FRST
FRST
2024
Ran by ak (administrator) on AKPC (12-07-2024 10:13:03)
Running from C:\Users\Lenovo\Downloads\FRST64.exe
Loaded Profiles: ak
Platform: Microsoft Windows 10 Pro Version 22H2 19045.4046 (X64) Language: English
(United States)
Default browser: Brave
Boot Mode: Normal
(If an entry is included in the fixlist, the process will be closed. The file will
not be moved.)
(If an entry is included in the fixlist, the registry item will be restored to
default or removed. The file will not be moved.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2617bc00-919f-4cc1-a09f-4abfb256c0cc}: [DhcpNameServer]
192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{85f57568-260a-481b-9e19-b5cdbc24e24c}: [DhcpNameServer]
192.168.1.1
Tcpip\..\Interfaces\{9aec1fa6-f19e-400e-a531-f900fde3dcab}: [DhcpNameServer]
192.168.1.1
Edge:
=======
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2024-
07-10]
Edge HomePage: Default -> hxxps://go.microsoft.com/fwlink/p/?
LinkId=619797&pc=UE01&ocid=UE01DHP
Edge Extension: (Grammarly: AI Writing and Grammar Checker App) - C:\Users\Lenovo\
AppData\Local\Microsoft\Edge\User Data\Default\Extensions\
cnlefmmeadmemmdciolhbnfeacpdfbkd [2024-07-05]
Edge Extension: (Google Docs Offline) - C:\Users\Lenovo\AppData\Local\Microsoft\
Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-02]
Edge Extension: (Edge relevant text changes) - C:\Users\Lenovo\AppData\Local\
Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-
01-23]
Edge Extension: (AdBlock — block ads across the web) - C:\Users\Lenovo\AppData\
Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog
[2024-06-27]
Edge HKU\S-1-5-21-2651249374-2078848904-2009966195-1001\SOFTWARE\Microsoft\Edge\
Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program
Files (x86)\Internet Download Manager\IDMEdgeExt.crx <not found>
FireFox:
========
FF DefaultProfile: q0x637k0.default-1697090705961
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\
q0x637k0.default-1697090705961 [2023-10-12]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\
Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\
SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF HKU\S-1-5-21-2651249374-2078848904-2009966195-1001\...\SeaMonkey\Extensions:
[[email protected]] - C:\Users\Lenovo\AppData\Roaming\IDM\
idmmzcc5
FF Extension: (IDM CC) - C:\Users\Lenovo\AppData\Roaming\IDM\idmmzcc5 [2021-10-19]
[Legacy] [not signed]
FF HKU\S-1-5-21-2651249374-2078848904-2009966195-1001\...\SeaMonkey\Extensions:
[[email protected]] - C:\Program Files (x86)\Internet
Download Manager\idmmzcc2.xpi => not found
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MIF5BA~1\
Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft
Office\root\Office16\NPSPWRAP.DLL [2024-06-28] (Microsoft Corporation -> Microsoft
Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\
OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF
Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\
Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF
Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\
Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\
Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft
Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-06-28]
(Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\
VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\
VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default [2024-
07-09]
CHR Session Restore: Default -> is enabled.
CHR Extension: (Delete Browsing History) - C:\Users\Lenovo\AppData\Local\Google\
Chrome\User Data\Default\Extensions\ehopggpdjobkakeanhlpiillmocedild [2024-03-20]
CHR Extension: (Google Docs Offline) - C:\Users\Lenovo\AppData\Local\Google\Chrome\
User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-04]
CHR Extension: (Clear Today's History and Cache) - C:\Users\Lenovo\AppData\Local\
Google\Chrome\User Data\Default\Extensions\nkcpfldfdhdkdgogfcnnpfnoilkanemk [2024-
03-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Lenovo\AppData\Local\Google\
Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-20]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program
Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-2651249374-2078848904-2009966195-1001\SOFTWARE\Google\Chrome\
Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-2651249374-2078848904-2009966195-1001\SOFTWARE\Google\Chrome\
Extensions\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program
Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program
Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
Brave:
=======
BRA Profile: C:\Users\Lenovo\AppData\Local\BraveSoftware\Brave-Browser\User Data\
Default [2024-07-12]
BRA Notifications: Default -> hxxps://ext.gmass.us
BRA StartupUrls: Default -> "hxxp://www.gmail.com/"
BRA DefaultSearchKeyword: Default -> :g
BRA Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Lenovo\
AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\
efaidnbmnnnibpcajpcglclefindmkaj [2024-07-05]
BRA Extension: (Black & White) - C:\Users\Lenovo\AppData\Local\BraveSoftware\Brave-
Browser\User Data\Default\Extensions\mhhlgkfginnlendpfkhcmldikeepoefa [2024-03-11]
BRA Extension: (Brave Ad Block Updater (Brave Ad Block First Party Filters
(plaintext))) - C:\Users\Lenovo\AppData\Local\BraveSoftware\Brave-Browser\User
Data\adcocjohghhfpidemphmcmlmhnfgikei [2024-07-10]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\Lenovo\AppData\Local\
BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2024-07-12]
BRA Extension: (Brave NTP background images) - C:\Users\Lenovo\AppData\Local\
BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2024-02-05]
BRA Extension: (Brave Ad Block Updater (Fanboy's Mobile Notifications (plaintext)))
- C:\Users\Lenovo\AppData\Local\BraveSoftware\Brave-Browser\User Data\
bfpgedeaaibpoidldhjcknekahbikncb [2024-07-12]
BRA Extension: (Wallet Data Files Updater) - C:\Users\Lenovo\AppData\Local\
BraveSoftware\Brave-Browser\User Data\BraveWallet [2024-01-24]
BRA Extension: (Brave Ad Block Updater (EasyList Cookie (plaintext))) - C:\Users\
Lenovo\AppData\Local\BraveSoftware\Brave-Browser\User Data\
cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2024-07-12]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\Lenovo\AppData\
Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2024-
06-24]
BRA Extension: (Brave NTP sponsored images) - C:\Users\Lenovo\AppData\Local\
BraveSoftware\Brave-Browser\User Data\gccbbckogglekeggclmmekihdgdpdgoe [2024-07-12]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\Lenovo\
AppData\Local\BraveSoftware\Brave-Browser\User Data\
gkboaolpopklhgplhaaiboijnklogmbc [2024-07-10]
BRA Extension: (Brave NTP Super Referrer mapping table) - C:\Users\Lenovo\AppData\
Local\BraveSoftware\Brave-Browser\User Data\heplpbhjcbmiibdlchlanmdenffpiibo [2023-
10-12]
BRA Extension: (Brave Ads Resources) - C:\Users\Lenovo\AppData\Local\BraveSoftware\
Brave-Browser\User Data\iblokdlgekdjophgeonmanpnjihcjkjj [2024-06-26]
BRA Extension: (Brave Ad Block Updater (Brave Ad Block Updater (plaintext))) - C:\
Users\Lenovo\AppData\Local\BraveSoftware\Brave-Browser\User Data\
iodkpdagapdfkphljnddpjlldadblomo [2024-07-12]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\Lenovo\AppData\
Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2024-
07-09]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\Lenovo\AppData\Local\
BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2023-10-25]
Vivaldi:
=======
VIV Profile: C:\Users\Lenovo\AppData\Local\Vivaldi\User Data\Default [2024-07-11]
VIV HomePage: Default -> hxxps://www.google.com/
VIV StartupUrls: Default -> "hxxps://www.google.com/"
VIV Extension: (Torrent Scanner) - C:\Users\Lenovo\AppData\Local\Vivaldi\User Data\
Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2024-06-06]
VIV Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Lenovo\
AppData\Local\Vivaldi\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj
[2024-07-09]
StartMenuInternet: (HKU\S-1-5-21-2651249374-2078848904-2009966195-1001)
Vivaldi.XN22U77HZROU4WMOBRHKUVC7K4 - "C:\Users\Lenovo\AppData\Local\Vivaldi\
Application\vivaldi.exe"
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
S3 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [5323592 2024-04-18]
(AnyDesk Software GmbH -> AnyDesk Software GmbH)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [175424 2023-
10-12] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 BraveElevationService; C:\Program Files\BraveSoftware\Brave-Browser\Application\
126.1.67.123\elevation_service.exe [2688024 2024-06-25] (Brave Software, Inc. ->
Brave Software, Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [175424
2023-10-12] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\
OfficeClickToRun.exe [9680472 2018-09-26] (Microsoft Corporation -> Microsoft
Corporation)
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\
HPLaserJetService.exe [136192 2009-10-15] (HP) [File not signed]
R2 HPM1210RcvFaxSrvc; C:\Program Files\HP\HP LaserJet M1210 MFP Series\
ReceiveFaxUtility.exe [361888 2012-07-25] (Hewlett-Packard Company -> HP)
R2 HPSIService; C:\WINDOWS\system32\HPSIsvc.exe [126856 2012-11-08] (Hewlett-
Packard Company -> HP)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\
MpDefenderCoreService.exe [1505416 2024-06-04] (Microsoft Windows Publisher ->
Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe
[534472 2024-03-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [21585720 2024-
03-18] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\
NisSrv.exe [3236728 2024-06-04] (Microsoft Windows Publisher -> Microsoft
Corporation)
R2 WifiAutoInstallSrv; C:\Program Files\EZCast\WifiAutoInstall\
WifiAutoInstallSrv.exe [118720 2019-03-21] (Realtek Semiconductor Corp. -> Realtek)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\
MsMpEng.exe [133704 2024-06-04] (Microsoft Windows Publisher -> Microsoft
Corporation)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)