Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-06-2025
Ran by linco (administrator) on DESKTOP-J0PJPO6 (ASUSTeK COMPUTER INC. FX502VE) (11-06-2025 09:16:36)
Running from C:\Users\linco\OneDrive\Počítač\FRST64.exe
Loaded Profiles: defaultuser0 & linco
Platform: Microsoft Windows 10 Home Version 22H2 19045.5965 (X64) Language: Čeština (Česká republika) -> Slovenčina (Slovensko)
Default browser: "C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --single-argument %1
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxEM.exe
(explorer.exe ->) (nordvpn s.a. -> NordVPN) C:\Program Files\NordVPN\NordVPN.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\asusptpfilter.inf_amd64_0cfea193ad379f88\AsusPTPService.exe
(services.exe ->) (CyberLink Corp. -> ) C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(services.exe ->) (ICEpower a/s -> ICEpower A/S) C:\Windows\System32\ICEsoundService64.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c18e9c8eed547b01\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_9abf929c7fde5205\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_9abf929c7fde5205\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_7ed3bacbb0a8cc67\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe
(services.exe ->) (nordvpn s.a. -> NordVPN) C:\Program Files\NordVPN\NordSec ThreatProtection\nordsec-threatprotection-service.exe
(services.exe ->) (nordvpn s.a. -> NordVPN) C:\Program Files\NordVPN\nordvpn-service.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_1f594fc858348d79\Display.NvContainer\NVDisplay.Container.exe <2>
(svchost.exe ->) () [File not signed] D:\WindowsApps\5319275A.51895FA4EA97F_2.2523.0.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2522.2.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\spaceman.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [] => [X]
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\108.0.1.0\GoogleDriveFS.exe [66258528 2025-05-18] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\108.0.1.0\GoogleDriveFS.exe [66258528 2025-05-18] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2298117505-976418258-3832342613-1000\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\108.0.1.0\GoogleDriveFS.exe [66258528 2025-05-18] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\108.0.1.0\GoogleDriveFS.exe [66258528 2025-05-18] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4698720 2025-05-19] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [Microsoft Edge Update] => C:\Users\linco\AppData\Local\Microsoft\EdgeUpdate\1.3.195.43\MicrosoftEdgeUpdateCore.exe [268360 2024-12-23] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45715776 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [] => [X]
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [MicrosoftEdgeAutoLaunch_E80CA25EB6CBA45C8EE4426DC76AE1DD] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4141136 2025-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [Spotify] => C:\Users\linco\AppData\Roaming\Spotify\Spotify.exe [36866888 2025-05-06] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [NordVPN] => C:\Program Files\NordVPN\NordVPN.exe [588720 2025-04-02] (nordvpn s.a. -> NordVPN)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Run: [com.squirrel.slack.slack] => C:\Users\linco\AppData\Local\slack\slack.exe [307504 2025-06-10] (Slack Technologies, LLC -> Slack Technologies Inc.)
HKU\S-1-5-21-2298117505-976418258-3832342613-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\108.0.1.0\GoogleDriveFS.exe [66258528 2025-05-18] (Google LLC -> Google LLC.)
HKLM\...\Windows x64\Print Processors\ssm4mPC: C:\Windows\System32\spool\prtprocs\x64\ssm4mpc.dll [61736 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\ssm4m Langmon: C:\Windows\system32\ssm4mlm.dll [40744 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\us008 Langmon: C:\Windows\system32\us008lm.dll [31256 2016-02-15] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files\AVAST Software\Browser\Application\136.0.30453.115\Installer\chrmstp.exe [2025-05-27] (Avast Software s.r.o. -> Gen Digital Inc.)
GroupPolicy-Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {9AC3B822-A126-4F56-8768-F12E5685B199} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-13] (Adobe Inc. -> Adobe)
Task: {188876BF-EDEE-4E8A-9387-CE265DA9046E} - System32\Tasks\ASUS Battery Health Charging Notification => C:\Program Files (x86)\ASUS\ASUS Battery Health Charging\BhcMgr.exe [2478776 2016-11-28] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {4FE10946-A7FF-4118-B9A9-310A4EB98032} - System32\Tasks\ASUS HotfixChecker => C:\Program Files (x86)\ASUS\HotfixChecker\HotfixChecker.exe [153808 2021-09-29] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
Task: {AEB63488-B184-44F6-9A95-2FD682825BE1} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19967504 2016-11-14] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {95B6C707-EEC3-4992-9DAE-1C9189872243} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122552 2016-11-14] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {CC41892C-860D-4898-A9DB-8C98DC996881} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122552 2016-11-14] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {51A38DCA-1882-4FF2-8238-E1A4645DF751} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3479216 2025-05-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {19D0D31F-4670-4438-B486-543971497DF8} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3479216 2025-05-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {0B235E34-AD8D-41B5-9D53-CCA0B6C82A89} - System32\Tasks\AvastBrowserProtectS-1-5-21-2298117505-976418258-3832342613-1001 => C:\Program Files\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1690008 2025-01-07] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {A381A9A5-98DE-4964-90A9-F38AFDF06F65} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-03-04] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {3888D9CE-1C4C-4128-A925-A8727FB6E9CE} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-03-04] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {5CA54F29-251A-496C-A631-D39CBA68EF8B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {175498EB-1652-4DC4-BD97-802421F18ED6} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6139704 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "82a402cc-f766-4bed-ab72-2310e8372526" --version "6.36.0.11508" --silent
Task: {523B0D20-DE49-4BF3-A2D3-9970D09ADCB4} - System32\Tasks\CCleanerSkipUAC - linco => C:\Program Files\CCleaner\CCleaner.exe [39558464 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B34DBE64-8E98-4416-B1E5-4D08416B5EE2} - System32\Tasks\CCleanerSkipUAC - SYSTEM => C:\Program Files\CCleaner\CCleaner.exe [39558464 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3567BFEF-785A-4F61-B7FC-7782D3C9A8C7} - System32\Tasks\Core Temp Autostart linco => "C:\Program Files\Core Temp\Core Temp.exe"  (No File)
Task: {0D4FFF2D-9A82-4983-9D66-82F740EA0894} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\linco\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe  LOGON (No File)
Task: {6A1DF42B-4775-4EE1-A55F-94814F1C2EF9} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\linco\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe  SCHED (No File)
Task: {20B9E710-7D87-45F4-A44E-D28053CC8645} - System32\Tasks\FastVPN_Boot => C:\Program Files (x86)\FastVPN\FastVPN.exe  (No File)
Task: {03B1E1FC-E6AB-49CB-B685-BF13F08707CA} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem126.0.6441.0{8E228A84-E35A-43A2-AE58-5614233831C6} => "C:\Program Files (x86)\Google\GoogleUpdater\126.0.6441.0\updater.exe"  --wake --system (No File)
Task: {4A8C43D8-01FE-4CE6-A69B-5713C0FAE13F} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem131.0.6776.0{01A1A7E3-7378-4893-83BC-902E5A13BC7A} => C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe [5507168 2024-10-14] (Google LLC -> Google LLC)
Task: {6CD296B0-39F0-49B6-904D-E508DC0C2039} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6833.0{4F3FFF86-1C06-4A46-9816-FDAAD9EF423F} => C:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\updater.exe [5591136 2024-11-11] (Google LLC -> Google LLC)
Task: {4B34A9FF-F055-4C46-8CE3-EA4A14413B33} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem134.0.6985.0{709A8B98-767B-463D-AD7B-897EDDF3ADED} => C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe [5672544 2025-01-28] (Google LLC -> Google LLC)
Task: {D107905F-B77B-42F8-B519-84C6E113E72D} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem135.0.7023.0{87B82315-7DBF-4803-86A5-ACB01F74D37C} => C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe [5745760 2025-02-19] (Google LLC -> Google LLC)
Task: {9DE4561B-12A2-4861-B70D-80355F153286} - System32\Tasks\IcarusAvastVpnUpgrade => C:\Program Files\AVAST Software\SecureLine\setup\avast_vpn_online_setup.exe  -> /silent /ShowVpnGui=0 /RestartUpdaterTaskName=IcarusAvastVpnUpgrade /RestartUpdaterAppExe="C:\Program Files\AVAST Software\SecureLine\setup\avast_vpn_online_setup.exe"
Task: {CCF5988C-6774-4BA2-9320-7C7EB01541E0} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4983528 2024-08-02] (Intel Corporation -> Intel Corporation)
Task: {A7FADEC0-DD55-4E8F-A646-26D6816E04FE} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4983528 2024-08-02] (Intel Corporation -> Intel Corporation)
Task: {0E70574C-2087-4D26-BE1A-BE2F5DFBD055} - System32\Tasks\Meta\Messenger-SL-Helper-S-1-5-21-2298117505-976418258-3832342613-1001 => C:\Users\linco\AppData\Local\Programs\Messenger\MessengerHelper.exe  --lassie (No File)
Task: {02253619-98FF-4241-937D-9DFD172FB739} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MpCmdRun.exe [469648 2020-02-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B7FC27D6-78A5-48EE-8F6C-3F47033397DD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MpCmdRun.exe [469648 2020-02-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B8146115-84C9-4DA8-A417-B9910D5E44F9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MpCmdRun.exe [469648 2020-02-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5D312B20-D74C-4942-A886-9BDD252048F5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MpCmdRun.exe [469648 2020-02-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B6D1F4E5-70EC-47F7-95E8-379B1D64B594} - System32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-2298117505-976418258-3832342613-1001Core{CB0193D1-E071-4979-9997-4AEB261EBD0E} => C:\Users\linco\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [206288 2023-10-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {50C670FF-BCA7-47E8-94BA-D0C394A40B01} - System32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-2298117505-976418258-3832342613-1001UA{6752B029-CFAB-45B2-B17F-00C67437588C} => C:\Users\linco\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [206288 2023-10-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {9D0B2021-E14F-466D-9BDB-C956EEE02C8F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34880 2025-06-01] (Mozilla Corporation -> Mozilla Foundation)
Task: {7EC9E74A-BA0E-418B-B327-50F35790C2A8} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3322400 2025-06-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BC0D86DD-ADC0-4E35-9CE2-912A7921AE6C} - System32\Tasks\Remove AdwCleaner Application => C:\Windows\system32\CMD.EXE [289792 2024-04-24] (Microsoft Windows -> Microsoft Corporation) -> /C DEL /F /Q "C:\Users\linco\OneDrive\Počítač\adwcleaner(1).exe"
Task: {42D5785A-35ED-43AA-AFA0-D6A8E6793A5A} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617864 2021-09-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {36535DC6-14B1-42EB-A962-BD22196A1949} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617864 2021-09-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {669BA5FE-B7DF-4A9D-AF12-4A8603F3A1D5} - System32\Tasks\UMonitor Task => C:\Windows\SysWOW64\UMonit64.exe [61752 2016-08-19] (GENESYS LOGIC, INC. -> )
Task: {A86480BD-6CD9-4CAD-938D-FFF05D262C8B} - System32\Tasks\Uninstall AdwCleaner Application => C:\Users\linco\OneDrive\Počítač\adwcleaner(1).exe  /uninstall (No File)
Task: {3EE7B9CA-7691-4C65-9D76-33F71BA2E766} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [181760 2025-04-22] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\WpsExternal_20161114022915.job => C:\Program Files (x86)\Kingsoft\WPS Office\ksolaunch.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5772fdae-c02a-42ee-a317-98789ad2831a}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5772fdae-c02a-42ee-a317-98789ad2831a}: [DhcpDomain] home
Tcpip\..\Interfaces\{5772fdae-c02a-42ee-a317-98789ad2831a}\255646D696021323: [DhcpNameServer] 192.168.102.52
Tcpip\..\Interfaces\{5772fdae-c02a-42ee-a317-98789ad2831a}\4505D2C496E6B6F573733443: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5772fdae-c02a-42ee-a317-98789ad2831a}\7596669663834303: [DhcpNameServer] 70.34.223.248 45.76.91.94
Tcpip\..\Interfaces\{5772fdae-c02a-42ee-a317-98789ad2831a}\7596669663834303: [DhcpDomain] home
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\255646D6960283: [DhcpNameServer] 192.168.163.216
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\354656D27457563747: [DhcpNameServer] 3.126.235.131 3.75.35.248
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\354656D27457563747: [DhcpDomain] internet.local
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\4556C69616537484A7D2231473345373: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\4556C69616537484A7D2231473345373: [DhcpDomain] lan
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\6427565675966496: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\6427565675966496: [DhcpDomain] lan
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\7596669663834303: [DhcpNameServer] 70.34.223.248 45.76.91.94
Tcpip\..\Interfaces\{cb788683-62bb-49bd-a2bd-8c95f035c6d8}\7596669663834303: [DhcpDomain] home
Tcpip\..\Interfaces\{fc01fcd5-2b9d-2fd8-78d8-cb78b313e2b2}: [NameServer] 103.86.96.100,103.86.99.100
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\linco\AppData\Local\Microsoft\Edge\User Data\Default [2025-06-09]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\linco\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2025-04-07]
Edge Extension: (Avira Safe Shopping) - C:\Users\linco\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caiblelclndcckfafdaggpephhgfpoip [2025-03-25]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\linco\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-07]
Edge Extension: (Edge relevant text changes) - C:\Users\linco\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKU\S-1-5-21-2298117505-976418258-3832342613-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [fjoaledfpmneenckfbpdfhkmimnjocfa]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]

FireFox:
========
FF DefaultProfile: xxf7iigu.default-1734383003279
FF ProfilePath: C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\8eme8siz.default-release-1734375673131 [2025-06-09]
FF Session Restore: Mozilla\Firefox\Profiles\8eme8siz.default-release-1734375673131 -> is enabled.
FF Extension: (DeepL: AI translator and writing assistant) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\8eme8siz.default-release-1734375673131\Extensions\firefox-extension@deepl.com.xpi [2024-12-16]
FF Extension: (To Google Translate) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\8eme8siz.default-release-1734375673131\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2024-12-16]
FF Extension: (uBlock Origin) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\8eme8siz.default-release-1734375673131\Extensions\uBlock0@raymondhill.net.xpi [2024-12-16]
FF Extension: (Bitwarden – Bezplatný správca hesiel) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\8eme8siz.default-release-1734375673131\Extensions\{446900e4-71c2-419f-a6a7-df9c091e268b}.xpi [2024-12-16]
FF Extension: (Plná Peňaženka Líštička) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\8eme8siz.default-release-1734375673131\Extensions\{5f383f45-0de3-43b3-838c-ea98916167e3}.xpi [2024-12-16]
FF ProfilePath: C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279 [2025-06-10]
FF Session Restore: Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279 -> is enabled.
FF Extension: (DeepL: AI translator and writing assistant) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279\Extensions\firefox-extension@deepl.com.xpi [2025-05-12]
FF Extension: (To Google Translate) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2024-12-16]
FF Extension: (Language: Slovenčina (Slovak)) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279\Extensions\langpack-sk@firefox.mozilla.org.xpi [2025-05-31]
FF Extension: (Avast Password Manager) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279\Extensions\passwordmanager@avast.com.xpi [2025-05-04]
FF Extension: (uBlock Origin) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279\Extensions\uBlock0@raymondhill.net.xpi [2025-05-20]
FF Extension: (Bitwarden – Bezplatný správca hesiel) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279\Extensions\{446900e4-71c2-419f-a6a7-df9c091e268b}.xpi [2025-05-23]
FF Extension: (Plná Peňaženka Líštička) - C:\Users\linco\AppData\Roaming\Mozilla\Firefox\Profiles\xxf7iigu.default-1734383003279\Extensions\{5f383f45-0de3-43b3-838c-ea98916167e3}.xpi [2025-05-31]
FF HKLM\...\Firefox\Extensions: [sparalarm@chip.de] - C:\Program Files (x86)\sparalarm\ff\chip_sparalarm-14.39.1-fx.xpi
FF Extension: (CHIP Sparalarm) - C:\Program Files (x86)\sparalarm\ff\chip_sparalarm-14.39.1-fx.xpi [2019-09-11]
FF HKLM-x32\...\Firefox\Extensions: [sparalarm@chip.de] - C:\Program Files (x86)\sparalarm\ff\chip_sparalarm-14.39.1-fx.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_465.dll [2020-12-13] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-13] (Adobe Inc. -> )
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-02] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> D:\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-02] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-02] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-02] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1697.6\npAvastBrowserUpdate3.dll [2025-03-04] (Avast Software s.r.o. -> Gen Digital Inc.)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1697.6\npAvastBrowserUpdate3.dll [2025-03-04] (Avast Software s.r.o. -> Gen Digital Inc.)

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-2298117505-976418258-3832342613-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-13] (Adobe Inc. -> Adobe)
S4 AsBhcService; C:\Program Files (x86)\ASUS\ASUS Battery Health Charging\AsBhcSrv.exe [114360 2016-10-20] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
R2 AsusPTPService; C:\WINDOWS\System32\DriverStore\FileRepository\asusptpfilter.inf_amd64_0cfea193ad379f88\AsusPTPService.exe [229728 2024-08-16] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-03-04] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-03-04] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 AvastSecureBrowserElevationService; C:\Program Files\AVAST Software\Browser\Application\136.0.30453.115\elevation_service.exe [2381128 2025-05-23] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1079608 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [124008 2025-06-03] (Intel Corporation -> Intel)
R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [123496 2025-06-03] (Intel Corporation -> Intel)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-11-22] (EasyAntiCheat Oy -> Epic Games, Inc)
S4 FoxitReaderUpdateService; C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2500072 2025-03-26] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S4 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460488 2024-04-03] (Canon Inc. -> )
S4 LibreOfficeMaintenance; D:\LibreOffice\program\update_service.exe [123304 2025-06-06] (The Document Foundation -> The Document Foundation)
R3 nordsec-threatprotection-service; C:\Program Files\NordVPN\NordSec ThreatProtection\nordsec-threatprotection-service.exe [2542112 2025-04-02] (nordvpn s.a. -> NordVPN)
R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2022-12-21] (nordvpn s.a. -> nordvpn S.A.)
R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [2542112 2025-04-02] (nordvpn s.a. -> NordVPN)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_1f594fc858348d79\Display.NvContainer\NVDisplay.Container.exe [1275544 2025-05-16] (NVIDIA Corporation -> NVIDIA Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] (CyberLink Corp. -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2304.8-0\NisSrv.exe [3216064 2023-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2304.8-0\MsMpEng.exe [133544 2023-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AiCharger; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [29312 2016-11-14] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R3 AsusHFilter; C:\WINDOWS\System32\drivers\AsusHFilter.sys [30200 2016-12-22] (ASUSTeK Computer Inc. -> )
R3 AsusPTPDrv; C:\WINDOWS\System32\DriverStore\FileRepository\asusptpfilter.inf_amd64_0cfea193ad379f88\AsusPTPFilter.sys [198632 2024-08-16] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [53904 2018-09-05] (AVAST Software s.r.o. -> The OpenVPN Project)
S3 aswWintun; C:\WINDOWS\System32\drivers\aswWintun.sys [40832 2024-01-25] (Microsoft Windows Hardware Compatibility Publisher -> Avast Software)
R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
S3 GeneStor; C:\WINDOWS\System32\drivers\GeneStor.sys [147808 2023-04-12] (GENESYS LOGIC, INC. -> Genesys Logic)
R2 googledrivefs31931; C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2025-05-18] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. -> ASUS)
R3 iaLPSS2_I2C; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_skl.inf_amd64_363c7132639e12a6\iaLPSS2_I2C_ICL.sys [200456 2020-04-27] (Intel Corporation -> Intel Corporation)
S3 MpKsl281a76c5; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1A70285A-755D-4EAC-8FD2-16BB7AA0B79A}\MpKslDrv.sys [212264 2023-05-10] (Microsoft Windows -> Microsoft Corporation)
R3 mshield; C:\Program Files\NordVPN\NordSec ThreatProtection\1.9.42.4\mshield.sys [45384 2025-05-29] (nordvpn s.a. -> Nordvpn S.A.)
R2 NDivert; C:\Program Files\NordVPN\7.42.1.0\Drivers\NDivert.sys [197592 2025-05-29] (nordvpn s.a. -> NordVPN S.A.)
R4 NordDivert10; C:\Program Files\NordVPN\7.42.1.0\NordDivert1064.sys [101240 2025-04-15] (nordvpn s.a. -> NordVPN/Basil)
R3 ovpn-dco; C:\WINDOWS\System32\drivers\ovpn-dco.sys [103528 2025-03-12] (WDKTestCert lev,133391533294737317 -> OpenVPN, Inc)
S1 rtp1; C:\WINDOWS\System32\DRIVERS\rtp1.sys [413096 2024-06-12] (Avira Operations GmbH -> Avira Operations GmbH)
S1 rtp2; C:\WINDOWS\System32\DRIVERS\rtp2.sys [412984 2024-06-12] (Avira Operations GmbH -> Avira Operations GmbH)
R2 SSPORT; C:\WINDOWS\system32\Drivers\SSPORT.sys [14224 2021-04-02] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [53088 2025-03-12] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 travis; C:\Program Files\NordVPN\NordSec ThreatProtection\1.9.42.4\travis.sys [59232 2025-05-29] (Microsoft Windows Hardware Compatibility Publisher -> Nordvpn S.A.)
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [24064 2020-09-09] (Microsoft Corporation) [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49616 2023-05-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [498944 2023-05-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99608 2023-05-10] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\WINDOWS\system32\DRIVERS\wintun.sys [29592 2022-03-13] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
R3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2025-03-09] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-06-10 22:49 - 2025-06-10 22:49 - 000003326 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2025-06-10 22:49 - 2025-06-10 22:49 - 000000670 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2025-06-10 22:41 - 2025-06-10 22:41 - 000000000 ____D C:\WINDOWS\system32\lxss
2025-06-10 22:41 - 2025-06-10 22:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-06-10 22:31 - 2025-06-10 22:31 - 000002209 _____ C:\Users\linco\OneDrive\Počítač\Slack.lnk
2025-06-10 22:31 - 2025-05-16 03:17 - 002072448 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-06-10 22:31 - 2025-05-16 03:17 - 002072448 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-06-10 22:31 - 2025-05-16 03:17 - 001614208 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-06-10 22:31 - 2025-05-16 03:17 - 001614208 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-06-10 22:31 - 2025-05-16 03:17 - 001576832 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-06-10 22:31 - 2025-05-16 03:17 - 001576832 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-06-10 22:31 - 2025-05-16 03:17 - 001389952 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-06-10 22:31 - 2025-05-16 03:17 - 001389952 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-06-10 22:31 - 2025-05-16 03:17 - 000477832 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-06-10 22:31 - 2025-05-16 03:17 - 000374936 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-06-10 22:31 - 2025-05-16 03:13 - 001259632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-06-10 22:31 - 2025-05-16 03:13 - 000674408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-06-10 22:31 - 2025-05-16 03:13 - 000509056 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-06-10 22:31 - 2025-05-16 03:12 - 026002056 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-06-10 22:31 - 2025-05-16 03:12 - 002313352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-06-10 22:31 - 2025-05-16 03:12 - 001713824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-06-10 22:31 - 2025-05-16 03:12 - 001569416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-06-10 22:31 - 2025-05-16 03:12 - 001220232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-06-10 22:31 - 2025-05-16 03:12 - 001053848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-06-10 22:31 - 2025-05-16 03:12 - 000942208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-06-10 22:31 - 2025-05-16 03:12 - 000809576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-06-10 22:31 - 2025-05-16 03:12 - 000467056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-06-10 22:31 - 2025-05-16 03:11 - 023034480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-06-10 22:31 - 2025-05-16 03:11 - 020517528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-06-10 22:31 - 2025-05-16 03:11 - 007322760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-06-10 22:31 - 2025-05-16 03:11 - 005913736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-06-10 22:31 - 2025-05-16 03:11 - 005240480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-06-10 22:31 - 2025-05-16 03:11 - 003994264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-06-10 22:31 - 2025-05-16 03:11 - 000853664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-06-10 22:31 - 2025-05-16 03:02 - 005601560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-06-10 22:31 - 2025-05-16 03:02 - 004901616 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-06-10 22:30 - 2025-05-15 03:15 - 000143016 _____ C:\WINDOWS\system32\nvinfo.pb
2025-06-10 21:16 - 2025-06-10 21:16 - 000000000 ___HD C:\$WinREAgent
2025-06-10 21:10 - 2025-06-10 21:10 - 000001586 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk
2025-06-10 16:02 - 2025-06-10 16:02 - 002406912 _____ (Farbar) C:\Users\linco\OneDrive\Počítač\FRST64.exe
2025-06-10 15:51 - 2025-06-11 08:53 - 000000000 ____D C:\Users\linco\AppData\Local\NordVPN
2025-06-10 15:50 - 2025-06-11 08:52 - 000000000 ____D C:\ProgramData\NordVPN
2025-06-10 15:50 - 2025-06-10 15:50 - 000000000 ____D C:\ProgramData\NordUpdater
2025-06-10 15:50 - 2025-06-10 15:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordSec
2025-06-10 15:50 - 2025-06-10 15:50 - 000000000 ____D C:\Program Files\NordVPN
2025-06-10 15:50 - 2025-06-10 15:50 - 000000000 ____D C:\Program Files\NordUpdater
2025-06-10 15:50 - 2025-03-12 17:21 - 000103528 _____ (OpenVPN, Inc) C:\WINDOWS\system32\Drivers\ovpn-dco.sys
2025-06-09 21:33 - 2025-06-09 21:44 - 000000620 _____ C:\Users\linco\OneDrive\Počítač\WizTree.lnk
2025-06-09 21:20 - 2025-06-09 21:21 - 000000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice
2025-06-09 20:15 - 2025-06-10 22:45 - 000003070 _____ C:\WINDOWS\system32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-06-01 23:07 - 2025-06-01 23:07 - 000000000 ____D C:\ProgramData\FileOpen
2025-05-29 20:05 - 2025-05-29 20:05 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-05-26 14:13 - 2025-05-26 14:17 - 000041129 _____ C:\Users\linco\OneDrive\Počítač\Toyota sťažnosť.odt
2025-05-23 09:18 - 2025-05-28 10:37 - 000000923 _____ C:\Users\linco\OneDrive\Počítač\Nový textový dokument (3).txt
2025-05-17 23:40 - 2025-06-10 22:31 - 000000000 ____D C:\Users\linco\AppData\Local\slack

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-06-11 09:19 - 2020-12-23 11:05 - 000000000 ____D C:\Users\linco\AppData\Roaming\Slack
2025-06-11 09:18 - 2025-02-08 11:53 - 000036013 _____ C:\Users\linco\OneDrive\Počítač\FRST.txt
2025-06-11 09:17 - 2020-08-22 14:05 - 000000000 ____D C:\FRST
2025-06-11 08:32 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-06-11 08:07 - 2021-12-16 20:58 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-06-11 08:07 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-06-11 08:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-06-11 08:06 - 2018-09-15 20:55 - 000000000 __SHD C:\Users\linco\IntelGraphicsProfiles
2025-06-10 23:05 - 2017-07-04 20:03 - 000000000 ____D C:\ProgramData\NVIDIA
2025-06-10 23:03 - 2018-09-15 20:55 - 000000000 ____D C:\Users\linco\AppData\Local\Packages
2025-06-10 22:58 - 2018-09-20 10:59 - 000000000 ____D C:\Users\linco\AppData\Local\D3DSCache
2025-06-10 22:53 - 2020-06-20 23:01 - 002229564 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-06-10 22:53 - 2020-06-20 21:24 - 000460920 _____ C:\WINDOWS\system32\perfh006.dat
2025-06-10 22:53 - 2020-06-20 21:24 - 000081102 _____ C:\WINDOWS\system32\perfc006.dat
2025-06-10 22:53 - 2019-12-07 16:41 - 000709160 _____ C:\WINDOWS\system32\perfh005.dat
2025-06-10 22:53 - 2019-12-07 16:41 - 000145492 _____ C:\WINDOWS\system32\perfc005.dat
2025-06-10 22:53 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2025-06-10 22:47 - 2024-03-30 10:44 - 000672120 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-06-10 22:47 - 2020-06-20 23:03 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-06-10 22:47 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2025-06-10 22:47 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Registration
2025-06-10 22:47 - 2019-12-07 11:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2025-06-10 22:47 - 2017-07-04 19:59 - 000000000 ___HD C:\Intel
2025-06-10 22:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-06-10 22:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-06-10 22:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-06-10 22:46 - 2018-09-16 14:50 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-06-10 22:44 - 2018-09-16 14:50 - 216824056 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-06-10 22:43 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-06-10 22:41 - 2023-10-17 22:18 - 000000000 ____D C:\Users\linco\AppData\LocalLow\NVIDIA
2025-06-10 22:41 - 2020-06-20 22:57 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-06-10 22:41 - 2017-07-04 20:03 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-06-10 22:34 - 2018-09-15 20:59 - 000000000 ____D C:\Users\linco\AppData\Local\NVIDIA
2025-06-10 22:31 - 2025-04-07 20:39 - 000000000 ____D C:\Users\linco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies Inc
2025-06-10 22:25 - 2025-04-08 19:46 - 000000000 ____D C:\Program Files (x86)\dotnet
2025-06-10 22:25 - 2022-08-21 23:08 - 000000000 ____D C:\Program Files\dotnet
2025-06-10 22:25 - 2017-07-04 19:59 - 000000000 ____D C:\ProgramData\Package Cache
2025-06-10 21:10 - 2017-07-04 20:00 - 000000000 ____D C:\Program Files (x86)\Intel
2025-06-10 20:28 - 2020-06-20 22:55 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-06-10 16:02 - 2024-08-09 07:03 - 000000000 ____D C:\Users\linco\OneDrive\Počítač\FRST-OlderVersion
2025-06-10 15:52 - 2024-12-16 23:03 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-06-10 15:51 - 2022-02-08 18:18 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-06-10 15:51 - 2018-09-15 20:54 - 000000000 ___SD C:\Users\linco\AppData\Roaming\Microsoft\Credentials
2025-06-09 21:37 - 2023-04-27 22:35 - 000000000 ____D C:\Program Files\CCleaner
2025-06-09 21:33 - 2025-02-08 11:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WizTree
2025-06-09 21:26 - 2024-06-20 16:40 - 000000000 ____D C:\Program Files\Avast Software
2025-06-09 21:26 - 2018-09-15 20:59 - 000000000 ____D C:\ProgramData\AVAST Software
2025-06-09 21:25 - 2024-06-20 16:43 - 000000000 ____D C:\Users\linco\AppData\Roaming\Avast Software
2025-06-09 21:25 - 2018-09-15 21:01 - 000000000 ____D C:\Users\linco\AppData\Local\AVAST Software
2025-06-09 20:30 - 2025-03-09 09:47 - 000002332 _____ C:\WINDOWS\system32\Tasks\FastVPN_Boot
2025-06-09 20:30 - 2024-07-09 09:02 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2025-06-09 20:30 - 2023-10-13 23:25 - 000003560 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-06-09 20:30 - 2023-10-13 23:25 - 000003334 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-06-09 20:30 - 2023-04-27 22:35 - 000002252 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - linco
2025-06-09 20:15 - 2017-07-04 20:03 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-06-08 16:37 - 2025-01-13 18:33 - 000002398 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-06-05 18:20 - 2024-12-16 23:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-06-02 11:20 - 2024-11-14 01:03 - 003175968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-06-02 11:20 - 2024-11-14 01:03 - 002522144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-06-02 11:20 - 2024-11-02 10:28 - 000271392 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-06-02 11:20 - 2024-11-02 10:28 - 000245792 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-06-02 10:53 - 2024-11-14 01:03 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-06-02 10:53 - 2024-11-14 01:03 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-06-02 10:51 - 2024-11-14 01:03 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2025-06-01 09:40 - 2024-12-16 23:03 - 000001085 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-05-29 20:43 - 2024-06-26 18:54 - 000000000 ____D C:\WINDOWS\system32\compatrel
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-05-29 20:43 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-05-28 10:40 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-05-27 17:08 - 2025-03-04 22:27 - 000002470 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2025-05-18 19:26 - 2020-06-20 21:45 - 000000000 ____D C:\Users\linco
2025-05-18 19:25 - 2021-09-21 18:09 - 000002251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2025-05-18 19:10 - 2020-06-20 21:45 - 000000000 ____D C:\Users\defaultuser0
2025-05-17 23:40 - 2018-12-05 20:57 - 000000000 ____D C:\Users\linco\AppData\Local\SquirrelTemp
2025-05-15 13:35 - 2024-08-22 09:31 - 000012759 _____ C:\Users\linco\OneDrive\Počítač\ElevatorTALE.odt
2025-05-14 22:45 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-05-14 22:45 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2025-05-13 20:53 - 2020-09-16 11:53 - 000000000 ____D C:\Users\linco\AppData\Roaming\Microsoft\Teams

==================== Files in the root of some directories ========

2024-01-17 12:55 - 2024-01-17 12:55 - 000000259 _____ () C:\ProgramData\fontcacheev1.dat
2020-11-13 15:22 - 2020-11-13 15:22 - 000004536 _____ () C:\Users\linco\AppData\Roaming\CamStudio.cfg
2018-09-15 20:58 - 2019-07-07 11:46 - 000000200 _____ () C:\Users\linco\AppData\Roaming\sp_data.sys
2020-11-13 15:20 - 2020-11-13 15:20 - 000000096 _____ () C:\Users\linco\AppData\Roaming\version2.xml
2020-12-01 11:07 - 2020-12-01 11:07 - 000415507 _____ () C:\Users\linco\AppData\Local\ars.cache
2020-12-01 11:08 - 2020-12-01 11:08 - 001139162 _____ () C:\Users\linco\AppData\Local\census.cache
2020-12-01 10:38 - 2020-12-01 10:38 - 000000036 _____ () C:\Users\linco\AppData\Local\housecall.guid.cache
2024-02-20 01:10 - 2024-02-20 01:10 - 000007605 _____ () C:\Users\linco\AppData\Local\Resmon.ResmonCfg
2020-12-01 10:42 - 2020-12-01 10:42 - 000000010 _____ () C:\Users\linco\AppData\Local\sponge.last.runtime.cache
2024-07-12 20:08 - 2024-07-12 20:08 - 000000036 _____ () C:\Users\linco\AppData\Local\_LOCAL_GUID

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================