Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2021 Ran by Admin (administrator) on PINKYPC (Acer Aspire E5-573) (14-03-2021 15:14:15) Running from D:\Users\Hari\Desktop Loaded Profiles: Admin Platform: Windows 10 Pro Version 2004 19041.508 (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\avp.exe (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\avpui.exe (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\plugins_nms.exe (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksde.exe (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksdeui.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe <2> (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <9> (philandro Software GmbH -> philandro Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14049536 2015-07-09] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-3076391084-2480122960-4283986350-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32726088 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-3076391084-2480122960-4283986350-1002\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [659976 2020-08-24] (Kaspersky Lab -> AO Kaspersky Lab) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\89.0.4389.82\Installer\chrmstp.exe [2021-03-07] (Google LLC -> Google LLC) Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kaspersky Internet Security.lnk [2020-09-23] ShortcutTarget: Kaspersky Internet Security.lnk -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 20.0\avpui.exe (No File) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2020-09-23] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {23BB1C95-11C8-4569-86B0-E37C0807DC2A} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-11-07] (Kaspersky Lab -> AO Kaspersky Lab) Task: {659FA745-4E68-444F-B1C5-308A4A0A1F52} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.) Task: {697FC4F7-25D7-40D1-AC40-B71C0DA3495F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-07-17] (Google LLC -> Google LLC) Task: {86FC3E9E-4270-4B9B-A0C6-05E4285690E4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [27168840 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd) Task: {A3E106E5-6FB5-4DBC-A095-9046A04338EE} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [694752 2021-03-09] (Mozilla Corporation -> Mozilla Foundation) Task: {B2929C97-4FA9-48E4-B6BB-ABFC746824CF} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-03-05] (Piriform Software Ltd -> Piriform) Task: {C70BCC36-0443-4DBE-9BB7-33D2A02C6387} - System32\Tasks\EOSv3 Scheduler onLogOn => D:\Users\Hari\Desktop\esetonlinescanner.exe [15019488 2021-03-14] (ESET, spol. s r.o. -> ESET spol. s r.o.) Task: {D8E8C76C-2743-4EE3-8119-747CEB56D454} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-07-17] (Google LLC -> Google LLC) Task: {FF86E1A9-FCA5-4150-8FDC-45DD0EDA2890} - System32\Tasks\EOSv3 Scheduler onTime => D:\Users\Hari\Desktop\esetonlinescanner.exe [15019488 2021-03-14] (ESET, spol. s r.o. -> ESET spol. s r.o.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{204c116b-6fd7-4c3b-9e48-c2e7e4617036}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{81111830-bb22-49f9-aff4-e32e13b38852}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{c23d7450-894e-4fc3-bf70-ee1640bd876d}: [DhcpNameServer] 192.168.0.1 Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default [2021-03-11] Edge Extension: (Kaspersky Protection) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2021-02-07] Edge Extension: (myTube! Companion) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cbfmaiojcgociaafdiagpdhhhflgmnch [2020-12-07] Edge Profile: C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Guest Profile [2021-03-11] Edge HKU\S-1-5-21-3076391084-2480122960-4283986350-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] Edge HKU\S-1-5-21-3076391084-2480122960-4283986350-1004\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FireFox: ======== FF DefaultProfile: utnvbqjy.default FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\utnvbqjy.default [2021-03-13] FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bk6gdjjl.default-release-1612322717294 [2021-03-14] FF Extension: (Kaspersky Protection) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bk6gdjjl.default-release-1612322717294\Extensions\light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com.xpi [2021-03-11] FF Extension: (Malwarebytes Browser Guard) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bk6gdjjl.default-release-1612322717294\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2021-03-14] FF HKLM-x32\...\Firefox\Extensions: [helper-sig@savefrom.net] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\utnvbqjy.default\extensions\staged\helper-sig@savefrom.net.xpi => not found FF HKU\S-1-5-21-3076391084-2480122960-4283986350-1002\...\Firefox\Extensions: [helper-sig@savefrom.net] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\utnvbqjy.default\extensions\staged\helper-sig@savefrom.net.xpi => not found FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-03-06] (Adobe Inc. -> Adobe Systems Inc.) FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2021-03-13] <==== ATTENTION (Points to *.cfg file) FF ExtraCheck: C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2021-03-13] <==== ATTENTION Chrome: ======= CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default [2021-03-13] CHR DownloadDir: D:\Users\Hari\Desktop\Downloads Chrome CHR Notifications: Default -> hxxps://babylonbee.com; hxxps://deadstate.org; hxxps://listenmusic.fun; hxxps://matswhyask.cam; hxxps://mewe.com; hxxps://nypost.com; hxxps://thepiratebay.org; hxxps://thewire.in; hxxps://web.whatsapp.com; hxxps://www.accuweather.com; hxxps://www.hindustantimes.com; hxxps://www.ndtv.com; hxxps://www.rawstory.com; hxxps://www.telegraphindia.com; hxxps://www.thenewsminute.com; hxxps://www.thewrap.com CHR HomePage: Default -> hxxps://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://www.google.com/" CHR DefaultSearchURL: Default -> hxxps://192.168.1.240/bahmni/favicon.ico CHR Extension: (Slides) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-07-23] CHR Extension: (Kaspersky Protection) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2021-02-21] CHR Extension: (Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-07-23] CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-29] CHR Extension: (WOT Web of Trust, Website Reputation Ratings) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2021-02-04] CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-07-23] CHR Extension: (OpenERP) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dapopdbfnfhcgfdldoielojfiidmecaj [2020-10-31] CHR Extension: (Volume Booster) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejkiikneibegknkgimmihdpcbcedgmpo [2021-03-07] CHR Extension: (ZenMate Free VPN–Best VPN for Chrome) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2021-01-22] CHR Extension: (Sheets) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-07-23] CHR Extension: (Sound Booster) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fncadplkibohomhpfeefbcohaooabokm [2020-10-31] CHR Extension: (AdBlock — best ad blocker) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-02-27] CHR Extension: (Ultimate Volume Booster) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfnhafpadfnabbnjnhdfdacolpmdbjo [2020-12-26] CHR Extension: (Save to Facebook) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfikkaogpplgnfjmbjdpalkhclendgd [2020-10-31] CHR Extension: (Anti-Phishing & Authenticity Checker) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mggehmlfnempkheebgikhmemhnnpacle [2020-10-31] CHR Extension: (Video Downloader PLUS) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\njgehaondchbmjmajphnhlojfnbfokng [2021-02-20] CHR Extension: (Bahmni Home) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlejgcccohmalhjkncfcbnbekihgnnmg [2020-10-31] CHR Extension: (Chrome Web Store Payments) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29] CHR Extension: (Smallpdf - Edit, Compress and Convert PDF) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohfgljdgelakfkefopgklcohadegdpjf [2021-02-10] CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-29] CHR Extension: (Chrome Media Router) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-07] CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm CHR HKU\S-1-5-21-3076391084-2480122960-4283986350-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKU\S-1-5-21-3076391084-2480122960-4283986350-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [moihledlmchhofenpacbhphnbnpakgmo] CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [moihledlmchhofenpacbhphnbnpakgmo] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.) R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [3743464 2021-03-09] (philandro Software GmbH -> philandro Software GmbH) R2 AVP21.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\avp.exe [381928 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) S2 FoxitReaderUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe [2357936 2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Software Inc.) S3 klvssbridge64_21.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.2\x64\vssbridge64.exe [467352 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) S2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [351424 2020-12-11] (Kaspersky Lab JSC -> AO Kaspersky Lab) R2 KSDE5.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksde.exe [644264 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-03-13] (Malwarebytes Inc -> Malwarebytes) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5097896 2020-09-14] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2101.9-0\NisSrv.exe [2462960 2021-02-15] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2101.9-0\MsMpEng.exe [128376 2021-02-15] (Microsoft Windows Publisher -> Microsoft Corporation) S3 wpscloudsvr; C:\ProgramData\Kingsoft\office6\wpscloudsvr.exe [1482496 2020-10-28] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [251608 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2021-03-13] (Malwarebytes Corporation -> Malwarebytes) R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [110392 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [212280 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [127288 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [37496 2020-10-21] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab) R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [523576 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [657176 2021-01-27] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [1400600 2021-01-27] (Kaspersky Lab JSC -> AO Kaspersky Lab) R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.2\Bases\klids.sys [245280 2021-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1025336 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [95544 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [113464 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [113464 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [85288 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [97080 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [55592 2020-10-21] (AnchorFree Inc -> The OpenVPN Project) R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [257208 2020-10-26] (Kaspersky Lab JSC -> AO Kaspersky Lab) R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2020-09-23] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [310232 2021-01-18] (Kaspersky Lab JSC -> AO Kaspersky Lab) R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [116888 2021-01-14] (Kaspersky Lab JSC -> AO Kaspersky Lab) R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [207352 2020-10-28] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [153400 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [250168 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [300856 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220616 2021-03-13] (Malwarebytes Inc -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198248 2021-03-14] (Malwarebytes Inc -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2021-03-14] (Malwarebytes Inc -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-03-13] (Malwarebytes Inc -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [155360 2021-03-14] (Malwarebytes Inc -> Malwarebytes) R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2020-05-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [55904 2019-06-26] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated) S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [70400 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.) S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [26368 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.) S3 vpnpbus; C:\WINDOWS\System32\drivers\vpnpbus.sys [20496 2019-10-07] (Microsoft Windows Hardware Compatibility Publisher -> Callback Technologies, Inc.) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49552 2021-02-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [419040 2021-02-15] (Microsoft Windows -> Microsoft Corporation) S3 wdm_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [151184 2016-07-15] (NGO -> MBB) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [71912 2021-02-15] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2021-03-14 15:10 - 2021-03-14 15:10 - 000003782 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn 2021-03-14 15:10 - 2021-03-14 15:10 - 000003340 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime 2021-03-14 14:41 - 2021-03-14 14:41 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\IGDump 2021-03-14 09:48 - 2021-03-14 09:49 - 000000687 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk 2021-03-14 09:48 - 2021-03-14 09:48 - 000000000 ____D C:\Users\Admin\AppData\Local\ESET 2021-03-14 09:09 - 2021-03-14 09:09 - 000198248 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2021-03-14 09:09 - 2021-03-14 09:09 - 000155360 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2021-03-14 09:09 - 2021-03-14 09:09 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2021-03-13 16:36 - 2021-03-13 16:36 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2021-03-13 16:36 - 2021-03-13 16:36 - 000220616 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2021-03-13 16:36 - 2021-03-13 16:36 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2021-03-13 16:36 - 2021-03-13 16:36 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2021-03-13 16:36 - 2021-03-13 16:36 - 000001993 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2021-03-13 16:36 - 2021-03-13 16:36 - 000001981 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2021-03-13 16:36 - 2021-03-13 16:36 - 000001981 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2021-03-13 16:13 - 2021-03-13 16:13 - 000000000 ____D C:\Program Files\Malwarebytes 2021-03-13 16:04 - 2021-03-14 09:04 - 000000000 ____D C:\AdwCleaner 2021-03-13 09:48 - 2021-03-13 09:48 - 000000008 __RSH C:\ProgramData\ntuser.pol 2021-03-09 08:16 - 2021-03-09 08:16 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2021-02-20 12:05 - 2021-02-27 08:33 - 000000000 ____D C:\ProgramData\Package Cache 2021-02-20 10:52 - 2021-02-20 10:52 - 000001155 _____ C:\Users\Public\Desktop\Kaspersky VPN.lnk 2021-02-20 10:52 - 2021-02-20 10:52 - 000001155 _____ C:\ProgramData\Desktop\Kaspersky VPN.lnk 2021-02-20 10:52 - 2021-02-20 10:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky VPN ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2021-03-14 15:17 - 2020-01-11 18:17 - 000000000 ____D C:\FRST 2021-03-14 15:13 - 2019-12-07 14:44 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-03-14 14:42 - 2020-07-18 07:49 - 000000000 ____D C:\Users\Admin\AppData\Roaming\qBittorrent 2021-03-14 13:45 - 2020-07-23 10:12 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-03-14 12:43 - 2020-08-24 12:49 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2021-03-14 10:22 - 2019-12-07 14:33 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-03-14 10:20 - 2020-08-25 10:32 - 000000000 ____D C:\Program Files\CCleaner 2021-03-14 09:22 - 2020-07-22 15:32 - 000000000 ___HD C:\$WinREAgent 2021-03-14 09:06 - 2020-07-14 10:45 - 000000000 ____D C:\ProgramData\Mozilla 2021-03-14 09:05 - 2019-06-10 08:10 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\Mozilla 2021-03-14 09:02 - 2019-06-09 20:01 - 000000000 __SHD C:\Users\Admin\IntelGraphicsProfiles 2021-03-14 09:01 - 2020-07-23 10:14 - 000000000 ____D C:\Users\Admin 2021-03-14 09:01 - 2020-07-14 09:45 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2021-03-14 09:00 - 2020-10-18 11:07 - 000008192 ___SH C:\DumpStack.log.tmp 2021-03-14 09:00 - 2020-07-23 10:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-03-13 19:58 - 2020-08-25 10:32 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2021-03-13 17:52 - 2019-12-07 14:33 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2021-03-13 16:58 - 2019-12-07 14:44 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-03-13 16:36 - 2019-12-07 14:44 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2021-03-13 16:14 - 2020-08-24 12:47 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2021-03-13 09:50 - 2020-09-02 06:35 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-03-13 09:49 - 2019-12-07 14:44 - 000000000 ___HD C:\Program Files\WindowsApps 2021-03-13 09:43 - 2020-07-15 08:45 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\Temp 2021-03-13 09:39 - 2020-07-14 22:45 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2021-03-13 09:00 - 2020-07-25 14:38 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashDumps 2021-03-13 08:33 - 2020-07-21 09:06 - 000002421 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-03-13 08:33 - 2020-07-21 09:06 - 000002259 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2021-03-13 08:33 - 2020-07-21 09:06 - 000002259 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk 2021-03-12 10:40 - 2019-12-07 14:43 - 000000000 ____D C:\WINDOWS\INF 2021-03-11 09:44 - 2020-07-21 09:52 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Telegram Desktop 2021-03-09 10:52 - 2019-12-07 14:33 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2021-03-09 08:25 - 2020-07-14 10:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2021-03-09 08:16 - 2020-07-14 10:45 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2021-03-09 08:09 - 2020-09-23 15:03 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2021-03-08 09:07 - 2020-10-18 09:06 - 000000000 ____D C:\Users\HKP 2021-03-07 11:09 - 2020-07-23 11:00 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-03-07 11:09 - 2020-07-23 11:00 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2021-03-07 11:09 - 2020-07-23 11:00 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2021-03-06 07:43 - 2018-11-14 22:42 - 000000000 __RHD C:\Users\Public\AccountPictures 2021-03-05 17:38 - 2020-07-14 12:44 - 000000000 ____D C:\Users\Admin\AppData\Local\D3DSCache 2021-03-05 10:46 - 2020-10-28 10:29 - 000000794 _____ C:\Users\Public\Desktop\Bandicut.lnk 2021-03-05 10:46 - 2020-10-28 10:29 - 000000794 _____ C:\ProgramData\Desktop\Bandicut.lnk 2021-03-05 10:45 - 2020-10-28 10:29 - 000000000 ____D C:\Program Files\Bandicut 2021-03-05 09:05 - 2021-01-14 19:14 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Signal 2021-03-04 18:18 - 2020-07-23 10:34 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-03-04 18:18 - 2020-07-23 10:34 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-03-03 18:48 - 2020-07-17 15:52 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-03-03 18:41 - 2020-07-17 15:52 - 130141752 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-02-28 16:35 - 2020-07-23 10:34 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3076391084-2480122960-4283986350-1002 2021-02-28 16:35 - 2020-07-23 10:14 - 000002367 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-02-28 16:35 - 2019-06-10 08:09 - 000000000 ___RD C:\Users\Admin\OneDrive 2021-02-27 15:39 - 2020-07-14 11:25 - 000000000 ____D C:\Users\Admin\AppData\Roaming\vlc 2021-02-27 09:07 - 2020-08-25 10:32 - 000000823 _____ C:\Users\Public\Desktop\CCleaner.lnk 2021-02-27 09:07 - 2020-08-25 10:32 - 000000823 _____ C:\ProgramData\Desktop\CCleaner.lnk 2021-02-27 09:07 - 2020-07-21 09:52 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop 2021-02-24 06:14 - 2020-07-23 10:24 - 000840598 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-02-22 18:30 - 2020-12-07 10:47 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-02-20 10:52 - 2020-09-23 20:41 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2021-02-20 10:52 - 2020-08-18 10:04 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab 2021-02-20 10:52 - 2020-07-24 07:48 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2021-02-16 12:47 - 2020-08-24 12:45 - 000000000 ____D C:\Program Files (x86)\Adobe 2021-02-15 09:01 - 2020-07-14 10:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-02-14 10:29 - 2019-12-07 14:44 - 000000000 ____D C:\WINDOWS\system32\NDF 2021-02-12 08:19 - 2019-12-07 14:44 - 000000000 ____D C:\WINDOWS\LiveKernelReports ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================