DRIVER_IRQL_NOT_LESS_OR_EQUAL
Napsal: 24 dub 2023 20:42
Po hromadné aktualizaci ovladačů přes Dell Support Assist padá systém při hraní her. Objevuje se modrá obrazovka s hláškou DRIVER_IRQL_NOT_LESS_OR_EQUAL (aswStm.sys), ale i jiné, které jsem nestihl zaznamenat. Na jaký ovladač se mám prosím zaměřit?
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-04-2023
Ran by Michal (administrator) on DESKTOP-RV3QMI2 (Dell Inc. Precision 7520) (24-04-2023 21:34:11)
Running from D:\Stažené soubory\FRST64.exe
Loaded Profiles: Michal
Platform: Microsoft Windows 10 Pro Version 22H2 19045.2846 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApntEx.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <5>
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.UserSessionAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\DCF\Dell.DCF.UA.Bradbury.API.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\DataManagerSubAgent\Dell.TechHub.DataManager.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApMsgFwd.exe
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\hidfind.exe
(DellTPad\Apoint.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\ApRemote.exe
(DellTPad\HidMonitorSvc.exe ->) (ALPS ALPINE CO.,LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\Apoint.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_e6d6f5a306002a89\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_e6d6f5a306002a89\igfxEM.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <41>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) ("STMicroelectronics Srl" -> ) C:\Windows\System32\drivers\DellFFDPWmiService.exe
(services.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\HidMonitorSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(services.exe ->) (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(services.exe ->) (Dell Inc -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(services.exe ->) (Dell Inc -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(services.exe ->) (Dell Inc -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(services.exe ->) (Dell Inc -> Dell) C:\Program Files\Dell\TechHub\Dell.TechHub.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_e6d6f5a306002a89\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_141eb88527011137\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d0b39b11619fd0c4\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d0b39b11619fd0c4\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\TPMProvisioningService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_7ed3bacbb0a8cc67\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\gamingservices.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ) C:\Windows\System32\UshUpgradeService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation) C:\Windows\System32\HostControlService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation) C:\Windows\System32\HostStorageService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\NVWMI\nvWmi64.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22062.534.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [220056 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11235920 2020-04-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-04-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1235160 2019-09-26] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1
HKLM\...\Policies\Explorer: [NoPublishingWizard] 1
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [40412472 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4362600 2023-03-24] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\112.0.5615.138\Installer\chrmstp.exe [2023-04-21] (Google LLC -> Google LLC)
Startup: C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon – zástupce.lnk [2022-07-28]
ShortcutTarget: ctfmon – zástupce.lnk -> C:\Windows\System32\ctfmon.exe (Microsoft Windows -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01F4EF06-D1B3-4304-951B-CF0DC8658CEF} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [745664 2016-01-12] (@ByELDI -> @ByELDI) [File not signed]
Task: {101744F1-3979-4B53-9280-2782403AF069} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [56816 2022-12-17] (HP Inc. -> HP Inc.)
Task: {1D88DA52-4CFB-4201-A028-A9082D5C1762} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4885912 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
Task: {2705B1E1-5411-4231-8999-2568C964FD6D} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\CCleanerCrashReporting" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\CCleanerSkipUAC - Michal" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\Dell SupportAssistAgent AutoUpdate" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore{559493EA-2EBE-4D42-8F6A-83A4C9D3BF0D}" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA{6BBA2034-FC4A-4486-9EB5-10C6EF9E7C46}" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {2B0D3F56-980D-4C39-A3C9-8A5368625132} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {32175321-8173-41D8-8B64-13A7E40F82E6} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2135448 2023-04-13] (Avast Software s.r.o. -> Avast Software)
Task: {385C5498-9A77-44B8-A717-CDD48D3A8852} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [168880 2023-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {3F19171A-EC1F-499B-94BD-626073B61EA3} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {46D79621-A058-47CF-899E-F9F77494B5D8} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {672412A2-6C3E-45C3-ADAE-1D59603D5D63} - System32\Tasks\Intel\Intel® Management and Security Status => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [219848 2022-08-21] (Intel Corporation -> Intel Corporation) -> "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" 60
Task: {71745EAD-62A4-4350-BDBF-0CD4111ED916} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703544 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "0ddc36cd-4798-4351-8296-eeba40e894fb" --version "6.11.10435" --silent
Task: {7F3BB80C-91BB-49C9-8E44-90B92810AF2D} - System32\Tasks\Optimize Thumbnail Cache => C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\isupdate.exe [61104 2020-09-26] (Flexera Software LLC -> InstallShield®) [File not signed] <==== ATTENTION
Task: {8AA701E3-DD7E-4BDA-9CB9-BD1CE48A8DDC} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144272 2023-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {97759FC0-7AEC-4788-8EB9-D544E1A72D52} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2302168 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {A1C52FA1-3FA1-4A94-8BFE-DE8787B58929} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26409896 2023-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {C9EF5D5A-5C60-4A57-8FC1-C8A8BEB82A50} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {CF51562C-0DC6-49EE-8C7C-1468DC27C63A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144272 2023-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {D072CAF3-3C1C-4345-AD9E-F9C08411D88F} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [665952 2023-01-31] (Dell Inc -> Dell Inc.)
Task: {D1324AD8-D84C-4671-9127-1703FA8D92EA} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [56816 2022-12-17] (HP Inc. -> HP Inc.)
Task: {D60A66E4-BE73-4231-A7F9-5B83B7590AB0} - System32\Tasks\CCleanerSkipUAC - Michal => C:\Program Files\CCleaner\CCleaner.exe [34159416 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {DC18CAC0-10E3-4077-8879-10B758A51D3D} - System32\Tasks\GoogleUpdateTaskMachineCore{559493EA-2EBE-4D42-8F6A-83A4C9D3BF0D} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2022-07-28] (Google Inc -> Google LLC)
Task: {E3B1ECB5-1188-48FE-91A7-C6D72D3AAED4} - System32\Tasks\KMSpico Automatic Update Scheduler => C:\Program Files\KMSpico\KMSUPD.exe [89272 2021-02-11] (KMSpico ByELDI LTD -> @ByELDI)
Task: {E8337FE9-AA51-4036-ACA0-6693F5DE75CC} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26409896 2023-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {FCC8F6CC-E2E9-478A-97C4-604ABBB002A5} - System32\Tasks\GoogleUpdateTaskMachineUA{6BBA2034-FC4A-4486-9EB5-10C6EF9E7C46} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2022-07-28] (Google Inc -> Google LLC)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
AutoConfigURL: [HKLM] => hxxp://127.0.0.1:86/ <==== ATTENTION
AutoConfigURL: [HKLM-x32] => hxxp://127.0.0.1:86/ <==== ATTENTION
AutoConfigURL: [{8EB8ACF2-18A8-4758-85C1-12B180D94138}] => hxxp://127.0.0.1:86/ <==== ATTENTION
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2f698019-3819-4aca-a144-560a4eac2d09}: [DhcpNameServer] 192.168.0.1
ManualProxies: 0hxxp://127.0.0.1:86/ <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
Edge:
=======
Edge Profile: C:\Users\Michal\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-24]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default [2023-04-24]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Dokumenty Google offline) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-20]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-04-24]
CHR Extension: (DownThemAll!) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nljkibfhlpcnanjgbnlnbjecgicbjkge [2023-02-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-07-28]
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\System Profile [2023-04-08]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ApHidMonitorService; C:\Windows\system32\DellTPad\HidMonitorSvc.exe [894848 2021-05-25] (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8808344 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [583064 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [584088 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2022-07-28] (Avast Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8894752 2021-11-18] (BattlEye Innovations e.K. -> )
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1063736 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12634544 2023-04-08] (Microsoft Corporation -> Microsoft Corporation)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [458960 2022-11-08] (Dell Inc -> Dell Technologies Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [161488 2022-11-08] (Dell Inc -> Dell Technologies Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [484560 2022-11-08] (Dell Inc -> Dell Technologies Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [47320 2022-11-18] (Dell Inc -> )
R2 DellFFDPWmiService; C:\Windows\System32\drivers\DellFFDPWmiService.exe [41136 2020-08-28] ("STMicroelectronics Srl" -> )
R2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [156064 2022-08-16] (Dell Inc -> Dell)
R2 FoxitReaderUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2358800 2022-05-19] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
R2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\GamingServices.exe [75256 2023-04-24] (Microsoft Corporation -> )
R2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [75256 2023-04-24] (Microsoft Corporation -> )
R2 hostcontrolsvc; C:\Windows\System32\HostControlService.exe [824424 2019-12-17] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation)
R2 hoststoragesvc; C:\Windows\System32\HostStorageService.exe [170088 2019-12-17] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [229360 2022-12-17] (HP Inc. -> HP Inc.)
R2 MbnExt; C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\MbnExt.dll [422608 2017-04-13] (Gemfor s.r.o. -> Gemfor s.r.o.)
R2 NVWMI; C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\NVWMI\nvWmi64.exe [4487208 2022-12-30] (Nvidia Corporation -> NVIDIA Corporation)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1846768 2023-04-07] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [285088 2023-03-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [160096 2023-01-31] (Dell Inc -> Dell Inc.)
R2 ushupgradesvc; C:\Windows\System32\UshUpgradeService.exe [274536 2019-12-17] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ApHidfiltrService; C:\Windows\System32\drivers\ApHidfiltr.sys [371312 2021-05-25] (ALPS ALPINE CO.,LTD. -> ALPSALPINE Co., Ltd.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [31376 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [235424 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [391808 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [297840 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [95960 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswElam; C:\Windows\System32\drivers\aswElam.sys [25576 2022-10-13] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [39608 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [269464 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [557096 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [105208 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [80376 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [942952 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [702784 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [212640 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [319568 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 cpuz150; C:\Windows\temp\cpuz150\cpuz150_x64.sys [44832 2023-04-24] (CPUID S.A.R.L.U. -> CPUID)
R3 DellInstrumentation; C:\Windows\System32\drivers\DellInstrumentation.sys [47472 2022-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Dell)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [109568 2013-01-25] (Huawei Technologies Co., Ltd.) [File not signed]
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [11776 2011-04-13] (Microsoft Windows Hardware Compatibility Publisher -> MBB Incorporated)
R0 MsSecCore; C:\Windows\System32\drivers\msseccore.sys [26480 2023-03-26] (Microsoft Windows -> Microsoft Corporation)
S3 MsSecWfp; C:\Windows\System32\drivers\mssecwfp.sys [29568 2023-03-26] (Microsoft Windows -> Microsoft Corporation)
R0 stdcfltn; C:\Windows\System32\DRIVERS\stdcfltn.sys [30352 2016-10-07] (STMICROELECTRONICS S.R.L. -> ST Microelectronics)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
U4 HomeGroupProvider; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-24 21:34 - 2023-04-24 21:34 - 000000000 ____D C:\FRST
2023-04-24 21:23 - 2023-04-24 21:23 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2023-04-24 21:23 - 2023-04-24 21:23 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput
2023-04-24 21:21 - 2023-04-24 21:22 - 002166364 _____ C:\Windows\Minidump\042423-12875-01.dmp
2023-04-24 21:21 - 2023-04-24 21:21 - 000008192 ___SH C:\DumpStack.log.tmp
2023-04-24 21:00 - 2023-04-24 21:00 - 000000000 ____D C:\Windows\system32\lxss
2023-04-24 21:00 - 2023-04-24 21:00 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2023-04-24 21:00 - 2023-04-24 21:00 - 000000000 ____D C:\Windows\LastGood.Tmp
2023-04-24 20:21 - 2023-04-24 21:21 - 1875332992 _____ C:\Windows\MEMORY.DMP
2023-04-24 20:21 - 2023-04-24 20:21 - 002030620 _____ C:\Windows\Minidump\042423-14203-01.dmp
2023-04-24 20:21 - 2023-04-24 20:21 - 000438944 _____ C:\Windows\system32\FNTCACHE.DAT
2023-04-24 17:43 - 2023-04-24 21:21 - 000003046 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2023-04-24 17:43 - 2023-04-24 21:21 - 000002988 _____ C:\Windows\system32\Tasks\CCleaner Update
2023-04-24 17:43 - 2023-04-24 21:21 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2023-04-20 19:15 - 2023-04-20 19:15 - 001135330 _____ C:\Users\Michal\Desktop\2023-04-20_191524.pdf
2023-04-19 22:54 - 2019-12-17 00:12 - 000614184 _____ (Broadcom Corporation) C:\Windows\system32\bipdll.dll
2023-04-19 22:54 - 2019-12-17 00:12 - 000232712 _____ (Broadcom Corp) C:\Windows\system32\BcmTokenProvider.dll
2023-04-19 22:54 - 2019-12-17 00:12 - 000075016 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\cvusbdrv.sys
2023-04-19 22:54 - 2019-12-13 03:21 - 000000226 _____ C:\Windows\system32\setcardsrouting.exe.config
2023-04-19 22:54 - 2019-12-13 03:21 - 000000128 _____ C:\Windows\system32\BcmTokenProvider.rsap
2023-04-13 21:11 - 2023-04-13 21:11 - 000000000 ___HD C:\$WinREAgent
2023-04-11 22:30 - 2023-04-11 22:30 - 000313240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2023-04-11 22:30 - 2023-04-11 22:30 - 000003990 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2023-03-27 06:41 - 2023-03-27 06:41 - 000000222 _____ C:\Users\Michal\Desktop\Euro Truck Simulator 2.url
2023-03-26 21:17 - 2023-04-24 21:21 - 000003306 _____ C:\Windows\system32\Tasks\Dell SupportAssistAgent AutoUpdate
2023-03-26 20:42 - 2023-03-26 20:42 - 000000000 ____D C:\Windows\system32\Drivers\mde
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-24 21:29 - 2022-07-28 10:44 - 000000000 ____D C:\Program Files (x86)\Google
2023-04-24 21:26 - 2022-07-28 11:45 - 000762592 _____ C:\Windows\system32\perfh019.dat
2023-04-24 21:26 - 2022-07-28 11:45 - 000152284 _____ C:\Windows\system32\perfc019.dat
2023-04-24 21:26 - 2022-07-28 10:43 - 002606902 _____ C:\Windows\system32\PerfStringBackup.INI
2023-04-24 21:26 - 2019-12-07 16:43 - 000719734 _____ C:\Windows\system32\perfh005.dat
2023-04-24 21:26 - 2019-12-07 16:43 - 000145860 _____ C:\Windows\system32\perfc005.dat
2023-04-24 21:26 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2023-04-24 21:23 - 2023-02-16 19:55 - 000079352 _____ (Microsoft Corporation) C:\Windows\system32\xgamehelper.exe
2023-04-24 21:23 - 2023-02-16 19:55 - 000062968 _____ (Microsoft Corporation) C:\Windows\system32\xgamecontrol.exe
2023-04-24 21:23 - 2022-07-29 22:09 - 002790904 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000484856 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000247248 _____ (Microsoft Corporation) C:\Windows\system32\gamingservicesproxy.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000202232 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000165368 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll
2023-04-24 21:23 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-04-24 21:23 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2023-04-24 21:22 - 2023-01-22 20:52 - 000000000 ____D C:\Windows\Minidump
2023-04-24 21:22 - 2022-10-16 04:35 - 000000000 ____D C:\Program Files (x86)\Steam
2023-04-24 21:22 - 2022-07-31 15:00 - 000000000 ____D C:\Program Files\CCleaner
2023-04-24 21:22 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-24 21:21 - 2022-08-29 19:42 - 000003486 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA{6BBA2034-FC4A-4486-9EB5-10C6EF9E7C46}
2023-04-24 21:21 - 2022-08-29 19:42 - 000003262 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore{559493EA-2EBE-4D42-8F6A-83A4C9D3BF0D}
2023-04-24 21:21 - 2022-07-31 15:00 - 000002254 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC - Michal
2023-04-24 21:21 - 2022-07-28 13:04 - 000003568 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-04-24 21:21 - 2022-07-28 13:04 - 000003344 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-04-24 21:21 - 2022-07-28 11:51 - 000000000 __SHD C:\Users\Michal\IntelGraphicsProfiles
2023-04-24 21:21 - 2022-07-28 11:19 - 000000000 ____D C:\Intel
2023-04-24 21:21 - 2022-07-28 11:07 - 000000000 ____D C:\ProgramData\NVIDIA
2023-04-24 21:21 - 2022-07-28 10:52 - 000115727 _____ C:\Windows\system32\CVFirmwareUpgradeLog.txt
2023-04-24 21:21 - 2022-07-28 10:34 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-04-24 21:21 - 2022-07-28 10:34 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-04-24 21:21 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2023-04-24 21:01 - 2022-07-28 10:42 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2023-04-24 21:00 - 2022-07-28 11:06 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2023-04-24 20:58 - 2022-07-28 11:52 - 000000000 ____D C:\Users\Michal\AppData\Local\NVIDIA
2023-04-24 20:58 - 2022-07-28 11:06 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2023-04-24 20:57 - 2023-01-22 15:38 - 000000000 ____D C:\ProgramData\Dell
2023-04-24 20:21 - 2022-07-28 10:37 - 000000000 ____D C:\Users\Michal
2023-04-24 19:52 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-04-23 08:47 - 2022-12-29 08:40 - 000000000 ____D C:\Users\Michal\AppData\Roaming\vlc
2023-04-22 20:53 - 2022-07-28 10:34 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-04-21 19:52 - 2022-07-28 10:48 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-04-21 19:52 - 2022-07-28 10:48 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-04-19 22:55 - 2022-07-28 10:40 - 000000000 ____D C:\ProgramData\Avast Software
2023-04-19 22:54 - 2022-07-28 10:38 - 000000000 ____D C:\Users\Michal\AppData\Local\Packages
2023-04-19 22:54 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI
2023-04-19 07:01 - 2022-07-31 16:13 - 000000000 ____D C:\Users\Michal\AppData\Roaming\AIMP
2023-04-16 09:00 - 2022-07-28 12:07 - 000000000 ____D C:\Program Files\Microsoft Office
2023-04-14 22:18 - 2022-07-28 16:42 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Excel
2023-04-13 21:24 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2023-04-13 21:24 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2023-04-13 21:17 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2023-04-13 21:15 - 2023-02-05 23:42 - 000000000 ____D C:\ProgramData\PCGameBoost
2023-04-13 21:15 - 2022-07-28 10:38 - 003015680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-04-13 18:07 - 2022-07-28 11:13 - 156112424 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-04-13 18:07 - 2022-07-28 11:13 - 000000000 ____D C:\Windows\system32\MRT
2023-04-11 22:30 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2023-04-11 18:35 - 2022-07-28 12:10 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Word
2023-04-08 11:45 - 2022-07-28 13:49 - 000000000 ____D C:\Users\Michal\AppData\Local\CrashDumps
2023-04-07 17:36 - 2022-08-29 21:36 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2023-04-07 17:36 - 2022-08-29 21:32 - 000000000 ____D C:\Program Files\Rockstar Games
2023-04-02 16:00 - 2022-07-28 12:25 - 000179694 _____ C:\Users\Michal\Desktop\Prachárna platby 03_2023.pdf
2023-03-31 20:24 - 2022-07-28 12:25 - 000000707 _____ C:\Users\Michal\Desktop\Sofisa_Michal_03_23.txt
2023-03-31 20:23 - 2022-07-28 12:25 - 000000596 _____ C:\Users\Michal\Desktop\ŽŠ_Michal_03_23.txt
2023-03-26 22:31 - 2023-01-22 15:40 - 000000000 ____D C:\Program Files\Dell
2023-03-26 22:31 - 2022-08-29 21:32 - 000000000 ____D C:\ProgramData\Package Cache
2023-03-26 22:00 - 2022-10-16 05:41 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-03-26 21:34 - 2023-01-22 16:11 - 000019632 _____ C:\Windows\SysWOW64\RtkMsgs.dll
2023-03-26 21:31 - 2022-07-28 11:34 - 000000000 ____D C:\Windows\Panther
2023-03-26 20:42 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\DDFs
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\PolicyDefinitions
==================== Files in the root of some directories ========
2022-09-07 22:05 - 2023-02-05 23:40 - 000007597 _____ () C:\Users\Michal\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-04-2023
Ran by Michal (administrator) on DESKTOP-RV3QMI2 (Dell Inc. Precision 7520) (24-04-2023 21:34:11)
Running from D:\Stažené soubory\FRST64.exe
Loaded Profiles: Michal
Platform: Microsoft Windows 10 Pro Version 22H2 19045.2846 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApntEx.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <5>
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.UserSessionAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\DCF\Dell.DCF.UA.Bradbury.API.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\DataManagerSubAgent\Dell.TechHub.DataManager.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Inc -> ) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApMsgFwd.exe
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\hidfind.exe
(DellTPad\Apoint.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\ApRemote.exe
(DellTPad\HidMonitorSvc.exe ->) (ALPS ALPINE CO.,LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\Apoint.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_e6d6f5a306002a89\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_e6d6f5a306002a89\igfxEM.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <41>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) ("STMicroelectronics Srl" -> ) C:\Windows\System32\drivers\DellFFDPWmiService.exe
(services.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\HidMonitorSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(services.exe ->) (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(services.exe ->) (Dell Inc -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(services.exe ->) (Dell Inc -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(services.exe ->) (Dell Inc -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(services.exe ->) (Dell Inc -> Dell) C:\Program Files\Dell\TechHub\Dell.TechHub.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_e6d6f5a306002a89\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_141eb88527011137\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d0b39b11619fd0c4\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d0b39b11619fd0c4\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\TPMProvisioningService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_7ed3bacbb0a8cc67\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\gamingservices.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ) C:\Windows\System32\UshUpgradeService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation) C:\Windows\System32\HostControlService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation) C:\Windows\System32\HostStorageService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\NVWMI\nvWmi64.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22062.534.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [220056 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11235920 2020-04-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-04-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1235160 2019-09-26] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1
HKLM\...\Policies\Explorer: [NoPublishingWizard] 1
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [40412472 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4362600 2023-03-24] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-2238093209-2022152676-238686933-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\112.0.5615.138\Installer\chrmstp.exe [2023-04-21] (Google LLC -> Google LLC)
Startup: C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon – zástupce.lnk [2022-07-28]
ShortcutTarget: ctfmon – zástupce.lnk -> C:\Windows\System32\ctfmon.exe (Microsoft Windows -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01F4EF06-D1B3-4304-951B-CF0DC8658CEF} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [745664 2016-01-12] (@ByELDI -> @ByELDI) [File not signed]
Task: {101744F1-3979-4B53-9280-2782403AF069} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [56816 2022-12-17] (HP Inc. -> HP Inc.)
Task: {1D88DA52-4CFB-4201-A028-A9082D5C1762} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4885912 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
Task: {2705B1E1-5411-4231-8999-2568C964FD6D} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\CCleanerCrashReporting" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\CCleanerSkipUAC - Michal" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\Dell SupportAssistAgent AutoUpdate" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore{559493EA-2EBE-4D42-8F6A-83A4C9D3BF0D}" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA{6BBA2034-FC4A-4486-9EB5-10C6EF9E7C46}" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE
Task: {28321526-692B-41A8-B979-34D51527CCC7} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {2B0D3F56-980D-4C39-A3C9-8A5368625132} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {32175321-8173-41D8-8B64-13A7E40F82E6} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2135448 2023-04-13] (Avast Software s.r.o. -> Avast Software)
Task: {385C5498-9A77-44B8-A717-CDD48D3A8852} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [168880 2023-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {3F19171A-EC1F-499B-94BD-626073B61EA3} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {46D79621-A058-47CF-899E-F9F77494B5D8} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {672412A2-6C3E-45C3-ADAE-1D59603D5D63} - System32\Tasks\Intel\Intel® Management and Security Status => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [219848 2022-08-21] (Intel Corporation -> Intel Corporation) -> "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" 60
Task: {71745EAD-62A4-4350-BDBF-0CD4111ED916} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703544 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "0ddc36cd-4798-4351-8296-eeba40e894fb" --version "6.11.10435" --silent
Task: {7F3BB80C-91BB-49C9-8E44-90B92810AF2D} - System32\Tasks\Optimize Thumbnail Cache => C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\isupdate.exe [61104 2020-09-26] (Flexera Software LLC -> InstallShield®) [File not signed] <==== ATTENTION
Task: {8AA701E3-DD7E-4BDA-9CB9-BD1CE48A8DDC} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144272 2023-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {97759FC0-7AEC-4788-8EB9-D544E1A72D52} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2302168 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {A1C52FA1-3FA1-4A94-8BFE-DE8787B58929} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26409896 2023-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {C9EF5D5A-5C60-4A57-8FC1-C8A8BEB82A50} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 ] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {CF51562C-0DC6-49EE-8C7C-1468DC27C63A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144272 2023-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {D072CAF3-3C1C-4345-AD9E-F9C08411D88F} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [665952 2023-01-31] (Dell Inc -> Dell Inc.)
Task: {D1324AD8-D84C-4671-9127-1703FA8D92EA} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [56816 2022-12-17] (HP Inc. -> HP Inc.)
Task: {D60A66E4-BE73-4231-A7F9-5B83B7590AB0} - System32\Tasks\CCleanerSkipUAC - Michal => C:\Program Files\CCleaner\CCleaner.exe [34159416 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {DC18CAC0-10E3-4077-8879-10B758A51D3D} - System32\Tasks\GoogleUpdateTaskMachineCore{559493EA-2EBE-4D42-8F6A-83A4C9D3BF0D} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2022-07-28] (Google Inc -> Google LLC)
Task: {E3B1ECB5-1188-48FE-91A7-C6D72D3AAED4} - System32\Tasks\KMSpico Automatic Update Scheduler => C:\Program Files\KMSpico\KMSUPD.exe [89272 2021-02-11] (KMSpico ByELDI LTD -> @ByELDI)
Task: {E8337FE9-AA51-4036-ACA0-6693F5DE75CC} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26409896 2023-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {FCC8F6CC-E2E9-478A-97C4-604ABBB002A5} - System32\Tasks\GoogleUpdateTaskMachineUA{6BBA2034-FC4A-4486-9EB5-10C6EF9E7C46} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2022-07-28] (Google Inc -> Google LLC)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
AutoConfigURL: [HKLM] => hxxp://127.0.0.1:86/ <==== ATTENTION
AutoConfigURL: [HKLM-x32] => hxxp://127.0.0.1:86/ <==== ATTENTION
AutoConfigURL: [{8EB8ACF2-18A8-4758-85C1-12B180D94138}] => hxxp://127.0.0.1:86/ <==== ATTENTION
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2f698019-3819-4aca-a144-560a4eac2d09}: [DhcpNameServer] 192.168.0.1
ManualProxies: 0hxxp://127.0.0.1:86/ <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
Edge:
=======
Edge Profile: C:\Users\Michal\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-24]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default [2023-04-24]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Dokumenty Google offline) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-20]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-04-24]
CHR Extension: (DownThemAll!) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nljkibfhlpcnanjgbnlnbjecgicbjkge [2023-02-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-07-28]
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\System Profile [2023-04-08]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ApHidMonitorService; C:\Windows\system32\DellTPad\HidMonitorSvc.exe [894848 2021-05-25] (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8808344 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [583064 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [584088 2023-04-11] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2022-07-28] (Avast Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8894752 2021-11-18] (BattlEye Innovations e.K. -> )
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1063736 2023-04-17] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12634544 2023-04-08] (Microsoft Corporation -> Microsoft Corporation)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [458960 2022-11-08] (Dell Inc -> Dell Technologies Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [161488 2022-11-08] (Dell Inc -> Dell Technologies Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [484560 2022-11-08] (Dell Inc -> Dell Technologies Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [47320 2022-11-18] (Dell Inc -> )
R2 DellFFDPWmiService; C:\Windows\System32\drivers\DellFFDPWmiService.exe [41136 2020-08-28] ("STMicroelectronics Srl" -> )
R2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [156064 2022-08-16] (Dell Inc -> Dell)
R2 FoxitReaderUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2358800 2022-05-19] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
R2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\GamingServices.exe [75256 2023-04-24] (Microsoft Corporation -> )
R2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_11.76.5001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [75256 2023-04-24] (Microsoft Corporation -> )
R2 hostcontrolsvc; C:\Windows\System32\HostControlService.exe [824424 2019-12-17] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation)
R2 hoststoragesvc; C:\Windows\System32\HostStorageService.exe [170088 2019-12-17] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [229360 2022-12-17] (HP Inc. -> HP Inc.)
R2 MbnExt; C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\MbnExt.dll [422608 2017-04-13] (Gemfor s.r.o. -> Gemfor s.r.o.)
R2 NVWMI; C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\NVWMI\nvWmi64.exe [4487208 2022-12-30] (Nvidia Corporation -> NVIDIA Corporation)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1846768 2023-04-07] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [285088 2023-03-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [160096 2023-01-31] (Dell Inc -> Dell Inc.)
R2 ushupgradesvc; C:\Windows\System32\UshUpgradeService.exe [274536 2019-12-17] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_a7d5d198678609bd\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ApHidfiltrService; C:\Windows\System32\drivers\ApHidfiltr.sys [371312 2021-05-25] (ALPS ALPINE CO.,LTD. -> ALPSALPINE Co., Ltd.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [31376 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [235424 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [391808 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [297840 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [95960 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswElam; C:\Windows\System32\drivers\aswElam.sys [25576 2022-10-13] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [39608 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [269464 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [557096 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [105208 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [80376 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [942952 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [702784 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [212640 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [319568 2023-04-11] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 cpuz150; C:\Windows\temp\cpuz150\cpuz150_x64.sys [44832 2023-04-24] (CPUID S.A.R.L.U. -> CPUID)
R3 DellInstrumentation; C:\Windows\System32\drivers\DellInstrumentation.sys [47472 2022-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Dell)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [109568 2013-01-25] (Huawei Technologies Co., Ltd.) [File not signed]
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [11776 2011-04-13] (Microsoft Windows Hardware Compatibility Publisher -> MBB Incorporated)
R0 MsSecCore; C:\Windows\System32\drivers\msseccore.sys [26480 2023-03-26] (Microsoft Windows -> Microsoft Corporation)
S3 MsSecWfp; C:\Windows\System32\drivers\mssecwfp.sys [29568 2023-03-26] (Microsoft Windows -> Microsoft Corporation)
R0 stdcfltn; C:\Windows\System32\DRIVERS\stdcfltn.sys [30352 2016-10-07] (STMICROELECTRONICS S.R.L. -> ST Microelectronics)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
U4 HomeGroupProvider; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-24 21:34 - 2023-04-24 21:34 - 000000000 ____D C:\FRST
2023-04-24 21:23 - 2023-04-24 21:23 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2023-04-24 21:23 - 2023-04-24 21:23 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput
2023-04-24 21:21 - 2023-04-24 21:22 - 002166364 _____ C:\Windows\Minidump\042423-12875-01.dmp
2023-04-24 21:21 - 2023-04-24 21:21 - 000008192 ___SH C:\DumpStack.log.tmp
2023-04-24 21:00 - 2023-04-24 21:00 - 000000000 ____D C:\Windows\system32\lxss
2023-04-24 21:00 - 2023-04-24 21:00 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2023-04-24 21:00 - 2023-04-24 21:00 - 000000000 ____D C:\Windows\LastGood.Tmp
2023-04-24 20:21 - 2023-04-24 21:21 - 1875332992 _____ C:\Windows\MEMORY.DMP
2023-04-24 20:21 - 2023-04-24 20:21 - 002030620 _____ C:\Windows\Minidump\042423-14203-01.dmp
2023-04-24 20:21 - 2023-04-24 20:21 - 000438944 _____ C:\Windows\system32\FNTCACHE.DAT
2023-04-24 17:43 - 2023-04-24 21:21 - 000003046 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2023-04-24 17:43 - 2023-04-24 21:21 - 000002988 _____ C:\Windows\system32\Tasks\CCleaner Update
2023-04-24 17:43 - 2023-04-24 21:21 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2023-04-20 19:15 - 2023-04-20 19:15 - 001135330 _____ C:\Users\Michal\Desktop\2023-04-20_191524.pdf
2023-04-19 22:54 - 2019-12-17 00:12 - 000614184 _____ (Broadcom Corporation) C:\Windows\system32\bipdll.dll
2023-04-19 22:54 - 2019-12-17 00:12 - 000232712 _____ (Broadcom Corp) C:\Windows\system32\BcmTokenProvider.dll
2023-04-19 22:54 - 2019-12-17 00:12 - 000075016 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\cvusbdrv.sys
2023-04-19 22:54 - 2019-12-13 03:21 - 000000226 _____ C:\Windows\system32\setcardsrouting.exe.config
2023-04-19 22:54 - 2019-12-13 03:21 - 000000128 _____ C:\Windows\system32\BcmTokenProvider.rsap
2023-04-13 21:11 - 2023-04-13 21:11 - 000000000 ___HD C:\$WinREAgent
2023-04-11 22:30 - 2023-04-11 22:30 - 000313240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2023-04-11 22:30 - 2023-04-11 22:30 - 000003990 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2023-03-27 06:41 - 2023-03-27 06:41 - 000000222 _____ C:\Users\Michal\Desktop\Euro Truck Simulator 2.url
2023-03-26 21:17 - 2023-04-24 21:21 - 000003306 _____ C:\Windows\system32\Tasks\Dell SupportAssistAgent AutoUpdate
2023-03-26 20:42 - 2023-03-26 20:42 - 000000000 ____D C:\Windows\system32\Drivers\mde
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-24 21:29 - 2022-07-28 10:44 - 000000000 ____D C:\Program Files (x86)\Google
2023-04-24 21:26 - 2022-07-28 11:45 - 000762592 _____ C:\Windows\system32\perfh019.dat
2023-04-24 21:26 - 2022-07-28 11:45 - 000152284 _____ C:\Windows\system32\perfc019.dat
2023-04-24 21:26 - 2022-07-28 10:43 - 002606902 _____ C:\Windows\system32\PerfStringBackup.INI
2023-04-24 21:26 - 2019-12-07 16:43 - 000719734 _____ C:\Windows\system32\perfh005.dat
2023-04-24 21:26 - 2019-12-07 16:43 - 000145860 _____ C:\Windows\system32\perfc005.dat
2023-04-24 21:26 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2023-04-24 21:23 - 2023-02-16 19:55 - 000079352 _____ (Microsoft Corporation) C:\Windows\system32\xgamehelper.exe
2023-04-24 21:23 - 2023-02-16 19:55 - 000062968 _____ (Microsoft Corporation) C:\Windows\system32\xgamecontrol.exe
2023-04-24 21:23 - 2022-07-29 22:09 - 002790904 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000484856 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000247248 _____ (Microsoft Corporation) C:\Windows\system32\gamingservicesproxy.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000202232 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000165368 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll
2023-04-24 21:23 - 2022-07-29 22:09 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll
2023-04-24 21:23 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-04-24 21:23 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2023-04-24 21:22 - 2023-01-22 20:52 - 000000000 ____D C:\Windows\Minidump
2023-04-24 21:22 - 2022-10-16 04:35 - 000000000 ____D C:\Program Files (x86)\Steam
2023-04-24 21:22 - 2022-07-31 15:00 - 000000000 ____D C:\Program Files\CCleaner
2023-04-24 21:22 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-24 21:21 - 2022-08-29 19:42 - 000003486 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA{6BBA2034-FC4A-4486-9EB5-10C6EF9E7C46}
2023-04-24 21:21 - 2022-08-29 19:42 - 000003262 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore{559493EA-2EBE-4D42-8F6A-83A4C9D3BF0D}
2023-04-24 21:21 - 2022-07-31 15:00 - 000002254 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC - Michal
2023-04-24 21:21 - 2022-07-28 13:04 - 000003568 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-04-24 21:21 - 2022-07-28 13:04 - 000003344 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-04-24 21:21 - 2022-07-28 11:51 - 000000000 __SHD C:\Users\Michal\IntelGraphicsProfiles
2023-04-24 21:21 - 2022-07-28 11:19 - 000000000 ____D C:\Intel
2023-04-24 21:21 - 2022-07-28 11:07 - 000000000 ____D C:\ProgramData\NVIDIA
2023-04-24 21:21 - 2022-07-28 10:52 - 000115727 _____ C:\Windows\system32\CVFirmwareUpgradeLog.txt
2023-04-24 21:21 - 2022-07-28 10:34 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-04-24 21:21 - 2022-07-28 10:34 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-04-24 21:21 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2023-04-24 21:01 - 2022-07-28 10:42 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2023-04-24 21:00 - 2022-07-28 11:06 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2023-04-24 20:58 - 2022-07-28 11:52 - 000000000 ____D C:\Users\Michal\AppData\Local\NVIDIA
2023-04-24 20:58 - 2022-07-28 11:06 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2023-04-24 20:57 - 2023-01-22 15:38 - 000000000 ____D C:\ProgramData\Dell
2023-04-24 20:21 - 2022-07-28 10:37 - 000000000 ____D C:\Users\Michal
2023-04-24 19:52 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-04-23 08:47 - 2022-12-29 08:40 - 000000000 ____D C:\Users\Michal\AppData\Roaming\vlc
2023-04-22 20:53 - 2022-07-28 10:34 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-04-21 19:52 - 2022-07-28 10:48 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-04-21 19:52 - 2022-07-28 10:48 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-04-19 22:55 - 2022-07-28 10:40 - 000000000 ____D C:\ProgramData\Avast Software
2023-04-19 22:54 - 2022-07-28 10:38 - 000000000 ____D C:\Users\Michal\AppData\Local\Packages
2023-04-19 22:54 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI
2023-04-19 07:01 - 2022-07-31 16:13 - 000000000 ____D C:\Users\Michal\AppData\Roaming\AIMP
2023-04-16 09:00 - 2022-07-28 12:07 - 000000000 ____D C:\Program Files\Microsoft Office
2023-04-14 22:18 - 2022-07-28 16:42 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Excel
2023-04-13 21:24 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2023-04-13 21:24 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2023-04-13 21:17 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2023-04-13 21:15 - 2023-02-05 23:42 - 000000000 ____D C:\ProgramData\PCGameBoost
2023-04-13 21:15 - 2022-07-28 10:38 - 003015680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-04-13 18:07 - 2022-07-28 11:13 - 156112424 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-04-13 18:07 - 2022-07-28 11:13 - 000000000 ____D C:\Windows\system32\MRT
2023-04-11 22:30 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2023-04-11 18:35 - 2022-07-28 12:10 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Word
2023-04-08 11:45 - 2022-07-28 13:49 - 000000000 ____D C:\Users\Michal\AppData\Local\CrashDumps
2023-04-07 17:36 - 2022-08-29 21:36 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2023-04-07 17:36 - 2022-08-29 21:32 - 000000000 ____D C:\Program Files\Rockstar Games
2023-04-02 16:00 - 2022-07-28 12:25 - 000179694 _____ C:\Users\Michal\Desktop\Prachárna platby 03_2023.pdf
2023-03-31 20:24 - 2022-07-28 12:25 - 000000707 _____ C:\Users\Michal\Desktop\Sofisa_Michal_03_23.txt
2023-03-31 20:23 - 2022-07-28 12:25 - 000000596 _____ C:\Users\Michal\Desktop\ŽŠ_Michal_03_23.txt
2023-03-26 22:31 - 2023-01-22 15:40 - 000000000 ____D C:\Program Files\Dell
2023-03-26 22:31 - 2022-08-29 21:32 - 000000000 ____D C:\ProgramData\Package Cache
2023-03-26 22:00 - 2022-10-16 05:41 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-03-26 21:34 - 2023-01-22 16:11 - 000019632 _____ C:\Windows\SysWOW64\RtkMsgs.dll
2023-03-26 21:31 - 2022-07-28 11:34 - 000000000 ____D C:\Windows\Panther
2023-03-26 20:42 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\DDFs
2023-03-26 20:42 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\PolicyDefinitions
==================== Files in the root of some directories ========
2022-09-07 22:05 - 2023-02-05 23:40 - 000007597 _____ () C:\Users\Michal\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================