vbsedit script launcher
Napsal: 09 pro 2023 09:49
Dobry den, poprosim kontrolu logu, vybehuje mi taketo okno.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-12-2023
Ran by Feri (administrator) on DESKTOP-L0K8E8M (ASUSTeK COMPUTER INC. G751JT) (09-12-2023 09:42:58)
Running from C:\Users\Feri\Desktop\FRST64.exe
Loaded Profiles: Feri
Platform: Microsoft Windows 10 Home Version 22H2 19045.3693 (X64) Language: Slovenčina (Slovensko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <5>
(C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(C:\Program Files (x86)\EaseUS\ENS\ensserver.exe ->) (CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Program Files (x86)\EaseUS\ENS\AliyunWrapExe.exe
(C:\Program Files\AVAST Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(C:\Program Files\Elantech\ETDCtrl.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\84.0.11.0\crashpad_handler.exe
(C:\Program Files\NordVPN\nordvpn-service.exe ->) (nordvpn s.a. -> The OpenVPN Project) C:\Program Files\NordVPN\7.15.6.0\Resources\Binaries\64bit\openvpn-nordvpn.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(explorer.exe ->) () [File not signed] C:\Users\Feri\AppData\Local\SmartGenius\resources\KeyboardDriver\SmartHID.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(explorer.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(explorer.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordVPN\NordVPN.exe
(explorer.exe ->) (VLC Mobile Remote) [File not signed] C:\Program Files (x86)\VMR Connect\VMRHub.exe
(CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\TrayPopupE\TrayTipAgentE.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <13>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Program Files (x86)\EaseUS\ENS\ensserver.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe
(services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordVPN\nordvpn-service.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_62bfdd1a54e22985\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2307.4.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(svchost.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3348712 2015-07-22] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [366488 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [SmartGenius] => C:\Users\Feri\AppData\Local\SmartGenius\SmartGenius.exe [93723136 2019-10-26] (KYE SYSTEMS CORP. -> GitHub, Inc.)
HKLM\...\Run: [RunSmartForeFile] => C:\Users\Feri\AppData\Local\SmartGenius\resources\KeyboardDriver\SmartHIDStart.exe [524288 2019-10-16] () [File not signed]
HKLM\...\Run: [RunSmartHIDFile] => C:\Users\Feri\AppData\Local\SmartGenius\resources\KeyboardDriver\SmartHID.exe [815616 2019-10-16] () [File not signed]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [4096992 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5314096 2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706680 2020-09-17] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [EaseUS Cleanup] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\CleanUpUI.exe [1227456 2016-04-26] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU Yiwo Tech Development Co., Ltd.) [File not signed]
HKLM-x32\...\Run: [EaseUS EPM Tray Agent] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\TrayPopupE\TrayTipAgentE.exe [255072 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [VMR Connect] => C:\Program Files (x86)\VMR Connect\VMRHub.exe [221696 2023-02-03] (VLC Mobile Remote) [File not signed]
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [f.lux] => C:\Users\Feri\AppData\Local\FluxSoftware\Flux\flux.exe [1511824 2021-02-04] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365760 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44529568 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [Disig Web Signer] => C:\Program Files (x86)\Disig\Web Signer\WebSignerTray.exe [254080 2021-02-04] (Disig a.s. -> Disig a.s.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [NordVPN] => C:\Program Files\NordVPN\NordVPN.exe [263256 2023-09-25] (nordvpn s.a. -> nordvpn S.A.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [MicrosoftEdgeAutoLaunch_936114D59439CCB60ADDCBF126B10BD5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3788736 2023-12-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [DQCIKCDACO] => C:\ProgramData\certlm.exe [498784 2023-12-09] (Adersoft -> Adersoft) <==== ATTENTION
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\MountPoints2: {0a4bdaee-6174-11ea-9d83-0862665357d3} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\MountPoints2: {586e074b-fd09-11eb-9edc-0862665357d3} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [65488 2020-03-05] (Adobe Inc. -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\119.0.6045.200\Installer\chrmstp.exe [2023-12-01] (Google LLC -> Google LLC)
Startup: C:\Users\Feri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\certlm.exe [2023-12-09] (Adersoft -> Adersoft)
Startup: C:\Users\Feri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\s.m3u - odkaz.lnk [2020-03-28]
ShortcutTarget: s.m3u - odkaz.lnk -> C:\Users\Feri\Desktop\s.m3u () [File not signed]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {6DFC4A2F-A7BB-458C-BB68-568FD0F6BE97} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-09-20] (Adobe Inc. -> Adobe Inc.)
Task: {6ADB278B-FACB-4200-92A0-75C94B358BC8} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [4096992 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {F0B8E88C-C1D6-42B4-A250-EDE1CCFD1D33} - System32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [4434400 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {94F54B93-9836-4EB0-B005-65B6AC17881C} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008 2015-09-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {35E585C5-F06E-4414-90AE-23085F52808A} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008 2015-09-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {FF791470-753F-4F9B-9DE3-5B755815DAF0} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [5043608 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
Task: {D738D04C-3AE8-4DDF-A122-C379BF48FDD6} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2144664 2023-08-02] (Avast Software s.r.o. -> Avast Software)
Task: {829B4C91-4674-44FD-AAFD-EFD3FC7333D9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {87898A05-5AD1-4A06-AA57-C64F345B3F57} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "59501efd-8594-4d70-8bbf-e8783ed2a29e" --version "6.18.10838" --silent
Task: {1F747F7A-22BF-4A60-A20A-A8E36721D8F3} - System32\Tasks\CCleanerSkipUAC - Feri => C:\Program Files\CCleaner\CCleaner.exe [37546912 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {61BBB357-49CF-4897-8128-C12BC579B156} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-10-02] (Google Inc -> Google LLC)
Task: {6C387EDD-31C7-4A40-91C2-2B77DC97D2BA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-10-02] (Google Inc -> Google LLC)
Task: {2A74DC91-FFAB-445A-A27C-32E747AEEA77} - System32\Tasks\Meta\Messenger-WSP-Helper-S-1-5-21-1483115711-3560660982-2862343009-1001 => C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_2000.24.217.0_x64__8xx8rvfyw5nnt\app\MessengerHelper.exe [2265336 2023-12-01] (6E08453F-9BA7-4311-999C-D22FBA2FB1B8 -> Meta Platforms, Inc.)
Task: {D80985D2-2080-42C0-A2E7-9C716474950C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28175336 2023-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {332E6DA7-FD5A-4EE9-ADEB-348A57D9A91B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28175336 2023-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {18D90D19-8F31-4D47-AB54-38E59E8B01F2} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [306624 2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D57A5C5-11C6-41AB-977E-742F0E38F3E8} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [306624 2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {5F79CCE9-77F6-4E97-BA66-3F5F66781656} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [169144 2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {546C50F8-E200-422C-BDC0-87C67A55C10F} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Refresh Group Policy Cache => {07369A67-07A6-4608-ABEA-379491CB7C46} C:\Windows\System32\UpdatePolicy.dll [251904 2023-11-15] (Microsoft Windows -> Microsoft Corporation)
Task: {A094AA8C-FC9A-48DD-B5A4-96AA56796AF4} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [674208 2023-11-30] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {B4704E0F-D55F-455B-8B2C-E85CBDE6CB2F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [35232 2023-11-30] (Mozilla Corporation -> Mozilla Foundation)
Task: {FAD1BF8C-F33D-48B8-AC94-30E3D0255557} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {98F67499-2E30-4C4E-85B7-A15156882249} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation)
Task: {A83FFF7F-F7B2-429D-8BB1-777D0A1685AC} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3F74182A-2E62-4F83-A70E-CD0CF13E89E5} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FBE56435-4994-4064-A8CD-E3BBBC4C7390} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {154EB26B-D525-4ED6-BFEC-C0C94AEC0C66} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6B7D4CB7-2DB8-4098-8F4B-913F7DE4D984} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B4BAAD94-55C1-4CAD-B89E-8CD4EE9EC067} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {79541E09-41B0-4F48-9646-A0B99C5D2767} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {937A4CB9-7D93-4BB8-A149-B46A38F54228} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1404656 2015-08-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {88E22AAA-0389-406C-871F-9406755106E4} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1404656 2015-08-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {69342EFD-5087-4034-BC42-406FB5C73AE9} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8520448 2015-08-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {E306D228-BE81-4399-8C68-8140E4C78D22} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [133905984 2023-03-10] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
Task: {A761E7ED-2151-43AB-92FA-616BDA6427A1} - System32\Tasks\Skype => C:\ProgramData\certlm.exe [498784 2023-12-09] (Adersoft -> Adersoft) <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 103.86.96.100 103.86.99.100
Tcpip\..\Interfaces\{6f55f6e8-747d-428b-abce-26cdf3d59c4c}: [DhcpNameServer] 103.86.96.100 103.86.99.100
Tcpip\..\Interfaces\{828f0c3a-62ae-4d8f-be48-e78a0a7c3f20}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Feri\AppData\Local\Microsoft\Edge\User Data\Default [2023-12-09]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\Feri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-07]
Edge Extension: (Edge relevant text changes) - C:\Users\Feri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-10-07]
FireFox:
========
FF DefaultProfile: dnbb8nse.default
FF ProfilePath: C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\dnbb8nse.default [2019-09-21]
FF ProfilePath: C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release [2023-12-09]
FF Homepage: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> moz-extension://cb123bd1-5cb6-422c-9548-a17752b9e8ba/dial.html
FF HomepageOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Enabled: admin@fastaddons.com_GroupSpeedDial
FF NewTabOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Enabled: admin@fastaddons.com_GroupSpeedDial
FF NewTabOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Disabled: nordvpnproxy@nordvpn.com
FF NewTabOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Enabled: uBlock0@raymondhill.net
FF Extension: (Group Speed Dial) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\admin@fastaddons.com_GroupSpeedDial.xpi [2023-12-04]
FF Extension: (NordVPN - A VPN Proxy Extension for Firefox) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\nordvpnproxy@nordvpn.com.xpi [2023-11-30]
FF Extension: (Správca preberania (S3)) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\s3download@statusbar.xpi [2019-09-21]
FF Extension: (uBlock Origin) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\uBlock0@raymondhill.net.xpi [2023-11-28]
FF Extension: (Skip silence) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\{89595993-7775-4bd4-af57-44e57302d5ce}.xpi [2023-06-27]
FF Extension: (Video DownloadHelper) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2023-08-27]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-06-21]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2020-03-05]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Feri\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.271.2 -> C:\Program Files (x86)\Java\jre1.8.0_271\bin\dtplugin\npDeployJava1.dll [2020-10-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.271.2 -> C:\Program Files (x86)\Java\jre1.8.0_271\bin\plugin2\npjp2.dll [2020-10-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems)
Chrome:
=======
CHR Profile: C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default [2023-10-07]
CHR Extension: (Adobe Acrobat: nástroje na upravovanie, prevádzanie a podpisovanie súborov PDF) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2023-10-07]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-07]
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-10-07]
CHR Extension: (Spúšťač aplikácie pre Disk (od Googlu)) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-11-24]
CHR HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-09-20] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [4555744 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [9003928 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [735640 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [1140120 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-06-03] (Avast Software s.r.o. -> AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13233744 2023-11-14] (Microsoft Corporation -> Microsoft Corporation)
R2 CMigrationService; C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe [761408 2023-03-10] (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4507328 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 EaseUS UPDATE SERVICE; C:\Program Files (x86)\EaseUS\ENS\ensserver.exe [26512 2022-11-16] (CHENGDU YIWO Tech Development Co., Ltd. -> )
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2023-08-02] (Epic Games Inc. -> Epic Games, Inc.)
R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2022-11-21] (nordvpn s.a. -> nordvpn S.A.)
R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [263256 2023-09-25] (nordvpn s.a. -> nordvpn S.A.)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1271280 2023-10-31] (Rockstar Games, Inc. -> Rockstar Games)
R2 SamsungMagicianSVC; C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe [381504 2023-03-10] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_62bfdd1a54e22985\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_62bfdd1a54e22985\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [31528 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [240688 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [393904 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [297984 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [96072 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [26616 2023-12-03] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [39752 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [276856 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [105352 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [80528 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [952856 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [710144 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [213296 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [319672 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [18016 2016-01-20] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2016-01-20] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R3 gFilterMouUsb; C:\WINDOWS\System32\drivers\gFilterMouUsb.sys [30576 2019-10-16] (KYE SYSTEMS CORP. -> KYE Systems Corp.)
R3 gKbdfltr; C:\WINDOWS\System32\drivers\gKbdfltr.sys [29576 2019-10-16] (KYE SYSTEMS CORP. -> )
R1 googledrivefs31357; C:\WINDOWS\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys [384712 2023-10-30] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. -> ASUS)
R3 ioFakDrv; C:\WINDOWS\System32\drivers\ioFakDrv.sys [35928 2019-10-16] (KYE Systems Corp -> KYE System Corp.)
R3 ioFakMap; C:\WINDOWS\System32\drivers\ioFakMap.sys [24664 2019-10-16] (KYE Systems Corp -> KYE System Corp.)
R2 NDivert; C:\Program Files\NordVPN\7.15.6.0\Drivers\NDivert.sys [131472 2023-05-24] (nordvpn s.a. -> Nordvpn S.A.)
R1 nordlwf; C:\WINDOWS\system32\DRIVERS\nordlwf.sys [44928 2022-02-22] (nordvpn s.a. -> TEFINCOM S.A.)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [49744 2022-06-29] (nordvpn s.a. -> The OpenVPN Project)
R3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 uvhid; C:\WINDOWS\System32\drivers\uvhid.sys [28128 2019-08-04] (Unified Intents AB -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [29592 2022-09-30] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2023-03-19] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
Error Reading file: "C:\Users\Public\Microsoft Edge.exe"
Error Reading file: "C:\ProgramData\start_ergo.bat"
Error Reading file: "C:\ProgramData\readme_zh.md"
Error Reading file: "C:\ProgramData\readme.md"
Error Reading file: "C:\ProgramData\nbminer.exe"
Error Reading file: "C:\ProgramData\info.exe"
2023-12-09 09:42 - 2023-12-09 09:43 - 000039008 _____ C:\Users\Feri\Desktop\FRST.txt
2023-12-09 09:41 - 2023-12-09 09:41 - 002384896 _____ (Farbar) C:\Users\Feri\Desktop\FRST64.exe
2023-12-09 09:35 - 2023-12-09 09:35 - 008791352 _____ (Malwarebytes) C:\Users\Feri\Downloads\AdwCleaner.exe
2023-12-09 08:45 - 2023-12-09 09:35 - 000000000 ____D C:\Users\Feri\Desktop\videaniko
2023-12-09 08:41 - 2023-12-09 08:41 - 000001412 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2023-12-09 08:41 - 2023-12-09 08:41 - 000001379 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2023-12-09 08:41 - 2023-12-09 08:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2023-12-09 08:40 - 2023-12-09 09:35 - 000000000 ____D C:\Users\Feri\AppData\Roaming\DVDVideoSoft
2023-12-09 08:40 - 2023-12-09 08:41 - 000000000 ____D C:\Program Files (x86)\FreeCodecPack
2023-12-09 08:40 - 2023-12-09 08:41 - 000000000 ____D C:\Program Files (x86)\DVDVideoSoft
2023-12-09 08:36 - 2023-12-09 08:36 - 000498784 _____ (Adersoft) C:\ProgramData\certlm.exe
2023-12-09 08:36 - 2023-12-09 08:36 - 000003520 _____ C:\WINDOWS\system32\Tasks\Skype
2023-12-09 08:36 - 2021-08-23 01:34 - 000000122 _____ C:\ProgramData\S.bat
2023-12-09 08:36 - 2021-08-20 13:37 - 000000078 _____ C:\ProgramData\nbminer.exe.sha256
2023-12-09 08:36 - 2021-06-11 15:12 - 000000120 _____ C:\ProgramData\start_etc.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000142 _____ C:\ProgramData\start_beam.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000116 _____ C:\ProgramData\start_eth.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000115 _____ C:\ProgramData\start_conflux.bat
2023-12-09 08:36 - 2020-05-13 03:56 - 000000106 _____ C:\ProgramData\start_rvn.bat
2023-12-09 08:36 - 2020-04-20 07:33 - 000000077 _____ C:\ProgramData\driver_uninstall.bat
2023-12-09 08:36 - 2020-04-20 07:33 - 000000075 _____ C:\ProgramData\driver_install.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000204 _____ C:\ProgramData\start_sero.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000148 _____ C:\ProgramData\modify_tdr_delay.reg
2023-12-09 08:36 - 2019-11-07 12:51 - 000000127 _____ C:\ProgramData\start_ae.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000107 _____ C:\ProgramData\open_web_monitor.url
2023-12-09 08:36 - 2019-11-07 12:51 - 000000022 _____ C:\ProgramData\start_config.bat
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\Users\Feri\AppData\Roaming\Key
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test9
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test8
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test7
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test6
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test5
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test4
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test3
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test2
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test17
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test16
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test15
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test14
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test13
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test12
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test11
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test10
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test1
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player9
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player8
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player7
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player6
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player5
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player4
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player3
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player2
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player17
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player16
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player15
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player14
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player13
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player12
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player11
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player10
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player1
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player
2023-12-09 08:32 - 2023-12-09 08:32 - 000012183 _____ C:\Users\Feri\Downloads\[SkT]Free_YouTube_Download_Premium_4.3.90.317_(x86).torrent
2023-12-09 08:30 - 2023-12-09 08:30 - 000019003 _____ C:\Users\Feri\Downloads\[SkT]YouTube_By_Click_2.3.2_[Full].torrent
2023-12-06 17:11 - 2023-12-06 17:11 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2023-12-03 09:28 - 2023-12-03 09:28 - 000313240 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2023-11-30 16:20 - 2023-12-09 09:37 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-11-22 17:27 - 2023-11-22 17:27 - 000015177 _____ C:\Users\Feri\Downloads\[SkT][Jackerman]_Mother's_Warmth_Chapter_2_(ENG).torrent
2023-11-18 15:42 - 2023-11-18 15:42 - 000020139 _____ C:\Users\Feri\Downloads\[SkT]ONEMANSHOW The Movie (CZ)(2023)(1080p)(WEB-DL) = CSFD 50%.torrent
2023-11-15 06:08 - 2023-11-15 06:08 - 000000000 ___HD C:\$WinREAgent
2023-11-10 17:58 - 2023-11-10 17:58 - 000023017 _____ C:\Users\Feri\Downloads\[SkT]Zabiják _ The Killer (2023)(CZ_EN)[WebRip][1080p] = CSFD 76%.torrent
2023-11-10 17:53 - 2023-11-10 17:53 - 000244792 _____ C:\Users\Feri\Downloads\[SkT]Loki S02E06 (CZ_SK_EN)[WEB-DL][1080p] = CSFD 80%.torrent
2023-11-09 18:55 - 2023-11-09 18:55 - 000012629 _____ C:\Users\Feri\Downloads\[SkT] Oppenheimer (2023)(CZ)[1080p] = CSFD 86%.torrent
2023-11-09 06:35 - 2023-11-09 06:35 - 000112484 _____ C:\Users\Feri\Downloads\[SkT]Letuska _ The Flight Attendant - 2. serie (CZ_EN)[Webrip][1080p] = CSFD 67%.torrent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-12-09 09:44 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2023-12-09 09:43 - 2020-03-28 14:13 - 000000000 ____D C:\FRST
2023-12-09 09:40 - 2022-02-08 17:39 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-12-09 09:39 - 2021-12-15 18:25 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-12-09 09:39 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-12-09 09:39 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-12-09 09:39 - 2019-10-02 17:43 - 000000000 ____D C:\Program Files (x86)\Google
2023-12-09 09:38 - 2022-11-09 19:31 - 000003382 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2023-12-09 09:38 - 2022-11-09 19:31 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2023-12-09 09:38 - 2020-11-01 08:46 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2023-12-09 09:38 - 2020-05-21 19:27 - 000000000 ____D C:\Program Files\CCleaner
2023-12-09 09:38 - 2019-09-21 11:06 - 000000000 ____D C:\Users\Feri\AppData\Local\CrashDumps
2023-12-09 09:37 - 2022-09-30 22:08 - 000000000 ____D C:\Users\Feri\AppData\Local\NordVPN
2023-12-09 09:37 - 2020-11-01 08:46 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-12-09 09:37 - 2020-11-01 08:40 - 000008192 ___SH C:\DumpStack.log.tmp
2023-12-09 09:37 - 2020-04-12 16:50 - 000000000 ___RD C:\Users\Feri\Disk Google
2023-12-09 09:37 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-12-09 09:37 - 2019-09-21 11:01 - 000000000 ____D C:\ProgramData\AVAST Software
2023-12-09 09:37 - 2019-09-21 10:54 - 000000000 ____D C:\Users\Feri\AppData\Roaming\vlc
2023-12-09 09:37 - 2019-09-21 10:35 - 000000000 ____D C:\ProgramData\NVIDIA
2023-12-09 09:37 - 2019-09-21 10:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-12-09 09:36 - 2019-12-07 10:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2023-12-09 09:13 - 2021-06-07 05:21 - 000000000 ____D C:\Users\Feri\AppData\Local\Avast Software
2023-12-09 09:05 - 2019-09-21 10:25 - 000000000 ___SD C:\Users\Feri\AppData\Roaming\Microsoft\Credentials
2023-12-09 08:57 - 2019-09-21 11:05 - 000000000 ____D C:\Users\Feri\AppData\Roaming\uTorrent
2023-12-09 08:35 - 2022-06-25 08:58 - 000000000 ____D C:\Users\Feri\AppData\Roaming\ByClick
2023-12-09 08:29 - 2020-11-01 08:40 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-12-09 08:05 - 2020-05-10 14:10 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2023-12-09 08:04 - 2020-06-10 05:31 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-12-08 20:52 - 2022-09-30 22:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordSec
2023-12-08 20:52 - 2022-09-30 22:08 - 000000000 ____D C:\Program Files\NordVPN
2023-12-07 05:52 - 2020-11-01 08:46 - 000003752 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-12-07 05:52 - 2020-11-01 08:46 - 000003628 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-12-06 17:13 - 2020-02-24 19:53 - 000000000 ____D C:\Program Files\Microsoft Office
2023-12-06 17:13 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2023-12-05 19:05 - 2023-08-02 15:40 - 000003530 _____ C:\WINDOWS\system32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0
2023-12-05 19:05 - 2020-11-01 08:46 - 000003506 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2023-12-04 05:56 - 2021-09-03 18:34 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-12-04 05:56 - 2021-09-03 18:34 - 000002008 _____ C:\Users\Default\Desktop\Google Slides.lnk
2023-12-04 05:56 - 2021-09-03 18:34 - 000002008 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2023-12-04 05:56 - 2021-09-03 18:34 - 000001996 _____ C:\Users\Default\Desktop\Google Docs.lnk
2023-12-03 09:28 - 2022-10-12 14:55 - 000026616 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
2023-12-03 09:28 - 2020-11-01 08:46 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2023-12-03 09:28 - 2020-10-23 17:06 - 000276856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2023-12-03 09:28 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-12-03 09:28 - 2019-09-21 11:02 - 000952856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000710144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000393904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000319672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000297984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000240688 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000105352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000096072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000080528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000039752 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000031528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2023-12-02 09:08 - 2019-09-21 12:20 - 000000000 ____D C:\Users\Feri\AppData\Local\D3DSCache
2023-12-02 08:20 - 2020-03-14 13:47 - 000000000 ____D C:\Users\Feri\AppData\Roaming\Microsoft\Excel
2023-12-01 05:58 - 2019-10-02 17:43 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-11-30 16:51 - 2019-09-21 10:32 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-11-15 06:32 - 2020-11-01 08:50 - 000904218 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-11-15 06:32 - 2020-02-27 17:25 - 000065100 _____ C:\WINDOWS\system32\perfh01B.dat
2023-11-15 06:32 - 2020-02-27 17:25 - 000016828 _____ C:\WINDOWS\system32\perfc01B.dat
2023-11-15 06:28 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-11-15 06:25 - 2020-11-01 08:40 - 000310528 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-11-15 06:23 - 2019-12-07 15:39 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2023-11-15 06:23 - 2019-12-07 15:39 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Com
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\IME
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2023-11-15 06:23 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2023-11-15 06:21 - 2019-12-07 15:39 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2023-11-15 06:21 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2023-11-15 06:21 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2023-11-15 06:21 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-11-15 06:14 - 2020-11-01 08:43 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-11-15 06:07 - 2019-09-21 12:46 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-11-15 06:04 - 2019-09-21 12:46 - 182871392 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-11-10 17:42 - 2020-02-24 19:57 - 000000000 ____D C:\Users\Feri\AppData\Roaming\Microsoft\Word
2023-11-10 06:05 - 2020-08-21 14:41 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
==================== Files in the root of some directories ========
2020-08-12 17:58 - 2020-08-12 17:58 - 000000000 ____D () C:\ProgramData\BatteryOptimizer.exe
2023-12-09 08:36 - 2023-12-09 08:36 - 000498784 _____ (Adersoft) C:\ProgramData\certlm.exe
2023-12-09 08:36 - 2020-04-20 07:33 - 000000075 _____ () C:\ProgramData\driver_install.bat
2023-12-09 08:36 - 2020-04-20 07:33 - 000000077 _____ () C:\ProgramData\driver_uninstall.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000148 _____ () C:\ProgramData\modify_tdr_delay.reg
2023-12-09 08:36 - 2021-08-23 01:34 - 000000122 _____ () C:\ProgramData\S.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000127 _____ () C:\ProgramData\start_ae.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000142 _____ () C:\ProgramData\start_beam.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000022 _____ () C:\ProgramData\start_config.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000115 _____ () C:\ProgramData\start_conflux.bat
2023-12-09 08:36 - 2021-06-11 15:12 - 000000120 _____ () C:\ProgramData\start_etc.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000116 _____ () C:\ProgramData\start_eth.bat
2023-12-09 08:36 - 2020-05-13 03:56 - 000000106 _____ () C:\ProgramData\start_rvn.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000204 _____ () C:\ProgramData\start_sero.bat
2020-04-10 07:36 - 2002-08-29 18:33 - 000319488 ____R () C:\Users\Feri\AppData\Roaming\MafiaSetup.exe
2020-05-10 20:02 - 2020-05-10 20:02 - 000000000 _____ () C:\Users\Feri\AppData\Local\oobelibMkey.log
2019-12-16 20:55 - 2022-12-02 06:28 - 000007603 _____ () C:\Users\Feri\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-12-2023
Ran by Feri (administrator) on DESKTOP-L0K8E8M (ASUSTeK COMPUTER INC. G751JT) (09-12-2023 09:42:58)
Running from C:\Users\Feri\Desktop\FRST64.exe
Loaded Profiles: Feri
Platform: Microsoft Windows 10 Home Version 22H2 19045.3693 (X64) Language: Slovenčina (Slovensko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <5>
(C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(C:\Program Files (x86)\EaseUS\ENS\ensserver.exe ->) (CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Program Files (x86)\EaseUS\ENS\AliyunWrapExe.exe
(C:\Program Files\AVAST Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(C:\Program Files\Elantech\ETDCtrl.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\84.0.11.0\crashpad_handler.exe
(C:\Program Files\NordVPN\nordvpn-service.exe ->) (nordvpn s.a. -> The OpenVPN Project) C:\Program Files\NordVPN\7.15.6.0\Resources\Binaries\64bit\openvpn-nordvpn.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(explorer.exe ->) () [File not signed] C:\Users\Feri\AppData\Local\SmartGenius\resources\KeyboardDriver\SmartHID.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(explorer.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(explorer.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordVPN\NordVPN.exe
(explorer.exe ->) (VLC Mobile Remote) [File not signed] C:\Program Files (x86)\VMR Connect\VMRHub.exe
(CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\TrayPopupE\TrayTipAgentE.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <13>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Program Files (x86)\EaseUS\ENS\ensserver.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe
(services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordVPN\nordvpn-service.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_62bfdd1a54e22985\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2307.4.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(svchost.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3348712 2015-07-22] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [366488 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [SmartGenius] => C:\Users\Feri\AppData\Local\SmartGenius\SmartGenius.exe [93723136 2019-10-26] (KYE SYSTEMS CORP. -> GitHub, Inc.)
HKLM\...\Run: [RunSmartForeFile] => C:\Users\Feri\AppData\Local\SmartGenius\resources\KeyboardDriver\SmartHIDStart.exe [524288 2019-10-16] () [File not signed]
HKLM\...\Run: [RunSmartHIDFile] => C:\Users\Feri\AppData\Local\SmartGenius\resources\KeyboardDriver\SmartHID.exe [815616 2019-10-16] () [File not signed]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [4096992 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5314096 2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706680 2020-09-17] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [EaseUS Cleanup] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\CleanUpUI.exe [1227456 2016-04-26] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU Yiwo Tech Development Co., Ltd.) [File not signed]
HKLM-x32\...\Run: [EaseUS EPM Tray Agent] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\TrayPopupE\TrayTipAgentE.exe [255072 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [VMR Connect] => C:\Program Files (x86)\VMR Connect\VMRHub.exe [221696 2023-02-03] (VLC Mobile Remote) [File not signed]
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [f.lux] => C:\Users\Feri\AppData\Local\FluxSoftware\Flux\flux.exe [1511824 2021-02-04] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365760 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44529568 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [Disig Web Signer] => C:\Program Files (x86)\Disig\Web Signer\WebSignerTray.exe [254080 2021-02-04] (Disig a.s. -> Disig a.s.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [NordVPN] => C:\Program Files\NordVPN\NordVPN.exe [263256 2023-09-25] (nordvpn s.a. -> nordvpn S.A.)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [MicrosoftEdgeAutoLaunch_936114D59439CCB60ADDCBF126B10BD5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3788736 2023-12-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Run: [DQCIKCDACO] => C:\ProgramData\certlm.exe [498784 2023-12-09] (Adersoft -> Adersoft) <==== ATTENTION
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\MountPoints2: {0a4bdaee-6174-11ea-9d83-0862665357d3} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\MountPoints2: {586e074b-fd09-11eb-9edc-0862665357d3} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\84.0.11.0\GoogleDriveFS.exe [58391840 2023-12-04] (Google LLC -> Google, Inc.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [65488 2020-03-05] (Adobe Inc. -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\119.0.6045.200\Installer\chrmstp.exe [2023-12-01] (Google LLC -> Google LLC)
Startup: C:\Users\Feri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\certlm.exe [2023-12-09] (Adersoft -> Adersoft)
Startup: C:\Users\Feri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\s.m3u - odkaz.lnk [2020-03-28]
ShortcutTarget: s.m3u - odkaz.lnk -> C:\Users\Feri\Desktop\s.m3u () [File not signed]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {6DFC4A2F-A7BB-458C-BB68-568FD0F6BE97} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-09-20] (Adobe Inc. -> Adobe Inc.)
Task: {6ADB278B-FACB-4200-92A0-75C94B358BC8} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [4096992 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {F0B8E88C-C1D6-42B4-A250-EDE1CCFD1D33} - System32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [4434400 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {94F54B93-9836-4EB0-B005-65B6AC17881C} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008 2015-09-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {35E585C5-F06E-4414-90AE-23085F52808A} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008 2015-09-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {FF791470-753F-4F9B-9DE3-5B755815DAF0} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [5043608 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
Task: {D738D04C-3AE8-4DDF-A122-C379BF48FDD6} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2144664 2023-08-02] (Avast Software s.r.o. -> Avast Software)
Task: {829B4C91-4674-44FD-AAFD-EFD3FC7333D9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {87898A05-5AD1-4A06-AA57-C64F345B3F57} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "59501efd-8594-4d70-8bbf-e8783ed2a29e" --version "6.18.10838" --silent
Task: {1F747F7A-22BF-4A60-A20A-A8E36721D8F3} - System32\Tasks\CCleanerSkipUAC - Feri => C:\Program Files\CCleaner\CCleaner.exe [37546912 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {61BBB357-49CF-4897-8128-C12BC579B156} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-10-02] (Google Inc -> Google LLC)
Task: {6C387EDD-31C7-4A40-91C2-2B77DC97D2BA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-10-02] (Google Inc -> Google LLC)
Task: {2A74DC91-FFAB-445A-A27C-32E747AEEA77} - System32\Tasks\Meta\Messenger-WSP-Helper-S-1-5-21-1483115711-3560660982-2862343009-1001 => C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_2000.24.217.0_x64__8xx8rvfyw5nnt\app\MessengerHelper.exe [2265336 2023-12-01] (6E08453F-9BA7-4311-999C-D22FBA2FB1B8 -> Meta Platforms, Inc.)
Task: {D80985D2-2080-42C0-A2E7-9C716474950C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28175336 2023-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {332E6DA7-FD5A-4EE9-ADEB-348A57D9A91B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28175336 2023-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {18D90D19-8F31-4D47-AB54-38E59E8B01F2} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [306624 2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D57A5C5-11C6-41AB-977E-742F0E38F3E8} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [306624 2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {5F79CCE9-77F6-4E97-BA66-3F5F66781656} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [169144 2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {546C50F8-E200-422C-BDC0-87C67A55C10F} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Refresh Group Policy Cache => {07369A67-07A6-4608-ABEA-379491CB7C46} C:\Windows\System32\UpdatePolicy.dll [251904 2023-11-15] (Microsoft Windows -> Microsoft Corporation)
Task: {A094AA8C-FC9A-48DD-B5A4-96AA56796AF4} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [674208 2023-11-30] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {B4704E0F-D55F-455B-8B2C-E85CBDE6CB2F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [35232 2023-11-30] (Mozilla Corporation -> Mozilla Foundation)
Task: {FAD1BF8C-F33D-48B8-AC94-30E3D0255557} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {98F67499-2E30-4C4E-85B7-A15156882249} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation)
Task: {A83FFF7F-F7B2-429D-8BB1-777D0A1685AC} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3F74182A-2E62-4F83-A70E-CD0CF13E89E5} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FBE56435-4994-4064-A8CD-E3BBBC4C7390} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {154EB26B-D525-4ED6-BFEC-C0C94AEC0C66} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6B7D4CB7-2DB8-4098-8F4B-913F7DE4D984} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B4BAAD94-55C1-4CAD-B89E-8CD4EE9EC067} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {79541E09-41B0-4F48-9646-A0B99C5D2767} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {937A4CB9-7D93-4BB8-A149-B46A38F54228} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1404656 2015-08-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {88E22AAA-0389-406C-871F-9406755106E4} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1404656 2015-08-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {69342EFD-5087-4034-BC42-406FB5C73AE9} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8520448 2015-08-06] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {E306D228-BE81-4399-8C68-8140E4C78D22} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [133905984 2023-03-10] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
Task: {A761E7ED-2151-43AB-92FA-616BDA6427A1} - System32\Tasks\Skype => C:\ProgramData\certlm.exe [498784 2023-12-09] (Adersoft -> Adersoft) <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 103.86.96.100 103.86.99.100
Tcpip\..\Interfaces\{6f55f6e8-747d-428b-abce-26cdf3d59c4c}: [DhcpNameServer] 103.86.96.100 103.86.99.100
Tcpip\..\Interfaces\{828f0c3a-62ae-4d8f-be48-e78a0a7c3f20}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Feri\AppData\Local\Microsoft\Edge\User Data\Default [2023-12-09]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\Feri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-07]
Edge Extension: (Edge relevant text changes) - C:\Users\Feri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-10-07]
FireFox:
========
FF DefaultProfile: dnbb8nse.default
FF ProfilePath: C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\dnbb8nse.default [2019-09-21]
FF ProfilePath: C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release [2023-12-09]
FF Homepage: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> moz-extension://cb123bd1-5cb6-422c-9548-a17752b9e8ba/dial.html
FF HomepageOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Enabled: admin@fastaddons.com_GroupSpeedDial
FF NewTabOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Enabled: admin@fastaddons.com_GroupSpeedDial
FF NewTabOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Disabled: nordvpnproxy@nordvpn.com
FF NewTabOverride: Mozilla\Firefox\Profiles\f7f9mbcn.default-release -> Enabled: uBlock0@raymondhill.net
FF Extension: (Group Speed Dial) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\admin@fastaddons.com_GroupSpeedDial.xpi [2023-12-04]
FF Extension: (NordVPN - A VPN Proxy Extension for Firefox) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\nordvpnproxy@nordvpn.com.xpi [2023-11-30]
FF Extension: (Správca preberania (S3)) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\s3download@statusbar.xpi [2019-09-21]
FF Extension: (uBlock Origin) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\uBlock0@raymondhill.net.xpi [2023-11-28]
FF Extension: (Skip silence) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\{89595993-7775-4bd4-af57-44e57302d5ce}.xpi [2023-06-27]
FF Extension: (Video DownloadHelper) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2023-08-27]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\f7f9mbcn.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-06-21]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2020-03-05]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Feri\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.271.2 -> C:\Program Files (x86)\Java\jre1.8.0_271\bin\dtplugin\npDeployJava1.dll [2020-10-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.271.2 -> C:\Program Files (x86)\Java\jre1.8.0_271\bin\plugin2\npjp2.dll [2020-10-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-12-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems)
Chrome:
=======
CHR Profile: C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default [2023-10-07]
CHR Extension: (Adobe Acrobat: nástroje na upravovanie, prevádzanie a podpisovanie súborov PDF) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2023-10-07]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-07]
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-10-07]
CHR Extension: (Spúšťač aplikácie pre Disk (od Googlu)) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Feri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-11-24]
CHR HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKU\S-1-5-21-1483115711-3560660982-2862343009-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-09-20] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [4555744 2023-11-07] (Adobe Inc. -> Adobe Systems, Incorporated)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [9003928 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [735640 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [1140120 2023-12-03] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-06-03] (Avast Software s.r.o. -> AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13233744 2023-11-14] (Microsoft Corporation -> Microsoft Corporation)
R2 CMigrationService; C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe [761408 2023-03-10] (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4507328 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 EaseUS UPDATE SERVICE; C:\Program Files (x86)\EaseUS\ENS\ensserver.exe [26512 2022-11-16] (CHENGDU YIWO Tech Development Co., Ltd. -> )
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2023-08-02] (Epic Games Inc. -> Epic Games, Inc.)
R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2022-11-21] (nordvpn s.a. -> nordvpn S.A.)
R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [263256 2023-09-25] (nordvpn s.a. -> nordvpn S.A.)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1271280 2023-10-31] (Rockstar Games, Inc. -> Rockstar Games)
R2 SamsungMagicianSVC; C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe [381504 2023-03-10] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_62bfdd1a54e22985\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_62bfdd1a54e22985\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [31528 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [240688 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [393904 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [297984 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [96072 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [26616 2023-12-03] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [39752 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [276856 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [105352 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [80528 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [952856 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [710144 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [213296 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [319672 2023-12-03] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-04-10] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [18016 2016-01-20] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2016-01-20] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R3 gFilterMouUsb; C:\WINDOWS\System32\drivers\gFilterMouUsb.sys [30576 2019-10-16] (KYE SYSTEMS CORP. -> KYE Systems Corp.)
R3 gKbdfltr; C:\WINDOWS\System32\drivers\gKbdfltr.sys [29576 2019-10-16] (KYE SYSTEMS CORP. -> )
R1 googledrivefs31357; C:\WINDOWS\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys [384712 2023-10-30] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. -> ASUS)
R3 ioFakDrv; C:\WINDOWS\System32\drivers\ioFakDrv.sys [35928 2019-10-16] (KYE Systems Corp -> KYE System Corp.)
R3 ioFakMap; C:\WINDOWS\System32\drivers\ioFakMap.sys [24664 2019-10-16] (KYE Systems Corp -> KYE System Corp.)
R2 NDivert; C:\Program Files\NordVPN\7.15.6.0\Drivers\NDivert.sys [131472 2023-05-24] (nordvpn s.a. -> Nordvpn S.A.)
R1 nordlwf; C:\WINDOWS\system32\DRIVERS\nordlwf.sys [44928 2022-02-22] (nordvpn s.a. -> TEFINCOM S.A.)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [49744 2022-06-29] (nordvpn s.a. -> The OpenVPN Project)
R3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2012-12-19] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 uvhid; C:\WINDOWS\System32\drivers\uvhid.sys [28128 2019-08-04] (Unified Intents AB -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [29592 2022-09-30] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2023-03-19] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
Error Reading file: "C:\Users\Public\Microsoft Edge.exe"
Error Reading file: "C:\ProgramData\start_ergo.bat"
Error Reading file: "C:\ProgramData\readme_zh.md"
Error Reading file: "C:\ProgramData\readme.md"
Error Reading file: "C:\ProgramData\nbminer.exe"
Error Reading file: "C:\ProgramData\info.exe"
2023-12-09 09:42 - 2023-12-09 09:43 - 000039008 _____ C:\Users\Feri\Desktop\FRST.txt
2023-12-09 09:41 - 2023-12-09 09:41 - 002384896 _____ (Farbar) C:\Users\Feri\Desktop\FRST64.exe
2023-12-09 09:35 - 2023-12-09 09:35 - 008791352 _____ (Malwarebytes) C:\Users\Feri\Downloads\AdwCleaner.exe
2023-12-09 08:45 - 2023-12-09 09:35 - 000000000 ____D C:\Users\Feri\Desktop\videaniko
2023-12-09 08:41 - 2023-12-09 08:41 - 000001412 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2023-12-09 08:41 - 2023-12-09 08:41 - 000001379 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2023-12-09 08:41 - 2023-12-09 08:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2023-12-09 08:40 - 2023-12-09 09:35 - 000000000 ____D C:\Users\Feri\AppData\Roaming\DVDVideoSoft
2023-12-09 08:40 - 2023-12-09 08:41 - 000000000 ____D C:\Program Files (x86)\FreeCodecPack
2023-12-09 08:40 - 2023-12-09 08:41 - 000000000 ____D C:\Program Files (x86)\DVDVideoSoft
2023-12-09 08:36 - 2023-12-09 08:36 - 000498784 _____ (Adersoft) C:\ProgramData\certlm.exe
2023-12-09 08:36 - 2023-12-09 08:36 - 000003520 _____ C:\WINDOWS\system32\Tasks\Skype
2023-12-09 08:36 - 2021-08-23 01:34 - 000000122 _____ C:\ProgramData\S.bat
2023-12-09 08:36 - 2021-08-20 13:37 - 000000078 _____ C:\ProgramData\nbminer.exe.sha256
2023-12-09 08:36 - 2021-06-11 15:12 - 000000120 _____ C:\ProgramData\start_etc.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000142 _____ C:\ProgramData\start_beam.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000116 _____ C:\ProgramData\start_eth.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000115 _____ C:\ProgramData\start_conflux.bat
2023-12-09 08:36 - 2020-05-13 03:56 - 000000106 _____ C:\ProgramData\start_rvn.bat
2023-12-09 08:36 - 2020-04-20 07:33 - 000000077 _____ C:\ProgramData\driver_uninstall.bat
2023-12-09 08:36 - 2020-04-20 07:33 - 000000075 _____ C:\ProgramData\driver_install.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000204 _____ C:\ProgramData\start_sero.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000148 _____ C:\ProgramData\modify_tdr_delay.reg
2023-12-09 08:36 - 2019-11-07 12:51 - 000000127 _____ C:\ProgramData\start_ae.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000107 _____ C:\ProgramData\open_web_monitor.url
2023-12-09 08:36 - 2019-11-07 12:51 - 000000022 _____ C:\ProgramData\start_config.bat
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\Users\Feri\AppData\Roaming\Key
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test9
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test8
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test7
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test6
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test5
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test4
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test3
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test2
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test17
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test16
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test15
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test14
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test13
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test12
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test11
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test10
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\Test1
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player9
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player8
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player7
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player6
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player5
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player4
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player3
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player2
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player17
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player16
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player15
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player14
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player13
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player12
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player11
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player10
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player1
2023-12-09 08:35 - 2023-12-09 08:35 - 000000000 ____D C:\ProgramData\player
2023-12-09 08:32 - 2023-12-09 08:32 - 000012183 _____ C:\Users\Feri\Downloads\[SkT]Free_YouTube_Download_Premium_4.3.90.317_(x86).torrent
2023-12-09 08:30 - 2023-12-09 08:30 - 000019003 _____ C:\Users\Feri\Downloads\[SkT]YouTube_By_Click_2.3.2_[Full].torrent
2023-12-06 17:11 - 2023-12-06 17:11 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2023-12-03 09:28 - 2023-12-03 09:28 - 000313240 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2023-11-30 16:20 - 2023-12-09 09:37 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-11-22 17:27 - 2023-11-22 17:27 - 000015177 _____ C:\Users\Feri\Downloads\[SkT][Jackerman]_Mother's_Warmth_Chapter_2_(ENG).torrent
2023-11-18 15:42 - 2023-11-18 15:42 - 000020139 _____ C:\Users\Feri\Downloads\[SkT]ONEMANSHOW The Movie (CZ)(2023)(1080p)(WEB-DL) = CSFD 50%.torrent
2023-11-15 06:08 - 2023-11-15 06:08 - 000000000 ___HD C:\$WinREAgent
2023-11-10 17:58 - 2023-11-10 17:58 - 000023017 _____ C:\Users\Feri\Downloads\[SkT]Zabiják _ The Killer (2023)(CZ_EN)[WebRip][1080p] = CSFD 76%.torrent
2023-11-10 17:53 - 2023-11-10 17:53 - 000244792 _____ C:\Users\Feri\Downloads\[SkT]Loki S02E06 (CZ_SK_EN)[WEB-DL][1080p] = CSFD 80%.torrent
2023-11-09 18:55 - 2023-11-09 18:55 - 000012629 _____ C:\Users\Feri\Downloads\[SkT] Oppenheimer (2023)(CZ)[1080p] = CSFD 86%.torrent
2023-11-09 06:35 - 2023-11-09 06:35 - 000112484 _____ C:\Users\Feri\Downloads\[SkT]Letuska _ The Flight Attendant - 2. serie (CZ_EN)[Webrip][1080p] = CSFD 67%.torrent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-12-09 09:44 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2023-12-09 09:43 - 2020-03-28 14:13 - 000000000 ____D C:\FRST
2023-12-09 09:40 - 2022-02-08 17:39 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-12-09 09:39 - 2021-12-15 18:25 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-12-09 09:39 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-12-09 09:39 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-12-09 09:39 - 2019-10-02 17:43 - 000000000 ____D C:\Program Files (x86)\Google
2023-12-09 09:38 - 2022-11-09 19:31 - 000003382 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2023-12-09 09:38 - 2022-11-09 19:31 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2023-12-09 09:38 - 2020-11-01 08:46 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2023-12-09 09:38 - 2020-05-21 19:27 - 000000000 ____D C:\Program Files\CCleaner
2023-12-09 09:38 - 2019-09-21 11:06 - 000000000 ____D C:\Users\Feri\AppData\Local\CrashDumps
2023-12-09 09:37 - 2022-09-30 22:08 - 000000000 ____D C:\Users\Feri\AppData\Local\NordVPN
2023-12-09 09:37 - 2020-11-01 08:46 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-12-09 09:37 - 2020-11-01 08:40 - 000008192 ___SH C:\DumpStack.log.tmp
2023-12-09 09:37 - 2020-04-12 16:50 - 000000000 ___RD C:\Users\Feri\Disk Google
2023-12-09 09:37 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-12-09 09:37 - 2019-09-21 11:01 - 000000000 ____D C:\ProgramData\AVAST Software
2023-12-09 09:37 - 2019-09-21 10:54 - 000000000 ____D C:\Users\Feri\AppData\Roaming\vlc
2023-12-09 09:37 - 2019-09-21 10:35 - 000000000 ____D C:\ProgramData\NVIDIA
2023-12-09 09:37 - 2019-09-21 10:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-12-09 09:36 - 2019-12-07 10:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2023-12-09 09:13 - 2021-06-07 05:21 - 000000000 ____D C:\Users\Feri\AppData\Local\Avast Software
2023-12-09 09:05 - 2019-09-21 10:25 - 000000000 ___SD C:\Users\Feri\AppData\Roaming\Microsoft\Credentials
2023-12-09 08:57 - 2019-09-21 11:05 - 000000000 ____D C:\Users\Feri\AppData\Roaming\uTorrent
2023-12-09 08:35 - 2022-06-25 08:58 - 000000000 ____D C:\Users\Feri\AppData\Roaming\ByClick
2023-12-09 08:29 - 2020-11-01 08:40 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-12-09 08:05 - 2020-05-10 14:10 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2023-12-09 08:04 - 2020-06-10 05:31 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-12-08 20:52 - 2022-09-30 22:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordSec
2023-12-08 20:52 - 2022-09-30 22:08 - 000000000 ____D C:\Program Files\NordVPN
2023-12-07 05:52 - 2020-11-01 08:46 - 000003752 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-12-07 05:52 - 2020-11-01 08:46 - 000003628 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-12-06 17:13 - 2020-02-24 19:53 - 000000000 ____D C:\Program Files\Microsoft Office
2023-12-06 17:13 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2023-12-05 19:05 - 2023-08-02 15:40 - 000003530 _____ C:\WINDOWS\system32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0
2023-12-05 19:05 - 2020-11-01 08:46 - 000003506 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2023-12-04 05:56 - 2021-09-03 18:34 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-12-04 05:56 - 2021-09-03 18:34 - 000002008 _____ C:\Users\Default\Desktop\Google Slides.lnk
2023-12-04 05:56 - 2021-09-03 18:34 - 000002008 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2023-12-04 05:56 - 2021-09-03 18:34 - 000001996 _____ C:\Users\Default\Desktop\Google Docs.lnk
2023-12-03 09:28 - 2022-10-12 14:55 - 000026616 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
2023-12-03 09:28 - 2020-11-01 08:46 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2023-12-03 09:28 - 2020-10-23 17:06 - 000276856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2023-12-03 09:28 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-12-03 09:28 - 2019-09-21 11:02 - 000952856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000710144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000393904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000319672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000297984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000240688 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000105352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000096072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000080528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000039752 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2023-12-03 09:28 - 2019-09-21 11:02 - 000031528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2023-12-02 09:08 - 2019-09-21 12:20 - 000000000 ____D C:\Users\Feri\AppData\Local\D3DSCache
2023-12-02 08:20 - 2020-03-14 13:47 - 000000000 ____D C:\Users\Feri\AppData\Roaming\Microsoft\Excel
2023-12-01 05:58 - 2019-10-02 17:43 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-11-30 16:51 - 2019-09-21 10:32 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-11-15 06:32 - 2020-11-01 08:50 - 000904218 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-11-15 06:32 - 2020-02-27 17:25 - 000065100 _____ C:\WINDOWS\system32\perfh01B.dat
2023-11-15 06:32 - 2020-02-27 17:25 - 000016828 _____ C:\WINDOWS\system32\perfc01B.dat
2023-11-15 06:28 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-11-15 06:25 - 2020-11-01 08:40 - 000310528 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-11-15 06:23 - 2019-12-07 15:39 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2023-11-15 06:23 - 2019-12-07 15:39 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Com
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\IME
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2023-11-15 06:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2023-11-15 06:23 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2023-11-15 06:21 - 2019-12-07 15:39 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2023-11-15 06:21 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2023-11-15 06:21 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2023-11-15 06:21 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-11-15 06:14 - 2020-11-01 08:43 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-11-15 06:07 - 2019-09-21 12:46 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-11-15 06:04 - 2019-09-21 12:46 - 182871392 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-11-10 17:42 - 2020-02-24 19:57 - 000000000 ____D C:\Users\Feri\AppData\Roaming\Microsoft\Word
2023-11-10 06:05 - 2020-08-21 14:41 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
==================== Files in the root of some directories ========
2020-08-12 17:58 - 2020-08-12 17:58 - 000000000 ____D () C:\ProgramData\BatteryOptimizer.exe
2023-12-09 08:36 - 2023-12-09 08:36 - 000498784 _____ (Adersoft) C:\ProgramData\certlm.exe
2023-12-09 08:36 - 2020-04-20 07:33 - 000000075 _____ () C:\ProgramData\driver_install.bat
2023-12-09 08:36 - 2020-04-20 07:33 - 000000077 _____ () C:\ProgramData\driver_uninstall.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000148 _____ () C:\ProgramData\modify_tdr_delay.reg
2023-12-09 08:36 - 2021-08-23 01:34 - 000000122 _____ () C:\ProgramData\S.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000127 _____ () C:\ProgramData\start_ae.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000142 _____ () C:\ProgramData\start_beam.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000022 _____ () C:\ProgramData\start_config.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000115 _____ () C:\ProgramData\start_conflux.bat
2023-12-09 08:36 - 2021-06-11 15:12 - 000000120 _____ () C:\ProgramData\start_etc.bat
2023-12-09 08:36 - 2020-11-26 16:16 - 000000116 _____ () C:\ProgramData\start_eth.bat
2023-12-09 08:36 - 2020-05-13 03:56 - 000000106 _____ () C:\ProgramData\start_rvn.bat
2023-12-09 08:36 - 2019-11-07 12:51 - 000000204 _____ () C:\ProgramData\start_sero.bat
2020-04-10 07:36 - 2002-08-29 18:33 - 000319488 ____R () C:\Users\Feri\AppData\Roaming\MafiaSetup.exe
2020-05-10 20:02 - 2020-05-10 20:02 - 000000000 _____ () C:\Users\Feri\AppData\Local\oobelibMkey.log
2019-12-16 20:55 - 2022-12-02 06:28 - 000007603 _____ () C:\Users\Feri\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================