Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Divně se chovající PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Rill
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 30 zář 2020 11:03

Divně se chovající PC

#1 Příspěvek od Rill »

Dobrý den,

rád bych požádal o kontrolu logu. PC se chová divným způsobem, dnes se mi několikrát stalo, že přeskakovaly složky v průzkumníkovi i v total comanderu. Ze složky, v které jsem byl a chtěl v ní spustit soubor, bylo vyskočeno do úplně jiné složky. Také se mi zdá, že se divně zaplňuje RAM, ikdyž se na pc nic nedělá. Adwcleaner něco už odstranil a eset online scaner taktéž.

Připojuji log z FRST.


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-09-2020
Ran by wlady (administrator) on DESKTOP-31SMPU8 (Micro-Star International Co., Ltd. MS-7C84) (30-09-2020 13:03:40)
Running from C:\Users\wlady\Desktop
Loaded Profiles: wlady
Platform: Windows 10 Pro Version 2004 19041.450 (X64) Language: Čeština (Česko)
Default browser: "C:\Program Files\Vivaldi\Application\vivaldi.exe" -- "%1"
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Alexey Nicolaychuk -> ) D:\Program Files\RivaTuner Statistics Server\EncoderServer.exe
(Alexey Nicolaychuk -> ) D:\Program Files\RivaTuner Statistics Server\RTSS.exe
(Alexey Nicolaychuk -> ) D:\Program Files\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(cFos Software GmbH -> cFos Software GmbH) C:\Program Files\cFosSpeed\spd.exe
(Comodo Security Solutions -> Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files (x86)\Comodo\Internet Security Essentials\isesrv.exe
(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files (x86)\Comodo\Internet Security Essentials\vkise.exe
(Comodo Security Solutions, Inc. -> COMODO) D:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Comodo Security Solutions, Inc. -> COMODO) D:\Program Files\COMODO\COMODO Internet Security\cis.exe <2>
(Comodo Security Solutions, Inc. -> COMODO) D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe <2>
(EIZO Corporation -> EIZO Corporation) C:\Program Files (x86)\EIZO\Screen InStyle\ScreenInStyle.exe
(Geek Software GmbH -> Geek Software GmbH) D:\Program Files\PDF24\pdf24.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files (x86)\GIGABYTE\RGBFusion\RGBFusion.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2009.2-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2009.2-0\NisSrv.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> ) D:\Program Files\MSI Afterburner\MSIAfterburner.exe
(Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\FoundationService\MSIAPService.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\MSI_Companion_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\MSI.CentralServer.exe <2>
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LEDKeeper2.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LightKeeperService.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Mystic_Light_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\Speed Up\StorageMonitor.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\True Color\MSI.True Color.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\VoiceControl\VoiceControl_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\VoiceControl\VoiceControlEngine.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\One Dragon Center\CC_Engine_x64.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\One Dragon Center\Super_Charger\MSI_Super_Charger_Service.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9cb6a07d60163933\Display.NvContainer\NVDisplay.Container.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [1138416 2020-07-23] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] => D:\Program Files\COMODO\COMODO Internet Security\cis.exe [13177008 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
HKLM-x32\...\Run: [PDFPrint] => D:\Program Files\PDF24\pdf24.exe [483976 2020-08-13] (Geek Software GmbH -> Geek Software GmbH)
HKLM-x32\...\Run: [IseUI] => C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe [4187856 2019-01-29] (Comodo Security Solutions, Inc. -> COMODO)
HKLM-x32\...\RunOnce: [SelLed] => C:\Program Files (x86)\GIGABYTE\RGBFusion\RunLed.exe [50096 2019-04-29] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\Run: [Vivaldi Update Notifier] => C:\Program Files\Vivaldi\Application\update_notifier.exe [1865288 2020-09-09] (Vivaldi Technologies AS -> Vivaldi Technologies AS)
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\Run: [Steam] => D:\Program Files\Steam\steam.exe [3395360 2020-09-04] (Valve -> Valve Corporation)
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\Run: [EpicGamesLauncher] => D:\Program Files\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32411536 2020-09-25] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\Run: [Opera Browser Assistant] => C:\Users\wlady\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3085336 2020-09-29] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\MountPoints2: {b3fc5501-f3f8-11ea-b047-14f6d8175a47} - "E:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{9C142C0C-124C-4467-B117-EBCC62801D7B}] -> C:\Program Files\Vivaldi\Application\3.3.2022.45\Installer\chrmstp.exe [2020-09-15] (Vivaldi Technologies AS -> Vivaldi Technologies AS)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Screen InStyle.lnk [2020-08-27]
ShortcutTarget: Screen InStyle.lnk -> C:\Program Files (x86)\EIZO\Screen InStyle\ScreenInStyle.exe (EIZO Corporation -> EIZO Corporation)
Startup: C:\Users\wlady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE AORUS GRAPHICS ENGINE.lnk [2020-08-30]
ShortcutTarget: GIGABYTE AORUS GRAPHICS ENGINE.lnk -> D:\Program Files\GIGABYTE\AORUS ENGINE\autorun.exe (No File)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0F86243A-0125-488F-AC91-EBD9238AC5A3} - System32\Tasks\MSI Task Host - Detect_Monitor => C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe [74384 2020-09-24] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {15795F06-9B70-4B02-95AA-BA4B8F87644B} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1D1FC87F-C9FC-49DB-9BCD-9F2D63C206F0} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {26470E3F-5950-430E-9DCB-5B98807639E0} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {26AA175A-77B1-48C9-BF9A-977031C73F34} - System32\Tasks\MSI Task Host - DisplayID => C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe [74384 2020-09-24] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {32E771CB-8CB0-4F02-87AA-2515995E3A10} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118120 2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {452ECB42-A549-4E92-B8C1-887E2FCE028A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.2-0\MpCmdRun.exe [533312 2020-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {48561EA5-9448-41F7-8BB8-C84D8C401296} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.2-0\MpCmdRun.exe [533312 2020-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4CDE73B2-A64E-43CC-9393-FFCA26D2ABB3} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [677624 2019-11-21] (Advanced Micro Devices INC. -> )
Task: {52705C8F-C7D9-4B3E-9BA2-1E8D1E270AE6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.2-0\MpCmdRun.exe [533312 2020-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {543AACC7-1289-486E-B396-84EADBA995BC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22764408 2020-09-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {5E46C15B-63BE-4C91-B882-013B5267EA41} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3292984 2020-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {62CA6CED-639B-4C57-BD6A-CBE8F3FB9B94} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => D:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5754352 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
Task: {7F01F97C-D257-4E74-8ED0-AB52A3FFDEEF} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {85834D9D-BCA3-4DEB-ABF9-80BA823E6534} - System32\Tasks\MSIAfterburner => D:\Program Files\MSI Afterburner\MSIAfterburner.exe [782320 2019-10-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {87B65CAC-53EC-44B6-9355-839CCDD5174A} - System32\Tasks\COMODO\COMODO Telemetry {18AD3DFA-30C0-4B5F-84F7-F1870B1A4921} => D:\Program Files\COMODO\COMODO Internet Security\cis.exe [13177008 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
Task: {87D6FCDA-9DCE-4905-8748-90EFAA6EC9B7} - System32\Tasks\Opera scheduled assistant Autoupdate 1598520323 => C:\Users\wlady\AppData\Local\Programs\Opera\launcher.exe [1529880 2020-09-15] (Opera Software AS -> Opera Software)
Task: {8ADDB502-DE86-4477-A22A-4EEDAAF5D491} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.2-0\MpCmdRun.exe [533312 2020-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {92140AA1-8B23-4E8D-8C5E-7C069487BD26} - System32\Tasks\Opera scheduled Autoupdate 1598520320 => C:\Users\wlady\AppData\Local\Programs\Opera\launcher.exe [1529880 2020-09-15] (Opera Software AS -> Opera Software)
Task: {ADA7B4CF-C94F-4544-AB8A-2B89694637BC} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B6856789-123E-436C-8DD8-47AE11A53277} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [3915168 2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B6A87278-F569-41C4-995C-D30935AF89DF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
Task: {BA6B1708-C8B3-4306-A47C-43490C6BB7CD} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BCCB963F-A4B6-40EE-A6A4-D08AFD15A6B2} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118120 2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {CC591700-3498-417D-92F9-39197A9A5B16} - System32\Tasks\Agent Activation Runtime\S-1-5-21-741997079-567957087-574048465-1001 => C:\Windows\System32\AgentActivationRuntimeStarter.exe [13312 2020-08-08] (Microsoft Windows -> )
Task: {CD5DCF5F-20A7-45B7-83EC-288159D6F99F} - System32\Tasks\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} => D:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5754352 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
Task: {CF87D3CA-4907-4918-A196-8C7928677B2D} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D272C9C7-BF25-4E5B-9026-06E8A2F1A320} - System32\Tasks\MSI Task Host - MSI.True Color => C:\Program Files (x86)\MSI\One Dragon Center\True Color\MSI.True Color.exe [44720 2020-05-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {D453038A-84D7-4FA5-AEC4-5EA902430F20} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => D:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5754352 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
Task: {D9D93DA8-05E8-4392-A1D4-0496E0471B3F} - System32\Tasks\MSI Task Host - LEDKeeper2_Host => C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LEDKeeper2.exe [1538224 2020-08-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {DDA18BE5-091E-4C4D-97DC-58E18CE9AD16} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => D:\Program Files\COMODO\COMODO Internet Security\cis.exe [13177008 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
Task: {E3B6CB19-1016-4C48-A9BB-1C4A41BFC36C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22764408 2020-09-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {EC99CE1A-802A-46DE-BCA7-BC920A86A7FE} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EDC86C22-E466-423B-BFDF-DB830BD1637B} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647656 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F24A6BFA-2973-45AB-9883-5D80827E7BC6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [3915168 2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {FC4C0B47-35FF-44B4-9CA1-7C470BB7638B} - System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => D:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5754352 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 0.0.0.0 account.zoner.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c39ea09f-3a78-4a71-bb85-fa111b878878}: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.11 -> D:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-09-11] (Adobe Inc. -> Adobe Systems Inc.)

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe [440368 2019-12-11] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8730200 2020-09-09] (BattlEye Innovations e.K. -> )
R2 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [613128 2020-09-10] (cFos Software GmbH -> cFos Software GmbH)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8838528 2020-09-04] (Microsoft Corporation -> Microsoft Corporation)
R2 CmdAgent; D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [11326384 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
R2 CmdAgentProt; D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [11326384 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
S3 cmdvirth; D:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2675496 2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2971640 2020-07-16] (Comodo Security Solutions -> Comodo)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [802432 2020-09-18] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 isesrv; C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe [1044176 2019-01-29] (Comodo Security Solutions, Inc. -> COMODO)
R2 LightKeeperService; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LightKeeperService.exe [87696 2020-07-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\FoundationService\MSIAPService.exe [61392 2020-07-21] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
R2 MSI_Central_Service; C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe [147088 2020-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 MSI_Companion_Service; C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\MSI_Companion_Service.exe [115344 2020-08-06] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MSI_Super_Charger_Service; C:\Program Files (x86)\MSI\One Dragon Center\Super_Charger\MSI_Super_Charger_Service.exe [31504 2020-09-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R2 Mystic_Light_Service; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Mystic_Light_Service.exe [35504 2020-07-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 PDF24; D:\Program Files\PDF24\pdf24.exe [483976 2020-08-13] (Geek Software GmbH -> Geek Software GmbH)
S3 Rockstar Service; D:\Program Files\Launcher\RockstarService.exe [1453184 2020-08-05] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5097344 2020-08-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 VoiceControlService; C:\Program Files (x86)\MSI\One Dragon Center\VoiceControl\VoiceControl_Service.exe [32400 2020-07-06] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.2-0\NisSrv.exe [2372048 2020-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.2-0\MsMpEng.exe [128360 2020-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9cb6a07d60163933\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9cb6a07d60163933\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AmdTools64; C:\Windows\System32\drivers\AmdTools64.sys [58216 2018-03-23] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [33832 2019-12-11] (ASUSTeK Computer Inc. -> )
R1 cFosSpeed; C:\Windows\system32\DRIVERS\cfosspeed6.sys [1748256 2020-09-10] (cFos Software GmbH -> cFos Software GmbH)
S0 cmdboot; C:\Windows\System32\DRIVERS\cmdboot.sys [17576 2020-01-27] (Microsoft Windows Early Launch Anti-malware Publisher -> COMODO)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [39056 2020-01-08] (Comodo Security Solutions, Inc. -> COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [844176 2020-01-08] (Comodo Security Solutions, Inc. -> COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [47072 2020-01-08] (Comodo Security Solutions, Inc. -> COMODO)
S3 cpuz149; C:\Windows\temp\cpuz149\cpuz149_x64.sys [44320 2020-08-30] (CPUID S.A.R.L.U. -> CPUID)
R1 EneTechIo; C:\Windows\system32\drivers\ene.sys [20992 2020-05-12] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 gdrv2; C:\Windows\gdrv2.sys [32600 2020-08-30] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> )
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [129208 2020-01-08] (Comodo Security Solutions, Inc. -> COMODO)
R1 isedrv; C:\Windows\system32\drivers\isedrv.sys [63256 2018-08-30] (Comodo Security Solutions, Inc. -> COMODO)
R1 ISODrive; D:\Program Files\UltraISO\drivers\ISODrv64.sys [124608 2020-07-10] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
U1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [25616 2018-02-12] (MICSYS Technology Co., Ltd. -> )
S3 NTIOLib_CC_Clock; C:\Program Files (x86)\MSI\One Dragon Center\Lib\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 NTIOLib_CC_COMM; C:\Program Files (x86)\MSI\One Dragon Center\Lib\SYS\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 NTIOLib_CC_CPU; C:\Program Files (x86)\MSI\One Dragon Center\Super_Charger\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 NTIOLib_MysticLight; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Lib\NTIOLib_X64.sys [14288 2017-07-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 Rockey_USB; C:\Windows\system32\DRIVERS\Rockey4USB.sys [23592 2020-08-27] (Feitian Technologies Co., Ltd. -> Feitian Technologies Co., Ltd.)
R3 RTCore64; D:\Program Files\MSI Afterburner\RTCore64.sys [24000 2019-09-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2020-09-17] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [428264 2020-09-17] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [69864 2020-09-17] (Microsoft Windows -> Microsoft Corporation)
R2 WiseFs; C:\Windows\WiseFs64.sys [66128 2020-08-29] (Beijing Lang Xingda Network Technology Co., Ltd -> WiseCleaner.com)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-09-30 13:03 - 2020-09-30 13:04 - 000026789 _____ C:\Users\wlady\Desktop\FRST.txt
2020-09-30 12:59 - 2020-09-30 13:03 - 000000000 ____D C:\FRST
2020-09-30 12:51 - 2020-09-30 12:51 - 000000534 _____ C:\Users\wlady\Desktop\eset.txt
2020-09-30 12:15 - 2020-09-30 12:14 - 001222144 _____ C:\Users\wlady\Desktop\RSITx64.exe
2020-09-30 12:10 - 2020-09-30 11:59 - 002299392 _____ (Farbar) C:\Users\wlady\Desktop\FRST64.exe
2020-09-30 12:10 - 2020-09-29 08:19 - 008414384 _____ (Malwarebytes) C:\Users\wlady\Desktop\adwcleaner_8.0.7.exe
2020-09-30 11:32 - 2020-09-30 11:32 - 000000822 _____ C:\Users\wlady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2020-09-30 11:32 - 2020-09-30 11:32 - 000000724 _____ C:\Users\wlady\Desktop\ESET Online Scanner.lnk
2020-09-30 11:32 - 2020-09-30 11:32 - 000000000 ____D C:\Users\wlady\AppData\Local\ESET
2020-09-29 08:20 - 2020-09-29 08:21 - 000000000 ____D C:\AdwCleaner
2020-09-28 17:41 - 2020-09-28 17:41 - 000000000 ____D C:\Windows\LastGood
2020-09-28 17:40 - 2020-09-25 01:02 - 000038632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
2020-09-28 17:39 - 2020-09-26 00:29 - 001769688 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2020-09-28 17:39 - 2020-09-26 00:29 - 001769688 _____ C:\Windows\system32\vulkaninfo.exe
2020-09-28 17:39 - 2020-09-26 00:29 - 001370328 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-09-28 17:39 - 2020-09-26 00:29 - 001370328 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2020-09-28 17:39 - 2020-09-26 00:29 - 001054944 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2020-09-28 17:39 - 2020-09-26 00:29 - 001054944 _____ C:\Windows\system32\vulkan-1.dll
2020-09-28 17:39 - 2020-09-26 00:29 - 000917728 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2020-09-28 17:39 - 2020-09-26 00:29 - 000917728 _____ C:\Windows\SysWOW64\vulkan-1.dll
2020-09-28 17:39 - 2020-09-26 00:29 - 000455408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2020-09-28 17:39 - 2020-09-26 00:29 - 000349936 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2020-09-28 17:39 - 2020-09-26 00:27 - 001022872 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2020-09-28 17:39 - 2020-09-26 00:27 - 000815856 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll
2020-09-28 17:39 - 2020-09-26 00:27 - 000674200 _____ C:\Windows\system32\nvofapi64.dll
2020-09-28 17:39 - 2020-09-26 00:27 - 000540912 _____ C:\Windows\SysWOW64\nvofapi.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 002097560 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 001585048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 001506200 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 001160600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 000811248 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 000670104 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 000656792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2020-09-28 17:39 - 2020-09-26 00:26 - 000586480 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2020-09-28 17:39 - 2020-09-26 00:26 - 000555928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2020-09-28 17:39 - 2020-09-26 00:25 - 007705328 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2020-09-28 17:39 - 2020-09-26 00:25 - 006859160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2020-09-28 17:39 - 2020-09-26 00:25 - 004174744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2020-09-28 17:39 - 2020-09-26 00:25 - 002509208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2020-09-28 17:39 - 2020-09-26 00:25 - 000850840 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2020-09-28 17:39 - 2020-09-26 00:25 - 000444656 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2020-09-28 17:39 - 2020-09-25 01:02 - 000080940 _____ C:\Windows\system32\nvinfo.pb
2020-09-28 17:09 - 2020-09-28 17:09 - 000003216 _____ C:\Windows\system32\Tasks\MSI Task Host - MSI.True Color
2020-09-28 17:08 - 2020-09-10 10:59 - 001748256 _____ (cFos Software GmbH) C:\Windows\system32\Drivers\cfosspeed6.sys
2020-09-28 17:07 - 2020-09-28 17:07 - 000000000 ____D C:\Users\wlady\AppData\Local\cFos
2020-09-25 19:32 - 2020-09-25 19:32 - 000001049 _____ C:\Users\wlady\Desktop\ABViewer 14.lnk
2020-09-25 19:32 - 2020-09-25 19:32 - 000000000 ____D C:\Users\wlady\Documents\ABViewer 14
2020-09-25 19:32 - 2020-09-25 19:32 - 000000000 ____D C:\Users\wlady\AppData\Roaming\CADSoftTools
2020-09-25 19:32 - 2020-09-25 19:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CADSoftTools ABViewer 14
2020-09-25 19:32 - 2020-09-25 19:32 - 000000000 ____D C:\ProgramData\CADSoftTools
2020-09-19 08:36 - 2020-09-19 08:36 - 000000000 ____D C:\Users\wlady\AppData\Roaming\EasyAntiCheat
2020-09-19 08:34 - 2020-09-19 08:34 - 000000000 ____D C:\ProgramData\Ubisoft
2020-09-19 08:33 - 2020-09-19 08:59 - 000000000 ____D C:\Users\wlady\AppData\Local\Ubisoft Game Launcher
2020-09-19 08:33 - 2020-09-19 08:36 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2020-09-19 08:33 - 2020-09-19 08:33 - 000001270 _____ C:\Users\wlady\Desktop\Uplay.lnk
2020-09-19 08:33 - 2020-09-19 08:33 - 000000000 ____D C:\Users\wlady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2020-09-19 08:33 - 2020-09-19 08:33 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2020-09-18 23:06 - 2020-09-18 23:06 - 000000216 _____ C:\Users\wlady\Desktop\Tom Clancy's Ghost Recon® Wildlands.url
2020-09-16 18:36 - 2020-09-16 18:40 - 000000000 ____D C:\Users\wlady\AppData\Local\Zoner
2020-09-16 18:36 - 2020-09-16 18:36 - 000000000 ____D C:\Users\wlady\AppData\Roaming\Zoner
2020-09-16 18:35 - 2020-09-16 18:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZPS 19 CZ
2020-09-16 18:34 - 2020-09-16 18:35 - 000000905 _____ C:\Users\wlady\Desktop\ZPS 19 CZ.lnk
2020-09-15 21:44 - 2020-09-15 21:44 - 000002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2020-09-15 21:44 - 2020-09-15 21:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2020-09-15 21:32 - 2020-09-15 21:32 - 000002198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vivaldi.lnk
2020-09-11 10:28 - 2020-09-11 10:28 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2020-09-04 23:19 - 2020-09-04 23:19 - 000011835 _____ C:\Users\wlady\Desktop\Arma3Launcher_Exception_20200904T211917.txt
2020-09-04 13:00 - 2020-09-04 13:00 - 000000000 ____D C:\Users\wlady\AppData\Local\DBG
2020-09-03 23:23 - 2020-09-16 00:45 - 000000081 _____ C:\Users\wlady\AppData\Local\.bidstack.fault
2020-08-31 18:15 - 2020-08-31 18:15 - 001060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2020-08-31 18:15 - 2020-08-31 18:15 - 000348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2020-08-31 12:11 - 2020-09-30 11:20 - 000868470 _____ C:\Windows\system32\Drivers\fvstore.dat
2020-08-31 12:11 - 2020-08-31 12:11 - 000000000 ___HD C:\VTRoot
2020-08-31 12:06 - 2020-08-31 18:15 - 000000000 ____D C:\Program Files (x86)\Comodo
2020-08-31 12:06 - 2020-08-31 12:06 - 000002177 _____ C:\Users\Public\Desktop\Comodo Dragon.lnk
2020-08-31 12:06 - 2020-08-31 12:06 - 000001101 _____ C:\Users\Public\Desktop\COMODO Firewall.lnk
2020-08-31 12:06 - 2020-08-31 12:06 - 000000000 ____D C:\Windows\system32\Tasks\COMODO
2020-08-31 12:06 - 2020-08-31 12:06 - 000000000 ____D C:\Users\wlady\AppData\Local\Comodo
2020-08-31 12:06 - 2020-08-31 12:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2020-08-31 12:06 - 2020-01-27 15:36 - 000017576 _____ (COMODO) C:\Windows\system32\Drivers\cmdboot.sys
2020-08-31 12:06 - 2019-01-29 10:42 - 000254440 _____ (COMODO) C:\Windows\system32\iseguard64.dll
2020-08-31 12:06 - 2019-01-29 10:42 - 000205024 _____ (COMODO) C:\Windows\SysWOW64\iseguard32.dll
2020-08-31 12:06 - 2018-08-30 00:55 - 000063256 _____ (COMODO) C:\Windows\system32\Drivers\isedrv.sys
2020-08-31 12:02 - 2020-08-31 12:06 - 000000000 ____D C:\ProgramData\Comodo
2020-08-31 12:02 - 2020-08-31 12:02 - 000000000 ____D C:\ProgramData\Shared Space
2020-08-31 00:34 - 2020-08-31 00:34 - 000000000 ____D C:\Users\wlady\AppData\Local\AMD
2020-08-31 00:33 - 2020-09-15 00:00 - 000000000 ____D C:\ProgramData\AMD AutoUpdate
2020-08-31 00:33 - 2020-08-31 00:33 - 000003484 _____ C:\Windows\system32\Tasks\AMDAutoUpdate
2020-08-31 00:33 - 2020-08-31 00:33 - 000002219 _____ C:\Users\Public\Desktop\AMD Ryzen Master.lnk
2020-08-31 00:33 - 2020-08-31 00:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Ryzen Master

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-09-30 12:56 - 2020-08-26 20:29 - 000000000 ____D C:\ProgramData\NVIDIA
2020-09-30 12:55 - 2020-08-27 11:04 - 000002116 _____ C:\Users\wlady\Desktop\Monitor Power OFF.lnk
2020-09-30 12:55 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-09-30 12:54 - 2020-08-26 22:51 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-09-30 12:54 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI
2020-09-30 12:19 - 2020-08-26 22:51 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-09-30 11:43 - 2020-08-28 23:30 - 000000000 ____D C:\Users\wlady\AppData\Local\ElevatedDiagnostics
2020-09-30 11:20 - 2020-08-28 10:15 - 000003130 _____ C:\Windows\system32\Tasks\MSIAfterburner
2020-09-30 08:24 - 2020-08-26 19:05 - 000000374 _____ C:\Users\wlady\.vivaldi_reporting_data
2020-09-30 08:16 - 2020-08-28 16:25 - 000004206 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{043870B4-35F3-4F34-915B-9D90B675AA1E}
2020-09-30 01:11 - 2020-08-27 00:19 - 000007601 _____ C:\Users\wlady\AppData\Local\resmon.resmoncfg
2020-09-29 19:11 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2020-09-29 19:01 - 2020-08-27 11:25 - 000004460 _____ C:\Windows\system32\Tasks\Opera scheduled assistant Autoupdate 1598520323
2020-09-29 17:59 - 2020-08-27 08:56 - 000000000 ____D C:\Users\wlady\AppData\Roaming\AIMP
2020-09-29 09:01 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2020-09-29 08:12 - 2020-08-26 20:58 - 000000000 ____D C:\Users\wlady\AppData\Local\CrashDumps
2020-09-28 17:42 - 2020-08-26 19:36 - 000000000 ____D C:\Users\wlady\AppData\Local\NVIDIA
2020-09-28 17:42 - 2020-08-26 17:00 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-09-28 17:42 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-09-28 17:09 - 2020-08-26 19:52 - 000082541 _____ C:\Windows\cFosSpeed_Setup_Log.txt
2020-09-28 17:08 - 2020-08-26 19:52 - 000000000 ____D C:\Program Files\cFosSpeed
2020-09-28 17:08 - 2020-08-26 19:52 - 000000000 ____D C:\MSI
2020-09-28 17:08 - 2020-08-26 19:46 - 000000000 ____D C:\ProgramData\MSI
2020-09-28 17:07 - 2020-08-26 19:39 - 000000000 ____D C:\Program Files (x86)\Realtek
2020-09-27 14:17 - 2020-08-29 17:32 - 000000216 ___SH C:\Windows\wisefs.dat
2020-09-27 09:18 - 2020-08-27 08:28 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2020-09-27 09:18 - 2020-08-27 08:28 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-09-26 12:33 - 2020-08-26 22:51 - 000444320 _____ C:\Windows\system32\FNTCACHE.DAT
2020-09-26 00:24 - 2020-08-26 17:00 - 006992200 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2020-09-26 00:24 - 2020-08-26 17:00 - 005964512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2020-09-25 01:02 - 2020-08-26 17:00 - 000222112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2020-09-20 21:41 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\NDF
2020-09-19 08:36 - 2020-08-27 14:30 - 000000000 ____D C:\Users\wlady\Documents\My Games
2020-09-18 23:06 - 2020-08-27 14:30 - 000000000 ____D C:\Users\wlady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2020-09-18 12:54 - 2020-08-27 11:25 - 000004206 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1598520320
2020-09-18 12:54 - 2020-08-27 11:25 - 000001401 _____ C:\Users\wlady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2020-09-17 12:40 - 2020-08-26 22:51 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-09-16 14:42 - 2020-08-27 09:13 - 000000000 ____D C:\Users\wlady\AppData\Roaming\vlc
2020-09-16 08:11 - 2020-08-26 19:05 - 000002216 _____ C:\Users\wlady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivaldi.lnk
2020-09-16 08:11 - 2020-08-26 19:05 - 000002157 _____ C:\Users\wlady\Desktop\Vivaldi.lnk
2020-09-15 21:44 - 2020-08-26 21:58 - 000002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-09-15 21:44 - 2020-08-26 21:58 - 000002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-09-15 21:44 - 2020-08-26 21:58 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2020-09-15 21:44 - 2020-08-26 21:58 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-09-15 21:44 - 2020-08-26 21:58 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-09-15 21:44 - 2020-08-26 21:58 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2020-09-15 21:44 - 2020-08-26 21:58 - 000002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2020-09-15 21:44 - 2020-08-26 21:56 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-09-15 21:32 - 2020-08-26 19:05 - 000000000 ____D C:\Program Files\Vivaldi
2020-09-12 10:24 - 2020-08-26 22:51 - 000008192 ___SH C:\DumpStack.log.tmp
2020-09-12 02:45 - 2020-08-27 19:48 - 000000000 ____D C:\Users\wlady\AppData\Local\Arma 3 Launcher
2020-09-12 00:52 - 2020-08-27 19:50 - 000000000 ____D C:\Users\wlady\AppData\Local\Arma 3
2020-09-09 20:44 - 2020-08-29 23:07 - 000000000 ____D C:\Program Files\Rockstar Games
2020-09-09 20:44 - 2020-08-29 23:07 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2020-09-02 23:28 - 2020-08-27 16:01 - 000000000 ____D C:\Users\wlady\Documents\Euro Truck Simulator 2
2020-08-31 12:06 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2020-08-31 09:28 - 2020-08-26 17:08 - 000000000 ____D C:\Users\wlady\AppData\Local\D3DSCache
2020-08-31 00:33 - 2020-08-26 19:50 - 000000000 ____D C:\Users\wlady\AppData\Local\Downloaded Installations
2020-08-31 00:33 - 2020-08-26 19:50 - 000000000 ____D C:\Program Files\AMD
2020-08-31 00:33 - 2020-08-26 16:59 - 000000000 ____D C:\Users\wlady
2020-08-31 00:32 - 2020-08-26 19:36 - 000000000 ____D C:\AMD

==================== Files in the root of some directories ========

2020-09-03 23:23 - 2020-09-16 00:45 - 000000081 _____ () C:\Users\wlady\AppData\Local\.bidstack.fault
2020-08-27 00:19 - 2020-09-30 01:11 - 000007601 _____ () C:\Users\wlady\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================







a zde Addition

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-09-2020
Ran by wlady (30-09-2020 13:04:25)
Running from C:\Users\wlady\Desktop
Windows 10 Pro Version 2004 19041.450 (X64) (2020-08-26 20:52:23)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-741997079-567957087-574048465-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-741997079-567957087-574048465-503 - Limited - Disabled)
Guest (S-1-5-21-741997079-567957087-574048465-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-741997079-567957087-574048465-504 - Limited - Disabled)
wlady (S-1-5-21-741997079-567957087-574048465-1001 - Administrator - Enabled) => C:\Users\wlady

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: COMODO Firewall (Enabled) {3D87FB90-B561-70B4-3B0B-BCEFE7656ABC}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 20.02 alpha (x64) (HKLM\...\7-Zip) (Version: 20.02 alpha - Igor Pavlov)
ABViewer 14 (HKLM-x32\...\ABViewer 14_is1) (Version: 14.1.0.76 - CADSoftTools ®.)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 20.012.20048 - Adobe Systems Incorporated)
AIMP (HKLM-x32\...\AIMP) (Version: v4.70.2224, 22.07.2020 - AIMP DevTeam)
Aktualizace NVIDIA 38.0.5.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 38.0.5.0 - NVIDIA Corporation) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.07.21.306 - Advanced Micro Devices, Inc.)
AMD Ryzen Master (HKLM\...\AMD Ryzen Master) (Version: 2.3.0.1591 - Advanced Micro Devices, Inc.)
AMD Ryzen Master SDK (HKLM\...\{DBD50508-5F75-416B-995D-C42433A00944}) (Version: 2.2.0.1506 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{7598e74a-915c-4911-918c-ca4b2c296122}) (Version: 2.07.21.306 - Advanced Micro Devices, Inc.) Hidden
ASUS Aac_NBDT HAL (HKLM\...\{01D3B7AA-D078-4506-B460-60877FCDDBD6}) (Version: 2.4.1.0 - ASUSTek COMPUTER INC.) Hidden
ASUS Aac_NBDT HAL (HKLM-x32\...\{62194eb5-96ca-4ebc-bb26-5433c914ac9b}) (Version: 2.4.1.0 - ASUSTek COMPUTER INC.) Hidden
ASUS AIOFan HAL (HKLM\...\{EAE80DED-1A39-41C5-9F60-87CC947F6454}) (Version: 1.0.19 - ASUSTek COMPUTER INC.) Hidden
ASUS AIOFan HAL (HKLM-x32\...\{1b15ca41-2671-4685-ab55-b8c814c4942a}) (Version: 1.0.19 - ASUSTek COMPUTER INC.) Hidden
ASUS AURA Display Component (HKLM\...\{AFD1CF98-FE97-434C-A095-9F27C5BEA53C}) (Version: 1.1.25 - ASUSTek COMPUTER INC. ) Hidden
ASUS AURA Display Component (HKLM-x32\...\{94267bd0-fa8a-4aa4-925d-ec3e0d130fba}) (Version: 1.1.25 - ASUSTek COMPUTER INC. ) Hidden
ASUS AURA Extension Card HAL (HKLM\...\{2C39FF80-1BB2-42C5-A58D-DC90EFF048F6}) (Version: 1.0.16 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM-x32\...\{e46f527f-1e64-4554-abc1-115f3429c25c}) (Version: 1.0.16 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Headset Component (HKLM\...\{A3C4120D-8096-4307-91A2-FFE37EBD5A3D}) (Version: 1.02.12 - ASUSTek COMPUTER INC.) Hidden
ASUS AURA Headset Component (HKLM-x32\...\{b96dabae-c7ef-45f2-95ab-1a4d917262a3}) (Version: 1.02.12 - ASUSTek COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM\...\{D800D836-DE15-4B00-8273-521F022CD837}) (Version: 1.0.58 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM-x32\...\{d00daf18-4c78-4fc6-bb05-376a06c79c48}) (Version: 1.0.58 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Odd Component (HKLM\...\{B5E322FB-C191-463E-BDDD-4F22290EDFDB}) (Version: 1.0.8 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Odd Component (HKLM-x32\...\{277875e0-972c-4705-b09c-ca5acf5b2f7c}) (Version: 1.0.8 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA VGA Component (HKLM\...\{71BB96A6-EAC4-45AE-A17D-D3ED43FF1D14}) (Version: 0.0.2.3 - ASUSTek COMPUTER INC. ) Hidden
ASUS AURA VGA Component (HKLM-x32\...\{2977b6c2-6523-42f4-8f52-bf4f7fc7a840}) (Version: 0.0.2.3 - ASUSTek COMPUTER INC. ) Hidden
ASUS GLCKIO2 Driver (HKLM-x32\...\{3507c756-a80f-4b0e-8475-975d8b432176}) (Version: 1.0.20 - ASUSTeK Computer Inc.) Hidden
ASUS GLCKIO2 Driver (HKLM-x32\...\{5960FD0F-BB3B-49AF-B175-F77DC91E995A}) (Version: 1.0.20 - ASUSTeK Computer Inc.) Hidden
ASUS Keyboard HAL (HKLM\...\{0FA0CDEE-5DC8-421E-A97D-C74FA6E66FC3}) (Version: 1.0.50 - ASUSTek COMPUTER INC.) Hidden
ASUS Keyboard HAL (HKLM-x32\...\{52400cff-4628-4ca3-a922-3767b198c1fd}) (Version: 1.0.50 - ASUSTek COMPUTER INC.) Hidden
ASUS MB Peripheral Products (HKLM\...\{BFED9861-7D96-4528-89F1-B090ABBF11A7}) (Version: 1.0.32 - ASUSTeK Computer Inc.) Hidden
ASUS MB Peripheral Products (HKLM-x32\...\{243ceb39-3b77-43ab-9135-fddab4ac7caf}) (Version: 1.0.32 - ASUSTeK Computer Inc.) Hidden
ASUS Mouse HAL (HKLM\...\{1838F91B-D481-45AA-B92F-071C62D0A19A}) (Version: 1.0.53 - ASUSTek COMPUTER INC.) Hidden
ASUS Mouse HAL (HKLM-x32\...\{3dcded5b-10da-4d98-9c1f-c33d25288ebd}) (Version: 1.0.53 - ASUSTek COMPUTER INC.) Hidden
ASUS MousePad HAL (HKLM\...\{723B40A4-5BF2-4DC6-834A-2ADF75F3CF7E}) (Version: 1.0.1.2 - ASUSTek COMPUTER INC.) Hidden
ASUS MousePad HAL (HKLM-x32\...\{0ebcd5fb-7bf9-45b4-a0b6-0932d728e289}) (Version: 1.0.1.2 - ASUSTek COMPUTER INC.) Hidden
AURA DRAM Component (HKLM\...\{3881F403-B6B7-4D2F-BDAC-7901EB677F52}) (Version: 1.0.37 - ASUS) Hidden
AURA DRAM Component (HKLM-x32\...\{60d8d6b5-0ec5-420a-a407-a42e19346d46}) (Version: 1.0.37 - ASUS) Hidden
BIMTech Tools for ZWCAD verze 2.0 (HKLM-x32\...\{93F25306-2C28-4216-91F2-A84319FB2883}_is1) (Version: 2.0 - BIM Technology s.r.o.)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.75.1089 - AB Team, d.o.o.)
cFosSpeed 11.05 (HKLM\...\cFosSpeed) (Version: 11.05 - cFos Software GmbH, Bonn)
Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 83.0.4103.116 - Comodo)
COMODO Firewall (HKLM\...\{0E9AFD45-C3BA-41D1-B54B-495A22CB3409}) (Version: 12.2.2.7036 - COMODO Security Solutions Inc.) Hidden
COMODO Firewall (HKLM\...\COMODO Internet Security) (Version: 12.2.2.7036 - COMODO Security Solutions Inc.)
Corsair AURA DRAM Component (HKLM\...\{376E0869-A4F1-4DC7-A1FD-EBF3AFFEB832}) (Version: 1.0.13 - CORSAIR COMPONENTS INC.) Hidden
Corsair AURA DRAM Component (HKLM-x32\...\{8fce5ea9-d56f-4f89-a363-830eceb72c72}) (Version: 1.0.13 - CORSAIR COMPONENTS INC.) Hidden
CPUID CPU-Z 1.93 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.93 - CPUID, Inc.)
CPUID CPU-Z MSI 1.92 (HKLM\...\CPUID CPU-Z MSI_is1) (Version: 1.92 - CPUID, Inc.)
Documentation Manager (HKLM\...\{59C2C057-0051-48B0-8570-75E21B5BBAE1}) (Version: 21.90.3.2 - Intel Corporation) Hidden
ENE IO Driver (HKLM-x32\...\{D0512FFD-6194-4D2E-967E-25B82A3322FF}) (Version: 3.3.0 - ENE TECHNOLOGY INC.) Hidden
ENE RGB HAL (HKLM\...\{8DA1B230-D82E-4A24-9237-363E2E1E2695}) (Version: 1.0.21.0 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{bb670f8d-3d66-4f36-8e60-02b71bb0a4e9}) (Version: 1.0.21.0 - Ene Tech.) Hidden
ENE_AIC_Marvell_HAL (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden
ENE_AIC_Marvell_HAL (HKLM-x32\...\{887e18fb-6bc3-4cd4-b34e-32d9ff71bbae}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden
ENE_DRAM_RGB_AURA42 (HKLM\...\{978E8FD1-5778-47EF-91A4-F891DA415DDE}) (Version: 1.0.4.0 - Ene Tech.) Hidden
ENE_DRAM_RGB_AURA42 (HKLM-x32\...\{587316c6-4804-4857-af01-1f2f78d4a0e5}) (Version: 1.0.4.0 - Ene Tech.) Hidden
ENE_EHD_ASM_HAL (HKLM\...\{CB19FBA3-7A4F-4D2A-A231-F580B5DCD203}) (Version: 1.00.05 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_ASM_HAL (HKLM-x32\...\{3532d794-73d7-42bd-af02-9f00623dd567}) (Version: 1.00.05 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.6.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{d8516682-de60-4332-ad6f-49373754b677}) (Version: 1.0.6.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_SSS_HAL (HKLM\...\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_SSS_HAL (HKLM-x32\...\{9eeadf99-713b-4ab5-9ccd-bf9c1c4d9daf}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden
ENE_QSI_Loki_HAL (HKLM\...\{BDE43F26-5917-44F8-B86A-F1D9A6B80B32}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
ENE_QSI_Loki_HAL (HKLM-x32\...\{205ef3a8-937b-43cb-90fc-2f58f71408d8}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
Epic Games Launcher (HKLM-x32\...\{0EE6DDEF-E36B-45EB-9E03-5A266EC8A8F8}) (Version: 1.1.279.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FM Genie Scout 20g version 1.1 20.4.1 (HKLM\...\FM Genie Scout 20g_is1) (Version: 1.1 20.4.1 - )
GALAX GAMER RGB (HKLM\...\{06A16AA8-BBA7-4362-962E-16651962D87C}) (Version: 1.00.02 - Galaxy Microsystems Ltd.) Hidden
GALAX GAMER RGB (HKLM-x32\...\{1257fdeb-ffa3-4e17-9d4b-189075ea3656}) (Version: 1.00.02 - Galaxy Microsystems Ltd.)
Geeks3D FurMark 1.21.2.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: 1.21.2.0 - Geeks3D)
Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{10764165-E41B-4A08-B2B0-950EA48A27AC}) (Version: 19.0.281 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000110-0210-1029-84C8-B8D95FA3C8C3}) (Version: 21.110.0.3 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{0c29cba7-104f-4464-8b3c-2dd1f7584b17}) (Version: 21.90.3.2 - Intel Corporation) Hidden
Internet Security Essentials (HKLM-x32\...\ComodoIse) (Version: 1.6.472587.185 - Comodo)
IrfanView 4.54 (64-bit) (HKLM\...\IrfanView64) (Version: 4.54 - Irfan Skiljan)
Kingston AURA DRAM Component (HKLM\...\{6D2D2DAF-BFE4-45A6-BF40-8A9F7FF54F42}) (Version: 1.0.20 - KINGSTON COMPONENTS INC.) Hidden
Kingston AURA DRAM Component (HKLM-x32\...\{c0c65c06-e79e-44b5-bd66-85099364afeb}) (Version: 1.0.20 - KINGSTON COMPONENTS INC.) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Microsoft Office Professional Plus 2019 - cs-cz (HKLM\...\ProPlus2019Retail - cs-cz) (Version: 16.0.13127.20408 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-741997079-567957087-574048465-1001\...\OneDriveSetup.exe) (Version: 20.143.0716.0003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{8e24fb65-31aa-446d-9c3e-35c5e11cb367}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.27.29016 (HKLM-x32\...\{40d3fee2-b257-46c2-bdc0-cb1088d97327}) (Version: 14.27.29016.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
MSI Afterburner 4.6.2 (HKLM-x32\...\Afterburner) (Version: 4.6.2 - MSI Co., LTD)
MSI SDK (HKLM-x32\...\{EE7D557C-3AE7-4348-8DCA-3A89790D0002}}_is1) (Version: 1.0.0.58 - MSI)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.8.9 - Notepad++ Team)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.27 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.4.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.4.14 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.38.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.35 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 456.55 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 456.55 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
NvModuleTracker (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver) (Version: 6.14.24033.38719 - NVIDIA Corporation) Hidden
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.13127.20164 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.13127.20164 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.13127.20378 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.13127.20164 - Microsoft Corporation) Hidden
Opera Stable 70.0.3728.189 (HKU\S-1-5-21-741997079-567957087-574048465-1001\...\Opera 70.0.3728.189) (Version: 70.0.3728.189 - Opera Software)
Patriot Viper M2 SSD RGB (HKLM\...\{0886A906-0625-4A43-930D-AA92F6665AF4}) (Version: 1.00.04 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM-x32\...\{ebb7013c-0b03-497c-bed1-1e48e806a593}) (Version: 1.00.04 - Patriot Memory)
Patriot Viper RGB (HKLM\...\{E42E13B0-071E-49C1-B1CC-58198E82F302}) (Version: 1.00.08 - Patriot Memory) Hidden
Patriot Viper RGB (HKLM-x32\...\{4b7bfeff-ac47-46c1-aea6-4556f5f0e6bb}) (Version: 1.00.08 - Patriot Memory)
PDF24 Creator 9.2.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: 9.2.0 - PDF24.org)
PerformanceTest v10.0 (HKLM\...\PerformanceTest 10_is1) (Version: 10.0.1008.0 - Passmark Software)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8991.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.42.526.2020 - Realtek)
RGB Fusion (HKLM-x32\...\{FFA8F1FA-3C2C-4A94-AC0B-0DF47272C25F}) (Version: 3.20.0721.1 - GIGABYTE)
RivaTuner Statistics Server 7.2.3 (HKLM-x32\...\RTSS) (Version: 7.2.3 - Unwinder)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.27.272 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.6.5 - Rockstar Games)
Screen InStyle (HKLM-x32\...\{B249FBDB-FAFA-4EED-8833-3073A0FC829F}_is1) (Version: 1.1.5.6 - EIZO Corporation)
SkiJo Software pro ZWCAD (HKLM-x32\...\SkiJo Software pro ZWCAD) (Version: - SkiJo Software)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TechPowerUp GPU-Z (HKLM-x32\...\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1) (Version: - TechPowerUp)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.51 - Ghisler Software GmbH)
Ulož.to FileManager 2.78 (64-bit) (HKLM\...\3f2e2cd28b0e4e4396c2402fbc85a0f0_is1) (Version: 2.78 - Uloz.to cloud a.s.)
UltraISO Premium V9.75 (HKLM-x32\...\UltraISO_is1) (Version: 9.75 - EZB Systems, Inc.)
Uplay (HKLM-x32\...\Uplay) (Version: 27.0 - Ubisoft)
Vivaldi (HKLM-x32\...\Vivaldi) (Version: 3.3.2022.45 - Vivaldi Technologies AS.)
Vivaldi (HKU\S-1-5-21-741997079-567957087-574048465-1001\...\Vivaldi) (Version: 3.2.1967.47 - Vivaldi Technologies AS.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.11 - VideoLAN)
Wise Folder Hider (HKLM-x32\...\Wise Folder Hider_is1) (Version: 4.3.4 - WiseCleaner.com, Inc.)
ZPS 19 CZ (HKU\S-1-5-21-741997079-567957087-574048465-1001\...\{E83AA227-7862-F115-2E87-46DCA9E3D879}) (Version: v.19.2004.2.262 - 18.08.2020 - libbi)
ZWCAD 2017 (HKLM\...\{26A7C767-A001-0000-A001-F87888BABDCA}) (Version: 17.0.2017.1013 - ZWSOFT) Hidden
ZWCAD 2017 Czech (HKLM\...\{26A7C767-A001-0000-A200-F87888BABDCA}) (Version: 17.0.2017.1013 - ZWSOFT)
ZWCAD 2017 Language Pack - Czech (HKLM\...\{26A7C767-A001-1029-A101-F87888BABDCA}) (Version: 17.0.2017.1013 - ZWSOFT) Hidden

Packages:
=========
DragonCenter -> C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.DragonCenter_2.0.65.0_x64__kzh8wxbdkxb8p [2020-08-30] (MICRO-STAR INTERNATIONAL CO., LTD) [Startup Task]
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_115.1.152.0_x64__v10z8vjag6ke6 [2020-08-27] (HP Inc.)
Live Home 3D Pro -> C:\Program Files\WindowsApps\BeLightSoftware3DUSALLC.LiveHome3DPro_3.8.1112.0_x64__72e05f7xb45sj [2020-08-27] (BeLight Software 3D USA LLC)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8101.0_x64__8wekyb3d8bbwe [2020-08-26] (Microsoft Studios) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.25.20211.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.958.0_x64__56jybvy8sckqj [2020-08-26] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.14.225.0_x64__dt26b99r8h8gj [2020-09-28] (Realtek Semiconductor Corp)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0 [2020-08-26] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-741997079-567957087-574048465-1001_Classes\CLSID\{BCA9D37C-CA60-4160-9115-97A00F24702D}\localserver32 -> "C:\Program Files\Vivaldi\Application\3.2.1967.47\notification_helper.exe" => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2020-08-08] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => D:\Program Files\AIMP\System\aimp_menu64.dll [2020-08-27] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => D:\Program Files\Notepad++\NppShell_06.dll [2020-07-15] (Notepad++ -> )
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => D:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
ContextMenuHandlers2: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => D:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
ContextMenuHandlers2: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => D:\Program Files\UltraISO\isoshl64.dll [2020-07-13] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2020-08-08] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => D:\Program Files\AIMP\System\aimp_menu64.dll [2020-08-27] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers4: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => D:\Program Files\UltraISO\isoshl64.dll [2020-07-13] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9cb6a07d60163933\nvshext.dll [2020-09-26] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2020-08-08] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => D:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2020-02-27] (Comodo Security Solutions, Inc. -> COMODO)
ContextMenuHandlers6: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => D:\Program Files\UltraISO\isoshl64.dll [2020-07-13] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\wlady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\969fa00ceac8236d\Vivaldi.lnk -> C:\Program Files\Vivaldi\Application\vivaldi_proxy.exe (Vivaldi Technologies AS) -> --profile-directory=Default

==================== Loaded Modules (Whitelisted) =============

2020-08-27 11:04 - 2020-06-02 09:10 - 000211968 _____ () [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\libcolour.dll
2019-08-05 19:50 - 2019-08-05 19:50 - 000009216 _____ () [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\Phison.dll
2020-08-26 19:52 - 2017-08-03 05:48 - 000237568 _____ () [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LEDControl.dll
2020-08-26 19:52 - 2019-09-27 14:08 - 000037376 _____ () [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Phison.dll
2019-10-26 13:04 - 2019-10-26 13:04 - 000232960 _____ () [File not signed] D:\Program Files\MSI Afterburner\RTCore.dll
2019-10-26 13:03 - 2019-10-26 13:03 - 000057344 _____ () [File not signed] D:\Program Files\MSI Afterburner\RTFC.dll
2019-10-26 13:04 - 2019-10-26 13:04 - 000650240 _____ () [File not signed] D:\Program Files\MSI Afterburner\RTHAL.dll
2019-10-26 13:03 - 2019-10-26 13:03 - 000074240 _____ () [File not signed] D:\Program Files\MSI Afterburner\RTMUI.dll
2019-10-26 13:03 - 2019-10-26 13:03 - 000369664 _____ () [File not signed] D:\Program Files\MSI Afterburner\RTUI.dll
2019-09-09 16:29 - 2019-09-09 16:29 - 000057344 _____ () [File not signed] D:\Program Files\RivaTuner Statistics Server\RTFC.dll
2019-09-09 16:30 - 2019-09-09 16:30 - 000074240 _____ () [File not signed] D:\Program Files\RivaTuner Statistics Server\RTMUI.dll
2019-09-09 16:30 - 2019-09-09 16:30 - 000368640 _____ () [File not signed] D:\Program Files\RivaTuner Statistics Server\RTUI.dll
2020-08-27 11:04 - 2020-06-02 09:10 - 000965632 _____ (EIZO Corporation) [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\libemc.dll
2020-08-27 11:04 - 2020-06-02 09:10 - 000100352 _____ (EIZO Corporation) [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\libHIDmctrl.dll
2020-08-27 11:04 - 2020-06-02 09:10 - 000162816 _____ (EIZO Corporation) [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\libmctrl.dll
2020-08-27 11:04 - 2020-06-02 09:10 - 000091648 _____ (EIZO Corporation) [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\libmptag.dll
2020-08-27 11:04 - 2020-06-02 09:10 - 000080384 _____ (EIZO NANANO CORPORATION) [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\libminfo.dll
2020-08-27 11:04 - 2020-06-02 09:10 - 000131072 _____ (EIZO NANAO CORPORATION) [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\libDDCCImctrl.dll
2019-04-15 16:24 - 2019-04-15 16:24 - 000155648 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\yccV2.DLL
2019-10-29 09:26 - 2019-10-29 09:26 - 000445952 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GVDisplay.dll
2018-09-11 19:53 - 2018-09-11 19:53 - 000237056 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GvIllumLib.dll
2020-06-18 08:01 - 2020-06-18 08:01 - 002057216 _____ (GIGABYTE) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\AACPCIeSSD_Lib.dll
2020-06-18 08:01 - 2020-06-18 08:01 - 002057728 _____ (GIGABYTE) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\AACSSD_Lib.dll
2020-08-26 19:35 - 2020-08-08 21:00 - 000076800 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2018-08-30 16:26 - 2018-08-30 16:26 - 000053760 _____ (MS) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\MsIo32_Galax.dll
2020-08-26 19:52 - 2018-04-04 06:22 - 000053248 _____ (MS) [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\MsIo32.dll
2020-08-26 19:52 - 2018-08-31 07:26 - 000053760 _____ (MS) [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\MsIo32_Galax.dll
2020-08-27 11:04 - 2015-12-09 21:08 - 001103360 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files (x86)\EIZO\Screen InStyle\x86\SQLite.Interop.dll
2017-10-05 15:26 - 2017-10-05 15:26 - 002247168 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\CRtive.dll
2018-12-08 08:22 - 2018-12-08 08:22 - 002059264 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GHidApi.dll
2020-07-06 19:33 - 2020-07-06 19:33 - 000478720 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GvLedLib.dll
2020-05-08 14:55 - 2020-05-08 14:55 - 002107392 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\SMBCtrl.dll
2020-08-26 19:52 - 2016-10-04 04:43 - 000399872 _____ (TODO: <公司名稱>) [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Lib\SDKDLL.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\.scr: ZWCAD.SCR.2017 => <==== ATTENTION

==================== Internet Explorer (Whitelisted) ==========

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2020-09-16 18:36 - 000000859 _____ C:\Windows\system32\drivers\etc\hosts
0.0.0.0 account.zoner.com

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %INTEL_DEV_REDIST%redist\intel64_win\compiler;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common
HKU\S-1-5-21-741997079-567957087-574048465-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\wlady\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

Network Binding:
=============
Wi-Fi: COMODO Internet Security Firewall Driver -> inspect (enabled)
Wi-Fi: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled)
Síťové připojení Bluetooth: COMODO Internet Security Firewall Driver -> inspect (enabled)
Ethernet: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled)
Ethernet: COMODO Internet Security Firewall Driver -> inspect (enabled)

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\StartupApproved\Run: => "Vivaldi Update Notifier"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{27B31AA6-1843-4E69-BEF2-10BD9009739A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{96921BC1-C152-4523-B789-90885C4F928C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3FF47041-1572-42E7-B643-B10A34063B36}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9B86ECAE-2995-4ADF-B729-6B627FE522F8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{5C2147C9-1467-4FD1-B37B-D1671FBBB872}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{BA739AB6-8A61-4423-8395-462756DFE62F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{C9AA8012-0FA0-4F87-B0F2-59A3D7313260}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{DA77C710-6379-45BF-A27A-68BE2A91E6CF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.140.508.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{6E28CD1D-1685-4F71-913C-263234F9E1D0}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{EA5B1948-7DB0-4027-A570-18A6EDAB29EF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{61E0DC12-7672-4A35-B303-D5B17B3CE753}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5DE87753-D748-4275-9B04-255D696D47C8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A9105912-DC2D-4901-9CD0-3CB94F6D639B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{54656559-2675-4A15-8A47-FD0A0FA87074}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{EDEB44A2-4C19-4718-9B24-42EE3E77372C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C3FF8D47-2835-48DA-9CD2-0266E2027CDE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{23104D9E-4A6E-46EA-B1CA-4805EB24C092}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{DBC04EA2-A59D-438B-93F3-DF045EAB0410}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{5B6915EF-9BFB-47E5-923B-F312B0AFC5F8}] => (Allow) D:\Program Files\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{186FEFB7-5AA9-42BF-A3DB-F49CE981EEBC}] => (Allow) D:\Program Files\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{55D46C79-77BA-484A-A533-2DBA1CAC6C02}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E620296A-6BAA-4621-AA77-93B5C5103262}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{84EAAAE6-DC7F-4519-B5C3-B05C278F12A6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{263E2417-15CC-4EF8-9DFF-4D170D06F111}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9B78827A-4611-426D-86B8-02D386E037ED}] => (Allow) D:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{7E04C1B4-157D-47E0-9AAD-9C851273A46B}] => (Allow) D:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{94F56398-1316-49E8-B910-F85971FE2D91}D:\program files\epic games\twinmotion2020.2\twinmotion\binaries\win64\twinmotion-win64-shipping.exe] => (Allow) D:\program files\epic games\twinmotion2020.2\twinmotion\binaries\win64\twinmotion-win64-shipping.exe (Epic Games, Inc. -> Epic Games)
FirewallRules: [UDP Query User{1F01F02A-1F95-4C5C-BC43-5CBCF1DEEF0B}D:\program files\epic games\twinmotion2020.2\twinmotion\binaries\win64\twinmotion-win64-shipping.exe] => (Allow) D:\program files\epic games\twinmotion2020.2\twinmotion\binaries\win64\twinmotion-win64-shipping.exe (Epic Games, Inc. -> Epic Games)
FirewallRules: [{63E60C94-EB89-4DC4-8B08-122235C198B9}] => (Allow) D:\Program Files\ZWCAD 2017\ZWCAD.EXE (ZWCAD Software Co.,LTD -> )
FirewallRules: [{E04F36BD-1FD2-4F22-896E-90315D1E2FE4}] => (Allow) D:\Program Files\ZWCAD 2017\ZWCAD.EXE (ZWCAD Software Co.,LTD -> )
FirewallRules: [{B3A6BAC8-3996-477F-B441-F3EF12A09A61}] => (Allow) D:\Program Files\ZWCAD 2017\ZwCrashReportManagement.exe => No File
FirewallRules: [{53807745-DFD9-4573-9ED7-D19A87E75A1E}] => (Allow) D:\Program Files\ZWCAD 2017\ZwCrashReportManagement.exe => No File
FirewallRules: [{A17506F3-BC9D-4F43-B030-D6C2448870F1}] => (Allow) D:\Program Files\ZWCAD 2017\ZWErrorDialog.exe => No File
FirewallRules: [{684B07A4-8A4F-4503-810A-E792C86F24BA}] => (Allow) D:\Program Files\ZWCAD 2017\ZWErrorDialog.exe => No File
FirewallRules: [{EC249626-8D3C-4BBE-8479-DCFA12AD0FA5}] => (Allow) D:\Program Files\ZWCAD 2017\ZwAuthHost.exe (ZWCAD Software Co.,LTD -> )
FirewallRules: [{397F480A-5B4A-45EB-BC0D-953335EEAAFC}] => (Allow) D:\Program Files\ZWCAD 2017\ZwAuthHost.exe (ZWCAD Software Co.,LTD -> )
FirewallRules: [{478BE5AF-25E2-4881-AAD0-E1DB31E6DAD2}] => (Allow) D:\Program Files\ZWCAD 2017\ZwUpdHost.exe (ZWCAD Software Co.,LTD -> )
FirewallRules: [{D40E4088-798E-477F-A03B-B7CF42E052BA}] => (Allow) D:\Program Files\ZWCAD 2017\ZwUpdHost.exe (ZWCAD Software Co.,LTD -> )
FirewallRules: [{897ACC14-07C3-4309-9171-2E8E26C96225}] => (Allow) D:\Program Files\ZWCAD 2017\ZwSyble.exe => No File
FirewallRules: [{B9D73C55-2FBE-4018-81EF-E02AFAE0AA22}] => (Allow) D:\Program Files\ZWCAD 2017\ZwSyble.exe => No File
FirewallRules: [{945D41B1-252B-4BB1-9A05-38FC3E144002}] => (Allow) D:\Program Files\ZWCAD 2017\XXX => No File
FirewallRules: [{117492E6-AE54-427C-8B3D-AE2D6A1B00B5}] => (Allow) D:\Program Files\ZWCAD 2017\XXX => No File
FirewallRules: [{FA38A301-1DA4-4735-9CC6-03A685B0583A}] => (Allow) D:\Program Files\Steam\steamapps\common\Farming Simulator 19\x64\FarmingSimulator2019Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{58B0765F-4D46-42BE-B545-FB957A04F154}] => (Allow) D:\Program Files\Steam\steamapps\common\Farming Simulator 19\x64\FarmingSimulator2019Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{051E38D1-3D61-43B3-9944-6FF111C3B681}] => (Allow) D:\Program Files\Steam\steamapps\common\Football Manager 2020\fm.exe (Sports Interactive) [File not signed]
FirewallRules: [{2215E0D7-7992-48DF-A5F2-FD1722476A3F}] => (Allow) D:\Program Files\Steam\steamapps\common\Football Manager 2020\fm.exe (Sports Interactive) [File not signed]
FirewallRules: [{A1B239C3-714A-4C69-B659-B667F0BBB11B}] => (Allow) D:\Program Files\Steam\steamapps\common\Arma 3\arma3launcher.exe (BOHEMIA INTERACTIVE a.s. -> Bohemia Interactive)
FirewallRules: [{32B1A6CD-6284-4C0D-B283-05531EAFE11A}] => (Allow) D:\Program Files\Steam\steamapps\common\Arma 3\arma3launcher.exe (BOHEMIA INTERACTIVE a.s. -> Bohemia Interactive)
FirewallRules: [{22914A1C-6C66-4183-B1D7-3C68A85816F2}] => (Allow) D:\Program Files\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{65DCC437-BBE1-4C0C-BCFA-83E0DD2A069D}] => (Allow) D:\Program Files\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{780CCED9-02BF-48D1-96C1-9E0A7CC7F0B6}D:\program files\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\program files\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{BCBE50C0-B7DD-4300-BA24-B64E8AD6A432}D:\program files\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\program files\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{B121DE0A-110F-4478-B30D-B6C789103698}] => (Allow) D:\Program Files\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{5B720373-620C-42F9-84BF-BFC38945453E}] => (Allow) D:\Program Files\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E5D76005-466E-465C-A3D6-A741223D5302}] => (Allow) C:\Program Files\Vivaldi\Application\vivaldi.exe (Vivaldi Technologies AS -> Vivaldi Technologies AS)
FirewallRules: [{6D0C3ECD-C68D-4DA7-A2F3-9E81A3B0176F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3A0EA0DE-7504-4385-971C-0E91F5CC08BD}] => (Allow) D:\Program Files\Steam\steamapps\common\Wildlands\GRW.exe (Blue Byte GmbH -> )
FirewallRules: [{023334B8-A664-4675-995F-65774180F394}] => (Allow) D:\Program Files\Steam\steamapps\common\Wildlands\GRW.exe (Blue Byte GmbH -> )
FirewallRules: [{5BF2D27E-2D24-450D-8CC9-C6840DF3B4EF}] => (Allow) D:\Program Files\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{378A4BEB-693B-4D5B-9095-FABD36C85A23}] => (Allow) D:\Program Files\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{3F1C0464-24A0-4391-89C2-A50CCEE2A423}] => (Allow) D:\Program Files\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{CF692315-F949-4B04-BEBB-606D43F3A87E}] => (Allow) D:\Program Files\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [TCP Query User{4655BA78-268F-437E-BB37-19A2A2BE6A9E}C:\users\wlady\appdata\local\programs\opera\70.0.3728.189\opera.exe] => (Allow) C:\users\wlady\appdata\local\programs\opera\70.0.3728.189\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [UDP Query User{6F6A87EA-6781-4F68-B43F-46BB81E95109}C:\users\wlady\appdata\local\programs\opera\70.0.3728.189\opera.exe] => (Allow) C:\users\wlady\appdata\local\programs\opera\70.0.3728.189\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{C3C23569-1629-4B9C-80A4-CF6BA9059B76}] => (Block) C:\users\wlady\appdata\local\programs\opera\70.0.3728.189\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{02022C08-7950-4B3D-8E99-9DFC77E48681}] => (Block) C:\users\wlady\appdata\local\programs\opera\70.0.3728.189\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{F59B0C2C-48E1-4131-BA1D-615D9D4E0F92}] => (Allow) LPort=32682

==================== Restore Points =========================

09-09-2020 20:44:48 Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821
18-09-2020 22:58:57 Naplánovaný kontrolní bod
28-09-2020 17:07:03 Instalováno Realtek Ethernet Controller Driver

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (09/30/2020 12:54:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Název chybujícího modulu: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Kód výjimky: 0xc0000005
Posun chyby: 0x0001c132
ID chybujícího procesu: 0x10a8
Čas spuštění chybující aplikace: 0x01d6971819f2f02c
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
ID zprávy: 9e1b1d99-4b3d-4cac-a326-47665765c4d5
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/30/2020 11:21:04 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Název chybujícího modulu: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Kód výjimky: 0xc0000005
Posun chyby: 0x0001c132
ID chybujícího procesu: 0x120c
Čas spuštění chybující aplikace: 0x01d6970b0440dc9b
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
ID zprávy: 46d8bc7c-2fa4-4fdd-a9ea-167b6e0b76bd
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/29/2020 06:56:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Název chybujícího modulu: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Kód výjimky: 0xc0000005
Posun chyby: 0x0001c132
ID chybujícího procesu: 0x1224
Čas spuštění chybující aplikace: 0x01d696817d8e014b
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
ID zprávy: 9f9efa27-9b01-400a-973a-6b02be722d0e
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/29/2020 08:21:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Název chybujícího modulu: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Kód výjimky: 0xc0000005
Posun chyby: 0x0001c132
ID chybujícího procesu: 0xd44
Čas spuštění chybující aplikace: 0x01d69628d351fee9
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
ID zprávy: 1e1097a6-761c-4d38-a798-63c58704665e
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/29/2020 08:15:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Název chybujícího modulu: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Kód výjimky: 0xc0000005
Posun chyby: 0x0001c132
ID chybujícího procesu: 0x11fc
Čas spuštění chybující aplikace: 0x01d69627ebb0d614
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
ID zprávy: 80852228-b0c4-4e9b-8aab-7b5625e0b4d4
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/29/2020 08:12:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: VoiceControlEngine.exe, verze: 1.0.0.4, časové razítko: 0xf2f01165
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.19041.423, časové razítko: 0x09cf3bbe
Kód výjimky: 0xe0434352
Posun chyby: 0x00129962
ID chybujícího procesu: 0x1dbc
Čas spuštění chybující aplikace: 0x01d696277977341f
Cesta k chybující aplikaci: C:\Program Files (x86)\MSI\One Dragon Center\VoiceControl\VoiceControlEngine.exe
Cesta k chybujícímu modulu: C:\Windows\System32\KERNELBASE.dll
ID zprávy: 4206d8cb-a80d-4bff-b2a1-419f1300a1f3
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/29/2020 08:12:16 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: VoiceControlEngine.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.Net.Sockets.SocketException
na System.Net.Sockets.Socket.DoBind(System.Net.EndPoint, System.Net.SocketAddress)
na System.Net.Sockets.Socket.Bind(System.Net.EndPoint)
na System.Net.Sockets.TcpListener.Start(Int32)
na VoiceControlEngine.WebSocketServer.Start()
na VoiceControlEngine.MainWindow..ctor()

Informace o výjimce: System.Windows.Markup.XamlParseException
na System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri)
na System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri)
na System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean)
na System.Windows.Application.LoadBamlStreamWithSyncInfo(System.IO.Stream, System.Windows.Markup.ParserContext)
na System.Windows.Application.LoadComponent(System.Uri, Boolean)
na System.Windows.Application.DoStartup()
na System.Windows.Application.<.ctor>b__1_0(System.Object)
na System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
na System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
na System.Windows.Threading.DispatcherOperation.InvokeImpl()
na System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object)
na MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object)
na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
na MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object)
na System.Windows.Threading.DispatcherOperation.Invoke()
na System.Windows.Threading.Dispatcher.ProcessQueue()
na System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
na MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
na MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
na System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
na System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
na System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
na MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
na MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
na System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
na System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
na System.Windows.Application.RunDispatcher(System.Object)
na System.Windows.Application.RunInternal(System.Windows.Window)
na System.Windows.Application.Run(System.Windows.Window)
na VoiceControlEngine.App.Main()

Error: (09/28/2020 05:43:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Název chybujícího modulu: atkexComSvc.exe, verze: 1.0.0.1, časové razítko: 0x5cac59e5
Kód výjimky: 0xc0000005
Posun chyby: 0x0001c132
ID chybujícího procesu: 0x110c
Čas spuštění chybující aplikace: 0x01d695ae0b7cda92
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\AXSP\4.00.38\atkexComSvc.exe
ID zprávy: b0bfd11c-2217-4a48-ae05-8f7813018180
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (09/30/2020 12:54:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby asComSvc bylo dosaženo časového limitu (60000 ms).

Error: (09/30/2020 12:54:34 PM) (Source: volmgr) (EventID: 46) (User: )
Description: Inicializace výpisu stavu systému se nezdařila.

Error: (09/30/2020 12:54:06 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\system32\IntelIHVRouter08.dll

Error: (09/30/2020 12:54:06 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\system32\IntelIHVRouter08.dll

Error: (09/30/2020 12:54:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\system32\IntelIHVRouter08.dll

Error: (09/30/2020 12:54:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba VoiceControlService byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/30/2020 12:54:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (09/30/2020 12:54:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Realtek Audio Universal Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.


Windows Defender:
===================================
Date: 2020-09-29 13:08:33.3240000Z
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6C8A0C9A-881E-4BF7-B820-FC8A1E198CDC}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2020-09-22 14:46:19.0800000Z
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {8C549616-55A3-4377-9B81-933978AAA5A0}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2020-09-21 17:48:01.0660000Z
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {5DF55FDB-DF9D-44D7-A299-B560349A9721}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2020-09-21 16:02:04.8410000Z
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6448A304-962C-48E5-9D1B-D9D9D7CC3A7F}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2020-09-21 14:36:13.2250000Z
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {F1B98F45-D598-4FF7-A593-B787D468C13E}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2020-09-30 11:31:24.9950000Z
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.323.2178.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.17400.5
Kód chyby: 0x80240438
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

CodeIntegrity:
===================================

Date: 2020-09-30 13:04:50.7960000Z
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-30 13:03:56.6900000Z
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-30 12:56:48.5080000Z
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-30 12:56:48.4230000Z
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-30 12:56:47.8350000Z
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-09-30 12:56:46.8890000Z
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-30 12:55:40.6540000Z
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-30 12:55:06.8970000Z
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 1.30 09/07/2020
Motherboard: Micro-Star International Co., Ltd. MAG X570 TOMAHAWK WIFI (MS-7C84)
Processor: AMD Ryzen 3 3100 4-Core Processor
Percentage of memory in use: 13%
Total physical RAM: 32689.86 MB
Available physical RAM: 28378.32 MB
Total Virtual: 32689.86 MB
Available Virtual: 26712.37 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.3 GB) (Free:43.85 GB) NTFS
Drive d: (Disk D) (Fixed) (Total:1757.81 GB) (Free:1250.03 GB) NTFS
Drive f: (16.0.12527.20482) (CDROM) (Total:3.28 GB) (Free:0 GB) UDF

\\?\Volume{0b1e30c3-b314-408e-8c7b-37d53ac45524}\ () (Fixed) (Total:0.49 GB) (Free:0.08 GB) NTFS
\\?\Volume{ca14aff6-cf34-43e6-aa98-7a0bcf3d26ba}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==================== End of Addition.txt =======================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divně se chovající PC

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rill
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 30 zář 2020 11:03

Re: Divně se chovající PC

#3 Příspěvek od Rill »

# -------------------------------
# Malwarebytes AdwCleaner 8.0.7.0
# -------------------------------
# Build: 07-22-2020
# Database: 2020-09-29.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-30-2020
# Duration: 00:00:00
# OS: Windows 10 Pro
# Cleaned: 0
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1489 octets] - [29/09/2020 08:20:52]
AdwCleaner[C00].txt - [1641 octets] - [29/09/2020 08:21:12]
AdwCleaner[S01].txt - [1527 octets] - [29/09/2020 08:23:22]
AdwCleaner[S02].txt - [1588 octets] - [30/09/2020 11:26:29]
AdwCleaner[S03].txt - [1649 octets] - [30/09/2020 12:52:52]
AdwCleaner[S04].txt - [1710 octets] - [30/09/2020 12:53:39]
AdwCleaner[C04].txt - [1900 octets] - [30/09/2020 12:54:01]
AdwCleaner[S05].txt - [1832 octets] - [30/09/2020 13:35:17]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C05].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divně se chovající PC

#4 Příspěvek od Rudy »

Toto je OK. Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\MountPoints2: {b3fc5501-f3f8-11ea-b047-14f6d8175a47} - "E:\HiSuiteDownLoader.exe"
ShortcutTarget: GIGABYTE AORUS GRAPHICS ENGINE.lnk -> D:\Program Files\GIGABYTE\AORUS ENGINE\autorun.exe (No File)
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
FirewallRules: [{B3A6BAC8-3996-477F-B441-F3EF12A09A61}] => (Allow) D:\Program Files\ZWCAD 2017\ZwCrashReportManagement.exe => No File
FirewallRules: [{53807745-DFD9-4573-9ED7-D19A87E75A1E}] => (Allow) D:\Program Files\ZWCAD 2017\ZwCrashReportManagement.exe => No File
FirewallRules: [{A17506F3-BC9D-4F43-B030-D6C2448870F1}] => (Allow) D:\Program Files\ZWCAD 2017\ZWErrorDialog.exe => No File
FirewallRules: [{684B07A4-8A4F-4503-810A-E792C86F24BA}] => (Allow) D:\Program Files\ZWCAD 2017\ZWErrorDialog.exe => No File
FirewallRules: [{897ACC14-07C3-4309-9171-2E8E26C96225}] => (Allow) D:\Program Files\ZWCAD 2017\ZwSyble.exe => No File
FirewallRules: [{B9D73C55-2FBE-4018-81EF-E02AFAE0AA22}] => (Allow) D:\Program Files\ZWCAD 2017\ZwSyble.exe => No File
FirewallRules: [{945D41B1-252B-4BB1-9A05-38FC3E144002}] => (Allow) D:\Program Files\ZWCAD 2017\XXX => No File
FirewallRules: [{117492E6-AE54-427C-8B3D-AE2D6A1B00B5}] => (Allow) D:\Program Files\ZWCAD 2017\XXX => No File

EmptyTemp:
Hosts:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rill
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 30 zář 2020 11:03

Re: Divně se chovající PC

#5 Příspěvek od Rill »

Fix result of Farbar Recovery Scan Tool (x64) Version: 30-09-2020
Ran by wlady (30-09-2020 17:05:08) Run:1
Running from C:\Users\wlady\Desktop
Loaded Profiles: wlady
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKU\S-1-5-21-741997079-567957087-574048465-1001\...\MountPoints2: {b3fc5501-f3f8-11ea-b047-14f6d8175a47} - "E:\HiSuiteDownLoader.exe"
ShortcutTarget: GIGABYTE AORUS GRAPHICS ENGINE.lnk -> D:\Program Files\GIGABYTE\AORUS ENGINE\autorun.exe (No File)
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
FirewallRules: [{B3A6BAC8-3996-477F-B441-F3EF12A09A61}] => (Allow) D:\Program Files\ZWCAD 2017\ZwCrashReportManagement.exe => No File
FirewallRules: [{53807745-DFD9-4573-9ED7-D19A87E75A1E}] => (Allow) D:\Program Files\ZWCAD 2017\ZwCrashReportManagement.exe => No File
FirewallRules: [{A17506F3-BC9D-4F43-B030-D6C2448870F1}] => (Allow) D:\Program Files\ZWCAD 2017\ZWErrorDialog.exe => No File
FirewallRules: [{684B07A4-8A4F-4503-810A-E792C86F24BA}] => (Allow) D:\Program Files\ZWCAD 2017\ZWErrorDialog.exe => No File
FirewallRules: [{897ACC14-07C3-4309-9171-2E8E26C96225}] => (Allow) D:\Program Files\ZWCAD 2017\ZwSyble.exe => No File
FirewallRules: [{B9D73C55-2FBE-4018-81EF-E02AFAE0AA22}] => (Allow) D:\Program Files\ZWCAD 2017\ZwSyble.exe => No File
FirewallRules: [{945D41B1-252B-4BB1-9A05-38FC3E144002}] => (Allow) D:\Program Files\ZWCAD 2017\XXX => No File
FirewallRules: [{117492E6-AE54-427C-8B3D-AE2D6A1B00B5}] => (Allow) D:\Program Files\ZWCAD 2017\XXX => No File

EmptyTemp:
Hosts:
End
*****************

Processes closed successfully.
HKU\S-1-5-21-741997079-567957087-574048465-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3fc5501-f3f8-11ea-b047-14f6d8175a47} => removed successfully
"D:\Program Files\GIGABYTE\AORUS ENGINE\autorun.exe" => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B3A6BAC8-3996-477F-B441-F3EF12A09A61}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{53807745-DFD9-4573-9ED7-D19A87E75A1E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A17506F3-BC9D-4F43-B030-D6C2448870F1}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{684B07A4-8A4F-4503-810A-E792C86F24BA}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{897ACC14-07C3-4309-9171-2E8E26C96225}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B9D73C55-2FBE-4018-81EF-E02AFAE0AA22}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{945D41B1-252B-4BB1-9A05-38FC3E144002}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{117492E6-AE54-427C-8B3D-AE2D6A1B00B5}" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8937472 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 201745328 B
Java, Flash, Steam htmlcache => 394792396 B
Windows/system/drivers => 11132468 B
Edge => 830375 B
Chrome => 0 B
Firefox => 0 B
Opera => 384213999 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 9056866 B
LocalService => 9056866 B
NetworkService => 9208226 B
wlady => 425509209 B

RecycleBin => 0 B
EmptyTemp: => 1.4 GB temporary data Removed.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divně se chovající PC

#6 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rill
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 30 zář 2020 11:03

Re: Divně se chovající PC

#7 Příspěvek od Rill »

Vypadá to v normě. To přeskakování zmizelo a to zaplnění RAM nějakou dobu trvá, než se zaplní. Po vypnutí všech aplikací zaplnění sice o něco klesne, ale něco to stále vytěžuje.
Zkusil jsem nové ovladače desky (LAN, zvuk), grafiky... Ale stále jsem na to nepřišel. Každopádně děkuji a zasílám příspěvěk na chod fóra :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divně se chovající PC

#8 Příspěvek od Rudy »

Za příspěvek děkujeme :) Který proces nevíce zatěžuje RAM?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rill
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 30 zář 2020 11:03

Re: Divně se chovající PC

#9 Příspěvek od Rill »

Kromě prohlížeče tam není nic, co by si bralo nějak hodně, ale těch procesů je cca 200 a když se to nasčítá, vezme si to třeba 20GB. Dnes mám spuštěnou Operu, tak to není tak hrozné, ale jinak používám Vivaldi a mám otevřených cca 5 oken. K tomu nějaká hra a po několika hodinách se to vyšplhá třeba až na 25GB, stalo se, že i Vivaldi spadlo, aby se uvolnila RAM. Myslím, že to rozhodně není normální stav. Zatím jsem na to nepřišel, čím by to mohlo být.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divně se chovající PC

#10 Příspěvek od Rudy »

O který prohlížeč jde? Zkusíme ho přeinstalovat.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rill
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 30 zář 2020 11:03

Re: Divně se chovající PC

#11 Příspěvek od Rill »

Nejvíc používám Vivaldi, Operu mám jako náhradní. Mám ho tedy zkusit odinstalovat a nainstalovat nový?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divně se chovající PC

#12 Příspěvek od Rudy »

Přesně tak. Tento prohlížeč neznám, patří k tzv. exotickému sw. Běžné prohlížeče se reinstalují se zálohou a smazáním nastavení v profilu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rill
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 30 zář 2020 11:03

Re: Divně se chovající PC

#13 Příspěvek od Rill »

Je to prohlížeč od tvůrců původní Opery, používám ho cca dva roky a dost jsem si ho oblíbil. Provedl jsem odinstalování a novou instalaci, tak uvidím, jak to bude fungovat.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divně se chovající PC

#14 Příspěvek od Rudy »

OK, nechám to tu otevřené.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět