Pomalý start a chod NTB
Napsal: 30 říj 2021 16:04
Dobrý den,
snažil jsem se po delší době rozjet NTB rodičů a pouhý start trval asi 15 minut.
Rozjel jsem FRST a log nabíhal asi 25 minut. Prosím o kontrolu. Rodiče měli z nějakého důvodu nainstalovaný AVG antivirus, ale nikdo ho prý vědomě neinstaloval...
Předem moc díky za případnou pomoc a log níže.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2021
Ran by Mamka a taťka (administrator) on DESKTOP-1FPBJIJ (LENOVO 81HL) (30-10-2021 16:41:59)
Running from C:\Users\Mamka a taťka\Desktop\Čištění
Loaded Profiles: Mamka a taťka
: Microsoft Windows 10 Home Version 21H1 19043.1288 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Conexant Systems LLC -> Conexant Systems, Inc.) C:\Windows\System32\CxUIUSvc32.exe
(Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Dolby Laboratories, Inc. -> ) C:\Windows\System32\dolbyaposvc\DAX3API.exe <2>
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <10>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) pGFX -> ) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_7177cf092021a5b2\OneApp.IGCC.WinService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_79ffdc5b7f66bb58\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_79ffdc5b7f66bb58\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_eab4a3cc9d877ce2\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_eab4a3cc9d877ce2\IntelCpHeciSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCopyAccelerator.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-21-1481426235-2738210657-3485090854-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35116160 2021-10-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\95.0.4638.54\Installer\chrmstp.exe [2021-10-27] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {083FDD92-4B46-4AE2-82E9-BAF8451BC3D5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1790184 2021-04-30] (Avast Software s.r.o. -> Avast Software)
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\Adobe Acrobat Update Task" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\Antivirus Emergency Update" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\CCleanerSkipUAC" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\CCleanerSkipUAC - Mamka a taťka" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore1d6ccc9b9f3b914" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(10): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(11): schtasks.exe -> /Change /TN "\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-1002" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(12): schtasks.exe -> /Change /TN "\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-500" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(13): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {508605AE-247D-4E69-AE2D-3FBC89C608A7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [29200512 2021-10-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {71FF3053-0A80-4BB0-B0AD-39702861F048} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-27] (Google Inc -> Google Inc.)
Task: {7ADC47E2-C247-4B10-9148-9EF69D66BBF8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-10-19] (Piriform Software Ltd -> Piriform)
Task: {C14FD7F8-8589-4AD2-A231-65D73BCFB284} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-27] (Google Inc -> Google Inc.)
Task: {C402DDC0-38F0-4948-B1FC-5C365588D986} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.)
Task: {C71C202B-12B3-4F6A-8CB6-83CDDA289DE4} - System32\Tasks\CCleanerSkipUAC - Mamka a taťka => C:\Program Files\CCleaner\CCleaner.exe [29200512 2021-10-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E14930CD-C30A-4E85-B2A8-75B80B64A8D6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {EA6E6608-3FA9-4EB2-B8B8-0A6159FB31DB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 81.200.55.161 81.200.48.13 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{2a1b4270-c285-4b96-8535-ca7573241bb2}: [DhcpNameServer] 81.200.55.161 81.200.48.13 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{cf192880-4ac5-46f7-86f9-381d7fbbe1e5}: [DhcpNameServer] 81.19.33.2 81.19.34.2
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Mamka a taťka\AppData\Local\Microsoft\Edge\User Data\Default [2021-09-06]
FireFox:
========
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-09-25] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default [2021-10-30]
CHR Notifications: Default -> hxxps//live-stream365.com; hxxps//meet.google.com; hxxps//www.youtube.com
CHR HomePage: Default -> hxxp//seznam.cz/
CHR Extension: (Prezentace) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-01-27]
CHR Extension: (Dokumenty) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-01-27]
CHR Extension: (Disk Google) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26]
CHR Extension: (YouTube) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-01-27]
CHR Extension: (Tabulky) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-01-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-10-21]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-10-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Gmail) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.)
R2 DolbyDAXAPI; C:\WINDOWS\system32\dolbyaposvc\DAX3API.exe [602632 2018-08-27] (Dolby Laboratories, Inc. -> )
R2 FMAPOService; C:\WINDOWS\System32\FMService64.exe [360320 2019-09-05] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-11-28] (ESET, spol. s r.o. -> ESET)
S4 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50280 2019-04-05] (ESET, spol. s r.o. -> ESET)
S4 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [82472 2019-04-05] (ESET, spol. s r.o. -> ESET)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48520 2021-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435424 2021-10-30] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-10-30] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-10-27 21:33 - 2021-10-27 21:33 - 000000000 ___HD C:\$WinREAgent
2021-10-23 19:18 - 2021-10-23 19:18 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2021-10-23 19:18 - 2021-10-23 19:18 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2021-10-23 19:16 - 2021-10-23 19:16 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-10-23 19:16 - 2021-10-23 19:16 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-10-23 19:16 - 2021-10-23 19:16 - 000011495 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-10-23 19:15 - 2021-10-23 19:15 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2021-10-23 19:15 - 2021-10-23 19:15 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-10-23 19:14 - 2021-10-23 19:14 - 001823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-10-23 19:14 - 2021-10-23 19:14 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-10-23 19:13 - 2021-10-23 19:13 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll
2021-10-23 19:13 - 2021-10-23 19:13 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-10-23 19:12 - 2021-10-23 19:12 - 000593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-10-23 19:12 - 2021-10-23 19:12 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2021-10-02 19:31 - 2021-09-21 14:18 - 000051453 ____N C:\Users\Mamka a taťka\Downloads\Informace o splatnosti ke smlouvě číslo 9730981610.pdf
2021-10-02 19:29 - 2021-10-02 19:29 - 000047215 _____ C:\Users\Mamka a taťka\Downloads\Informace o splatnosti ke smlouve cislo 9730981610.zip
2021-10-02 19:28 - 2021-10-02 19:29 - 000047215 _____ C:\Users\Mamka a taťka\Downloads\Informace o splatnosti ke smlouve cislo 9730981610 (1).zip
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-10-30 16:52 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-10-30 16:52 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-10-30 16:49 - 2019-01-27 14:41 - 000000000 ____D C:\Program Files (x86)\Google
2021-10-30 16:46 - 2019-01-18 20:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-10-30 16:45 - 2021-04-04 11:00 - 000000000 ____D C:\FRST
2021-10-30 16:41 - 2021-04-04 12:05 - 000000000 ____D C:\Users\Mamka a taťka\Desktop\Čištění
2021-10-30 16:38 - 2019-05-04 12:46 - 000000000 ____D C:\Program Files\CCleaner
2021-10-30 16:35 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-10-30 16:33 - 2019-01-27 14:23 - 000000000 __SHD C:\Users\Mamka a taťka\IntelGraphicsProfiles
2021-10-30 16:32 - 2020-06-19 19:31 - 000000134 _____ C:\WINDOWS\system32\regtest.txt
2021-10-30 16:31 - 2021-07-25 10:19 - 000000000 ____D C:\ProgramData\AVG
2021-10-30 16:31 - 2020-12-07 21:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-10-30 16:31 - 2020-12-07 20:35 - 000008192 ___SH C:\DumpStack.log.tmp
2021-10-30 16:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-10-30 16:30 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-10-30 16:29 - 2020-12-07 20:40 - 000000000 ____D C:\Users\Mamka a taťka
2021-10-30 16:27 - 2019-01-18 14:23 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-10-28 11:38 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-10-27 22:19 - 2021-01-20 11:45 - 000003318 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6ccc9b9f3b914
2021-10-27 22:19 - 2020-12-07 21:06 - 000003512 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-10-27 22:19 - 2020-12-07 21:06 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-10-27 22:19 - 2020-12-07 21:06 - 000003402 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-10-27 22:19 - 2020-12-07 21:06 - 000003288 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-10-27 22:19 - 2020-12-07 21:06 - 000003178 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-10-27 22:19 - 2020-12-07 21:06 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-10-27 22:19 - 2020-12-07 21:06 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-1002
2021-10-27 22:19 - 2020-12-07 21:06 - 000002856 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-500
2021-10-27 22:19 - 2020-12-07 21:06 - 000002238 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2021-10-27 22:19 - 2020-12-07 20:36 - 000349128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-10-27 21:53 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-10-27 20:29 - 2021-08-18 20:43 - 000002270 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Mamka a taťka
2021-10-27 18:51 - 2020-12-07 20:36 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-10-27 18:31 - 2019-01-27 14:43 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-10-27 18:31 - 2019-01-27 14:43 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-10-27 18:27 - 2020-12-07 21:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2021-10-25 19:39 - 2020-06-08 20:46 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-10-25 19:39 - 2020-06-08 20:46 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-10-21 09:56 - 2019-01-18 14:30 - 139806512 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-10-21 09:56 - 2019-01-18 14:30 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-10-21 09:52 - 2020-12-07 20:40 - 000002405 _____ C:\Users\Mamka a taťka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-10-18 08:57 - 2019-07-19 08:54 - 000000000 ____D C:\Users\Mamka a taťka\AppData\Local\CrashDumps
2021-10-03 17:53 - 2020-09-30 14:59 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-10-02 19:36 - 2019-03-06 16:02 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
snažil jsem se po delší době rozjet NTB rodičů a pouhý start trval asi 15 minut.
Rozjel jsem FRST a log nabíhal asi 25 minut. Prosím o kontrolu. Rodiče měli z nějakého důvodu nainstalovaný AVG antivirus, ale nikdo ho prý vědomě neinstaloval...
Předem moc díky za případnou pomoc a log níže.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2021
Ran by Mamka a taťka (administrator) on DESKTOP-1FPBJIJ (LENOVO 81HL) (30-10-2021 16:41:59)
Running from C:\Users\Mamka a taťka\Desktop\Čištění
Loaded Profiles: Mamka a taťka
: Microsoft Windows 10 Home Version 21H1 19043.1288 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Conexant Systems LLC -> Conexant Systems, Inc.) C:\Windows\System32\CxUIUSvc32.exe
(Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Dolby Laboratories, Inc. -> ) C:\Windows\System32\dolbyaposvc\DAX3API.exe <2>
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <10>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) pGFX -> ) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_7177cf092021a5b2\OneApp.IGCC.WinService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_79ffdc5b7f66bb58\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_79ffdc5b7f66bb58\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_eab4a3cc9d877ce2\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_eab4a3cc9d877ce2\IntelCpHeciSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCopyAccelerator.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-21-1481426235-2738210657-3485090854-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35116160 2021-10-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\95.0.4638.54\Installer\chrmstp.exe [2021-10-27] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {083FDD92-4B46-4AE2-82E9-BAF8451BC3D5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1790184 2021-04-30] (Avast Software s.r.o. -> Avast Software)
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\Adobe Acrobat Update Task" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\Antivirus Emergency Update" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\CCleanerSkipUAC" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\CCleanerSkipUAC - Mamka a taťka" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore1d6ccc9b9f3b914" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(10): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(11): schtasks.exe -> /Change /TN "\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-1002" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(12): schtasks.exe -> /Change /TN "\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-500" /ENABLE
Task: {2DFFB822-54AA-4689-B713-4A311F397B3A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(13): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {508605AE-247D-4E69-AE2D-3FBC89C608A7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [29200512 2021-10-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {71FF3053-0A80-4BB0-B0AD-39702861F048} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-27] (Google Inc -> Google Inc.)
Task: {7ADC47E2-C247-4B10-9148-9EF69D66BBF8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-10-19] (Piriform Software Ltd -> Piriform)
Task: {C14FD7F8-8589-4AD2-A231-65D73BCFB284} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-27] (Google Inc -> Google Inc.)
Task: {C402DDC0-38F0-4948-B1FC-5C365588D986} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.)
Task: {C71C202B-12B3-4F6A-8CB6-83CDDA289DE4} - System32\Tasks\CCleanerSkipUAC - Mamka a taťka => C:\Program Files\CCleaner\CCleaner.exe [29200512 2021-10-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E14930CD-C30A-4E85-B2A8-75B80B64A8D6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {EA6E6608-3FA9-4EB2-B8B8-0A6159FB31DB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 81.200.55.161 81.200.48.13 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{2a1b4270-c285-4b96-8535-ca7573241bb2}: [DhcpNameServer] 81.200.55.161 81.200.48.13 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{cf192880-4ac5-46f7-86f9-381d7fbbe1e5}: [DhcpNameServer] 81.19.33.2 81.19.34.2
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Mamka a taťka\AppData\Local\Microsoft\Edge\User Data\Default [2021-09-06]
FireFox:
========
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-09-25] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default [2021-10-30]
CHR Notifications: Default -> hxxps//live-stream365.com; hxxps//meet.google.com; hxxps//www.youtube.com
CHR HomePage: Default -> hxxp//seznam.cz/
CHR Extension: (Prezentace) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-01-27]
CHR Extension: (Dokumenty) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-01-27]
CHR Extension: (Disk Google) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26]
CHR Extension: (YouTube) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-01-27]
CHR Extension: (Tabulky) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-01-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-10-21]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-10-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Gmail) - C:\Users\Mamka a taťka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.)
R2 DolbyDAXAPI; C:\WINDOWS\system32\dolbyaposvc\DAX3API.exe [602632 2018-08-27] (Dolby Laboratories, Inc. -> )
R2 FMAPOService; C:\WINDOWS\System32\FMService64.exe [360320 2019-09-05] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-11-28] (ESET, spol. s r.o. -> ESET)
S4 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50280 2019-04-05] (ESET, spol. s r.o. -> ESET)
S4 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [82472 2019-04-05] (ESET, spol. s r.o. -> ESET)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48520 2021-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435424 2021-10-30] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-10-30] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-10-27 21:33 - 2021-10-27 21:33 - 000000000 ___HD C:\$WinREAgent
2021-10-23 19:18 - 2021-10-23 19:18 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2021-10-23 19:18 - 2021-10-23 19:18 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2021-10-23 19:16 - 2021-10-23 19:16 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-10-23 19:16 - 2021-10-23 19:16 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-10-23 19:16 - 2021-10-23 19:16 - 000011495 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-10-23 19:15 - 2021-10-23 19:15 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2021-10-23 19:15 - 2021-10-23 19:15 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-10-23 19:14 - 2021-10-23 19:14 - 001823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-10-23 19:14 - 2021-10-23 19:14 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-10-23 19:13 - 2021-10-23 19:13 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll
2021-10-23 19:13 - 2021-10-23 19:13 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-10-23 19:12 - 2021-10-23 19:12 - 000593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-10-23 19:12 - 2021-10-23 19:12 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2021-10-02 19:31 - 2021-09-21 14:18 - 000051453 ____N C:\Users\Mamka a taťka\Downloads\Informace o splatnosti ke smlouvě číslo 9730981610.pdf
2021-10-02 19:29 - 2021-10-02 19:29 - 000047215 _____ C:\Users\Mamka a taťka\Downloads\Informace o splatnosti ke smlouve cislo 9730981610.zip
2021-10-02 19:28 - 2021-10-02 19:29 - 000047215 _____ C:\Users\Mamka a taťka\Downloads\Informace o splatnosti ke smlouve cislo 9730981610 (1).zip
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-10-30 16:52 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-10-30 16:52 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-10-30 16:49 - 2019-01-27 14:41 - 000000000 ____D C:\Program Files (x86)\Google
2021-10-30 16:46 - 2019-01-18 20:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-10-30 16:45 - 2021-04-04 11:00 - 000000000 ____D C:\FRST
2021-10-30 16:41 - 2021-04-04 12:05 - 000000000 ____D C:\Users\Mamka a taťka\Desktop\Čištění
2021-10-30 16:38 - 2019-05-04 12:46 - 000000000 ____D C:\Program Files\CCleaner
2021-10-30 16:35 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-10-30 16:33 - 2019-01-27 14:23 - 000000000 __SHD C:\Users\Mamka a taťka\IntelGraphicsProfiles
2021-10-30 16:32 - 2020-06-19 19:31 - 000000134 _____ C:\WINDOWS\system32\regtest.txt
2021-10-30 16:31 - 2021-07-25 10:19 - 000000000 ____D C:\ProgramData\AVG
2021-10-30 16:31 - 2020-12-07 21:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-10-30 16:31 - 2020-12-07 20:35 - 000008192 ___SH C:\DumpStack.log.tmp
2021-10-30 16:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-10-30 16:30 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-10-30 16:29 - 2020-12-07 20:40 - 000000000 ____D C:\Users\Mamka a taťka
2021-10-30 16:27 - 2019-01-18 14:23 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-10-28 11:38 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-10-27 22:19 - 2021-01-20 11:45 - 000003318 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6ccc9b9f3b914
2021-10-27 22:19 - 2020-12-07 21:06 - 000003512 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-10-27 22:19 - 2020-12-07 21:06 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-10-27 22:19 - 2020-12-07 21:06 - 000003402 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-10-27 22:19 - 2020-12-07 21:06 - 000003288 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-10-27 22:19 - 2020-12-07 21:06 - 000003178 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-10-27 22:19 - 2020-12-07 21:06 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-10-27 22:19 - 2020-12-07 21:06 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-1002
2021-10-27 22:19 - 2020-12-07 21:06 - 000002856 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1481426235-2738210657-3485090854-500
2021-10-27 22:19 - 2020-12-07 21:06 - 000002238 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2021-10-27 22:19 - 2020-12-07 20:36 - 000349128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2021-10-27 22:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-10-27 21:53 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-10-27 20:29 - 2021-08-18 20:43 - 000002270 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Mamka a taťka
2021-10-27 18:51 - 2020-12-07 20:36 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-10-27 18:31 - 2019-01-27 14:43 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-10-27 18:31 - 2019-01-27 14:43 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-10-27 18:27 - 2020-12-07 21:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2021-10-25 19:39 - 2020-06-08 20:46 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-10-25 19:39 - 2020-06-08 20:46 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-10-21 09:56 - 2019-01-18 14:30 - 139806512 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-10-21 09:56 - 2019-01-18 14:30 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-10-21 09:52 - 2020-12-07 20:40 - 000002405 _____ C:\Users\Mamka a taťka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-10-18 08:57 - 2019-07-19 08:54 - 000000000 ____D C:\Users\Mamka a taťka\AppData\Local\CrashDumps
2021-10-03 17:53 - 2020-09-30 14:59 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-10-02 19:36 - 2019-03-06 16:02 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================