Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Spomalene PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
alfonz.flower
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 20 říj 2019 16:46

Spomalene PC

#1 Příspěvek od alfonz.flower »

Dobry den,

poprosil by som vas o kontrolu logov, PC je znacne spomalene, pritom ani RAM ani disk nebezi na vysokych hodnotach.
Pustil som FRST, nasledne ADW a na koniec opat FRST, prikladam logy.
Přílohy
Desktop.rar
(50.9 KiB) Staženo 81 x

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: Spomalene PC

#2 Příspěvek od Diallix »

Dobry den.

:arrow: Stiahnite si na plochu nastroj AdwCleaner, link. na stiahnutie tu: https://toolslib.net/downloads/finish/1/
Pred spustenim nastroja povypinajte vsetke beziace okna programov, to su vsetke beziace programy pod desktopom.
Kliknite pravym tlacidlom mysi na program -> spustit ako Administrator.
Pokracujte kliknutim na tlacidlo Prehladaj teraz (Scan now) a pockajte, kym sa system doskenuje.
Po skene nechajte oznacene vsetky chlieviky, pripadne najdene hrozieby a pokracujte v dolnom pravom rohu tlacidlom Vycistit Teraz (Clean and Repair).
Po restartovani PC sa spusti nastroj AdwCleaner, kliknite na Zobrazit soubor protokolu.
Spusti sa log, jeho obsah skopirujte sem.
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

alfonz.flower
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 20 říj 2019 16:46

Re: Spomalene PC

#3 Příspěvek od alfonz.flower »

# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-09-29.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 11-03-2020
# Duration: 00:00:20
# OS: Windows 8.1
# Scanned: 31837
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.


AdwCleaner[S00].txt - [8158 octets] - [02/11/2020 09:58:48]
AdwCleaner[C00].txt - [8065 octets] - [02/11/2020 10:07:02]
AdwCleaner[S01].txt - [1555 octets] - [02/11/2020 14:36:14]
AdwCleaner[C01].txt - [1722 octets] - [02/11/2020 14:36:26]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: Spomalene PC

#4 Příspěvek od Diallix »

Mozete sem, prosim, vlozit aktualne logy z FRST + ADDITION?

Dakujem :]]
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

alfonz.flower
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 20 říj 2019 16:46

Re: Spomalene PC

#5 Příspěvek od alfonz.flower »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2020
Ran by Kitti (administrator) on LENOVO (LENOVO 20C60044MC) (04-11-2020 10:26:55)
Running from C:\Users\Kitti\Desktop
Loaded Profiles: Kitti
Platform: Windows 8.1 (Update) (X64) Language: Slovenčina (Slovensko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\dvt-jb-lic-server\dvt-jb_licsrv.amd64.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvLaunch.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(CONDUSIV TECHNOLOGIES -> Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
(CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation - pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation-Mobile Wireless Group -> Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation-Mobile Wireless Group -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Wireless Display -> Intel) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Intel(R) Corporation) [File not signed] C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Lenovo -> Lenovo.) C:\Windows\System32\LPlatSvc.exe <2>
(Lenovo Information Products (Shenzhen) Co.,Ltd -> LENOVO INCORPORATED.) C:\Program Files\Lenovo\QuickSnipService\QuickSnipService.exe
(Lenovo Information Products (Shenzhen) Co.,Ltd -> LENOVO INCORPORATED.) C:\Program Files\Lenovo\SystemAgent\SystemAgentService.exe
(Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo) C:\Program Files (x86)\Common Files\Lenovo\LPU\Lpu.exe
(Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo) C:\Program Files\Lenovo\QuickSnipService\QuickSnipInput.exe
(LENOVO(JAPAN)LTD. -> ) C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
(LENOVO(JAPAN)LTD. -> ) C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
(LENOVO(JAPAN)LTD. -> Lenovo Group Limited) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe
(LENOVO(JAPAN)LTD. -> Lenovo Group Limited) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe
(LENOVO(JAPAN)LTD. -> Lenovo Group Limited) C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
(Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(LENOVO(JAPAN)LTD. -> Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(LENOVO(JAPAN)LTD. -> Lenovo.) C:\Windows\System32\TpShocks.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Program Files\Synaptics\SynFP\Shared\SensorDBSynch.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Windows\System32\valWbioSyncSvc.exe
(Motorola Solutions Inc. -> Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions Inc. -> Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Opera Software AS -> Opera Software) C:\Users\Kitti\AppData\Local\Programs\Opera\assistant\browser_assistant.exe <2>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\pg_ctl.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\postgres.exe <7>
(Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) C:\Windows\RtsCM64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Validity Sensors, Inc -> Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(Validity Sensors, Inc -> Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\SwipeMonitor.exe
(Validity Sensors, Inc -> Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1804616 2015-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [RtsCM] => C:\WINDOWS\RTSCM64.EXE [140872 2013-03-21] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [7830328 2013-05-21] (Motorola Solutions Inc. -> Motorola Solutions, Inc.)
HKLM\...\Run: [TpShocks] => C:\WINDOWS\system32\TpShocks.exe [382248 2013-06-20] (LENOVO(JAPAN)LTD. -> Lenovo.)
HKLM\...\Run: [LnvMobHotspotClient] => C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [937976 2013-06-25] (LENOVO(JAPAN)LTD. -> Lenovo)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2986224 2013-07-09] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [109664 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-05-16] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [740232 2015-01-22] (Lenovo -> Lenovo)
HKLM-x32\...\Run: [PWMTRV] => C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL [6618920 2013-08-01] (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\Run: [uTorrent] => C:\Users\Kitti\AppData\Roaming\uTorrent\uTorrent.exe [2005224 2019-12-01] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\Run: [Opera Browser Assistant] => C:\Users\Kitti\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3152920 2020-10-28] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\MountPoints2: {c00353d6-cf5f-11e8-be97-a0a8cdeebc9e} - "F:\SETUP.EXE"
HKLM\...\Windows x64\Print Processors\SX450SPC: C:\Windows\System32\spool\prtprocs\x64\sx450spc.dll [33792 2009-10-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Print\Monitors\SX450S Langmon: C:\WINDOWS\system32\sx450sl6.dll [22016 2009-10-26] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.111\Installer\chrmstp.exe [2020-11-02] (Google LLC -> Google LLC)
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [181280 2017-01-25] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [181280 2017-01-25] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [158392 2017-01-25] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0312134E-18E7-46CF-9558-FE2B08F9EB59} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [4496488 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
Task: {094CD275-5C71-4753-B57E-5566CA859498} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {0CD3F400-CA2D-4DC4-8514-A4606E69B795} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939512 2020-10-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {0F6DBBD1-1FA5-490B-A482-1F43FCC689E6} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {3BD750D7-FB48-418A-B337-4F9922FB30A7} - System32\Tasks\Lenovo\LenovoDependencyVersionTask => C:\Program Files\lenovo\SystemAgent\DependencyVersion.exe [15176 2013-06-05] (Lenovo Information Products (Shenzhen) Co.,Ltd -> )
Task: {44758607-FDDB-49A4-878B-F4E87A640EF6} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [117616 2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {49FC8992-C129-486E-9CC6-811956BD0A61} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {6EBB251D-1404-439C-9720-2C73C032C29F} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [16744 2013-08-08] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo)
Task: {77B1DE84-2CCA-47B1-A233-BFB907A24E61} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe
Task: {7C645685-5FF5-4E26-9FBC-329B96C8C4F5} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1146776 2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {7CCD5822-4616-44AA-B27F-009010137202} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {7D941448-B477-4E0C-B331-DBF54D7EA3F6} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe
Task: {82CD34E4-6599-460A-AC5D-60848BAE2ED3} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [257824 2013-03-08] (Intel® Services Manager -> Intel Corporation)
Task: {82E65D8F-AFED-4E37-A078-5302D505DA28} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {8B6759EE-1C08-4B8F-955C-774AB5A6544E} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDfE067B1}
Task: {8BF61003-D7CA-435A-BAE1-0F55BDBDE0C1} - System32\Tasks\Lenovo\LenovoWarrantyChinaTask => C:\Program Files\lenovo\SystemAgent\ChinaWarrantyService.exe [35144 2013-06-05] (Lenovo Information Products (Shenzhen) Co.,Ltd -> )
Task: {A6689FA2-A7E6-44C2-91B9-804DD0182EA0} - System32\Tasks\Intel(R) Small Business Advantage\Notifier => C:\Program Files\Intel\Intel(R) Small Business Advantage\UI\SBA_Notifier.exe [27840 2013-04-10] (Intel Corporation - Business Client Platform Division -> Intel Corporation)
Task: {AC55AB50-D211-490D-8C86-DC4290B16874} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [257824 2013-03-08] (Intel® Services Manager -> Intel Corporation)
Task: {B622F51C-747F-47B4-936F-94C089B74C4B} - System32\Tasks\Lenovo\LenovoUserguidesCopy => C:\Program Files\lenovo\SystemAgent\UserguidesCopy.exe [13128 2013-06-05] (Lenovo Information Products (Shenzhen) Co.,Ltd -> )
Task: {B849E3C3-AB80-49E8-AB6C-410337327381} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1741416 2020-11-02] (Avast Software s.r.o. -> Avast Software)
Task: {BBB5725B-E66C-429D-B563-79FE4B9B5E29} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {C4594538-2AE1-4882-A6ED-802FE30EF43C} - System32\Tasks\Lenovo\LenovoMachineInformation => C:\Program Files\lenovo\SystemAgent\MachineInformation.exe [21832 2013-06-05] (Lenovo Information Products (Shenzhen) Co.,Ltd -> )
Task: {C6B56E2E-E7DA-481F-9A2C-8AF14BD46141} - System32\Tasks\Opera scheduled Autoupdate 1519024679 => C:\Users\Kitti\AppData\Local\Programs\Opera\launcher.exe [1721368 2020-10-28] (Opera Software AS -> Opera Software)
Task: {C9DCF59E-6B97-4C0C-8641-B8261089C8CA} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E}
Task: {CD3B96E1-3897-44CC-87A2-0FA08A89FD21} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-02] (Google Inc -> Google Inc.)
Task: {CEB17C1C-599B-482F-815E-02BF41747D90} - System32\Tasks\StartPowerDVDService => C:\PROGRAM FILES (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [100712 2013-06-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {CEBD46F0-C4B7-4A7A-92BB-0AEF35A56B0D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [117616 2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF7E7FD9-1D72-4257-B93E-84594DF1B165} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2986224 2013-07-09] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {D08B918C-88AC-42FC-B756-654C0BB5E2E4} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => C:\windows\system32\rundll32.exe C:\windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)"
Task: {D34018F8-7596-4186-A88F-E1845B172A82} - System32\Tasks\Opera scheduled assistant Autoupdate 1559795400 => C:\Users\Kitti\AppData\Local\Programs\Opera\launcher.exe [1721368 2020-10-28] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Kitti\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {D836176E-20B9-497B-AFF8-A9F828C0A836} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe
Task: {DB21EF32-6BA9-4118-BBC1-BC4FF48961E5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4f47-879B-29A80C355D61}
Task: {E75187C7-BB82-4413-9759-E461AF85298B} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe
Task: {F0CFAA2D-70BF-4226-ADB5-31A21ADC2084} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939512 2020-10-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {F57A437A-0D3E-446C-8250-15DD5BD6C791} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-02] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 194.1.157.28
Tcpip\..\Interfaces\{662C7CBF-6148-49CE-9A35-5457CBC1B317}: [DhcpNameServer] 192.168.100.1 194.1.157.28

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-11-02] [UpdateUrl:hxxps://sadownload.mcafee.com/products/SA/Win/xpi/webadvisor/update.json]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Plugin: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-10-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-10-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default [2020-11-03]
CHR Notifications: Default -> hxxps://www.daemon-tools.cc
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://mrdoob.com/projects/chromeexperiments/google_gravity/","hxxps://www.google.com/","hxxp://www.google.sk/"
CHR Extension: (Slides) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-18]
CHR Extension: (Docs) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-18]
CHR Extension: (Google Drive) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-02]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2016-10-02]
CHR Extension: (iPad Simulator) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\biamdeofchcbekmcakjcfnpdipmkmkbb [2016-10-02]
CHR Extension: (YouTube) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-02]
CHR Extension: (GeoGebra Classic) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2020-11-02]
CHR Extension: (Learn Italian - Molto Bene) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadgddaepklpemjojmnhgdjmmkmefihe [2016-10-02]
CHR Extension: (The Rise of Atlantis) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcmgcfmfemlhoncahhnmhinceggddcnp [2016-10-02]
CHR Extension: (Daum Equation Editor) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dinfmiceliiomokeofbocegmacmagjhe [2016-10-02]
CHR Extension: (Logarithms Table) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekflgjlkhleiegpledpmjcpaoblbaong [2016-10-02]
CHR Extension: (Sheets) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-18]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-11-02]
CHR Extension: (Google Docs Offline) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-02]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-11-02]
CHR Extension: (Wiki Search) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkpndjkfbnfjochpfomhdiddefaidnfn [2016-10-02]
CHR Extension: (Refundo Toolbar) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbjmbmcpeaglnnglogmcnhcdagdaepep [2020-11-02]
CHR Extension: (StudentBook) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiimjijildjkajollpjecaocbbjfobed [2016-10-02]
CHR Extension: (Google Keep - Notes and Lists) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2020-11-02]
CHR Extension: (Learn English) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibcmkebindgfngkjhamkkebgpjfffmjj [2016-10-02]
CHR Extension: (American/English Radio) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijfcgghijnhpmnllfnjmgecgnhmjpdli [2016-10-02]
CHR Extension: (TOEFL 5000 Words in 120 Days) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jedheaebdffklhgodepimamapjcjhgfl [2018-02-18]
CHR Extension: (MeeGenius! Children's Books) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhfhmaajajcjoijfaceafiembkmhcddc [2016-10-02]
CHR Extension: (Little Alchemy) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2016-10-02]
CHR Extension: (English Lit) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchmjdjgeenheaobgcdcmgoajknooalk [2016-10-02]
CHR Extension: (ChemReference: Periodic Table) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjpnebljmdbglkmlnijcaplhfhkhdnib [2016-10-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-05]
CHR Extension: (Scientific Calculator) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\npoipmeppdioagbkigdlnpmjphnolaog [2018-02-18]
CHR Extension: (Gmail) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-02]
CHR Extension: (Chrome Media Router) - C:\Users\Kitti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-11-03]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [8450976 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [360408 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [101536 2013-04-11] (Intel Wireless Display -> Intel)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9057136 2020-10-24] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3729512 2018-10-19] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [107792 2013-07-03] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [144416 2015-01-22] (Lenovo -> Lenovo)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [155448 2013-08-20] (Intel Corporation -> Intel Corporation)
S3 intelsba; C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [48832 2013-04-10] (Intel Corporation - Business Client Platform Division -> Intel Corporation)
R2 JetBrainsLicServerDVT; c:\dvt-jb-lic-server\dvt-jb_licsrv.amd64.exe [5762048 2018-10-09] () [File not signed]
R2 Lenovo QuickSnip Service; C:\Program Files\lenovo\QuickSnipService\QuickSnipService.exe [219976 2013-06-05] (Lenovo Information Products (Shenzhen) Co.,Ltd -> LENOVO INCORPORATED.)
R2 Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2044408 2013-07-17] (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
R2 Lenovo System Agent Service; C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe [562504 2013-06-05] (Lenovo Information Products (Shenzhen) Co.,Ltd -> LENOVO INCORPORATED.)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo(Japan)Ltd. -> Lenovo Group Limited)
S3 LnvHotSpotSvc; C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe [468984 2013-06-25] (LENOVO(JAPAN)LTD. -> Lenovo)
R2 LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [465912 2013-06-21] (LENOVO(JAPAN)LTD. -> )
R2 LPlatSvc; C:\WINDOWS\system32\LPlatSvc.exe [711248 2017-02-20] (Lenovo -> Lenovo.)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [953544 2020-11-02] (McAfee, LLC -> McAfee, LLC)
R2 postgresql-x64-9.6; C:\Program Files\PostgreSQL\9.6\bin\pg_ctl.exe [95232 2017-07-18] (PostgreSQL Global Development Group) [File not signed]
R2 QuickControlMasterSvc; C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe [59384 2013-07-16] (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
R3 QuickControlService; C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe [138232 2013-07-16] (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11787504 2018-11-13] (TeamViewer GmbH -> TeamViewer GmbH)
R2 ValBioService; C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe [24112 2013-09-05] (Validity Sensors, Inc -> Validity Sensors, Inc.)
R2 valWBFPolicyService; C:\WINDOWS\system32\valWBFPolicyService.exe [49040 2014-07-24] (Validity Sensors, Inc -> Synaptics Incorporated)
R2 valWbioSyncSvc; C:\WINDOWS\system32\valWbioSyncSvc.exe [32256 2014-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S3 AVControlCenter; "C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe" [X]
S3 LENOVO.CAMMUTE; "C:\Program Files\Lenovo\Communications Utility\cammute.exe" [X]
S2 LENOVO.MICMUTE; "C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe" [X]
S3 LENOVO.TPKNRSVC; "C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe" [X]
S3 LENOVO.TVTVCAM; "C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe" [X]
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
S3 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [X]
S2 TPHKLOAD; "C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe" [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AMPPAL; C:\WINDOWS\System32\drivers\AMPPAL.sys [164080 2013-04-09] (Intel Corporation-Mobile Wireless Group -> Windows (R) Win 7 DDK provider)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37152 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [206408 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [236112 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [195664 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [60496 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42784 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [175720 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [518664 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [109280 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84856 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [851608 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [470912 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [217336 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [326928 2020-11-02] (Avast Software s.r.o. -> AVAST Software)
R3 btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [1385272 2013-08-01] (Motorola Solutions Inc. -> Motorola Solutions, Inc.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-10-25] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-10-25] (Disc Soft Ltd -> Disc Soft Ltd)
R1 excfs; C:\WINDOWS\System32\DRIVERS\excfs.sys [25872 2013-07-03] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
R0 excsd; C:\WINDOWS\System32\DRIVERS\excsd.sys [112912 2013-07-03] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
R0 Fastboot; C:\WINDOWS\System32\DRIVERS\fastboot.sys [68128 2015-01-22] (Lenovo -> Windows (R) Win 7 DDK provider)
S3 MOSUMAC; C:\WINDOWS\system32\DRIVERS\MOSUMAC.sys [57208 2014-03-26] (WDKTestCert Alex,130389727012273971 -> ASIX Electronics Corp.)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [207256 2013-04-11] (Intel Wireless Display -> Windows (R) Win 7 DDK provider)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-11-04 10:26 - 2020-11-04 10:27 - 000035660 _____ C:\Users\Kitti\Desktop\FRST.txt
2020-11-04 10:26 - 2020-11-04 10:26 - 000000000 ____D C:\Users\Kitti\Desktop\FRST-OlderVersion
2020-11-04 09:14 - 2020-11-04 09:14 - 000000000 ___SH C:\DkHyperbootSync
2020-11-02 21:18 - 2020-11-02 21:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
2020-11-02 10:37 - 2020-11-02 10:37 - 000052121 _____ C:\Users\Kitti\Desktop\Desktop.rar
2020-11-02 10:36 - 2020-11-02 10:37 - 000000000 ____D C:\Users\Kitti\Desktop\adw
2020-11-02 10:36 - 2020-11-02 10:36 - 000000000 ____D C:\Users\Kitti\Desktop\FRST2
2020-11-02 09:57 - 2020-11-02 10:05 - 000000000 ____D C:\AdwCleaner
2020-11-02 09:57 - 2020-11-02 09:57 - 008447152 _____ (Malwarebytes) C:\Users\Kitti\Downloads\AdwCleaner.exe
2020-11-02 09:57 - 2020-11-02 09:57 - 008447152 _____ (Malwarebytes) C:\Users\Kitti\Desktop\AdwCleaner.exe
2020-11-02 09:51 - 2020-11-02 10:16 - 000000000 ____D C:\Users\Kitti\Desktop\FRST1
2020-11-02 09:23 - 2020-11-04 10:27 - 000000000 ____D C:\FRST
2020-11-02 09:23 - 2020-11-02 09:23 - 000003170 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1470621731-751767047-2422543840-1002
2020-11-02 09:23 - 2020-11-02 09:17 - 000217336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2020-11-02 09:23 - 2020-11-02 09:16 - 000175720 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2020-11-02 09:23 - 2020-11-02 09:14 - 000339552 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2020-11-02 09:22 - 2020-11-04 10:26 - 002298368 _____ (Farbar) C:\Users\Kitti\Desktop\FRST64.exe
2020-11-02 09:20 - 2020-11-02 09:21 - 002298368 _____ (Farbar) C:\Users\Kitti\Downloads\FRST64.exe
2020-11-02 09:07 - 2020-11-02 09:11 - 003189712 _____ (philandro Software GmbH) C:\Users\Kitti\Downloads\support.exe
2020-11-02 09:07 - 2020-11-02 09:11 - 003189712 _____ (philandro Software GmbH) C:\Users\Kitti\Downloads\support (5).exe
2020-11-02 09:07 - 2020-11-02 09:11 - 003189712 _____ (philandro Software GmbH) C:\Users\Kitti\Downloads\support (4).exe
2020-11-02 09:07 - 2020-11-02 09:11 - 003189712 _____ (philandro Software GmbH) C:\Users\Kitti\Downloads\support (3).exe
2020-11-02 09:07 - 2020-11-02 09:11 - 003189712 _____ (philandro Software GmbH) C:\Users\Kitti\Downloads\support (2).exe
2020-11-02 09:07 - 2020-11-02 09:11 - 003189712 _____ (philandro Software GmbH) C:\Users\Kitti\Downloads\support (1).exe
2020-11-02 08:55 - 2020-11-02 08:56 - 000002334 _____ C:\Users\Kitti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2020-11-02 08:49 - 2020-11-02 08:49 - 000004280 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1559795400

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-11-04 10:26 - 2016-11-11 22:55 - 000000000 __SHD C:\Users\Kitti\IntelGraphicsProfiles
2020-11-04 10:26 - 2016-10-02 13:59 - 000000193 _____ C:\Users\Kitti\AppData\Local\RegisteredPackageInformation.xml
2020-11-03 18:34 - 2016-10-02 23:23 - 000003598 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1470621731-751767047-2422543840-1002
2020-11-03 18:33 - 2013-08-22 07:36 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-03 18:33 - 2013-08-22 07:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-03 18:29 - 2018-02-18 23:18 - 000004058 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1519024679
2020-11-03 18:29 - 2018-02-18 23:18 - 000001388 _____ C:\Users\Kitti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prehliadač Opera.lnk
2020-11-03 18:22 - 2016-11-11 22:59 - 000000000 __RDO C:\Users\Kitti\OneDrive
2020-11-03 18:21 - 2012-07-25 23:59 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-03 17:24 - 2018-06-23 14:46 - 000017082 _____ C:\WINDOWS\system32\perfh01B.dat
2020-11-03 17:24 - 2018-06-23 14:46 - 000006132 _____ C:\WINDOWS\system32\perfc01B.dat
2020-11-03 17:24 - 2014-11-20 17:39 - 000870760 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-03 17:24 - 2013-08-22 05:36 - 000000000 ____D C:\WINDOWS\Inf
2020-11-02 21:17 - 2016-10-04 20:56 - 000030171 _____ C:\WINDOWS\SysWOW64\QuickControlService.dmp
2020-11-02 21:16 - 2018-11-13 18:42 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-11-02 21:16 - 2015-01-22 14:49 - 000000000 ____D C:\ProgramData\Validity
2020-11-02 21:16 - 2015-01-22 14:34 - 000000000 ____D C:\ProgramData\NVIDIA
2020-11-02 21:16 - 2013-08-22 06:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-02 14:44 - 2016-10-02 14:05 - 000002267 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-02 14:44 - 2016-10-02 14:05 - 000002226 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-02 14:44 - 2016-10-02 14:05 - 000002226 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-11-02 10:17 - 2018-02-18 23:15 - 000000000 ____D C:\ProgramData\AVAST Software
2020-11-02 10:09 - 2013-08-22 05:25 - 000262144 ___SH C:\WINDOWS\system32\config\BBI
2020-11-02 10:07 - 2015-01-22 14:35 - 000000000 ____D C:\Program Files\Lenovo
2020-11-02 10:07 - 2015-01-22 14:35 - 000000000 ____D C:\Program Files (x86)\Lenovo
2020-11-02 10:06 - 2018-08-12 17:41 - 000000000 ____D C:\Users\Kitti\AppData\Roaming\Lavasoft
2020-11-02 10:06 - 2018-08-12 17:41 - 000000000 ____D C:\Users\Kitti\AppData\Local\Lavasoft
2020-11-02 10:06 - 2018-08-12 17:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2020-11-02 10:06 - 2018-08-12 17:41 - 000000000 ____D C:\ProgramData\Lavasoft
2020-11-02 10:06 - 2018-08-12 17:41 - 000000000 ____D C:\Program Files (x86)\Lavasoft
2020-11-02 09:41 - 2013-08-22 07:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-02 09:33 - 2019-06-02 18:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2020-11-02 09:33 - 2015-01-22 14:58 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-11-02 09:24 - 2020-08-01 18:35 - 000518664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetHub.sys
2020-11-02 09:24 - 2018-09-23 07:47 - 000003910 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-11-02 09:17 - 2019-03-30 21:06 - 000195664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2020-11-02 09:17 - 2019-03-30 21:06 - 000060496 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2020-11-02 09:17 - 2018-09-23 07:47 - 000470912 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2020-11-02 09:17 - 2018-09-23 07:47 - 000326928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2020-11-02 09:17 - 2018-09-23 07:47 - 000084856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2020-11-02 09:16 - 2018-10-25 17:43 - 000042784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2020-11-02 09:16 - 2018-09-23 07:47 - 000109280 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2020-11-02 09:11 - 2019-03-30 21:06 - 000037152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2020-11-02 09:11 - 2018-09-23 07:47 - 000851608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2020-11-02 09:11 - 2018-09-23 07:47 - 000206408 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2020-11-02 09:09 - 2019-03-30 21:06 - 000236112 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2020-11-02 08:56 - 2016-10-02 14:04 - 000003370 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-11-02 08:55 - 2016-10-02 14:04 - 000003242 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-11-02 08:45 - 2018-11-27 19:31 - 000003962 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{E7801AE6-AFCB-45BB-B933-D0D34909525D}

==================== Files in the root of some directories ========

2017-07-23 22:26 - 2017-07-23 22:26 - 010604880 _____ (EnterpriseDB) C:\Users\Kitti\edb_pgjdbc.exe
2017-07-23 22:26 - 2017-07-23 22:26 - 017626568 _____ (EnterpriseDB) C:\Users\Kitti\edb_psqlodbc.exe
2017-07-23 22:06 - 2017-07-23 22:18 - 176400104 _____ (PostgreSQL Global Development Group) C:\Users\Kitti\postgresql_96.exe
2016-10-02 14:00 - 2018-02-18 23:29 - 000007546 _____ () C:\Users\Kitti\AppData\Roaming\AbsoluteReminder.xml
2016-10-02 13:59 - 2020-11-04 10:26 - 000000193 _____ () C:\Users\Kitti\AppData\Local\RegisteredPackageInformation.xml

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2020-11-03 17:49
==================== End of FRST.txt ========================

alfonz.flower
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 20 říj 2019 16:46

Re: Spomalene PC

#6 Příspěvek od alfonz.flower »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2020
Ran by Kitti (04-11-2020 10:28:19)
Running from C:\Users\Kitti\Desktop
Windows 8.1 (Update) (X64) (2016-11-12 06:55:06)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1470621731-751767047-2422543840-500 - Administrator - Disabled)
Guest (S-1-5-21-1470621731-751767047-2422543840-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1470621731-751767047-2422543840-1004 - Limited - Enabled)
Kitti (S-1-5-21-1470621731-751767047-2422543840-1002 - Administrator - Enabled) => C:\Users\Kitti
Majko (S-1-5-21-1470621731-751767047-2422543840-1005 - Administrator - Enabled) => C:\Users\Majko

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\uTorrent) (Version: 3.5.5.45395 - BitTorrent Inc.)
Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.3.0.1 - Absolute Software)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Aktualizácie NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.8.2432 - Avast Software)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Caesar IV (HKLM-x32\...\1460037487_is1) (Version: 2.0.0.5 - GOG.com)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.55.62 - Conexant)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.9.0.0650 - Disc Soft Ltd)
ExpressCache (HKLM\...\{6E55C9F8-138E-4128-8A9F-6464725BE98A}) (Version: 1.0.102.0 - Condusiv Technologies)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 86.0.4240.111 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.31 - Google LLC) Hidden
iCloud (HKLM\...\{DA6D808E-3629-4933-8FB3-583F9BCB0DEF}) (Version: 7.12.0.14 - Apple Inc.)
Integrated Camera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10224 - Realtek Semiconductor Corp.)
Intel Collaborative Processor Performance Control (HKLM-x32\...\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: 1.0.0.1011 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.10.1372 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4264 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 3.0.1332.1) (HKLM\...\{302600C1-6BDF-4FD1-1307-148929CC1385}) (Version: 3.1.1307.0366 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{20D9D0D9-1659-4775-992E-5F5650AD9B87}) (Version: 1.6.0.56 - Intel Corporation) Hidden
Intel(R) Update Manager (HKLM-x32\...\{608E1B9B-A2E8-4A1F-8BAB-874EB0DD25E3}) (Version: 1.0.0.36888 - Intel Corporation) Hidden
Intel(R) WiDi (HKLM\...\{AD5700DA-F9C5-432B-9927-F555204E38CE}) (Version: 4.1.52.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{12fc27dc-b637-4ebb-b424-26feff9598c5}) (Version: 16.0.4 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
IntelliJ IDEA 2017.1.5 (HKLM-x32\...\IntelliJ IDEA 2017.1.5) (Version: 171.4694.70 - JetBrains s.r.o.)
iTunes (HKLM\...\{3239AFA9-496A-4D7C-A706-E04F2173338F}) (Version: 12.9.5.7 - Apple Inc.)
Java 8 Update 101 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Java 8 Update 181 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
Java SE Development Kit 8 Update 101 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180101}) (Version: 8.0.1010.13 - Oracle Corporation)
Java SE Development Kit 8 Update 181 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180181}) (Version: 8.0.1810.13 - Oracle Corporation)
JavaFX 2.2.21 (64-bit) (HKLM\...\{1111706F-666A-4037-7777-222106464D10}) (Version: 2.2.21 - Oracle Corporation)
JavaFX 2.2.21 SDK (64-bit) (HKLM\...\{2222706F-666A-4037-7777-222106464D10}) (Version: 2.2.21 - Oracle Corporation)
Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.01 - )
Lenovo Fingerprint Manager (HKLM\...\{3CD9E377-7148-4319-A14E-B64FCA008FE9}) (Version: 4.5.132.0 - Validity Sensors, Inc.)
Lenovo Fingerprint Manager (HKLM\...\{F7AB2C19-6A27-4C75-A92A-8CC7C59E5FA2}) (Version: 4.5.132.0 - )
Lenovo Patch Utility (HKLM-x32\...\{E8F27ADF-B1ED-41AF-A7EF-D5E71778480C}) (Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Patch Utility 64 bit (HKLM\...\{49A09C2C-FFF4-478E-B397-5E0979F67F5D}) (Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.12.23 - Lenovo) Hidden
Lenovo QuickControl (HKLM-x32\...\{4855C42F-5197-4AAD-A50D-5066D2CC4647}) (Version: 1.10 - Lenovo Group Limited)
Lenovo Settings Dependency Package (HKLM\...\{3694BA2E-BE31-4B7E-886B-A0B559E69D4D}_is1) (Version: 1.2.5.8 - Lenovo Group Limited)
Lenovo Settings Mobile Hotspot (HKLM\...\{42603F7D-B08D-436B-B0D8-3E2DEF1AFD41}_is1) (Version: 1.2.0.80 - Lenovo)
Lenovo Solution Center (HKLM\...\{B73D2BF9-2C82-40A4-AFA8-32CE2E501640}) (Version: 2.2.002.00 - Lenovo Group Limited)
Lenovo Solutions for Small Business (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 2.0.32.7350 - Intel(R) Corporation)
Lenovo Solutions for Small Business Customizations (HKLM-x32\...\{AFD7B869-3B70-40C7-8983-769256BA3BD2}) (Version: 2.0.0005.00 - Lenovo Group Limited)
Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited)
Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo)
MCS783x Windows 8.x Drivers (HKLM-x32\...\{2BDD8E68-208B-45E0-BEE7-FB379FBA5D78}) (Version: 1.0.1.0 - ASIX Electronics Corporation) Hidden
MCS783x Windows 8.x Drivers (HKLM-x32\...\InstallShield_{2BDD8E68-208B-45E0-BEE7-FB379FBA5D78}) (Version: 1.0.1.0 - ASIX Electronics Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.13328.20292 - Microsoft Corporation)
Microsoft Office Professional 2016 - en-us (HKLM\...\ProfessionalRetail - en-us) (Version: 16.0.13328.20292 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\OneDriveSetup.exe) (Version: 20.169.0823.0008 - Microsoft Corporation)
Microsoft Project Standard 2013 (HKLM-x32\...\Office15.PRJSTD) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
NVIDIA Grafický ovládač 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.13328.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.13328.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.13328.20292 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.13328.20278 - Microsoft Corporation) Hidden
Opera Stable 72.0.3815.186 (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\Opera 72.0.3815.186) (Version: 72.0.3815.186 - Opera Software)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Ovládací panel NVIDIA 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 376.54 - NVIDIA Corporation) Hidden
pgJDBC 42.1.1 (HKLM-x32\...\pgJDBC 42.1.1-1) (Version: 42.1.1-1 - EnterpriseDB)
Podpora Apple aplikácií (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.)
Podpora Apple aplikácií(64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.)
PostgreSQL 9.6 (HKLM\...\PostgreSQL 9.6) (Version: 9.6 - PostgreSQL Global Development Group)
PowerDVD Create (HKLM-x32\...\InstallShield_{DE485075-8CD3-4A1E-9ABC-6412EBA44872}) (Version: 10.0 - CyberLink Corp.)
PowerDVD Create 10 (HKLM-x32\...\{D6E853EC-8960-4D44-AF03-7361BB93227C}) (Version: 10.0.1.2704 - CyberLink Corp.) Hidden
psqlODBC 09.06.0310 (HKLM\...\psqlODBC 09.06.0310-1) (Version: 09.06.0310-1 - EnterpriseDB)
RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 2.1.1.0 - Lenovo)
rcssserver3d 0.6.7 (HKLM-x32\...\rcssserver3d 0.6.7) (Version: 0.6.7 - RoboCup Soccer Server 3D Maintenance Group)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.21234 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
simspark (HKLM-x32\...\simspark) (Version: 0.2.4 - RoboCup Soccer Server 3D Maintenance Group)
SourceMonitor V3.5.6.334 (HKLM-x32\...\{6B0F5080-66F9-11D0-B63D-00A0240C90F6}_is1) (Version: 3.5.6.334 - Campwood Software)
SourceTree (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\SourceTree) (Version: 2.6.10 - Atlassian)
Spotify (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\Spotify) (Version: 1.1.3.259.g8172f63a - Spotify AB)
SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.80.99066 - SugarSync, Inc.)
TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.0.13488 - TeamViewer)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.4.27 - )
ThinkVantage Active Protection System (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.77.0.26 - Lenovo)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
WaveEditor (HKLM-x32\...\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}) (Version: 1.0.1.4514 - CyberLink Corp.) Hidden
WebAdvisor od McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.163 - McAfee, LLC)
Windows Driver Package - Intel Corporation (iaStorA) HDC (08/01/2013 12.8.0.1016) (HKLM\...\C8A921233C0C441A4E4EAABC2AB08C872FD77A6E) (Version: 08/01/2013 12.8.0.1016 - Intel Corporation)
Windows Driver Package - Lenovo 1.67.00.02 (04/17/2013 1.67.00.02) (HKLM\...\907DA143458FE258EFEB416B946DE8DF2B87A0BA) (Version: 04/17/2013 1.67.00.02 - Lenovo)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Wireshark 2.2.1 (64-bit) (HKLM-x32\...\Wireshark) (Version: 2.2.1 - The Wireshark developer community, hxxps://www.wireshark.org)

Packages:
=========
AccuWeather for Windows 8 -> C:\Program Files\WindowsApps\AccuWeather.AccuWeatherforWindows8_4.1.0.31_x64__8zz2pj9h1h1d8 [2016-11-13] (AccuWeather)
Companion -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.26.0_x86__k1h2ywk1493x8 [2016-11-13] (LENOVO INC.)
Evernote Touch -> C:\Program Files\WindowsApps\Evernote.Evernote_3.3.0.102_x86__q4d96b2w5wcc2 [2016-11-13] (Evernote)
Hry -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2014-11-21] (Microsoft Corporation) [MS Ad]
Hudba -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.6.672.0_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2016-11-13] (AMZN Mobile LLC)
Lenovo Cloud Storage by SugarSync -> C:\Program Files\WindowsApps\C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhj [2016-10-02] (SugarSync Inc.)
Lenovo QuickCast -> C:\Program Files\WindowsApps\E046963F.LenovoQuickCast_2.5.11.0_x86__k1h2ywk1493x8 [2016-11-13] (Lenovo, INC.)
Lenovo Settings -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoSettings_2.4.0.24644_x86__4642shxvsv8s2 [2016-11-13] (LENOVO INCORPORATED.)
Lenovo Support -> C:\Program Files\WindowsApps\E046963F.LenovoSupport_2.0.5.0_x86__k1h2ywk1493x8 [2016-11-13] (Lenovo, INC.)
MSN Cestovanie -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Financie -> C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.4.344_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Jedlá a nápoje -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Počasie -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe [2016-11-26] (Microsoft Corporation) [MS Ad]
MSN Správy -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Šport -> C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.345_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Zdravie a fitnes -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
Norton Studio -> C:\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.5.0.41_x86__v68kp9n051hdp [2016-11-13] (Symantec Corporation)
PowerDVD for Lenovo Think -> C:\Program Files\WindowsApps\CyberLinkCorp.th.PowerDVDforLenovoThink_4.1.731.32473_x86__m916jedk64snt [2016-11-13] (CYBERLINKCOM CORPORATION)
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c [2016-11-19] (Skype) [MS Ad]
Video -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.6.446.0_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
Zinio -> C:\Program Files\WindowsApps\ZinioLLC.Zinio_2.1.0.317_x64__0q6dqzpp40p2e [2016-11-13] (Zinio LLC)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1470621731-751767047-2422543840-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2019-05-08] (Apple Inc. -> Apple Inc.)
ContextMenuHandlers1: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2015-08-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Kitti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - Notes and Lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki

==================== Loaded Modules (Whitelisted) =============

2015-01-22 14:56 - 2013-08-01 07:42 - 000104960 _____ () [File not signed] C:\Program Files (x86)\ThinkPad\Utilities\US\PWMRT64V.DLL
2017-07-23 22:00 - 2017-07-18 14:26 - 000183296 _____ () [File not signed] C:\Program Files\PostgreSQL\9.6\bin\LIBPQ.dll
2017-07-23 22:02 - 2016-08-01 03:29 - 002264576 _____ () [File not signed] C:\Program Files\PostgreSQL\9.6\bin\libxml2.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000236032 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\NsNtfsAutoAnalyze.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000455168 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\NsNtfsBootOptimization.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000310272 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\NsNtfsTVE-Ex.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000087552 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\PrFacade.dll
2017-07-23 22:02 - 2016-01-12 02:14 - 001690490 _____ (Free Software Foundation) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\libiconv-2.dll
2017-07-23 22:02 - 2016-01-13 19:34 - 000685747 _____ (Free Software Foundation) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\libintl-8.dll
2015-01-22 14:53 - 2015-01-22 14:53 - 000348160 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\CyberLink\PowerDVD10\MSVCR71.dll
2017-07-23 22:02 - 2017-06-01 22:32 - 001660928 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\LIBEAY32.dll
2017-07-23 22:02 - 2017-06-01 22:32 - 000351744 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\SSLEAY32.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKU\S-1-5-21-1470621731-751767047-2422543840-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13-comm.msn.com/?pc=LNJB
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> DefaultScope {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_181\bin\ssv.dll [2018-10-09] (Oracle America, Inc. -> Oracle Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-11-02] (McAfee, LLC -> McAfee, LLC)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-10-09] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-11-02] (McAfee, LLC -> McAfee, LLC)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\localhost -> localhost

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 05:25 - 2019-01-12 16:53 - 000000847 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\Condusiv Technologies\ExpressCache\;C:\ProgramData\Lenovo\ReadyApps;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Kitti\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\{0f1a7bb3-1351-432e-80a0-586abe1d9364}.jpg
DNS Servers: 192.168.100.1 - 194.1.157.28
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "BTMTrayAgent"
HKLM\...\StartupApproved\Run: => "cAudioFilterAgent"
HKLM\...\StartupApproved\Run: => "ForteConfig"
HKLM\...\StartupApproved\Run: => "LnvMobHotspotClient"
HKLM\...\StartupApproved\Run32: => "PWMTRV"
HKLM\...\StartupApproved\Run32: => "IMSS"
HKLM\...\StartupApproved\Run32: => "Fastboot"
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{53C664A1-6D8D-4DB2-A9B0-45A2CFA17307}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation-Mobile Wireless Group -> )
FirewallRules: [{16C045E2-4B3B-488A-B4F6-2DDE4CD89809}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe (Intel Wireless Display -> Intel Corporation)
FirewallRules: [{E987AD0A-7BFF-49AC-BD09-E96BDBB520EB}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{2AB2721D-79AD-4894-A123-3984866C679F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{8F0A8E09-8D8B-416F-A9B0-FE74EAE91576}] => (Allow) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
FirewallRules: [{BA35AB06-3A0F-433F-BFF6-78AE8A392A5B}] => (Allow) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
FirewallRules: [{1191CC85-42F5-4DA0-9C97-76056110C9D2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{D13412ED-5192-4E29-8C5E-946897B859B6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{B7560904-4C17-4B39-9AB1-ED1774994D92}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{138596AE-7FCC-478A-A2CC-1E85064355F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8F1B5080-FE35-4D7E-BB1F-8DB301ED9291}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B3A36153-A03C-4FED-92E7-45EE4B85F4CF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{973FC60B-96B5-4AAC-869D-0B133E8D2926}] => (Allow) C:\Users\Kitti\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{F8D20480-EE3E-42F0-9A7A-476E09720B86}] => (Allow) C:\Users\Kitti\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{FC897C19-2485-4A53-8E0B-600A3D910473}C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Block) C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{722CC47A-6F40-4701-8848-6091296E31D1}C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Block) C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{0626BFD4-F495-41BE-A035-B5ACE29145F0}C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe] => (Allow) C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe (Eclipse Foundation, Inc. -> )
FirewallRules: [UDP Query User{7FC68554-F082-475D-B47C-3647D45678BA}C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe] => (Allow) C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe (Eclipse Foundation, Inc. -> )
FirewallRules: [TCP Query User{DE53752C-33F6-4F48-B49B-49B0FB6E9140}C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe] => (Allow) C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe () [File not signed]
FirewallRules: [UDP Query User{5DC466C8-72A6-4729-80A7-9B2132797A08}C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe] => (Allow) C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe () [File not signed]
FirewallRules: [TCP Query User{BBDFD981-8555-4D68-B308-B6538C01142B}C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe] => (Allow) C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe () [File not signed]
FirewallRules: [UDP Query User{E957FC7F-3B5B-4C50-8B82-2A89A4026D0C}C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe] => (Allow) C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe () [File not signed]
FirewallRules: [TCP Query User{56E72853-24C5-4309-9CCB-DF1CE2B3A0F3}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{EFE02111-C491-4BC3-B351-C98CF93A11D0}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{504AF97B-B4F8-4987-A6D6-808CE43AABAF}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{6187FCFA-2912-4747-B20B-74AE26C866C9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{5BD11A60-1090-4238-A396-85AA5BF2267F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{AEAA25CE-8706-4D68-81E3-5FFF9C09C825}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{761D2EF3-7F34-4E55-A4FD-47E0D312675A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [TCP Query User{0DACCB64-236F-4B38-AEDC-E67226671673}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{737B60C7-A242-48AF-BC1E-8FC45548C069}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{44CA60E1-66B5-40C7-8C73-3E10BB1873C2}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D50235B3-5543-4D7D-A94B-1E415C835E53}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{42A49617-16B0-4237-9C29-830991A60766}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{DF2099C7-2015-47DF-A76C-AF2878368EA1}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{143888C0-57A1-42FD-ACDB-15618FE18A4F}] => (Allow) C:\Users\Kitti\AppData\Local\Programs\Opera\71.0.3770.271\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{8AF19252-8B4C-4F6B-A183-A6ECDE5442EE}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{1D1FC30A-D228-4F00-930B-8F55B6D1A1C2}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{6D960A02-6BAB-4EA1-9B6A-FD1255BB3511}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2A7FCEF3-9702-4BC8-910F-6D8E3DB7516B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{7D5F7A01-851F-4F67-862A-7F8F7A027764}] => (Allow) C:\Users\Kitti\AppData\Local\Programs\Opera\72.0.3815.186\opera.exe (Opera Software AS -> Opera Software)

==================== Restore Points =========================

01-08-2020 17:52:37 Windows Update
02-11-2020 10:04:23 AdwCleaner_BeforeCleaning_02/11/2020_10:04:22

==================== Faulty Device Manager Devices ============

Name: IWD Bus Enumerator
Description: IWD Bus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service: iwdbus
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: ========================

Application errors:
==================
Error: (11/04/2020 09:25:28 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (11/03/2020 09:31:39 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.

Error: (11/03/2020 07:31:39 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.

Error: (11/03/2020 05:33:14 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (11/02/2020 02:33:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.

Error: (11/02/2020 09:55:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Adobe AIR Installer.exe version 18.0.0.144 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1664

Start Time: 01d6b13a3c3619c2

Termination Time: 130

Application Path: C:\Users\Kitti\AppData\Local\Temp\AIRC8DF.tmp\Adobe AIR Installer.exe

Report Id: 8b126046-1d34-11eb-bea6-a0a8cdeebc9e

Faulting package full name:

Faulting package-relative application ID:

Error: (11/02/2020 09:20:24 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.

Error: (11/02/2020 08:56:10 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0


System errors:
=============
Error: (11/03/2020 06:35:13 PM) (Source: Service Control Manager) (EventID: 7046) (User: )
Description: Nasledujúca služba sa opakovane zastavila pri reakcii na požiadavky riadenia služieb: Lenovo QuickControl Service

Informujte sa u dodávateľa služby alebo správcu systému, kde možno túto službu vypnúť, kým sa nezistí problém.

Pred vypnutím služby možno budete musieť reštartovať počítač v bezpečnom režime.

Error: (11/03/2020 06:23:00 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).

Error: (11/03/2020 05:24:23 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).

Error: (11/03/2020 05:21:26 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).

Error: (11/03/2020 05:20:56 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).

Error: (11/03/2020 05:20:26 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).

Error: (11/02/2020 09:19:07 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).

Error: (11/02/2020 09:18:36 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).


Windows Defender:
===================================
Date: 2018-09-22 15:03:16.495
Description:
Windows Defender has detected malware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid= ... terprise=0
Name: HackTool:Win32/Keygen
ID: 2147593794
Severity: Vysoká
Category: Nástroj
Path: file:_C:\Users\Kitti\Downloads\Windows 7 Loader Extreme Edition v3.503.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Kitti\AppData\Roaming\uTorrent\updates\3.5.3_44494.exe
Signature Version: AV: 1.275.1628.0, AS: 1.275.1628.0, NIS: 119.0.0.0
Engine Version: AM: 1.1.15300.6, NIS: 2.1.14600.4

Date: 2018-09-22 12:53:58.959
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {BA8154C0-53D7-4610-B05F-C97802EAED17}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-09-22 12:48:51.410
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {6AF8208C-DD86-4E60-9B95-015CF2A217AC}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-09-22 12:33:28.105
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {C1472B73-D40C-4828-84D4-9EF728297310}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-09-22 12:19:22.189
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {6C3A2D5A-C13B-4D78-A1EA-9EDB86204651}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-02-03 14:26:38.707
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 118.2.0.0
Update Source: Microsoft Malware Protection Center
Signature Type: Network Inspection System
Update Type: Full
Current Engine Version:
Previous Engine Version: 2.1.14202.0
Error code: 0x80070652
Error description: Práve prebieha iná inštalácia. Pred spustením novej inštalácie je nutné danú inštaláciu dokončiť.

Date: 2018-02-03 14:26:37.286
Description:
Windows Defender has encountered an error trying to update the engine.
New Engine Version:
Previous Engine Version: 2.1.14202.0
Error Code: 0x80070666
Error description: Už je nainštalovaná iná verzia produktu. Inštaláciu tejto verzie nemožno dokončiť. Ak chcete existujúcu verziu produktu nakonfigurovať alebo odstrániť, použite ovládací panel Pridať alebo odstrániť programy.

Date: 2018-02-03 14:26:37.286
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 118.2.0.0
Update Source: User
Signature Type: Network Inspection System
Update Type: Full
Current Engine Version:
Previous Engine Version: 2.1.14202.0
Error code: 0x80070666
Error description: Už je nainštalovaná iná verzia produktu. Inštaláciu tejto verzie nemožno dokončiť. Ak chcete existujúcu verziu produktu nakonfigurovať alebo odstrániť, použite ovládací panel Pridať alebo odstrániť programy.

Date: 2018-02-03 14:26:37.005
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Práve prebieha iná inštalácia. Pred spustením novej inštalácie je nutné danú inštaláciu dokončiť.

Date: 2018-02-03 14:26:33.772
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Práve prebieha iná inštalácia. Pred spustením novej inštalácie je nutné danú inštaláciu dokončiť.

CodeIntegrity:
===================================

Date: 2018-09-21 20:50:44.569
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-02-18 23:19:01.008
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-02-18 23:18:19.929
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-12-11 16:26:49.516
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-12-11 16:26:49.300
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-12-11 16:26:48.753
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-12-11 16:26:48.544
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-12-09 00:11:31.327
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info ===========================

BIOS: LENOVO J9ET92WW (2.12 ) 07/31/2014
Motherboard: LENOVO 20C60044MC
Processor: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz
Percentage of memory in use: 49%
Total physical RAM: 8082.58 MB
Available physical RAM: 4076 MB
Total Virtual: 9362.58 MB
Available Virtual: 5153.63 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:916.45 GB) (Free:744.96 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{996bd3b6-73e8-4e2a-8195-c69126bbf90d}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.67 GB) NTFS
\\?\Volume{484770d0-5bfe-40e0-8ed0-d3af161a22fb}\ () (Fixed) (Total:0.49 GB) (Free:0.18 GB) NTFS
\\?\Volume{241a46c0-f7a8-448b-86da-c123e9328b25}\ (Lenovo_Recovery) (Fixed) (Total:13.21 GB) (Free:2.93 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: F2FF3AE7)

Partition: GPT.

==========================================================
Disk: 1 (Size: 14.9 GB) (Disk ID: F2FF3ABE)

Partition: GPT.

==================== End of Addition.txt =======================

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: Spomalene PC

#7 Příspěvek od Diallix »

Do poznamkoveho bloku skopirujte obsah dole:

Kód: Vybrat vše

CloseProcesses:
CreateRestorePoint:

C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Bonjour
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\MountPoints2: {c00353d6-cf5f-11e8-be97-a0a8cdeebc9e} - "F:\SETUP.EXE"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {82E65D8F-AFED-4E37-A078-5302D505DA28} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {CD3B96E1-3897-44CC-87A2-0FA08A89FD21} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-02] (Google Inc -> Google Inc.)
Task: {F57A437A-0D3E-446C-8250-15DD5BD6C791} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-02] (Google Inc -> Google Inc.)
S3 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [X]
S2 TPHKLOAD; "C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe" [X]
S3 AVControlCenter; "C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe" [X]
S3 LENOVO.CAMMUTE; "C:\Program Files\Lenovo\Communications Utility\cammute.exe" [X]
S2 LENOVO.MICMUTE; "C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe" [X]
S3 LENOVO.TPKNRSVC; "C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe" [X]
S3 LENOVO.TVTVCAM; "C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe" [X]
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [X]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> DefaultScope {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
FirewallRules: [{8AF19252-8B4C-4F6B-A183-A6ECDE5442EE}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{1D1FC30A-D228-4F00-930B-8F55B6D1A1C2}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{42A49617-16B0-4237-9C29-830991A60766}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{DF2099C7-2015-47DF-A76C-AF2878368EA1}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{1191CC85-42F5-4DA0-9C97-76056110C9D2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{D13412ED-5192-4E29-8C5E-946897B859B6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{B7560904-4C17-4B39-9AB1-ED1774994D92}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{138596AE-7FCC-478A-A2CC-1E85064355F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8F1B5080-FE35-4D7E-BB1F-8DB301ED9291}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B3A36153-A03C-4FED-92E7-45EE4B85F4CF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
Task: {E75187C7-BB82-4413-9759-E461AF85298B} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe

EmptyTemp:

Poznamkovy blok ulozte pod nazvom fixlist.txt do umiestnenia kde je FRST.
Spustite FRST a odkliknite tlacidlo: Fix
Vykona sa funkcionalita po ktorej sa pocitac rebootuje. Po reboote sem vlozte obsah logu: fixlog.txt ulozeneho v umiestneni FRST.
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

alfonz.flower
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 20 říj 2019 16:46

Re: Spomalene PC

#8 Příspěvek od alfonz.flower »

Fix result of Farbar Recovery Scan Tool (x64) Version: 02-11-2020
Ran by Kitti (04-11-2020 11:14:58) Run:1
Running from C:\Users\Kitti\Desktop
Loaded Profiles: Kitti
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:

C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Bonjour
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\MountPoints2: {c00353d6-cf5f-11e8-be97-a0a8cdeebc9e} - "F:\SETUP.EXE"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {82E65D8F-AFED-4E37-A078-5302D505DA28} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {CD3B96E1-3897-44CC-87A2-0FA08A89FD21} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-02] (Google Inc -> Google Inc.)
Task: {F57A437A-0D3E-446C-8250-15DD5BD6C791} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-02] (Google Inc -> Google Inc.)
S3 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [X]
S2 TPHKLOAD; "C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe" [X]
S3 AVControlCenter; "C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe" [X]
S3 LENOVO.CAMMUTE; "C:\Program Files\Lenovo\Communications Utility\cammute.exe" [X]
S2 LENOVO.MICMUTE; "C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe" [X]
S3 LENOVO.TPKNRSVC; "C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe" [X]
S3 LENOVO.TVTVCAM; "C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe" [X]
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [X]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> DefaultScope {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
FirewallRules: [{8AF19252-8B4C-4F6B-A183-A6ECDE5442EE}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{1D1FC30A-D228-4F00-930B-8F55B6D1A1C2}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{42A49617-16B0-4237-9C29-830991A60766}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{DF2099C7-2015-47DF-A76C-AF2878368EA1}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{1191CC85-42F5-4DA0-9C97-76056110C9D2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{D13412ED-5192-4E29-8C5E-946897B859B6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{B7560904-4C17-4B39-9AB1-ED1774994D92}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{138596AE-7FCC-478A-A2CC-1E85064355F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8F1B5080-FE35-4D7E-BB1F-8DB301ED9291}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B3A36153-A03C-4FED-92E7-45EE4B85F4CF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
Task: {E75187C7-BB82-4413-9759-E461AF85298B} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe

EmptyTemp:

*****************

Processes closed successfully.
Restore point was successfully created.
C:\Program Files\Bonjour\mDNSResponder.exe => moved successfully
C:\Program Files\Bonjour => moved successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c00353d6-cf5f-11e8-be97-a0a8cdeebc9e} => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{82E65D8F-AFED-4E37-A078-5302D505DA28}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82E65D8F-AFED-4E37-A078-5302D505DA28}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\EOSNotify" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CD3B96E1-3897-44CC-87A2-0FA08A89FD21}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD3B96E1-3897-44CC-87A2-0FA08A89FD21}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F57A437A-0D3E-446C-8250-15DD5BD6C791}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F57A437A-0D3E-446C-8250-15DD5BD6C791}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
HKLM\System\CurrentControlSet\Services\SUService => removed successfully
SUService => service removed successfully
HKLM\System\CurrentControlSet\Services\TPHKLOAD => removed successfully
TPHKLOAD => service removed successfully
HKLM\System\CurrentControlSet\Services\AVControlCenter => removed successfully
AVControlCenter => service removed successfully
HKLM\System\CurrentControlSet\Services\LENOVO.CAMMUTE => removed successfully
LENOVO.CAMMUTE => service removed successfully
HKLM\System\CurrentControlSet\Services\LENOVO.MICMUTE => removed successfully
LENOVO.MICMUTE => service removed successfully
HKLM\System\CurrentControlSet\Services\LENOVO.TPKNRSVC => removed successfully
LENOVO.TPKNRSVC => service removed successfully
HKLM\System\CurrentControlSet\Services\LENOVO.TVTVCAM => removed successfully
LENOVO.TVTVCAM => service removed successfully
HKLM\System\CurrentControlSet\Services\LSCWinService => removed successfully
LSCWinService => service removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
"HKU\S-1-5-21-1470621731-751767047-2422543840-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{02A260C8-D34C-412D-9B26-F2DB90C02459} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8AF19252-8B4C-4F6B-A183-A6ECDE5442EE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1D1FC30A-D228-4F00-930B-8F55B6D1A1C2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{42A49617-16B0-4237-9C29-830991A60766}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DF2099C7-2015-47DF-A76C-AF2878368EA1}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1191CC85-42F5-4DA0-9C97-76056110C9D2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D13412ED-5192-4E29-8C5E-946897B859B6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B7560904-4C17-4B39-9AB1-ED1774994D92}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{138596AE-7FCC-478A-A2CC-1E85064355F3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8F1B5080-FE35-4D7E-BB1F-8DB301ED9291}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B3A36153-A03C-4FED-92E7-45EE4B85F4CF}" => removed successfully
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} => removed successfully
HKLM\Software\Classes\CLSID\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E75187C7-BB82-4413-9759-E461AF85298B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E75187C7-BB82-4413-9759-E461AF85298B}" => removed successfully
C:\WINDOWS\System32\Tasks\TVT\TVSUUpdateTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TVT\TVSUUpdateTask" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 23261835 B
Java, Flash, Steam htmlcache => 492 B
Windows/system/drivers => 349783926 B
Edge => 0 B
Chrome => 164238021 B
Firefox => 0 B
Opera => 20112678 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 491758 B
systemprofile32 => 491886 B
LocalService => 549102 B
NetworkService => 2361520 B
UpdatusUser => 2361520 B
Kitti => 1056913172 B
Majko => 1057001567 B

RecycleBin => 946306020 B
EmptyTemp: => 3.4 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 11:15:58 ====

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: Spomalene PC

#9 Příspěvek od Diallix »

Ako je na tom pocitac?
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

Odpovědět