Po odinštalovaní Odmeňovač.exe nejde internet
Napsal: 19 kvě 2021 19:19
Ahojte, inštalovala a odinštalovala som Odmeňovač.exe a odvtedy mi na ntb nejde internet. Vopred ďakujem za pomoc. Idem krkolomne z mobilu, tak jeden log prikladám sem a druhý ako zip v prílohe.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2021
Ran by Lenovo (administrator) on DESKTOP-06V2301 (LENOVO 80M3) (19-05-2021 19:27:04)
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Platform: Windows 10 Pro Version 1709 16299.98 (X64) Language: Angličtina (USA) -> Slovenčina (Slovensko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation -> Microsoft Corporation) [File not signed] C:\Windows\servicing\Skype.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.51.72.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [916184 2014-07-02] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1903040 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM-x32\...\Run: [HKLM] => C:\Windows\servicing\Skype.exe [53104 2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed] <==== ATTENTION
HKLM-x32\...\Run: [EAC_MW_klient] => C:\Program Files (x86)\EAC MW klient\EAC_MW_klient.exe [10897808 2020-06-29] (Ministerstvo vnútra Slovenskej republiky -> Ministerstvo vnútra Slovenskej republiky)
HKLM\ DisallowedCertificates: 18AA37360A0698E6A1F54A9E8268FB127B70E189 (AVG Netherlands B.V) <==== ATTENTION
HKLM\ DisallowedCertificates: 1B581436B0ED7536755B8B1C81112509A5AAF6ED (Panda Security S.L) <==== ATTENTION
HKLM\ DisallowedCertificates: 1F25DF887B158E34E2FCB13171924610C8F6BA2F (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 2CC344E13934A69AA993E80C8E20FF0ACCB33F1E (Qihu 360 Software Co. Limited) <==== ATTENTION
HKLM\ DisallowedCertificates: 2F56FF8F95EE69A27C05DBB35924F847C86A66B4 (SurfRight B.V.) <==== ATTENTION
HKLM\ DisallowedCertificates: 31F5EE85DA34AD374D43776B54F6686E7E922737 (SurfRight B.V.) <==== ATTENTION
HKLM\ DisallowedCertificates: 3C92C9274AB6D3DD520B13029A2490C4A1D98BC0 (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: 42A8984E8B9C51F6B7274866F8726CA1E9057FAA (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: 58939B78BC28EF464220127BB754E3D130306988 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: 5ACE40BD51EE148F299D37527AE1AD744CDE8EBB (U)
HKLM\ DisallowedCertificates: 5CA5F811E011742B05D014D03F85848D81F41A63 (Zemana) <==== ATTENTION
HKLM\ DisallowedCertificates: 622271AF668F99BD94AC12E5EBF86E48FD50AECB (Qihu 360 Software Co. Limited) <==== ATTENTION
HKLM\ DisallowedCertificates: 6CD253D636A7B4D0E0981431BC064061A9853ED9 (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 76FBABF1EADED3B91DD7A76A6678301F1F87AA97 (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 84C08B7A367422AF5FEF8D353B36191ECE9DBAF7 (Check Point Software Technologies Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 9900CFAABC45B4247F9D78EE7E12B102D25EA325 (Avira Operations GmbH & Co. KG) <==== ATTENTION
HKLM\ DisallowedCertificates: 9A32249E9A6B9CF5C36B0749C81613524D37C594 (Safer Networking Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9C2479D4BEF807FEFE3CE2B6B2D7FC4C71E0EBA5 (Sophos Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: BEBFAE20957D4DE689A8B962AEE358EFE39F195F (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: BF9254919794C1075EA027889C5D304F1121C653 (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: BFA87DC996BD6BCB02B6F530D2C646A0B5A0D5A9 (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: DBFAD9D59A6A07DCEB004DBE2DC246B547249E86 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: E64232B7757A335C032414C6888633CC498E7CD6 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: F74407DCA8D49D42D72D88863C17AB905EB94D1C (U)
HKLM\ DisallowedCertificates: F75019695C0504E3ABEFEDCD8FBE500DA08EC8FA (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== ATTENTION
HKU\S-1-5-21-2628802422-3275970452-2401892349-1002\...\Run: [HKCU] => C:\Windows\servicing\Skype.exe [53104 2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed] <==== ATTENTION
HKU\S-1-5-21-2628802422-3275970452-2401892349-1002\...\Run: [Spotify] => C:\Users\Lenovo\AppData\Roaming\Spotify\Spotify.exe [23924296 2021-05-17] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-2628802422-3275970452-2401892349-1002\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [91016568 2020-12-02] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [HKCU] => C:\Windows\servicing\Skype.exe [53104 2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed] <==== ATTENTION
HKLM\...\Print\Monitors\IppMon: C:\Windows\system32\IPPMon.dll [226816 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.212\Installer\chrmstp.exe [2021-05-11] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{5460C4DF-B266-909E-CB58-E32B79832EB2}] -> C:\Windows\servicing\Skype.exe [2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Web Signer.lnk [2020-03-09]
ShortcutTarget: Web Signer.lnk -> C:\Program Files (x86)\Disig\Disig Web Signer 1.0.7\Updater\WebSignerTray.exe (Disig a.s. -> Disig a.s.)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0A04B061-C5DA-417D-98B9-B919B26194FC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {0AE5C622-0BB2-45B6-92E9-6EC664ECEA18} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [732096 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {11FAB1A1-5A55-46A5-85AA-680633E5201C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-22] (Google Inc -> Google LLC)
Task: {1AEADA79-BDFA-487E-BA46-A4983585AF0E} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1704384 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {24FA3197-2039-4433-A6A9-9B1B33D5D617} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {3280F8B7-EA58-4906-ADCE-E422D621ED91} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141152 2021-05-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {394E0E86-0146-425C-9F10-C3A28D416176} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {484B2982-622D-464D-9B81-D99FB9A33EDD} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [649152 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {55C379FB-9E8B-4BBF-9964-C10FE648667D} - System32\Tasks\KMS_VL_ALL => C:\Windows\schemas\Scripts\KMS_VL_ALL.cmd 0
Task: {7587DD83-4E3D-4248-BA3B-F45F16150EC4} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436672 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {84DE3DE4-BBAA-417A-906C-E31EE3707E10} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-22] (Google Inc -> Google LLC)
Task: {86FF91C9-7B19-43C6-8DB2-2C4502D62938} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {A305BA0A-E3F6-4EB8-B537-6B24F50602CC} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [732096 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A34A5849-7716-46D2-BA71-E66D0FFB28B3} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {D137A0B0-2101-4EAC-8804-3F81F3EBBFAC} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe
Task: {DE780A30-EAE2-4B2F-ACF1-CE9BC4E0D7C9} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5229504 2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {E1A24716-7FA3-41D4-9FC2-9653CD9E167A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [649152 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E235584B-AA0E-4CCA-9832-C882E4D6CC5E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141152 2021-05-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {EBC8A8A4-020D-4809-B772-E876D2276FB6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [946112 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F0F022BD-4E95-4300-A87B-43238A8BA564} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5229504 2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-2628802422-3275970452-2401892349-1002] => Proxy is enabled.
ProxyServer: [S-1-5-21-2628802422-3275970452-2401892349-1002] => http=127.0.0.1:8877;https=127.0.0.1:8877
Tcpip\..\Interfaces\{3522593f-d6cc-46cd-af0b-dfb6eb3b14e5}: [DhcpNameServer] 10.9.0.2 10.9.0.4
Tcpip\..\Interfaces\{62c471aa-6048-45fd-9aa4-dd66eebd4b0f}: [DhcpNameServer] 89.207.131.21 8.8.8.8
ManualProxies: 1http=127.0.0.1:8877;https=127.0.0.1:8877
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-19]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-27] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: ditec.sk/DAsicFac -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~1.DLL [2019-03-06] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/DitecZepDViewerFb -> C:\PROGRA~2\Ditec\DViewer\NPDITE~1.DLL [2020-01-21] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigMessageContainer -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~2.DLL [2016-12-15] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesExtender -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~3.DLL [2016-12-15] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~1.DLL [2019-12-09] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/XmlDataContainerFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~2.DLL [2019-12-09] (DITEC, a.s. -> Ditec,a.s.)
Chrome:
=======
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default [2021-05-19]
CHR HomePage: Default -> hxxp://www.zoznam.sk/
CHR StartupUrls: Default -> "hxxp://www.facebook.com/","hxxp://www.twitter. ... google.sk/"
CHR Extension: (Prezentácie) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-08-22]
CHR Extension: (Dokumenty) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-08-22]
CHR Extension: (Disk Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-23]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-08-22]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-05-19]
CHR Extension: (Tabuľky) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-08-22]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-17]
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-05-07]
CHR Extension: (Kontrola pošty Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2019-09-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-11]
CHR Extension: (Disig Web Signer 1.0.7) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odbdbcaekkgabdfaabepfjgiooilmaoe [2020-03-09]
CHR Extension: (Gmail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23]
CHR Extension: (Chrome Media Router) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-05-03]
CHR HKLM-x32\...\Chrome\Extension: [odbdbcaekkgabdfaabepfjgiooilmaoe]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8798600 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
S2 dLauncherLoopback; C:\Program Files (x86)\Ditec\DLauncher\dLauncherLoopback.exe [154960 2019-08-02] (DITEC, a.s. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4329952 2017-11-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 TermService; C:\Windows\SysWOW64\termsrv.dll [1018880 2019-02-08] (Microsoft Corporation) [File not signed] <==== ATTENTION (no ServiceDLL)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation -> Microsoft Corporation)
S2 Windows Shadow Copy Service; C:\Windows\servicing\secinit.exe [100864 2018-05-04] () [File not signed]
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
S2 Windows Updates Services; C:\Windows\servicing\starter.exe [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R3 MpKsl30f73fb6; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0D597868-B6A0-4AD6-AE87-7EA3D4CA551D}\MpKslDrv.sys [47336 2021-05-19] (Microsoft Windows -> Microsoft Corporation)
R3 tap0901; C:\Windows\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-19 19:27 - 2021-05-19 19:29 - 000020920 _____ C:\Users\Lenovo\Desktop\FRST.txt
2021-05-19 19:20 - 2021-05-19 19:25 - 000000000 ____D C:\AdwCleaner
2021-05-19 19:18 - 2021-05-19 19:19 - 008534696 _____ (Malwarebytes) C:\Users\Lenovo\Desktop\AdwCleaner.exe
2021-05-19 19:01 - 2021-05-19 19:28 - 000000000 ____D C:\FRST
2021-05-19 19:00 - 2021-05-19 19:00 - 002299904 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2021-05-19 18:02 - 2021-05-19 18:02 - 000000000 ____D C:\Users\Lenovo\Documents\TNS
2021-05-19 18:01 - 2021-05-19 18:27 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Deployment
2021-05-19 18:01 - 2021-05-19 18:01 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Apps\2.0
2021-05-17 17:50 - 2018-02-18 00:31 - 042864583 _____ C:\Users\Lenovo\Desktop\VID_20180217_233105.mp4
2021-05-11 20:57 - 2021-05-19 17:35 - 000000000 ____D C:\Users\Lenovo\Desktop\čaje pr
2021-05-10 19:37 - 2021-05-10 19:36 - 000045706 _____ C:\Users\Lenovo\Desktop\Bláznova ukolébavka - ukulele.pdf
2021-05-10 19:30 - 2021-05-10 19:26 - 000017256 _____ C:\Users\Lenovo\Desktop\splnomocnenie-na-prepis-vozidla.pdf
2021-05-09 21:20 - 2021-05-09 21:37 - 000000000 ____D C:\Users\Lenovo\Desktop\Chvojnica foto
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-19 19:26 - 2019-08-22 16:29 - 000000000 ____D C:\ProgramData\NVIDIA
2021-05-19 19:20 - 2019-08-27 17:39 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Spotify
2021-05-19 19:01 - 2017-09-29 15:44 - 000000000 ____D C:\Windows\INF
2021-05-19 18:59 - 2017-11-28 05:51 - 002644372 _____ C:\Windows\system32\PerfStringBackup.INI
2021-05-19 18:58 - 2019-08-22 16:13 - 000003200 _____ C:\Windows\system32\Tasks\KMS_VL_ALL
2021-05-19 18:55 - 2019-08-27 17:39 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Spotify
2021-05-19 18:54 - 2019-08-22 16:35 - 000000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2021-05-19 18:54 - 2019-08-22 16:34 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2021-05-19 18:54 - 2017-11-28 05:44 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-05-19 18:53 - 2017-09-29 10:45 - 000524288 _____ C:\Windows\system32\config\BBI
2021-05-19 18:48 - 2019-08-26 19:35 - 000000585 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2021-05-19 18:21 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\DeliveryOptimization
2021-05-19 18:16 - 2017-09-29 15:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-19 18:12 - 2019-08-25 18:04 - 000000000 ____D C:\Program Files\Microsoft Office
2021-05-19 17:35 - 2017-11-28 05:44 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-05-19 16:00 - 2020-03-09 19:45 - 000004214 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{98A11743-34EF-462B-BA7B-90F714C10810}
2021-05-17 18:11 - 2019-08-25 17:10 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\vlc
2021-05-17 17:28 - 2020-03-17 15:22 - 000001235 _____ C:\Users\Lenovo\Desktop\NBA 2K12.lnk
2021-05-17 14:50 - 2021-01-26 14:02 - 000002306 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-17 14:50 - 2021-01-26 14:02 - 000002265 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-05-17 14:50 - 2021-01-26 14:02 - 000002265 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-05-17 14:48 - 2019-08-25 18:00 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-05-11 23:30 - 2019-08-22 21:20 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-05-11 23:30 - 2019-08-22 21:20 - 000002272 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-05-11 23:30 - 2019-08-22 21:20 - 000002272 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-05-11 20:20 - 2019-08-22 21:09 - 000003382 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2628802422-3275970452-2401892349-1002
2021-05-11 20:19 - 2019-08-22 16:14 - 000002358 _____ C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-11 20:19 - 2019-08-22 16:14 - 000000000 ___RD C:\Users\Lenovo\OneDrive
2021-05-09 22:05 - 2020-03-21 13:50 - 000000000 ____D C:\Windows\Minidump
2021-04-26 15:49 - 2021-01-26 14:02 - 000003016 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateBrowserReplacementTask
2021-04-26 15:44 - 2021-01-26 14:01 - 000003480 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-04-26 15:44 - 2021-01-26 14:01 - 000003356 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-04-21 16:24 - 2019-08-22 21:19 - 000003418 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-21 16:24 - 2019-08-22 21:19 - 000003294 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
==================== Files in the root of some directories ========
2019-08-25 20:30 - 2019-08-25 20:30 - 000000017 _____ () C:\Users\Lenovo\AppData\Local\resmon.resmoncfg
==================== FCheck ================================
(If an entry is included in the fixlist, the file/folder will be moved.)
FCheck: C:\Windows\servicing\Skype.exe [2018-08-04] <==== ATTENTION
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2021-05-13 16:00
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2021
Ran by Lenovo (administrator) on DESKTOP-06V2301 (LENOVO 80M3) (19-05-2021 19:27:04)
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Platform: Windows 10 Pro Version 1709 16299.98 (X64) Language: Angličtina (USA) -> Slovenčina (Slovensko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation -> Microsoft Corporation) [File not signed] C:\Windows\servicing\Skype.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.51.72.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [916184 2014-07-02] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1903040 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM-x32\...\Run: [HKLM] => C:\Windows\servicing\Skype.exe [53104 2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed] <==== ATTENTION
HKLM-x32\...\Run: [EAC_MW_klient] => C:\Program Files (x86)\EAC MW klient\EAC_MW_klient.exe [10897808 2020-06-29] (Ministerstvo vnútra Slovenskej republiky -> Ministerstvo vnútra Slovenskej republiky)
HKLM\ DisallowedCertificates: 18AA37360A0698E6A1F54A9E8268FB127B70E189 (AVG Netherlands B.V) <==== ATTENTION
HKLM\ DisallowedCertificates: 1B581436B0ED7536755B8B1C81112509A5AAF6ED (Panda Security S.L) <==== ATTENTION
HKLM\ DisallowedCertificates: 1F25DF887B158E34E2FCB13171924610C8F6BA2F (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 2CC344E13934A69AA993E80C8E20FF0ACCB33F1E (Qihu 360 Software Co. Limited) <==== ATTENTION
HKLM\ DisallowedCertificates: 2F56FF8F95EE69A27C05DBB35924F847C86A66B4 (SurfRight B.V.) <==== ATTENTION
HKLM\ DisallowedCertificates: 31F5EE85DA34AD374D43776B54F6686E7E922737 (SurfRight B.V.) <==== ATTENTION
HKLM\ DisallowedCertificates: 3C92C9274AB6D3DD520B13029A2490C4A1D98BC0 (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: 42A8984E8B9C51F6B7274866F8726CA1E9057FAA (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: 58939B78BC28EF464220127BB754E3D130306988 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: 5ACE40BD51EE148F299D37527AE1AD744CDE8EBB (U)
HKLM\ DisallowedCertificates: 5CA5F811E011742B05D014D03F85848D81F41A63 (Zemana) <==== ATTENTION
HKLM\ DisallowedCertificates: 622271AF668F99BD94AC12E5EBF86E48FD50AECB (Qihu 360 Software Co. Limited) <==== ATTENTION
HKLM\ DisallowedCertificates: 6CD253D636A7B4D0E0981431BC064061A9853ED9 (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 76FBABF1EADED3B91DD7A76A6678301F1F87AA97 (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 84C08B7A367422AF5FEF8D353B36191ECE9DBAF7 (Check Point Software Technologies Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 9900CFAABC45B4247F9D78EE7E12B102D25EA325 (Avira Operations GmbH & Co. KG) <==== ATTENTION
HKLM\ DisallowedCertificates: 9A32249E9A6B9CF5C36B0749C81613524D37C594 (Safer Networking Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9C2479D4BEF807FEFE3CE2B6B2D7FC4C71E0EBA5 (Sophos Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: BEBFAE20957D4DE689A8B962AEE358EFE39F195F (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: BF9254919794C1075EA027889C5D304F1121C653 (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: BFA87DC996BD6BCB02B6F530D2C646A0B5A0D5A9 (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: DBFAD9D59A6A07DCEB004DBE2DC246B547249E86 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: E64232B7757A335C032414C6888633CC498E7CD6 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: F74407DCA8D49D42D72D88863C17AB905EB94D1C (U)
HKLM\ DisallowedCertificates: F75019695C0504E3ABEFEDCD8FBE500DA08EC8FA (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== ATTENTION
HKU\S-1-5-21-2628802422-3275970452-2401892349-1002\...\Run: [HKCU] => C:\Windows\servicing\Skype.exe [53104 2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed] <==== ATTENTION
HKU\S-1-5-21-2628802422-3275970452-2401892349-1002\...\Run: [Spotify] => C:\Users\Lenovo\AppData\Roaming\Spotify\Spotify.exe [23924296 2021-05-17] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-2628802422-3275970452-2401892349-1002\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [91016568 2020-12-02] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [HKCU] => C:\Windows\servicing\Skype.exe [53104 2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed] <==== ATTENTION
HKLM\...\Print\Monitors\IppMon: C:\Windows\system32\IPPMon.dll [226816 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.212\Installer\chrmstp.exe [2021-05-11] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{5460C4DF-B266-909E-CB58-E32B79832EB2}] -> C:\Windows\servicing\Skype.exe [2018-08-04] (Microsoft Corporation -> Microsoft Corporation) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Web Signer.lnk [2020-03-09]
ShortcutTarget: Web Signer.lnk -> C:\Program Files (x86)\Disig\Disig Web Signer 1.0.7\Updater\WebSignerTray.exe (Disig a.s. -> Disig a.s.)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0A04B061-C5DA-417D-98B9-B919B26194FC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {0AE5C622-0BB2-45B6-92E9-6EC664ECEA18} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [732096 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {11FAB1A1-5A55-46A5-85AA-680633E5201C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-22] (Google Inc -> Google LLC)
Task: {1AEADA79-BDFA-487E-BA46-A4983585AF0E} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1704384 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {24FA3197-2039-4433-A6A9-9B1B33D5D617} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {3280F8B7-EA58-4906-ADCE-E422D621ED91} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141152 2021-05-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {394E0E86-0146-425C-9F10-C3A28D416176} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {484B2982-622D-464D-9B81-D99FB9A33EDD} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [649152 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {55C379FB-9E8B-4BBF-9964-C10FE648667D} - System32\Tasks\KMS_VL_ALL => C:\Windows\schemas\Scripts\KMS_VL_ALL.cmd 0
Task: {7587DD83-4E3D-4248-BA3B-F45F16150EC4} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436672 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {84DE3DE4-BBAA-417A-906C-E31EE3707E10} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-22] (Google Inc -> Google LLC)
Task: {86FF91C9-7B19-43C6-8DB2-2C4502D62938} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {A305BA0A-E3F6-4EB8-B537-6B24F50602CC} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [732096 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A34A5849-7716-46D2-BA71-E66D0FFB28B3} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {D137A0B0-2101-4EAC-8804-3F81F3EBBFAC} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe
Task: {DE780A30-EAE2-4B2F-ACF1-CE9BC4E0D7C9} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5229504 2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {E1A24716-7FA3-41D4-9FC2-9653CD9E167A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [649152 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E235584B-AA0E-4CCA-9832-C882E4D6CC5E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141152 2021-05-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {EBC8A8A4-020D-4809-B772-E876D2276FB6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [946112 2017-06-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F0F022BD-4E95-4300-A87B-43238A8BA564} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5229504 2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-2628802422-3275970452-2401892349-1002] => Proxy is enabled.
ProxyServer: [S-1-5-21-2628802422-3275970452-2401892349-1002] => http=127.0.0.1:8877;https=127.0.0.1:8877
Tcpip\..\Interfaces\{3522593f-d6cc-46cd-af0b-dfb6eb3b14e5}: [DhcpNameServer] 10.9.0.2 10.9.0.4
Tcpip\..\Interfaces\{62c471aa-6048-45fd-9aa4-dd66eebd4b0f}: [DhcpNameServer] 89.207.131.21 8.8.8.8
ManualProxies: 1http=127.0.0.1:8877;https=127.0.0.1:8877
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-19]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-27] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: ditec.sk/DAsicFac -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~1.DLL [2019-03-06] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/DitecZepDViewerFb -> C:\PROGRA~2\Ditec\DViewer\NPDITE~1.DLL [2020-01-21] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigMessageContainer -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~2.DLL [2016-12-15] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesExtender -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~3.DLL [2016-12-15] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~1.DLL [2019-12-09] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/XmlDataContainerFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~2.DLL [2019-12-09] (DITEC, a.s. -> Ditec,a.s.)
Chrome:
=======
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default [2021-05-19]
CHR HomePage: Default -> hxxp://www.zoznam.sk/
CHR StartupUrls: Default -> "hxxp://www.facebook.com/","hxxp://www.twitter. ... google.sk/"
CHR Extension: (Prezentácie) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-08-22]
CHR Extension: (Dokumenty) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-08-22]
CHR Extension: (Disk Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-23]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-08-22]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-05-19]
CHR Extension: (Tabuľky) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-08-22]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-17]
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-05-07]
CHR Extension: (Kontrola pošty Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2019-09-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-11]
CHR Extension: (Disig Web Signer 1.0.7) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\odbdbcaekkgabdfaabepfjgiooilmaoe [2020-03-09]
CHR Extension: (Gmail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23]
CHR Extension: (Chrome Media Router) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-05-03]
CHR HKLM-x32\...\Chrome\Extension: [odbdbcaekkgabdfaabepfjgiooilmaoe]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8798600 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
S2 dLauncherLoopback; C:\Program Files (x86)\Ditec\DLauncher\dLauncherLoopback.exe [154960 2019-08-02] (DITEC, a.s. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4329952 2017-11-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 TermService; C:\Windows\SysWOW64\termsrv.dll [1018880 2019-02-08] (Microsoft Corporation) [File not signed] <==== ATTENTION (no ServiceDLL)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation -> Microsoft Corporation)
S2 Windows Shadow Copy Service; C:\Windows\servicing\secinit.exe [100864 2018-05-04] () [File not signed]
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
S2 Windows Updates Services; C:\Windows\servicing\starter.exe [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R3 MpKsl30f73fb6; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0D597868-B6A0-4AD6-AE87-7EA3D4CA551D}\MpKslDrv.sys [47336 2021-05-19] (Microsoft Windows -> Microsoft Corporation)
R3 tap0901; C:\Windows\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-19 19:27 - 2021-05-19 19:29 - 000020920 _____ C:\Users\Lenovo\Desktop\FRST.txt
2021-05-19 19:20 - 2021-05-19 19:25 - 000000000 ____D C:\AdwCleaner
2021-05-19 19:18 - 2021-05-19 19:19 - 008534696 _____ (Malwarebytes) C:\Users\Lenovo\Desktop\AdwCleaner.exe
2021-05-19 19:01 - 2021-05-19 19:28 - 000000000 ____D C:\FRST
2021-05-19 19:00 - 2021-05-19 19:00 - 002299904 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2021-05-19 18:02 - 2021-05-19 18:02 - 000000000 ____D C:\Users\Lenovo\Documents\TNS
2021-05-19 18:01 - 2021-05-19 18:27 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Deployment
2021-05-19 18:01 - 2021-05-19 18:01 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Apps\2.0
2021-05-17 17:50 - 2018-02-18 00:31 - 042864583 _____ C:\Users\Lenovo\Desktop\VID_20180217_233105.mp4
2021-05-11 20:57 - 2021-05-19 17:35 - 000000000 ____D C:\Users\Lenovo\Desktop\čaje pr
2021-05-10 19:37 - 2021-05-10 19:36 - 000045706 _____ C:\Users\Lenovo\Desktop\Bláznova ukolébavka - ukulele.pdf
2021-05-10 19:30 - 2021-05-10 19:26 - 000017256 _____ C:\Users\Lenovo\Desktop\splnomocnenie-na-prepis-vozidla.pdf
2021-05-09 21:20 - 2021-05-09 21:37 - 000000000 ____D C:\Users\Lenovo\Desktop\Chvojnica foto
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-19 19:26 - 2019-08-22 16:29 - 000000000 ____D C:\ProgramData\NVIDIA
2021-05-19 19:20 - 2019-08-27 17:39 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Spotify
2021-05-19 19:01 - 2017-09-29 15:44 - 000000000 ____D C:\Windows\INF
2021-05-19 18:59 - 2017-11-28 05:51 - 002644372 _____ C:\Windows\system32\PerfStringBackup.INI
2021-05-19 18:58 - 2019-08-22 16:13 - 000003200 _____ C:\Windows\system32\Tasks\KMS_VL_ALL
2021-05-19 18:55 - 2019-08-27 17:39 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Spotify
2021-05-19 18:54 - 2019-08-22 16:35 - 000000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2021-05-19 18:54 - 2019-08-22 16:34 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2021-05-19 18:54 - 2017-11-28 05:44 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-05-19 18:53 - 2017-09-29 10:45 - 000524288 _____ C:\Windows\system32\config\BBI
2021-05-19 18:48 - 2019-08-26 19:35 - 000000585 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2021-05-19 18:21 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\DeliveryOptimization
2021-05-19 18:16 - 2017-09-29 15:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-19 18:12 - 2019-08-25 18:04 - 000000000 ____D C:\Program Files\Microsoft Office
2021-05-19 17:35 - 2017-11-28 05:44 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-05-19 16:00 - 2020-03-09 19:45 - 000004214 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{98A11743-34EF-462B-BA7B-90F714C10810}
2021-05-17 18:11 - 2019-08-25 17:10 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\vlc
2021-05-17 17:28 - 2020-03-17 15:22 - 000001235 _____ C:\Users\Lenovo\Desktop\NBA 2K12.lnk
2021-05-17 14:50 - 2021-01-26 14:02 - 000002306 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-17 14:50 - 2021-01-26 14:02 - 000002265 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-05-17 14:50 - 2021-01-26 14:02 - 000002265 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-05-17 14:48 - 2019-08-25 18:00 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-05-11 23:30 - 2019-08-22 21:20 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-05-11 23:30 - 2019-08-22 21:20 - 000002272 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-05-11 23:30 - 2019-08-22 21:20 - 000002272 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-05-11 20:20 - 2019-08-22 21:09 - 000003382 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2628802422-3275970452-2401892349-1002
2021-05-11 20:19 - 2019-08-22 16:14 - 000002358 _____ C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-11 20:19 - 2019-08-22 16:14 - 000000000 ___RD C:\Users\Lenovo\OneDrive
2021-05-09 22:05 - 2020-03-21 13:50 - 000000000 ____D C:\Windows\Minidump
2021-04-26 15:49 - 2021-01-26 14:02 - 000003016 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateBrowserReplacementTask
2021-04-26 15:44 - 2021-01-26 14:01 - 000003480 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-04-26 15:44 - 2021-01-26 14:01 - 000003356 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-04-21 16:24 - 2019-08-22 21:19 - 000003418 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-21 16:24 - 2019-08-22 21:19 - 000003294 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
==================== Files in the root of some directories ========
2019-08-25 20:30 - 2019-08-25 20:30 - 000000017 _____ () C:\Users\Lenovo\AppData\Local\resmon.resmoncfg
==================== FCheck ================================
(If an entry is included in the fixlist, the file/folder will be moved.)
FCheck: C:\Windows\servicing\Skype.exe [2018-08-04] <==== ATTENTION
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2021-05-13 16:00
==================== End of FRST.txt ========================