Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

"preventivni" kontrola

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Skaal
Návštěvník
Návštěvník
Příspěvky: 87
Registrován: 24 črc 2007 19:14

"preventivni" kontrola

#1 Příspěvek od Skaal »

Dobrý den, prosím o preventivní kontrolu, ntb ztrácí výkon a nevím jestli je to stářím, přeplněností nebo něčím horším. Děkuji.

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <3>
(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\AVAST Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(C:\Program Files\McAfee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(cmd.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <35>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\CCleanerBrowserCrashHandler.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\CCleanerBrowserCrashHandler64.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(services.exe ->) (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(services.exe ->) (Gemalto, Inc. -> SafeNet, Inc.) C:\Program Files (x86)\Common Files\Aladdin Shared\HASP\hasplms.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9270216 2018-05-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-11-27] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [157464 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [709152 2018-03-22] (HP Inc. -> HP Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706288 2021-04-09] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [1713432 2021-09-17] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2151360 2022-02-21] (Wargaming.net Limited -> Wargaming.net)
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35888256 2022-03-10] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\Run: [CiscoMeetingDaemon] => C:\Users\David\AppData\Local\WebEx\ciscowebexstart.exe [4934984 2021-10-29] (Cisco WebEx LLC -> Cisco Webex LLC)
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4268456 2022-01-16] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\Run: [CCleanerBrowserAutoLaunch_5BA5164DD8F38CE23F51EAA85BC0ACF2] => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2744592 2022-03-21] (Piriform Software Ltd -> Piriform Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files (x86)\CCleaner Browser\Application\99.0.15283.85\Installer\chrmstp.exe [2022-04-02] (Piriform Software Ltd -> Piriform Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\99.0.4844.84\Installer\chrmstp.exe [2022-03-30] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {030A2527-1E25-4B8D-A648-675D627F96E3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe /send (No File)
Task: {0A04DACC-813E-4187-82AF-9F3B5EE5B967} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {192EAA09-0138-4AA4-BCD5-CCB14428111A} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [4992280 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
Task: {1A2B562D-F0A0-4D2D-89D0-C07985D56C79} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1930312 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2116D03E-F808-45FB-9737-6EF054281346} - System32\Tasks\CCleanerSkipUAC - David => C:\Program Files\CCleaner\CCleaner.exe [30053504 2022-03-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {257A243F-F194-4AFD-B746-A0789B8099B9} - System32\Tasks\CCleanerUpdateTaskMachineUA => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-04-02] (Piriform Software Ltd -> Piriform Software)
Task: {26D442B5-8007-43B4-95D4-BB1FC0A13E1F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [660040 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2BC2E817-88EF-414C-A010-BD5496A4243D} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2296088 2022-03-07] (Avast Software s.r.o. -> Avast Software)
Task: {323E8586-BCCA-4A5B-B52C-E9E46490568A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /taskrestart (No File)
Task: {40CAE2D2-B35B-4248-9D58-C8770D49CD21} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4668944 2018-10-14] (McAfee, Inc. -> McAfee, Inc.)
Task: {485E7C68-E1BB-4B52-AC02-47A42F69BEAD} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [660040 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {48D66572-7D28-4B41-AEBD-5C9E882D93AE} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-03-10] (Piriform Software Ltd -> Piriform)
Task: {54969A66-73CB-43BA-B13B-81FDF7E25ECA} - System32\Tasks\PostponeDeviceSetupToast_S-1-5-21-3865996780-1229757397-3250398075-1001_5 => {5ded83ef-1e99-48cf-bf83-676d2a6db408} C:\Windows\System32\oobe\UserOOBE.dll [417280 2022-03-13] (Microsoft Windows -> Microsoft Corporation)
Task: {58CD4B91-9F93-4AB9-9C1E-F4800FF2BD80} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [746056 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {595BA9E3-7557-4106-96DC-703F7402D3DC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-10] (Google Inc -> Google Inc.)
Task: {6ACEE45F-616C-4C55-AC6C-FA3BBF48C50C} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [968264 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6E730E2B-F60F-44AA-89E4-C7DD4CC81DD4} - \HP\HP CoolSense\HP CoolSense Start at Logon -> No File <==== ATTENTION
Task: {731AD808-D2AE-4CD4-A703-074D606A9E0D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519240 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {81F30E4E-DF35-4954-8D30-F471148C8398} - System32\Tasks\CCleaner Browser Heartbeat Task (Logon) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2744592 2022-03-21] (Piriform Software Ltd -> Piriform Software)
Task: {88EB102E-B353-4C22-92ED-9A23045CD6EB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - resources updates => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe /r (No File)
Task: {93151D23-4DB9-4CF8-8E86-70C112394E49} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [524360 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9B037B41-10B1-48A7-BED1-98A572DDEA10} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {9CC53E0E-BABB-43B7-B5DB-44065CE4F822} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe -task -source HPSA (No File)
Task: {9D05239D-A97F-4E5D-B147-9CB007B67E17} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /L Analysis (No File)
Task: {A293BD02-9CCA-41BC-BF71-5D62419B77A4} - System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2744592 2022-03-21] (Piriform Software Ltd -> Piriform Software)
Task: {A302F10C-32D3-467A-ADE7-8B6BB4791F25} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [746056 2018-05-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AFAB8809-9AC5-4867-86DC-8DBE79669002} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.)
Task: {B18FEF6F-8407-4286-B6FE-5FA2FA81C2E4} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {B81DDD30-587C-41A2-AA81-639EA91C2EF5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe /noreport (No File)
Task: {BD2E08D9-D274-4804-B076-1326C976B017} - System32\Tasks\CCleanerUpdateTaskMachineCore => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-04-02] (Piriform Software Ltd -> Piriform Software)
Task: {DE1B5124-12ED-48FC-BECB-4F8B58C73342} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe /u (No File)
Task: {E4B432E9-A255-4F82-99E6-4D45D90BC2B7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-10] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{83bc7085-2cec-4696-8bbe-880c656b11f1}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{f859c34c-acf1-4720-a1d2-83ff109c4592}: [DhcpNameServer] 192.168.20.30 147.231.150.2

Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default [2022-04-02]

FireFox:
========
FF DefaultProfile: w6u33map.default
FF ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\w6u33map.default [2021-03-31]
FF ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\s6lmb6qp.default-release [2022-04-02]
FF Plugin: @java.com/DTPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\dtplugin\npDeployJava1.dll [2021-06-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\plugin2\npjp2.dll [2021-06-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-03-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\npCCleanerBrowserUpdate3.dll [2022-04-02] (Piriform Software Ltd -> Piriform Software)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\npCCleanerBrowserUpdate3.dll [2022-04-02] (Piriform Software Ltd -> Piriform Software)

Chrome:
=======
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Default [2022-04-02]
CHR DownloadDir: C:\Users\David\Desktop
CHR Notifications: Default -> hxxps://app.slack.com; hxxps://kfc.cz; hxxps://meet.google.com
CHR HomePage: Default -> hxxp://google.com/iq
CHR StartupUrls: Default -> ""
CHR DefaultSearchKeyword: Default -> google.cz__
CHR Session Restore: Default -> is enabled.
CHR Extension: (Prezentace) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-11-10]
CHR Extension: (Dokumenty) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-10]
CHR Extension: (Lucidchart Diagrams) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\apboafhkiegglekeafbckfjldecefkhn [2020-05-30]
CHR Extension: (Disk Google) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-25]
CHR Extension: (YouTube) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-10]
CHR Extension: (Multi Chat - Messenger for Whatsapp) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllplfhjknghhdneiblmkolbjappecbe [2021-08-27]
CHR Extension: (Timer) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\edebbhkhcaafmolanelponjjanocpacd [2019-01-13]
CHR Extension: (Gmail Offline) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2019-01-13]
CHR Extension: (Tabulky) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-11-10]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-03-20]
CHR Extension: (Tab Suspender) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiabciakcmgepblmdkmemdbbkilneeeh [2022-02-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-03-20]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-03-11]
CHR Extension: (Cool Hodin) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\icegcmhgphfkgglbljbkdegiaaihifce [2018-11-10]
CHR Extension: (PDF to Word Converter App) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\jclipofobaadknkadkpgggmjkebddjam [2019-01-13]
CHR Extension: (Grammarly for Chrome) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2022-03-31]
CHR Extension: (Unit Convertor) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkaklafnbnpegjnlplfgadnobkgdkinf [2019-01-13]
CHR Extension: (Steambirds: Survival) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhpokmalcfjnfkjlfncgekebcojinn [2019-01-13]
CHR Extension: (Mapy Google) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2019-01-13]
CHR Extension: (Grass) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmiboiefncpfjihjdedpaoammipkilla [2018-11-10]
CHR Extension: (Graph.tk) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkhkaamdeplibnmodcgodlkghphdbahk [2019-01-13]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-02]
CHR Extension: (Psykopaint) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2019-01-13]
CHR Extension: (Gmail) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-25]
CHR Extension: (Connected Mind) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmkffmgahaepmhkhkblhopnpleeikokc [2019-01-13]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [8483920 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [564504 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [563992 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-05-27] (Avast Software s.r.o. -> AVAST Software)
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-04-02] (Piriform Software Ltd -> Piriform Software)
S3 CCleanerBrowserElevationService; C:\Program Files (x86)\CCleaner Browser\Application\99.0.15283.85\elevation_service.exe [1876832 2022-03-21] (Piriform Software Ltd -> Piriform Software)
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-04-02] (Piriform Software Ltd -> Piriform Software)
S2 ciscod.exe; C:\Program Files (x86)\Cisco\Cisco HostScan\bin\ciscod.exe [885528 2021-09-17] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
S3 CZCanSrv; C:\Program Files (x86)\Common Files\Carl Zeiss\CZCanSrv.exe [630272 2021-02-24] (Carl Zeiss Microscopy GmbH) [File not signed]
S2 F5 Networks Component Installer; C:\WINDOWS\SysWOW64\F5InstallerService.exe [581560 2021-03-01] (F5 Networks Inc -> F5 Networks, Inc.)
S2 F5FltSrv; C:\WINDOWS\SysWOW64\F5FltSrv.exe [660920 2021-03-01] (F5 Networks Inc -> F5 Networks, Inc.)
R2 hasplms; C:\Program Files (x86)\Common Files\Aladdin Shared\HASP\hasplms.exe [5730312 2020-05-29] (Gemalto, Inc. -> SafeNet, Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1075744 2017-10-11] (HP Inc. -> HP)
S2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [972936 2022-03-31] (McAfee, LLC -> McAfee, LLC)
S2 MTBService_2.1.0.8; C:\Program Files\Carl Zeiss\MTB 2011 - 2.1.0.8\MTB Server Console\MTBService.exe [20480 2013-02-15] (Carl Zeiss) [File not signed]
S2 MTBService_3.1.11.0; C:\Program Files\Carl Zeiss\MTB 2011 - 3.1.11.0\MTB Server Console\MTBService.exe [24576 2021-07-22] (Carl Zeiss) [File not signed]
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182392 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 ZoomCptService; "C:\Program Files (x86)\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\David\AppData\Roaming\Zoom"

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [50616 2021-11-24] (WDKTestCert VssAdministrator,132811656475919983 -> HP)
S3 acsock; C:\WINDOWS\system32\DRIVERS\acsock64.sys [300456 2021-09-17] (Microsoft Windows Hardware Compatibility Publisher -> Cisco Systems, Inc.)
R2 aksdf; C:\WINDOWS\system32\drivers\aksdf.sys [389560 2020-05-29] (Gemalto, Inc. -> SafeNet, Inc.)
R2 aksfridge; C:\WINDOWS\system32\drivers\aksfridge.sys [510800 2020-05-29] (Gemalto, Inc. -> SafeNet, Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [36784 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [228928 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [370752 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [252992 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [100416 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [21936 2021-09-23] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42416 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [269440 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [546320 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [108912 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83976 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [855336 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [551920 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [215920 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [318760 2022-03-24] (Avast Software s.r.o. -> AVAST Software)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-03-27] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-03-27] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 F5FltDrv; C:\WINDOWS\SysWOW64\drivers\F5FltDrv.sys [55648 2021-03-01] (F5 Networks Inc -> F5 Networks, Inc.)
S3 f5ipfw; C:\WINDOWS\system32\drivers\urfltv64.sys [44440 2021-01-07] (F5 Networks Inc -> F5 Networks, Inc.)
R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [1970104 2020-05-29] (Gemalto, Inc. -> SafeNet, Inc.)
R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [60448 2021-11-24] (WDKTestCert VssAdministrator,132811656475919983 -> HP)
S3 monectdevices; C:\WINDOWS\System32\drivers\monectdevices.sys [15768 2013-12-03] (Kasherlab Technology Inc. -> )
S3 NVHDA; C:\WINDOWS\system32\drivers\nvhda64v.sys [138584 2021-11-05] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 NVSWCFilter; C:\WINDOWS\System32\drivers\nvswcfilter.sys [26696 2018-05-02] (NVIDIA Corporation -> Windows (R) Win 7 DDK provider)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43640 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 urvpndrv; C:\WINDOWS\System32\drivers\covpnv64.sys [57736 2021-01-07] (F5 Networks Inc -> F5 Networks, Inc.)
R3 voxaldriver; C:\WINDOWS\system32\DRIVERS\voxaldriverx64.sys [55936 2019-11-16] (NCH Software Pty Ltd -> )
S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [74064 2021-09-17] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [37280 2021-11-23] (HP Inc. -> HP)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-04-02 13:15 - 2022-04-02 13:16 - 000029752 ____C C:\Users\David\Desktop\FRST.txt
2022-04-02 13:15 - 2022-04-02 13:16 - 000000000 ____D C:\FRST
2022-04-02 13:14 - 2022-04-02 13:14 - 002365440 ____C (Farbar) C:\Users\David\Desktop\FRST64.exe
2022-04-02 13:06 - 2022-04-02 13:06 - 008540344 ____C (Malwarebytes) C:\Users\David\Desktop\adwcleaner.exe
2022-04-02 13:01 - 2022-04-02 13:01 - 000003842 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Hourly)
2022-04-02 13:01 - 2022-04-02 13:01 - 000003474 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineUA
2022-04-02 13:01 - 2022-04-02 13:01 - 000003350 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineCore
2022-04-02 13:01 - 2022-04-02 13:01 - 000003258 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Logon)
2022-04-02 13:01 - 2022-04-02 13:01 - 000002470 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2022-04-02 13:01 - 2022-04-02 13:01 - 000002435 _____ C:\Users\Public\Desktop\CCleaner Browser.lnk
2022-04-02 13:01 - 2022-04-02 13:01 - 000000000 ____D C:\Users\David\AppData\Local\CCleaner Browser
2022-04-02 13:01 - 2022-04-02 13:01 - 000000000 ____D C:\ProgramData\CCleaner Browser
2022-04-02 13:01 - 2022-04-02 13:01 - 000000000 ____D C:\Program Files (x86)\CCleaner Browser
2022-04-02 12:57 - 2022-04-02 12:57 - 000004040 _____ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-3865996780-1229757397-3250398075-1001_5
2022-04-02 10:36 - 2022-04-02 10:36 - 000009131 _____ C:\Users\David\AppData\Local\recently-used.xbel
2022-04-02 10:35 - 2022-04-02 10:35 - 000096578 ____C C:\Users\David\Desktop\versions.pdf
2022-04-01 21:43 - 2022-04-01 21:43 - 000487212 ____C C:\Users\David\Desktop\monster-1-1.tif
2022-04-01 21:40 - 2022-04-01 21:41 - 099777120 ____C C:\Users\David\Desktop\monster.czi
2022-04-01 16:20 - 2022-04-02 10:03 - 000000000 ___DC C:\Users\David\Desktop\faust program
2022-04-01 14:25 - 2022-04-01 14:25 - 000000000 ___DC C:\Users\David\Desktop\ruchy
2022-03-31 10:00 - 2022-03-31 10:00 - 000000000 ____D C:\WINDOWS\system32\gf2engine
2022-03-31 03:32 - 2022-03-31 03:32 - 000047635 ____C C:\Users\David\Desktop\GA_Acquirium.6180330457925.avif
2022-03-31 00:33 - 2022-03-31 00:33 - 000000000 ____C C:\Users\David\Desktop\New Text Document.txt
2022-03-31 00:32 - 2022-03-31 00:32 - 000003688 ____C C:\Users\David\Desktop\seqdump.fas
2022-03-31 00:08 - 2022-03-31 00:08 - 000082346 ____C C:\Users\David\Desktop\perdix_tva_v1.gb
2022-03-30 17:31 - 2022-03-30 17:31 - 000000000 ___DC C:\Users\David\AppData\LocalLow\NVIDIA
2022-03-30 13:44 - 2022-03-30 13:44 - 001508117 ____C C:\Users\David\Desktop\41551_2022_864_MOESM1_ESM.pdf
2022-03-30 12:34 - 2022-04-01 23:22 - 000000000 ___DC C:\Users\David\Desktop\Tva paper
2022-03-30 11:29 - 2022-03-30 11:29 - 003544098 ____C C:\Users\David\Desktop\s41551-022-00864-8.pdf
2022-03-24 10:09 - 2022-03-24 10:09 - 000000000 ___DC C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2022-03-24 10:09 - 2022-03-24 10:09 - 000000000 ____D C:\Users\David\AppData\Local\Zoom
2022-03-24 10:02 - 2022-03-24 10:02 - 000340760 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2022-03-24 10:02 - 2022-03-24 10:02 - 000215920 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2022-03-15 02:12 - 2022-03-31 10:00 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-03-13 00:11 - 2022-03-13 00:11 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2022-03-13 00:11 - 2022-03-13 00:11 - 000011911 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-03-13 00:10 - 2022-03-13 00:10 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-03-13 00:10 - 2022-03-13 00:10 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll
2022-03-13 00:10 - 2022-03-13 00:10 - 000272896 _____ C:\WINDOWS\system32\TpmTool.exe
2022-03-13 00:02 - 2022-03-13 00:02 - 000000000 ___HD C:\$WinREAgent
2022-03-10 13:56 - 2022-04-02 13:01 - 000000000 ____D C:\WINDOWS\Minidump
2022-03-10 13:55 - 2022-03-10 13:55 - 000000112 ___SH C:\bootTel.dat

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-04-02 13:07 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-04-02 13:07 - 2018-08-26 04:03 - 000000000 ____D C:\ProgramData\NVIDIA
2022-04-02 13:03 - 2019-01-26 07:10 - 000000000 ___DC C:\Users\David\AppData\Local\D3DSCache
2022-04-02 13:01 - 2022-01-06 21:17 - 000000000 ____D C:\Program Files (x86)\Steam
2022-04-02 13:01 - 2019-01-15 20:50 - 000000000 ___DC C:\Users\David\AppData\Local\CrashDumps
2022-04-02 13:00 - 2020-03-28 10:51 - 000000000 ____D C:\Program Files\CCleaner
2022-04-02 12:56 - 2018-11-10 19:16 - 000000000 ____D C:\Program Files (x86)\Google
2022-04-02 12:56 - 2018-11-10 19:13 - 000000000 __SHD C:\Users\David\IntelGraphicsProfiles
2022-04-02 11:56 - 2019-01-07 06:26 - 000000000 ___DC C:\Users\David\AppData\Local\babl-0.1
2022-04-02 11:12 - 2021-03-31 16:05 - 000000000 ___DC C:\Users\David\AppData\LocalLow\Mozilla
2022-04-02 11:06 - 2021-12-13 22:44 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3865996780-1229757397-3250398075-1001
2022-04-02 11:06 - 2021-11-30 18:01 - 000002254 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - David
2022-04-02 11:06 - 2020-08-27 17:34 - 000003408 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-04-02 11:06 - 2020-08-27 17:34 - 000003184 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-04-02 11:06 - 2020-08-24 05:56 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-04-02 11:06 - 2020-08-24 05:56 - 000003348 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2022-04-02 11:06 - 2020-08-24 05:56 - 000003124 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2022-04-02 11:06 - 2020-08-24 05:56 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2022-04-02 11:06 - 2020-08-24 05:56 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3865996780-1229757397-3250398075-1001
2022-04-02 11:05 - 2020-08-24 05:56 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2022-04-02 10:36 - 2019-01-12 16:43 - 000000000 ___DC C:\Users\David\AppData\Local\gtk-2.0
2022-04-02 10:00 - 2020-08-24 05:47 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-04-02 09:16 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-04-02 05:05 - 2020-08-27 17:35 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-04-02 05:05 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-04-01 18:46 - 2021-06-08 19:58 - 000000000 ___DC C:\Users\David\Desktop\icy-2.1.4.0-all
2022-03-31 10:08 - 2020-08-24 05:58 - 001797014 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-03-31 10:08 - 2019-12-07 10:41 - 000753578 _____ C:\WINDOWS\system32\perfh005.dat
2022-03-31 10:08 - 2019-12-07 10:41 - 000163100 _____ C:\WINDOWS\system32\perfc005.dat
2022-03-31 10:08 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2022-03-31 10:00 - 2021-03-31 16:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-03-31 10:00 - 2020-09-13 12:56 - 000008192 ___SH C:\DumpStack.log.tmp
2022-03-31 10:00 - 2020-08-24 05:56 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-03-31 10:00 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-03-31 10:00 - 2019-12-07 05:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2022-03-31 10:00 - 2019-01-09 19:13 - 000000000 ____D C:\ProgramData\AVAST Software
2022-03-31 09:59 - 2019-01-13 17:05 - 000000000 ____D C:\VNTI Database
2022-03-30 11:51 - 2019-01-09 19:15 - 000000000 ___DC C:\Users\David\AppData\Local\AVAST Software
2022-03-30 11:25 - 2020-08-24 05:48 - 000002390 ____C C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-03-30 11:22 - 2018-11-10 19:17 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-03-27 14:37 - 2020-08-24 05:56 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2022-03-25 21:56 - 2022-02-10 09:31 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-03-25 21:56 - 2021-03-31 16:05 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-03-24 10:09 - 2020-04-23 11:50 - 000000000 ____D C:\Users\David\AppData\Roaming\Zoom
2022-03-24 10:02 - 2020-10-16 23:08 - 000269440 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2022-03-24 10:02 - 2020-04-15 17:11 - 000546320 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetHub.sys
2022-03-24 10:02 - 2019-12-07 05:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-03-24 10:02 - 2019-01-14 13:41 - 000370752 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000855336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000551920 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000318760 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000252992 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000228928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000108912 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000100416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000083976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000042416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2022-03-24 10:02 - 2019-01-09 19:15 - 000036784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2022-03-21 21:12 - 2021-11-22 01:10 - 000002080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2022-03-20 12:03 - 2022-02-11 20:31 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-03-13 21:32 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-03-13 12:10 - 2020-08-24 05:47 - 000351048 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-03-13 12:09 - 2020-08-24 05:48 - 000000000 ____D C:\Users\David
2022-03-13 12:09 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-03-13 12:09 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-03-13 12:09 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2022-03-13 12:09 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-03-13 12:09 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2022-03-13 12:09 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-03-13 12:09 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-03-13 12:09 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\servicing
2022-03-13 00:14 - 2021-01-24 05:25 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-03-13 00:10 - 2020-08-24 05:53 - 002877952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-03-13 00:02 - 2018-11-11 15:40 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-03-12 23:59 - 2018-11-11 15:40 - 145666720 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-03-11 13:02 - 2018-11-11 12:59 - 000000000 ___DC C:\Users\David\AppData\Roaming\vlc
2022-03-06 11:54 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports

==================== Files in the root of some directories ========

2022-04-02 10:36 - 2022-04-02 10:36 - 000009131 _____ () C:\Users\David\AppData\Local\recently-used.xbel
2020-03-29 10:35 - 2020-03-29 10:35 - 000000000 _____ () C:\Users\David\AppData\Local\STAR.trace

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-04-2022
Ran by David (02-04-2022 13:17:07)
Running from C:\Users\David\Desktop
Microsoft Windows 10 Home Version 21H1 19043.1586 (X64) (2020-08-24 09:56:21)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3865996780-1229757397-3250398075-500 - Administrator - Disabled)
David (S-1-5-21-3865996780-1229757397-3250398075-1001 - Administrator - Enabled) => C:\Users\David
DefaultAccount (S-1-5-21-3865996780-1229757397-3250398075-503 - Limited - Disabled)
Guest (S-1-5-21-3865996780-1229757397-3250398075-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3865996780-1229757397-3250398075-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat DC (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 22.001.20085 - Adobe)
AliView version 1.x (HKLM-x32\...\{DC75EEAA-05CC-4923-ADE4-0D84CBD25703}_is1) (Version: 1.x - Systematic Biology, Uppsala University)
Aplikace Intel® PROSet/Wireless (HKLM-x32\...\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
Audacity 2.4.2 (HKLM-x32\...\Audacity_is1) (Version: 2.4.2 - Audacity Team)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 22.2.6003 - Avast Software)
AxioCamDrivers (HKLM\...\{8859F71B-C1E2-435A-BAC4-87529EA7E275}) (Version: 1.0.4 - Carl Zeiss Microscopy GmbH)
Barvy 4.1 (HKLM\...\Barvy_is1) (Version: - Vlastimil Burian)
BIG-IP Edge Client (HKLM-x32\...\{6D4839CB-28B4-4070-8CA7-612CA92CA3D0}) (Version: 72.2021.0107.1217 - F5 Networks, Inc.)
BIG-IP Edge Client Components (All Users) (HKLM-x32\...\F5 Networks Client Components) (Version: 72.2021.0107.1217 - F5 Networks, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CanCheck (HKLM-x32\...\{D4000D0F-9072-467A-B7BD-C9A6B73CC566}) (Version: 6.09.0.2 - Carl Zeiss Microscopy GmbH)
CCleaner (HKLM\...\CCleaner) (Version: 5.91 - Piriform)
CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 99.0.15283.85 - Piriform Software)
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1208.2 - Piriform Software) Hidden
Chromas version 2.6.5 (HKLM\...\{B6EF9938-F178-44C7-8B7A-AD29D4AAFF1F}_is1) (Version: 2.6.5 - Technelysium Pty Ltd)
Cisco AnyConnect Posture Module (HKLM-x32\...\{19F4F0C0-8B20-44B8-B8AD-1FF3950D39C9}) (Version: 4.10.03104 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 4.10.03104 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\{A4076314-DE10-4FEB-A977-A3AF859B4073}) (Version: 4.10.03104 - Cisco Systems, Inc.) Hidden
Cisco Webex Meetings (HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\ActiveTouchMeetingClient) (Version: 41.9.5 - Cisco Webex LLC)
Cytoscape 3.9.1 (HKLM\...\5211-3645-3154-2580) (Version: 3.9.1 - Cytoscape Consortium)
CZCanServer (HKLM\...\{e675f0ef-4c62-46da-bb6c-055707e067fb}) (Version: 8.8.1.0 - Carl Zeiss Microscopy GmbH)
Energy Star (HKLM\...\{5CB22648-35F8-41BC-9C35-1E41FE6E12A5}) (Version: 1.1.1 - HP Inc.)
Exodus (HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\exodus) (Version: 21.1.7 - Exodus Movement Inc)
FlowJo VX (HKLM\...\FlowJo VX) (Version: 10.0.7.2 - )
GIMP 2.10.8 (HKLM\...\GIMP-2_is1) (Version: 2.10.8 - The GIMP Team)
GoldWave v6.40 (HKLM\...\GoldWave v6.40) (Version: 6.40 - GoldWave Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 99.0.4844.84 - Google LLC)
GraphPad Prism 8.0.1.244 (HKLM\...\{1D0625E1-610F-499E-BA99-CAF230096AE1}) (Version: 8.1.244 - GraphPad Software Inc.)
HP Audio Switch (HKLM-x32\...\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
HP CoolSense (HKLM-x32\...\{10F0BF3E-DBDB-422A-8C12-B4D46711D7C8}) (Version: 2.22.2 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP ePrint SW (HKLM-x32\...\{cdb5f70f-5107-4613-bf69-15de903b5b5d}) (Version: 5.5.22560 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\...\{3FC961DB-BD36-4D8D-B276-0C456A2BB638}) (Version: 1.4.0.441 - HP Inc.)
HP JumpStart Launch (HKLM-x32\...\{F213102E-FD30-4E22-AF73-4C682D65FFEE}) (Version: 1.4.441.0 - HP Inc.)
HP PC Hardware Diagnostics Windows (HKLM-x32\...\{5C591A5B-EA74-44F7-81DD-A757B5935AAD}) (Version: 1.5.0.0 - HP Inc)
HP Support Solutions Framework (HKLM-x32\...\{4E100CB6-9312-48BC-9DC0-4F4D5C338449}) (Version: 12.18.34.21 - HP Inc.)
HP System Event Utility (HKLM-x32\...\{5D308D1F-E37B-431A-8D35-67D16287467D}) (Version: 1.4.28 - HP Inc.)
Inkscape (HKLM-x32\...\Inkscape) (Version: 1.0.1- - Inkscape)
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.3.10208.5644 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1069 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 24.20.100.6344 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.9.1.1020 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000060-0200-1029-84C8-B8D95FA3C8C3}) (Version: 20.60.0 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{44ded3eb-1686-46a6-9770-fd79096c29f7}) (Version: 10.1.1.45 - Intel(R) Corporation) Hidden
Java 8 Update 291 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180291F0}) (Version: 8.0.2910.10 - Oracle Corporation)
Lasergene 7 v7.1.0 (HKLM-x32\...\Lasergene 7) (Version: - )
MEGA-X version 10.0.5 (HKLM-x32\...\{A0000B39-6F7D-4A5A-95D4-47B44B658854}_is1) (Version: 10.0.5 - iGEM)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 100.0.1185.29 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\OneDriveSetup.exe) (Version: 22.045.0227.0004 - Microsoft Corporation)
Microsoft SQL Server 2014 Express LocalDB (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{5016990D-7F61-4A20-9451-A915D6616DD9}) (Version: 3.66.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29325 (HKLM-x32\...\{33628a12-6787-4b9f-95a1-92449f69fae0}) (Version: 14.28.29325.2 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 98.0.2 (x64 cs)) (Version: 98.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 89.0 - Mozilla)
MTB2011 3.1.11.0 (HKLM\...\{367f8f66-8119-480e-8cb6-a618b14dc111}) (Version: 3.1.11.0 - Carl Zeiss Microscopy GmbH)
NVIDIA GeForce Experience 3.12.0.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.12.0.84 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.38.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.60 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 472.47 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 472.47 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.370.179 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.23.1003.2017 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8412 - Realtek Semiconductor Corp.)
SnapGene Viewer (HKLM-x32\...\SnapGene Viewer) (Version: 4.3.8 - GSL Biotech LLC)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
uc480 (HKLM-x32\...\{3F07FD73-E122-4F05-BD15-DEE3D99E5964}) (Version: 4.80 - OEMINC)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Vector NTI Suite 7.0.0.3 (HKLM-x32\...\{AC0D7292-6F88-4F44-B2E6-076A3FC4352F}) (Version: - )
VLC media player (HKLM\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Voxal Voice Changer (HKLM-x32\...\Voxal) (Version: 4.02 - NCH Software)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Wargaming.net Game Center (HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\Wargaming.net Game Center) (Version: 22.0.0.8225 - Wargaming.net)
WebAdvisor od společnosti McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.691 - McAfee, LLC)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Driver Package - Carl Zeiss Microscopy GmbH (tvmcam) Image (04/30/2011 9.2.0.0) (HKLM\...\4B1A19641FF6C68E6C4968D20DC7DDD950F259CF) (Version: 04/30/2011 9.2.0.0 - Carl Zeiss Microscopy GmbH)
Windows Driver Package - Carl Zeiss Microscopy GmbH (usbzss) ZeissCanNode (06/15/2012 1.0.0.0) (HKLM\...\4EEE4AC06A5B0B2ECC96AAA8AD8BF74B49F5D2C9) (Version: 06/15/2012 1.0.0.0 - Carl Zeiss Microscopy GmbH)
Windows Driver Package - Carl Zeiss Microscopy GmbH (WinUSB) Axiocam USB 3.0 Devices (07/05/2019 2.0.000) (HKLM\...\B1BB8D22F257BAA9E5E47EBA71BE10FA27B45F84) (Version: 07/05/2019 2.0.000 - Carl Zeiss Microscopy GmbH)
Windows Driver Package - Carl Zeiss Microscopy GmbH USBDevice (03/16/2015 1.0.000) (HKLM\...\07F87AF9FF502E14A9FAC105FBD573145694E13B) (Version: 03/16/2015 1.0.000 - Carl Zeiss Microscopy GmbH)
Windows Driver Package - libusb-win32 (libusb0) libusb-win32 devices (01/18/2012 1.2.6.0) (HKLM\...\00AE6C86D9068290DC65DBCFB142C5CD2B74AE8A) (Version: 01/18/2012 1.2.6.0 - libusb-win32)
Windows Driver Package - libusb-win32 (libusb0) libusb-win32 devices (01/18/2012 1.2.6.0) (HKLM\...\5EE2F70CD40ADEBCFF284796757BB42BDA3F6EAB) (Version: 01/18/2012 1.2.6.0 - libusb-win32)
Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation)
WinRAR 5.70 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.70.0 - win.rar GmbH)
World of Tanks EU (HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\WOT.EU.PRODUCTION) (Version: - Wargaming.net)
ZEISS Help Viewer 1.3.21089.3 (64-Bit) (HKLM\...\{0B88E0E8-B9E8-4C60-AC5C-E44D375922BB}) (Version: 1.3.21089.3 - Carl Zeiss Microscopy GmbH)
ZeissPy 21042.1 (HKLM\...\ZeissPy21042.1_is1) (Version: 21042.1 - Carl Zeiss Microscopy GmbH)
ZEN x64 (HKLM\...\{EDA2DA46-6678-47DB-AD5E-44A19E4C81D6}) (Version: 1.1.1 - Carl Zeiss Microscopy GmbH)
Zoom (HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\ZoomUMX) (Version: 5.9.7 (3931) - Zoom Video Communications, Inc.)

Packages:
=========
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.12.419.0_x64__rz1tebttyb220 [2022-02-26] (Dolby Laboratories)
Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_20.4.3.0_x64__xbfy0k16fey96 [2021-07-08] (Dropbox Inc.)
HP JumpStart -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStart_1.4.481.0_x86__v10z8vjag6ke6 [2018-08-26] (HP Inc.)
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_2.1.7098.0_neutral__w1wdnht996qgy [2018-11-10] (LinkedIn)
Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.14931.20132.0_x86__8wekyb3d8bbwe [2022-03-15] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-24] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-24] (Microsoft Corporation) [MS Ad]
Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.14931.20132.0_x86__8wekyb3d8bbwe [2022-03-15] (Microsoft Corporation)
Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.14931.20132.0_x86__8wekyb3d8bbwe [2022-03-15] (Microsoft Corporation)
Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.14931.20132.0_x86__8wekyb3d8bbwe [2022-03-15] (Microsoft Corporation)
Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.14931.20132.0_x86__8wekyb3d8bbwe [2022-03-15] (Microsoft Corporation)
Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.14931.20132.0_x86__8wekyb3d8bbwe [2022-03-15] (Microsoft Corporation)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.3171.0_x64__8wekyb3d8bbwe [2022-03-25] (Microsoft Studios) [MS Ad]
Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.14931.20132.0_x86__8wekyb3d8bbwe [2022-03-15] (Microsoft Corporation)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-03-12] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-11-14] (Microsoft Corporation)
Power Media Player 14 for HP Consumer PCs with DVD -> C:\Program Files\WindowsApps\CyberLinkCorp.hs.PowerMediaPlayer14forHPConsumerPC_14.2.9528.0_x86__06qsbagp91rvg [2019-01-27] (CYBERLINKCOM CORP)
Simple Solitaire -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.SimpleSolitaire_7.4.4.0_x64__kx24dqmazqk8j [2021-10-10] (Random Salad Games LLC)
Synaptics TouchPad -> C:\Program Files\WindowsApps\SynapticsIncorporated.SynHPConsumerDApp_19005.35054.0.0_x64__807d65c4rvak2 [2020-03-12] (Synaptics Incorporated)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3865996780-1229757397-3250398075-1001_Classes\CLSID\{1019ADC7-17CB-4489-AFD5-6642C7400ACE}\localserver32 -> C:\Users\David\AppData\Local\Webex\Webex\Applications\ptOIEx64.exe (Cisco WebEx LLC -> Cisco WebEx LLC)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-03-24] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-03-24] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-03-24] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [JRcm] -> {C20B9A7B-ED5B-4CEB-B2A6-F1F62E99C539} => -> No File
ContextMenuHandlers1: [JRcm64] -> {013BF2A8-A4B1-11DF-A865-F509E0D72085} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-03-24] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki130350.inf_amd64_696b7c6764071b63\igfxDTCM.dll [2018-12-07] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2021-10-26] (Nvidia Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-03-24] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [JRcm] -> {C20B9A7B-ED5B-4CEB-B2A6-F1F62E99C539} => -> No File
ContextMenuHandlers6: [JRcm64] -> {013BF2A8-A4B1-11DF-A865-F509E0D72085} => -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\David\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\4838af181287e456\WhatsGreen Multi Messenger.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=emipoepfakonicaobeeejombhfkbicld

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM -> {BA580274-1C14-4872-91A9-F964F4877C8A} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM-x32 -> {BA580274-1C14-4872-91A9-F964F4877C8A} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-3865996780-1229757397-3250398075-1001 -> {BA580274-1C14-4872-91A9-F964F4877C8A} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_291\bin\ssv.dll [2021-06-09] (Oracle America, Inc. -> Oracle Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2022-03-31] (McAfee, LLC -> McAfee, LLC)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_291\bin\jp2ssv.dll [2021-06-09] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2022-03-31] (McAfee, LLC -> McAfee, LLC)
DPF: HKLM-x32 {00627E89-A19D-4A2B-938B-059CB7B1B493} file://C:/Program Files (x86)/F5 VPN/F5_TMP/f5certchk.cab
DPF: HKLM-x32 {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} file://C:/Program Files (x86)/F5 VPN/F5_TMP/cachecleaner.cab
DPF: HKLM-x32 {2BCDB465-81F9-41CB-832C-8037A4064446} file://C:/Program Files (x86)/F5 VPN/F5_TMP/urxvpn.cab
DPF: HKLM-x32 {2c8ffa64-e3f7-49ae-87c2-49018fde3aea} file://C:/Program Files (x86)/F5 VPN/F5_TMP/OesisInspector.cab
DPF: HKLM-x32 {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} file://C:/Program Files (x86)/F5 VPN/F5_TMP/f5tunsrv.cab
DPF: HKLM-x32 {45B69029-F3AB-4204-92DE-D5140C3E8E74} file://C:/Program Files (x86)/F5 VPN/F5_TMP/InstallerControl.cab
DPF: HKLM-x32 {57C76689-F052-487B-A19F-855AFDDF28EE} file://C:/Program Files (x86)/F5 VPN/F5_TMP/f5InspectionHost.cab
DPF: HKLM-x32 {7E73BE8F-FD87-44EC-8E22-023D5FF960FF} file://C:/Program Files (x86)/F5 VPN/F5_TMP/vdeskctrl.cab
DPF: HKLM-x32 {A83FB16F-F96A-4724-A5B1-AC999860A218} file://C:/Program Files (x86)/F5 VPN/F5_TMP/OesisInspector.cab
DPF: HKLM-x32 {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} file://C:/Program Files (x86)/F5 VPN/F5_TMP/urxshost.cab
DPF: HKLM-x32 {E0FF21FA-B857-45C5-8621-F120A0C17FF2} file://C:/Program Files (x86)/F5 VPN/F5_TMP/urxhost.cab
DPF: HKLM-x32 {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} file://C:/Program Files (x86)/F5 VPN/F5_TMP/f5syschk.cab

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\emory.edu -> hxxps://vpn.emory.edu

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-04-11 19:38 - 2018-04-11 19:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\windows\system32;C:\windows;C:\windows\System32\Wbem;C:\windows\System32\WindowsPowerShell\v1.0\;C:\windows\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files\MEGA-X;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\David\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKLM\...\StartupApproved\Run32: => "HPMessageService"
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\StartupApproved\Run: => "Wargaming.net Game Center"
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-3865996780-1229757397-3250398075-1001\...\StartupApproved\Run: => "Steam"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{3968E7BB-5E0E-439F-B5F8-95F9BFC6DED9}] => (Allow) C:\Users\David\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [UDP Query User{93005BE4-21A4-4756-86AD-B3FF76BA6E3B}D:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [TCP Query User{2D9456B1-0FCA-4A80-8F12-4ACB215AC54A}D:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [UDP Query User{47B70DB4-6C2F-4998-8B75-F3FC987D71E8}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{3297396F-FCAC-48FC-9776-ADE69C67E927}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{5DC32868-0276-4F20-AE34-61DF1F3BF050}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{5E13EB91-023C-4F67-85F5-8161D50CE4B6}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [UDP Query User{2284FE61-5BBE-4B09-A006-3778FD9D1C5A}D:\games\world_of_tanks_eu\win32\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\win32\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [TCP Query User{B72D9071-F57C-4568-A51C-79D9D05ADF61}D:\games\world_of_tanks_eu\win32\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\win32\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [UDP Query User{F41EFAEB-51B5-4C32-99D9-49A577FA8ED6}C:\program files\flowjo vx\jre\bin\javaw.exe] => (Allow) C:\program files\flowjo vx\jre\bin\javaw.exe
FirewallRules: [TCP Query User{24D194DC-B869-41A0-95BB-5D06287BD729}C:\program files\flowjo vx\jre\bin\javaw.exe] => (Allow) C:\program files\flowjo vx\jre\bin\javaw.exe
FirewallRules: [UDP Query User{05009B4B-40D1-4C86-8B2C-A15908815F6E}C:\program files (x86)\vector nti suite 7\vector nti 7.exe] => (Allow) C:\program files (x86)\vector nti suite 7\vector nti 7.exe (InforMax, Inc.) [File not signed]
FirewallRules: [TCP Query User{8DBCCBC2-E634-4C54-9D06-177706B16001}C:\program files (x86)\vector nti suite 7\vector nti 7.exe] => (Allow) C:\program files (x86)\vector nti suite 7\vector nti 7.exe (InforMax, Inc.) [File not signed]
FirewallRules: [{75C735E7-D2C8-4C96-B1C7-C5BCAB61044B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{0640A5D2-D8AF-4EE7-B2CF-C88CAD79457A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D83D545C-D234-4C72-A91C-2B242A41A4B7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5533F2FF-8A09-41E6-A55F-617C59672BB7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A9006D21-685E-4162-97FE-1B3C567F6379}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F492B352-244A-48FC-8C59-C02934C73E76}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{05A443FA-172E-4FED-AC52-3B956B462092}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{7955A918-084C-41FC-BDF1-B4B747DFE6A3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BAB7F248-D03D-4C44-BB42-54F0CD822670}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E0DE58B2-445F-48D5-AE27-360A0A473A93}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{2270DB2B-D493-4D8E-8B6F-3C61F5330084}C:\program files (x86)\vector nti suite 7\vector nti 7.exe] => (Allow) C:\program files (x86)\vector nti suite 7\vector nti 7.exe (InforMax, Inc.) [File not signed]
FirewallRules: [UDP Query User{DC47D60D-F3C1-4685-9834-4D89B872B1A8}C:\program files (x86)\vector nti suite 7\vector nti 7.exe] => (Allow) C:\program files (x86)\vector nti suite 7\vector nti 7.exe (InforMax, Inc.) [File not signed]
FirewallRules: [TCP Query User{53040FB1-DC82-4757-BCC2-3CE4BCB9D74E}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [UDP Query User{F07053CE-3E42-4074-9707-E9858743342B}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [TCP Query User{32009963-F06E-46B5-8397-D9C05A2419B2}D:\games\world_of_tanks_eu\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [UDP Query User{96CE0321-EDFD-4782-A92D-022A22D153FE}D:\games\world_of_tanks_eu\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [TCP Query User{5E07131F-B6DD-4E5B-925E-181324D6C3D1}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [UDP Query User{D96921D1-06E0-422C-A810-4B8FF006CB13}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [TCP Query User{DC0AAA08-2838-46F8-B864-2B16515744FC}C:\program files\flowjo vx\jre\bin\javaw.exe] => (Allow) C:\program files\flowjo vx\jre\bin\javaw.exe
FirewallRules: [UDP Query User{8929B6D5-F89F-47F8-ADF4-BB5B4111D3B9}C:\program files\flowjo vx\jre\bin\javaw.exe] => (Allow) C:\program files\flowjo vx\jre\bin\javaw.exe
FirewallRules: [{E03C4A25-033D-4B0B-859C-A5DA2DCFAF7F}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{9937DBE9-6EF2-4D36-BD89-70BFCFB9B8A7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C9924654-C9B2-4029-9764-2150FC567C7C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{3510FFEF-EC8F-4191-834E-D3364C65991A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{EC1906B4-6D34-428A-9609-F0F260BFC3A8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{65A53C76-2D59-4398-9AD1-DEAFD15D6663}] => (Allow) C:\Users\David\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{CF4D82AE-9A1C-4B73-BD7C-B70EF8031E08}] => (Allow) C:\Users\David\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{CDD2FFB1-7212-416A-9FF4-B73F5CA86DA4}] => (Allow) C:\Users\David\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{ABF49522-2FAB-4632-B289-0D5F046F2D23}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{12DB7C5E-987E-4794-8706-5769D34D8281}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{ADCD0E21-E7EC-4FF9-B85E-D82B237E6061}] => (Allow) C:\Program Files (x86)\Common Files\Aladdin Shared\HASP\hasplms.exe (Gemalto, Inc. -> SafeNet, Inc.)
FirewallRules: [{AFBFF033-699E-4895-BDFF-5B441C1F6BA1}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{27F0367B-EB36-4A7A-BF48-611D74C6925B}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{1B733DD5-2887-43F8-8AFF-6E6F93D22AC4}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{54B153AF-9091-42DF-8C53-738CBC902B52}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{9E770BEA-2C13-4B6A-AE94-B3D261A5A173}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{07828CDC-32AD-4401-BC7E-AA2009CD548F}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{09A2BEC3-1998-4C2A-9A97-BCABF8E162BD}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{7B07444A-57F5-492A-A88F-66E7882109A3}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{15472166-1E2C-4875-9CBD-B6D0C58D456D}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{D2A1A065-9A45-4ABB-82C9-607B0570EB90}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{C1DCE5F2-025D-4E2D-9963-94172D5D6412}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{A32B2F3F-A0BE-48F1-9725-31B1AECD6FF9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{CEAAF5B6-1DA3-4DA2-B94E-20F4C5BB204F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{18A21409-FD0C-4F0B-8589-B48D2781DAF8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{BE273026-363D-45A7-B9D8-630CB3138E37}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades' Star\hadesstar.exe () [File not signed]
FirewallRules: [{F8A46B7C-7FAE-4B4B-B258-15BA213D0236}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades' Star\hadesstar.exe () [File not signed]
FirewallRules: [{DFF1DEDA-BD60-44B3-9E32-B3DBA84D2B7E}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{E1556980-D979-4F84-A19C-E18D24643AC4}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [TCP Query User{7FF88FF7-CAA0-4F11-8391-4E59427E0FF3}C:\program files\cytoscape_v3.9.1\cytoscape.exe] => (Allow) C:\program files\cytoscape_v3.9.1\cytoscape.exe () [File not signed]
FirewallRules: [UDP Query User{736E36E4-E9C6-448A-84A7-AB58CC1EB10A}C:\program files\cytoscape_v3.9.1\cytoscape.exe] => (Allow) C:\program files\cytoscape_v3.9.1\cytoscape.exe () [File not signed]
FirewallRules: [{491D25D2-DF32-472E-B7FC-4C086943BC2C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.14931.20132.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3F9A4040-C762-4012-9F43-0591F1670DDF}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{CE5B647B-F16F-4E71-88B6-56C92859BB30}] => (Block) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{60E2DA2E-85D1-47E9-8612-BE35580BA0D7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{DEE538DE-EE16-48C6-BDFD-3751F0BCABC6}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (Piriform Software Ltd -> Piriform Software)

==================== Restore Points =========================

31-03-2022 17:46:33 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices ============

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (04/02/2022 01:04:36 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ImageJ-win64.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 43fc

Start Time: 01d846b2bce6b601

Termination Time: 4294967295

Application Path: D:\plochy\plocha20210816\fiji-win64\Fiji.app\ImageJ-win64.exe

Report Id: 77336cd4-832e-4e4a-844b-9743b1f74814

Faulting package full name:

Faulting package-relative application ID:

Hang type: Top level window is idle

Error: (04/02/2022 12:15:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ImageJ-win64.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 2b28

Start Time: 01d846aa5e86655e

Termination Time: 4294967295

Application Path: D:\plochy\plocha20210816\fiji-win64\Fiji.app\ImageJ-win64.exe

Report Id: 55d18a68-49e8-4bde-83c2-a9386520b26d

Faulting package full name:

Faulting package-relative application ID:

Hang type: Top level window is idle

Error: (04/02/2022 11:57:32 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ImageJ-win64.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 11e4

Start Time: 01d846a9865097bd

Termination Time: 4294967295

Application Path: D:\plochy\plocha20210816\fiji-win64\Fiji.app\ImageJ-win64.exe

Report Id: 1aa0642d-10fb-432a-b7ac-fc5fae30d40d

Faulting package full name:

Faulting package-relative application ID:

Hang type: Top level window is idle

Error: (04/01/2022 10:00:21 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname LAPTOP-7R2RQFPR.local already in use; will try LAPTOP-7R2RQFPR-2.local instead

Error: (04/01/2022 10:00:21 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 LAPTOP-7R2RQFPR.local. Addr 10.0.0.199

Error: (04/01/2022 10:00:21 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 10.0.0.199:5353 16 LAPTOP-7R2RQFPR.local. AAAA 2601:00C6:8302:CC00:A083:C64E:0382:0B39

Error: (04/01/2022 10:00:21 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Resetting to Probing: 16 LAPTOP-7R2RQFPR.local. AAAA FE80:0000:0000:0000:9CC5:7A9F:B206:AAA8

Error: (04/01/2022 10:00:21 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 10.0.0.199:5353 16 LAPTOP-7R2RQFPR.local. AAAA 2601:00C6:8302:CC00:A083:C64E:0382:0B39


System errors:
=============
Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly. It has done this 1 time(s).

Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MTB2011 Server (2.1.0.8) service terminated unexpectedly. It has done this 1 time(s).

Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Zoom Sharing Service service terminated unexpectedly. It has done this 1 time(s).

Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The HPWMISVC service terminated unexpectedly. It has done this 1 time(s).

Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Event Log service terminated unexpectedly. It has done this 1 time(s).

Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Content Protection HECI Service service terminated unexpectedly. It has done this 1 time(s).

Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee WebAdvisor service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1 milliseconds: Restartovat službu.

Error: (04/02/2022 01:07:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).


CodeIntegrity:
===============
Date: 2022-04-01 22:01:13
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2022-04-01 22:00:52
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\drivers\aswVmm.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

BIOS: Insyde F.63 06/22/2018
Motherboard: HP 8422
Processor: Intel(R) Core(TM) i5-7200U CPU @ 2.50GHz
Percentage of memory in use: 67%
Total physical RAM: 8078.22 MB
Available physical RAM: 2619.74 MB
Total Virtual: 17468.87 MB
Available Virtual: 9909.11 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:118.01 GB) (Free:29.33 GB) NTFS
Drive d: (DATA) (Fixed) (Total:917.15 GB) (Free:82.29 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:14.37 GB) (Free:1.71 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{4ddff926-364a-4f20-a043-ce4626e6a119}\ (Windows RE tools) (Fixed) (Total:0.96 GB) (Free:0.37 GB) NTFS
\\?\Volume{ed4e179a-b77d-4367-baaf-1246f08892ea}\ () (Fixed) (Total:0.25 GB) (Free:0.2 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 2502AE95)

Partition: GPT.

==========================================================
Disk: 1 (Size: 119.2 GB) (Disk ID: E94BCF98)

Partition: GPT.

==================== End of Addition.txt =======================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15214
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: "preventivni" kontrola

#2 Příspěvek od JaRon »

ahoj,
- vycisti registre s CCleanerom, ak si tak neurobil
- aka je velkost adresara C:\Users\David\Desktop :???:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět