Zpomalené PC - Děkuji za pomoc
Napsal: 08 led 2021 09:10
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-01-2021
Ran by PC (administrator) on DESKTOP-3N07L5T (08-01-2021 09:07:09)
Running from D:\Users\akhav\Downloads
Loaded Profiles: PC
Platform: Windows 10 Home Version 1909 18363.1256 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <27>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler64.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2011.16.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(SatoshiLabs, s.r.o. -> ) C:\Program Files (x86)\TREZOR Bridge\trezord.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(TEFINCOM S.A. -> ) D:\Program Files (x86)\NordVPN\nordvpn-service.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-11-02] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [97703592 2020-02-13] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [${_APP_NAME}] => D:\Program Files (x86)\WellWeWeb\CheVolume\CheVolume.exe
HKLM-x32\...\Run: [VirtualCloneDrive] => D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [105280 2020-02-23] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32762440 2021-01-07] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\Run: [NordVPN] => D:\Program Files (x86)\NordVPN\NordVPN.exe [1844688 2020-05-28] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3411232 2020-12-21] (Valve -> Valve Corporation)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\MountPoints2: {0bf88ee0-12c9-11eb-878b-6045cb7226b1} - "E:\setup.exe"
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\MountPoints2: {cd80bf90-1831-11eb-878c-6045cb7226b1} - "E:\setup.exe"
HKLM\...\Print\Monitors\us008 Langmon: C:\WINDOWS\system32\us008lm.dll [31256 2016-02-15] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.88\Installer\chrmstp.exe [2020-12-08] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CheVolume.lnk [2020-05-02]
ShortcutTarget: CheVolume.lnk -> D:\Program Files (x86)\WellWeWeb\CheVolume\CheVolume.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TREZOR Bridge.lnk [2020-12-18]
ShortcutTarget: TREZOR Bridge.lnk -> C:\Program Files (x86)\TREZOR Bridge\trezord.exe (SatoshiLabs, s.r.o. -> )
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06FFBEB6-4DA5-4F39-8F0B-AAB139E905DB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5142960 2020-12-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {20DBED21-5151-4335-B73D-6E1E821680B3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3EA66AC4-9D96-43DC-97F5-788DF6511AE1} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {49A25387-5DAC-4927-AC0E-D5D68AAC24EB} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4D3D13E8-81F8-4F07-8BFD-3206DC7D4564} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {4F65E85A-DF52-42CE-BF80-0032F1A2CCE8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-04-02] (Google LLC -> Google LLC)
Task: {5484845F-D67B-45DE-B013-B04FCACAC304} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5C58382E-E9C8-4458-B7ED-000E3798642A} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054216 2020-12-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {615F0DB0-D123-46E1-B889-283DF4C212C5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5142960 2020-12-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {624D03F5-6285-491F-A14A-2A82FFB522B0} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {71F4B82E-7A79-41FC-B97D-EC8624FE1D81} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054216 2020-12-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {807E8A7E-041A-45D2-A694-481FBC938881} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301176 2020-10-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A20C42BE-424E-4A51-9705-CE9B6EF2F6AF} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A323B995-E4EC-49D8-A1A0-438557D90EB3} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143720 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {BC3ACC02-D5A0-4715-BE3D-911E40B63F9A} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_pepper.exe [1499704 2020-12-30] (Adobe Inc. -> Adobe)
Task: {C0150820-0A64-42D2-BFD6-099868C9CFE9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-04-02] (Google LLC -> Google LLC)
Task: {CD4FAC08-D429-4EC7-950A-034FDBB90A5F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {CF85638D-3A8C-4401-A5F9-53A629A54AFF} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D7F25BDC-65CF-449A-800A-15F263C5E640} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143720 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {DAF29880-C928-4D8C-B0AA-BE88F8068071} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {F3123CDC-9C8A-4A54-849A-4C141D73842C} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F8D29B52-4B9F-49DA-B16F-444E97E63BB5} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1532312 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{4e133736-f63e-4bf6-b314-b6da0d61e04a}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{d5d71ac8-32bd-4498-9b9c-3912d527cda1}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{d5d71ac8-32bd-4498-9b9c-3912d527cda1}: [DhcpNameServer] 10.0.0.138
Edge:
======
Edge Profile: C:\Users\akhav\AppData\Local\Microsoft\Edge\User Data\Default [2020-12-31]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default [2021-01-08]
CHR Extension: (Překladač Google) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2020-04-02]
CHR Extension: (Prezentace) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-02]
CHR Extension: (Dokumenty) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-02]
CHR Extension: (Disk Google) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2020-10-15]
CHR Extension: (YouTube) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-02]
CHR Extension: (Zeus - Degiro Portfolio Manager) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckgeffpapoiemciaenjgbelealaekgic [2020-12-16]
CHR Extension: (Tabulky) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-02]
CHR Extension: (Dokumenty Google offline) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-19]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-12-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-02]
CHR Extension: (Gmail) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23]
CHR Extension: (Chrome Media Router) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-10]
CHR Profile: C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-01-02]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-05-20] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9105800 2020-12-01] (Microsoft Corporation -> Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-02] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-02] (ESET, spol. s r.o. -> ESET)
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [287720 2020-10-19] (NVIDIA Corporation -> NVIDIA)
R2 nordvpn-service; D:\Program Files (x86)\NordVPN\nordvpn-service.exe [244176 2020-05-28] (TEFINCOM S.A. -> )
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2519864 2020-09-09] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3473216 2020-09-09] (Electronic Arts, Inc. -> Electronic Arts)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 TwitchService; C:\Program Files\Common Files\Twitch\TwitchService.exe [334208 2020-07-11] (Twitch Interactive, Inc. -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\NisSrv.exe [2169568 2020-08-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MsMpEng.exe [128376 2020-08-05] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AKSUP; C:\WINDOWS\system32\drivers\aksup.sys [44712 2017-08-03] (Aladdin Knowledge Systems Inc. -> Aladdin Knowledge Systems, Ltd.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 busenum; C:\WINDOWS\System32\drivers\busenum.sys [57824 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-26] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-26] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-09-16] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-26] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [42616 2017-05-14] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-26] (ESET, spol. s r.o. -> ESET)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2020-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
R3 nlwt; C:\WINDOWS\system32\DRIVERS\nlwt.sys [39360 2020-04-24] (TEFINCOM S.A. -> WireGuard LLC)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 VClone; C:\WINDOWS\System32\drivers\VClone.sys [44544 2020-02-22] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [78216 2020-08-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [430320 2020-08-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [98520 2020-08-05] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-08 09:06 - 2021-01-08 09:07 - 000000000 ____D C:\FRST
2021-01-07 23:29 - 2021-01-07 23:29 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2021-01-07 23:28 - 2021-01-04 15:28 - 001855192 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001855192 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001454488 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 001435864 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001435864 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001193880 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 001094880 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 001094880 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 002104216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 001589144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 001512856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 001165720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000813976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000680856 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000673688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000559000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000548248 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 008262552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 007393176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 004612504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 002731928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 001733016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446109.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 001492376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446109.dll
2021-01-07 23:28 - 2021-01-04 15:23 - 006071032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-01-07 23:28 - 2020-12-31 15:03 - 000038640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2021-01-03 11:22 - 2021-01-03 11:22 - 000000000 ____D C:\Users\akhav\AppData\Roaming\Macromedia
2020-12-30 20:02 - 2020-12-30 20:02 - 000004608 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-12-30 20:01 - 2020-12-30 20:02 - 000000000 ____D C:\Users\akhav\AppData\Local\Adobe
2020-12-18 16:31 - 2021-01-07 17:55 - 000000000 ____D C:\Users\akhav\AppData\Roaming\TREZOR Bridge
2020-12-18 16:31 - 2020-12-18 16:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TREZOR Bridge
2020-12-18 16:31 - 2020-12-18 16:31 - 000000000 ____D C:\Program Files (x86)\TREZOR Bridge
2020-12-15 17:57 - 2020-12-15 17:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MetaTrader
2020-12-15 17:57 - 2020-12-15 17:57 - 000000000 ____D C:\Program Files\MetaTrader
2020-12-15 17:50 - 2020-12-15 17:57 - 000000000 ____D C:\Users\akhav\AppData\Roaming\MetaQuotes
2020-12-10 10:29 - 2020-12-10 10:29 - 002045952 _____ C:\WINDOWS\system32\rdpnano.dll
2020-12-10 10:29 - 2020-12-10 10:29 - 000171008 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2020-12-10 10:28 - 2020-12-10 10:28 - 001756600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-12-10 10:28 - 2020-12-10 10:28 - 001366144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-12-10 10:28 - 2020-12-10 10:28 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncpa.cpl
2020-12-10 10:28 - 2020-12-10 10:28 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncpa.cpl
2020-12-10 10:28 - 2020-12-10 10:28 - 000059392 _____ C:\WINDOWS\system32\runexehelper.exe
2020-12-10 10:28 - 2020-12-10 10:28 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt
2020-12-10 10:28 - 2020-12-10 10:28 - 000000357 _____ C:\WINDOWS\system32\DrtmAuth14.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000357 _____ C:\WINDOWS\system32\DrtmAuth13.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth18.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth17.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth16.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth15.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-08 09:00 - 2020-07-26 20:50 - 000000000 ____D C:\Program Files (x86)\Steam
2021-01-08 08:59 - 2020-04-02 18:39 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-08 08:59 - 2020-04-02 17:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-01-08 00:28 - 2020-04-02 18:39 - 000000000 ___HD C:\Program Files\WindowsApps
2021-01-08 00:28 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-01-07 23:49 - 2020-04-02 18:40 - 000716944 _____ C:\WINDOWS\system32\perfh005.dat
2021-01-07 23:49 - 2020-04-02 18:40 - 000145024 _____ C:\WINDOWS\system32\perfc005.dat
2021-01-07 23:49 - 2020-04-02 18:38 - 000000000 ____D C:\WINDOWS\INF
2021-01-07 23:49 - 2020-04-02 17:56 - 001693704 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-01-07 23:45 - 2020-04-02 17:46 - 000000000 ____D C:\ProgramData\NVIDIA
2021-01-07 23:43 - 2020-04-09 10:01 - 000000000 ____D C:\Users\akhav\AppData\Local\SquirrelTemp
2021-01-07 23:43 - 2020-04-02 18:03 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-01-07 23:43 - 2020-04-02 17:51 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-01-07 23:42 - 2020-04-30 22:07 - 000000000 ____D C:\Users\akhav\AppData\Roaming\discord
2021-01-07 23:42 - 2020-04-02 18:36 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-01-07 23:42 - 2020-04-02 17:48 - 000000000 ____D C:\Users\akhav
2021-01-07 23:34 - 2020-09-18 18:39 - 000000000 ____D C:\Users\akhav\AppData\Local\CrashDumps
2021-01-07 23:28 - 2020-04-03 17:40 - 000000000 ____D C:\Users\akhav\AppData\Local\Battle.net
2021-01-07 23:21 - 2020-04-03 17:42 - 000000000 ____D C:\Program Files (x86)\Call of Duty Modern Warfare
2021-01-07 17:39 - 2020-04-02 17:59 - 000000000 ____D C:\Users\akhav\Desktop\Věci z plochy 2.4.20
2021-01-06 22:23 - 2020-04-02 17:54 - 000000000 ____D C:\Users\akhav\AppData\Local\Packages
2021-01-06 21:33 - 2020-04-03 17:38 - 000000000 ____D C:\Program Files (x86)\Battle.net
2021-01-04 15:26 - 2020-12-03 18:28 - 000657816 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-01-04 15:23 - 2020-03-23 22:09 - 007115280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2020-12-31 15:03 - 2020-03-23 22:09 - 001682376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2020-12-31 15:03 - 2020-03-23 22:09 - 000135592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2020-12-31 15:03 - 2020-03-23 22:09 - 000060966 _____ C:\WINDOWS\system32\nvinfo.pb
2020-12-31 10:48 - 2020-04-02 17:46 - 005623272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 002637800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 001760232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 000992232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 000122344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 000084456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2020-12-30 20:02 - 2020-04-02 18:40 - 000842296 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-12-30 20:02 - 2020-04-02 18:40 - 000175160 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-12-30 20:02 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-12-30 20:02 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-12-29 00:27 - 2020-04-02 17:46 - 009381947 _____ C:\WINDOWS\system32\nvcoproc.bin
2020-12-28 13:44 - 2020-04-02 19:17 - 000000000 ____D C:\Users\akhav\AppData\Roaming\BitLord
2020-12-28 13:42 - 2020-04-02 19:17 - 000000000 _____ C:\Users\akhav\AppData\Roaming\bitlord_log.txt
2020-12-28 10:59 - 2020-10-06 20:18 - 000001128 _____ C:\Users\akhav\Desktop\RebelBetting.lnk
2020-12-28 10:59 - 2020-08-15 18:16 - 000001878 _____ C:\Users\akhav\Desktop\YMS 3028 Gaming Mouse.lnk
2020-12-28 10:59 - 2020-04-30 22:07 - 000002237 _____ C:\Users\akhav\Desktop\Discord.lnk
2020-12-28 10:59 - 2020-04-02 19:16 - 000002100 _____ C:\Users\akhav\Desktop\BitLord.lnk
2020-12-26 14:58 - 2020-04-02 18:01 - 000000000 ____D C:\Users\akhav\Desktop\faktury
2020-12-25 18:39 - 2020-04-08 11:16 - 000000000 ____D C:\Program Files\Microsoft Office
2020-12-22 23:02 - 2020-04-02 17:57 - 000000000 ____D C:\Users\akhav\AppData\Local\PlaceholderTileLogoFolder
2020-12-19 12:10 - 2020-06-05 09:41 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-12-18 13:44 - 2020-04-03 08:21 - 000000000 ____D C:\Users\akhav\AppData\Local\D3DSCache
2020-12-17 19:59 - 2020-04-02 17:57 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4158704578-2855211266-1573636166-1001
2020-12-17 19:59 - 2020-04-02 17:55 - 000000000 ___RD C:\Users\akhav\OneDrive
2020-12-17 19:59 - 2020-04-02 17:48 - 000002365 _____ C:\Users\akhav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-12-10 13:20 - 2020-04-02 17:55 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-12-10 13:20 - 2020-04-02 17:55 - 000000000 ___RD C:\Users\akhav\3D Objects
2020-12-10 13:20 - 2020-04-02 17:45 - 000637560 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\SystemResources
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\Program Files\Windows Defender
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-12-10 10:30 - 2020-04-02 18:36 - 000000000 ____D C:\WINDOWS\CbsTemp
==================== Files in the root of some directories ========
2020-04-02 19:17 - 2020-12-28 13:42 - 000000000 _____ () C:\Users\akhav\AppData\Roaming\bitlord_log.txt
2020-10-12 23:30 - 2020-10-12 23:30 - 000000218 _____ () C:\Users\akhav\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by PC (administrator) on DESKTOP-3N07L5T (08-01-2021 09:07:09)
Running from D:\Users\akhav\Downloads
Loaded Profiles: PC
Platform: Windows 10 Home Version 1909 18363.1256 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <27>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler64.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2011.16.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(SatoshiLabs, s.r.o. -> ) C:\Program Files (x86)\TREZOR Bridge\trezord.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(TEFINCOM S.A. -> ) D:\Program Files (x86)\NordVPN\nordvpn-service.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-11-02] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [97703592 2020-02-13] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [${_APP_NAME}] => D:\Program Files (x86)\WellWeWeb\CheVolume\CheVolume.exe
HKLM-x32\...\Run: [VirtualCloneDrive] => D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [105280 2020-02-23] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32762440 2021-01-07] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\Run: [NordVPN] => D:\Program Files (x86)\NordVPN\NordVPN.exe [1844688 2020-05-28] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3411232 2020-12-21] (Valve -> Valve Corporation)
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\MountPoints2: {0bf88ee0-12c9-11eb-878b-6045cb7226b1} - "E:\setup.exe"
HKU\S-1-5-21-4158704578-2855211266-1573636166-1001\...\MountPoints2: {cd80bf90-1831-11eb-878c-6045cb7226b1} - "E:\setup.exe"
HKLM\...\Print\Monitors\us008 Langmon: C:\WINDOWS\system32\us008lm.dll [31256 2016-02-15] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.88\Installer\chrmstp.exe [2020-12-08] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CheVolume.lnk [2020-05-02]
ShortcutTarget: CheVolume.lnk -> D:\Program Files (x86)\WellWeWeb\CheVolume\CheVolume.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TREZOR Bridge.lnk [2020-12-18]
ShortcutTarget: TREZOR Bridge.lnk -> C:\Program Files (x86)\TREZOR Bridge\trezord.exe (SatoshiLabs, s.r.o. -> )
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06FFBEB6-4DA5-4F39-8F0B-AAB139E905DB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5142960 2020-12-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {20DBED21-5151-4335-B73D-6E1E821680B3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3EA66AC4-9D96-43DC-97F5-788DF6511AE1} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {49A25387-5DAC-4927-AC0E-D5D68AAC24EB} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4D3D13E8-81F8-4F07-8BFD-3206DC7D4564} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {4F65E85A-DF52-42CE-BF80-0032F1A2CCE8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-04-02] (Google LLC -> Google LLC)
Task: {5484845F-D67B-45DE-B013-B04FCACAC304} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5C58382E-E9C8-4458-B7ED-000E3798642A} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054216 2020-12-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {615F0DB0-D123-46E1-B889-283DF4C212C5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5142960 2020-12-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {624D03F5-6285-491F-A14A-2A82FFB522B0} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {71F4B82E-7A79-41FC-B97D-EC8624FE1D81} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054216 2020-12-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {807E8A7E-041A-45D2-A694-481FBC938881} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301176 2020-10-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A20C42BE-424E-4A51-9705-CE9B6EF2F6AF} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A323B995-E4EC-49D8-A1A0-438557D90EB3} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143720 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {BC3ACC02-D5A0-4715-BE3D-911E40B63F9A} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_pepper.exe [1499704 2020-12-30] (Adobe Inc. -> Adobe)
Task: {C0150820-0A64-42D2-BFD6-099868C9CFE9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-04-02] (Google LLC -> Google LLC)
Task: {CD4FAC08-D429-4EC7-950A-034FDBB90A5F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {CF85638D-3A8C-4401-A5F9-53A629A54AFF} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D7F25BDC-65CF-449A-800A-15F263C5E640} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143720 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {DAF29880-C928-4D8C-B0AA-BE88F8068071} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {F3123CDC-9C8A-4A54-849A-4C141D73842C} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F8D29B52-4B9F-49DA-B16F-444E97E63BB5} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1532312 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{4e133736-f63e-4bf6-b314-b6da0d61e04a}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{d5d71ac8-32bd-4498-9b9c-3912d527cda1}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{d5d71ac8-32bd-4498-9b9c-3912d527cda1}: [DhcpNameServer] 10.0.0.138
Edge:
======
Edge Profile: C:\Users\akhav\AppData\Local\Microsoft\Edge\User Data\Default [2020-12-31]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default [2021-01-08]
CHR Extension: (Překladač Google) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2020-04-02]
CHR Extension: (Prezentace) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-02]
CHR Extension: (Dokumenty) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-02]
CHR Extension: (Disk Google) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2020-10-15]
CHR Extension: (YouTube) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-02]
CHR Extension: (Zeus - Degiro Portfolio Manager) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckgeffpapoiemciaenjgbelealaekgic [2020-12-16]
CHR Extension: (Tabulky) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-02]
CHR Extension: (Dokumenty Google offline) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-19]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-12-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-02]
CHR Extension: (Gmail) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23]
CHR Extension: (Chrome Media Router) - C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-10]
CHR Profile: C:\Users\akhav\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-01-02]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-05-20] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9105800 2020-12-01] (Microsoft Corporation -> Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-02] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-02] (ESET, spol. s r.o. -> ESET)
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [287720 2020-10-19] (NVIDIA Corporation -> NVIDIA)
R2 nordvpn-service; D:\Program Files (x86)\NordVPN\nordvpn-service.exe [244176 2020-05-28] (TEFINCOM S.A. -> )
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2519864 2020-09-09] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3473216 2020-09-09] (Electronic Arts, Inc. -> Electronic Arts)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 TwitchService; C:\Program Files\Common Files\Twitch\TwitchService.exe [334208 2020-07-11] (Twitch Interactive, Inc. -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\NisSrv.exe [2169568 2020-08-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MsMpEng.exe [128376 2020-08-05] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AKSUP; C:\WINDOWS\system32\drivers\aksup.sys [44712 2017-08-03] (Aladdin Knowledge Systems Inc. -> Aladdin Knowledge Systems, Ltd.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 busenum; C:\WINDOWS\System32\drivers\busenum.sys [57824 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-26] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-26] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-09-16] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-26] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [42616 2017-05-14] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-26] (ESET, spol. s r.o. -> ESET)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2020-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
R3 nlwt; C:\WINDOWS\system32\DRIVERS\nlwt.sys [39360 2020-04-24] (TEFINCOM S.A. -> WireGuard LLC)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 VClone; C:\WINDOWS\System32\drivers\VClone.sys [44544 2020-02-22] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [78216 2020-08-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [430320 2020-08-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [98520 2020-08-05] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-08 09:06 - 2021-01-08 09:07 - 000000000 ____D C:\FRST
2021-01-07 23:29 - 2021-01-07 23:29 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2021-01-07 23:28 - 2021-01-04 15:28 - 001855192 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001855192 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001454488 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 001435864 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001435864 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-01-07 23:28 - 2021-01-04 15:28 - 001193880 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 001094880 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 001094880 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-01-07 23:28 - 2021-01-04 15:28 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 002104216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 001589144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 001512856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 001165720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000813976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000680856 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000673688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000559000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-01-07 23:28 - 2021-01-04 15:26 - 000548248 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 008262552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 007393176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 004612504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 002731928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 001733016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446109.dll
2021-01-07 23:28 - 2021-01-04 15:25 - 001492376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446109.dll
2021-01-07 23:28 - 2021-01-04 15:23 - 006071032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-01-07 23:28 - 2020-12-31 15:03 - 000038640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2021-01-03 11:22 - 2021-01-03 11:22 - 000000000 ____D C:\Users\akhav\AppData\Roaming\Macromedia
2020-12-30 20:02 - 2020-12-30 20:02 - 000004608 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-12-30 20:01 - 2020-12-30 20:02 - 000000000 ____D C:\Users\akhav\AppData\Local\Adobe
2020-12-18 16:31 - 2021-01-07 17:55 - 000000000 ____D C:\Users\akhav\AppData\Roaming\TREZOR Bridge
2020-12-18 16:31 - 2020-12-18 16:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TREZOR Bridge
2020-12-18 16:31 - 2020-12-18 16:31 - 000000000 ____D C:\Program Files (x86)\TREZOR Bridge
2020-12-15 17:57 - 2020-12-15 17:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MetaTrader
2020-12-15 17:57 - 2020-12-15 17:57 - 000000000 ____D C:\Program Files\MetaTrader
2020-12-15 17:50 - 2020-12-15 17:57 - 000000000 ____D C:\Users\akhav\AppData\Roaming\MetaQuotes
2020-12-10 10:29 - 2020-12-10 10:29 - 002045952 _____ C:\WINDOWS\system32\rdpnano.dll
2020-12-10 10:29 - 2020-12-10 10:29 - 000171008 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2020-12-10 10:28 - 2020-12-10 10:28 - 001756600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-12-10 10:28 - 2020-12-10 10:28 - 001366144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-12-10 10:28 - 2020-12-10 10:28 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncpa.cpl
2020-12-10 10:28 - 2020-12-10 10:28 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncpa.cpl
2020-12-10 10:28 - 2020-12-10 10:28 - 000059392 _____ C:\WINDOWS\system32\runexehelper.exe
2020-12-10 10:28 - 2020-12-10 10:28 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt
2020-12-10 10:28 - 2020-12-10 10:28 - 000000357 _____ C:\WINDOWS\system32\DrtmAuth14.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000357 _____ C:\WINDOWS\system32\DrtmAuth13.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth18.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth17.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth16.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth15.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-12-10 10:28 - 2020-12-10 10:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-08 09:00 - 2020-07-26 20:50 - 000000000 ____D C:\Program Files (x86)\Steam
2021-01-08 08:59 - 2020-04-02 18:39 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-08 08:59 - 2020-04-02 17:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-01-08 00:28 - 2020-04-02 18:39 - 000000000 ___HD C:\Program Files\WindowsApps
2021-01-08 00:28 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-01-07 23:49 - 2020-04-02 18:40 - 000716944 _____ C:\WINDOWS\system32\perfh005.dat
2021-01-07 23:49 - 2020-04-02 18:40 - 000145024 _____ C:\WINDOWS\system32\perfc005.dat
2021-01-07 23:49 - 2020-04-02 18:38 - 000000000 ____D C:\WINDOWS\INF
2021-01-07 23:49 - 2020-04-02 17:56 - 001693704 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-01-07 23:45 - 2020-04-02 17:46 - 000000000 ____D C:\ProgramData\NVIDIA
2021-01-07 23:43 - 2020-04-09 10:01 - 000000000 ____D C:\Users\akhav\AppData\Local\SquirrelTemp
2021-01-07 23:43 - 2020-04-02 18:03 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-01-07 23:43 - 2020-04-02 17:51 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-01-07 23:42 - 2020-04-30 22:07 - 000000000 ____D C:\Users\akhav\AppData\Roaming\discord
2021-01-07 23:42 - 2020-04-02 18:36 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-01-07 23:42 - 2020-04-02 17:48 - 000000000 ____D C:\Users\akhav
2021-01-07 23:34 - 2020-09-18 18:39 - 000000000 ____D C:\Users\akhav\AppData\Local\CrashDumps
2021-01-07 23:28 - 2020-04-03 17:40 - 000000000 ____D C:\Users\akhav\AppData\Local\Battle.net
2021-01-07 23:21 - 2020-04-03 17:42 - 000000000 ____D C:\Program Files (x86)\Call of Duty Modern Warfare
2021-01-07 17:39 - 2020-04-02 17:59 - 000000000 ____D C:\Users\akhav\Desktop\Věci z plochy 2.4.20
2021-01-06 22:23 - 2020-04-02 17:54 - 000000000 ____D C:\Users\akhav\AppData\Local\Packages
2021-01-06 21:33 - 2020-04-03 17:38 - 000000000 ____D C:\Program Files (x86)\Battle.net
2021-01-04 15:26 - 2020-12-03 18:28 - 000657816 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-01-04 15:23 - 2020-03-23 22:09 - 007115280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2020-12-31 15:03 - 2020-03-23 22:09 - 001682376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2020-12-31 15:03 - 2020-03-23 22:09 - 000135592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2020-12-31 15:03 - 2020-03-23 22:09 - 000060966 _____ C:\WINDOWS\system32\nvinfo.pb
2020-12-31 10:48 - 2020-04-02 17:46 - 005623272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 002637800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 001760232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 000992232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 000122344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2020-12-31 10:48 - 2020-04-02 17:46 - 000084456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2020-12-30 20:02 - 2020-04-02 18:40 - 000842296 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-12-30 20:02 - 2020-04-02 18:40 - 000175160 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-12-30 20:02 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-12-30 20:02 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-12-29 00:27 - 2020-04-02 17:46 - 009381947 _____ C:\WINDOWS\system32\nvcoproc.bin
2020-12-28 13:44 - 2020-04-02 19:17 - 000000000 ____D C:\Users\akhav\AppData\Roaming\BitLord
2020-12-28 13:42 - 2020-04-02 19:17 - 000000000 _____ C:\Users\akhav\AppData\Roaming\bitlord_log.txt
2020-12-28 10:59 - 2020-10-06 20:18 - 000001128 _____ C:\Users\akhav\Desktop\RebelBetting.lnk
2020-12-28 10:59 - 2020-08-15 18:16 - 000001878 _____ C:\Users\akhav\Desktop\YMS 3028 Gaming Mouse.lnk
2020-12-28 10:59 - 2020-04-30 22:07 - 000002237 _____ C:\Users\akhav\Desktop\Discord.lnk
2020-12-28 10:59 - 2020-04-02 19:16 - 000002100 _____ C:\Users\akhav\Desktop\BitLord.lnk
2020-12-26 14:58 - 2020-04-02 18:01 - 000000000 ____D C:\Users\akhav\Desktop\faktury
2020-12-25 18:39 - 2020-04-08 11:16 - 000000000 ____D C:\Program Files\Microsoft Office
2020-12-22 23:02 - 2020-04-02 17:57 - 000000000 ____D C:\Users\akhav\AppData\Local\PlaceholderTileLogoFolder
2020-12-19 12:10 - 2020-06-05 09:41 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-12-18 13:44 - 2020-04-03 08:21 - 000000000 ____D C:\Users\akhav\AppData\Local\D3DSCache
2020-12-17 19:59 - 2020-04-02 17:57 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4158704578-2855211266-1573636166-1001
2020-12-17 19:59 - 2020-04-02 17:55 - 000000000 ___RD C:\Users\akhav\OneDrive
2020-12-17 19:59 - 2020-04-02 17:48 - 000002365 _____ C:\Users\akhav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-12-10 13:20 - 2020-04-02 17:55 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-12-10 13:20 - 2020-04-02 17:55 - 000000000 ___RD C:\Users\akhav\3D Objects
2020-12-10 13:20 - 2020-04-02 17:45 - 000637560 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\SystemResources
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\Program Files\Windows Defender
2020-12-10 13:19 - 2020-04-02 18:39 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-12-10 10:30 - 2020-04-02 18:36 - 000000000 ____D C:\WINDOWS\CbsTemp
==================== Files in the root of some directories ========
2020-04-02 19:17 - 2020-12-28 13:42 - 000000000 _____ () C:\Users\akhav\AppData\Roaming\bitlord_log.txt
2020-10-12 23:30 - 2020-10-12 23:30 - 000000218 _____ () C:\Users\akhav\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================