Farbar Recovery Scan Tool

Discussion in 'Malware Help (A Specialist Will Reply)' started by kerryh_r, Aug 13, 2026.

  1. kerryh_r

    kerryh_r Private First Class

    Based on your guide, i downloaded, installed and ran this tool. During execution, it started to download files from my personal folder. Why does it do that, and where are the files going? It seems rather dubious to me
     
  2. Oh My!

    Oh My! Malware Expert Staff Member

    FRST does not do that. It may create a randomly named temporary file that should be automatically deleted once the program has completed running.

    Can you describe what you see? It is possible that activity is related to something other than FRST.
     
    xrobwx71 likes this.
  3. kerryh_r

    kerryh_r Private First Class

    Text in the tool window clearly said it was downloading files from my personal folder that contained documents with private name, address, email and financial information. There was no detail about a specific temporary file. I stopped the process when I realised. I am loathe to retry if I am unsure where they are going
     
  4. Oh My!

    Oh My! Malware Expert Staff Member

    Are you sure you are not seeing the entries being scanned rather than downloaded? The entries roll by quite fast.
     
  5. kerryh_r

    kerryh_r Private First Class

    To be sure, I just started up in safe mode, and ran it again. There were no downloading messages from my personal folder.
    I dont know if that will impact your analysis, but attached are the two files.
    Thanks again for your assistance. Ive used your website intermittently for a long time now
     

    Attached Files:

  6. Oh My!

    Oh My! Malware Expert Staff Member

    May I ask what issue(s) caused you to post a topic?
     
  7. kerryh_r

    kerryh_r Private First Class

    I have noticed suspicious activity on my laptop, possible email hack (I’ve reset the password), and very slow laptop activity. Also Norton has identified something a couple of times.
    We’re supposed to add the 2 attachments for you guys to look at, which I have. The only other issue was this odd download activity this tool made, when executing normally. as I said, I have added the 2 attachments, which were generated after a safe mode restart
     
  8. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the additional information.

    A scan completed in Safe Mode does not provide a full picture of your system.

    Are you able to take a cellphone video of the downloading of files you see?
     
  9. kerryh_r

    kerryh_r Private First Class

    Thanks again. I have downloaded a new version of FRST via your link to Bleepimg computer, installed, and rerun in normal, not safe mode. I did not see any download messages from my personal folder this time
    Be very grateful if you could take a look at the two new attachments
     

    Attached Files:

  10. Oh My!

    Oh My! Malware Expert Staff Member

    Is this a company owned computer?
     
  11. kerryh_r

    kerryh_r Private First Class

    Interesting question. I bought it “new” around lockdown 2020 from a company in the Italian speaking part of Switzerland. When booting it I was getting some company info, but I corrected the BIOS. It’s been working fine up until recently. Apart from that, what has your analysis identified?
     
  12. Oh My!

    Oh My! Malware Expert Staff Member

    The reason why I asked is because if the computer is owned by a company we would be unable to work on it.

    I do not see any evidence of malware. The older hardware on the computer will limit how much we can expect to get out of it. Some space needs to be freed up on the hard drive (at least a total of 16GB) and there is not a lot of free memory. The processor is 8 years old and trying to run Windows 11 Pro.

    Here is what I think we should do. Run the below to clean up some things and check the overall health of the operating system. Once we are done with that we can review what is actually on the system and remove anything that is not relevant to you. As an example, I doubt you are using Citrix and it is probably a leftover from the company who sold it.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION 
    S3 avgm; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2024-03-02] (AVG Technologies USA, LLC -> AVG Technologies)
    S3 AVGSecureBrowserElevationService; C:\Program Files\AVG\Browser\Application\130.0.27176.93\elevation_service.exe [1880672 2024-11-06] (AVG Technologies USA, LLC -> Gen Digital Inc.)
    FF Plugin-x32: @update.norton.securebrowser.com/Norton Browser;version=3 -> C:\Program Files (x86)\Norton\Browser\Update\1.8.1689.6\npNortonBrowserUpdate3.dll [2024-05-14] (NortonLifeLock Inc. -> Gen Digital Inc.)
    FF Plugin-x32: @update.norton.securebrowser.com/Norton Browser;version=9 -> C:\Program Files (x86)\Norton\Browser\Update\1.8.1689.6\npNortonBrowserUpdate3.dll [2024-05-14] (NortonLifeLock Inc. -> Gen Digital Inc.)
    FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=3 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1650.5\npAvgBrowserUpdate3.dll [2024-03-02] (AVG Technologies USA, LLC -> AVG Technologies)
    FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=9 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1650.5\npAvgBrowserUpdate3.dll [2024-03-02] (AVG Technologies USA, LLC -> AVG Technologies)
    Task: {3DE1F63D-2592-471A-A507-4425DFD48E51} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => C:\Program Files\AVG\Browser\Application\AVGBrowser.exe [3171968 2024-11-06] (AVG Technologies USA, LLC -> Gen Digital Inc.)
    Task: {246C2EBC-6D7C-4799-AFA0-89B2449A1549} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => C:\Program Files\AVG\Browser\Application\AVGBrowser.exe [3171968 2024-11-06] (AVG Technologies USA, LLC -> Gen Digital Inc.)
    Task: {F33C4116-C2D5-4CD7-94B5-159D0D674CA5} - System32\Tasks\AVGBrowserProtectS-1-5-21-1344224880-3252628158-2191329646-1001 => C:\Program Files\AVG\Browser\Application\AVGBrowserProtect.exe [1690040 2024-04-29] (AVG Technologies USA, LLC -> Gen Digital Inc.)
    Task: {9A51E215-5703-4299-8218-AC2648CFBDB3} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2024-03-02] (AVG Technologies USA, LLC -> AVG Technologies)
    Task: {45CF837A-5FA2-4A3F-A6A1-E7D6258A93C9} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2024-03-02] (AVG Technologies USA, LLC -> AVG Technologies)
    HKU\S-1-5-21-1344224880-3252628158-2191329646-1001\...\MountPoints2: {c9000277-f773-11f0-9025-18cc18e76bc4} - "E:\setup.exe"
    2026-08-20 10:02 - 2022-04-19 11:39 - 000012288 ___SH C:\DumpStack.log.tmp 
    HKLM\...\Run: [deviceTRUST Client User] => "" (No File) 
    Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe  (No File) 
    Task: {D54F94D0-C38A-4093-B287-53F0B17BF327} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File) 
    Task: {1931D6A5-9F5D-4EA9-96C1-146F591843F8} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC RebootDialog (No File) 
    Task: {4DF70715-398B-410A-B483-BCB091C44B27} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery RebootDialog (No File) 
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File) 
    Winsock: Catalog5 02 %SystemRoot%\system32\pnrpnsp.dll => No File  
    Winsock: Catalog5 03 %SystemRoot%\system32\pnrpnsp.dll => No File  
    Winsock: Catalog5-x64 02 %SystemRoot%\system32\pnrpnsp.dll => No File  
    Winsock: Catalog5-x64 03 %SystemRoot%\system32\pnrpnsp.dll => No File  
    S3 Browser; %SystemRoot%\System32\browser.dll (No File) 
    U3 TrueSight; \??\C:\Windows\System32\drivers\truesight.sys (No File) 
    U3 FamilySvc; no ImagePath 
    AlternateDataStreams: C:\Users\kerry\Downloads\Kerry Passport.jpeg:3or4kl4x13tuuug3Byamue2s4b [93] 
    AlternateDataStreams: C:\Users\kerry\Downloads\Kerry Passport.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
    2023-05-22 08:32 - 2023-02-07 01:48 - 006152624 _____ (Cloud Software Group, Inc.) C:\Program Files (x86)\Cln1BB.tmp 
    2025-02-14 10:57 - 2023-08-08 01:37 - 006181712 _____ (Citrix Systems, Inc.) C:\Program Files (x86)\Cln6D21.tmp 
    Task: {068D086F-8744-4ED6-858E-E372458B4B95} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe [454656 2026-07-21] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\-Command "Start-Process -WindowStyle Hidden task.bat" 
    HKU\S-1-5-80-863171341-2975503981-1811344707-3769924460-3995132968\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4753808 2026-08-13] (Microsoft Corporation -> Microsoft Corporation) 
    AV: Kaspersky Total Security (Disabled - Out of date) {4F76F112-43EB-40E8-11D8-F7BD1853EA23}
    FW: Kaspersky Total Security (Disabled) {774D7037-0984-41B0-3A87-5E88E680AD58}
    HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION 
    HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION 
    S3 PRI-Driver; \??\C:\Windows\System32\drivers\PRI-Driver.sys (No File) 
    AlternateDataStreams: C:\MGtools.exe:MBAM.Zone.Identifier [91] 
    2026-08-14 10:41 - 2022-04-19 11:39 - 000012288 ___SH C:\DumpStack.log.tmp 
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
    C:\Firewall.reg
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: bitsadmin /reset /allusers
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • Note: This step resets your Firewall settings and you may be asked later to grant permission for legitimate programs to pass through the Firewall. If you recognize the program agree to the request.
    • WARNING Regarding the Emptytemp: command, please see here before running the Fixlist. If you have concerns stop and let me know.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds