View Single Post
  #3  
Old January 11th, 2021, 04:17 PM
Han Solo Han Solo is offline
Senior Member
 
Join Date: Jun 2005
Posts: 134
Hi olgun52, thank you for taking a look and helping me

here are the two files. I didn't click on any additional options


First:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-01-2021
Ran by Hans (administrator) on PC (Dell Inc. Inspiron 620) (11-01-2021 09:46:33)
Running from C:\Users\Hans\Desktop
Loaded Profiles: Hans
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Safe Mode (with Networking)

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <59>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Nir Sofer -> NirSoft) C:\Users\Hans\Downloads\New Downloads\Now\bluescreenview\BlueScreenView.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2055016 2011-04-29] (Unlimited Realities -> )
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2782096 2010-07-25] (Canon Inc. -> CANON INC.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc)
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1519312 2017-06-25] (Open Source Developer, Phillip Gibbons -> Highresolution Enterprises)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions -> Sonic Solutions)
HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [885760 2011-04-29] () [File not signed]
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1213848 2010-09-14] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-11-17] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft, Inc. -> ArcSoft Inc.)
HKLM-x32\...\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Symantec Corporation -> Dell, Inc.)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] (Sonic Solutions -> )
HKLM-x32\...\Run: [SilentCleanService] => C:\Program Files (x86)\iMobie\AnyTrans\${CHECK_RUNSERVICE_NAME}
HKU\S-1-5-21-4200521874-2590480824-2585516950-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-11-17] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-4200521874-2590480824-2585516950-1000\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [24283120 2020-01-23] (Plex, Inc. -> Plex, Inc.)
HKU\S-1-5-21-4200521874-2590480824-2585516950-1000\...\Run: [ProtonVPN] => C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.exe [7452480 2020-10-06] (ProtonVPN AG -> )
HKU\S-1-5-21-4200521874-2590480824-2585516950-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_ 0_0_465_Plugin.exe [1504312 2020-12-08] (Adobe Inc. -> Adobe)
HKU\S-1-5-18\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [24283120 2020-01-23] (Plex, Inc. -> Plex, Inc.)
HKLM\...\Windows x64\Print Processors\Canon MX880 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDAN.DLL [30208 2012-03-14] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon BJ FAX Language Monitor MX880 series: C:\Windows\system32\CNCALAN.DLL [302080 2010-11-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MX880 series: C:\Windows\system32\CNMLMAN.DLL [385024 2012-03-14] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\system32\CNMN6PPM.DLL [328192 2010-09-08] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.88\Insta ller\chrmstp.exe [2020-12-02] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Insta ller\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2020-05-03] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk [2012-04-01]
ShortcutTarget: Kodak EasyShare software.lnk -> C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2012-09-02]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia -> Secunia)
GroupPolicy: Restriction - Chrome <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0110782D-8874-4428-9253-0FC0001794D1} - System32\Tasks\NWC => C:\Program Files (x86)\ASCOMP Software\Synchredible\nwc.exe [332288 2014-09-30] () [File not signed]
Task: {0D0524A3-E68F-41E8-B8A2-324632A5A01A} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {49A214E5-828F-47E3-9685-505850C22A4B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [3545880 2013-04-23] (Piriform Ltd -> Piriform Ltd)
Task: {4F723766-9267-4A0F-9E80-D4E473128B8D} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1491664 2013-05-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {55C3090F-E86F-4E6C-A6B8-5D233BA03727} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {6E62607A-A35F-40C0-8F80-E2C36B212A02} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyb oardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2179792 2013-05-13] (Microsoft Corporation -> Microsoft)
Task: {6E8648CE-0E52-48D2-851F-17A79C334E78} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe
Task: {776D0E2E-4453-445C-9DAF-D36387F055DC} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe
Task: {77CCD346-000C-4879-AD86-4593016FA8D7} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2108624 2013-05-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {7AC189AF-7198-46AE-AAC5-C9E80539CC24} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-19] (Google Inc -> Google Inc.)
Task: {8104CE8F-1675-47ED-85F8-1C7A7ABC903C} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1491664 2013-05-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {8331C3DD-5990-4F43-8B2C-2CB9B6765CA2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {A2080677-F342-4763-97C0-B18542DEE646} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_ 0_0_465_Plugin.exe [1504312 2020-12-08] (Adobe Inc. -> Adobe)
Task: {B06D5F00-8C5D-4EF5-BD3B-97D1AF788933} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [410784 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {B7B8E81D-307B-4C1F-9CF8-633D619CFA41} - System32\Tasks\{F4F46FA1-7FD6-4681-A330-8AD497C43C02} => C:\Windows\system32\pcalua.exe -a "C:\Users\Hans\AppData\Local\Microsoft\Windows\Tem porary Internet Files\Content.IE5\5XOIFA2S\WBSP_IE_Setup.exe" -d C:\Users\Hans\Desktop
Task: {BEBA5329-B275-46AA-9B33-842800D3B30A} - System32\Tasks\Microsoft_Hardware_Launch_rundll32_ exe => rundll32.exe url.dll,OpenURL http://go.microsoft.com/fwlink/?LinkID=230628
Task: {D788AB35-C928-481C-AE04-49F6A2E2CD42} - System32\Tasks\{FCEF3078-6348-4EF2-A133-EA5922813B83} => C:\Windows\system32\pcalua.exe -a C:\Users\Hans\Downloads\WBSP_IE_Setup.exe -d C:\Users\Hans\Desktop
Task: {DA526EE1-9119-49D3-A2EB-D46AC198046E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe)
Task: {DDD9C578-3B5F-4035-99FD-B3C48CC2126D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-19] (Google Inc -> Google Inc.)
Task: {E4F6B829-35D7-4354-9AA1-B10A7AC332F3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [569416 2016-02-23] (Apple Inc. -> Apple Inc.)
Task: {EC0AC83F-1CB1-4464-A104-888B1807169E} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_ex e => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2108624 2013-05-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {EEE16815-66A5-4908-BAEB-30D61334AE14} - System32\Tasks\{E22B9F1E-B872-4306-8F1C-2D709707F048} => C:\Windows\system32\pcalua.exe -a "C:\Users\Hans\AppData\Local\Microsoft\Windows\Tem porary Internet Files\Content.IE5\MQ3KEK3B\PCHCInstallerPackage.ex e" -d C:\Users\Hans\Desktop
Task: {EEEAA326-2308-475C-99AF-BABE00811BD0} - System32\Tasks\{1D7851FC-923C-4BF0-9EF7-98C14DFD5E08} => C:\Windows\system32\pcalua.exe -a "C:\Users\Hans\Downloads\Shockwave_Installer_S lim 11.6.1.629.exe" -d C:\Users\Hans\Downloads
Task: {F15BA0EF-5B72-42B2-B343-928E8E85294F} - System32\Tasks\ProtonVPN Update => C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe [61760 2020-10-06] (ProtonVPN AG -> )

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\..\Interfaces\{66647859-4A98-410D-A6EA-64B8B46ABB45}: [NameServer] 209.18.47.61,209.18.47.62
Tcpip\..\Interfaces\{7E5C2F57-B30D-4B48-80C9-D5628F55B906}: [DhcpNameServer] 10.80.0.1
HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,192.168.0.1,-1]

FireFox:
========
FF ProfilePath: C:\Users\Hans\AppData\Roaming\Mozilla\Firefox\Prof iles\mwg4kyqa.default [2020-04-12]
FF Extension: (HydraReader Class) - C:\Users\Hans\AppData\Roaming\Mozilla\Firefox\Prof iles\mwg4kyqa.default\Extensions\{37D4A353-C49B-8A56-4230-FE2A6C825946} [2014-11-06] [Legacy] [not signed]
FF Extension: (WOT) - C:\Users\Hans\AppData\Roaming\Mozilla\Firefox\Prof iles\mwg4kyqa.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-11-02] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_ 465.dll [2020-12-08] (Adobe Inc. -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_ 465.dll [2020-12-08] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2013-06-26] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-14] (CANON INC.) [File not signed]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2013-04-02] (Google Inc. -> Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN -> VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp .dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-12-07] (Adobe Inc. -> Adobe Systems Inc.)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default [2021-01-11]
CHR DownloadDir: N:\
CHR StartupUrls: Default -> "hxxps://www.google.com/?gws_rd=ssl"
CHR DefaultSearchURL: Default -> hxxps://vortex.accuweather.com/adc2010/images/favicons/awx-2013-master.ico
CHR Extension: (Slides) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhon fmgoek [2017-10-17]
CHR Extension: (Sparta: War of Empires) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\agcokacflmihcgkgjofglkhobj kheeic [2016-01-16]
CHR Extension: (Docs) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfi lokake [2017-10-17]
CHR Extension: (Google Drive) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigk jlhalf [2020-10-30]
CHR Extension: (WOT Web of Trust, Website Reputation Ratings) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp [2021-01-10]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkop ceiche [2020-10-18]
CHR Extension: (YouTube) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldk acnbeo [2015-12-19]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddi lifddb [2020-12-24]
CHR Extension: (OneTab) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkd nihall [2020-09-21]
CHR Extension: (uBlock Origin) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm [2021-01-11]
CHR Extension: (Google Search) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljnie djpjpf [2015-12-19]
CHR Extension: (Tab Restore) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbndgjfafojhfndfgpcibceghe lbbnep [2018-02-04]
CHR Extension: (Session Buddy) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbc dcpbko [2020-05-13]
CHR Extension: (Recent History) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbmkfdfomhhlonpbnpiibloace mdhjjm [2019-12-23]
CHR Extension: (Sheets) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpeb giejap [2017-10-17]
CHR Extension: (History Button) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\fofpnhmbgmmeaialapfddhbhfo ngoinh [2018-02-04]
CHR Extension: (2nd Toolbar Spacer) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplioachhfdbehddoehahffjbc feinid [2018-02-04]
CHR Extension: (Fair Ads) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\gagfkmknmijppikpcikmbbkdkh ggcmge [2017-05-29]
CHR Extension: (Google Docs Offline) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdl olhkhi [2020-11-27]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbi glidom [2020-12-25]
CHR Extension: (VPN Free - Betternet Unlimited VPN Proxy) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjknjjomckknofjidppipffbpo ekiipm [2020-10-18]
CHR Extension: (Hola Free VPN Proxy Unblocker - Best VPN) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfb nlmeio [2021-01-06]
CHR Extension: (Toolbar Spacer) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\golladjmjodbefcoombodcdhim kmgemd [2018-02-04]
CHR Extension: (Windscribe - Free Proxy and Ad Blocker) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpcagpplmpfojmgmnngilcna nddlhb [2021-01-06]
CHR Extension: (Open in VLC™ media player) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihpiinojhnfhpdmmacgmpoonph himkaj [2021-01-01]
CHR Extension: (Recently Closed) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\khiocfdofmabcpofejbffpboco abcjib [2020-07-24]
CHR Extension: (Zoom for Google Chrome) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\lajondecmobodlejlcjllhojik agldgd [2020-08-13]
CHR Extension: (Fair AdBlocker) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgblnfidahcdcjddiepkckcfdh pknnjh [2020-10-18]
CHR Extension: (Extensions) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjcdccmhfohhffdhmleihkcge fgnghb [2020-05-13]
CHR Extension: (Oriental, NC Interactive Weather Rada...) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbkkhmpidoemedicppkhfklljp pccaan [2018-01-29]
CHR Extension: (Free VPN Proxy Unlimited VPN) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\mojliakllambnopeaalgddbiip ohdgol [2020-12-16]
CHR Extension: (Hotspot Shield Free VPN Proxy - Unlimited VPN) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbejmccbhkncgokjcmghpfloa ajcffj [2020-10-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2019-10-14]
CHR Extension: (Weather Forecast) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofobaelkgcpicbdoabokjlnmdc bjellg [2020-06-13]
CHR Extension: (Bookmarks) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogpfecfneobbmjefimpeomoelo ahjmcm [2019-10-31]
CHR Extension: (AdBlocker Ultimate) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohahllgiabjaoigichmmfljhkc fikeof [2020-12-09]
CHR Extension: (TunnelBear VPN) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdakjcmkglenbhjadbccaookp fjihpa [2021-01-06]
CHR Extension: (Browsec VPN - Free VPN for Chrome) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\omghfjlpggmjjaagoclmmobgdo dcjboh [2021-01-06]
CHR Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\oofgbpoabipfcfjapgnbbjjaen ockbdp [2020-10-18]
CHR Extension: (uBlock Plus Adblocker) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\oofnbdifeelbaidfgpikinijek kjcicg [2018-02-06]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjp fogcam [2020-12-25]
CHR Extension: (VLC Video Downloader) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\pggkpkppiimfmjhlnkdhaleiom ejgedd [2018-12-21]
CHR Extension: (Gmail) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoe jaedia [2020-10-30]
CHR Extension: (Chrome Media Router) - C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm [2020-12-14]
CHR Profile: C:\Users\Hans\AppData\Local\Google\Chrome\User Data\System Profile [2019-05-24]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft, Inc. -> ArcSoft Inc.)
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc. -> Apple Inc.)
S2 GenieTimelineService; C:\Program Files\NETGEAR\ReadySHARE Vault\GenieTimelineService.exe [671744 2016-12-18] (Genie9) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S2 NOBU; C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2823000 2010-08-25] (Symantec Corporation -> Dell, Inc.)
S2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [2136056 2020-01-23] (Plex, Inc. -> Plex, Inc.)
S3 ProtonVPN Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe [99136 2020-10-06] (ProtonVPN AG -> )
S3 ProtonVPN Update Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe [61760 2020-10-06] (ProtonVPN AG -> )
S2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1326176 2012-07-25] (Secunia -> Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [681056 2012-07-25] (Secunia -> Secunia)
S2 SftService; C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE [1695040 2012-02-16] (Dell Inc -> SoftThinks SAS)
S2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [253912 2019-10-30] (Synology Inc. -> )
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R3 busenum; C:\Windows\System32\DRIVERS\busenum.sys [55776 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
S3 ProtonVPNSplitTunnel; C:\Program Files (x86)\Proton Technologies\ProtonVPN\x64\Win7\ProtonVPN.SplitTun nelDriver.sys [22456 2020-08-19] (ProtonVPN AG -> Proton Technologies AG)
R3 tapprotonvpn; C:\Windows\System32\DRIVERS\tapprotonvpn.sys [39864 2020-08-19] (ProtonVPN AG -> The OpenVPN Project)
R3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64.sys [23200 2015-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
S3 MpKsl323b3910; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BFC668F6-368B-4AB5-8795-4CA4B6CACD86}\MpKslDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-01-11 09:46 - 2021-01-11 09:47 - 000028162 _____ C:\Users\Hans\Desktop\FRST.txt
2021-01-10 18:07 - 2021-01-10 18:07 - 002281472 _____ (Farbar) C:\Users\Hans\Desktop\FRST64.exe
2021-01-06 15:20 - 2021-01-06 15:20 - 000278504 _____ C:\Windows\Minidump\010621-23337-01.dmp
2021-01-06 14:50 - 2021-01-09 12:39 - 000097272 _____ C:\Windows\ntbtlog.txt
2021-01-06 14:50 - 2021-01-06 14:50 - 000278504 _____ C:\Windows\Minidump\010621-24133-01.dmp
2021-01-06 14:49 - 2021-01-06 14:49 - 000278504 _____ C:\Windows\Minidump\010621-19125-01.dmp
2021-01-06 14:47 - 2021-01-06 14:47 - 000278560 _____ C:\Windows\Minidump\010621-23306-01.dmp
2020-12-31 12:49 - 2020-12-31 12:49 - 000001194 _____ C:\Users\Public\Desktop\Synology Assistant.lnk
2020-12-31 12:49 - 2020-12-31 12:49 - 000001194 _____ C:\ProgramData\Desktop\Synology Assistant.lnk
2020-12-31 12:49 - 2020-12-31 12:49 - 000000000 ____D C:\ProgramData\Synology
2020-12-31 12:49 - 2020-12-31 12:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Synology
2020-12-31 11:46 - 2020-12-31 12:49 - 000000000 ____D C:\Program Files (x86)\Synology

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-01-11 09:46 - 2014-11-20 18:54 - 000000000 ____D C:\FRST
2021-01-11 09:44 - 2015-01-07 18:26 - 000000000 ____D C:\Users\Hans\Documents\New Stuff
2021-01-09 12:40 - 2009-07-14 00:13 - 000783424 _____ C:\Windows\system32\PerfStringBackup.INI
2021-01-09 12:40 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2021-01-06 15:20 - 2020-09-21 19:04 - 444147567 _____ C:\Windows\MEMORY.DMP
2021-01-06 15:20 - 2015-11-05 09:22 - 000000000 ____D C:\Windows\Minidump
2021-01-06 15:19 - 2012-09-12 15:47 - 000000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2021-01-06 15:19 - 2011-08-17 20:36 - 000000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2021-01-06 15:19 - 2011-08-17 20:36 - 000000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2021-01-06 15:18 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-01-06 15:05 - 2011-12-26 14:34 - 000000000 ____D C:\Users\Hans\AppData\Local\ElevatedDiagnostics
2021-01-06 02:04 - 2018-02-03 21:46 - 000000000 ____D C:\Users\Hans\AppData\Roaming\vlc
2021-01-03 20:21 - 2009-07-13 23:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2021-01-03 20:21 - 2009-07-13 23:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2021-01-02 18:58 - 2014-11-07 01:30 - 000000000 ____D C:\Users\Hans\Downloads\New Downloads
2020-12-31 12:18 - 2019-08-17 18:01 - 000000000 ____D C:\Users\Hans\AppData\Local\Plex Media Server
2020-12-24 17:44 - 2011-12-26 15:18 - 000000000 ____D C:\Users\Hans\AppData\Roaming\SoftGrid Client
2020-12-19 15:24 - 2011-12-26 10:20 - 000075248 _____ C:\Users\Hans\AppData\Local\GDIPFONTCACHEV1.DAT
2020-12-16 22:31 - 2009-07-14 00:08 - 000032634 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2020-12-13 08:22 - 2016-06-08 17:50 - 000002089 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk

==================== Files in the root of some directories ========

2014-11-12 17:42 - 2014-11-12 17:42 - 000000272 _____ () C:\Users\Hans\AppData\Roaming\DECRYPT_INSTRUCTION. URL
2014-11-12 17:41 - 2014-11-12 17:41 - 000000272 _____ () C:\Users\Hans\AppData\Roaming\Microsoft\DECRYPT_IN STRUCTION.URL
2012-12-13 07:48 - 2019-12-15 17:14 - 000164864 _____ () C:\Users\Hans\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-12 17:39 - 2014-11-12 17:39 - 000000272 _____ () C:\Users\Hans\AppData\Local\DECRYPT_INSTRUCTION.UR L
2012-04-01 19:23 - 2012-04-01 19:23 - 000000022 _____ () C:\Users\Hans\AppData\Local\kodakpcd.ini
2012-01-09 11:17 - 2020-06-09 19:57 - 000007613 _____ () C:\Users\Hans\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2020-12-23 00:39
==================== End of FRST.txt ========================
Reply With Quote