Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 11-10-2020 Gestart door lenovo (Beheerder) op DESKTOP-H2EJPNK (LENOVO 4480B2G) (14-10-2020 11:32:10) Gestart vanaf C:\Users\lenovo\Desktop Geladen Profielen: lenovo Platform: Windows 10 Pro Versie 2004 19041.508 (X64) Taal: Nederlands (Nederland) Standaardbrowser: Chrome Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, zal het proces worden gesloten. Het bestand zal niet worden verplaatst.) (Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3> (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\107.4.443\QtWebEngineProcess.exe <2> (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Safe Online\fshoster32.exe <3> (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Safe Online\Ultralight\ulcore\1602225647\fshoster64.exe <2> (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Safe Online\Ultralight\ulcore\1602225647\fsorsp64.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Safe Online\Ultralight\ulcore\1602225647\FsPisces.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Safe Online\Ultralight\ulcore\1602225647\fsulprothoster.exe (Gadwin, Ltd. -> Gadwin Systems, Inc) C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <11> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\commsapps.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12010.1001.2.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\NisSrv.exe (Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe (Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe ==================== Register (gefilterd) =================== (Als een item is opgenomen in de fixlist, zal het registeritem worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe" HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [7929856 2020-10-06] (Dropbox, Inc -> Dropbox, Inc.) HKU\S-1-5-21-3808283307-1243482618-78075021-1001\...\Run: [Gadwin PrintScreen] => C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe [1842384 2012-05-30] (Gadwin, Ltd. -> Gadwin Systems, Inc) HKU\S-1-5-21-3808283307-1243482618-78075021-1001\...\Run: [CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [144008 2019-10-22] (Adobe Inc. -> Adobe Systems Incorporated) HKU\S-1-5-21-3808283307-1243482618-78075021-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [30870200 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-3808283307-1243482618-78075021-1001\...\Run: [Opera Browser Assistant] => C:\Users\lenovo\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3085336 2020-10-06] (Opera Software AS -> Opera Software) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.121\Installer\chrmstp.exe [2020-09-23] (Google LLC -> Google LLC) ==================== Geplande Taken (gefilterd) ============ (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) Task: {04035174-0F32-4BBD-9BAB-7FFFF89606B2} - System32\Tasks\Opera scheduled assistant Autoupdate 1581137829 => C:\Users\lenovo\AppData\Local\Programs\Opera\launcher.exe [1712152 2020-10-06] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\lenovo\AppData\Local\Programs\Opera\assistant" $(Arg0) Task: {241E7B4D-8C95-4782-A892-A2DF502385BB} - System32\Tasks\F-Secure\F-Secure Hotfix => C:\Program Files (x86)\Safe Online\fs_hotfix.exe [293248 2020-08-03] (F-Secure Corporation -> F-Secure Corporation) Task: {2575C68E-DB49-4DF7-90A4-43C12E46AED5} - System32\Tasks\Opera scheduled Autoupdate 1584812392 => C:\Users\lenovo\AppData\Local\Programs\Opera\launcher.exe [1712152 2020-10-06] (Opera Software AS -> Opera Software) Task: {2A281643-102E-4198-9BB8-3A33E17B3962} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd) Task: {2AE2688A-A2AF-4348-BDE2-4717261C9A70} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-06-16] (Dropbox, Inc -> Dropbox, Inc.) Task: {460BC576-1CF1-41AB-ABD1-7BA235FE59B6} - System32\Tasks\Opera scheduled Autoupdate 1560681574 => C:\Users\lenovo\AppData\Local\Programs\Opera\launcher.exe [1712152 2020-10-06] (Opera Software AS -> Opera Software) Task: {572C93CE-3430-4D43-A7E3-2137363AEE4A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {6C1A9F69-E2D5-4209-BF93-35671C5CE18D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-06-16] (Google Inc -> Google LLC) Task: {8DCDE83B-6859-4AEA-ADA0-2928BA9442CE} - System32\Tasks\FreedomeReset => C:\Program Files (x86)\F-Secure\Freedome\Freset.exe Task: {8FB2C648-28AD-4062-8640-D6EA6A650535} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A8A1CC23-5ABD-41D0-8577-D8EEE153DD0B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {CA89EC08-567E-487C-A9AE-465725EA8303} - System32\Tasks\Agent Activation Runtime\S-1-5-21-3808283307-1243482618-78075021-1001 => C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe [13312 2020-06-10] (Microsoft Windows -> ) Task: {E580E016-25AD-4F4F-ACFF-C3D6E9CDD8A7} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\lenovo\Documents\esetonlinescanner_nld.exe Task: {E85A6617-E599-414B-B933-E65CF2572EE5} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\lenovo\Documents\esetonlinescanner_nld.exe Task: {EE0F70D7-0D88-4FF0-B259-0DCF29A88E5C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [25492152 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd) Task: {F0E3F5E6-D82B-4527-ADED-5F379FDE4500} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F8DC90D6-C5E3-4537-B7A5-367AF0CAE72C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-06-16] (Dropbox, Inc -> Dropbox, Inc.) Task: {F9928937-6C4D-4314-8563-055D2B720D13} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-06-16] (Google Inc -> Google LLC) (Als een item is opgenomen in de fixlist, wordt de taak (job) bestand verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist en een registeritem is, wordt het verwijderd of hersteld naar de standaard.) Hosts: Er is meer dan één item in Hosts. Zie Hosts deel van Addition.txt Tcpip\Parameters: [DhcpNameServer] 84.116.46.22 84.116.46.23 Tcpip\..\Interfaces\{ae9af8b6-7675-4463-a24c-21cddb475ef9}: [DhcpNameServer] 84.116.46.22 84.116.46.23 Edge: ====== DownloadDir: C:\Users\lenovo\Downloads Edge Extension: (AdBlock — best ad blocker) -> EdgeExtension_BetaFishAdBlock_c1wakc4j0nefm => C:\Program Files\WindowsApps\BetaFish.AdBlock_2.13.0.0_neutral__c1wakc4j0nefm [2020-03-04] Edge DefaultProfile: Default Edge Profile: C:\Users\lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2020-10-13] Edge HomePage: Default -> hxxp://pspismagic.jouwpagina.nl/ Edge StartupUrls: Default -> "hxxp://pspismagic.jouwpagina.nl/" Edge Extension: (Browsing Protection by F-Secure) - C:\Users\lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2020-10-05] Edge Extension: (Google Mail Checker) - C:\Users\lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2020-05-02] Edge Extension: (AdBlock - de beste advertentieblokker) - C:\Users\lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2020-10-09] Edge Extension: (I don’t care about cookies) - C:\Users\lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oholpbloipjbbhlhohaebmieiiieioal [2020-10-05] Edge HKLM\...\Edge\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] Edge HKLM-x32\...\Edge\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default [2020-10-14] CHR Notifications: Default -> hxxps://mono5.biz CHR HomePage: Default -> hxxp://pspismagic.jouwpagina.nl/ CHR StartupUrls: Default -> "hxxp://pspismagic.jouwpagina.nl/" CHR Extension: (Presentaties) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-06-25] CHR Extension: (Documenten) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-06-25] CHR Extension: (Google Drive) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-06-25] CHR Extension: (ColorZilla) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhlhnicpbhignbdhedgjhgdocnmhomnp [2019-11-01] CHR Extension: (YouTube) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-06-25] CHR Extension: (Adblock Plus - gratis adblocker) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-09-10] CHR Extension: (Spreadsheets) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-06-25] CHR Extension: (I don’t care about cookies) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2020-09-30] CHR Extension: (Offline Documenten) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-09-17] CHR Extension: (IE Tab) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2020-10-14] CHR Extension: (Browsing Protection by F-Secure) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2020-10-06] CHR Extension: (Google Mail Checker) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2020-03-04] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04] CHR Extension: (Gmail) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-25] CHR Extension: (Chrome Media Router) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-08-27] CHR Profile: C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-10-13] CHR Profile: C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-10-14] CHR Extension: (Presentaties) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-23] CHR Extension: (Documenten) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-23] CHR Extension: (Moonlit Reflection) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apakhamomlpjegjclmgimiapigoeoglb [2020-06-10] CHR Extension: (Google Drive) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-23] CHR Extension: (YouTube) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-23] CHR Extension: (Muis rechts klikken inschakelen) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bofdamlbkfkjnecfjbhpncokfalmmbii [2020-09-05] CHR Extension: (Adblock Plus - gratis adblocker) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-09-10] CHR Extension: (Spreadsheets) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-23] CHR Extension: (I don’t care about cookies) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2020-10-01] CHR Extension: (Offline Documenten) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-09-16] CHR Extension: (Browsing Protection by F-Secure) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2020-10-06] CHR Extension: (Google Mail Checker) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2020-04-23] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-23] CHR Extension: (Gmail) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-23] CHR Extension: (Chrome Media Router) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-08-27] CHR Profile: C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\System Profile [2020-10-13] CHR HKLM\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] Opera: ======= OPR Extension: (Notifier for Gmail™) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\flkijckbigolpahbkklilflpmkalfohc [2019-06-25] OPR Extension: (I don't care about cookies) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\iambaeepkgdclnmbfdnnohkjjpdglbeo [2020-10-13] OPR Extension: (Close & Clean) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\lgnmpbijlfdkoindhleemckiandljdah [2019-12-28] OPR Extension: (Google Translate) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\mchdgimobfnilobnllpdnompfjkkfdmi [2020-08-27]