==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 88.212.8.8 88.212.8.88
Tcpip\..\Interfaces\{5c362e89-8288-4ab5-958b-95c3bff238f2}: [DhcpNameServer] 88.212.8.8 88.212.8.88
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}: [DhcpNameServer] 88.212.8.8 88.212.8.88
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}\445636F6F543735334: [DhcpNameServer] 192.168.68.1
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}\4505D2C494E4B4F573733414: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}\4505D2C494E4B4F583234323: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2025-07-01]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-09-06]
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.361.2 -> C:\Program Files\Java\jre1.8.0_361\bin\dtplugin\npDeployJava1.dll [2023-01-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.361.2 -> C:\Program Files\Java\jre1.8.0_361\bin\plugin2\npjp2.dll [2023-01-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2025-06-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: ditec.sk/DAsicFac -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~1.DLL [2021-02-09] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/DitecZepDViewerFb -> C:\PROGRA~2\Ditec\DViewer\NPDITE~1.DLL [2021-02-09] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigMessageContainer -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~2.DLL [2021-02-09] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesExtender -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~3.DLL [2021-02-09] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~1.DLL [2021-09-06] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/XmlDataContainerFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~2.DLL [2021-09-06] (DITEC, a.s. -> Ditec,a.s.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2025-07-05]
CHR Notifications: Default -> hxxps://gw.lightinthebox.com; hxxps://
www.aliexpress.com
CHR Session Restore: Default -> is enabled.
CHR Extension: (Authenticator) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhghoamapcdpbohphigoooaddinpkbai [2024-08-28]
CHR Extension: (Adblock pre Youtube™) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2025-06-23]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-26]
CHR Extension: (AVG SafePrice) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2025-05-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Guest Profile [2025-06-28]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\System Profile [2024-12-24]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
Opera:
=======
OPR DefaultProfile: Opera Stable
OPR Profile: C:\Users\User\AppData\Roaming\Opera Software\Opera Stable [2024-02-01]
OPR DefaultSearchURL: Opera Stable -> hxxps://
www.google.com/search?client=opera&q={s ... utEncoding}
OPR DefaultSearchKeyword: Opera Stable -> g
OPR Extension: (Rich Hints Agent) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2023-09-22]
OPR Extension: (Opera Wallet) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\gojhcdgcpbpfigcaejpfhfegekdgiblk [2023-09-22]
OPR Extension: (Aria) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\igpdmclhhlcpoindmhkhillbfhdgoegm [2023-09-22]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
R3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1087792 2024-11-06] (Gen Digital Inc. -> Piriform Software Ltd)
R2 CloudflareWARP; C:\Program Files\Cloudflare\Cloudflare WARP\warp-svc.exe [18228128 2022-06-16] (Cloudflare, Inc. -> )
R2 dLauncherLoopback; C:\Program Files (x86)\Ditec\DLauncher\dLauncherLoopback.exe [154960 2019-08-02] (DITEC, a.s. -> )
R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [189464 2020-06-02] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\4.3.50.0\LenovoVantageService.exe [34792 2025-06-17] (Lenovo -> Lenovo)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpDefenderCoreService.exe [2071592 2025-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [189792 2022-04-25] (Qualcomm Atheros, Inc. -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\NisSrv.exe [4513624 2025-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MsMpEng.exe [278328 2025-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvla.inf_amd64_a6a2da7e042e0376\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvla.inf_amd64_a6a2da7e042e0376\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [330112 2025-06-13] (Microsoft Windows -> Microsoft Corporation)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [347224 2024-12-01] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20032 2025-06-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [612768 2025-06-13] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-06-13] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-07-05 10:31 - 2025-07-05 10:32 - 000008809 ____C C:\Users\User\Desktop\FRST.txt
2025-07-05 10:30 - 2025-07-05 10:31 - 000000000 ___DC C:\FRST
2025-07-05 10:24 - 2025-07-05 10:24 - 002100224 ____C (Farbar) C:\Users\User\Desktop\FRST.exe
2025-07-05 10:16 - 2025-07-05 10:16 - 002407936 ____C (Farbar) C:\Users\User\Desktop\FRST64.exe
2025-07-05 07:33 - 2025-07-05 07:33 - 000000000 ____D C:\WINDOWS\system32\Tasks\Event Viewer Tasks
2025-07-04 05:46 - 2025-07-04 05:46 - 002034388 _____ C:\WINDOWS\Minidump\070425-18484-01.dmp
2025-07-03 17:53 - 2025-07-03 17:53 - 002057132 _____ C:\WINDOWS\Minidump\070325-17171-01.dmp
2025-07-03 07:17 - 2025-07-03 07:17 - 001582140 _____ C:\WINDOWS\Minidump\070325-20015-01.dmp
2025-07-02 15:17 - 2025-07-02 15:17 - 001725380 _____ C:\WINDOWS\Minidump\070225-16234-01.dmp
2025-07-01 20:52 - 2025-07-01 20:52 - 000000000 _____ C:\Users\User\chkdsk
2025-07-01 19:09 - 2025-07-01 19:09 - 002281404 _____ C:\WINDOWS\Minidump\070125-19828-01.dmp
2025-06-28 11:47 - 2025-06-28 12:17 - 000000000 ___DC C:\Users\User\Desktop\cucky
2025-06-25 19:11 - 2025-06-25 19:11 - 000023172 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-06-25 19:10 - 2025-06-25 19:10 - 000023172 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-06-10 19:46 - 2025-06-10 19:46 - 000000000 __HDC C:\$WinREAgent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-07-05 10:16 - 2019-10-10 07:51 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps
2025-07-05 10:16 - 2019-10-08 13:15 - 000000000 ____D C:\Program Files\CCleaner
2025-07-05 10:15 - 2020-12-06 08:56 - 001693350 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-07-05 10:15 - 2019-12-07 16:41 - 000716770 _____ C:\WINDOWS\system32\perfh005.dat
2025-07-05 10:15 - 2019-12-07 16:41 - 000144948 _____ C:\WINDOWS\system32\perfc005.dat
2025-07-05 10:15 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2025-07-05 10:09 - 2022-11-17 06:27 - 000000000 ____D C:\Users\User\AppData\Roaming\WD Discovery
2025-07-05 10:09 - 2022-11-17 06:26 - 000000000 ____D C:\Users\User\.wdc
2025-07-05 10:08 - 2020-12-06 08:52 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-07-05 10:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2025-07-05 10:08 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-07-05 10:08 - 2019-05-30 22:02 - 000000000 _SHDC C:\Users\User\IntelGraphicsProfiles
2025-07-05 10:08 - 2019-05-30 21:47 - 000000000 __HDC C:\Intel
2025-07-05 10:08 - 2019-05-30 21:42 - 000000000 ____D C:\ProgramData\NVIDIA
2025-07-05 08:28 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2025-07-05 06:59 - 2020-12-06 08:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-07-05 04:56 - 2021-12-17 21:08 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-07-04 17:33 - 2019-06-05 11:35 - 000000000 ___DC C:\Users\User\AppData\Roaming\ViberPC
2025-07-04 17:05 - 2025-05-29 14:25 - 000000000 ___DC C:\Users\User\Documents\ViberDownloads
2025-07-04 17:05 - 2022-08-30 07:48 - 000000000 ___DC C:\Users\User\AppData\Local\Viber
2025-07-04 08:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-07-04 06:10 - 2020-06-10 10:27 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-07-04 06:10 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-07-04 06:10 - 2019-05-30 22:02 - 000000000 ___DC C:\Users\User\AppData\Local\Packages
2025-07-04 05:46 - 2022-09-13 06:31 - 000000000 ____D C:\WINDOWS\Minidump
2025-07-02 06:37 - 2022-11-11 08:56 - 000000000 ____D C:\Program Files\RUXIM
2025-07-01 18:50 - 2025-02-07 19:47 - 000003556 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-1496144255-991381806-58249036-1001
2025-07-01 18:50 - 2021-12-11 08:21 - 000003580 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1496144255-991381806-58249036-1001
2025-07-01 18:50 - 2020-12-06 08:52 - 000003354 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1496144255-991381806-58249036-1001
2025-07-01 18:50 - 2020-12-06 08:48 - 000002367 ____C C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-06-28 12:52 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-06-28 11:24 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-06-27 14:16 - 2019-06-05 11:06 - 000002320 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-06-27 09:35 - 2019-06-05 11:36 - 000000000 ___DC C:\Users\User\AppData\Roaming\uTorrent
2025-06-26 18:53 - 2019-06-25 09:44 - 000000000 ____D C:\Users\User\AppData\Local\D3DSCache
2025-06-26 18:38 - 2019-06-05 07:13 - 000000000 ____D C:\ProgramData\Packages
2025-06-26 18:35 - 2020-12-06 08:46 - 000448008 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-06-25 19:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-06-25 19:21 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2025-06-25 19:10 - 2020-12-06 08:49 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-06-25 19:04 - 2021-10-26 17:33 - 000000000 ____D C:\Users\User\AppData\Roaming\Telegram Desktop
2025-06-13 14:55 - 2019-06-19 09:35 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-06-13 10:15 - 2022-10-12 18:38 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2025-06-12 10:53 - 2019-06-05 03:17 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-06-12 10:51 - 2019-06-05 03:17 - 216824056 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-06-12 08:52 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================