PROSÍM O KONTROLU LOGU
Napsal: 25 dub 2023 15:14
NTB je zpomalený , seká se i prohlížeč občas i videa.
Prosím o kontrolu logu.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-04-2023
Ran by david (administrator) on DESKTOP-57398S1 (LENOVO 80M3) (25-04-2023 15:41:53)
Running from C:\Users\david\Desktop\FRST64.exe
Loaded Profiles: david
Platform: Microsoft Windows 10 Home Version 22H2 19045.2846 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\IObit\Driver Booster\8.7.0\DriverBooster.exe ->) (IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\Driver Booster\8.7.0\ScanWinUpd.exe
(C:\Program Files\Elantech\ETDCtrl.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(C:\Program Files\Elantech\ETDCtrl.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(C:\Program Files\Elantech\ETDService.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(explorer.exe ->) (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(explorer.exe ->) (Fortemedia Inc -> ) C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Hewlett-Packard) [File not signed] C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\Driver Booster\8.7.0\DriverBooster.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(services.exe ->) (Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(services.exe ->) (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(services.exe ->) (Conexant Systems, Inc.) [File not signed] C:\Windows\SysWOW64\UIUSrv.exe
(services.exe ->) (Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
(services.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\NisSrv.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23032.186.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [916184 2014-07-02] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [168064 2022-03-15] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [OrderReminder] => C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-07-30] (Hewlett-Packard) [File not signed]
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\david\AppData\Local\Microsoft\Teams\Update.exe [2459304 2022-01-12] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [4338880 2016-02-02] (Disc Soft Ltd -> Disc Soft Ltd) [File not signed]
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: I - "I:\Install.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14a63-829d-11ec-b698-b46d83ba83d9} - "G:\Setup.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14a9d-829d-11ec-b698-b46d83ba83d9} - "I:\Install.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14c8a-829d-11ec-b698-b46d83ba83d9} - "I:\Install.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14dab-829d-11ec-b698-b46d83ba83d9} - "J:\Setup.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {c0b04164-35ae-11ec-b690-507b9d329ba3} - "E:\HiSuiteDownLoader.exe"
HKLM\...\Windows x64\Print Processors\Canon MP250 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD9W.DLL [28672 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\HP1020PrintProc: C:\Windows\System32\spool\prtprocs\x64\pphp1020.dll [65024 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP250 series: C:\Windows\system32\CNMLM9W.DLL [336896 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\HPLJ1020LM: C:\Windows\system32\zlhp1020.dll [192512 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08257850-F2D0-4F0E-9987-974E67665DED} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23709664 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {105BC3E5-814E-45D6-A8D3-146A9732E60F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1BE7CC90-9E4F-4365-BE8B-E424B306A25A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142272 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {21F48AFA-3B21-471B-8538-4E6D9E21B798} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [718752 2023-04-20] (Mozilla Corporation -> Mozilla Foundation)
Task: {266314D3-AA18-4C69-88A3-D6A5EC196407} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23709664 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {4461C2FA-823F-4D38-A1B1-88DAC8615942} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8522672 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {5C3FA62F-EA6F-48FC-882E-19DB098898A6} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [64408 2023-02-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {61EE689E-5C27-4257-83FD-766686AB69C8} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676768 2023-04-20] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {73EB0D44-17A9-4997-99B1-088568D37269} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8522672 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {88CC84D8-3487-4F5A-AF1F-76FDED4512CD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D7D49EB0-2A5F-4A58-AF30-FFF97E70A41A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D9E74B24-E794-40E9-9A87-FE60C1B4421A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F240F192-B69F-4154-9D3C-68F70CB4C085} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [3854464 2023-02-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {F548359C-8D91-4438-B78B-4E295F771E5A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142272 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{65237ec6-51a7-455c-a40a-96b45a6ca434}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{7e008ce8-e8c5-44f1-8bf0-9af172295d08}: [DhcpNameServer] 10.0.0.138
Edge:
=======
Edge Profile: C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-06]
FireFox:
========
FF DefaultProfile: mkwa0ay5.default
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\mkwa0ay5.default [2022-02-15]
FF user.js: detected! => C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\mkwa0ay5.default\user.js [2022-02-15]
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668 [2023-04-25]
FF Homepage: Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668 -> www.seznam.cz
FF Extension: (Simple Translate) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668\Extensions\simple-translate@sienori.xpi [2023-03-27]
FF Extension: (No Name) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-03-27]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-02-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-08-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-02-04] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2023-04-25]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-05-20] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12126112 2023-02-23] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Ultra Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [1439424 2016-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [3210720 2022-03-15] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [3210720 2022-03-15] (ESET, spol. s r.o. -> ESET)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [11950544 2022-05-26] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 OfficeSvcManagerAddons; C:\Windows\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21312 2021-04-09] (Microsoft Windows -> Microsoft Corporation)
R2 UIUService; C:\Windows\SysWOW64\UIUSrv.exe [105984 2022-02-27] (Conexant Systems, Inc.) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\NisSrv.exe [3228400 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MsMpEng.exe [133536 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 dtultrascsibus; C:\Windows\System32\drivers\dtultrascsibus.sys [30264 2022-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtultrausbbus; C:\Windows\System32\drivers\dtultrausbbus.sys [47672 2022-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [183888 2022-03-15] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15824 2022-03-11] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [226264 2022-03-15] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [111624 2022-03-15] (ESET, spol. s r.o. -> ESET)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18816 2021-10-25] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2021-10-25] (Martin Malik - REALiX -> REALiX(tm))
S2 SecDrv; C:\Windows\SysWOW64\drivers\SECDRV.SYS [28400 2022-02-02] () [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49600 2023-04-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [497920 2023-04-20] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [99608 2023-04-20] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsl4a8fc08e; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96F416EE-FF6C-42EA-A491-CC838A391A6C}\MpKslDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-25 15:41 - 2023-04-25 15:45 - 000017493 _____ C:\Users\david\Desktop\FRST.txt
2023-04-25 15:41 - 2023-04-25 15:41 - 002382336 _____ (Farbar) C:\Users\david\Desktop\FRST64.exe
2023-04-25 15:41 - 2023-04-25 15:41 - 000000000 ____D C:\Users\david\Desktop\FRST-OlderVersion
2023-04-25 15:40 - 2023-04-25 15:43 - 000000000 ____D C:\FRST
2023-04-25 15:37 - 2023-04-25 15:38 - 000000000 ____D C:\rsit
2023-04-25 15:32 - 2023-04-25 15:32 - 001185640 _____ (Realtek ) C:\Windows\system32\Drivers\rt640x64.sys
2023-04-25 15:26 - 2023-04-25 15:26 - 017388440 _____ C:\Windows\system32\RsEyeContactCorrection_Assets.dll
2023-04-25 15:26 - 2023-04-25 15:26 - 015824792 _____ C:\Windows\system32\RsDMFT_Assets.dll
2023-04-25 15:26 - 2023-04-25 15:26 - 013414320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RsDMFT64.dll
2023-04-25 15:23 - 2021-01-17 22:06 - 008447152 _____ (Malwarebytes) C:\Users\david\Desktop\AdwCleaner.exe
2023-04-25 15:22 - 2021-08-28 21:01 - 001053600 _____ (ESET) C:\Users\david\Desktop\esetuninstaller.exe
2023-04-25 15:22 - 2019-04-13 10:13 - 001663040 _____ (Malwarebytes) C:\Users\david\Desktop\JRT.exe
2023-04-25 15:14 - 2023-04-25 15:15 - 000000000 ____D C:\Users\david\Desktop\FILMY
2023-04-25 14:59 - 2023-04-25 14:59 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2023-04-25 14:26 - 2023-04-25 14:26 - 000000000 ___HD C:\$WinREAgent
2023-04-23 20:01 - 2023-04-25 14:58 - 000008192 ___SH C:\DumpStack.log.tmp
2023-04-23 20:01 - 2023-04-23 20:02 - 000911876 _____ C:\Windows\Minidump\042323-50031-01.dmp
2023-04-23 14:07 - 2023-04-23 15:42 - 1748916153 _____ C:\Users\david\Downloads\Nejdrsnější věznice světa_S05E03_Grónsko_ Ledové vězení.mkv
2023-04-23 12:10 - 2023-04-23 12:47 - 672190999 _____ C:\Users\david\Downloads\Nejdrsnější věznice světa S04E02 Německo Vězeňská terapie.mkv
2023-04-20 17:08 - 2023-04-23 20:01 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-04-20 16:52 - 2023-04-20 16:52 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3476297074-517369176-1764710931-1001
2023-04-20 16:52 - 2023-04-20 16:52 - 000002383 _____ C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-03-29 18:30 - 2023-03-29 18:30 - 000002048 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star Stable Online.lnk
2023-03-29 18:30 - 2023-03-29 18:30 - 000002036 _____ C:\Users\Public\Desktop\Star Stable Online.lnk
2023-03-29 18:29 - 2023-03-29 19:45 - 000000000 ____D C:\Program Files\Star Stable Online
2023-03-29 18:21 - 2023-04-23 20:01 - 727716806 _____ C:\Windows\MEMORY.DMP
2023-03-29 18:21 - 2023-03-29 18:55 - 001810612 _____ C:\Windows\Minidump\032923-66281-01.dmp
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-25 15:37 - 2022-01-21 21:18 - 000000000 ____D C:\Program Files\trend micro
2023-04-25 15:36 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-25 15:35 - 2021-10-25 22:05 - 000000000 ____D C:\ProgramData\IObit
2023-04-25 15:34 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2023-04-25 15:24 - 2022-02-15 21:23 - 000000000 ____D C:\ProgramData\ProductData
2023-04-25 15:18 - 2022-02-15 21:33 - 000002284 _____ C:\Users\david\Desktop\Loader-IDB.lnk
2023-04-25 15:06 - 2021-09-28 16:15 - 001605602 _____ C:\Windows\system32\PerfStringBackup.INI
2023-04-25 15:06 - 2019-12-07 16:41 - 000683426 _____ C:\Windows\system32\perfh005.dat
2023-04-25 15:06 - 2019-12-07 16:41 - 000137206 _____ C:\Windows\system32\perfc005.dat
2023-04-25 15:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-04-25 15:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2023-04-25 15:02 - 2023-01-26 19:41 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-04-25 15:02 - 2021-09-28 16:02 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-04-25 14:59 - 2021-09-28 16:27 - 000000000 __SHD C:\Users\david\IntelGraphicsProfiles
2023-04-25 14:58 - 2021-09-28 16:00 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-04-25 14:57 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2023-04-25 14:55 - 2021-09-28 16:00 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-04-25 14:54 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2023-04-25 14:19 - 2021-12-30 17:17 - 000000000 ____D C:\Program Files (x86)\EaseUS
2023-04-23 20:07 - 2021-09-28 15:59 - 000441584 _____ C:\Windows\system32\FNTCACHE.DAT
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\DDFs
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2023-04-23 20:01 - 2021-11-21 18:57 - 000000000 ____D C:\Windows\Minidump
2023-04-23 20:01 - 2021-09-28 16:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-04-23 19:50 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-04-23 12:14 - 2021-10-05 21:23 - 000000000 ____D C:\Program Files\Microsoft Office
2023-04-23 12:00 - 2022-02-13 18:21 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-04-21 21:37 - 2021-09-28 16:03 - 003015680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-04-21 19:17 - 2021-09-28 16:35 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-04-21 18:05 - 2021-09-28 16:44 - 000000000 ____D C:\Users\david\AppData\Roaming\Kodi
2023-04-20 20:34 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2023-04-20 20:34 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\setup
2023-04-20 20:31 - 2021-09-28 16:35 - 000000000 ____D C:\Users\david\AppData\LocalLow\Mozilla
2023-04-20 20:00 - 2021-09-28 17:57 - 000000000 ____D C:\Windows\system32\MRT
2023-04-20 19:49 - 2021-09-28 17:57 - 156112424 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-04-20 19:42 - 2021-10-05 23:53 - 000000000 ____D C:\Users\david\AppData\Roaming\Microsoft\Teams
2023-04-20 19:41 - 2022-05-16 20:36 - 000000000 ____D C:\Splines
2023-04-20 19:41 - 2022-05-16 20:35 - 000000000 ____D C:\Sceneryobjects
2023-04-20 19:38 - 2021-12-23 18:25 - 000000000 ____D C:\Users\david\AppData\Local\Roblox
2023-04-20 17:09 - 2021-10-18 20:06 - 000000000 ____D C:\Users\david\AppData\Roaming\Microsoft\Word
2023-04-20 16:59 - 2021-09-28 16:00 - 000000000 ____D C:\Windows\system32\Drivers\wd
2023-04-20 16:52 - 2021-12-23 18:19 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3476297074-517369176-1764710931-1001
2023-04-07 23:32 - 2021-09-28 16:23 - 000000000 ____D C:\Users\david\AppData\Local\Packages
2023-04-07 19:51 - 2021-09-28 16:02 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-04-07 19:51 - 2021-09-28 16:02 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-03-29 19:45 - 2022-03-18 17:58 - 000000000 ____D C:\Users\david\AppData\Roaming\Star Stable Online
2023-03-29 19:43 - 2021-10-20 17:21 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2023-03-29 18:35 - 2021-09-28 16:42 - 000000000 ____D C:\ProgramData\Package Cache
2023-03-29 18:29 - 2022-03-18 17:57 - 000000000 ____D C:\Program Files (x86)\Star Stable Online
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Prosím o kontrolu logu.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-04-2023
Ran by david (administrator) on DESKTOP-57398S1 (LENOVO 80M3) (25-04-2023 15:41:53)
Running from C:\Users\david\Desktop\FRST64.exe
Loaded Profiles: david
Platform: Microsoft Windows 10 Home Version 22H2 19045.2846 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\IObit\Driver Booster\8.7.0\DriverBooster.exe ->) (IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\Driver Booster\8.7.0\ScanWinUpd.exe
(C:\Program Files\Elantech\ETDCtrl.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(C:\Program Files\Elantech\ETDCtrl.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(C:\Program Files\Elantech\ETDService.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(explorer.exe ->) (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(explorer.exe ->) (Fortemedia Inc -> ) C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Hewlett-Packard) [File not signed] C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\Driver Booster\8.7.0\DriverBooster.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(services.exe ->) (Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(services.exe ->) (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(services.exe ->) (Conexant Systems, Inc.) [File not signed] C:\Windows\SysWOW64\UIUSrv.exe
(services.exe ->) (Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
(services.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\NisSrv.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23032.186.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [916184 2014-07-02] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [168064 2022-03-15] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [OrderReminder] => C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-07-30] (Hewlett-Packard) [File not signed]
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\david\AppData\Local\Microsoft\Teams\Update.exe [2459304 2022-01-12] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [4338880 2016-02-02] (Disc Soft Ltd -> Disc Soft Ltd) [File not signed]
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: I - "I:\Install.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14a63-829d-11ec-b698-b46d83ba83d9} - "G:\Setup.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14a9d-829d-11ec-b698-b46d83ba83d9} - "I:\Install.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14c8a-829d-11ec-b698-b46d83ba83d9} - "I:\Install.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {8fc14dab-829d-11ec-b698-b46d83ba83d9} - "J:\Setup.exe"
HKU\S-1-5-21-3476297074-517369176-1764710931-1001\...\MountPoints2: {c0b04164-35ae-11ec-b690-507b9d329ba3} - "E:\HiSuiteDownLoader.exe"
HKLM\...\Windows x64\Print Processors\Canon MP250 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD9W.DLL [28672 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\HP1020PrintProc: C:\Windows\System32\spool\prtprocs\x64\pphp1020.dll [65024 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP250 series: C:\Windows\system32\CNMLM9W.DLL [336896 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\HPLJ1020LM: C:\Windows\system32\zlhp1020.dll [192512 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08257850-F2D0-4F0E-9987-974E67665DED} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23709664 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {105BC3E5-814E-45D6-A8D3-146A9732E60F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1BE7CC90-9E4F-4365-BE8B-E424B306A25A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142272 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {21F48AFA-3B21-471B-8538-4E6D9E21B798} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [718752 2023-04-20] (Mozilla Corporation -> Mozilla Foundation)
Task: {266314D3-AA18-4C69-88A3-D6A5EC196407} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23709664 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {4461C2FA-823F-4D38-A1B1-88DAC8615942} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8522672 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {5C3FA62F-EA6F-48FC-882E-19DB098898A6} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [64408 2023-02-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {61EE689E-5C27-4257-83FD-766686AB69C8} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676768 2023-04-20] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {73EB0D44-17A9-4997-99B1-088568D37269} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8522672 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {88CC84D8-3487-4F5A-AF1F-76FDED4512CD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D7D49EB0-2A5F-4A58-AF30-FFF97E70A41A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D9E74B24-E794-40E9-9A87-FE60C1B4421A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MpCmdRun.exe [1645864 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F240F192-B69F-4154-9D3C-68F70CB4C085} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [3854464 2023-02-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {F548359C-8D91-4438-B78B-4E295F771E5A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142272 2023-04-23] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{65237ec6-51a7-455c-a40a-96b45a6ca434}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{7e008ce8-e8c5-44f1-8bf0-9af172295d08}: [DhcpNameServer] 10.0.0.138
Edge:
=======
Edge Profile: C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-06]
FireFox:
========
FF DefaultProfile: mkwa0ay5.default
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\mkwa0ay5.default [2022-02-15]
FF user.js: detected! => C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\mkwa0ay5.default\user.js [2022-02-15]
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668 [2023-04-25]
FF Homepage: Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668 -> www.seznam.cz
FF Extension: (Simple Translate) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668\Extensions\simple-translate@sienori.xpi [2023-03-27]
FF Extension: (No Name) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\4nli3p9u.default-release-1644957994668\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-03-27]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-02-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-08-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-02-04] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2023-04-25]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-05-20] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12126112 2023-02-23] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Ultra Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [1439424 2016-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [3210720 2022-03-15] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [3210720 2022-03-15] (ESET, spol. s r.o. -> ESET)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [11950544 2022-05-26] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 OfficeSvcManagerAddons; C:\Windows\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21312 2021-04-09] (Microsoft Windows -> Microsoft Corporation)
R2 UIUService; C:\Windows\SysWOW64\UIUSrv.exe [105984 2022-02-27] (Conexant Systems, Inc.) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\NisSrv.exe [3228400 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2303.8-0\MsMpEng.exe [133536 2023-04-20] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 dtultrascsibus; C:\Windows\System32\drivers\dtultrascsibus.sys [30264 2022-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtultrausbbus; C:\Windows\System32\drivers\dtultrausbbus.sys [47672 2022-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [183888 2022-03-15] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15824 2022-03-11] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [226264 2022-03-15] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [111624 2022-03-15] (ESET, spol. s r.o. -> ESET)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18816 2021-10-25] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2021-10-25] (Martin Malik - REALiX -> REALiX(tm))
S2 SecDrv; C:\Windows\SysWOW64\drivers\SECDRV.SYS [28400 2022-02-02] () [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49600 2023-04-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [497920 2023-04-20] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [99608 2023-04-20] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsl4a8fc08e; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96F416EE-FF6C-42EA-A491-CC838A391A6C}\MpKslDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-25 15:41 - 2023-04-25 15:45 - 000017493 _____ C:\Users\david\Desktop\FRST.txt
2023-04-25 15:41 - 2023-04-25 15:41 - 002382336 _____ (Farbar) C:\Users\david\Desktop\FRST64.exe
2023-04-25 15:41 - 2023-04-25 15:41 - 000000000 ____D C:\Users\david\Desktop\FRST-OlderVersion
2023-04-25 15:40 - 2023-04-25 15:43 - 000000000 ____D C:\FRST
2023-04-25 15:37 - 2023-04-25 15:38 - 000000000 ____D C:\rsit
2023-04-25 15:32 - 2023-04-25 15:32 - 001185640 _____ (Realtek ) C:\Windows\system32\Drivers\rt640x64.sys
2023-04-25 15:26 - 2023-04-25 15:26 - 017388440 _____ C:\Windows\system32\RsEyeContactCorrection_Assets.dll
2023-04-25 15:26 - 2023-04-25 15:26 - 015824792 _____ C:\Windows\system32\RsDMFT_Assets.dll
2023-04-25 15:26 - 2023-04-25 15:26 - 013414320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RsDMFT64.dll
2023-04-25 15:23 - 2021-01-17 22:06 - 008447152 _____ (Malwarebytes) C:\Users\david\Desktop\AdwCleaner.exe
2023-04-25 15:22 - 2021-08-28 21:01 - 001053600 _____ (ESET) C:\Users\david\Desktop\esetuninstaller.exe
2023-04-25 15:22 - 2019-04-13 10:13 - 001663040 _____ (Malwarebytes) C:\Users\david\Desktop\JRT.exe
2023-04-25 15:14 - 2023-04-25 15:15 - 000000000 ____D C:\Users\david\Desktop\FILMY
2023-04-25 14:59 - 2023-04-25 14:59 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2023-04-25 14:26 - 2023-04-25 14:26 - 000000000 ___HD C:\$WinREAgent
2023-04-23 20:01 - 2023-04-25 14:58 - 000008192 ___SH C:\DumpStack.log.tmp
2023-04-23 20:01 - 2023-04-23 20:02 - 000911876 _____ C:\Windows\Minidump\042323-50031-01.dmp
2023-04-23 14:07 - 2023-04-23 15:42 - 1748916153 _____ C:\Users\david\Downloads\Nejdrsnější věznice světa_S05E03_Grónsko_ Ledové vězení.mkv
2023-04-23 12:10 - 2023-04-23 12:47 - 672190999 _____ C:\Users\david\Downloads\Nejdrsnější věznice světa S04E02 Německo Vězeňská terapie.mkv
2023-04-20 17:08 - 2023-04-23 20:01 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-04-20 16:52 - 2023-04-20 16:52 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3476297074-517369176-1764710931-1001
2023-04-20 16:52 - 2023-04-20 16:52 - 000002383 _____ C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-03-29 18:30 - 2023-03-29 18:30 - 000002048 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star Stable Online.lnk
2023-03-29 18:30 - 2023-03-29 18:30 - 000002036 _____ C:\Users\Public\Desktop\Star Stable Online.lnk
2023-03-29 18:29 - 2023-03-29 19:45 - 000000000 ____D C:\Program Files\Star Stable Online
2023-03-29 18:21 - 2023-04-23 20:01 - 727716806 _____ C:\Windows\MEMORY.DMP
2023-03-29 18:21 - 2023-03-29 18:55 - 001810612 _____ C:\Windows\Minidump\032923-66281-01.dmp
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-04-25 15:37 - 2022-01-21 21:18 - 000000000 ____D C:\Program Files\trend micro
2023-04-25 15:36 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-25 15:35 - 2021-10-25 22:05 - 000000000 ____D C:\ProgramData\IObit
2023-04-25 15:34 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2023-04-25 15:24 - 2022-02-15 21:23 - 000000000 ____D C:\ProgramData\ProductData
2023-04-25 15:18 - 2022-02-15 21:33 - 000002284 _____ C:\Users\david\Desktop\Loader-IDB.lnk
2023-04-25 15:06 - 2021-09-28 16:15 - 001605602 _____ C:\Windows\system32\PerfStringBackup.INI
2023-04-25 15:06 - 2019-12-07 16:41 - 000683426 _____ C:\Windows\system32\perfh005.dat
2023-04-25 15:06 - 2019-12-07 16:41 - 000137206 _____ C:\Windows\system32\perfc005.dat
2023-04-25 15:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-04-25 15:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2023-04-25 15:02 - 2023-01-26 19:41 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-04-25 15:02 - 2021-09-28 16:02 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-04-25 14:59 - 2021-09-28 16:27 - 000000000 __SHD C:\Users\david\IntelGraphicsProfiles
2023-04-25 14:58 - 2021-09-28 16:00 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-04-25 14:57 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2023-04-25 14:55 - 2021-09-28 16:00 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-04-25 14:54 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2023-04-25 14:19 - 2021-12-30 17:17 - 000000000 ____D C:\Program Files (x86)\EaseUS
2023-04-23 20:07 - 2021-09-28 15:59 - 000441584 _____ C:\Windows\system32\FNTCACHE.DAT
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\DDFs
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2023-04-23 20:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2023-04-23 20:01 - 2021-11-21 18:57 - 000000000 ____D C:\Windows\Minidump
2023-04-23 20:01 - 2021-09-28 16:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-04-23 19:50 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-04-23 12:14 - 2021-10-05 21:23 - 000000000 ____D C:\Program Files\Microsoft Office
2023-04-23 12:00 - 2022-02-13 18:21 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-04-21 21:37 - 2021-09-28 16:03 - 003015680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-04-21 19:17 - 2021-09-28 16:35 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-04-21 18:05 - 2021-09-28 16:44 - 000000000 ____D C:\Users\david\AppData\Roaming\Kodi
2023-04-20 20:34 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2023-04-20 20:34 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\setup
2023-04-20 20:31 - 2021-09-28 16:35 - 000000000 ____D C:\Users\david\AppData\LocalLow\Mozilla
2023-04-20 20:00 - 2021-09-28 17:57 - 000000000 ____D C:\Windows\system32\MRT
2023-04-20 19:49 - 2021-09-28 17:57 - 156112424 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-04-20 19:42 - 2021-10-05 23:53 - 000000000 ____D C:\Users\david\AppData\Roaming\Microsoft\Teams
2023-04-20 19:41 - 2022-05-16 20:36 - 000000000 ____D C:\Splines
2023-04-20 19:41 - 2022-05-16 20:35 - 000000000 ____D C:\Sceneryobjects
2023-04-20 19:38 - 2021-12-23 18:25 - 000000000 ____D C:\Users\david\AppData\Local\Roblox
2023-04-20 17:09 - 2021-10-18 20:06 - 000000000 ____D C:\Users\david\AppData\Roaming\Microsoft\Word
2023-04-20 16:59 - 2021-09-28 16:00 - 000000000 ____D C:\Windows\system32\Drivers\wd
2023-04-20 16:52 - 2021-12-23 18:19 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3476297074-517369176-1764710931-1001
2023-04-07 23:32 - 2021-09-28 16:23 - 000000000 ____D C:\Users\david\AppData\Local\Packages
2023-04-07 19:51 - 2021-09-28 16:02 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-04-07 19:51 - 2021-09-28 16:02 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-03-29 19:45 - 2022-03-18 17:58 - 000000000 ____D C:\Users\david\AppData\Roaming\Star Stable Online
2023-03-29 19:43 - 2021-10-20 17:21 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2023-03-29 18:35 - 2021-09-28 16:42 - 000000000 ____D C:\ProgramData\Package Cache
2023-03-29 18:29 - 2022-03-18 17:57 - 000000000 ____D C:\Program Files (x86)\Star Stable Online
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================