Vyšší vytížení CPU
Napsal: 09 lis 2023 20:51
Dobrý den, mám postarší ntb. Zdá se mi pomalejší než obvykle. Processor se jeví více vytěžovaný, a pak se ntb o to hlučnější.
Prosím o kontrolu jestli je něco v nepořádku, nebo už je jen starý a nezvládá to.
Děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-11-2023 02
Ran by Roman (administrator) on ROMANNTB (LENOVO 42406AG) (09-11-2023 20:40:46)
Running from C:\Users\Roman\Desktop\FRST64.exe
Loaded Profiles: Roman
Platform: Microsoft Windows 10 Pro Version 22H2 19045.3570 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\Lenovo\HOTKEY\tphkload.exe ->) (LENOVO -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
(C:\Program Files\Lenovo\HOTKEY\tphkload.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(C:\Program Files\Lenovo\HOTKEY\tphkload.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ->) (Synaptics Incorporated -> Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(explorer.exe ->) (Hanvon Ugee Technology Co., Ltd. -> XPPEN TECHNOLOGY CO.) C:\Program Files\Pentablet\PenTablet.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(explorer.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(explorer.exe ->) (Thesycon Software Solutions GmbH & Co. KG -> ) C:\Program Files\Native Instruments\Komplete Audio Driver\W10_x64\NativeInstrumentsUsbAudioCpl.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Ericsson AB -> Ericsson AB) C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (LENOVO -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(services.exe ->) (Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(services.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CredentialEnrollmentManager.exe
(services.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Proton Technologies AG -> ) C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe
(services.exe ->) (Proton Technologies AG -> ) C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(svchost.exe ->) (Lenovo -> Lenovo) C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LenovoOptMouseUpdate] => C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2013-05-22] (Lenovo(Japan)Ltd. -> Lenovo Group Limited)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [193984 2023-09-26] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [PenTablet] => C:\Program Files\Pentablet\PenTablet.exe [1103480 2022-09-26] (Hanvon Ugee Technology Co., Ltd. -> XPPEN TECHNOLOGY CO.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-225735304-3798317993-2765611396-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [42727840 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-225735304-3798317993-2765611396-1001\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe -os-restarted --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\upd (the data entry has 80 more characters). [676768 2023-10-26] (Mozilla Corporation -> Mozilla Corporation)
AppInit_DLLs: C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinitx.dll => C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinitx.dll [209936 2020-12-08] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinit.dll => C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinit.dll [184656 2020-12-08] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Native Instruments Komplete Audio Control Panel Autostart.lnk [2021-02-14]
ShortcutTarget: Native Instruments Komplete Audio Control Panel Autostart.lnk -> C:\Program Files\Native Instruments\Komplete Audio Driver\W10_x64\NativeInstrumentsUsbAudioCpl.exe (Thesycon Software Solutions GmbH & Co. KG -> )
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy-Firefox: Restriction <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4992AE14-9D7C-4802-842C-7BD6098AFBFD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-09-20] (Adobe Inc. -> Adobe Inc.)
Task: {5868E12E-3CEB-4317-B7FA-EFC09FD60CF4} - System32\Tasks\AdobeAAMUpdater-1.0-ROMANNTB-Roman => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {72BAEE3E-9176-4EB0-B3D4-0BBB0A695014} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {B0BB5206-4A2F-4802-8460-8A4D1B683698} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "18f3e8f9-51c5-4020-a1af-51b26ae1a469" --version "6.17.10746" --silent
Task: {B7BDD226-E5E2-4981-A768-EA68EF0D3015} - System32\Tasks\CCleanerSkipUAC - Roman => C:\Program Files\CCleaner\CCleaner.exe [35664800 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {00160B95-5EC7-432C-A4C7-A20937CA7229} - System32\Tasks\Lenovo\Power Manager\Background monitor => C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe [129016 2022-12-04] (Lenovo -> Lenovo)
Task: {0243E96B-55C6-445A-A674-F5DEA2D5D795} - System32\Tasks\Lenovo\Power Manager\Uninstall task => C:\Windows\SysWOW64\PowerMgrInst.exe [65016 2022-12-04] (Lenovo -> )
Task: {A8539234-89F0-4621-805F-4B7848786C0A} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676768 2023-10-26] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {B17F6709-11F0-40D2-9EE2-6FEFF55AB294} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [723872 2023-10-26] (Mozilla Corporation -> Mozilla Foundation)
Task: {17EE55CC-3054-44AB-8791-23C5544483D4} - System32\Tasks\nWizard_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2104648 2020-12-08] (NVIDIA Corporation -> )
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 1.1.1.1 8.8.4.4
Tcpip\..\Interfaces\{1774d3b4-6a36-4a96-8960-08261cf52bae}: [DhcpNameServer] 1.1.1.1 8.8.4.4
Tcpip\..\Interfaces\{380a19ed-d466-4072-9807-8e5380484841}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\Roman\AppData\Local\Microsoft\Edge\User Data\Default [2023-10-30]
Edge Extension: (Edge relevant text changes) - C:\Users\Roman\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-07-04]
FireFox:
========
FF DefaultProfile: ub6lu8b3.default
FF ProfilePath: C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\ub6lu8b3.default [2021-02-03]
FF ProfilePath: C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release [2023-11-09]
FF Homepage: Mozilla\Firefox\Profiles\2enufo14.default-release -> www.advaita.cz
FF Session Restore: Mozilla\Firefox\Profiles\2enufo14.default-release -> is enabled.
FF Extension: (SaveFrom.net helper) - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release\Extensions\helper@savefrom.net.xpi [2023-10-30]
FF Extension: (YouTube NonStop) - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release\Extensions\{0d7cafdd-501c-49ca-8ebb-e3341caaa55e}.xpi [2023-11-02]
FF Extension: (No Name) - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-06-24]
FF Extension: (SaveFrom.net helper) - C:\Program Files\Mozilla Firefox\distribution\extensions\helper@savefrom.net.xpi [2021-02-05]
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-10-09] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2019-04-13] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2019-04-13] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @videolan.org/vlc,version=3.0.12 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2023-11-09]
Opera:
=======
OPR Profile: C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable [2023-10-30]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=o ... utEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-03-06]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2022-03-06]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-09-20] (Adobe Inc. -> Adobe Inc.)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [2528888 2023-09-26] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [3860080 2023-09-26] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [3860080 2023-09-26] (ESET, spol. s r.o. -> ESET)
S2 LPlatSvc; C:\Windows\System32\LPlatSvc.exe [892288 2019-12-11] (Lenovo -> Lenovo.)
R3 ProtonVPN Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe [119912 2022-02-03] (Proton Technologies AG -> )
R3 ProtonVPN Update Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe [65640 2022-02-03] (Proton Technologies AG -> )
S3 ProtonVPN WireGuard; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.WireGuardService.exe [50792 2022-02-03] (Proton Technologies AG -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402264 2023-10-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2021-02-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2021-02-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WMCoreService; C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe [648744 2011-08-12] (Ericsson AB -> Ericsson AB)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [208704 2023-08-02] (ESET, spol. s r.o. -> ESET)
R3 ecnssndis; C:\Windows\System32\Drivers\wwuss64.sys [26664 2011-06-13] (Ericsson AB -> Ericsson AB)
R3 ecnssndisfltr; C:\Windows\System32\Drivers\wwussf64.sys [30248 2011-06-13] (Ericsson AB -> Ericsson AB)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [118904 2023-08-02] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [16336 2022-08-24] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [249544 2023-08-02] (ESET, spol. s r.o. -> ESET)
S4 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [55424 2023-08-02] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [81712 2023-08-02] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [123040 2023-08-02] (ESET, spol. s r.o. -> ESET)
R3 hanvonugeemfilter; C:\Windows\System32\drivers\hanvonugeemfilter.sys [9728 2022-04-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 l36wgps; C:\Windows\system32\DRIVERS\l36wgps64.sys [101416 2011-07-01] (Ericsson AB -> Ericsson AB)
R3 Mbm3CBus; C:\Windows\System32\drivers\Mbm3CBus.sys [419400 2011-04-29] (MCCI Corporation -> MCCI Corporation)
R3 Mbm3DevMt; C:\Windows\system32\DRIVERS\Mbm3DevMt.sys [430664 2011-04-29] (MCCI Corporation -> MCCI Corporation)
R3 Mbm3mdfl; C:\Windows\system32\DRIVERS\Mbm3mdfl.sys [19528 2011-04-29] (MCCI Corporation -> MCCI Corporation)
R3 Mbm3Mdm; C:\Windows\system32\DRIVERS\Mbm3Mdm.sys [483400 2011-04-29] (MCCI Corporation -> MCCI Corporation)
S3 NativeInstrumentsUsbAudio; C:\Windows\System32\drivers\NativeInstrumentsUsbAudio.sys [400952 2020-12-16] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 NativeInstrumentsUsbAudioks; C:\Windows\System32\drivers\NativeInstrumentsUsbAudioks.sys [53816 2020-12-16] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 nika6m2dfu; C:\Windows\System32\drivers\nika6m2dfu.sys [39672 2019-03-25] (Native Instruments GmbH -> Native Instruments GmbH)
R0 PMDRVS; C:\Windows\System32\drivers\pmdrvs.sys [38160 2019-12-11] (Lenovo -> Lenovo.)
S3 ProtonVPNCallout; C:\Program Files (x86)\Proton Technologies\ProtonVPN\x64\Win10\ProtonVPN.CalloutDriver.sys [34176 2021-05-28] (Microsoft Windows Hardware Compatibility Publisher -> Proton Technologies AG)
R3 risdxc; C:\Windows\System32\drivers\risdxc64.sys [105472 2012-07-04] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R3 tapprotonvpn; C:\Windows\System32\drivers\tapprotonvpn.sys [49024 2021-05-28] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48536 2021-02-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [429296 2021-02-02] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2021-02-02] (Microsoft Windows -> Microsoft Corporation)
R3 wintun; C:\Windows\system32\DRIVERS\wintun.sys [29680 2022-03-07] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2022-03-07] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
R3 WwanUsbServ; C:\Windows\System32\drivers\WwanUsbMp64.sys [268840 2011-08-12] (Ericsson AB -> Ericsson AB)
R3 XPPenTablet; C:\Windows\System32\drivers\XPPenTablet.sys [10752 2022-04-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-11-09 20:40 - 2023-11-09 20:41 - 000020647 _____ C:\Users\Roman\Desktop\FRST.txt
2023-11-09 20:40 - 2023-11-09 20:41 - 000000000 ____D C:\FRST
2023-11-09 20:38 - 2023-11-09 20:37 - 002383872 _____ (Farbar) C:\Users\Roman\Desktop\FRST64.exe
2023-11-09 20:37 - 2023-11-09 20:37 - 002383872 _____ (Farbar) C:\Users\Roman\Downloads\FRST64.exe
2023-10-13 19:52 - 2023-10-13 19:52 - 000016059 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2023-10-13 19:41 - 2023-10-13 19:41 - 000000000 ___HD C:\$WinREAgent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-11-09 20:23 - 2021-02-09 00:56 - 000000000 ____D C:\Users\Roman\AppData\Local\Adobe
2023-11-09 20:23 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2023-11-09 20:22 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-11-09 20:20 - 2021-01-26 20:46 - 001605602 _____ C:\Windows\system32\PerfStringBackup.INI
2023-11-09 20:20 - 2019-12-07 15:43 - 000683504 _____ C:\Windows\system32\perfh005.dat
2023-11-09 20:20 - 2019-12-07 15:43 - 000137284 _____ C:\Windows\system32\perfc005.dat
2023-11-09 20:20 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2023-11-08 14:25 - 2021-01-26 21:11 - 000000000 ____D C:\ProgramData\NVIDIA
2023-11-08 14:25 - 2021-01-26 20:39 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-11-08 11:36 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-11-08 11:28 - 2021-02-03 22:47 - 000000000 ____D C:\Users\Roman\AppData\Roaming\vlc
2023-11-08 11:16 - 2021-01-26 21:50 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-11-03 15:24 - 2021-01-26 21:05 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-10-31 00:01 - 2022-02-11 20:05 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-10-30 19:27 - 2021-02-09 17:04 - 000000000 ____D C:\Users\Roman\AppData\Local\CrashDumps
2023-10-30 19:26 - 2021-02-02 19:52 - 000000000 ____D C:\Program Files\CCleaner
2023-10-30 18:42 - 2021-12-13 18:21 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-225735304-3798317993-2765611396-1001
2023-10-30 18:42 - 2021-01-26 20:46 - 000003364 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-225735304-3798317993-2765611396-1001
2023-10-30 18:42 - 2021-01-26 20:42 - 000002377 _____ C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-10-30 18:41 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2023-10-26 17:25 - 2021-02-03 16:52 - 000000965 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-10-26 17:25 - 2021-02-03 16:52 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-10-26 17:25 - 2021-02-03 16:52 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-10-26 17:06 - 2022-10-03 15:43 - 000003474 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2023-10-26 17:06 - 2022-10-03 15:43 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2023-10-26 17:06 - 2021-02-02 19:52 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2023-10-26 15:16 - 2021-01-26 20:43 - 000000000 ____D C:\Users\Roman\AppData\Local\Packages
2023-10-26 14:53 - 2021-01-26 21:50 - 000003638 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-10-26 14:53 - 2021-01-26 21:50 - 000003514 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-10-21 09:40 - 2021-02-09 01:00 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2023-10-21 09:39 - 2022-10-14 20:36 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2023-10-21 09:39 - 2022-10-14 20:36 - 000002021 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2023-10-14 20:42 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-10-14 20:38 - 2021-01-26 20:39 - 000611864 _____ C:\Windows\system32\FNTCACHE.DAT
2023-10-14 20:38 - 2021-01-26 20:39 - 000008192 ___SH C:\DumpStack.log.tmp
2023-10-14 20:38 - 2021-01-26 20:39 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-10-14 20:38 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ServiceState
2023-10-14 20:37 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2023-10-14 20:37 - 2019-12-07 10:03 - 000786432 _____ C:\Windows\system32\config\BBI
2023-10-14 20:36 - 2019-12-07 15:47 - 000000000 ___SD C:\Windows\system32\AppV
2023-10-14 20:36 - 2019-12-07 15:43 - 000000000 ____D C:\Windows\SysWOW64\cs
2023-10-14 20:36 - 2019-12-07 15:43 - 000000000 ____D C:\Windows\system32\cs
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\UNP
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\F12
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Com
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Sysprep
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\setup
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\migwiz
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lv-LV
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lt-LT
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\et-EE
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Com
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\AdvancedInstallers
2023-10-14 20:35 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2023-10-14 20:35 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-10-14 20:35 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\PrintDialog
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellComponents
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Provisioning
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\IME
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2023-10-14 20:35 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2023-10-13 20:02 - 2019-12-07 15:47 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2023-10-13 20:02 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2023-10-13 20:02 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2023-10-13 19:52 - 2021-01-26 20:43 - 003014144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-10-13 19:24 - 2021-01-26 21:12 - 000000000 ____D C:\Windows\system32\MRT
2023-10-13 19:20 - 2021-01-26 21:12 - 181553176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-10-13 19:19 - 2022-02-16 00:43 - 000000000 ____D C:\Program Files\RUXIM
==================== Files in the root of some directories ========
2021-06-15 15:36 - 2023-07-29 12:31 - 000000034 _____ () C:\Users\Roman\AppData\Roaming\AdobeWLCMCache.dat
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Prosím o kontrolu jestli je něco v nepořádku, nebo už je jen starý a nezvládá to.
Děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-11-2023 02
Ran by Roman (administrator) on ROMANNTB (LENOVO 42406AG) (09-11-2023 20:40:46)
Running from C:\Users\Roman\Desktop\FRST64.exe
Loaded Profiles: Roman
Platform: Microsoft Windows 10 Pro Version 22H2 19045.3570 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\Lenovo\HOTKEY\tphkload.exe ->) (LENOVO -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
(C:\Program Files\Lenovo\HOTKEY\tphkload.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(C:\Program Files\Lenovo\HOTKEY\tphkload.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ->) (Synaptics Incorporated -> Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(explorer.exe ->) (Hanvon Ugee Technology Co., Ltd. -> XPPEN TECHNOLOGY CO.) C:\Program Files\Pentablet\PenTablet.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(explorer.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(explorer.exe ->) (Thesycon Software Solutions GmbH & Co. KG -> ) C:\Program Files\Native Instruments\Komplete Audio Driver\W10_x64\NativeInstrumentsUsbAudioCpl.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Ericsson AB -> Ericsson AB) C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (LENOVO -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(services.exe ->) (Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(services.exe ->) (Lenovo(Japan)Ltd. -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CredentialEnrollmentManager.exe
(services.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Proton Technologies AG -> ) C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe
(services.exe ->) (Proton Technologies AG -> ) C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(svchost.exe ->) (Lenovo -> Lenovo) C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LenovoOptMouseUpdate] => C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2013-05-22] (Lenovo(Japan)Ltd. -> Lenovo Group Limited)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [193984 2023-09-26] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [PenTablet] => C:\Program Files\Pentablet\PenTablet.exe [1103480 2022-09-26] (Hanvon Ugee Technology Co., Ltd. -> XPPEN TECHNOLOGY CO.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-225735304-3798317993-2765611396-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [42727840 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-225735304-3798317993-2765611396-1001\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe -os-restarted --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\upd (the data entry has 80 more characters). [676768 2023-10-26] (Mozilla Corporation -> Mozilla Corporation)
AppInit_DLLs: C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinitx.dll => C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinitx.dll [209936 2020-12-08] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinit.dll => C:\Windows\system32\DriverStore\FileRepository\nvltwi.inf_amd64_02ae1c51f1fc4c9a\nvinit.dll [184656 2020-12-08] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Native Instruments Komplete Audio Control Panel Autostart.lnk [2021-02-14]
ShortcutTarget: Native Instruments Komplete Audio Control Panel Autostart.lnk -> C:\Program Files\Native Instruments\Komplete Audio Driver\W10_x64\NativeInstrumentsUsbAudioCpl.exe (Thesycon Software Solutions GmbH & Co. KG -> )
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy-Firefox: Restriction <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4992AE14-9D7C-4802-842C-7BD6098AFBFD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-09-20] (Adobe Inc. -> Adobe Inc.)
Task: {5868E12E-3CEB-4317-B7FA-EFC09FD60CF4} - System32\Tasks\AdobeAAMUpdater-1.0-ROMANNTB-Roman => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {72BAEE3E-9176-4EB0-B3D4-0BBB0A695014} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {B0BB5206-4A2F-4802-8460-8A4D1B683698} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "18f3e8f9-51c5-4020-a1af-51b26ae1a469" --version "6.17.10746" --silent
Task: {B7BDD226-E5E2-4981-A768-EA68EF0D3015} - System32\Tasks\CCleanerSkipUAC - Roman => C:\Program Files\CCleaner\CCleaner.exe [35664800 2023-10-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {00160B95-5EC7-432C-A4C7-A20937CA7229} - System32\Tasks\Lenovo\Power Manager\Background monitor => C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe [129016 2022-12-04] (Lenovo -> Lenovo)
Task: {0243E96B-55C6-445A-A674-F5DEA2D5D795} - System32\Tasks\Lenovo\Power Manager\Uninstall task => C:\Windows\SysWOW64\PowerMgrInst.exe [65016 2022-12-04] (Lenovo -> )
Task: {A8539234-89F0-4621-805F-4B7848786C0A} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676768 2023-10-26] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {B17F6709-11F0-40D2-9EE2-6FEFF55AB294} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [723872 2023-10-26] (Mozilla Corporation -> Mozilla Foundation)
Task: {17EE55CC-3054-44AB-8791-23C5544483D4} - System32\Tasks\nWizard_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2104648 2020-12-08] (NVIDIA Corporation -> )
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 1.1.1.1 8.8.4.4
Tcpip\..\Interfaces\{1774d3b4-6a36-4a96-8960-08261cf52bae}: [DhcpNameServer] 1.1.1.1 8.8.4.4
Tcpip\..\Interfaces\{380a19ed-d466-4072-9807-8e5380484841}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\Roman\AppData\Local\Microsoft\Edge\User Data\Default [2023-10-30]
Edge Extension: (Edge relevant text changes) - C:\Users\Roman\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-07-04]
FireFox:
========
FF DefaultProfile: ub6lu8b3.default
FF ProfilePath: C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\ub6lu8b3.default [2021-02-03]
FF ProfilePath: C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release [2023-11-09]
FF Homepage: Mozilla\Firefox\Profiles\2enufo14.default-release -> www.advaita.cz
FF Session Restore: Mozilla\Firefox\Profiles\2enufo14.default-release -> is enabled.
FF Extension: (SaveFrom.net helper) - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release\Extensions\helper@savefrom.net.xpi [2023-10-30]
FF Extension: (YouTube NonStop) - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release\Extensions\{0d7cafdd-501c-49ca-8ebb-e3341caaa55e}.xpi [2023-11-02]
FF Extension: (No Name) - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\2enufo14.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-06-24]
FF Extension: (SaveFrom.net helper) - C:\Program Files\Mozilla Firefox\distribution\extensions\helper@savefrom.net.xpi [2021-02-05]
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-10-09] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2019-04-13] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2019-04-13] (NVIDIA Corporation-PE-Prod-Sha1 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @videolan.org/vlc,version=3.0.12 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2023-11-09]
Opera:
=======
OPR Profile: C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable [2023-10-30]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=o ... utEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-03-06]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2022-03-06]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-09-20] (Adobe Inc. -> Adobe Inc.)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [2528888 2023-09-26] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [3860080 2023-09-26] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [3860080 2023-09-26] (ESET, spol. s r.o. -> ESET)
S2 LPlatSvc; C:\Windows\System32\LPlatSvc.exe [892288 2019-12-11] (Lenovo -> Lenovo.)
R3 ProtonVPN Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe [119912 2022-02-03] (Proton Technologies AG -> )
R3 ProtonVPN Update Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe [65640 2022-02-03] (Proton Technologies AG -> )
S3 ProtonVPN WireGuard; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.WireGuardService.exe [50792 2022-02-03] (Proton Technologies AG -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402264 2023-10-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2021-02-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2021-02-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WMCoreService; C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe [648744 2011-08-12] (Ericsson AB -> Ericsson AB)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [208704 2023-08-02] (ESET, spol. s r.o. -> ESET)
R3 ecnssndis; C:\Windows\System32\Drivers\wwuss64.sys [26664 2011-06-13] (Ericsson AB -> Ericsson AB)
R3 ecnssndisfltr; C:\Windows\System32\Drivers\wwussf64.sys [30248 2011-06-13] (Ericsson AB -> Ericsson AB)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [118904 2023-08-02] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [16336 2022-08-24] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [249544 2023-08-02] (ESET, spol. s r.o. -> ESET)
S4 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [55424 2023-08-02] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [81712 2023-08-02] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [123040 2023-08-02] (ESET, spol. s r.o. -> ESET)
R3 hanvonugeemfilter; C:\Windows\System32\drivers\hanvonugeemfilter.sys [9728 2022-04-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 l36wgps; C:\Windows\system32\DRIVERS\l36wgps64.sys [101416 2011-07-01] (Ericsson AB -> Ericsson AB)
R3 Mbm3CBus; C:\Windows\System32\drivers\Mbm3CBus.sys [419400 2011-04-29] (MCCI Corporation -> MCCI Corporation)
R3 Mbm3DevMt; C:\Windows\system32\DRIVERS\Mbm3DevMt.sys [430664 2011-04-29] (MCCI Corporation -> MCCI Corporation)
R3 Mbm3mdfl; C:\Windows\system32\DRIVERS\Mbm3mdfl.sys [19528 2011-04-29] (MCCI Corporation -> MCCI Corporation)
R3 Mbm3Mdm; C:\Windows\system32\DRIVERS\Mbm3Mdm.sys [483400 2011-04-29] (MCCI Corporation -> MCCI Corporation)
S3 NativeInstrumentsUsbAudio; C:\Windows\System32\drivers\NativeInstrumentsUsbAudio.sys [400952 2020-12-16] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 NativeInstrumentsUsbAudioks; C:\Windows\System32\drivers\NativeInstrumentsUsbAudioks.sys [53816 2020-12-16] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 nika6m2dfu; C:\Windows\System32\drivers\nika6m2dfu.sys [39672 2019-03-25] (Native Instruments GmbH -> Native Instruments GmbH)
R0 PMDRVS; C:\Windows\System32\drivers\pmdrvs.sys [38160 2019-12-11] (Lenovo -> Lenovo.)
S3 ProtonVPNCallout; C:\Program Files (x86)\Proton Technologies\ProtonVPN\x64\Win10\ProtonVPN.CalloutDriver.sys [34176 2021-05-28] (Microsoft Windows Hardware Compatibility Publisher -> Proton Technologies AG)
R3 risdxc; C:\Windows\System32\drivers\risdxc64.sys [105472 2012-07-04] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R3 tapprotonvpn; C:\Windows\System32\drivers\tapprotonvpn.sys [49024 2021-05-28] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48536 2021-02-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [429296 2021-02-02] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2021-02-02] (Microsoft Windows -> Microsoft Corporation)
R3 wintun; C:\Windows\system32\DRIVERS\wintun.sys [29680 2022-03-07] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2022-03-07] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
R3 WwanUsbServ; C:\Windows\System32\drivers\WwanUsbMp64.sys [268840 2011-08-12] (Ericsson AB -> Ericsson AB)
R3 XPPenTablet; C:\Windows\System32\drivers\XPPenTablet.sys [10752 2022-04-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-11-09 20:40 - 2023-11-09 20:41 - 000020647 _____ C:\Users\Roman\Desktop\FRST.txt
2023-11-09 20:40 - 2023-11-09 20:41 - 000000000 ____D C:\FRST
2023-11-09 20:38 - 2023-11-09 20:37 - 002383872 _____ (Farbar) C:\Users\Roman\Desktop\FRST64.exe
2023-11-09 20:37 - 2023-11-09 20:37 - 002383872 _____ (Farbar) C:\Users\Roman\Downloads\FRST64.exe
2023-10-13 19:52 - 2023-10-13 19:52 - 000016059 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2023-10-13 19:41 - 2023-10-13 19:41 - 000000000 ___HD C:\$WinREAgent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-11-09 20:23 - 2021-02-09 00:56 - 000000000 ____D C:\Users\Roman\AppData\Local\Adobe
2023-11-09 20:23 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2023-11-09 20:22 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-11-09 20:20 - 2021-01-26 20:46 - 001605602 _____ C:\Windows\system32\PerfStringBackup.INI
2023-11-09 20:20 - 2019-12-07 15:43 - 000683504 _____ C:\Windows\system32\perfh005.dat
2023-11-09 20:20 - 2019-12-07 15:43 - 000137284 _____ C:\Windows\system32\perfc005.dat
2023-11-09 20:20 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2023-11-08 14:25 - 2021-01-26 21:11 - 000000000 ____D C:\ProgramData\NVIDIA
2023-11-08 14:25 - 2021-01-26 20:39 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-11-08 11:36 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-11-08 11:28 - 2021-02-03 22:47 - 000000000 ____D C:\Users\Roman\AppData\Roaming\vlc
2023-11-08 11:16 - 2021-01-26 21:50 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-11-03 15:24 - 2021-01-26 21:05 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-10-31 00:01 - 2022-02-11 20:05 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-10-30 19:27 - 2021-02-09 17:04 - 000000000 ____D C:\Users\Roman\AppData\Local\CrashDumps
2023-10-30 19:26 - 2021-02-02 19:52 - 000000000 ____D C:\Program Files\CCleaner
2023-10-30 18:42 - 2021-12-13 18:21 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-225735304-3798317993-2765611396-1001
2023-10-30 18:42 - 2021-01-26 20:46 - 000003364 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-225735304-3798317993-2765611396-1001
2023-10-30 18:42 - 2021-01-26 20:42 - 000002377 _____ C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-10-30 18:41 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2023-10-26 17:25 - 2021-02-03 16:52 - 000000965 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-10-26 17:25 - 2021-02-03 16:52 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-10-26 17:25 - 2021-02-03 16:52 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-10-26 17:06 - 2022-10-03 15:43 - 000003474 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2023-10-26 17:06 - 2022-10-03 15:43 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2023-10-26 17:06 - 2021-02-02 19:52 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2023-10-26 15:16 - 2021-01-26 20:43 - 000000000 ____D C:\Users\Roman\AppData\Local\Packages
2023-10-26 14:53 - 2021-01-26 21:50 - 000003638 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-10-26 14:53 - 2021-01-26 21:50 - 000003514 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-10-21 09:40 - 2021-02-09 01:00 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2023-10-21 09:39 - 2022-10-14 20:36 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2023-10-21 09:39 - 2022-10-14 20:36 - 000002021 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2023-10-14 20:42 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-10-14 20:38 - 2021-01-26 20:39 - 000611864 _____ C:\Windows\system32\FNTCACHE.DAT
2023-10-14 20:38 - 2021-01-26 20:39 - 000008192 ___SH C:\DumpStack.log.tmp
2023-10-14 20:38 - 2021-01-26 20:39 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-10-14 20:38 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ServiceState
2023-10-14 20:37 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2023-10-14 20:37 - 2019-12-07 10:03 - 000786432 _____ C:\Windows\system32\config\BBI
2023-10-14 20:36 - 2019-12-07 15:47 - 000000000 ___SD C:\Windows\system32\AppV
2023-10-14 20:36 - 2019-12-07 15:43 - 000000000 ____D C:\Windows\SysWOW64\cs
2023-10-14 20:36 - 2019-12-07 15:43 - 000000000 ____D C:\Windows\system32\cs
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\UNP
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\F12
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Com
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Sysprep
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\setup
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\migwiz
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lv-LV
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lt-LT
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\et-EE
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Com
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2023-10-14 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\AdvancedInstallers
2023-10-14 20:35 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2023-10-14 20:35 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-10-14 20:35 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\PrintDialog
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellComponents
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Provisioning
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\IME
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2023-10-14 20:35 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2023-10-14 20:35 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2023-10-13 20:02 - 2019-12-07 15:47 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2023-10-13 20:02 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2023-10-13 20:02 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2023-10-13 19:52 - 2021-01-26 20:43 - 003014144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-10-13 19:24 - 2021-01-26 21:12 - 000000000 ____D C:\Windows\system32\MRT
2023-10-13 19:20 - 2021-01-26 21:12 - 181553176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-10-13 19:19 - 2022-02-16 00:43 - 000000000 ____D C:\Program Files\RUXIM
==================== Files in the root of some directories ========
2021-06-15 15:36 - 2023-07-29 12:31 - 000000034 _____ () C:\Users\Roman\AppData\Roaming\AdobeWLCMCache.dat
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================