preventívna kontrola na keylogger
Napsal: 28 pro 2023 13:45
Zdravím,
poprosím preventívku na keylogger, adwcleaner nenašiel nič
ďakujem
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-12-2023
Ran by igorv (administrator) on DESKTOP-AJTU3EA (TOSHIBA Satellite L650) (28-12-2023 13:35:14)
Running from C:\Users\igorv\Downloads\FRST64.exe
Loaded Profiles: igorv
Platform: Microsoft Windows 10 Home Version 22H2 19045.3803 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(atiesrxx.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe ->) (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\81.0.5.0\crashpad_handler.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe <2>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <10>
(services.exe ->) (Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDFunctionKeyCtlService.exe <2>
(services.exe ->) (Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\dynabookSystemService.exe
(services.exe ->) (Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\RMService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2307.4.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2310.8.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1004790077-1547760064-1104730356-1001\...\Run: [MicrosoftEdgeAutoLaunch_12DCDEA817FD98234F2AB1F8B100D4B7] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3854280 2023-12-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1004790077-1547760064-1104730356-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {72FC70C0-806D-4579-A3E1-3781E7B108F3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0EDA6F0C-943A-468D-9124-722835978AE1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1A21B449-8406-4B5F-BC0D-510BBB6ADADC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {62856FA8-0D8F-4E92-B951-99836F9DA033} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.31.248 1.1.1.1
Tcpip\..\Interfaces\{dc256726-0bb1-4482-b09a-11f3a97e50ba}: [DhcpNameServer] 192.168.31.248 1.1.1.1
Tcpip\..\Interfaces\{dc256726-0bb1-4482-b09a-11f3a97e50ba}: [DhcpDomain] local
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Default [2023-12-28]
Edge HomePage: Default -> hxxp://www.google.sk/
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-17]
Edge Extension: (Edge relevant text changes) - C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-13]
Edge Profile: C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Guest Profile [2023-12-20]
Chrome:
=======
CHR HKU\S-1-5-21-1004790077-1547760064-1104730356-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 DSDFunctionKeyCtlService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDFunctionKeyCtlService.exe [718168 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
S2 DSDTabletControlService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDTabSysSvc.exe [330136 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R2 DSDWirelessLEDCtlService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\RMService.exe [480144 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R2 dynabookSettingService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\dynabookSystemService.exe [24153096 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe [3174840 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe [133592 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 dhotkey; C:\Windows\System32\drivers\dhotkey.sys [52736 2023-03-22] (Dynabook Inc. -> Dynabook Inc.)
R1 dsrvctldrv; C:\Windows\System32\drivers\dsrvctldrv.sys [30232 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R0 DVALZ_O; C:\Windows\System32\drivers\DVALZ_O.SYS [47464 2022-07-17] (Dynabook Inc. -> Dynabook Inc.)
R1 googledrivefs31092; C:\Windows\System32\DRIVERS\googledrivefs31092.sys [384600 2023-09-24] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [55856 2023-12-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [594304 2023-12-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105856 2023-12-06] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-12-28 13:35 - 2023-12-28 13:36 - 000010464 _____ C:\Users\igorv\Downloads\FRST.txt
2023-12-28 13:35 - 2023-12-28 13:35 - 000000000 ____D C:\FRST
2023-12-28 13:34 - 2023-12-28 13:34 - 002387456 _____ (Farbar) C:\Users\igorv\Downloads\FRST64.exe
2023-12-21 12:22 - 2023-12-21 12:22 - 000000000 ____D C:\Users\igorv\AppData\Local\CrashDumps
2023-12-20 15:07 - 2023-12-20 15:08 - 000000000 ____D C:\Windows\InboxApps
2023-12-20 11:52 - 2023-12-20 11:52 - 000016707 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2023-12-20 11:42 - 2023-12-20 11:42 - 000000000 ___HD C:\$WinREAgent
2023-11-30 17:25 - 2023-11-30 17:25 - 000000000 ____D C:\Users\igorv\AppData\Roaming\WinRAR
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-12-28 13:18 - 2023-07-06 11:48 - 000000000 ___SD C:\Users\igorv\AppData\Roaming\Microsoft\Credentials
2023-12-28 13:14 - 2023-07-06 11:32 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-12-28 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-12-28 09:50 - 2023-07-06 11:40 - 000804470 _____ C:\Windows\system32\PerfStringBackup.INI
2023-12-28 09:50 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2023-12-28 09:46 - 2023-07-06 11:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-12-28 09:46 - 2023-07-06 11:32 - 000008192 ___SH C:\DumpStack.log.tmp
2023-12-28 09:45 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2023-12-27 16:07 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2023-12-23 14:33 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-12-23 11:16 - 2023-07-06 11:33 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-12-20 20:02 - 2023-08-17 10:22 - 000000000 ____D C:\Windows\Minidump
2023-12-20 15:09 - 2023-07-06 11:52 - 000000000 ____D C:\Users\igorv\AppData\Local\Packages
2023-12-20 15:09 - 2023-07-06 11:32 - 000259760 _____ C:\Windows\system32\FNTCACHE.DAT
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lv-LV
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lt-LT
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\et-EE
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Provisioning
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2023-12-20 15:08 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2023-12-20 15:07 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2023-12-20 15:06 - 2019-12-07 15:39 - 000023040 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2023-12-20 15:06 - 2019-12-07 15:39 - 000020827 _____ C:\Windows\system32\OEMDefaultAssociations.xml
2023-12-20 11:52 - 2023-07-06 11:35 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-12-16 20:58 - 2023-07-08 21:54 - 000000000 ____D C:\2
2023-12-13 17:30 - 2023-07-06 11:48 - 000000000 ____D C:\Users\igorv
2023-12-06 17:44 - 2023-07-06 11:33 - 000000000 ____D C:\Windows\system32\Drivers\wd
2023-12-03 13:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\NDF
2023-12-03 11:43 - 2023-07-08 21:54 - 000000000 ____D C:\1
2023-11-29 22:02 - 2023-08-01 15:27 - 000000000 ____D C:\Users\igorv\AppData\LocalLow\Temp
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
poprosím preventívku na keylogger, adwcleaner nenašiel nič
ďakujem
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-12-2023
Ran by igorv (administrator) on DESKTOP-AJTU3EA (TOSHIBA Satellite L650) (28-12-2023 13:35:14)
Running from C:\Users\igorv\Downloads\FRST64.exe
Loaded Profiles: igorv
Platform: Microsoft Windows 10 Home Version 22H2 19045.3803 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(atiesrxx.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe ->) (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\81.0.5.0\crashpad_handler.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe <2>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <10>
(services.exe ->) (Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDFunctionKeyCtlService.exe <2>
(services.exe ->) (Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\dynabookSystemService.exe
(services.exe ->) (Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\RMService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2307.4.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2310.8.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1004790077-1547760064-1104730356-1001\...\Run: [MicrosoftEdgeAutoLaunch_12DCDEA817FD98234F2AB1F8B100D4B7] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3854280 2023-12-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1004790077-1547760064-1104730356-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\81.0.5.0\GoogleDriveFS.exe [55259936 2023-09-24] (Google LLC -> Google, Inc.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {72FC70C0-806D-4579-A3E1-3781E7B108F3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0EDA6F0C-943A-468D-9124-722835978AE1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1A21B449-8406-4B5F-BC0D-510BBB6ADADC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {62856FA8-0D8F-4E92-B951-99836F9DA033} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.31.248 1.1.1.1
Tcpip\..\Interfaces\{dc256726-0bb1-4482-b09a-11f3a97e50ba}: [DhcpNameServer] 192.168.31.248 1.1.1.1
Tcpip\..\Interfaces\{dc256726-0bb1-4482-b09a-11f3a97e50ba}: [DhcpDomain] local
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Default [2023-12-28]
Edge HomePage: Default -> hxxp://www.google.sk/
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-17]
Edge Extension: (Edge relevant text changes) - C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-13]
Edge Profile: C:\Users\igorv\AppData\Local\Microsoft\Edge\User Data\Guest Profile [2023-12-20]
Chrome:
=======
CHR HKU\S-1-5-21-1004790077-1547760064-1104730356-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 DSDFunctionKeyCtlService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDFunctionKeyCtlService.exe [718168 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
S2 DSDTabletControlService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDTabSysSvc.exe [330136 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R2 DSDWirelessLEDCtlService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\RMService.exe [480144 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R2 dynabookSettingService; C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\dynabookSystemService.exe [24153096 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe [3174840 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe [133592 2023-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 dhotkey; C:\Windows\System32\drivers\dhotkey.sys [52736 2023-03-22] (Dynabook Inc. -> Dynabook Inc.)
R1 dsrvctldrv; C:\Windows\System32\drivers\dsrvctldrv.sys [30232 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
R0 DVALZ_O; C:\Windows\System32\drivers\DVALZ_O.SYS [47464 2022-07-17] (Dynabook Inc. -> Dynabook Inc.)
R1 googledrivefs31092; C:\Windows\System32\DRIVERS\googledrivefs31092.sys [384600 2023-09-24] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [55856 2023-12-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [594304 2023-12-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105856 2023-12-06] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-12-28 13:35 - 2023-12-28 13:36 - 000010464 _____ C:\Users\igorv\Downloads\FRST.txt
2023-12-28 13:35 - 2023-12-28 13:35 - 000000000 ____D C:\FRST
2023-12-28 13:34 - 2023-12-28 13:34 - 002387456 _____ (Farbar) C:\Users\igorv\Downloads\FRST64.exe
2023-12-21 12:22 - 2023-12-21 12:22 - 000000000 ____D C:\Users\igorv\AppData\Local\CrashDumps
2023-12-20 15:07 - 2023-12-20 15:08 - 000000000 ____D C:\Windows\InboxApps
2023-12-20 11:52 - 2023-12-20 11:52 - 000016707 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2023-12-20 11:42 - 2023-12-20 11:42 - 000000000 ___HD C:\$WinREAgent
2023-11-30 17:25 - 2023-11-30 17:25 - 000000000 ____D C:\Users\igorv\AppData\Roaming\WinRAR
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-12-28 13:18 - 2023-07-06 11:48 - 000000000 ___SD C:\Users\igorv\AppData\Roaming\Microsoft\Credentials
2023-12-28 13:14 - 2023-07-06 11:32 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-12-28 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-12-28 09:50 - 2023-07-06 11:40 - 000804470 _____ C:\Windows\system32\PerfStringBackup.INI
2023-12-28 09:50 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2023-12-28 09:46 - 2023-07-06 11:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-12-28 09:46 - 2023-07-06 11:32 - 000008192 ___SH C:\DumpStack.log.tmp
2023-12-28 09:45 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2023-12-27 16:07 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2023-12-23 14:33 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-12-23 11:16 - 2023-07-06 11:33 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-12-20 20:02 - 2023-08-17 10:22 - 000000000 ____D C:\Windows\Minidump
2023-12-20 15:09 - 2023-07-06 11:52 - 000000000 ____D C:\Users\igorv\AppData\Local\Packages
2023-12-20 15:09 - 2023-07-06 11:32 - 000259760 _____ C:\Windows\system32\FNTCACHE.DAT
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lv-LV
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\lt-LT
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\et-EE
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\es-MX
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Provisioning
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2023-12-20 15:08 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2023-12-20 15:08 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2023-12-20 15:07 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2023-12-20 15:06 - 2019-12-07 15:39 - 000023040 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2023-12-20 15:06 - 2019-12-07 15:39 - 000020827 _____ C:\Windows\system32\OEMDefaultAssociations.xml
2023-12-20 11:52 - 2023-07-06 11:35 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-12-16 20:58 - 2023-07-08 21:54 - 000000000 ____D C:\2
2023-12-13 17:30 - 2023-07-06 11:48 - 000000000 ____D C:\Users\igorv
2023-12-06 17:44 - 2023-07-06 11:33 - 000000000 ____D C:\Windows\system32\Drivers\wd
2023-12-03 13:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\NDF
2023-12-03 11:43 - 2023-07-08 21:54 - 000000000 ____D C:\1
2023-11-29 22:02 - 2023-08-01 15:27 - 000000000 ____D C:\Users\igorv\AppData\LocalLow\Temp
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================