
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-04-2025
Ran by frost (administrator) on LAPTOP-JBRVN3F9 (LENOVO 81BV) (05-04-2025 18:01:25)
Running from C:\Users\frost\Desktop\FRST64.exe
Loaded Profiles: frost
Platform: Microsoft Windows 11 Home Version 24H2 26100.3476 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <4>
(DriverStore\FileRepository\igdlh64.inf_amd64_6d34ac0763025a06\igfxCUIService.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6d34ac0763025a06\igfxEM.exe
(explorer.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <5>
(explorer.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <34>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_25044.2208.3471.2155_x64__8wekyb3d8bbwe\ms-teams.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_d372a4ea3b959b1c\aesm_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0a3294d3216a4a83\jhi_service.exe
(services.exe ->) (Intel(R) Online Connect -> Intel Corporation) C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe
(services.exe ->) (Intel(R) Online Connect Access -> Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6d34ac0763025a06\igfxCUIService.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6d34ac0763025a06\IntelCpHDCPSvc.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6d34ac0763025a06\IntelCpHeciSvc.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(services.exe ->) (LENOVO -> Lenovo) C:\Windows\System32\ymc.exe
(services.exe ->) (McAfee, LLC -> McAfee, Inc.) C:\Program Files\mcafee\WebAdvisor\servicehost.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_18.2503.1198.0_x64__8wekyb3d8bbwe\WebViewHost.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25022.57.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2509.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.296.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.5100.40.0_x64__cw5n1h2txyewy\WidgetBoard.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (SweetLabs Inc -> SweetLabs, Inc) C:\Users\frost\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18382824 2017-08-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LVA] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493992 2017-08-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493992 2017-08-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493992 2017-08-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [APP] => C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe [999216 2017-04-28] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [455976 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-676903284-4003579358-1577344595-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\frost\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [87577920 2025-04-05] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-676903284-4003579358-1577344595-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\frost\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-676903284-4003579358-1577344595-1001\...\RunOnce: [Uninstall 25.041.0303.0002\i386] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\frost\AppData\Local\Microsoft\OneDrive\25.041.0303.0002\i386" [0 2025-04-05] () <==== ATTENTION [zero byte File/Folder]
HKU\S-1-5-21-676903284-4003579358-1577344595-1001\...\RunOnce: [Uninstall 25.041.0303.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\frost\AppData\Local\Microsoft\OneDrive\25.041.0303.0002" [0 2025-04-05] () <==== ATTENTION [zero byte File/Folder]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\134.0.6998.179\Installer\chrmstp.exe [2025-04-01] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files\AVAST Software\Browser\Application\133.0.29113.143\Installer\chrmstp.exe [2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {3A3D7D64-C4FC-4EAD-8716-12388001445A} - System32\Tasks\App Explorer => C:\Users\frost\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [8875296 2024-09-10] (SweetLabs Inc -> SweetLabs, Inc) <==== ATTENTION
Task: {02D34073-2B6B-445E-A5E9-5CA91594B646} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3738496 2025-03-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {F087988E-68A7-4270-8226-92C8D6F77C96} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3738496 2025-03-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {DBA12989-1E8C-4377-A53A-690D4733D2D0} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [8594216 2025-03-27] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {6C657120-987A-45EA-B411-6641FAC7C2A2} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5293864 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {E9DA3383-7042-47E4-BE26-806062B7F3DF} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2564904 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {AC4DF60D-92DF-4943-9D3C-C931059614D3} - System32\Tasks\AvastBrowserProtectS-1-5-21-676903284-4003579358-1577344595-1001 => C:\Program Files\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1690008 2025-03-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {DEA6CF81-4679-437F-A326-B89F2C06D8B3} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {FF76CE82-C918-43F2-B0F8-7A6BD8554F2D} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {B55D48EE-FF0C-42B8-B107-367B942E363A} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem136.0.7079.0{B4E143C0-A387-44B6-B611-56236E67E86B} => C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\updater.exe [7017568 2025-03-20] (Google LLC -> Google LLC)
Task: {D89693B1-FDC0-4F12-857C-36609FE73AC1} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2017-06-20] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {B9E7F88B-511D-44B3-B2C2-D80A9FF14C6F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2017-06-20] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {59FD38CD-EF77-4039-8187-952349736C85} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2017-06-20] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {AFD8C0B4-04C1-4FCC-9E26-69A000AD9105} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2250472 2017-06-20] (Intel(R) Client Connectivity Division SW -> Intel Corporation) -> C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalServiceStart
Task: {F3DD2D20-09F9-4D83-8088-47FBD595A435} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => C:\WINDOWS\system32\sc.exe [102400 2025-04-02] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files (x86)\Intel\Thunderbolt Software\\start ThunderboltService
Task: {AC4CDDBA-1F26-41B4-8A86-8F1B66F9303F} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 => C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-12-21] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {6ED0DF23-88DE-476A-BC47-87F8AE7A19FA} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon => C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-12-21] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {AF9C78DB-95C6-4917-A6DD-6D70B3792A9D} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {429495E9-746C-4049-9718-9851DF71710B} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [94496 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {69E6AE1E-6DB5-4C41-9F3C-767DCE0C635E} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => C:\WINDOWS\system32\sc.exe [102400 2025-04-02] (Microsoft Windows -> Microsoft Corporation) -> START ImControllerService
Task: {5F412E8D-D531-4B44-9C05-251CA6FB9E22} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => C:\WINDOWS\System32\reg.exe [110592 2025-04-02] (Microsoft Windows -> Microsoft Corporation) -> add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {578BF0A6-A2CA-4AC2-9805-9D38F3269205} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\6425d98b-f694-4833-9a56-8d5dcf02b50b => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {4F39C8CA-4021-424C-80F1-3283D4D45E78} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\86220c72-8401-4910-9107-5886ebd4f315 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {C24469BF-D201-427D-A775-B56C1275C6FD} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\98ceae96-9e43-4a56-90d2-2ffe6dca103d => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {7B3A1229-523F-487C-8B93-FF301B93D474} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\ada41752-eb7f-4561-a1d8-43862d9a570b => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {53BC1918-C778-4970-BFB8-816C24C530D9} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\df35f897-a8a4-4e06-baf7-955c7cd42727 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {28D78A84-A7B8-4195-8223-E7F3BCEE8661} - System32\Tasks\Microsoft\Office\Office Apps Prewarm => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [223864 2025-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {CC5AB87A-F1A0-4920-8836-7C586DD017E6} - System32\Tasks\Microsoft\Office\Office Apps Prewarm Recurring => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [223864 2025-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {198BB6B0-3B61-4FFA-A224-36D25B831F05} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28895464 2025-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {7C869DD1-706A-40F1-A2C0-27C51E268D2B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28895464 2025-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {82AF27C4-70C9-474C-A91B-70208CDFFA64} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [223864 2025-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {D3A34BD0-5A75-4253-A7EF-8AADFF7D52AF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [223864 2025-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {02E0A684-EC74-4AC9-93EF-B6D0D65313C5} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe [72896 2025-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {4338904F-BDAC-42F4-8987-0F4DB50CA6D4} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (No File)
Task: {5C505926-3C79-4785-9101-E5C723A4CDBA} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (No File)
Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe RebootDialog (No File)
Task: {4CC9745D-D891-463A-8BA4-E9918C6BA000} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC ReadyToReboot (No File)
Task: {F4E19356-FC93-4526-AB87-38E029F6F218} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery ReadyToReboot (No File)
Task: {40581C0F-CE77-437A-81AE-DB398578C3F6} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe Display (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {04099E9D-B7C5-4F64-9F2D-8D5E7D4E2B59} - System32\Tasks\OneDrive Startup Task-S-1-5-21-676903284-4003579358-1577344595-1001 => C:\Users\frost\AppData\Local\Microsoft\OneDrive\25.046.0310.0005\OneDriveLauncher.exe [673600 2025-04-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {D836A0FE-3D60-49C9-A942-7A7E2E2E077F} - System32\Tasks\Zoner.Updater.S-1-5-21-676903284-4003579358-1577344595-1001 => C:\ProgramData\Zoner\Zoner.Installer.Core\updater.exe [1609528 2025-03-31] (ZONER a.s. -> ZONER a.s.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.138
Tcpip\..\Interfaces\{5ffd5bc0-2f2f-4708-ad6d-d8a46880aa8c}: [DhcpNameServer] 10.0.1.138
Tcpip\..\Interfaces\{5ffd5bc0-2f2f-4708-ad6d-d8a46880aa8c}: [DhcpDomain] home
Tcpip\..\Interfaces\{a901f015-c0a9-4d74-9596-b724b4efe3a5}: [DhcpNameServer] 150.206.1.2
Edge:
=======
Edge DefaultProfile: Profile 2
Edge Profile: C:\Users\frost\AppData\Local\Microsoft\Edge\User Data\Profile 2 [2025-04-04]
Edge Extension: (Dokumenty Google offline) - C:\Users\frost\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-03]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\frost\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-12]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2019-07-07]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-12-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1697.6\npAvastBrowserUpdate3.dll [2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1697.6\npAvastBrowserUpdate3.dll [2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\frost\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-01-13]
CHR Profile: C:\Users\frost\AppData\Local\Google\Chrome\User Data\Profile 1 [2025-04-05]
CHR Notifications: Profile 1 -> hxxps://cvokdum071bc739l60gg.steadychainconnection.co.in; hxxps://cvoke7m071bc739l6f90.steadychainconnection.co.in; hxxps://mf3vnxzxfvqna3.steadychainconnection.co.in; hxxps://teams.microsoft.com; hxxps://www.facebook.com; hxxps://www.youtube.com
CHR StartupUrls: Profile 1 -> "hxxps://www.facebook.com/","hxxp://email.cz/"," ... ge-creator"
CHR Extension: (Sloučit PDF online) - C:\Users\frost\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ehbfcoenegfhpnnmkoaimmmlhikfccli [2025-03-31]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (McAfee® WebAdvisor) - C:\Users\frost\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2025-03-31]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Dokumenty Google offline) - C:\Users\frost\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-31]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (EPUBReader) - C:\Users\frost\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jhhclmfgfllimlhabjkgkeebkbiadflb [2025-04-01]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\frost\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-01-13]hxxps://clients2.google.com/service/update2/crx
CHR Profile: C:\Users\frost\AppData\Local\Google\Chrome\User Data\System Profile [2022-09-24]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 0200431743757269mcinstcleanup; C:\ProgramData\McInstTemp0200431743757269\mcinst.exe [941448 2019-08-14] (McAfee, LLC. -> McAfee, LLC.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7500072 2025-04-05] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [807208 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2478376 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [859432 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2025-04-05] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 AvastSecureBrowserElevationService; C:\Program Files\AVAST Software\Browser\Application\133.0.29113.143\elevation_service.exe [2207056 2025-03-23] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2025-04-05] (Avast Software s.r.o. -> AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13768912 2025-03-10] (Microsoft Corporation -> Microsoft Corporation)
R2 Dolby DAX API Service; C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe [212784 2017-04-28] (Dolby Laboratories, Inc. -> )
R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
R3 Intel(R) Online Connect; C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe [575216 2017-05-10] (Intel(R) Online Connect -> Intel Corporation)
S2 Intel(R) Online Connect Helper; C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe [306928 2017-05-10] (Intel(R) Online Connect -> Intel Corporation)
S3 Intel(R) Online Connect Software Asset Manager; C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-12-21] (Intel(R) Software Asset Manager -> Intel Corporation)
R2 Intel(R) TechnologyAccessService; C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe [395000 2017-04-28] (Intel(R) Online Connect Access -> Intel(R) Corporation)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [899264 2019-07-15] (McAfee, LLC -> McAfee, Inc.)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpDefenderCoreService.exe [1968320 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\NisSrv.exe [4464024 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MsMpEng.exe [270040 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 YMC; C:\WINDOWS\System32\ymc.exe [66384 2017-06-18] (LENOVO -> Lenovo)
S3 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe" [X]
S2 mfemms; "C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe" [X]
S3 mfevtp; "C:\Windows\system32\mfevtps.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [20536 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [248376 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [393296 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [296528 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [84560 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [28280 2025-04-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [37944 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [282680 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [553528 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [98872 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [69688 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [942672 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1427512 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [207440 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [391760 2025-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [278960 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R1 ndisrd; C:\WINDOWS\system32\DRIVERS\ndisrfl.sys [50776 2017-03-06] (Intel(R) Online Connect Access -> Intel Corporation)
R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2019-07-16] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [20016 2025-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [601520 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R0 WinSetupMon; C:\WINDOWS\System32\DRIVERS\WinSetupMon.sys [169440 2025-03-05] (Microsoft Windows -> Microsoft Corporation)
S0 cfwids; system32\drivers\cfwids.sys [X]
R0 mfeaack; system32\drivers\mfeaack.sys [X]
R0 mfeavfk; system32\drivers\mfeavfk.sys [X]
S0 mfeelamk; system32\drivers\mfeelamk.sys [X]
S0 mfefirek; system32\drivers\mfefirek.sys [X]
R0 mfehidk; system32\drivers\mfehidk.sys [X]
R0 mfeplk; system32\drivers\mfeplk.sys [X]
R0 mfewfpk; system32\drivers\mfewfpk.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-05 18:01 - 2025-04-05 18:01 - 000032409 _____ C:\Users\frost\Desktop\FRST.txt
2025-04-05 18:01 - 2025-04-05 18:01 - 000000000 ____D C:\FRST
2025-04-05 17:59 - 2025-04-05 17:59 - 002097152 _____ (Farbar) C:\Users\frost\Downloads\FRST (1).exe
2025-04-05 17:56 - 2025-04-05 17:56 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (8).exe
2025-04-05 17:56 - 2025-04-05 17:56 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (7).exe
2025-04-05 17:56 - 2025-04-05 17:56 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (6).exe
2025-04-05 17:56 - 2025-04-05 17:56 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (5).exe
2025-04-05 17:56 - 2025-04-05 17:56 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (4).exe
2025-04-05 17:56 - 2025-04-05 17:56 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (3).exe
2025-04-05 17:56 - 2025-04-05 17:56 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (2).exe
2025-04-05 17:55 - 2025-04-05 17:55 - 002404864 _____ (Farbar) C:\Users\frost\Downloads\FRST64 (1).exe
2025-04-05 17:55 - 2025-04-05 17:55 - 002097152 _____ (Farbar) C:\Users\frost\Downloads\FRST.exe
2025-04-05 17:54 - 2025-04-05 17:54 - 002404864 _____ (Farbar) C:\Users\frost\Desktop\FRST64.exe
2025-04-05 17:38 - 2025-04-05 17:38 - 000002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2025-04-05 17:38 - 2025-04-05 17:38 - 000002488 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2025-04-05 17:38 - 2025-04-05 17:38 - 000000000 ____D C:\Users\frost\AppData\Roaming\Avast Software
2025-04-05 17:33 - 2025-04-05 17:38 - 000000000 ____D C:\Users\frost\AppData\Local\AVAST Software
2025-04-05 17:33 - 2025-04-05 17:33 - 000003844 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2025-04-05 17:33 - 2025-04-05 17:33 - 000003810 _____ C:\WINDOWS\system32\Tasks\AvastBrowserProtectS-1-5-21-676903284-4003579358-1577344595-1001
2025-04-05 17:33 - 2025-04-05 17:33 - 000003510 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineUA
2025-04-05 17:33 - 2025-04-05 17:33 - 000003386 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineCore
2025-04-05 17:33 - 2025-04-05 17:33 - 000003260 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2025-04-05 17:33 - 2025-04-05 17:33 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2025-04-05 17:32 - 2025-04-05 17:38 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-04-05 17:32 - 2025-04-05 17:33 - 000000000 ____D C:\Program Files\Avast Software
2025-04-05 17:32 - 2025-04-05 17:32 - 000316200 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2025-04-05 17:32 - 2025-04-05 17:32 - 000002209 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2025-04-05 17:32 - 2025-04-05 17:32 - 000002197 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2025-04-05 17:32 - 2025-04-05 17:32 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-04-05 17:32 - 2025-04-05 17:31 - 000055064 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2025-04-05 17:31 - 2025-04-05 17:32 - 000000000 ____D C:\ProgramData\Avast Software
2025-04-05 17:31 - 2025-04-05 17:31 - 000249072 _____ (Gen Digital Inc.) C:\Users\frost\Downloads\online_instalační_soubor_aplikace_avast_free_antivirus (3).exe
2025-04-05 17:31 - 2025-04-05 17:31 - 000249072 _____ (Gen Digital Inc.) C:\Users\frost\Downloads\online_instalační_soubor_aplikace_avast_free_antivirus (2).exe
2025-04-05 17:31 - 2025-04-05 17:31 - 000249072 _____ (Gen Digital Inc.) C:\Users\frost\Downloads\online_instalační_soubor_aplikace_avast_free_antivirus (1).exe
2025-04-05 17:30 - 2025-04-05 17:30 - 000249072 _____ (Gen Digital Inc.) C:\Users\frost\Downloads\online_instalační_soubor_aplikace_avast_free_antivirus.exe
2025-04-04 11:01 - 2025-04-04 11:01 - 000000000 ____D C:\ProgramData\McInstTemp0200431743757269
2025-04-04 10:17 - 2025-04-04 10:17 - 000714490 _____ C:\WINDOWS\system32\perfh005.dat
2025-04-04 10:17 - 2025-04-04 10:17 - 000153652 _____ C:\WINDOWS\system32\perfc005.dat
2025-04-03 09:38 - 2025-04-04 10:17 - 001692324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-03 09:35 - 2025-04-03 09:35 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2025-04-03 09:33 - 2025-04-03 09:33 - 000000020 ___SH C:\Users\frost\ntuser.ini
2025-04-03 01:12 - 2025-04-03 09:33 - 000000000 ____D C:\Windows.old
2025-04-03 01:09 - 2025-04-03 01:12 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2025-04-03 01:08 - 2025-04-03 01:09 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-04-03 01:08 - 2025-04-03 01:08 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-04-03 01:06 - 2025-04-03 01:06 - 000000000 ____D C:\WINDOWS\Windows.SystemToast.PresenceSensing.OnlookerDetection
2025-04-03 01:06 - 2025-04-03 01:06 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-03 01:04 - 2025-04-03 01:04 - 000070484 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-04-03 01:04 - 2025-04-03 01:04 - 000070484 _____ C:\WINDOWS\system32\ctac.json
2025-04-03 01:04 - 2025-04-03 01:04 - 000005264 _____ C:\WINDOWS\system32\ecoscore_config.json
2025-04-03 01:04 - 2025-04-03 01:04 - 000000998 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-04-03 01:03 - 2025-04-03 01:03 - 000027617 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-03 01:03 - 2025-04-03 01:03 - 000027617 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\WINDOWS\addins
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\Program Files\MSBuild
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-04-03 01:00 - 2025-04-03 01:00 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-04-03 00:57 - 2025-04-03 01:10 - 000000000 ____D C:\WINDOWS\system32\Intel
2025-04-03 00:57 - 2025-04-03 00:57 - 000000000 ____D C:\WINDOWS\system32\cAVS
2025-04-03 00:57 - 2025-04-03 00:57 - 000000000 ____D C:\WINDOWS\Lenovo
2025-04-03 00:18 - 2025-04-05 10:06 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-676903284-4003579358-1577344595-1001
2025-04-03 00:18 - 2025-04-05 10:06 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-676903284-4003579358-1577344595-1001
2025-04-03 00:18 - 2025-04-05 10:06 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-676903284-4003579358-1577344595-1001
2025-04-03 00:18 - 2025-04-05 10:00 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-04-03 00:18 - 2025-04-05 10:00 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-04-03 00:18 - 2025-04-04 11:08 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2025-04-03 00:18 - 2025-04-04 10:13 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-03 00:18 - 2025-04-03 00:18 - 000003162 _____ C:\WINDOWS\system32\Tasks\Zoner.Updater.S-1-5-21-676903284-4003579358-1577344595-1001
2025-04-03 00:18 - 2025-04-03 00:18 - 000003074 _____ C:\WINDOWS\system32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7
2025-04-03 00:18 - 2025-04-03 00:18 - 000003042 _____ C:\WINDOWS\system32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2025-04-03 00:18 - 2025-04-03 00:18 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-676903284-4003579358-1577344595-500
2025-04-03 00:18 - 2025-04-03 00:18 - 000002708 _____ C:\WINDOWS\system32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon
2025-04-03 00:18 - 2025-04-03 00:18 - 000002408 _____ C:\WINDOWS\system32\Tasks\App Explorer
2025-04-03 00:18 - 2025-04-03 00:18 - 000000000 ____D C:\WINDOWS\system32\Tasks\Lenovo
2025-04-03 00:18 - 2025-04-03 00:18 - 000000000 ____D C:\WINDOWS\system32\Tasks\Intel
2025-04-03 00:18 - 2025-04-03 00:18 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-04-03 00:18 - 2025-04-03 00:18 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2025-04-03 00:18 - 2020-09-27 09:59 - 000003394 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1523831307-1528709374-2172491333-500
2025-04-03 00:17 - 2025-04-03 00:17 - 000000000 ____D C:\Users\frost\AppData\Roaming\Microsoft\SystemCertificates
2025-04-03 00:17 - 2025-04-03 00:17 - 000000000 ____D C:\Users\frost\AppData\Roaming\Microsoft\Network
2025-04-03 00:17 - 2025-04-03 00:17 - 000000000 ____D C:\Users\frost\AppData\Roaming\Microsoft\Crypto
2025-04-03 00:17 - 2025-04-03 00:17 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2025-04-03 00:16 - 2025-04-04 10:13 - 000000438 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-03 00:14 - 2025-04-03 09:33 - 000000000 ____D C:\Users\frost
2025-04-03 00:14 - 2025-04-03 00:17 - 000000000 ____D C:\Users\frost\AppData\Roaming\Microsoft\Windows
2025-04-03 00:14 - 2025-04-03 00:15 - 000000000 ____D C:\Users\frost\AppData\Roaming\Microsoft\Spelling
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Šablony
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Soubory cookie
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Poslední
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Okolní tiskárny
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Okolní síť
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Nabídka Start
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Dokumenty
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Documents\Obrázky
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Documents\Hudba
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Documents\Filmy
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\Data aplikací
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2025-04-03 00:14 - 2025-04-03 00:14 - 000000000 _SHDL C:\Users\frost\AppData\Local\Data aplikací
2025-04-03 00:13 - 2025-04-03 00:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2025-04-03 00:13 - 2025-04-03 00:13 - 000000000 ____D C:\Program Files\Dolby
2025-04-03 00:13 - 2025-04-03 00:13 - 000000000 ____D C:\Program Files\Common Files\Dolby
2025-04-03 00:12 - 2025-04-05 15:38 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-04-03 00:12 - 2025-04-03 00:12 - 000473360 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-02 12:12 - 2025-04-02 23:31 - 000006464 _____ C:\Users\frost\Downloads\Jenny a Pandora po letech.odt
2025-04-01 22:03 - 2025-04-01 22:03 - 000000000 ____D C:\Users\frost\Desktop\Nová složka
2025-04-01 21:50 - 2025-04-01 21:50 - 003470031 _____ C:\Users\frost\Downloads\Dvur_kridel_a_zmaru (2).epub
2025-04-01 21:50 - 2025-04-01 21:50 - 003470031 _____ C:\Users\frost\Downloads\Dvur_kridel_a_zmaru (1).epub
2025-04-01 21:48 - 2025-04-01 21:48 - 003470031 _____ C:\Users\frost\Downloads\Dvur_kridel_a_zmaru.epub
2025-04-01 03:38 - 2025-04-05 09:59 - 000000000 ___DC C:\WINDOWS\Panther
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-05 17:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-05 17:37 - 2019-02-12 20:47 - 000000000 ____D C:\Users\frost\AppData\Roaming\Microsoft\Word
2025-04-05 17:36 - 2019-01-01 22:39 - 000000000 ____D C:\Users\frost\AppData\Local\Packages
2025-04-05 17:35 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-05 17:35 - 2021-10-09 22:58 - 000000000 ____D C:\Users\frost\AppData\Local\D3DSCache
2025-04-05 17:32 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-04-05 15:39 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-05 15:39 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-05 15:38 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-05 10:06 - 2023-07-04 13:03 - 000002384 _____ C:\Users\frost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-05 10:06 - 2020-09-27 09:53 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-05 10:06 - 2020-09-27 09:53 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-04-05 10:06 - 2019-01-01 22:41 - 000000000 ___RD C:\Users\frost\OneDrive
2025-04-05 10:02 - 2019-01-01 22:36 - 000000000 ____D C:\Users\frost\AppData\Local\Host App Service
2025-04-05 09:59 - 2019-01-01 22:39 - 000000000 __SHD C:\Users\frost\IntelGraphicsProfiles
2025-04-04 11:34 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-04 11:08 - 2024-04-01 09:21 - 000008192 _____ C:\WINDOWS\system32\config\ELAM
2025-04-04 11:08 - 2017-10-22 01:20 - 000000000 ____D C:\ProgramData\McAfee
2025-04-04 11:02 - 2019-04-04 19:28 - 000000000 ____D C:\Program Files\McAfeeDashboard
2025-04-04 11:01 - 2017-10-22 01:20 - 000000000 ____D C:\Program Files\Common Files\mcafee
2025-04-04 10:43 - 2020-09-27 09:55 - 000000000 ____D C:\ProgramData\Packages
2025-04-04 10:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ServiceState
2025-04-04 10:13 - 2020-09-27 07:50 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-03 23:56 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-04-03 12:03 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\appcompat
2025-04-03 09:48 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-04-03 09:34 - 2020-05-12 10:57 - 000000000 ____D C:\Users\frost\AppData\Local\PlaceholderTileLogoFolder
2025-04-03 09:33 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Windows NT
2025-04-03 09:33 - 2020-09-27 09:55 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-04-03 01:12 - 2024-04-01 09:29 - 000000000 ____D C:\WINDOWS\Setup
2025-04-03 01:12 - 2024-04-01 09:26 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\spool
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\NDF
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\IME
2025-04-03 01:12 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-04-03 01:12 - 2022-05-07 12:14 - 000000000 ____D C:\WINDOWS\system32\Hydrogen
2025-04-03 01:12 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2025-04-03 01:12 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2025-04-03 01:12 - 2021-10-08 14:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2025-04-03 01:12 - 2020-02-17 04:06 - 000000000 ____D C:\WINDOWS\system32\%ProgramData%
2025-04-03 01:12 - 2019-07-09 01:40 - 000000000 ____D C:\Program Files\UNP
2025-04-03 01:12 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2025-04-03 01:12 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2025-04-03 01:12 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2025-04-03 01:12 - 2017-10-22 01:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbolt™ Software
2025-04-03 01:12 - 2017-10-22 01:13 - 000000000 ____D C:\Program Files\Intel
2025-04-03 01:11 - 2024-04-01 09:26 - 000000000 __RHD C:\Users\Public\Libraries
2025-04-03 01:10 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-03 01:10 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\schemas
2025-04-03 01:10 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Resources
2025-04-03 01:10 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Help
2025-04-03 01:10 - 2023-04-23 18:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
2025-04-03 01:10 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2025-04-03 01:10 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2025-04-03 01:10 - 2017-10-22 01:17 - 000000000 ____D C:\Program Files\Realtek
2025-04-03 01:06 - 2024-04-01 18:31 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2025-04-03 01:06 - 2024-04-01 18:31 - 000028898 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2025-04-03 01:06 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-04-03 01:06 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-04-03 01:06 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-03 01:06 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-03 01:06 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-04-03 01:06 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\WUModels
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-plocm
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-ploc
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\et-EE
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Com
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\am-ET
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-03 01:06 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-04-03 01:06 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-04-03 01:04 - 2024-04-01 09:22 - 000063064 _____ (Microsoft Corporation) C:\WINDOWS\system32\HalExtIntcLpioDMA.dll
2025-04-03 01:04 - 2024-04-01 09:22 - 000062952 _____ (Microsoft Corporation) C:\WINDOWS\system32\HalExtIntcPseDMA.dll
2025-04-03 01:04 - 2024-04-01 09:22 - 000062944 _____ (Microsoft Corporation) C:\WINDOWS\system32\HalExtPL080.dll
2025-04-03 01:01 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\OCR
2025-04-03 01:00 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2025-04-03 01:00 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\MUI
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\system32\winrm
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\system32\WCN
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\system32\slmgr
2025-04-03 00:59 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2025-04-03 00:59 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files (x86)\Windows Defender
2025-04-03 00:18 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-04-03 00:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Registration
2025-04-03 00:16 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-03 00:16 - 2019-02-05 20:47 - 000023020 _____ C:\WINDOWS\system32\emptyregdb.dat
2025-04-03 00:15 - 2019-01-01 22:43 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-03 00:15 - 2019-01-01 22:43 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-04-03 00:14 - 2024-04-01 09:26 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
2025-04-03 00:14 - 2017-10-22 01:15 - 000000000 ___HD C:\Intel
2025-04-03 00:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-04-03 00:13 - 2017-10-22 01:17 - 000312687 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2025-04-03 00:13 - 2017-10-22 01:17 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2025-04-03 00:13 - 2017-10-22 01:17 - 000000000 ____D C:\WINDOWS\system32\DAX3
2025-04-03 00:13 - 2017-10-22 01:17 - 000000000 ____D C:\WINDOWS\system32\DAX2
2025-04-03 00:13 - 2017-10-22 01:15 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2025-04-03 00:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2025-04-01 21:42 - 2019-02-12 20:47 - 000000000 ____D C:\Users\frost\AppData\Roaming\Microsoft\Office
2025-04-01 03:33 - 2020-09-27 09:51 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-03-31 21:22 - 2020-09-27 15:21 - 000000000 ____D C:\ProgramData\Zoner
2025-03-31 15:23 - 2020-09-27 15:22 - 000001566 _____ C:\Users\frost\AppData\Roaming\Microsoft\Windows\Start Menu\Zoner Photo Studio X.lnk
2025-03-31 15:14 - 2019-01-30 22:17 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-03-31 15:13 - 2019-01-30 22:17 - 209365816 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-03-31 13:48 - 2017-10-22 00:57 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================