Annihilator

    Chaos Annihilator Private First Class

    Here is the fix log, the windows update log is too large to attach. What do you want me to do with it?

    Fix result of Farbar Recovery Scan Tool (x64) Version: 12-03-2026
    Ran by Mariah (12-03-2026 09:55:27) Run:5
    Running from C:\Users\Mariah\Desktop
    Loaded Profiles: Mariah
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    Powershell: Get-WindowsUpdateLog
    End::
    *****************


    ========= Get-WindowsUpdateLog =========


    ========= End of Powershell: =========


    ==== End of Fixlog 10:15:58 ====
     
  18. Oh My!

    Oh My! Malware Expert Staff Member

    Upload it in the same fashion as the other folders.
     
  19. Chaos Annihilator

    Chaos Annihilator Private First Class

    Okay, here's the link.

    https://gofile.io/d/POsXKs

    How's it looking so far? Do you think a trojan is messing with my memory, or something else is going on? Thanks for your help.
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    I don't think this is malware related but rather it involves system corruptions. I don't know whether this is directly impacting your memory or if the memory issue is related to something else.

    This is what is contained in the CBS log. Quite a number of corrupted files were successfully repaired.

    Let's try running a command directly from an Administrator command prompt rather than through FRST64. Please do this.
    • Click Start, type cmd, then select Run as administrator
    • Copy and paste DISM /Online /Cleanup-Image /RestoreHealth after the command prompt then hit Enter
    • Let it run and report the results
     
  21. Chaos Annihilator

    Chaos Annihilator Private First Class

    I'm waiting for the command prompt to finish. Do you think it is safe to use this computer for things (shopping, email, banking, etc) or do you think I should wait until we figure this out?
     
  22. Chaos Annihilator

    Chaos Annihilator Private First Class

    The restore operation completed successfully.
     
  23. Oh My!

    Oh My! Malware Expert Staff Member

    Outstanding.

    Yes, your computer is safe to use.

    Please run a new FRST Scan and attach both reports to your reply.
     
  24. Chaos Annihilator

    Chaos Annihilator Private First Class

    Here are the logs. Thanks!
     

    Attached Files:

  25. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the reports

    We are still very low on available memory. 4GB to start with is not much and not sure how much we can do about it. Is the computer performing reasonably well?

    Please do this.

    ===================================================

    Reviewing Resource Monitor Memory Information

    --------------------
    • Press the Windows Key + R at the same time
    • Type resmon and press Enter
    • Click on the Memory tab
    • Click Commit (KB) so that the highest number is at the top
    • Take and save a Screenshot of the window
    • Attach the screenshot to your reply
    ===================================================

    GSmartControl for Windows - Portable

    -------------------
    • Download GSmartControl for Windows - Portable and save it to your desktop
    • Right click on gsmartcontrol.zip icon and select Extract All... then Extract
    • Double click on the gsmartcontrol folder
    • Right click on gsmartcontrol (not .manifest) and select Run as administrator
    • Allow the program to search for and list your hard drive(s)
    • Double click your drive C: drive
    • Go to the Self-tests tab
    • Make sure that the Test Type is set to Short Self-test
    • Click the Execute button
    • After the test completes, click the View Output button and copy and paste the contents in your reply
    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Close any open programs or windows because your computer will automatically reboot after FRST64 is run
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: type "C:\WINDOWS\wininit.ini"
    2026-03-11 23:00 - 2026-03-11 23:00 - 000000049 _____ C:\Users\Mariah\Desktop\qpcjgbxgopbudb.txt
    2026-03-11 11:40 - 2026-03-11 11:40 - 000000385 _____ C:\Users\Mariah\Desktop\irybwgflubgwioajh.txt
    2026-03-11 03:54 - 2021-09-11 16:49 - 000000132 _____ C:\WINDOWS\wininit.ini
    2026-03-11 03:14 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2026-03-11 02:04 - 2018-11-22 20:49 - 000000000 ____D C:\Users\Mariah\AppData\Roaming\Macromedia
    2026-03-11 02:04 - 2018-11-22 11:36 - 000000000 ____D C:\Users\Mariah\AppData\Roaming\Adobe
    AV: Spybot - Search and Destroy (Disabled - Out of date) {F77C7796-45C4-531E-0DAE-B4A8229B11C8}
    HKLM\...\StartupApproved\Run32: => "SDTray"
    HKU\S-1-5-21-4161042128-27025238-194098315-1001\...\Run: [MicrosoftEdgeAutoLaunch_C7A758F97B67A36FC173A1DB646841D7] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4342312 2026-03-06] (Microsoft Corporation -> Microsoft Corporation)
    Task: {C85B768E-84EE-4649-A729-B63CED61B0AB} - System32\Tasks\Microsoft\Windows\Setup\SetupRecoveryDataTask => {717aa9c3-17e5-483b-81cc-8e27ed927763} C:\WINDOWS\system32\oobe\SetupRecoveryDataTask.dll [106496 2026-03-10] (Microsoft Windows -> Microsoft Corporation)
    ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> No File 
    ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> No File 
    ContextMenuHandlers2: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> No File 
    ContextMenuHandlers2: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> No File 
    ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> No File 
    ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> No File 
    FirewallRules: [{FAFE5243-D959-4CB9-928B-1A024702687B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File 
    FirewallRules: [{5A4E17E0-8BFC-4585-BC09-015E0D1DDCED}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File 
    FirewallRules: [{5180858E-BF8D-4DD6-93CA-84E2540D1E69}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Barrow Hill\Barrow Hill.exe => No File 
    FirewallRules: [{49719C84-5817-4668-A95A-DA8438364CE7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Barrow Hill\Barrow Hill.exe => No File 
    FirewallRules: [{F83DAFE8-69F7-49D0-8E87-EAFC9DDEC073}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File 
    FirewallRules: [{A20D8879-D92D-4203-90E2-B541FF9F03C0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File 
    cmd: chkdsk
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Farbar Recovery Scan Tool SearchAll

    --------------------
    • Launch FRST
    • Copy and paste the following in the Search: box
    Code:
    SearchAll: SweetLabs;"Lenovo App Explorer";Spybot;"Flash Player"
    
    • Click the Search Files button
    • When completed click OK and a Search.txt document will open on your desktop
    • Attach the report to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • How is your system running?
    • Resource Monitor screen shot
    • GSmart report
    • Fixlog
    • Search.txt
     
  26. Chaos Annihilator

    Chaos Annihilator Private First Class

    This computer runs generally well. Often it gets slow, but as soon as I get really fed up with it, it starts working fine again. I really thought this computer was done for after updating to windows 11 in october, but eventually it straightened up. It has been slower than usual this week so far, but not too bad. Updates tend to be a headache and can be a day long ordeal where I cannot use the computer until it's done. If I'm really unlucky, an update can cause my computer to be basically unusable for 3 days.

    But otherwise (when it isn't trying to update) I like how it works, though if you have a magic spell to make it work better, I'll take it :). I worried this week about it being slow because of the trojans found on both computers, but if you don't consider that and take into account that it updated on Tuesday (and Wednesday), it hasn't been too bad.

    Are you sure there's no malware? Should I be running any other virus scans?

    Attached is the screenshot, let me know if I didn't catch all the information you wanted. The GSmart report follows, and I am still working on the rest. You're amazing, Thank You!

    smartctl 6.6 2017-11-05 r4594 [x86_64-w64-mingw32-w10-b26200] (sf-6.6-1)
    Copyright (C) 2002-17, Bruce Allen, Christian Franke, www.smartmontools.org

    === START OF INFORMATION SECTION ===
    Device Model: ST1000LM035-1RK172
    Serial Number: WL12YNWR
    LU WWN Device Id: 5 000c50 0b9367432
    Firmware Version: LCM2
    User Capacity: 1,000,204,886,016 bytes [1.00 TB]
    Sector Sizes: 512 bytes logical, 4096 bytes physical
    Rotation Rate: 5400 rpm
    Form Factor: 2.5 inches
    Device is: Not in smartctl database [for details use: -P showall]
    ATA Version is: ACS-3 T13/2161-D revision 3b
    SATA Version is: SATA 3.1, 6.0 Gb/s (current: 6.0 Gb/s)
    Local Time is: Thu Mar 12 19:20:11 2026 CDT
    SMART support is: Available - device has SMART capability.
    SMART support is: Enabled
    AAM feature is: Unavailable
    APM level is: 128 (minimum power consumption without standby)
    Rd look-ahead is: Enabled
    Write cache is: Enabled
    DSN feature is: Unavailable
    ATA Security is: Disabled, frozen [SEC2]

    === START OF READ SMART DATA SECTION ===
    SMART overall-health self-assessment test result: PASSED
    See vendor-specific Attribute list for marginal Attributes.

    General SMART Values:
    Offline data collection status: (0x00) Offline data collection activity
    was never started.
    Auto Offline Data Collection: Disabled.
    Self-test execution status: ( 0) The previous self-test routine completed
    without error or no self-test has ever
    been run.
    Total time to complete Offline
    data collection: ( 0) seconds.
    Offline data collection
    capabilities: (0x71) SMART execute Offline immediate.
    No Auto Offline data collection support.
    Suspend Offline collection upon new
    command.
    No Offline surface scan supported.
    Self-test supported.
    Conveyance Self-test supported.
    Selective Self-test supported.
    SMART capabilities: (0x0003) Saves SMART data before entering
    power-saving mode.
    Supports SMART auto save timer.
    Error logging capability: (0x01) Error logging supported.
    General Purpose Logging supported.
    Short self-test routine
    recommended polling time: ( 1) minutes.
    Extended self-test routine
    recommended polling time: ( 162) minutes.
    Conveyance self-test routine
    recommended polling time: ( 2) minutes.
    SCT capabilities: (0x3035) SCT Status supported.
    SCT Feature Control supported.
    SCT Data Table supported.

    SMART Attributes Data Structure revision number: 10
    Vendor Specific SMART Attributes with Thresholds:
    ID# ATTRIBUTE_NAME FLAGS VALUE WORST THRESH FAIL RAW_VALUE
    1 Raw_Read_Error_Rate POSR-- 083 064 034 - 209512107
    3 Spin_Up_Time PO---- 099 099 000 - 0
    4 Start_Stop_Count -O--CK 037 037 020 - 65535
    5 Reallocated_Sector_Ct PO--CK 100 100 036 - 0
    7 Seek_Error_Rate POSR-- 089 060 045 - 747323029
    9 Power_On_Hours -O--CK 086 086 000 - 12876 (174 27 0)
    10 Spin_Retry_Count PO--C- 100 100 097 - 0
    12 Power_Cycle_Count -O--CK 084 084 020 - 16995
    184 End-to-End_Error -O--CK 100 100 099 - 0
    187 Reported_Uncorrect -O--CK 100 100 000 - 0
    188 Command_Timeout -O--CK 100 001 000 - 253
    189 High_Fly_Writes -O-RCK 100 100 000 - 0
    190 Airflow_Temperature_Cel -O---K 061 037 040 Past 39 (Min/Max 18/43 #8)
    191 G-Sense_Error_Rate -O--CK 100 100 000 - 49
    192 Power-Off_Retract_Count -O--CK 100 100 000 - 19
    193 Load_Cycle_Count -O--CK 001 001 000 - 239297
    194 Temperature_Celsius -O---K 039 063 000 - 39 (0 4 0 0 0)
    196 Reallocated_Event_Count -O--CK 100 100 000 - 0
    197 Current_Pending_Sector -O--C- 100 100 000 - 0
    198 Offline_Uncorrectable ----C- 100 100 000 - 0
    199 UDMA_CRC_Error_Count -OSRCK 200 200 000 - 0
    240 Head_Flying_Hours POSR-- 087 087 030 - 12246 (129 87 0)
    254 Free_Fall_Sensor -O--CK 100 100 000 - 0
    ||||||_ K auto-keep
    |||||__ C event count
    ||||___ R error rate
    |||____ S speed/performance
    ||_____ O updated online
    |______ P prefailure warning

    General Purpose Log Directory Version 1
    SMART Log Directory Version 1 [multi-sector log support]
    Address Access R/W Size Description
    0x00 GPL,SL R/O 1 Log Directory
    0x01 SL R/O 1 Summary SMART error log
    0x02 SL R/O 5 Comprehensive SMART error log
    0x03 GPL R/O 5 Ext. Comprehensive SMART error log
    0x04 GPL,SL R/O 8 Device Statistics log
    0x06 SL R/O 1 SMART self-test log
    0x07 GPL R/O 1 Extended self-test log
    0x09 SL R/W 1 Selective self-test log
    0x10 GPL R/O 1 NCQ Command Error log
    0x11 GPL R/O 1 SATA Phy Event Counters log
    0x21 GPL R/O 1 Write stream error log
    0x22 GPL R/O 1 Read stream error log
    0x24 GPL R/O 512 Current Device Internal Status Data log
    0x30 GPL,SL R/O 9 IDENTIFY DEVICE data log
    0x80-0x9f GPL,SL R/W 16 Host vendor specific log
    0xa1 GPL,SL VS 24 Device vendor specific log
    0xa2 GPL VS 8160 Device vendor specific log
    0xa8 GPL,SL VS 136 Device vendor specific log
    0xa9 GPL,SL VS 1 Device vendor specific log
    0xab GPL VS 1 Device vendor specific log
    0xb0 GPL VS 8920 Device vendor specific log
    0xbe-0xbf GPL VS 65535 Device vendor specific log
    0xc0 GPL,SL VS 1 Device vendor specific log
    0xc1 GPL,SL VS 16 Device vendor specific log
    0xc2 GPL,SL VS 240 Device vendor specific log
    0xc3 GPL,SL VS 8 Device vendor specific log
    0xc4 GPL,SL VS 24 Device vendor specific log
    0xc9 GPL,SL VS 1 Device vendor specific log
    0xca GPL,SL VS 16 Device vendor specific log
    0xd3 GPL VS 1920 Device vendor specific log
    0xdf GPL,SL VS 1 Device vendor specific log
    0xe0 GPL,SL R/W 1 SCT Command/Status
    0xe1 GPL,SL R/W 1 SCT Data Transfer

    SMART Extended Comprehensive Error Log Version: 1 (5 sectors)
    No Errors Logged

    SMART Extended Self-test Log Version: 1 (1 sectors)
    Num Test_Description Status Remaining LifeTime(hours) LBA_of_first_error
    # 1 Short offline Completed without error 00% 12876 -

    SMART Selective self-test log data structure revision number 1
    SPAN MIN_LBA MAX_LBA CURRENT_TEST_STATUS
    1 0 0 Not_testing
    2 0 0 Not_testing
    3 0 0 Not_testing
    4 0 0 Not_testing
    5 0 0 Not_testing
    Selective self-test flags (0x0):
    After scanning selected spans, do NOT read-scan remainder of disk.
    If Selective self-test is pending on power-up, resume after 0 minute delay.

    SCT Status Version: 3
    SCT Version (vendor specific): 522 (0x020a)
    SCT Support Level: 1
    Device State: Active (0)
    Current Temperature: 39 Celsius
    Power Cycle Min/Max Temperature: 18/43 Celsius
    Lifetime Min/Max Temperature: 4/63 Celsius
    Under/Over Temperature Limit Count: 0/54
    Vendor specific:
    00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

    SCT Temperature History Version: 2
    Temperature Sampling Period: 1 minute
    Temperature Logging Interval: 11 minutes
    Min/Max recommended Temperature: 0/ 0 Celsius
    Min/Max Temperature Limit: 0/ 0 Celsius
    Temperature History Size (Index): 128 (122)

    Index Estimated Time Temperature Celsius
    123 2026-03-11 19:53 39 ********************
    124 2026-03-11 20:04 39 ********************
    125 2026-03-11 20:15 39 ********************
    126 2026-03-11 20:26 40 *********************
    127 2026-03-11 20:37 41 **********************
    0 2026-03-11 20:48 40 *********************
    1 2026-03-11 20:59 40 *********************
    2 2026-03-11 21:10 39 ********************
    3 2026-03-11 21:21 40 *********************
    4 2026-03-11 21:32 39 ********************
    5 2026-03-11 21:43 40 *********************
    6 2026-03-11 21:54 40 *********************
    7 2026-03-11 22:05 39 ********************
    8 2026-03-11 22:16 39 ********************
    9 2026-03-11 22:27 39 ********************
    10 2026-03-11 22:38 ? -
    11 2026-03-11 22:49 21 **
    12 2026-03-11 23:00 30 ***********
    13 2026-03-11 23:11 33 **************
    14 2026-03-11 23:22 34 ***************
    15 2026-03-11 23:33 37 ******************
    16 2026-03-11 23:44 36 *****************
    17 2026-03-11 23:55 39 ********************
    18 2026-03-12 00:06 40 *********************
    19 2026-03-12 00:17 41 **********************
    20 2026-03-12 00:28 42 ***********************
    21 2026-03-12 00:39 42 ***********************
    22 2026-03-12 00:50 41 **********************
    23 2026-03-12 01:01 41 **********************
    24 2026-03-12 01:12 40 *********************
    25 2026-03-12 01:23 39 ********************
    26 2026-03-12 01:34 40 *********************
    27 2026-03-12 01:45 39 ********************
    28 2026-03-12 01:56 40 *********************
    29 2026-03-12 02:07 41 **********************
    30 2026-03-12 02:18 41 **********************
    31 2026-03-12 02:29 42 ***********************
    32 2026-03-12 02:40 43 ************************
    33 2026-03-12 02:51 43 ************************
    34 2026-03-12 03:02 42 ***********************
    ... ..( 7 skipped). .. ***********************
    42 2026-03-12 04:30 42 ***********************
    43 2026-03-12 04:41 41 **********************
    44 2026-03-12 04:52 41 **********************
    45 2026-03-12 05:03 42 ***********************
    46 2026-03-12 05:14 41 **********************
    47 2026-03-12 05:25 42 ***********************
    48 2026-03-12 05:36 42 ***********************
    49 2026-03-12 05:47 43 ************************
    ... ..( 3 skipped). .. ************************
    53 2026-03-12 06:31 43 ************************
    54 2026-03-12 06:42 42 ***********************
    55 2026-03-12 06:53 40 *********************
    56 2026-03-12 07:04 ? -
    57 2026-03-12 07:15 28 *********
    58 2026-03-12 07:26 37 ******************
    59 2026-03-12 07:37 36 *****************
    60 2026-03-12 07:48 32 *************
    61 2026-03-12 07:59 34 ***************
    62 2026-03-12 08:10 36 *****************
    63 2026-03-12 08:21 38 *******************
    64 2026-03-12 08:32 39 ********************
    65 2026-03-12 08:43 38 *******************
    66 2026-03-12 08:54 ? -
    67 2026-03-12 09:05 25 ******
    68 2026-03-12 09:16 ? -
    69 2026-03-12 09:27 18 -
    70 2026-03-12 09:38 30 ***********
    71 2026-03-12 09:49 34 ***************
    72 2026-03-12 10:00 37 ******************
    73 2026-03-12 10:11 37 ******************
    74 2026-03-12 10:22 35 ****************
    75 2026-03-12 10:33 34 ***************
    76 2026-03-12 10:44 35 ****************
    77 2026-03-12 10:55 35 ****************
    78 2026-03-12 11:06 30 ***********
    79 2026-03-12 11:17 30 ***********
    80 2026-03-12 11:28 29 **********
    81 2026-03-12 11:39 30 ***********
    82 2026-03-12 11:50 30 ***********
    83 2026-03-12 12:01 29 **********
    84 2026-03-12 12:12 29 **********
    85 2026-03-12 12:23 29 **********
    86 2026-03-12 12:34 28 *********
    87 2026-03-12 12:45 27 ********
    88 2026-03-12 12:56 26 *******
    89 2026-03-12 13:07 33 **************
    90 2026-03-12 13:18 37 ******************
    91 2026-03-12 13:29 36 *****************
    92 2026-03-12 13:40 34 ***************
    93 2026-03-12 13:51 35 ****************
    94 2026-03-12 14:02 35 ****************
    95 2026-03-12 14:13 33 **************
    96 2026-03-12 14:24 33 **************
    97 2026-03-12 14:35 34 ***************
    98 2026-03-12 14:46 37 ******************
    99 2026-03-12 14:57 40 *********************
    100 2026-03-12 15:08 41 **********************
    101 2026-03-12 15:19 41 **********************
    102 2026-03-12 15:30 41 **********************
    103 2026-03-12 15:41 42 ***********************
    104 2026-03-12 15:52 43 ************************
    105 2026-03-12 16:03 43 ************************
    106 2026-03-12 16:14 43 ************************
    107 2026-03-12 16:25 42 ***********************
    108 2026-03-12 16:36 42 ***********************
    109 2026-03-12 16:47 41 **********************
    110 2026-03-12 16:58 41 **********************
    111 2026-03-12 17:09 40 *********************
    112 2026-03-12 17:20 37 ******************
    113 2026-03-12 17:31 40 *********************
    114 2026-03-12 17:42 40 *********************
    115 2026-03-12 17:53 39 ********************
    116 2026-03-12 18:04 37 ******************
    117 2026-03-12 18:15 33 **************
    118 2026-03-12 18:26 33 **************
    119 2026-03-12 18:37 34 ***************
    120 2026-03-12 18:48 35 ****************
    121 2026-03-12 18:59 36 *****************
    122 2026-03-12 19:10 39 ********************

    SCT Error Recovery Control command not supported

    Device Statistics (GP Log 0x04)
    Page Offset Size Value Flags Description
    0x01 ===== = = === == General Statistics (rev 1) ==
    0x01 0x008 4 16995 --- Lifetime Power-On Resets
    0x01 0x010 4 12876 --- Power-on Hours
    0x01 0x018 6 61515080746 --- Logical Sectors Written
    0x01 0x020 6 1335282478 --- Number of Write Commands
    0x01 0x028 6 104001125907 --- Logical Sectors Read
    0x01 0x030 6 2258036430 --- Number of Read Commands
    0x01 0x038 6 - --- Date and Time TimeStamp
    0x03 ===== = = === == Rotating Media Statistics (rev 1) ==
    0x03 0x008 4 7209 --- Spindle Motor Power-on Hours
    0x03 0x010 4 3961 --- Head Flying Hours
    0x03 0x018 4 239297 --- Head Load Events
    0x03 0x020 4 0 --- Number of Reallocated Logical Sectors
    0x03 0x028 4 0 --- Read Recovery Attempts
    0x03 0x030 4 0 --- Number of Mechanical Start Failures
    0x03 0x038 4 0 --- Number of Realloc. Candidate Logical Sectors
    0x04 ===== = = === == General Errors Statistics (rev 1) ==
    0x04 0x008 4 75 --- Number of Reported Uncorrectable Errors
    0x04 0x010 4 253 --- Resets Between Cmd Acceptance and Completion
    |||_ C monitored condition met
    ||__ D supports DSN
    |___ N normalized value

    SATA Phy Event Counters (GP Log 0x11)
    ID Size Value Description
    0x000a 2 3 Device-to-host register FISes sent due to a COMRESET
    0x0001 2 0 Command failed due to ICRC error
    0x0003 2 0 R_ERR response for device-to-host data FIS
    0x0004 2 0 R_ERR response for host-to-device data FIS
    0x0006 2 0 R_ERR response for device-to-host non-data FIS
    0x0007 2 0 R_ERR response for host-to-device non-data FIS
     
  27. Chaos Annihilator

    Chaos Annihilator Private First Class

    Oops, I just realized I didn't attach the screenshot. Here it is with the fix log, now I'm onto the search.
     

    Attached Files:

  28. Chaos Annihilator

    Chaos Annihilator Private First Class

    The search took a while, here it is. Have a good night!
     

    Attached Files:

  29. Oh My!

    Oh My! Malware Expert Staff Member

    I am sure there is no malware.

    Relatively speaking the guts of your computer are dated and minimal. In its current state it is difficult for the computer to complete Windows Updates. I am not sure how much we can improve the performance.

    Your hard drive looks fine and there is no evidence of concerning degradation.

    I would have expected Avast to be a resource hog but the memory screen shot is indicating a lot of memory is being utilized by Firefox.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a log on the desktop called Fixlog.txt
    • Copy and paste the contents of the report in your reply. If it is too large you can attach it or uploaded here
    ===================================================

    Managing Firefox and System Memory Usage

    --------------------

    • Launch Firefox
    • Copy and paste the below in the address bar then Enter
      Code:
      about:preferences
    • Scroll down to Performance
    • Uncheck Use recommended performance settings
    • Uncheck Use hardware acceleration when available
    • Copy and paste the below in the address bar then Enter
      Code:
      about:config
    • Click Accept the Risk and Continue
    • Copy and paste the below in the Search preference name
      Code:
      browser.tabs.unloadOnLowMemory
    • If the setting is false, click on the opposing arrows to the far right to toggle the setting to true
    • Copy and paste the below in the address bar then Enter
      Code:
      about:memory
    • Select Minimize Memory Usage
    • Close then re-open Firefox
    • Copy and paste the below in the address bar then Enter
      Code:
      about:processes
    • Click on the Memory tab to list the highest to lowest number
    • Monitor memory usage, in particular Firefox and Extensions, and report the top 5 highest Name entries and the amount of memory being used by each
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Firefox results?
     

    Attached Files:

  30. Chaos Annihilator

    Chaos Annihilator Private First Class

    I guess this computer is a little old, but it's still going so I hate to replace it. Should I stop windows updates? Unless it is updating, it works well enough for me, but if it continues to update, will it get worse?

    I thought Avast was really slowing down my computer after switching to Windows 11. I just now put it back on a few days ago, and really didn't notice it affecting the performance any. I wonder if it didn't show up though because I have it in passive mode right now so that I could do the Windows offline scan.

    Attached is the fix log. The top memory users in firefox were:
    Firefox 184MB
    GPU 135MB
    Extensions 84MB
    About Pages 42MB
    preloaded new tabs
    Data Decoder 24MB

    Is there something better to use than Firefox? Microsoft Edge really slows down my computer, even when it was Windows 10 I could hardly get it to work.

    Thanks!
     

    Attached Files:

  31. Oh My!

    Oh My! Malware Expert Staff Member

    As long as the performance is sufficient for you there is no need to replace it. I would recommend trying to keep Windows 11 updated.

    I don't think changing browsers will do much.

    If you would like, we could investigate the possibility of adding more RAM. Not sure that is possible or if RAM for that computer is available but we could look into it I guess.
     
  32. Chaos Annihilator

    Chaos Annihilator Private First Class

    No, that's okay. It's working well enough for me, as long as you don't think updating windows 11 will break it.

    Since we found no malware on this computer, do you think my USB stick is okay? I had it plugged in with all the scans I ran before asking you for help, and I specifically did a targeted Avast scan for my stick alone, and it found nothing. Do we need to do anything to it before we move on the Computer 1?

    Is it easy to spread malware from one laptop to another through your home wifi, or would it have only been possible through the USB stick?
     
  33. Chaos Annihilator

    Chaos Annihilator Private First Class

    And I'm not exactly sure what all we've done, but this computer seems to be much faster today. Thank you!
     
  34. Oh My!

    Oh My! Malware Expert Staff Member

    Malware can spread through connected network devices but I see no evidence of that. However, the historical information from Avast doesn't go back to your original concern/detection.

    I suspect your USB drive is fine but we can do one of two things. Run an ESET scan of the USB even though you already ran Avast or completely reformat the USB drive. Which would you like?
     
  35. Chaos Annihilator

    Chaos Annihilator Private First Class

    I'm not sure, what does each do?
     
  36. Chaos Annihilator

    Chaos Annihilator Private First Class

    To save me from asking stupid questions, I looked each up. It seems like an eset scan checks for viruses, and completely reformatting would wipe everything off. Is this right? If so, I'd rather not completely wipe it, and prefer to do the scan. Let me know if I have it wrong. Thanks.
     
  37. Oh My!

    Oh My! Malware Expert Staff Member

    The only reason I gave the option to reformat the USB is because of your level of concern regarding a possible virus. Personally I think running an ESET scan is sufficient, as long as that step will provide you peace of mind if nothing is found.

    Here is the ESET instructions.

    ===================================================

    ESET Online Scanner

    --------------------

    Note: You can expect this process to take a long time, up to several hours.
    • Download ESET Free Online Scanner and save it to your Desktop
    • Right click on the esetonlinescanner icon and select Run as administrator
    • Select Computer Scan
    • Click Custom Scan
    • Place a check mark in every drive you wish to scan, including any external drive you would like to scan
    • Click Save and continue
    • Select Enable ESET to detect and quarantine potentially unwanted applications
    • Click Start scan
    • Once completed click View detailed results Note: if nothing is found you may not get a report. Let me know if that happens
    • Review the list of detected items for things you don't want to remove (sometimes Potentially Unwanted Applications)
    • If there entries you would like to keep click Restore cleaned files
    • Place a check mark in each entry you would like to restore then click Restore files then confirm the action
    • Click Finish
    • Click Save scan log and save it to your Desktop as ESETScan.txt
    • Click Continue then finally click Close
    • Copy and paste the ESETScan.txt file contents in your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • ESET results
     
  38. Chaos Annihilator

    Chaos Annihilator Private First Class

    I think my level of concern is often over the top, but I figure it is better to be safe than sorry. I trust you if you think the ESET is sufficient. Since it can take several hours, I'll run it tonight and let you know what happens.
     
  39. Chaos Annihilator

    Chaos Annihilator Private First Class

    You were right, nothing was found! Here are the results:

    3/14/2026 13:32:31 PM
    Scanned files: 721341
    Detected files: 0
    Cleaned files: 0
    Total scan time: 05:55:40
    Scan status: Finished
     
  40. Oh My!

    Oh My! Malware Expert Staff Member

    Great, are we all done with this computer?
     
  41. Chaos Annihilator

    Chaos Annihilator Private First Class

    Yes! Can I delete everything we used from my desktop, or is there more to it than that? Often they don't show up in my installed apps for me to uninstall.

    Thanks for all your help, you're great!
     
  42. Oh My!

    Oh My! Malware Expert Staff Member

    You are most welcome.

    Let's take care of the cleanup on this computer with this.

    ===================================================

    KpRm by Kernel-panik

    --------------
    • Download KpRm and save it to your Desktop (see here if you must use Chrome)
    • Note: If the file is detected as malware it is not and it is safe to download. If necessary click More info then Run anyway.
    • Right click on the icon and select Run as administrator
    • Click Yes on the Disclaimer
    • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
    • Click Run
    • Click OK on All operations are completed
    • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
    • You are free to remove any other tools/reports still remaining

    When you are ready to start on Computer 1, run a new FRST scan and attach the reports to your reply.
     
    Chaos Annihilator likes this.
  43. Chaos Annihilator

    Chaos Annihilator Private First Class


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds