Preventivní kontrola - zvláštní chování FF
Napsal: 12 čer 2022 18:35
Zdravím, prosím o kontrolu logu. Firefox se mi poslední dobou chová nějak zvláštně, jako kdyby pořád na pozadí pracoval (vedle šipky se pravidelně ukazuje to kolečko). Díky!
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-06-2022 01
Ran by previ (administrator) on PC-PREVIT (12-06-2022 19:17:44)
Running from D:\Download
Loaded Profiles: previ & vitda
Platform: Microsoft Windows 11 Enterprise Version 21H2 22000.708 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Ostatni\Snagit 13\SnagitEditor.exe
(C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Ostatni\Snagit 13\SnagPriv.exe
(C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer.exe
(C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\tv_w32.exe
(C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\tv_x64.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\LGHUB\lghub.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_agent.exe
(C:\Program Files\Ostatni\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\Ostatni\ESET Security\eguiProxy.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\Ostatni\VirtualCloneDrive\VCDDaemon.exe
(explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub.exe <3>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(explorer.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe
(Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <14>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Safer-Networking Limited -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDTray.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Blizzard\Bonjour Service\mDNSResponder.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) E:\Hry\Origin\OriginWebHelperService.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\Ostatni\ESET Security\ekrn.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_577b4722c749a41f\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(services.exe ->) (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\Ostatni\MysticLight\MysticLight2_Service.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Safer-Networking Limited -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDFSSvc.exe
(services.exe ->) (Safer-Networking Limited -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDUpdSvc.exe
(services.exe ->) (Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDWSCSvc.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagicianSVC.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(services.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.GamingServices_4.66.2001.0_x64__8wekyb3d8bbwe\gamingservices.exe
(services.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.GamingServices_4.66.2001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
(sihost.exe ->) (0) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3408.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(svchost.exe ->) (0) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3408.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Intel(R) Software Development Products -> Intel Corporation) C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (QNAP Systems, Inc. -> QNAP Systems, Inc.) C:\Program Files (x86)\QNAP\Qsync\Qsync.exe
(svchost.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22042.168.0_x64__8wekyb3d8bbwe\YourPhone.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\Ostatni\ESET Security\ecmdS.exe [168064 2022-03-31] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [3465608 2017-10-01] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3427104 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDTray.exe [5204968 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\Ostatni\KeePass Password Safe 2\KeePass.exe [3074752 2020-05-07] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Ostatni\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [Qsync] => C:\Program Files (x86)\QNAP\Qsync\Qsync.exe [93184760 2022-03-23] (QNAP Systems, Inc. -> QNAP Systems, Inc.)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [CorsairLink4] => C:\Program Files (x86)\Ostatni\Corsair Link 4\CorsairLink4.exe [27146448 2018-03-30] (Corsair Components, Inc. -> Corsair Components, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [146943096 2022-06-10] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [EpicGamesLauncher] => E:\Hry\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32648144 2022-06-08] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [Discord] => C:\Users\vitda\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [146943096 2022-06-10] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [Adobe Reader Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe" (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\102.0.5005.63\Installer\chrmstp.exe [2022-05-29] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TSC_SI_13.lnk [2017-11-03]
ShortcutTarget: TSC_SI_13.lnk -> C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe (TechSmith Corporation -> TechSmith Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy\User: Restriction ? <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0027F47E-6741-4D14-B18E-9D20C5B37A7C} - System32\Tasks\klcp_update => C:\Program Files (x86)\Ostatni\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2022-05-12] () [File not signed]
Task: {05B5B170-AA01-4FA7-8139-9CC5BE65385D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {0BA0ADDA-3D98-4467-9818-8D9A6C05B9AB} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4214144 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {1281D64D-298F-4A23-8E76-428E1115A054} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8304592 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {15B3A5BA-B7B5-41E6-A68F-3EEE5220821E} - System32\Tasks\LED Sync => C:\Program Files (x86)\Ostatni\EVGA Precision XOC\LEDSync\LEDSync.exe /s (No File)
Task: {1790D9B8-D3A3-47BC-8FFB-D5EA03E1E573} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8304592 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {1B4D8300-2E10-48AC-BC22-B7D39C10B592} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23244744 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {1C5E85DE-24B4-4290-843F-4FA1872E8271} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3098928 2020-08-02] (Intel(R) Software Development Products -> Intel Corporation)
Task: {1C944813-4DE9-4176-8095-F7F279A311AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.)
Task: {20CCFA65-3459-45A8-938C-7FCF8339CAA7} - System32\Tasks\Speedfan\Speedfan => C:\Program Files (x86)\Ostatni\SpeedFan\speedfan.exe [8166536 2016-06-29] (SOKNO S.R.L. -> )
Task: {2B592120-E8C7-458E-9666-32B9156CC483} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {2CEB1744-AA96-467A-8417-7D80901C1F2F} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {364162D9-EE10-44A4-BB69-166CD2F5729B} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXvGPUDisableTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe [12288 2020-07-14] (Microsoft Corporation) [File not signed]
Task: {3655E6CB-A89E-4BBD-A66C-BBB4D944DB4C} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {3AB2697A-2C4D-434E-B796-C58D2CF245F8} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [67472 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {427E2CDC-2296-4F07-92A9-CB3DA2417096} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3098928 2020-08-02] (Intel(R) Software Development Products -> Intel Corporation)
Task: {46CF54F1-22F8-418B-863B-8633BE0B8C0E} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4214144 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {65782AE6-A2CB-4A51-99E3-A57B1AB07B03} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDImmunize.exe [5629064 2021-11-23] (Safer-Networking Limited -> Safer-Networking Ltd.)
Task: {712A7997-721E-4950-AC43-A093DAF54FEA} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [71232 2016-09-06] (TechSmith Corporation -> TechSmith Corporation)
Task: {749585AF-7C1F-442D-8FD8-9E92D1EE203F} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3427104 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {7788B837-8A8F-43BE-BEB2-BB283302352B} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {78C6D9DD-357B-4BAB-9654-D61CEBBA6336} - System32\Tasks\QNAPQsyncAutoLaunch => C:\Program Files (x86)\QNAP\Qsync\Qsync.exe [93184760 2022-03-23] (QNAP Systems, Inc. -> QNAP Systems, Inc.)
Task: {7A3EBA05-7F97-45A6-83EE-60ECFE874504} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\Ostatni\MSI Afterburner\MSIAfterburner.exe [804408 2021-12-03] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {88BD8066-8928-4B9E-A105-24E2BC0F8B2A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-11-03] (Google Inc -> Google Inc.)
Task: {8B5D307A-494A-44EC-B2BD-5A31A5307DBB} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {8DE88AD4-F38B-498A-9A85-5AD27B08A9F9} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4214144 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {9102587C-8819-44A0-B248-23C0D601CC41} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144792 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {A7D270C6-052D-42B5-B511-625DAA7BE699} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {ABBA29B5-A802-492E-A1BA-A79DD0465409} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342080 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {B4547647-DEF0-49C3-A1C2-06CE6D324F13} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-11-03] (Google Inc -> Google Inc.)
Task: {B4C2E4DD-2F5F-4E79-BA54-829FD7B4E350} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (No File)
Task: {D413A0C6-F490-4587-90C3-7B1CAFC67E57} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {D4A36851-28D9-452B-B69C-81B4926F690D} - System32\Tasks\Microsoft\Windows\Clip\LicenseImdsIntegration => C:\WINDOWS\system32\fclip.exe [480720 2022-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D8837779-68DF-4821-BB44-2A9C5F33B77E} - System32\Tasks\MSILEDKeeper_Host => C:\Program Files (x86)\Ostatni\MysticLight\LEDKeeper.exe [1071760 2019-09-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {DA47F067-F497-4F4B-B07A-789A3305956C} - System32\Tasks\S-1-5-21-2089558188-2690222546-326603744-1002\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe (No File)
Task: {DDF64CF8-CB71-484C-8E15-4CC364C0F7FE} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23244744 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {DE9E467B-0009-46DA-8F56-6748F23670BE} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {E586F5B9-21E6-4C42-ADF3-EC43B809BAE5} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXWarningTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe [12288 2020-07-14] (Microsoft Corporation) [File not signed]
Task: {EB07954E-190B-42D9-94E2-B23CE32CEDB8} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-01] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {EC72FD6A-2070-4A32-BA8B-0375FD425F3D} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
Task: {EE707CAB-19DA-42F4-A724-C93FBB3A696E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDUpdate.exe [5363552 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
Task: {F1670D46-BC54-48F9-808E-5381851E3299} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {F6FAF34F-AADF-4A76-B619-FC302391637D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144792 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {FF93E0F4-D9B9-4D4F-AD17-7CBAEAA2D6DE} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagician.exe [109697976 2021-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\MSILEDKeeper_Host.job => C:\Program Files (x86)\Ostatni\MysticLight\LEDKeeper.exe
Task: C:\WINDOWS\Tasks\MSISW_Host.job => C:\WINDOWS\SysWOW64\muachost.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 192.168.1.254
Tcpip\..\Interfaces\{2ad5fd0a-8626-4be6-b629-4758e329ddd7}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{9b67b8dc-37e9-483c-885e-c11011f37c88}: [DhcpNameServer] 8.8.8.8 192.168.1.254
Tcpip\..\Interfaces\{9fe4da26-d4e8-47da-ba1d-0489aabb6f7d}: [DhcpNameServer] 192.168.93.166
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\previ\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-12]
Edge HKU\S-1-5-21-2089558188-2690222546-326603744-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [njjljiblognghfjfpcdpdbpbfcmhgafg]
FireFox:
========
FF DefaultProfile: v4b410mp.default
FF ProfilePath: C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default [2022-04-24]
FF DownloadDir: D:\Download
FF Homepage: Mozilla\Firefox\Profiles\v4b410mp.default -> www.seznam.cz
FF Extension: (Tipli do prohlížeče) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\@tipli-do-prohlizece-.xpi [2021-07-23]
FF Extension: (VratnePenize.cz Připomínáček) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\toolbar@vratnepenize.cz.xpi [2021-04-06]
FF Extension: (Video DownloadHelper) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-07-23]
FF Extension: (No Name) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-01-30]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2022-06-12]
Chrome:
=======
CHR Profile: C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default [2021-02-07]
CHR DownloadDir: D:\Download
CHR HomePage: Default -> hxxps://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/"
CHR Extension: (Prezentace) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-04]
CHR Extension: (Dokumenty) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-04]
CHR Extension: (Disk Google) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-02-07]
CHR Extension: (YouTube) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-11-04]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-02-07]
CHR Extension: (Tabulky) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-04]
CHR Extension: (Black & white theme) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmohofkmppcgglcmlccpbokkkefigipi [2017-11-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-02-07]
CHR Extension: (Video DownloadHelper) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2019-05-05]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-05-05]
CHR Extension: (Fullscreen Anything) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\olcfgpmjldkkjdclidhcbonieibfhhdh [2017-11-04]
CHR Extension: (Gmail) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-05]
CHR Extension: (Chrome Media Router) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-05-05]
CHR HKU\S-1-5-21-2089558188-2690222546-326603744-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gjgfobnenmnljakmhboildkafdkicala]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3815712 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3580200 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Bonjour Service; C:\Program Files (x86)\Blizzard\Bonjour Service\mDNSResponder.exe [390504 2019-08-06] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11988424 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
S3 CLink4Service; C:\Program Files (x86)\Ostatni\Corsair Link 4\CorsairLink4.Service.exe [34512 2018-03-30] (Corsair Components, Inc. -> Corsair Components, Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-05-18] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 ekrn; C:\Program Files\Ostatni\ESET Security\ekrn.exe [3210720 2022-03-31] (ESET, spol. s r.o. -> ESET)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-08] (Epic Games Inc. -> Epic Games, Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.111.0522.0002\FileSyncHelper.exe [3373960 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
S3 GalaxyClientService; E:\Hry\GOG Galaxy\GalaxyClientService.exe [1959776 2022-01-03] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6484832 2021-11-10] (GOG Sp. z o.o. -> GOG.com)
S2 GameInput Service; C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe [75240 2022-05-25] (Microsoft Corporation -> Microsoft Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [11523704 2022-06-10] (Logitech Inc -> Logitech, Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [4065096 2017-10-12] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
S3 MagicianSVC; C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagicianSVC.exe [347576 2021-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 MysticLight2_Service; C:\Program Files (x86)\Ostatni\MysticLight\MysticLight2_Service.exe [34976 2018-12-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.111.0522.0002\OneDriveUpdaterService.exe [3812760 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
S3 Origin Client Service; E:\Hry\Origin\OriginClientService.exe [2575064 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; E:\Hry\Origin\OriginWebHelperService.exe [3494672 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
U2 SamsungMagicianSVC; C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagicianSVC.exe [347576 2021-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 SDScannerService; C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDFSSvc.exe [2782080 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDUpdSvc.exe [4605312 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDWSCSvc.exe [940976 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6207704 2022-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182128 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-06-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [935352 2020-06-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe [14585832 2022-05-11] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3661096 2015-09-14] (TechSmith Corporation -> TechSmith Corporation)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [7374576 2021-08-11] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 VBoxSDS; C:\Program Files\Ostatni\Oracle VirtualBox\VBoxSDS.exe [746728 2022-03-23] (Oracle Corporation -> Oracle Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [2599312 2021-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [128376 2021-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [7550152 2021-08-11] (PUBG CORPORATION -> PUBG Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_647b4244e991951b\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [98304 2021-06-05] (Microsoft Corporation) [File not signed]
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [75560 2020-12-25] (Broadcom Corporation -> Broadcom Corporation.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [183888 2022-03-31] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107944 2022-03-31] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15824 2021-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [226264 2022-03-31] (ESET, spol. s r.o. -> ESET)
R1 EneIo; C:\WINDOWS\system32\drivers\ene.sys [17624 2019-05-22] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [111624 2022-03-31] (ESET, spol. s r.o. -> ESET)
S3 Hsp; C:\WINDOWS\System32\drivers\Hsp.sys [111960 2022-05-11] (Microsoft Windows -> Microsoft Corporation)
R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [33528 2022-03-23] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [21704 2022-03-23] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [62904 2022-03-23] (WDKTestCert builder,132743893872553407 -> Logitech)
S3 NTIOLib_MysticLight; C:\Program Files (x86)\Ostatni\MysticLight\Lib\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48552 2021-11-01] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [189152 2017-08-08] (Paramount Software UK Ltd -> Windows (R) Win 7 DDK provider)
S3 RTCore64; C:\Program Files (x86)\Ostatni\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43376 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [240704 2022-03-22] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [250608 2022-03-22] (Oracle Corporation -> Oracle Corporation)
R1 VBoxSup; C:\WINDOWS\system32\DRIVERS\VBoxSup.sys [1046392 2022-03-22] (Oracle Corporation -> Oracle Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [49560 2021-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [421112 2021-06-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [73960 2021-06-05] (Microsoft Windows -> Microsoft Corporation)
R2 WinRing0_1_2_0; E:\Hry\Steam\steamapps\common\EVGA PrecisionX\WinRing0\WinRing0x64.sys [14536 2018-01-05] (EVGA -> OpenLibSys.org)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [2729456 2021-08-16] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-06-12 19:16 - 2022-06-12 19:18 - 000000000 ____D C:\FRST
2022-06-11 15:03 - 2022-06-11 15:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi
2022-06-11 15:03 - 2022-06-11 15:03 - 000000000 ____D C:\Program Files\LGHUB
2022-06-09 18:13 - 2022-06-09 18:13 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-06-07 20:59 - 2022-06-07 20:59 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2022-06-07 20:59 - 2022-06-07 20:59 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput
2022-05-28 23:23 - 2022-05-28 23:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2022-05-27 21:33 - 2022-05-27 21:33 - 000001425 _____ C:\WINDOWS\system32\default_error_stack-000102-000000.txt
2022-05-27 00:24 - 2022-05-27 00:24 - 000001435 _____ C:\WINDOWS\system32\default_error_stack-000101-000000.txt
2022-05-27 00:24 - 2019-06-21 07:34 - 000019904 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\Spybot3ELAM.sys
2022-05-27 00:20 - 2022-05-27 00:20 - 000557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2022-05-27 00:20 - 2022-05-27 00:20 - 000524288 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2022-05-27 00:20 - 2022-05-27 00:20 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2022-05-27 00:20 - 2022-05-27 00:20 - 000167936 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll
2022-05-27 00:20 - 2022-05-27 00:20 - 000057344 _____ C:\WINDOWS\system32\uwfservicingapi.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000614400 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000335872 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000299008 _____ C:\WINDOWS\system32\EsclScan.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000180224 _____ C:\WINDOWS\system32\EsclProtocol.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000015004 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-05-27 00:15 - 2022-05-27 00:15 - 000000000 ___HD C:\$WinREAgent
2022-05-25 18:04 - 2022-05-25 18:04 - 000001424 _____ C:\WINDOWS\system32\default_error_stack-000100-000000.txt
2022-05-25 18:02 - 2022-05-21 05:22 - 000724688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2022-05-25 18:02 - 2022-05-21 05:20 - 005730880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001905912 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001905912 _____ C:\WINDOWS\system32\vulkaninfo.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001478384 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001478384 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001467080 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001432304 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001432304 _____ C:\WINDOWS\system32\vulkan-1.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001209408 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001145584 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001145584 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2022-05-25 18:01 - 2022-05-21 05:23 - 000587336 _____ C:\WINDOWS\system32\nvofapi64.dll
2022-05-25 18:01 - 2022-05-21 05:23 - 000460496 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 002120896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 001603144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 001530456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 001177312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 000730320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 000712416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2022-05-25 18:01 - 2022-05-21 05:21 - 006964824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 006226640 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 005100752 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 002932952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 000582712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 000457944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2022-05-25 18:01 - 2022-05-21 05:19 - 000851136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2022-05-25 18:01 - 2022-05-21 05:18 - 006465200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2022-05-25 18:01 - 2022-05-20 02:51 - 000089337 _____ C:\WINDOWS\system32\nvinfo.pb
2022-05-18 11:49 - 2022-05-18 11:49 - 000000000 ____D C:\Users\vitda\AppData\Local\DeadByDaylight
2022-05-14 20:41 - 2022-05-14 20:41 - 000001434 _____ C:\WINDOWS\system32\default_error_stack-000099-000000.txt
2022-05-13 17:11 - 2022-05-13 17:11 - 000000028 ____H C:\.GamingRoot
2022-05-13 17:11 - 2022-05-13 17:11 - 000000000 ____D C:\XboxGames
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-06-12 19:08 - 2017-11-03 18:57 - 000000000 ____D C:\Program Files (x86)\Google
2022-06-12 19:00 - 2021-06-05 14:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-06-12 18:59 - 2022-02-08 20:38 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-06-12 18:58 - 2017-11-04 18:46 - 000000000 ____D C:\Users\vitda\AppData\LocalLow\Mozilla
2022-06-12 18:46 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-06-12 18:37 - 2021-01-07 20:59 - 000000000 ____D C:\ProgramData\NVIDIA
2022-06-12 18:37 - 2020-01-13 20:57 - 000000000 ____D C:\Users\vitda\AppData\Roaming\LGHUB
2022-06-12 18:37 - 2020-01-13 20:57 - 000000000 ____D C:\Users\vitda\AppData\Local\LGHUB
2022-06-12 18:37 - 2017-11-04 18:46 - 000000000 ___RD C:\Users\vitda\OneDrive
2022-06-12 15:22 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SystemTemp
2022-06-12 12:51 - 2022-01-31 20:01 - 000000000 ____D C:\Users\vitda\AppData\Roaming\.minecraft
2022-06-12 12:14 - 2018-05-12 01:16 - 000000000 ____D C:\Users\vitda\AppData\Local\D3DSCache
2022-06-12 12:03 - 2021-10-06 21:58 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-06-12 10:52 - 2017-11-04 18:44 - 000000000 ____D C:\Users\vitda\AppData\Local\Packages
2022-06-11 15:09 - 2021-06-05 14:10 - 000000000 ___HD C:\Program Files\WindowsApps
2022-06-11 15:09 - 2020-06-09 20:45 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-06-11 15:03 - 2021-10-10 08:53 - 000003546 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d7baeca9818c49
2022-06-11 15:03 - 2021-10-06 22:04 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-06-10 23:25 - 2022-01-11 00:30 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1001
2022-06-10 23:25 - 2021-12-11 13:37 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1002
2022-06-10 23:25 - 2021-10-06 22:04 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-06-10 23:25 - 2021-06-22 19:14 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-06-10 23:25 - 2019-09-15 19:11 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-06-09 21:38 - 2021-10-06 22:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-06-09 21:38 - 2017-11-03 18:53 - 000001015 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-06-07 23:32 - 2017-11-04 19:53 - 000000000 ____D C:\Users\vitda\AppData\Roaming\Origin
2022-06-07 23:32 - 2017-11-04 01:16 - 000000000 ____D C:\ProgramData\Origin
2022-06-07 23:26 - 2017-11-04 19:53 - 000000000 ____D C:\Users\vitda\AppData\Local\Origin
2022-06-07 23:25 - 2017-11-04 19:53 - 000000000 ____D C:\Users\vitda\AppData\Local\Battle.net
2022-06-07 20:59 - 2022-01-24 22:15 - 002762208 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000402920 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000230864 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000198112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000136672 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000062928 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe
2022-06-07 20:59 - 2021-06-05 14:09 - 000000000 ____D C:\WINDOWS\INF
2022-06-05 11:20 - 2018-02-18 03:21 - 000000000 ____D C:\Users\vitda\AppData\Roaming\discord
2022-06-05 11:19 - 2018-02-18 03:21 - 000000000 ____D C:\Users\vitda\AppData\Local\Discord
2022-06-04 18:52 - 2020-05-22 08:56 - 000000000 ____D C:\Users\vitda\AppData\Local\EpicGamesLauncher
2022-06-04 11:54 - 2017-12-29 01:56 - 000000000 ____D C:\Users\vitda\AppData\Local\id Software
2022-06-04 11:54 - 2017-11-03 18:37 - 000000000 ____D C:\ProgramData\Package Cache
2022-06-02 21:57 - 2019-04-23 23:05 - 000000000 ____D C:\Users\vitda\AppData\Local\Ubisoft Game Launcher
2022-05-31 20:37 - 2017-11-03 18:53 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-05-29 13:20 - 2018-04-10 22:37 - 000000000 ____D C:\Users\vitda\.VirtualBox
2022-05-29 13:12 - 2019-01-24 00:40 - 000000000 ____D C:\ProgramData\VirtualBox
2022-05-29 12:58 - 2018-07-25 23:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2022-05-29 10:25 - 2019-02-08 18:00 - 000000000 ____D C:\Program Files\Microsoft Office
2022-05-29 00:49 - 2017-11-03 18:57 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-05-28 23:50 - 2021-10-06 22:04 - 000003316 _____ C:\WINDOWS\system32\Tasks\klcp_update
2022-05-28 23:50 - 2021-02-07 15:32 - 000000000 ____D C:\Users\previ\AppData\Local\NVIDIA
2022-05-28 23:50 - 2017-11-04 00:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2022-05-28 23:29 - 2018-04-15 21:01 - 000000000 ____D C:\Users\previ\.VirtualBox
2022-05-28 20:21 - 2020-01-19 16:41 - 000000000 ____D C:\Users\vitda\AppData\Roaming\HandBrake
2022-05-28 20:13 - 2021-10-06 21:38 - 000000000 ____D C:\Program Files\MSBuild
2022-05-28 20:13 - 2021-10-06 21:38 - 000000000 ____D C:\Program Files (x86)\MSBuild
2022-05-28 17:39 - 2022-05-11 21:58 - 000724674 _____ C:\WINDOWS\system32\perfh005.dat
2022-05-28 17:39 - 2022-05-11 21:58 - 000150580 _____ C:\WINDOWS\system32\perfc005.dat
2022-05-28 17:39 - 2021-10-06 22:03 - 001714894 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-05-27 21:34 - 2021-10-06 22:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-05-27 21:34 - 2020-05-30 09:50 - 000012288 ___SH C:\DumpStack.log.tmp
2022-05-27 21:34 - 2018-06-10 17:52 - 000000000 ____D C:\Intel
2022-05-27 21:33 - 2021-06-05 14:01 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2022-05-27 21:33 - 2021-06-05 14:01 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-05-27 00:25 - 2020-05-30 09:52 - 000000256 ____H C:\WINDOWS\Tasks\MSILEDKeeper_Host.job
2022-05-27 00:24 - 2022-05-03 17:19 - 000479672 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-05-27 00:24 - 2021-06-05 19:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2022-05-27 00:24 - 2021-06-05 19:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-05-27 00:24 - 2021-06-05 19:31 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ___SD C:\WINDOWS\system32\F12
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SystemResources
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\id-ID
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\et-EE
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\appraiser
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\ShellExperiences
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\ShellComponents
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-05-27 00:24 - 2017-11-03 18:59 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2022-05-27 00:24 - 2017-11-03 18:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2022-05-27 00:19 - 2021-10-06 21:59 - 003101184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-05-25 18:05 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\ServiceState
2022-05-21 14:41 - 2021-02-04 21:47 - 000000000 ____D C:\Users\vitda\AppData\Roaming\Microsoft\Windows\Start Menu\SteamVR
2022-05-21 05:18 - 2021-10-13 21:16 - 007618584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2022-05-18 12:31 - 2021-10-06 22:04 - 000003522 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2022-05-18 11:49 - 2020-05-22 08:56 - 000000000 ____D C:\Users\vitda\AppData\Local\UnrealEngine
2022-05-18 11:48 - 2018-04-20 23:05 - 000000000 ____D C:\Users\vitda\AppData\Roaming\EasyAntiCheat
==================== Files in the root of some directories ========
2018-12-30 21:24 - 2018-12-30 21:25 - 000000022 _____ () C:\Users\vitda\mn1.bat
2019-03-26 01:34 - 2019-03-26 01:34 - 000000291 _____ () C:\Users\previ\AppData\Local\ledConfiguration.config
2021-04-20 19:57 - 2021-04-20 19:57 - 000000205 _____ () C:\Users\previ\AppData\Local\oobelibMkey.log
2017-11-04 19:12 - 2017-11-04 19:12 - 000000017 _____ () C:\Users\previ\AppData\Local\resmon.resmoncfg
2020-12-25 00:47 - 2020-12-25 00:47 - 000012288 _____ () C:\Users\previ\AppData\Local\vita_uranus.data
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-06-2022 01
Ran by previ (administrator) on PC-PREVIT (12-06-2022 19:17:44)
Running from D:\Download
Loaded Profiles: previ & vitda
Platform: Microsoft Windows 11 Enterprise Version 21H2 22000.708 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Ostatni\Snagit 13\SnagitEditor.exe
(C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Ostatni\Snagit 13\SnagPriv.exe
(C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer.exe
(C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\tv_w32.exe
(C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\tv_x64.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\LGHUB\lghub.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_agent.exe
(C:\Program Files\Ostatni\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\Ostatni\ESET Security\eguiProxy.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\Ostatni\VirtualCloneDrive\VCDDaemon.exe
(explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub.exe <3>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(explorer.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe
(Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <14>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Safer-Networking Limited -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDTray.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Blizzard\Bonjour Service\mDNSResponder.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) E:\Hry\Origin\OriginWebHelperService.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\Ostatni\ESET Security\ekrn.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_577b4722c749a41f\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(services.exe ->) (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\Ostatni\MysticLight\MysticLight2_Service.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Safer-Networking Limited -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDFSSvc.exe
(services.exe ->) (Safer-Networking Limited -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDUpdSvc.exe
(services.exe ->) (Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDWSCSvc.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagicianSVC.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(services.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.GamingServices_4.66.2001.0_x64__8wekyb3d8bbwe\gamingservices.exe
(services.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.GamingServices_4.66.2001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
(sihost.exe ->) (0) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3408.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(svchost.exe ->) (0) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3408.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Intel(R) Software Development Products -> Intel Corporation) C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (QNAP Systems, Inc. -> QNAP Systems, Inc.) C:\Program Files (x86)\QNAP\Qsync\Qsync.exe
(svchost.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) 0 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22042.168.0_x64__8wekyb3d8bbwe\YourPhone.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\Ostatni\ESET Security\ecmdS.exe [168064 2022-03-31] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [3465608 2017-10-01] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3427104 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDTray.exe [5204968 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\Ostatni\KeePass Password Safe 2\KeePass.exe [3074752 2020-05-07] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Ostatni\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [Qsync] => C:\Program Files (x86)\QNAP\Qsync\Qsync.exe [93184760 2022-03-23] (QNAP Systems, Inc. -> QNAP Systems, Inc.)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [CorsairLink4] => C:\Program Files (x86)\Ostatni\Corsair Link 4\CorsairLink4.exe [27146448 2018-03-30] (Corsair Components, Inc. -> Corsair Components, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [146943096 2022-06-10] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1001\...\Run: [EpicGamesLauncher] => E:\Hry\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32648144 2022-06-08] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2632064 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [Discord] => C:\Users\vitda\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [146943096 2022-06-10] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-2089558188-2690222546-326603744-1002\...\Run: [Adobe Reader Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe" (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\102.0.5005.63\Installer\chrmstp.exe [2022-05-29] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TSC_SI_13.lnk [2017-11-03]
ShortcutTarget: TSC_SI_13.lnk -> C:\Program Files (x86)\Ostatni\Snagit 13\Snagit32.exe (TechSmith Corporation -> TechSmith Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy\User: Restriction ? <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0027F47E-6741-4D14-B18E-9D20C5B37A7C} - System32\Tasks\klcp_update => C:\Program Files (x86)\Ostatni\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2022-05-12] () [File not signed]
Task: {05B5B170-AA01-4FA7-8139-9CC5BE65385D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {0BA0ADDA-3D98-4467-9818-8D9A6C05B9AB} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4214144 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {1281D64D-298F-4A23-8E76-428E1115A054} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8304592 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {15B3A5BA-B7B5-41E6-A68F-3EEE5220821E} - System32\Tasks\LED Sync => C:\Program Files (x86)\Ostatni\EVGA Precision XOC\LEDSync\LEDSync.exe /s (No File)
Task: {1790D9B8-D3A3-47BC-8FFB-D5EA03E1E573} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8304592 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {1B4D8300-2E10-48AC-BC22-B7D39C10B592} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23244744 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {1C5E85DE-24B4-4290-843F-4FA1872E8271} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3098928 2020-08-02] (Intel(R) Software Development Products -> Intel Corporation)
Task: {1C944813-4DE9-4176-8095-F7F279A311AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.)
Task: {20CCFA65-3459-45A8-938C-7FCF8339CAA7} - System32\Tasks\Speedfan\Speedfan => C:\Program Files (x86)\Ostatni\SpeedFan\speedfan.exe [8166536 2016-06-29] (SOKNO S.R.L. -> )
Task: {2B592120-E8C7-458E-9666-32B9156CC483} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {2CEB1744-AA96-467A-8417-7D80901C1F2F} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {364162D9-EE10-44A4-BB69-166CD2F5729B} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXvGPUDisableTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe [12288 2020-07-14] (Microsoft Corporation) [File not signed]
Task: {3655E6CB-A89E-4BBD-A66C-BBB4D944DB4C} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {3AB2697A-2C4D-434E-B796-C58D2CF245F8} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [67472 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {427E2CDC-2296-4F07-92A9-CB3DA2417096} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3098928 2020-08-02] (Intel(R) Software Development Products -> Intel Corporation)
Task: {46CF54F1-22F8-418B-863B-8633BE0B8C0E} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4214144 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {65782AE6-A2CB-4A51-99E3-A57B1AB07B03} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDImmunize.exe [5629064 2021-11-23] (Safer-Networking Limited -> Safer-Networking Ltd.)
Task: {712A7997-721E-4950-AC43-A093DAF54FEA} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [71232 2016-09-06] (TechSmith Corporation -> TechSmith Corporation)
Task: {749585AF-7C1F-442D-8FD8-9E92D1EE203F} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3427104 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {7788B837-8A8F-43BE-BEB2-BB283302352B} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {78C6D9DD-357B-4BAB-9654-D61CEBBA6336} - System32\Tasks\QNAPQsyncAutoLaunch => C:\Program Files (x86)\QNAP\Qsync\Qsync.exe [93184760 2022-03-23] (QNAP Systems, Inc. -> QNAP Systems, Inc.)
Task: {7A3EBA05-7F97-45A6-83EE-60ECFE874504} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\Ostatni\MSI Afterburner\MSIAfterburner.exe [804408 2021-12-03] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {88BD8066-8928-4B9E-A105-24E2BC0F8B2A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-11-03] (Google Inc -> Google Inc.)
Task: {8B5D307A-494A-44EC-B2BD-5A31A5307DBB} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {8DE88AD4-F38B-498A-9A85-5AD27B08A9F9} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4214144 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {9102587C-8819-44A0-B248-23C0D601CC41} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144792 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {A7D270C6-052D-42B5-B511-625DAA7BE699} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {ABBA29B5-A802-492E-A1BA-A79DD0465409} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342080 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {B4547647-DEF0-49C3-A1C2-06CE6D324F13} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-11-03] (Google Inc -> Google Inc.)
Task: {B4C2E4DD-2F5F-4E79-BA54-829FD7B4E350} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (No File)
Task: {D413A0C6-F490-4587-90C3-7B1CAFC67E57} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {D4A36851-28D9-452B-B69C-81B4926F690D} - System32\Tasks\Microsoft\Windows\Clip\LicenseImdsIntegration => C:\WINDOWS\system32\fclip.exe [480720 2022-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D8837779-68DF-4821-BB44-2A9C5F33B77E} - System32\Tasks\MSILEDKeeper_Host => C:\Program Files (x86)\Ostatni\MysticLight\LEDKeeper.exe [1071760 2019-09-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {DA47F067-F497-4F4B-B07A-789A3305956C} - System32\Tasks\S-1-5-21-2089558188-2690222546-326603744-1002\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe (No File)
Task: {DDF64CF8-CB71-484C-8E15-4CC364C0F7FE} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23244744 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {DE9E467B-0009-46DA-8F56-6748F23670BE} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {E586F5B9-21E6-4C42-ADF3-EC43B809BAE5} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXWarningTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe [12288 2020-07-14] (Microsoft Corporation) [File not signed]
Task: {EB07954E-190B-42D9-94E2-B23CE32CEDB8} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-01] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {EC72FD6A-2070-4A32-BA8B-0375FD425F3D} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
Task: {EE707CAB-19DA-42F4-A724-C93FBB3A696E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDUpdate.exe [5363552 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
Task: {F1670D46-BC54-48F9-808E-5381851E3299} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {F6FAF34F-AADF-4A76-B619-FC302391637D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144792 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {FF93E0F4-D9B9-4D4F-AD17-7CBAEAA2D6DE} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagician.exe [109697976 2021-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\MSILEDKeeper_Host.job => C:\Program Files (x86)\Ostatni\MysticLight\LEDKeeper.exe
Task: C:\WINDOWS\Tasks\MSISW_Host.job => C:\WINDOWS\SysWOW64\muachost.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 192.168.1.254
Tcpip\..\Interfaces\{2ad5fd0a-8626-4be6-b629-4758e329ddd7}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{9b67b8dc-37e9-483c-885e-c11011f37c88}: [DhcpNameServer] 8.8.8.8 192.168.1.254
Tcpip\..\Interfaces\{9fe4da26-d4e8-47da-ba1d-0489aabb6f7d}: [DhcpNameServer] 192.168.93.166
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\previ\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-12]
Edge HKU\S-1-5-21-2089558188-2690222546-326603744-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [njjljiblognghfjfpcdpdbpbfcmhgafg]
FireFox:
========
FF DefaultProfile: v4b410mp.default
FF ProfilePath: C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default [2022-04-24]
FF DownloadDir: D:\Download
FF Homepage: Mozilla\Firefox\Profiles\v4b410mp.default -> www.seznam.cz
FF Extension: (Tipli do prohlížeče) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\@tipli-do-prohlizece-.xpi [2021-07-23]
FF Extension: (VratnePenize.cz Připomínáček) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\toolbar@vratnepenize.cz.xpi [2021-04-06]
FF Extension: (Video DownloadHelper) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-07-23]
FF Extension: (No Name) - C:\Users\previ\AppData\Roaming\Mozilla\Firefox\Profiles\v4b410mp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-01-30]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2022-06-12]
Chrome:
=======
CHR Profile: C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default [2021-02-07]
CHR DownloadDir: D:\Download
CHR HomePage: Default -> hxxps://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/"
CHR Extension: (Prezentace) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-04]
CHR Extension: (Dokumenty) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-04]
CHR Extension: (Disk Google) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-02-07]
CHR Extension: (YouTube) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-11-04]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-02-07]
CHR Extension: (Tabulky) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-04]
CHR Extension: (Black & white theme) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmohofkmppcgglcmlccpbokkkefigipi [2017-11-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-02-07]
CHR Extension: (Video DownloadHelper) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2019-05-05]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-05-05]
CHR Extension: (Fullscreen Anything) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\olcfgpmjldkkjdclidhcbonieibfhhdh [2017-11-04]
CHR Extension: (Gmail) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-05]
CHR Extension: (Chrome Media Router) - C:\Users\previ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-05-05]
CHR HKU\S-1-5-21-2089558188-2690222546-326603744-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gjgfobnenmnljakmhboildkafdkicala]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3815712 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3580200 2022-04-13] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Bonjour Service; C:\Program Files (x86)\Blizzard\Bonjour Service\mDNSResponder.exe [390504 2019-08-06] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11988424 2022-05-29] (Microsoft Corporation -> Microsoft Corporation)
S3 CLink4Service; C:\Program Files (x86)\Ostatni\Corsair Link 4\CorsairLink4.Service.exe [34512 2018-03-30] (Corsair Components, Inc. -> Corsair Components, Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-05-18] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 ekrn; C:\Program Files\Ostatni\ESET Security\ekrn.exe [3210720 2022-03-31] (ESET, spol. s r.o. -> ESET)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-08] (Epic Games Inc. -> Epic Games, Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.111.0522.0002\FileSyncHelper.exe [3373960 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
S3 GalaxyClientService; E:\Hry\GOG Galaxy\GalaxyClientService.exe [1959776 2022-01-03] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6484832 2021-11-10] (GOG Sp. z o.o. -> GOG.com)
S2 GameInput Service; C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe [75240 2022-05-25] (Microsoft Corporation -> Microsoft Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [11523704 2022-06-10] (Logitech Inc -> Logitech, Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [4065096 2017-10-12] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
S3 MagicianSVC; C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagicianSVC.exe [347576 2021-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 MysticLight2_Service; C:\Program Files (x86)\Ostatni\MysticLight\MysticLight2_Service.exe [34976 2018-12-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.111.0522.0002\OneDriveUpdaterService.exe [3812760 2022-06-10] (Microsoft Corporation -> Microsoft Corporation)
S3 Origin Client Service; E:\Hry\Origin\OriginClientService.exe [2575064 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; E:\Hry\Origin\OriginWebHelperService.exe [3494672 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
U2 SamsungMagicianSVC; C:\Program Files (x86)\Ostatni\Samsung Magician\SamsungMagicianSVC.exe [347576 2021-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 SDScannerService; C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDFSSvc.exe [2782080 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDUpdSvc.exe [4605312 2021-11-16] (Safer-Networking Limited -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Ostatni\Spybot - Search & Destroy 2\SDWSCSvc.exe [940976 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6207704 2022-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182128 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-06-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [935352 2020-06-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\Ostatni\TeamViewer\TeamViewer_Service.exe [14585832 2022-05-11] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3661096 2015-09-14] (TechSmith Corporation -> TechSmith Corporation)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [7374576 2021-08-11] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 VBoxSDS; C:\Program Files\Ostatni\Oracle VirtualBox\VBoxSDS.exe [746728 2022-03-23] (Oracle Corporation -> Oracle Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [2599312 2021-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [128376 2021-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [7550152 2021-08-11] (PUBG CORPORATION -> PUBG Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_647b4244e991951b\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [98304 2021-06-05] (Microsoft Corporation) [File not signed]
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [75560 2020-12-25] (Broadcom Corporation -> Broadcom Corporation.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [183888 2022-03-31] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107944 2022-03-31] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15824 2021-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [226264 2022-03-31] (ESET, spol. s r.o. -> ESET)
R1 EneIo; C:\WINDOWS\system32\drivers\ene.sys [17624 2019-05-22] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [111624 2022-03-31] (ESET, spol. s r.o. -> ESET)
S3 Hsp; C:\WINDOWS\System32\drivers\Hsp.sys [111960 2022-05-11] (Microsoft Windows -> Microsoft Corporation)
R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [33528 2022-03-23] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [21704 2022-03-23] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [62904 2022-03-23] (WDKTestCert builder,132743893872553407 -> Logitech)
S3 NTIOLib_MysticLight; C:\Program Files (x86)\Ostatni\MysticLight\Lib\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48552 2021-11-01] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [189152 2017-08-08] (Paramount Software UK Ltd -> Windows (R) Win 7 DDK provider)
S3 RTCore64; C:\Program Files (x86)\Ostatni\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43376 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [240704 2022-03-22] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [250608 2022-03-22] (Oracle Corporation -> Oracle Corporation)
R1 VBoxSup; C:\WINDOWS\system32\DRIVERS\VBoxSup.sys [1046392 2022-03-22] (Oracle Corporation -> Oracle Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [49560 2021-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [421112 2021-06-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [73960 2021-06-05] (Microsoft Windows -> Microsoft Corporation)
R2 WinRing0_1_2_0; E:\Hry\Steam\steamapps\common\EVGA PrecisionX\WinRing0\WinRing0x64.sys [14536 2018-01-05] (EVGA -> OpenLibSys.org)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [2729456 2021-08-16] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-06-12 19:16 - 2022-06-12 19:18 - 000000000 ____D C:\FRST
2022-06-11 15:03 - 2022-06-11 15:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi
2022-06-11 15:03 - 2022-06-11 15:03 - 000000000 ____D C:\Program Files\LGHUB
2022-06-09 18:13 - 2022-06-09 18:13 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-06-07 20:59 - 2022-06-07 20:59 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2022-06-07 20:59 - 2022-06-07 20:59 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput
2022-05-28 23:23 - 2022-05-28 23:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2022-05-27 21:33 - 2022-05-27 21:33 - 000001425 _____ C:\WINDOWS\system32\default_error_stack-000102-000000.txt
2022-05-27 00:24 - 2022-05-27 00:24 - 000001435 _____ C:\WINDOWS\system32\default_error_stack-000101-000000.txt
2022-05-27 00:24 - 2019-06-21 07:34 - 000019904 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\Spybot3ELAM.sys
2022-05-27 00:20 - 2022-05-27 00:20 - 000557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2022-05-27 00:20 - 2022-05-27 00:20 - 000524288 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2022-05-27 00:20 - 2022-05-27 00:20 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2022-05-27 00:20 - 2022-05-27 00:20 - 000167936 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll
2022-05-27 00:20 - 2022-05-27 00:20 - 000057344 _____ C:\WINDOWS\system32\uwfservicingapi.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000614400 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000335872 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000299008 _____ C:\WINDOWS\system32\EsclScan.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000180224 _____ C:\WINDOWS\system32\EsclProtocol.dll
2022-05-27 00:19 - 2022-05-27 00:19 - 000015004 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-05-27 00:15 - 2022-05-27 00:15 - 000000000 ___HD C:\$WinREAgent
2022-05-25 18:04 - 2022-05-25 18:04 - 000001424 _____ C:\WINDOWS\system32\default_error_stack-000100-000000.txt
2022-05-25 18:02 - 2022-05-21 05:22 - 000724688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2022-05-25 18:02 - 2022-05-21 05:20 - 005730880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001905912 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001905912 _____ C:\WINDOWS\system32\vulkaninfo.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001478384 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001478384 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2022-05-25 18:01 - 2022-05-21 05:26 - 001467080 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001432304 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001432304 _____ C:\WINDOWS\system32\vulkan-1.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001209408 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001145584 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2022-05-25 18:01 - 2022-05-21 05:26 - 001145584 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2022-05-25 18:01 - 2022-05-21 05:23 - 000587336 _____ C:\WINDOWS\system32\nvofapi64.dll
2022-05-25 18:01 - 2022-05-21 05:23 - 000460496 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 002120896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 001603144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 001530456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 001177312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 000730320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2022-05-25 18:01 - 2022-05-21 05:22 - 000712416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2022-05-25 18:01 - 2022-05-21 05:21 - 006964824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 006226640 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 005100752 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 002932952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 000582712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2022-05-25 18:01 - 2022-05-21 05:21 - 000457944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2022-05-25 18:01 - 2022-05-21 05:19 - 000851136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2022-05-25 18:01 - 2022-05-21 05:18 - 006465200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2022-05-25 18:01 - 2022-05-20 02:51 - 000089337 _____ C:\WINDOWS\system32\nvinfo.pb
2022-05-18 11:49 - 2022-05-18 11:49 - 000000000 ____D C:\Users\vitda\AppData\Local\DeadByDaylight
2022-05-14 20:41 - 2022-05-14 20:41 - 000001434 _____ C:\WINDOWS\system32\default_error_stack-000099-000000.txt
2022-05-13 17:11 - 2022-05-13 17:11 - 000000028 ____H C:\.GamingRoot
2022-05-13 17:11 - 2022-05-13 17:11 - 000000000 ____D C:\XboxGames
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-06-12 19:08 - 2017-11-03 18:57 - 000000000 ____D C:\Program Files (x86)\Google
2022-06-12 19:00 - 2021-06-05 14:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-06-12 18:59 - 2022-02-08 20:38 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-06-12 18:58 - 2017-11-04 18:46 - 000000000 ____D C:\Users\vitda\AppData\LocalLow\Mozilla
2022-06-12 18:46 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-06-12 18:37 - 2021-01-07 20:59 - 000000000 ____D C:\ProgramData\NVIDIA
2022-06-12 18:37 - 2020-01-13 20:57 - 000000000 ____D C:\Users\vitda\AppData\Roaming\LGHUB
2022-06-12 18:37 - 2020-01-13 20:57 - 000000000 ____D C:\Users\vitda\AppData\Local\LGHUB
2022-06-12 18:37 - 2017-11-04 18:46 - 000000000 ___RD C:\Users\vitda\OneDrive
2022-06-12 15:22 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SystemTemp
2022-06-12 12:51 - 2022-01-31 20:01 - 000000000 ____D C:\Users\vitda\AppData\Roaming\.minecraft
2022-06-12 12:14 - 2018-05-12 01:16 - 000000000 ____D C:\Users\vitda\AppData\Local\D3DSCache
2022-06-12 12:03 - 2021-10-06 21:58 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-06-12 10:52 - 2017-11-04 18:44 - 000000000 ____D C:\Users\vitda\AppData\Local\Packages
2022-06-11 15:09 - 2021-06-05 14:10 - 000000000 ___HD C:\Program Files\WindowsApps
2022-06-11 15:09 - 2020-06-09 20:45 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-06-11 15:03 - 2021-10-10 08:53 - 000003546 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d7baeca9818c49
2022-06-11 15:03 - 2021-10-06 22:04 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-06-10 23:25 - 2022-01-11 00:30 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1001
2022-06-10 23:25 - 2021-12-11 13:37 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2089558188-2690222546-326603744-1002
2022-06-10 23:25 - 2021-10-06 22:04 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-06-10 23:25 - 2021-06-22 19:14 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-06-10 23:25 - 2019-09-15 19:11 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-06-09 21:38 - 2021-10-06 22:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-06-09 21:38 - 2017-11-03 18:53 - 000001015 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-06-07 23:32 - 2017-11-04 19:53 - 000000000 ____D C:\Users\vitda\AppData\Roaming\Origin
2022-06-07 23:32 - 2017-11-04 01:16 - 000000000 ____D C:\ProgramData\Origin
2022-06-07 23:26 - 2017-11-04 19:53 - 000000000 ____D C:\Users\vitda\AppData\Local\Origin
2022-06-07 23:25 - 2017-11-04 19:53 - 000000000 ____D C:\Users\vitda\AppData\Local\Battle.net
2022-06-07 20:59 - 2022-01-24 22:15 - 002762208 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000402920 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000230864 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000198112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000136672 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2022-06-07 20:59 - 2022-01-24 22:15 - 000062928 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe
2022-06-07 20:59 - 2021-06-05 14:09 - 000000000 ____D C:\WINDOWS\INF
2022-06-05 11:20 - 2018-02-18 03:21 - 000000000 ____D C:\Users\vitda\AppData\Roaming\discord
2022-06-05 11:19 - 2018-02-18 03:21 - 000000000 ____D C:\Users\vitda\AppData\Local\Discord
2022-06-04 18:52 - 2020-05-22 08:56 - 000000000 ____D C:\Users\vitda\AppData\Local\EpicGamesLauncher
2022-06-04 11:54 - 2017-12-29 01:56 - 000000000 ____D C:\Users\vitda\AppData\Local\id Software
2022-06-04 11:54 - 2017-11-03 18:37 - 000000000 ____D C:\ProgramData\Package Cache
2022-06-02 21:57 - 2019-04-23 23:05 - 000000000 ____D C:\Users\vitda\AppData\Local\Ubisoft Game Launcher
2022-05-31 20:37 - 2017-11-03 18:53 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-05-29 13:20 - 2018-04-10 22:37 - 000000000 ____D C:\Users\vitda\.VirtualBox
2022-05-29 13:12 - 2019-01-24 00:40 - 000000000 ____D C:\ProgramData\VirtualBox
2022-05-29 12:58 - 2018-07-25 23:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2022-05-29 10:25 - 2019-02-08 18:00 - 000000000 ____D C:\Program Files\Microsoft Office
2022-05-29 00:49 - 2017-11-03 18:57 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-05-28 23:50 - 2021-10-06 22:04 - 000003316 _____ C:\WINDOWS\system32\Tasks\klcp_update
2022-05-28 23:50 - 2021-02-07 15:32 - 000000000 ____D C:\Users\previ\AppData\Local\NVIDIA
2022-05-28 23:50 - 2017-11-04 00:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2022-05-28 23:29 - 2018-04-15 21:01 - 000000000 ____D C:\Users\previ\.VirtualBox
2022-05-28 20:21 - 2020-01-19 16:41 - 000000000 ____D C:\Users\vitda\AppData\Roaming\HandBrake
2022-05-28 20:13 - 2021-10-06 21:38 - 000000000 ____D C:\Program Files\MSBuild
2022-05-28 20:13 - 2021-10-06 21:38 - 000000000 ____D C:\Program Files (x86)\MSBuild
2022-05-28 17:39 - 2022-05-11 21:58 - 000724674 _____ C:\WINDOWS\system32\perfh005.dat
2022-05-28 17:39 - 2022-05-11 21:58 - 000150580 _____ C:\WINDOWS\system32\perfc005.dat
2022-05-28 17:39 - 2021-10-06 22:03 - 001714894 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-05-27 21:34 - 2021-10-06 22:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-05-27 21:34 - 2020-05-30 09:50 - 000012288 ___SH C:\DumpStack.log.tmp
2022-05-27 21:34 - 2018-06-10 17:52 - 000000000 ____D C:\Intel
2022-05-27 21:33 - 2021-06-05 14:01 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2022-05-27 21:33 - 2021-06-05 14:01 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-05-27 00:25 - 2020-05-30 09:52 - 000000256 ____H C:\WINDOWS\Tasks\MSILEDKeeper_Host.job
2022-05-27 00:24 - 2022-05-03 17:19 - 000479672 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-05-27 00:24 - 2021-06-05 19:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2022-05-27 00:24 - 2021-06-05 19:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-05-27 00:24 - 2021-06-05 19:31 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ___SD C:\WINDOWS\system32\F12
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SystemResources
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\id-ID
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\et-EE
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\appraiser
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\ShellExperiences
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\ShellComponents
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-05-27 00:24 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-05-27 00:24 - 2017-11-03 18:59 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2022-05-27 00:24 - 2017-11-03 18:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2022-05-27 00:19 - 2021-10-06 21:59 - 003101184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-05-25 18:05 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\ServiceState
2022-05-21 14:41 - 2021-02-04 21:47 - 000000000 ____D C:\Users\vitda\AppData\Roaming\Microsoft\Windows\Start Menu\SteamVR
2022-05-21 05:18 - 2021-10-13 21:16 - 007618584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2022-05-18 12:31 - 2021-10-06 22:04 - 000003522 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2022-05-18 11:49 - 2020-05-22 08:56 - 000000000 ____D C:\Users\vitda\AppData\Local\UnrealEngine
2022-05-18 11:48 - 2018-04-20 23:05 - 000000000 ____D C:\Users\vitda\AppData\Roaming\EasyAntiCheat
==================== Files in the root of some directories ========
2018-12-30 21:24 - 2018-12-30 21:25 - 000000022 _____ () C:\Users\vitda\mn1.bat
2019-03-26 01:34 - 2019-03-26 01:34 - 000000291 _____ () C:\Users\previ\AppData\Local\ledConfiguration.config
2021-04-20 19:57 - 2021-04-20 19:57 - 000000205 _____ () C:\Users\previ\AppData\Local\oobelibMkey.log
2017-11-04 19:12 - 2017-11-04 19:12 - 000000017 _____ () C:\Users\previ\AppData\Local\resmon.resmoncfg
2020-12-25 00:47 - 2020-12-25 00:47 - 000012288 _____ () C:\Users\previ\AppData\Local\vita_uranus.data
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================