asi virus
Napsal: 29 črc 2021 07:15
zdravim, od vcerejska mi vyskakuje okno s nehezkou reklamou a take zpravou, ze muj laptop je v ohrozeni, vim, ze jsem neco otevrela, co jsem zrejme nemela, prosim o kontrolu, dekuji vrele. bl.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-07-2021 01
Ran by A (administrator) on DESKTOP-V7NF5M6 (LENOVO 20BTS1R400) (29-07-2021 08:10:59)
Running from C:\Users\A\Desktop\vyhodit
Loaded Profiles: A
Platform: Windows 10 Pro Version 20H2 19042.1110 (X64) Language: English (United Kingdom)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe <4>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.92\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.92\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <50>
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\A\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Program Files\Synaptics\SynFP\Shared\SensorDBSynch.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Windows\System32\valWbioSyncSvc.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated -> Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [114273560 2020-10-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\A\AppData\Local\Microsoft\Teams\Update.exe [2454200 2021-07-01] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\A\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\A\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\RunOnce: [Uninstall 21.129.0627.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\A\AppData\Local\Microsoft\OneDrive\21.129.0627.0002"
HKLM\...\Windows x64\Print Processors\shj2mPC: C:\Windows\System32\spool\prtprocs\x64\shj2mpc.dll [65256 2019-04-01] (联想图像(天津)科技有限公司 -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\shj2m Langmon: C:\WINDOWS\system32\shj2mlm.dll [44264 2019-04-01] (联想图像(天津)科技有限公司 -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\92.0.4515.107\Installer\chrmstp.exe [2021-07-23] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0E8E41B8-AFD2-4A41-9655-60680F77FC2B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-26] (Adobe Inc. -> Adobe Inc.)
Task: {13A68152-6271-404D-B82A-8F02F6E77D73} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {19944E34-E891-4BAA-8111-0DC43ED4A769} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5311416 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {468A783A-023F-4DCD-8B33-1C48DF177996} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [696304 2021-04-16] (Mozilla Corporation -> Mozilla Foundation)
Task: {539A192D-5B6E-4EEE-88C9-10A39D19C56C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5311416 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {54C0F3D7-12EE-4B00-98E3-5C0EB979AA5A} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617584 2020-04-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {6A57FBC4-7598-4AFF-B436-D51F2FB9B769} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-02-24] (Google LLC -> Google LLC)
Task: {6AD1005C-70EB-4DEE-B11A-3FC9AB739CC3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7AC46872-A315-47BB-A064-C6B7DE6A82A1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9C185CA2-9AA2-4960-B1AA-345C2A64ED08} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B00317DE-B765-43D2-83E6-FE2DE83D28A0} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617584 2020-04-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {B99B3B4D-910E-4B21-8BDA-AE9EFC3D3FAE} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23182216 2021-07-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {C919DEE5-802E-4C97-B36E-AC15953EC371} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23182216 2021-07-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {D16ABE1E-0298-4226-A191-C0FCF9776C11} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-02-24] (Google LLC -> Google LLC)
Task: {D987AA6C-CD4E-4E3D-B56D-1F4F058AB151} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147296 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {E252C6D2-4452-467B-B39A-5BDBBD086F86} - System32\Tasks\RtsCM => C:\WINDOWS\RtsCM64.exe [225248 2017-10-31] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
Task: {FE6203F2-4ABF-44A2-BAFE-964DC6202F37} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147296 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{a444201f-da03-4fc3-9f12-69083a7c2b85}: [DhcpNameServer] 192.168.10.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\A\AppData\Local\Microsoft\Edge\User Data\Default [2021-07-26]
FireFox:
========
FF DefaultProfile: wuydc3is.default
FF ProfilePath: C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\wuydc3is.default [2021-04-29]
FF ProfilePath: C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\qt2z2wn1.default-release [2021-04-29]
FF Extension: (Video DownloadHelper) - C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\qt2z2wn1.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-04-29]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-05-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-05-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-06-27] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\A\AppData\Local\Google\Chrome\User Data\Default [2021-07-29]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://captchadecode.com; hxxps://meet.google.com
CHR HomePage: Default -> hxxp://search.findwide.com/?guid={85EE7439-38F2-48C5-8D6E-0748D8390267}&serpv=22
CHR StartupUrls: Default -> "hxxps://www.google.com/?trackid=sp-006","hxxps: ... google.com"
CHR Extension: (Slides) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-02-24]
CHR Extension: (Docs) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-02-24]
CHR Extension: (Google Drive) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-02-24]
CHR Extension: (YouTube) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-02-24]
CHR Extension: (Sheets) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-02-24]
CHR Extension: (Google Docs Offline) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-24]
CHR Extension: (Gmail) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-02-24]
CHR Extension: (Chrome Media Router) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-07-26]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-26] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9056672 2021-07-18] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5395384 2021-07-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182128 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 valWBFPolicyService; C:\WINDOWS\system32\valWBFPolicyService.exe [77792 2018-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated)
R2 valWbioSyncSvc; C:\WINDOWS\system32\valWbioSyncSvc.exe [48608 2018-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe [2665432 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe [136640 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2020-11-19] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 dlcdcncm; C:\WINDOWS\System32\drivers\dlcdcncm62_x64.sys [90328 2020-09-30] (DISPLAYLINK (UK) LIMITED -> DisplayLink Corp.)
R1 SMIDriverGen; C:\WINDOWS\system32\DRIVERS\smi.sys [31440 2018-04-25] (Synaptics Inc. -> Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43376 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 Tdsshbecr; C:\WINDOWS\System32\drivers\shbecr.sys [38496 2017-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gemalto)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-07-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [425192 2021-07-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76008 2021-07-10] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-07-29 08:10 - 2021-07-29 08:11 - 000000000 ____D C:\FRST
2021-07-18 14:12 - 2021-07-18 14:12 - 001823280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-07-18 14:12 - 2021-07-18 14:12 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-07-18 14:12 - 2021-07-18 14:12 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsraLegacy.tlb
2021-07-18 14:12 - 2021-07-18 14:12 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsraLegacy.tlb
2021-07-18 14:12 - 2021-07-18 14:12 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rendezvousSession.tlb
2021-07-18 14:12 - 2021-07-18 14:12 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\rendezvousSession.tlb
2021-07-11 11:12 - 2021-07-11 11:12 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll
2021-07-11 11:12 - 2021-07-11 11:12 - 001314128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-07-11 11:12 - 2021-07-11 11:12 - 000570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-07-11 11:12 - 2021-07-11 11:12 - 000452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-07-11 11:12 - 2021-07-11 11:12 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2021-07-11 11:12 - 2021-07-11 11:12 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2021-07-11 11:11 - 2021-07-11 11:11 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-07-11 11:11 - 2021-07-11 11:11 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-07-11 11:11 - 2021-07-11 11:11 - 000097792 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-07-11 11:11 - 2021-07-11 11:11 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-07-11 10:08 - 2021-07-11 10:08 - 000048773 _____ C:\Users\A\Downloads\ink1_195807128615.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-07-29 08:10 - 2021-03-03 14:20 - 000000000 ____D C:\Users\A\Desktop\vyhodit
2021-07-29 08:07 - 2021-02-24 08:54 - 000000000 ____D C:\Program Files (x86)\Google
2021-07-29 08:07 - 2021-02-08 15:13 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-07-29 08:05 - 2021-02-17 20:47 - 000003370 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-778287325-1988700057-2922616860-1001
2021-07-29 08:05 - 2021-02-17 20:47 - 000000000 ___RD C:\Users\A\OneDrive
2021-07-29 08:05 - 2021-02-17 20:43 - 000002367 _____ C:\Users\A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-07-29 08:04 - 2021-02-08 15:20 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-07-28 08:08 - 2021-02-08 15:13 - 000000000 ___HD C:\Program Files\WindowsApps
2021-07-28 08:08 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-07-26 21:35 - 2021-02-24 11:24 - 000000000 __SHD C:\Users\A\IntelGraphicsProfiles
2021-07-26 21:35 - 2021-02-24 06:58 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2021-07-26 21:35 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\ServiceState
2021-07-26 05:59 - 2021-02-26 12:08 - 000000000 ____D C:\Program Files\Microsoft Office
2021-07-23 17:57 - 2021-02-24 08:55 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-07-23 17:57 - 2021-02-24 08:55 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-07-23 17:57 - 2021-02-08 15:22 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-07-23 17:57 - 2021-02-08 15:22 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-07-21 11:47 - 2021-03-02 07:06 - 000000000 ____D C:\Users\A\Documents\finance
2021-07-21 06:57 - 2021-02-08 15:12 - 000000000 ____D C:\WINDOWS\INF
2021-07-19 09:26 - 2021-02-24 09:19 - 000687848 _____ C:\WINDOWS\system32\perfh005.dat
2021-07-19 09:26 - 2021-02-24 09:19 - 000141456 _____ C:\WINDOWS\system32\perfc005.dat
2021-07-19 09:26 - 2021-02-24 09:14 - 000684554 _____ C:\WINDOWS\system32\perfh01D.dat
2021-07-19 09:26 - 2021-02-24 09:14 - 000142014 _____ C:\WINDOWS\system32\perfc01D.dat
2021-07-19 09:26 - 2021-02-17 20:46 - 002412730 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-07-18 21:38 - 2021-02-24 06:57 - 000000000 ____D C:\ProgramData\Synaptics
2021-07-18 21:38 - 2021-02-08 15:20 - 000440784 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-07-18 21:38 - 2021-02-08 15:20 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-07-18 21:37 - 2021-02-08 15:20 - 000008192 ___SH C:\DumpStack.log.tmp
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SystemResources
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\Program Files\Common Files\System
2021-07-18 21:37 - 2021-02-08 15:08 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-07-18 14:15 - 2021-02-08 15:09 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-07-18 14:05 - 2021-02-25 08:16 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-07-18 14:03 - 2021-02-25 08:16 - 133422552 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-07-16 07:22 - 2021-02-24 08:54 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-07-16 07:22 - 2021-02-24 08:54 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-07-15 08:07 - 2021-02-17 20:43 - 000000000 ____D C:\Users\A\AppData\Local\Packages
2021-07-13 17:21 - 2021-02-24 09:25 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\setup
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\Provisioning
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-07-10 17:12 - 2021-02-08 15:20 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-07-05 11:41 - 2021-02-17 20:43 - 000000000 ____D C:\Users\A
2021-07-02 06:32 - 2021-02-08 15:21 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-07-02 06:32 - 2021-02-08 15:21 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-07-01 09:39 - 2021-02-26 12:35 - 000002344 _____ C:\Users\A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-07-01 09:39 - 2021-02-26 12:35 - 000002336 _____ C:\Users\A\Desktop\Microsoft Teams.lnk
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-07-2021 01
Ran by A (administrator) on DESKTOP-V7NF5M6 (LENOVO 20BTS1R400) (29-07-2021 08:10:59)
Running from C:\Users\A\Desktop\vyhodit
Loaded Profiles: A
Platform: Windows 10 Pro Version 20H2 19042.1110 (X64) Language: English (United Kingdom)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe <4>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.92\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.92\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <50>
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\A\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Program Files\Synaptics\SynFP\Shared\SensorDBSynch.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Windows\System32\valWbioSyncSvc.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated -> Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [114273560 2020-10-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\A\AppData\Local\Microsoft\Teams\Update.exe [2454200 2021-07-01] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\A\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\A\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-778287325-1988700057-2922616860-1001\...\RunOnce: [Uninstall 21.129.0627.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\A\AppData\Local\Microsoft\OneDrive\21.129.0627.0002"
HKLM\...\Windows x64\Print Processors\shj2mPC: C:\Windows\System32\spool\prtprocs\x64\shj2mpc.dll [65256 2019-04-01] (联想图像(天津)科技有限公司 -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\shj2m Langmon: C:\WINDOWS\system32\shj2mlm.dll [44264 2019-04-01] (联想图像(天津)科技有限公司 -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\92.0.4515.107\Installer\chrmstp.exe [2021-07-23] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0E8E41B8-AFD2-4A41-9655-60680F77FC2B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-26] (Adobe Inc. -> Adobe Inc.)
Task: {13A68152-6271-404D-B82A-8F02F6E77D73} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {19944E34-E891-4BAA-8111-0DC43ED4A769} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5311416 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {468A783A-023F-4DCD-8B33-1C48DF177996} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [696304 2021-04-16] (Mozilla Corporation -> Mozilla Foundation)
Task: {539A192D-5B6E-4EEE-88C9-10A39D19C56C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5311416 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {54C0F3D7-12EE-4B00-98E3-5C0EB979AA5A} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617584 2020-04-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {6A57FBC4-7598-4AFF-B436-D51F2FB9B769} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-02-24] (Google LLC -> Google LLC)
Task: {6AD1005C-70EB-4DEE-B11A-3FC9AB739CC3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7AC46872-A315-47BB-A064-C6B7DE6A82A1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9C185CA2-9AA2-4960-B1AA-345C2A64ED08} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B00317DE-B765-43D2-83E6-FE2DE83D28A0} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617584 2020-04-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {B99B3B4D-910E-4B21-8BDA-AE9EFC3D3FAE} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23182216 2021-07-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {C919DEE5-802E-4C97-B36E-AC15953EC371} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23182216 2021-07-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {D16ABE1E-0298-4226-A191-C0FCF9776C11} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-02-24] (Google LLC -> Google LLC)
Task: {D987AA6C-CD4E-4E3D-B56D-1F4F058AB151} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147296 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {E252C6D2-4452-467B-B39A-5BDBBD086F86} - System32\Tasks\RtsCM => C:\WINDOWS\RtsCM64.exe [225248 2017-10-31] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
Task: {FE6203F2-4ABF-44A2-BAFE-964DC6202F37} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147296 2021-07-24] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{a444201f-da03-4fc3-9f12-69083a7c2b85}: [DhcpNameServer] 192.168.10.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\A\AppData\Local\Microsoft\Edge\User Data\Default [2021-07-26]
FireFox:
========
FF DefaultProfile: wuydc3is.default
FF ProfilePath: C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\wuydc3is.default [2021-04-29]
FF ProfilePath: C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\qt2z2wn1.default-release [2021-04-29]
FF Extension: (Video DownloadHelper) - C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\qt2z2wn1.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-04-29]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-05-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-05-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-06-27] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\A\AppData\Local\Google\Chrome\User Data\Default [2021-07-29]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://captchadecode.com; hxxps://meet.google.com
CHR HomePage: Default -> hxxp://search.findwide.com/?guid={85EE7439-38F2-48C5-8D6E-0748D8390267}&serpv=22
CHR StartupUrls: Default -> "hxxps://www.google.com/?trackid=sp-006","hxxps: ... google.com"
CHR Extension: (Slides) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-02-24]
CHR Extension: (Docs) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-02-24]
CHR Extension: (Google Drive) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-02-24]
CHR Extension: (YouTube) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-02-24]
CHR Extension: (Sheets) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-02-24]
CHR Extension: (Google Docs Offline) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-24]
CHR Extension: (Gmail) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-02-24]
CHR Extension: (Chrome Media Router) - C:\Users\A\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-07-26]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-26] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9056672 2021-07-18] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5395384 2021-07-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182128 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 valWBFPolicyService; C:\WINDOWS\system32\valWBFPolicyService.exe [77792 2018-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated)
R2 valWbioSyncSvc; C:\WINDOWS\system32\valWbioSyncSvc.exe [48608 2018-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe [2665432 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe [136640 2021-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2020-11-19] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 dlcdcncm; C:\WINDOWS\System32\drivers\dlcdcncm62_x64.sys [90328 2020-09-30] (DISPLAYLINK (UK) LIMITED -> DisplayLink Corp.)
R1 SMIDriverGen; C:\WINDOWS\system32\DRIVERS\smi.sys [31440 2018-04-25] (Synaptics Inc. -> Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43376 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 Tdsshbecr; C:\WINDOWS\System32\drivers\shbecr.sys [38496 2017-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gemalto)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-07-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [425192 2021-07-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76008 2021-07-10] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-07-29 08:10 - 2021-07-29 08:11 - 000000000 ____D C:\FRST
2021-07-18 14:12 - 2021-07-18 14:12 - 001823280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-07-18 14:12 - 2021-07-18 14:12 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-07-18 14:12 - 2021-07-18 14:12 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsraLegacy.tlb
2021-07-18 14:12 - 2021-07-18 14:12 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsraLegacy.tlb
2021-07-18 14:12 - 2021-07-18 14:12 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rendezvousSession.tlb
2021-07-18 14:12 - 2021-07-18 14:12 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\rendezvousSession.tlb
2021-07-11 11:12 - 2021-07-11 11:12 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll
2021-07-11 11:12 - 2021-07-11 11:12 - 001314128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-07-11 11:12 - 2021-07-11 11:12 - 000570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-07-11 11:12 - 2021-07-11 11:12 - 000452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-07-11 11:12 - 2021-07-11 11:12 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2021-07-11 11:12 - 2021-07-11 11:12 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2021-07-11 11:11 - 2021-07-11 11:11 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-07-11 11:11 - 2021-07-11 11:11 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-07-11 11:11 - 2021-07-11 11:11 - 000097792 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-07-11 11:11 - 2021-07-11 11:11 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-07-11 10:08 - 2021-07-11 10:08 - 000048773 _____ C:\Users\A\Downloads\ink1_195807128615.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-07-29 08:10 - 2021-03-03 14:20 - 000000000 ____D C:\Users\A\Desktop\vyhodit
2021-07-29 08:07 - 2021-02-24 08:54 - 000000000 ____D C:\Program Files (x86)\Google
2021-07-29 08:07 - 2021-02-08 15:13 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-07-29 08:05 - 2021-02-17 20:47 - 000003370 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-778287325-1988700057-2922616860-1001
2021-07-29 08:05 - 2021-02-17 20:47 - 000000000 ___RD C:\Users\A\OneDrive
2021-07-29 08:05 - 2021-02-17 20:43 - 000002367 _____ C:\Users\A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-07-29 08:04 - 2021-02-08 15:20 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-07-28 08:08 - 2021-02-08 15:13 - 000000000 ___HD C:\Program Files\WindowsApps
2021-07-28 08:08 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-07-26 21:35 - 2021-02-24 11:24 - 000000000 __SHD C:\Users\A\IntelGraphicsProfiles
2021-07-26 21:35 - 2021-02-24 06:58 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2021-07-26 21:35 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\ServiceState
2021-07-26 05:59 - 2021-02-26 12:08 - 000000000 ____D C:\Program Files\Microsoft Office
2021-07-23 17:57 - 2021-02-24 08:55 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-07-23 17:57 - 2021-02-24 08:55 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-07-23 17:57 - 2021-02-08 15:22 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-07-23 17:57 - 2021-02-08 15:22 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-07-21 11:47 - 2021-03-02 07:06 - 000000000 ____D C:\Users\A\Documents\finance
2021-07-21 06:57 - 2021-02-08 15:12 - 000000000 ____D C:\WINDOWS\INF
2021-07-19 09:26 - 2021-02-24 09:19 - 000687848 _____ C:\WINDOWS\system32\perfh005.dat
2021-07-19 09:26 - 2021-02-24 09:19 - 000141456 _____ C:\WINDOWS\system32\perfc005.dat
2021-07-19 09:26 - 2021-02-24 09:14 - 000684554 _____ C:\WINDOWS\system32\perfh01D.dat
2021-07-19 09:26 - 2021-02-24 09:14 - 000142014 _____ C:\WINDOWS\system32\perfc01D.dat
2021-07-19 09:26 - 2021-02-17 20:46 - 002412730 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-07-18 21:38 - 2021-02-24 06:57 - 000000000 ____D C:\ProgramData\Synaptics
2021-07-18 21:38 - 2021-02-08 15:20 - 000440784 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-07-18 21:38 - 2021-02-08 15:20 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-07-18 21:37 - 2021-02-08 15:20 - 000008192 ___SH C:\DumpStack.log.tmp
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SystemResources
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-07-18 21:37 - 2021-02-08 15:13 - 000000000 ____D C:\Program Files\Common Files\System
2021-07-18 21:37 - 2021-02-08 15:08 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-07-18 14:15 - 2021-02-08 15:09 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-07-18 14:05 - 2021-02-25 08:16 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-07-18 14:03 - 2021-02-25 08:16 - 133422552 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-07-16 07:22 - 2021-02-24 08:54 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-07-16 07:22 - 2021-02-24 08:54 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-07-15 08:07 - 2021-02-17 20:43 - 000000000 ____D C:\Users\A\AppData\Local\Packages
2021-07-13 17:21 - 2021-02-24 09:25 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\setup
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\Provisioning
2021-07-11 21:41 - 2021-02-08 15:13 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-07-10 17:12 - 2021-02-08 15:20 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-07-05 11:41 - 2021-02-17 20:43 - 000000000 ____D C:\Users\A
2021-07-02 06:32 - 2021-02-08 15:21 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-07-02 06:32 - 2021-02-08 15:21 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-07-01 09:39 - 2021-02-26 12:35 - 000002344 _____ C:\Users\A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-07-01 09:39 - 2021-02-26 12:35 - 000002336 _____ C:\Users\A\Desktop\Microsoft Teams.lnk
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================