kontrola logu / pre Rudy
Napsal: 30 zář 2021 15:59
Logy sú urobené až po kontrole ADW cleanera, ktorý nič nenašiel
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-09-2021 02
Ran by saullerist (administrator) on DESKTOP-3SMP07F (TOSHIBA Satellite L650) (30-09-2021 16:49:58)
Running from C:\Users\saullerist\Downloads
Loaded Profiles: saullerist
Platform: Windows 10 Home Version Dev 21390.1000 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\DSDFunctionKeyCtlService.exe <2>
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\dynabookSystemService.exe
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\RMService.exe
(Google LLC -> ) C:\Program Files\Google\Drive File Stream\50.0.11.0\crashpad_handler.exe <2>
(Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> ) C:\Windows\System32\AggregatorHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.21390.1000_none_58f0e9ab64f38697\TiWorker.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\NisSrv.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Scans\MsMpEngCP.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\...\Run: [MicrosoftEdgeAutoLaunch_E9148071064FDAAA5D19B03EFBB79618] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\...\MountPoints2: {14f1611b-ca97-11eb-bc9d-00266c5324d3} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
HKLM\Software\...\Winlogon\GPExtensions: [{8472C2C4-6B70-4301-A20D-A6CEA5F82B7E}] -> C:\WINDOWS\System32\StartTileData.dll [2021-05-22] (Microsoft Windows -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {12469F3F-5031-4F7B-8132-E18178931DA8} - System32\Tasks\Microsoft\Windows\Shell\UpdateAgentTask_SetCBSEndOfLife => C:\WINDOWS\System32\ShellUpdateAgentTask.exe [70656 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {379DF88D-08EE-4275-9075-B4D700B3AAB3} - System32\Tasks\Microsoft\Windows\Printing\PrinterCleanupTask => {C56F065E-DE49-4E42-BE7C-305C45609D25} C:\Windows\System32\PrinterCleanupTask.dll [118784 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {3B945F77-EE4A-4117-89AF-DDAA236F2199} - System32\Tasks\Microsoft\Windows\AppListBackup\Backup => {E0DCC2CC-3354-45F2-8914-519E07809082} C:\WINDOWS\system32\AppListBackupLauncher.dll [110592 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {5A7B58D1-CE41-4C5B-B700-D3C6E5FA97A7} - System32\Tasks\Microsoft\Windows\Shell\ThemesSyncedImageDownload => {79F8E185-4E45-4B74-8182-02AA430661E4} C:\Windows\System32\Themes.SsfDownload.ScheduledTask.dll [200704 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {6421D9B9-C0DC-407A-A6CF-75D420E93DCD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6C0D9967-CD8A-4636-806A-C46992D7C871} - System32\Tasks\Microsoft\Windows\Shell\UpdateAgentTask_AcquireFOD => C:\WINDOWS\System32\ShellUpdateAgentTask.exe [70656 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {6CCBF424-E5AA-43D1-8288-B15995B8BE36} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {71509BA9-E999-493C-8018-9E4520B1DCB5} - System32\Tasks\Microsoft\Windows\Shell\UpdateAgentTask_RemoveFOD => C:\WINDOWS\System32\ShellUpdateAgentTask.exe [70656 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {7AF922E2-481A-48DC-8C9B-692F6D73701F} - System32\Tasks\Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup => C:\WINDOWS\system32\MdmDiagnosticsTool.exe [90112 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {83CE6C76-3F28-489E-A7C6-794989F68298} - System32\Tasks\S-1-5-21-1796023744-1759536030-3900380101-1002\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe
Task: {8EA618F5-29D9-4485-85C0-49A2C95463C7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B40F8511-B9B4-4F7B-9312-FC6DAA6B9F00} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {B91219DC-34E0-47A2-B494-6279369FA6B4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {BFB7A246-72BE-40AD-A724-9BE219683B69} - System32\Tasks\microsoft\windows\capabilityaccessmanager\maintenancetasks => %windir%\system32\rundll32.exe %windir%\system32\CapabilityAccessManager.dll,CapabilityAccessManagerDoStoreMaintenance
Task: {C5708D88-E25B-426C-A468-69F68E7A2CE6} - System32\Tasks\Microsoft\Windows\Kernel\La57Cleanup => C:\WINDOWS\system32\la57setup.exe [36864 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {DCB6B88A-7EDE-48DD-80A7-832385E1711A} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe
Task: {FC3FFFB2-C10E-4A94-8716-98ADE9FC8C3B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\WINDOWS\SysWOW64\nlansp_c.dll [83456 2021-05-22] (Microsoft Windows -> Microsoft Corporation) ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 07 C:\Windows\system32\nlansp_c.dll [126976 2021-05-22] (Microsoft Windows -> Microsoft Corporation) ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{5c6459f7-5caf-472f-850f-576031683b95}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{5c6459f7-5caf-472f-850f-576031683b95}: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{6246c65d-bac1-4762-89a6-06049b6e07d8}: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{6f775dc0-2278-405d-8f3d-3e457ae63af2}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9dfcf0d8-e52f-4e05-8126-662ce4070db5}: [DhcpNameServer] 192.168.1.1
Edge:
=======
DownloadDir: C:\Users\saullerist\Downloads
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\saullerist\AppData\Local\Microsoft\Edge\User Data\Default [2021-09-30]
Edge DownloadDir: Default -> C:\Users\saullerist\Downloads
Edge HomePage: Default -> hxxp://www.google.sk/
Edge StartupUrls: Default -> "hxxp://www.google.sk/"
Edge HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx <not found>
FireFox:
========
FF DefaultProfile: 7922d3ji.default
FF ProfilePath: C:\Users\saullerist\AppData\Roaming\Mozilla\Firefox\Profiles\7922d3ji.default [2021-06-02]
FF ProfilePath: C:\Users\saullerist\AppData\Roaming\Mozilla\Firefox\Profiles\4qhn5rad.default-release [2021-08-31]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 DSDFunctionKeyCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\DSDFunctionKeyCtlService.exe [625776 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
S3 FrameServerMonitor; C:\WINDOWS\system32\FrameServerMonitor.dll [319488 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 McpManagementService; C:\WINDOWS\System32\McpManagementService.dll [319488 2021-06-08] (Microsoft Windows -> Microsoft Corporation)
S3 NPSMSvc; C:\WINDOWS\System32\npsm.dll [233472 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 NPSMSvc; C:\WINDOWS\SysWOW64\npsm.dll [163840 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 P9RdrService; C:\WINDOWS\system32\p9rdrservice.dll [122880 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
R2 TSDSettingService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\dynabookSystemService.exe [44773040 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
S2 TSDTabletControlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\TOSTABSYSSVC.exe [296272 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
R2 TSDWirelessLEDCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\RMService.exe [446248 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\NisSrv.exe [2855480 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MsMpEng.exe [128376 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 a016bus; C:\WINDOWS\System32\drivers\a016bus.sys [109096 2008-01-18] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 a016mgmt; C:\WINDOWS\System32\drivers\a016mgmt.sys [130600 2008-01-18] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 a016obex; C:\WINDOWS\System32\drivers\a016obex.sys [125480 2008-01-18] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S0 ebdrv; C:\WINDOWS\System32\drivers\evbda.sys [3436320 2021-05-22] (Microsoft Windows -> Marvell Semiconductor Inc.)
S0 ebdrv0; C:\WINDOWS\System32\drivers\evbd0a.sys [3418912 2021-05-22] (Microsoft Windows -> QLogic Corporation)
S3 ExecutionContext; C:\WINDOWS\System32\Drivers\ExecutionContext.sys [61440 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
R3 FwLnk; C:\WINDOWS\System32\drivers\FwLnk.sys [9216 2009-07-07] (Microsoft Windows Hardware Compatibility Publisher -> TOSHIBA Corporation)
R1 googledrivefs3514; C:\WINDOWS\System32\DRIVERS\googledrivefs3514.sys [389144 2021-06-25] (Google LLC -> Google, Inc.)
R1 googledrivefs3525; C:\WINDOWS\System32\DRIVERS\googledrivefs3525.sys [389640 2021-08-09] (Google LLC -> Google, Inc.)
S3 HidSpiCx; C:\WINDOWS\System32\drivers\HidSpiCx.sys [118784 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 HWHandSet; C:\WINDOWS\System32\drivers\hw_quusbmdm.sys [226560 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hw_usbdev; C:\WINDOWS\System32\drivers\hw_usbdev.sys [116864 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R0 IntelPMT; C:\WINDOWS\System32\drivers\IntelPMT.sys [69952 2021-05-22] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
S0 megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [96032 2021-05-22] (Microsoft Windows -> Broadcom Inc)
S0 mpi3drvi; C:\WINDOWS\System32\drivers\mpi3drvi.sys [83232 2021-05-22] (Microsoft Windows -> Broadcom Limited)
S3 NDKPerf; C:\WINDOWS\System32\drivers\NDKPerf.sys [74016 2021-05-22] (Microsoft Windows -> )
S0 nvmedisk; C:\WINDOWS\System32\drivers\nvmedisk.sys [78112 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 s0016bus; C:\WINDOWS\System32\drivers\s0016bus.sys [115240 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0016mgmt; C:\WINDOWS\System32\drivers\s0016mgmt.sys [137256 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0016obex; C:\WINDOWS\System32\drivers\s0016obex.sys [136744 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0016unic; C:\WINDOWS\System32\drivers\s0016unic.sys [151592 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017bus; C:\WINDOWS\System32\drivers\s0017bus.sys [113704 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017mgmt; C:\WINDOWS\System32\drivers\s0017mgmt.sys [133160 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017obex; C:\WINDOWS\System32\drivers\s0017obex.sys [128552 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017unic; C:\WINDOWS\System32\drivers\s0017unic.sys [145960 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018bus; C:\WINDOWS\System32\drivers\s1018bus.sys [113704 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018mgmt; C:\WINDOWS\System32\drivers\s1018mgmt.sys [133160 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018obex; C:\WINDOWS\System32\drivers\s1018obex.sys [128552 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018unic; C:\WINDOWS\System32\drivers\s1018unic.sys [146472 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029bus; C:\WINDOWS\System32\drivers\s1029bus.sys [116264 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029mgmt; C:\WINDOWS\System32\drivers\s1029mgmt.sys [139304 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029obex; C:\WINDOWS\System32\drivers\s1029obex.sys [135208 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029unic; C:\WINDOWS\System32\drivers\s1029unic.sys [151592 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1039mgmt; C:\WINDOWS\System32\drivers\s1039mgmt.sys [141424 2010-03-15] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1039obex; C:\WINDOWS\System32\drivers\s1039obex.sys [137328 2010-03-15] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1039unic; C:\WINDOWS\System32\drivers\s1039unic.sys [158320 2010-03-15] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s916bus; C:\WINDOWS\System32\drivers\s916bus.sys [108072 2007-11-02] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s916mgmt; C:\WINDOWS\System32\drivers\s916mgmt.sys [130088 2007-11-02] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s916obex; C:\WINDOWS\System32\drivers\s916obex.sys [124968 2007-11-02] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 se3ebus; C:\WINDOWS\System32\drivers\se3ebus.sys [107784 2007-04-10] (MCCI Corporation -> MCCI Corporation)
S3 se3emgmt; C:\WINDOWS\System32\drivers\se3emgmt.sys [126216 2007-04-10] (MCCI Corporation -> MCCI Corporation)
S3 se3eobex; C:\WINDOWS\System32\drivers\se3eobex.sys [123144 2007-04-10] (MCCI Corporation -> MCCI Corporation)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [47816 2020-07-21] (Dynabook Inc. -> Dynabook Inc.)
R1 TosSrvCtlDrv; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\TosSrvCtlDrv.sys [25584 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
R0 TVALZ_O; C:\WINDOWS\System32\drivers\TVALZ_O.SYS [46088 2019-04-30] (Dynabook Inc. -> Dynabook Inc.)
S3 Usb4DeviceRouter; C:\WINDOWS\System32\DriverStore\FileRepository\usb4devicerouter.inf_amd64_9f6d680e75a57995\Usb4DeviceRouter.sys [827680 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 Usb4HostRouter; C:\WINDOWS\System32\DriverStore\FileRepository\usb4hostrouter.inf_amd64_cd0f44882a83a62c\Usb4HostRouter.sys [536864 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48544 2021-09-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [434400 2021-09-24] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-09-24] (Microsoft Windows -> Microsoft Corporation)
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-30 16:44 - 2021-09-30 16:47 - 000050080 _____ C:\Users\saullerist\Downloads\Addition.txt
2021-09-30 16:41 - 2021-09-30 16:51 - 000020923 _____ C:\Users\saullerist\Downloads\FRST.txt
2021-09-30 16:40 - 2021-09-30 16:50 - 000000000 ____D C:\FRST
2021-09-30 16:40 - 2021-09-30 16:40 - 002304512 _____ (Farbar) C:\Users\saullerist\Downloads\FRST64.exe
2021-09-30 16:38 - 2021-09-30 16:38 - 000000000 ____D C:\AdwCleaner
2021-09-30 16:37 - 2021-09-30 16:37 - 008553680 _____ (Malwarebytes) C:\Users\saullerist\Downloads\adwcleaner_8.3.0.exe
2021-09-01 19:22 - 2021-08-09 14:57 - 000389640 _____ (Google, Inc.) C:\WINDOWS\system32\Drivers\googledrivefs3525.sys
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-30 16:47 - 2021-05-22 14:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-09-30 15:51 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-09-30 15:48 - 2021-06-09 14:48 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-09-30 15:48 - 2021-06-09 14:26 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-09-30 15:48 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\SystemTemp
2021-09-30 15:48 - 2020-02-21 12:41 - 000012288 ___SH C:\DumpStack.log.tmp
2021-09-30 15:47 - 2021-05-22 14:36 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-09-30 15:38 - 2020-02-04 19:05 - 000000000 ____D C:\Users\saullerist\AppData\Local\CrashDumps
2021-09-30 13:18 - 2021-05-22 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2021-09-30 13:18 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-09-29 14:57 - 2021-06-08 13:18 - 000000000 ____D C:\Users\saullerist
2021-09-27 18:38 - 2021-07-06 20:45 - 000000000 ____D C:\WINDOWS\Minidump
2021-09-27 18:37 - 2016-01-06 01:43 - 000848265 ____N C:\WINDOWS\Minidump\092721-36625-01.dmp
2021-09-27 12:19 - 2020-05-06 20:08 - 000002527 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-24 12:37 - 2018-03-01 11:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-09-11 16:44 - 2017-10-18 10:41 - 000000000 ____D C:\Users\saullerist\AppData\Local\Packages
2021-09-11 16:42 - 2016-11-18 22:37 - 000000000 ____D C:\Users\saullerist\AppData\Roaming\Mozilla
2021-09-08 13:04 - 2021-06-09 14:39 - 009035642 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-09-08 13:04 - 2021-05-22 14:44 - 000000000 ____D C:\WINDOWS\INF
2021-09-08 13:04 - 2016-11-28 18:10 - 006209702 _____ C:\WINDOWS\system32\perfh01B.dat
2021-09-08 13:04 - 2016-11-28 18:10 - 001846180 _____ C:\WINDOWS\system32\perfc01B.dat
2021-09-03 16:40 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\SystemResources
2021-09-03 16:40 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-09-03 16:40 - 2021-05-22 14:36 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-09-03 16:39 - 2018-07-19 09:34 - 000000000 ____D C:\ProgramData\Packages
2021-09-01 19:23 - 2021-07-13 20:43 - 000002071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2021-08-31 12:03 - 2016-11-28 17:03 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-08-31 11:50 - 2021-06-08 10:30 - 000000000 ___DC C:\WINDOWS\Panther
==================== Files in the root of some directories ========
2020-02-26 21:13 - 2020-02-26 21:17 - 000000062 _____ () C:\Users\saullerist\AppData\Roaming\FalconX.cfg
2017-10-18 10:16 - 2020-04-08 14:19 - 000007597 _____ () C:\Users\saullerist\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-09-2021 02
Ran by saullerist (administrator) on DESKTOP-3SMP07F (TOSHIBA Satellite L650) (30-09-2021 16:49:58)
Running from C:\Users\saullerist\Downloads
Loaded Profiles: saullerist
Platform: Windows 10 Home Version Dev 21390.1000 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\DSDFunctionKeyCtlService.exe <2>
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\dynabookSystemService.exe
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\RMService.exe
(Google LLC -> ) C:\Program Files\Google\Drive File Stream\50.0.11.0\crashpad_handler.exe <2>
(Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> ) C:\Windows\System32\AggregatorHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.21390.1000_none_58f0e9ab64f38697\TiWorker.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\NisSrv.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Scans\MsMpEngCP.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\...\Run: [MicrosoftEdgeAutoLaunch_E9148071064FDAAA5D19B03EFBB79618] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\...\MountPoints2: {14f1611b-ca97-11eb-bc9d-00266c5324d3} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\50.0.11.0\GoogleDriveFS.exe [53381464 2021-08-09] (Google LLC -> Google, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
HKLM\Software\...\Winlogon\GPExtensions: [{8472C2C4-6B70-4301-A20D-A6CEA5F82B7E}] -> C:\WINDOWS\System32\StartTileData.dll [2021-05-22] (Microsoft Windows -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {12469F3F-5031-4F7B-8132-E18178931DA8} - System32\Tasks\Microsoft\Windows\Shell\UpdateAgentTask_SetCBSEndOfLife => C:\WINDOWS\System32\ShellUpdateAgentTask.exe [70656 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {379DF88D-08EE-4275-9075-B4D700B3AAB3} - System32\Tasks\Microsoft\Windows\Printing\PrinterCleanupTask => {C56F065E-DE49-4E42-BE7C-305C45609D25} C:\Windows\System32\PrinterCleanupTask.dll [118784 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {3B945F77-EE4A-4117-89AF-DDAA236F2199} - System32\Tasks\Microsoft\Windows\AppListBackup\Backup => {E0DCC2CC-3354-45F2-8914-519E07809082} C:\WINDOWS\system32\AppListBackupLauncher.dll [110592 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {5A7B58D1-CE41-4C5B-B700-D3C6E5FA97A7} - System32\Tasks\Microsoft\Windows\Shell\ThemesSyncedImageDownload => {79F8E185-4E45-4B74-8182-02AA430661E4} C:\Windows\System32\Themes.SsfDownload.ScheduledTask.dll [200704 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {6421D9B9-C0DC-407A-A6CF-75D420E93DCD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6C0D9967-CD8A-4636-806A-C46992D7C871} - System32\Tasks\Microsoft\Windows\Shell\UpdateAgentTask_AcquireFOD => C:\WINDOWS\System32\ShellUpdateAgentTask.exe [70656 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {6CCBF424-E5AA-43D1-8288-B15995B8BE36} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {71509BA9-E999-493C-8018-9E4520B1DCB5} - System32\Tasks\Microsoft\Windows\Shell\UpdateAgentTask_RemoveFOD => C:\WINDOWS\System32\ShellUpdateAgentTask.exe [70656 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {7AF922E2-481A-48DC-8C9B-692F6D73701F} - System32\Tasks\Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup => C:\WINDOWS\system32\MdmDiagnosticsTool.exe [90112 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {83CE6C76-3F28-489E-A7C6-794989F68298} - System32\Tasks\S-1-5-21-1796023744-1759536030-3900380101-1002\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe
Task: {8EA618F5-29D9-4485-85C0-49A2C95463C7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B40F8511-B9B4-4F7B-9312-FC6DAA6B9F00} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {B91219DC-34E0-47A2-B494-6279369FA6B4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {BFB7A246-72BE-40AD-A724-9BE219683B69} - System32\Tasks\microsoft\windows\capabilityaccessmanager\maintenancetasks => %windir%\system32\rundll32.exe %windir%\system32\CapabilityAccessManager.dll,CapabilityAccessManagerDoStoreMaintenance
Task: {C5708D88-E25B-426C-A468-69F68E7A2CE6} - System32\Tasks\Microsoft\Windows\Kernel\La57Cleanup => C:\WINDOWS\system32\la57setup.exe [36864 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
Task: {DCB6B88A-7EDE-48DD-80A7-832385E1711A} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe
Task: {FC3FFFB2-C10E-4A94-8716-98ADE9FC8C3B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MpCmdRun.exe [884544 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\WINDOWS\SysWOW64\nlansp_c.dll [83456 2021-05-22] (Microsoft Windows -> Microsoft Corporation) ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 07 C:\Windows\system32\nlansp_c.dll [126976 2021-05-22] (Microsoft Windows -> Microsoft Corporation) ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{5c6459f7-5caf-472f-850f-576031683b95}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{5c6459f7-5caf-472f-850f-576031683b95}: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{6246c65d-bac1-4762-89a6-06049b6e07d8}: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{6f775dc0-2278-405d-8f3d-3e457ae63af2}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9dfcf0d8-e52f-4e05-8126-662ce4070db5}: [DhcpNameServer] 192.168.1.1
Edge:
=======
DownloadDir: C:\Users\saullerist\Downloads
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\saullerist\AppData\Local\Microsoft\Edge\User Data\Default [2021-09-30]
Edge DownloadDir: Default -> C:\Users\saullerist\Downloads
Edge HomePage: Default -> hxxp://www.google.sk/
Edge StartupUrls: Default -> "hxxp://www.google.sk/"
Edge HKU\S-1-5-21-1796023744-1759536030-3900380101-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx <not found>
FireFox:
========
FF DefaultProfile: 7922d3ji.default
FF ProfilePath: C:\Users\saullerist\AppData\Roaming\Mozilla\Firefox\Profiles\7922d3ji.default [2021-06-02]
FF ProfilePath: C:\Users\saullerist\AppData\Roaming\Mozilla\Firefox\Profiles\4qhn5rad.default-release [2021-08-31]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 DSDFunctionKeyCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\DSDFunctionKeyCtlService.exe [625776 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
S3 FrameServerMonitor; C:\WINDOWS\system32\FrameServerMonitor.dll [319488 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 McpManagementService; C:\WINDOWS\System32\McpManagementService.dll [319488 2021-06-08] (Microsoft Windows -> Microsoft Corporation)
S3 NPSMSvc; C:\WINDOWS\System32\npsm.dll [233472 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 NPSMSvc; C:\WINDOWS\SysWOW64\npsm.dll [163840 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 P9RdrService; C:\WINDOWS\system32\p9rdrservice.dll [122880 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
R2 TSDSettingService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\dynabookSystemService.exe [44773040 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
S2 TSDTabletControlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\TOSTABSYSSVC.exe [296272 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
R2 TSDWirelessLEDCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\RMService.exe [446248 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\NisSrv.exe [2855480 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2109.4-0\MsMpEng.exe [128376 2021-09-24] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 a016bus; C:\WINDOWS\System32\drivers\a016bus.sys [109096 2008-01-18] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 a016mgmt; C:\WINDOWS\System32\drivers\a016mgmt.sys [130600 2008-01-18] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 a016obex; C:\WINDOWS\System32\drivers\a016obex.sys [125480 2008-01-18] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S0 ebdrv; C:\WINDOWS\System32\drivers\evbda.sys [3436320 2021-05-22] (Microsoft Windows -> Marvell Semiconductor Inc.)
S0 ebdrv0; C:\WINDOWS\System32\drivers\evbd0a.sys [3418912 2021-05-22] (Microsoft Windows -> QLogic Corporation)
S3 ExecutionContext; C:\WINDOWS\System32\Drivers\ExecutionContext.sys [61440 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
R3 FwLnk; C:\WINDOWS\System32\drivers\FwLnk.sys [9216 2009-07-07] (Microsoft Windows Hardware Compatibility Publisher -> TOSHIBA Corporation)
R1 googledrivefs3514; C:\WINDOWS\System32\DRIVERS\googledrivefs3514.sys [389144 2021-06-25] (Google LLC -> Google, Inc.)
R1 googledrivefs3525; C:\WINDOWS\System32\DRIVERS\googledrivefs3525.sys [389640 2021-08-09] (Google LLC -> Google, Inc.)
S3 HidSpiCx; C:\WINDOWS\System32\drivers\HidSpiCx.sys [118784 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 HWHandSet; C:\WINDOWS\System32\drivers\hw_quusbmdm.sys [226560 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hw_usbdev; C:\WINDOWS\System32\drivers\hw_usbdev.sys [116864 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R0 IntelPMT; C:\WINDOWS\System32\drivers\IntelPMT.sys [69952 2021-05-22] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
S0 megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [96032 2021-05-22] (Microsoft Windows -> Broadcom Inc)
S0 mpi3drvi; C:\WINDOWS\System32\drivers\mpi3drvi.sys [83232 2021-05-22] (Microsoft Windows -> Broadcom Limited)
S3 NDKPerf; C:\WINDOWS\System32\drivers\NDKPerf.sys [74016 2021-05-22] (Microsoft Windows -> )
S0 nvmedisk; C:\WINDOWS\System32\drivers\nvmedisk.sys [78112 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 s0016bus; C:\WINDOWS\System32\drivers\s0016bus.sys [115240 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0016mgmt; C:\WINDOWS\System32\drivers\s0016mgmt.sys [137256 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0016obex; C:\WINDOWS\System32\drivers\s0016obex.sys [136744 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0016unic; C:\WINDOWS\System32\drivers\s0016unic.sys [151592 2008-05-16] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017bus; C:\WINDOWS\System32\drivers\s0017bus.sys [113704 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017mgmt; C:\WINDOWS\System32\drivers\s0017mgmt.sys [133160 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017obex; C:\WINDOWS\System32\drivers\s0017obex.sys [128552 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s0017unic; C:\WINDOWS\System32\drivers\s0017unic.sys [145960 2008-10-21] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018bus; C:\WINDOWS\System32\drivers\s1018bus.sys [113704 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018mgmt; C:\WINDOWS\System32\drivers\s1018mgmt.sys [133160 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018obex; C:\WINDOWS\System32\drivers\s1018obex.sys [128552 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1018unic; C:\WINDOWS\System32\drivers\s1018unic.sys [146472 2009-03-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029bus; C:\WINDOWS\System32\drivers\s1029bus.sys [116264 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029mgmt; C:\WINDOWS\System32\drivers\s1029mgmt.sys [139304 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029obex; C:\WINDOWS\System32\drivers\s1029obex.sys [135208 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1029unic; C:\WINDOWS\System32\drivers\s1029unic.sys [151592 2009-05-25] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1039mgmt; C:\WINDOWS\System32\drivers\s1039mgmt.sys [141424 2010-03-15] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1039obex; C:\WINDOWS\System32\drivers\s1039obex.sys [137328 2010-03-15] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s1039unic; C:\WINDOWS\System32\drivers\s1039unic.sys [158320 2010-03-15] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s916bus; C:\WINDOWS\System32\drivers\s916bus.sys [108072 2007-11-02] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s916mgmt; C:\WINDOWS\System32\drivers\s916mgmt.sys [130088 2007-11-02] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 s916obex; C:\WINDOWS\System32\drivers\s916obex.sys [124968 2007-11-02] (Sony Ericsson Mobile Communications AB -> MCCI Corporation)
S3 se3ebus; C:\WINDOWS\System32\drivers\se3ebus.sys [107784 2007-04-10] (MCCI Corporation -> MCCI Corporation)
S3 se3emgmt; C:\WINDOWS\System32\drivers\se3emgmt.sys [126216 2007-04-10] (MCCI Corporation -> MCCI Corporation)
S3 se3eobex; C:\WINDOWS\System32\drivers\se3eobex.sys [123144 2007-04-10] (MCCI Corporation -> MCCI Corporation)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [47816 2020-07-21] (Dynabook Inc. -> Dynabook Inc.)
R1 TosSrvCtlDrv; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_f06ed65d98eceea8\TosSrvCtlDrv.sys [25584 2021-05-26] (Dynabook Inc. -> Dynabook Inc.)
R0 TVALZ_O; C:\WINDOWS\System32\drivers\TVALZ_O.SYS [46088 2019-04-30] (Dynabook Inc. -> Dynabook Inc.)
S3 Usb4DeviceRouter; C:\WINDOWS\System32\DriverStore\FileRepository\usb4devicerouter.inf_amd64_9f6d680e75a57995\Usb4DeviceRouter.sys [827680 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S3 Usb4HostRouter; C:\WINDOWS\System32\DriverStore\FileRepository\usb4hostrouter.inf_amd64_cd0f44882a83a62c\Usb4HostRouter.sys [536864 2021-05-22] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48544 2021-09-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [434400 2021-09-24] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-09-24] (Microsoft Windows -> Microsoft Corporation)
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-30 16:44 - 2021-09-30 16:47 - 000050080 _____ C:\Users\saullerist\Downloads\Addition.txt
2021-09-30 16:41 - 2021-09-30 16:51 - 000020923 _____ C:\Users\saullerist\Downloads\FRST.txt
2021-09-30 16:40 - 2021-09-30 16:50 - 000000000 ____D C:\FRST
2021-09-30 16:40 - 2021-09-30 16:40 - 002304512 _____ (Farbar) C:\Users\saullerist\Downloads\FRST64.exe
2021-09-30 16:38 - 2021-09-30 16:38 - 000000000 ____D C:\AdwCleaner
2021-09-30 16:37 - 2021-09-30 16:37 - 008553680 _____ (Malwarebytes) C:\Users\saullerist\Downloads\adwcleaner_8.3.0.exe
2021-09-01 19:22 - 2021-08-09 14:57 - 000389640 _____ (Google, Inc.) C:\WINDOWS\system32\Drivers\googledrivefs3525.sys
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-30 16:47 - 2021-05-22 14:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-09-30 15:51 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-09-30 15:48 - 2021-06-09 14:48 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-09-30 15:48 - 2021-06-09 14:26 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-09-30 15:48 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\SystemTemp
2021-09-30 15:48 - 2020-02-21 12:41 - 000012288 ___SH C:\DumpStack.log.tmp
2021-09-30 15:47 - 2021-05-22 14:36 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-09-30 15:38 - 2020-02-04 19:05 - 000000000 ____D C:\Users\saullerist\AppData\Local\CrashDumps
2021-09-30 13:18 - 2021-05-22 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2021-09-30 13:18 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-09-29 14:57 - 2021-06-08 13:18 - 000000000 ____D C:\Users\saullerist
2021-09-27 18:38 - 2021-07-06 20:45 - 000000000 ____D C:\WINDOWS\Minidump
2021-09-27 18:37 - 2016-01-06 01:43 - 000848265 ____N C:\WINDOWS\Minidump\092721-36625-01.dmp
2021-09-27 12:19 - 2020-05-06 20:08 - 000002527 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-24 12:37 - 2018-03-01 11:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-09-11 16:44 - 2017-10-18 10:41 - 000000000 ____D C:\Users\saullerist\AppData\Local\Packages
2021-09-11 16:42 - 2016-11-18 22:37 - 000000000 ____D C:\Users\saullerist\AppData\Roaming\Mozilla
2021-09-08 13:04 - 2021-06-09 14:39 - 009035642 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-09-08 13:04 - 2021-05-22 14:44 - 000000000 ____D C:\WINDOWS\INF
2021-09-08 13:04 - 2016-11-28 18:10 - 006209702 _____ C:\WINDOWS\system32\perfh01B.dat
2021-09-08 13:04 - 2016-11-28 18:10 - 001846180 _____ C:\WINDOWS\system32\perfc01B.dat
2021-09-03 16:40 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\SystemResources
2021-09-03 16:40 - 2021-05-22 14:46 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-09-03 16:40 - 2021-05-22 14:36 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-09-03 16:39 - 2018-07-19 09:34 - 000000000 ____D C:\ProgramData\Packages
2021-09-01 19:23 - 2021-07-13 20:43 - 000002071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2021-08-31 12:03 - 2016-11-28 17:03 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-08-31 11:50 - 2021-06-08 10:30 - 000000000 ___DC C:\WINDOWS\Panther
==================== Files in the root of some directories ========
2020-02-26 21:13 - 2020-02-26 21:17 - 000000062 _____ () C:\Users\saullerist\AppData\Roaming\FalconX.cfg
2017-10-18 10:16 - 2020-04-08 14:19 - 000007597 _____ () C:\Users\saullerist\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================