FRST poprosim o preventivku...
Napsal: 14 led 2024 12:55
Sem tam mi vyskoci nejaka reklama v browseri od g.chrome a sekaju videa na YT....dakujem za kontrolu.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11.01.2024
Ran by PC1 (administrator) on DESKTOP-NORVJE6 (MSI MS-7A39) (14-01-2024 12:53:32)
Running from C:\Users\PC1\Desktop\FRST64 (1).exe
Loaded Profiles: PC1
Platform: Microsoft Windows 10 Home Version 21H2 19044.3086 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe ->) (Reaction Software Limited -> Weather Zero) C:\Program Files (x86)\WeatherZero\WeatherZero.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\atieclxx.exe
(explorer.exe ->) (ACD Systems International Inc. -> ) [File not signed] C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\ACDSeeCommanderUltimate17.exe
(explorer.exe ->) (ACD Systems International Inc. -> ACD Systems International Inc.) [File not signed] C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\acdIDInTouch2.exe
(explorer.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files\AdGuard\Adguard.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <15>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.352\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.352\GoogleCrashHandler64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(services.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files\AdGuard\AdguardSvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\atiesrxx.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe
(services.exe ->) (Reaction Software Limited -> Weather Information Service) C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(win.rar GmbH -> Alexander Roshal) C:\Program Files\WinRAR\WinRAR.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102816 2022-01-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Adguard] => C:\Program Files\AdGuard\Adguard.exe [7147224 2023-12-23] (Adguard Software Limited -> Adguard Software Limited)
HKLM\...\Run: [ACUW17EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\acdIDInTouch2.exe [3508784 2024-01-13] (ACD Systems International Inc. -> ACD Systems International Inc.) [File not signed]
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [235624 2015-01-09] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37188048 2024-01-13] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4388200 2024-01-13] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [bt] => C:\Users\PC1\AppData\Roaming\BitTorrent\BitTorrent.exe [2279976 2022-01-22] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [PC1] => cmd.exe /c start www.exinariuminix.info (No File)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [482128 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44486048 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [MicrosoftEdgeAutoLaunch_3ED1524B1F1362DAB86361CACD0A8016] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3854272 2024-01-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [ut] => E:\Downloads\uTorrent Proň\App\uTorrent\uTorrent.exe [1946664 2022-02-04] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Adguard] => "C:\Program Files (x86)\Adguard\Adguard.exe" /nosplash (No File)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [ACDSeeCommanderUltimate17] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\ACDSeeCommanderUltimate17.exe [8257104 2024-01-13] (ACD Systems International Inc. -> ) [File not signed]
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\MountPoints2: {283cab94-2c81-11ea-925c-309c239b7301} - "F:\setup.exe"
HKLM\...\Windows x64\Print Processors\Canon MG3600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDCT.DLL [30208 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3600 series: C:\WINDOWS\system32\CNMLMCT.DLL [406528 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [375296 2015-03-17] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\120.0.6099.217\Installer\chrmstp.exe [2024-01-13] (Google LLC -> Google LLC)
IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll
IFEO\SppExtComObj.Exe: [VerifierDlls] SppExtComObjHook.dll
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {A36F405B-56F6-4E1E-AAA4-A8E8C5419461} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-09-20] (Adobe Inc. -> Adobe Inc.)
Task: {C9EE2F49-9A35-4606-8064-C015B14D20E1} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-08-05] (Avast Software s.r.o. -> Avast Software)
Task: {B1A13BC1-FD4F-487E-9988-C25C9BD56D65} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {ED4D2979-356B-4079-90AE-E23016CCF19B} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "f629c2c0-113b-48e0-87af-a975de79342f" --version "6.19.10858" --silent
Task: {8A4A45D0-D188-4B76-B6A7-55090433182C} - System32\Tasks\CCleanerSkipUAC - PC1 => C:\Program Files\CCleaner\CCleaner.exe [37458848 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {E0292ECE-8FE0-47B7-8656-4B2C9C1B4DFF} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\11.1.0\Scheduler.exe [160744 2023-09-28] (IObit CO., LTD -> IObit)
Task: {3EAE689C-5A13-4DA9-8503-0B51B0F1E34D} - System32\Tasks\Driver Booster SkipUAC (PC1) => C:\Program Files (x86)\IObit\Driver Booster\11.1.0\DriverBooster.exe [9044456 2023-10-26] (IObit CO., LTD -> IObit)
Task: {9D32F5B1-3F14-4580-B034-C304F8F368AD} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\11.1.0\AutoUpdate.exe [2524648 2023-09-28] (IObit CO., LTD -> IObit)
Task: {93A99B83-4F2A-4BD8-8C22-25FA2926AA64} - System32\Tasks\Google Play Games Notifier => C:\Program Files\Google\Play Games\Bootstrapper.exe [374560 2023-12-21] (Google LLC -> Google LLC)
Task: {DEFD6772-DE31-451F-B4D8-D880013A760C} - System32\Tasks\GoogleUpdateTaskMachineCore{05E95706-AA36-4A71-B668-2969215B9D40} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-20] (Google LLC -> Google LLC)
Task: {3C9E39AE-B26D-4F26-A516-B1207D428E69} - System32\Tasks\GoogleUpdateTaskMachineUA{DF0D55E6-D4D6-4216-AF10-109ABF22750F} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-20] (Google LLC -> Google LLC)
Task: {7EE7F7E0-3F0F-4093-9B95-D073D3BF70A0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {9A172CAE-E594-4004-8274-80EA84D69601} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {A689333B-D9AD-4A1E-BE3E-5A99BCA6022A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {3C9669D7-9BE7-4E1F-A396-4BA2DF95DED3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {DC7F1F62-2A22-455E-BD63-3A83557D2C67} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [65448 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {8487B275-D178-4E77-88A7-78C1BF6695FF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {C2C716A0-254D-4164-84C2-6810D9A8B11F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {41F3364A-21C6-4486-A98D-F75E7FDACB3C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C07386BD-B1AE-4E7E-B75E-38EDF9C6FC23} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5409B531-8D87-4E32-B273-55E08BDD9D87} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2B0A8281-E2F5-4515-8F8A-369ED34BD5B4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4FB3A957-445C-4EFB-A0F8-0C00CB583A0E} - System32\Tasks\PC1 => C:\WINDOWS\system32\cmd.exe [289792 2021-01-13] (Microsoft Windows -> Microsoft Corporation) -> /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v PC1 /t REG_SZ /d "cmd.exe /c start www.exinariuminix.info" <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{54db6741-c35b-439b-9673-ac7e98521184}: [DhcpNameServer] 192.168.1.1 195.146.128.62
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default [2024-01-14]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-01]
Edge Extension: (Edge relevant text changes) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-22]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-01-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default [2024-01-14]
CHR Notifications: Default -> hxxps://jutes.ru; hxxps://sibirem.ru; hxxps://slo.wikiwiex.com; hxxps://www.giveawayoftheday.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-01-13]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-12-27]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1 [2023-12-27]
CHR Extension: (Torrent Scanner) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2023-03-04]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-12-27]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4 [2024-01-13]
CHR Extension: (Torrent Scanner) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2024-01-11]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2024-01-11]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-03-30]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\System Profile [2024-01-14]
CHR HKLM\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
Opera:
=======
OPR Profile: C:\Users\PC1\AppData\Roaming\Opera Software\Opera Stable [2023-12-27]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Adguard Service; C:\Program Files\AdGuard\AdguardSvc.exe [797400 2023-12-23] (Adguard Software Limited -> Adguard Software Limited)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-09-20] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12477392 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4976976 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-10] (Epic Games Inc. -> Epic Games, Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpDefenderCoreService.exe [1418736 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [4505072 2023-12-21] (Rockstar Games, Inc. -> Rockstar Games)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13353768 2021-09-15] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe [3174840 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WeatherZeroSvc; C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe [3256744 2022-06-12] (Reaction Software Limited -> Weather Information Service)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe [133592 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 2C50ECBD; C:\WINDOWS\System32\drivers\2C50ECBD.sys [478392 2021-04-14] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 adgnetworkwfpdrv; C:\WINDOWS\System32\drivers\adgnetworkwfpdrv.sys [89272 2023-11-03] (Microsoft Windows Hardware Compatibility Publisher -> Adguard Software Limited)
S3 AIDA64Driver; C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [68376 2021-03-29] (FinalWire Kft. -> )
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [49768 2022-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [36928 2023-04-04] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\amdkmdag.sys [106378272 2023-12-27] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2020-11-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [63696 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit Information Technology -> IObit)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2022-07-04] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-12-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [594304 2023-12-22] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105856 2023-12-22] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2022-10-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [312776 2020-12-24] (Microsoft Windows Hardware Compatibility Publisher -> Nox Limited Corporation)
S3 cpuz149; \??\C:\Users\PC1\AppData\Local\Temp\cpuz149\cpuz149_x64.sys [X] <==== ATTENTION
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-01-14 12:53 - 2024-01-14 12:54 - 000024219 _____ C:\Users\PC1\Desktop\FRST.txt
2024-01-14 12:52 - 2024-01-14 12:52 - 002389504 _____ (Farbar) C:\Users\PC1\Downloads\FRST64 (1).exe
2024-01-14 12:52 - 2024-01-14 12:52 - 002389504 _____ (Farbar) C:\Users\PC1\Desktop\FRST64 (1).exe
2024-01-13 16:56 - 2024-01-13 16:56 - 000000000 ____D C:\Users\PC1\AppData\Roaming\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:56 - 000000000 ____D C:\Users\PC1\AppData\Local\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:56 - 000000000 ____D C:\ProgramData\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:53 - 000002527 _____ C:\Users\Public\Desktop\ACDSee Photo Studio Ultimate 2024.lnk
2024-01-13 16:53 - 2024-01-13 16:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:53 - 000000000 ____D C:\Program Files\Common Files\ACD Systems
2024-01-13 16:52 - 2024-01-13 16:53 - 000000000 ____D C:\Program Files\ACD Systems
2024-01-13 16:52 - 2024-01-13 16:52 - 000000000 ____D C:\ProgramData\Apple
2024-01-13 16:52 - 2024-01-13 16:52 - 000000000 ____D C:\Program Files\Bonjour
2024-01-13 16:52 - 2024-01-13 16:52 - 000000000 ____D C:\Program Files (x86)\Bonjour
2024-01-04 16:21 - 2024-01-04 16:21 - 013619024 _____ C:\Users\PC1\Downloads\CheatEvolution.zip
2024-01-04 16:20 - 2024-01-04 16:20 - 000144416 _____ (WeMod LLC) C:\Users\PC1\Downloads\Kingdom Rush Vengeance - Tower Defense (Steam) Trainer Setup.exe
2024-01-04 16:10 - 2024-01-04 16:19 - 000000000 ____D C:\Users\PC1\AppData\Local\Kingdom Rush Vengeance
2024-01-04 16:10 - 2022-02-02 15:31 - 000001367 __RSH C:\WINDOWS\system32\Drivers\etc\hosts.check
2024-01-04 16:10 - 2022-02-02 15:31 - 000001367 __RSH C:\WINDOWS\system32\Drivers\etc\hosts.backup
2024-01-04 16:02 - 2024-01-04 16:02 - 000000683 _____ C:\Users\Public\Desktop\Kingdom Rush - Vengeance.lnk
2024-01-04 12:39 - 2024-01-04 12:39 - 000002086 _____ C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2024-01-04 12:39 - 2024-01-04 12:39 - 000000000 ____D C:\WINDOWS\system32\STRING
2024-01-04 12:39 - 2024-01-04 12:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2024-01-04 12:39 - 2024-01-04 12:39 - 000000000 ____D C:\ProgramData\Canon IJ Network Tool
2024-01-04 12:39 - 2015-03-17 08:51 - 000375296 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6PPM.DLL
2024-01-04 12:39 - 2015-03-17 08:51 - 000039424 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6UI.DLL
2024-01-04 12:39 - 2015-03-17 08:50 - 000380928 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNMNPPM.DLL
2024-01-04 12:38 - 2024-01-04 12:38 - 038653736 _____ C:\Users\PC1\Downloads\m68n-win-mg3600-1_02-ea34_2.exe
2024-01-04 12:38 - 2024-01-04 12:38 - 000000000 ___HD C:\Program Files\CanonBJ
2024-01-04 12:38 - 2024-01-04 12:38 - 000000000 ____D C:\Users\PC1\Downloads\m68n-win-mg3600-1_02-ea34_2
2024-01-04 12:33 - 2024-01-04 12:33 - 050630472 _____ C:\Users\PC1\Downloads\win-mg3600-1_1-n_mcd.exe
2024-01-04 12:33 - 2024-01-04 12:33 - 000000000 ____D C:\Users\PC1\Downloads\win-mg3600-1_1-n_mcd
2024-01-04 11:48 - 2024-01-04 12:39 - 000000000 ____D C:\Program Files (x86)\Canon
2024-01-04 11:48 - 2024-01-04 11:48 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Canon
2024-01-04 11:48 - 2024-01-04 11:48 - 000000000 ____D C:\ProgramData\Canon
2024-01-04 11:47 - 2024-01-04 11:47 - 021368608 _____ C:\Users\PC1\Downloads\win-g3060-1_4-n_mcd.exe
2024-01-04 11:47 - 2024-01-04 11:47 - 000000000 ____D C:\Users\PC1\Downloads\win-g3060-1_4-n_mcd
2024-01-03 16:55 - 2024-01-03 16:55 - 000047870 _____ C:\Users\PC1\Downloads\[SkT]Kingdom_Rush_-_Vengeance.torrent
2024-01-03 16:54 - 2024-01-03 16:54 - 001893949 _____ C:\Users\PC1\Downloads\Hogwarts_Legacy_CZ_V094.zip
2024-01-03 11:02 - 2024-01-03 11:02 - 000172022 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_Update_3_ _crack (1).torrent
2024-01-02 15:34 - 2024-01-02 15:34 - 000831947 _____ C:\Users\PC1\Downloads\Hogwarts.Legacy.v1.0-v20230504.Plus.32.Trainer-FLiNG.zip
2024-01-02 12:40 - 2024-01-02 12:40 - 000002780 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_(0.9) (1).torrent
2024-01-02 12:37 - 2024-01-02 21:04 - 000000000 ____D C:\ProgramData\Hogwarts Legacy
2024-01-02 12:37 - 2024-01-02 12:37 - 000000000 ____D C:\Users\PC1\AppData\Local\Phoenix
2024-01-02 11:21 - 2024-01-02 11:21 - 000000769 _____ C:\Users\Public\Desktop\Hogwarts Legacy CZ.lnk
2024-01-02 11:21 - 2024-01-02 11:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hogwarts Legacy CZ
2024-01-02 09:45 - 2024-01-02 09:45 - 000172022 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_Update_3_ _crack.torrent
2024-01-01 19:36 - 2024-01-01 19:36 - 000357219 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_CZ_Empress_b.1117238 (1).torrent
2023-12-27 21:22 - 2023-12-29 16:54 - 000000000 ____D C:\Users\PC1\AppData\Roaming\FikitRDR2
2023-12-27 21:17 - 2024-01-04 17:13 - 000000000 ____D C:\Users\PC1\Desktop\assets
2023-12-27 21:17 - 2023-12-27 21:17 - 030972948 _____ C:\Users\PC1\Desktop\Loader.exe
2023-12-27 21:17 - 2023-12-27 21:17 - 000000000 ____D C:\Users\PC1\AppData\Roaming\MyCompany
2023-12-27 21:17 - 2023-12-27 21:17 - 000000000 ____D C:\Users\PC1\AppData\Roaming\FikitNetwork
2023-12-27 20:39 - 2024-01-04 12:40 - 000000000 ____D C:\Program Files\AdGuard
2023-12-27 20:39 - 2023-12-27 20:39 - 000001938 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdGuard.lnk
2023-12-27 20:39 - 2023-12-27 20:39 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Adguard Software Limited
2023-12-27 20:39 - 2023-12-27 20:39 - 000000000 ____D C:\Users\PC1\AppData\Local\Adguard_Software_Limited
2023-12-27 20:39 - 2023-12-27 20:39 - 000000000 ____D C:\Users\Default\AppData\Roaming\Adobe
2023-12-27 20:34 - 2023-12-27 20:34 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Adguard Software Ltd
2023-12-27 20:31 - 2024-01-14 12:24 - 000000000 ____D C:\ProgramData\Adguard
2023-12-27 20:31 - 2023-12-27 20:39 - 000000972 _____ C:\Users\Public\Desktop\Adguard.lnk
2023-12-27 20:29 - 2023-12-27 20:30 - 000000000 ____D C:\Users\PC1\Downloads\ADGUARD
2023-12-27 19:39 - 2023-12-27 19:39 - 006705829 _____ C:\Users\PC1\Downloads\Adguard Premium v7.0.2617.6509 Nightly Patch.LHA
2023-12-27 19:35 - 2023-12-27 20:13 - 027862834 _____ C:\Users\PC1\Downloads\Adguard 2023 6 mesiacov.zip
2023-12-27 16:23 - 2023-12-27 16:23 - 000000223 _____ C:\Users\PC1\Desktop\Red Dead Online.url
2023-12-27 10:50 - 2023-12-27 10:50 - 021365284 _____ C:\Users\PC1\Downloads\adlock.apk
2023-12-27 10:44 - 2023-12-27 10:44 - 000003294 _____ C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (PC1)
2023-12-27 10:44 - 2023-12-27 10:44 - 000003186 _____ C:\WINDOWS\system32\Tasks\Driver Booster Scheduler
2023-12-27 10:44 - 2023-12-27 10:44 - 000003172 _____ C:\WINDOWS\system32\Tasks\Driver Booster Update
2023-12-27 10:44 - 2023-12-27 10:44 - 000002366 _____ C:\Users\Public\Desktop\Driver Booster 11.lnk
2023-12-27 10:44 - 2023-12-27 10:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 11
2023-12-27 10:42 - 2023-12-27 10:42 - 029556352 _____ (IObit ) C:\Users\PC1\Downloads\SharewareOnSale_Giveaway_Driver_Booster_11_PRO (1).exe
2023-12-27 10:41 - 2023-12-27 10:41 - 029556352 _____ (IObit ) C:\Users\PC1\Downloads\SharewareOnSale_Giveaway_Driver_Booster_11_PRO.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 109628272 _____ C:\WINDOWS\system32\amdxc64.so
2023-12-27 10:38 - 2023-12-27 10:38 - 011747104 _____ C:\WINDOWS\system32\amdsmi.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 004375072 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdadlx64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 004180000 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdadlx32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 002235424 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsasrv64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 002089912 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001701144 _____ (AMD) C:\WINDOWS\system32\amf-mft-mjpeg-decoder64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001607600 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001607600 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001378456 _____ (AMD) C:\WINDOWS\SysWOW64\amf-mft-mjpeg-decoder32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001328672 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsacli64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001049632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdsacli32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000965664 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000933920 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000846880 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000846880 _____ C:\WINDOWS\system32\vulkaninfo.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000761376 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000727584 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000727584 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000672192 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000672192 _____ C:\WINDOWS\system32\vulkan-1.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000657792 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000657792 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000597936 _____ C:\WINDOWS\system32\GameManager64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000560160 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000557448 _____ C:\WINDOWS\system32\amdmiracast.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000539064 _____ C:\WINDOWS\system32\libsmi_guest.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000527392 _____ C:\WINDOWS\system32\atieah64.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000514480 _____ C:\WINDOWS\system32\libsmi_host.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000494008 _____ C:\WINDOWS\system32\EEURestart.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000463392 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000452536 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000423856 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000396320 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000256952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000219168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000200936 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000197560 _____ C:\WINDOWS\system32\mantle64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000186400 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000176560 _____ C:\WINDOWS\system32\mantleaxl64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000174624 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000166328 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000164960 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000155968 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000155968 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000155680 _____ C:\WINDOWS\SysWOW64\mantle32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000146064 _____ C:\WINDOWS\system32\atidxx64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000141272 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000139296 _____ C:\WINDOWS\SysWOW64\mantleaxl32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000138784 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000132528 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000129056 _____ C:\WINDOWS\system32\amdxc64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000127440 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000127328 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000119984 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000108464 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000104888 _____ C:\WINDOWS\SysWOW64\amdxc32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000064944 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2023-12-25 10:22 - 2023-12-25 10:22 - 000187338 _____ C:\Users\PC1\Downloads\[TreZzoR]BeamNG.drive [Alpha v0.30.6].torrent
2023-12-23 09:04 - 2024-01-13 20:03 - 004562448 _____ C:\Users\PC1\Desktop\Launcher.exe
2023-12-23 09:04 - 2023-12-29 17:30 - 004276752 _____ C:\Users\PC1\Desktop\Launcher15.exe
2023-12-23 05:02 - 2023-12-23 05:02 - 000033255 _____ C:\WINDOWS\system32\prfc0003.dat.tmp
2023-12-22 18:13 - 2023-12-22 18:13 - 004497936 _____ C:\Users\PC1\Downloads\Launcher14.exe
2023-12-22 11:31 - 2023-12-22 11:31 - 006527872 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2023-12-21 20:39 - 2023-12-23 09:02 - 004276752 _____ C:\WINDOWS\system32\Launcher.exe
2023-12-21 14:44 - 2023-12-21 14:44 - 001376304 _____ (Google LLC) C:\Users\PC1\Downloads\ChromeSetup.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-01-14 12:53 - 2020-12-19 10:48 - 000000000 ____D C:\FRST
2024-01-14 12:52 - 2021-03-09 15:44 - 000000000 ____D C:\Users\PC1\AppData\Local\CrashDumps
2024-01-14 12:50 - 2020-12-20 10:32 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-01-14 12:28 - 2021-12-16 21:47 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-01-14 12:28 - 2020-12-20 11:00 - 000000000 ____D C:\Program Files (x86)\Google
2024-01-13 22:18 - 2021-06-26 12:26 - 000000000 ____D C:\Program Files (x86)\Steam
2024-01-13 22:05 - 2020-12-20 10:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-01-13 20:42 - 2022-10-07 07:39 - 000000282 _____ C:\Users\PC1\Desktop\imgui.ini
2024-01-13 20:04 - 2022-10-12 06:10 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Atlas
2024-01-13 20:03 - 2023-10-14 06:47 - 000000113 _____ C:\WINDOWS\AUTH
2024-01-13 19:10 - 2020-12-20 10:55 - 000000000 ____D C:\Users\PC1\AppData\Local\D3DSCache
2024-01-13 17:07 - 2022-05-22 13:05 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Word
2024-01-13 14:05 - 2020-12-20 10:44 - 000000000 ____D C:\Users\PC1
2024-01-13 11:21 - 2023-04-05 07:10 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-01-13 11:18 - 2023-09-03 07:06 - 000001134 _____ C:\WINDOWS\system32\config\VSMIDK
2024-01-13 11:18 - 2021-01-02 12:33 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2024-01-13 11:18 - 2020-12-20 10:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-01-13 11:18 - 2020-11-07 10:27 - 000008192 ___SH C:\DumpStack.log.tmp
2024-01-13 10:52 - 2020-12-20 10:32 - 000000000 ___HD C:\Program Files\WindowsApps
2024-01-13 10:52 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-01-13 08:21 - 2020-12-23 17:30 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-01-13 08:21 - 2020-12-20 14:09 - 000918944 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2024-01-13 08:21 - 2020-12-20 11:00 - 000002259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-01-13 08:21 - 2020-12-20 11:00 - 000002218 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-01-13 08:21 - 2020-06-10 20:36 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-01-11 19:13 - 2020-12-20 11:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-01-11 19:10 - 2020-12-20 11:41 - 189718008 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-01-07 08:02 - 2020-04-13 19:05 - 000000000 ____D C:\Users\PC1\AppData\LocalLow\Adobe
2024-01-06 11:02 - 2022-04-03 10:14 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-01-06 11:01 - 2022-10-14 12:10 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-01-06 11:01 - 2022-10-14 12:10 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2024-01-05 17:17 - 2022-10-04 08:35 - 000000660 _____ C:\Users\PC1\Downloads\imgui.ini
2024-01-05 14:05 - 2021-03-29 05:02 - 000000000 ____D C:\ProgramData\IObit
2024-01-04 16:11 - 2019-12-30 14:00 - 000000000 ____D C:\Users\PC1\AppData\LocalLow\Mozilla
2024-01-04 16:08 - 2021-02-09 15:56 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2024-01-04 12:40 - 2020-12-20 10:41 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2024-01-04 12:40 - 2020-12-20 10:27 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-01-04 12:39 - 2020-12-20 10:32 - 000000000 __RSD C:\WINDOWS\Media
2024-01-04 12:38 - 2020-12-20 10:31 - 000000000 ____D C:\WINDOWS\INF
2024-01-04 12:31 - 2021-11-13 11:01 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Wise Uninstaller
2024-01-03 17:10 - 2020-12-20 10:59 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Spelling
2024-01-03 10:07 - 2020-12-20 10:28 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-01-03 09:57 - 2020-12-20 10:34 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2024-01-03 09:57 - 2020-12-20 10:34 - 000000000 ____D C:\WINDOWS\system32\WCN
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\IME
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files\Windows Defender
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files\Common Files\System
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2024-01-03 09:57 - 2020-12-20 10:27 - 000000000 ____D C:\WINDOWS\servicing
2024-01-03 09:55 - 2020-12-20 10:57 - 000000000 ____D C:\Users\PC1\AppData\Local\PlaceholderTileLogoFolder
2024-01-03 09:55 - 2020-12-20 10:55 - 000000000 ____D C:\Users\PC1\AppData\Local\Packages
2024-01-03 09:55 - 2020-12-20 10:35 - 000000000 ____D C:\WINDOWS\OCR
2024-01-02 12:37 - 2022-08-10 18:07 - 000000000 ____D C:\Users\Public\Documents\EMPRESS
2023-12-31 13:15 - 2023-05-16 16:02 - 004562448 _____ C:\Users\PC1\Downloads\Launcher.exe
2023-12-27 21:00 - 2021-06-27 06:43 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2023-12-27 20:39 - 2021-10-17 12:09 - 000000000 ____D C:\ProgramData\Package Cache
2023-12-27 17:35 - 2023-05-16 16:02 - 004276752 _____ C:\Users\PC1\Downloads\Launcher15.exe
2023-12-27 16:23 - 2020-01-08 09:46 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-12-27 10:44 - 2021-03-29 05:02 - 000000000 ____D C:\Program Files (x86)\IObit
2023-12-27 10:43 - 2023-04-05 07:10 - 000000000 ____D C:\Program Files\CCleaner
2023-12-27 10:43 - 2021-09-17 19:29 - 000000000 ____D C:\ProgramData\ProductData
2023-12-27 10:38 - 2022-01-30 14:10 - 000177856 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
2023-12-27 10:38 - 2021-01-08 09:29 - 000222688 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
2023-12-27 10:30 - 2022-01-30 17:11 - 000000000 ____D C:\Users\PC1\AppData\Roaming\IObit
2023-12-27 10:25 - 2022-02-06 14:04 - 000000000 ____D C:\Users\PC1\AppData\Roaming\uTorrent
2023-12-25 20:53 - 2021-12-07 12:48 - 000000000 ____D C:\Users\PC1\AppData\Local\BeamNG.drive
2023-12-23 17:31 - 2021-01-22 21:06 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-12-23 16:54 - 2022-11-26 06:18 - 000000187 _____ C:\WINDOWS\system32\imgui.ini
2023-12-23 09:01 - 2021-06-26 12:27 - 000000000 ____D C:\Users\PC1\AppData\Local\Steam
2023-12-22 18:15 - 2023-10-21 14:58 - 004497936 _____ C:\WINDOWS\system32\Launcher14.exe
2023-12-22 11:33 - 2023-04-05 07:10 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2023-12-22 09:18 - 2020-12-20 10:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2023-12-22 09:08 - 2023-04-05 07:10 - 000003382 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2023-12-21 20:45 - 2023-05-23 20:38 - 000000000 ____D C:\Users\PC1\AppData\Local\ElevatedDiagnostics
2023-12-21 20:31 - 2021-01-03 15:05 - 000000000 ____D C:\Program Files\Rockstar Games
2023-12-21 20:31 - 2021-01-03 15:05 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2023-12-21 14:43 - 2022-04-24 19:02 - 000003828 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA{DF0D55E6-D4D6-4216-AF10-109ABF22750F}
2023-12-21 14:43 - 2022-04-24 19:02 - 000003704 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore{05E95706-AA36-4A71-B668-2969215B9D40}
2023-12-21 14:41 - 2021-10-08 18:04 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Kodi
2023-12-21 14:38 - 2022-05-12 19:30 - 000655014 _____ C:\WINDOWS\system32\perfh01B.dat
2023-12-21 14:38 - 2022-05-12 19:30 - 000126024 _____ C:\WINDOWS\system32\perfc01B.dat
2023-12-21 14:38 - 2022-02-10 22:30 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2023-12-21 14:38 - 2022-01-22 13:11 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2023-12-21 14:38 - 2020-12-20 10:53 - 001547404 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-12-21 14:38 - 2020-12-20 10:44 - 000002365 _____ C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
==================== Files in the root of some directories ========
2023-04-17 18:04 - 2023-04-17 18:04 - 000000255 _____ () C:\ProgramData\fontcacheev1.dat
2021-06-06 09:33 - 2021-07-21 20:43 - 000000055 _____ () C:\Users\PC1\AppData\Roaming\EHWID.txt
2022-08-12 16:55 - 2023-09-16 19:35 - 000208896 _____ () C:\Users\PC1\AppData\Roaming\emp.bin
2021-06-06 09:33 - 2021-12-12 18:52 - 000000011 _____ () C:\Users\PC1\AppData\Roaming\EPW.txt
2021-06-06 09:33 - 2021-07-21 20:43 - 000000009 _____ () C:\Users\PC1\AppData\Roaming\ERole.txt
2021-06-06 09:33 - 2021-12-12 18:52 - 000000012 _____ () C:\Users\PC1\AppData\Roaming\EUser.txt
2021-03-07 19:58 - 2021-03-07 19:58 - 000016438 _____ () C:\Users\PC1\AppData\Local\partner.bmp
==================== FCheck ================================
(If an entry is included in the fixlist, the file/folder will be moved.)
FCheck: C:\WINDOWS\SysWOW64\version_IObitDel.dll [2023-04-04] <==== ATTENTION (zero byte File/Folder)
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11.01.2024
Ran by PC1 (administrator) on DESKTOP-NORVJE6 (MSI MS-7A39) (14-01-2024 12:53:32)
Running from C:\Users\PC1\Desktop\FRST64 (1).exe
Loaded Profiles: PC1
Platform: Microsoft Windows 10 Home Version 21H2 19044.3086 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe ->) (Reaction Software Limited -> Weather Zero) C:\Program Files (x86)\WeatherZero\WeatherZero.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\atieclxx.exe
(explorer.exe ->) (ACD Systems International Inc. -> ) [File not signed] C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\ACDSeeCommanderUltimate17.exe
(explorer.exe ->) (ACD Systems International Inc. -> ACD Systems International Inc.) [File not signed] C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\acdIDInTouch2.exe
(explorer.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files\AdGuard\Adguard.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <15>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.352\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.352\GoogleCrashHandler64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(services.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files\AdGuard\AdguardSvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\atiesrxx.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe
(services.exe ->) (Reaction Software Limited -> Weather Information Service) C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(win.rar GmbH -> Alexander Roshal) C:\Program Files\WinRAR\WinRAR.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102816 2022-01-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Adguard] => C:\Program Files\AdGuard\Adguard.exe [7147224 2023-12-23] (Adguard Software Limited -> Adguard Software Limited)
HKLM\...\Run: [ACUW17EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\acdIDInTouch2.exe [3508784 2024-01-13] (ACD Systems International Inc. -> ACD Systems International Inc.) [File not signed]
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [235624 2015-01-09] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37188048 2024-01-13] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4388200 2024-01-13] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [bt] => C:\Users\PC1\AppData\Roaming\BitTorrent\BitTorrent.exe [2279976 2022-01-22] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [PC1] => cmd.exe /c start www.exinariuminix.info (No File)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [482128 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44486048 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [MicrosoftEdgeAutoLaunch_3ED1524B1F1362DAB86361CACD0A8016] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3854272 2024-01-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [ut] => E:\Downloads\uTorrent Proň\App\uTorrent\uTorrent.exe [1946664 2022-02-04] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Adguard] => "C:\Program Files (x86)\Adguard\Adguard.exe" /nosplash (No File)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [ACDSeeCommanderUltimate17] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\ACDSeeCommanderUltimate17.exe [8257104 2024-01-13] (ACD Systems International Inc. -> ) [File not signed]
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\MountPoints2: {283cab94-2c81-11ea-925c-309c239b7301} - "F:\setup.exe"
HKLM\...\Windows x64\Print Processors\Canon MG3600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDCT.DLL [30208 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3600 series: C:\WINDOWS\system32\CNMLMCT.DLL [406528 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [375296 2015-03-17] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\120.0.6099.217\Installer\chrmstp.exe [2024-01-13] (Google LLC -> Google LLC)
IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll
IFEO\SppExtComObj.Exe: [VerifierDlls] SppExtComObjHook.dll
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {A36F405B-56F6-4E1E-AAA4-A8E8C5419461} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-09-20] (Adobe Inc. -> Adobe Inc.)
Task: {C9EE2F49-9A35-4606-8064-C015B14D20E1} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-08-05] (Avast Software s.r.o. -> Avast Software)
Task: {B1A13BC1-FD4F-487E-9988-C25C9BD56D65} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {ED4D2979-356B-4079-90AE-E23016CCF19B} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "f629c2c0-113b-48e0-87af-a975de79342f" --version "6.19.10858" --silent
Task: {8A4A45D0-D188-4B76-B6A7-55090433182C} - System32\Tasks\CCleanerSkipUAC - PC1 => C:\Program Files\CCleaner\CCleaner.exe [37458848 2023-12-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {E0292ECE-8FE0-47B7-8656-4B2C9C1B4DFF} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\11.1.0\Scheduler.exe [160744 2023-09-28] (IObit CO., LTD -> IObit)
Task: {3EAE689C-5A13-4DA9-8503-0B51B0F1E34D} - System32\Tasks\Driver Booster SkipUAC (PC1) => C:\Program Files (x86)\IObit\Driver Booster\11.1.0\DriverBooster.exe [9044456 2023-10-26] (IObit CO., LTD -> IObit)
Task: {9D32F5B1-3F14-4580-B034-C304F8F368AD} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\11.1.0\AutoUpdate.exe [2524648 2023-09-28] (IObit CO., LTD -> IObit)
Task: {93A99B83-4F2A-4BD8-8C22-25FA2926AA64} - System32\Tasks\Google Play Games Notifier => C:\Program Files\Google\Play Games\Bootstrapper.exe [374560 2023-12-21] (Google LLC -> Google LLC)
Task: {DEFD6772-DE31-451F-B4D8-D880013A760C} - System32\Tasks\GoogleUpdateTaskMachineCore{05E95706-AA36-4A71-B668-2969215B9D40} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-20] (Google LLC -> Google LLC)
Task: {3C9E39AE-B26D-4F26-A516-B1207D428E69} - System32\Tasks\GoogleUpdateTaskMachineUA{DF0D55E6-D4D6-4216-AF10-109ABF22750F} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-20] (Google LLC -> Google LLC)
Task: {7EE7F7E0-3F0F-4093-9B95-D073D3BF70A0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {9A172CAE-E594-4004-8274-80EA84D69601} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {A689333B-D9AD-4A1E-BE3E-5A99BCA6022A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {3C9669D7-9BE7-4E1F-A396-4BA2DF95DED3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {DC7F1F62-2A22-455E-BD63-3A83557D2C67} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [65448 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {8487B275-D178-4E77-88A7-78C1BF6695FF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {C2C716A0-254D-4164-84C2-6810D9A8B11F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {41F3364A-21C6-4486-A98D-F75E7FDACB3C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C07386BD-B1AE-4E7E-B75E-38EDF9C6FC23} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5409B531-8D87-4E32-B273-55E08BDD9D87} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2B0A8281-E2F5-4515-8F8A-369ED34BD5B4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4FB3A957-445C-4EFB-A0F8-0C00CB583A0E} - System32\Tasks\PC1 => C:\WINDOWS\system32\cmd.exe [289792 2021-01-13] (Microsoft Windows -> Microsoft Corporation) -> /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v PC1 /t REG_SZ /d "cmd.exe /c start www.exinariuminix.info" <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{54db6741-c35b-439b-9673-ac7e98521184}: [DhcpNameServer] 192.168.1.1 195.146.128.62
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default [2024-01-14]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-01]
Edge Extension: (Edge relevant text changes) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-22]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-01-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default [2024-01-14]
CHR Notifications: Default -> hxxps://jutes.ru; hxxps://sibirem.ru; hxxps://slo.wikiwiex.com; hxxps://www.giveawayoftheday.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-01-13]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-12-27]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1 [2023-12-27]
CHR Extension: (Torrent Scanner) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2023-03-04]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-12-27]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4 [2024-01-13]
CHR Extension: (Torrent Scanner) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2024-01-11]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2024-01-11]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-03-30]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\System Profile [2024-01-14]
CHR HKLM\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
Opera:
=======
OPR Profile: C:\Users\PC1\AppData\Roaming\Opera Software\Opera Stable [2023-12-27]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Adguard Service; C:\Program Files\AdGuard\AdguardSvc.exe [797400 2023-12-23] (Adguard Software Limited -> Adguard Software Limited)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-09-20] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12477392 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4976976 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-10] (Epic Games Inc. -> Epic Games, Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpDefenderCoreService.exe [1418736 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [4505072 2023-12-21] (Rockstar Games, Inc. -> Rockstar Games)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13353768 2021-09-15] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe [3174840 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WeatherZeroSvc; C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe [3256744 2022-06-12] (Reaction Software Limited -> Weather Information Service)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe [133592 2023-12-22] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 2C50ECBD; C:\WINDOWS\System32\drivers\2C50ECBD.sys [478392 2021-04-14] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 adgnetworkwfpdrv; C:\WINDOWS\System32\drivers\adgnetworkwfpdrv.sys [89272 2023-11-03] (Microsoft Windows Hardware Compatibility Publisher -> Adguard Software Limited)
S3 AIDA64Driver; C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [68376 2021-03-29] (FinalWire Kft. -> )
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [49768 2022-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [36928 2023-04-04] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0397033.inf_amd64_bf2b1fc18ba7195d\B396953\amdkmdag.sys [106378272 2023-12-27] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2020-11-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [63696 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit Information Technology -> IObit)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2022-07-04] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-12-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [594304 2023-12-22] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105856 2023-12-22] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2022-10-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [312776 2020-12-24] (Microsoft Windows Hardware Compatibility Publisher -> Nox Limited Corporation)
S3 cpuz149; \??\C:\Users\PC1\AppData\Local\Temp\cpuz149\cpuz149_x64.sys [X] <==== ATTENTION
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-01-14 12:53 - 2024-01-14 12:54 - 000024219 _____ C:\Users\PC1\Desktop\FRST.txt
2024-01-14 12:52 - 2024-01-14 12:52 - 002389504 _____ (Farbar) C:\Users\PC1\Downloads\FRST64 (1).exe
2024-01-14 12:52 - 2024-01-14 12:52 - 002389504 _____ (Farbar) C:\Users\PC1\Desktop\FRST64 (1).exe
2024-01-13 16:56 - 2024-01-13 16:56 - 000000000 ____D C:\Users\PC1\AppData\Roaming\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:56 - 000000000 ____D C:\Users\PC1\AppData\Local\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:56 - 000000000 ____D C:\ProgramData\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:53 - 000002527 _____ C:\Users\Public\Desktop\ACDSee Photo Studio Ultimate 2024.lnk
2024-01-13 16:53 - 2024-01-13 16:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems
2024-01-13 16:53 - 2024-01-13 16:53 - 000000000 ____D C:\Program Files\Common Files\ACD Systems
2024-01-13 16:52 - 2024-01-13 16:53 - 000000000 ____D C:\Program Files\ACD Systems
2024-01-13 16:52 - 2024-01-13 16:52 - 000000000 ____D C:\ProgramData\Apple
2024-01-13 16:52 - 2024-01-13 16:52 - 000000000 ____D C:\Program Files\Bonjour
2024-01-13 16:52 - 2024-01-13 16:52 - 000000000 ____D C:\Program Files (x86)\Bonjour
2024-01-04 16:21 - 2024-01-04 16:21 - 013619024 _____ C:\Users\PC1\Downloads\CheatEvolution.zip
2024-01-04 16:20 - 2024-01-04 16:20 - 000144416 _____ (WeMod LLC) C:\Users\PC1\Downloads\Kingdom Rush Vengeance - Tower Defense (Steam) Trainer Setup.exe
2024-01-04 16:10 - 2024-01-04 16:19 - 000000000 ____D C:\Users\PC1\AppData\Local\Kingdom Rush Vengeance
2024-01-04 16:10 - 2022-02-02 15:31 - 000001367 __RSH C:\WINDOWS\system32\Drivers\etc\hosts.check
2024-01-04 16:10 - 2022-02-02 15:31 - 000001367 __RSH C:\WINDOWS\system32\Drivers\etc\hosts.backup
2024-01-04 16:02 - 2024-01-04 16:02 - 000000683 _____ C:\Users\Public\Desktop\Kingdom Rush - Vengeance.lnk
2024-01-04 12:39 - 2024-01-04 12:39 - 000002086 _____ C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2024-01-04 12:39 - 2024-01-04 12:39 - 000000000 ____D C:\WINDOWS\system32\STRING
2024-01-04 12:39 - 2024-01-04 12:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2024-01-04 12:39 - 2024-01-04 12:39 - 000000000 ____D C:\ProgramData\Canon IJ Network Tool
2024-01-04 12:39 - 2015-03-17 08:51 - 000375296 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6PPM.DLL
2024-01-04 12:39 - 2015-03-17 08:51 - 000039424 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6UI.DLL
2024-01-04 12:39 - 2015-03-17 08:50 - 000380928 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNMNPPM.DLL
2024-01-04 12:38 - 2024-01-04 12:38 - 038653736 _____ C:\Users\PC1\Downloads\m68n-win-mg3600-1_02-ea34_2.exe
2024-01-04 12:38 - 2024-01-04 12:38 - 000000000 ___HD C:\Program Files\CanonBJ
2024-01-04 12:38 - 2024-01-04 12:38 - 000000000 ____D C:\Users\PC1\Downloads\m68n-win-mg3600-1_02-ea34_2
2024-01-04 12:33 - 2024-01-04 12:33 - 050630472 _____ C:\Users\PC1\Downloads\win-mg3600-1_1-n_mcd.exe
2024-01-04 12:33 - 2024-01-04 12:33 - 000000000 ____D C:\Users\PC1\Downloads\win-mg3600-1_1-n_mcd
2024-01-04 11:48 - 2024-01-04 12:39 - 000000000 ____D C:\Program Files (x86)\Canon
2024-01-04 11:48 - 2024-01-04 11:48 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Canon
2024-01-04 11:48 - 2024-01-04 11:48 - 000000000 ____D C:\ProgramData\Canon
2024-01-04 11:47 - 2024-01-04 11:47 - 021368608 _____ C:\Users\PC1\Downloads\win-g3060-1_4-n_mcd.exe
2024-01-04 11:47 - 2024-01-04 11:47 - 000000000 ____D C:\Users\PC1\Downloads\win-g3060-1_4-n_mcd
2024-01-03 16:55 - 2024-01-03 16:55 - 000047870 _____ C:\Users\PC1\Downloads\[SkT]Kingdom_Rush_-_Vengeance.torrent
2024-01-03 16:54 - 2024-01-03 16:54 - 001893949 _____ C:\Users\PC1\Downloads\Hogwarts_Legacy_CZ_V094.zip
2024-01-03 11:02 - 2024-01-03 11:02 - 000172022 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_Update_3_ _crack (1).torrent
2024-01-02 15:34 - 2024-01-02 15:34 - 000831947 _____ C:\Users\PC1\Downloads\Hogwarts.Legacy.v1.0-v20230504.Plus.32.Trainer-FLiNG.zip
2024-01-02 12:40 - 2024-01-02 12:40 - 000002780 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_(0.9) (1).torrent
2024-01-02 12:37 - 2024-01-02 21:04 - 000000000 ____D C:\ProgramData\Hogwarts Legacy
2024-01-02 12:37 - 2024-01-02 12:37 - 000000000 ____D C:\Users\PC1\AppData\Local\Phoenix
2024-01-02 11:21 - 2024-01-02 11:21 - 000000769 _____ C:\Users\Public\Desktop\Hogwarts Legacy CZ.lnk
2024-01-02 11:21 - 2024-01-02 11:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hogwarts Legacy CZ
2024-01-02 09:45 - 2024-01-02 09:45 - 000172022 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_Update_3_ _crack.torrent
2024-01-01 19:36 - 2024-01-01 19:36 - 000357219 _____ C:\Users\PC1\Downloads\[SkT]Hogwarts_Legacy_CZ_Empress_b.1117238 (1).torrent
2023-12-27 21:22 - 2023-12-29 16:54 - 000000000 ____D C:\Users\PC1\AppData\Roaming\FikitRDR2
2023-12-27 21:17 - 2024-01-04 17:13 - 000000000 ____D C:\Users\PC1\Desktop\assets
2023-12-27 21:17 - 2023-12-27 21:17 - 030972948 _____ C:\Users\PC1\Desktop\Loader.exe
2023-12-27 21:17 - 2023-12-27 21:17 - 000000000 ____D C:\Users\PC1\AppData\Roaming\MyCompany
2023-12-27 21:17 - 2023-12-27 21:17 - 000000000 ____D C:\Users\PC1\AppData\Roaming\FikitNetwork
2023-12-27 20:39 - 2024-01-04 12:40 - 000000000 ____D C:\Program Files\AdGuard
2023-12-27 20:39 - 2023-12-27 20:39 - 000001938 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdGuard.lnk
2023-12-27 20:39 - 2023-12-27 20:39 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Adguard Software Limited
2023-12-27 20:39 - 2023-12-27 20:39 - 000000000 ____D C:\Users\PC1\AppData\Local\Adguard_Software_Limited
2023-12-27 20:39 - 2023-12-27 20:39 - 000000000 ____D C:\Users\Default\AppData\Roaming\Adobe
2023-12-27 20:34 - 2023-12-27 20:34 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Adguard Software Ltd
2023-12-27 20:31 - 2024-01-14 12:24 - 000000000 ____D C:\ProgramData\Adguard
2023-12-27 20:31 - 2023-12-27 20:39 - 000000972 _____ C:\Users\Public\Desktop\Adguard.lnk
2023-12-27 20:29 - 2023-12-27 20:30 - 000000000 ____D C:\Users\PC1\Downloads\ADGUARD
2023-12-27 19:39 - 2023-12-27 19:39 - 006705829 _____ C:\Users\PC1\Downloads\Adguard Premium v7.0.2617.6509 Nightly Patch.LHA
2023-12-27 19:35 - 2023-12-27 20:13 - 027862834 _____ C:\Users\PC1\Downloads\Adguard 2023 6 mesiacov.zip
2023-12-27 16:23 - 2023-12-27 16:23 - 000000223 _____ C:\Users\PC1\Desktop\Red Dead Online.url
2023-12-27 10:50 - 2023-12-27 10:50 - 021365284 _____ C:\Users\PC1\Downloads\adlock.apk
2023-12-27 10:44 - 2023-12-27 10:44 - 000003294 _____ C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (PC1)
2023-12-27 10:44 - 2023-12-27 10:44 - 000003186 _____ C:\WINDOWS\system32\Tasks\Driver Booster Scheduler
2023-12-27 10:44 - 2023-12-27 10:44 - 000003172 _____ C:\WINDOWS\system32\Tasks\Driver Booster Update
2023-12-27 10:44 - 2023-12-27 10:44 - 000002366 _____ C:\Users\Public\Desktop\Driver Booster 11.lnk
2023-12-27 10:44 - 2023-12-27 10:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 11
2023-12-27 10:42 - 2023-12-27 10:42 - 029556352 _____ (IObit ) C:\Users\PC1\Downloads\SharewareOnSale_Giveaway_Driver_Booster_11_PRO (1).exe
2023-12-27 10:41 - 2023-12-27 10:41 - 029556352 _____ (IObit ) C:\Users\PC1\Downloads\SharewareOnSale_Giveaway_Driver_Booster_11_PRO.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 109628272 _____ C:\WINDOWS\system32\amdxc64.so
2023-12-27 10:38 - 2023-12-27 10:38 - 011747104 _____ C:\WINDOWS\system32\amdsmi.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 004375072 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdadlx64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 004180000 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdadlx32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 002235424 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsasrv64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 002089912 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001701144 _____ (AMD) C:\WINDOWS\system32\amf-mft-mjpeg-decoder64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001607600 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001607600 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001378456 _____ (AMD) C:\WINDOWS\SysWOW64\amf-mft-mjpeg-decoder32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001328672 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsacli64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 001049632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdsacli32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000965664 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000933920 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000846880 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000846880 _____ C:\WINDOWS\system32\vulkaninfo.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000761376 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000727584 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000727584 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000672192 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000672192 _____ C:\WINDOWS\system32\vulkan-1.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000657792 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000657792 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000597936 _____ C:\WINDOWS\system32\GameManager64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000560160 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000557448 _____ C:\WINDOWS\system32\amdmiracast.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000539064 _____ C:\WINDOWS\system32\libsmi_guest.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000527392 _____ C:\WINDOWS\system32\atieah64.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000514480 _____ C:\WINDOWS\system32\libsmi_host.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000494008 _____ C:\WINDOWS\system32\EEURestart.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000463392 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000452536 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000423856 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000396320 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2023-12-27 10:38 - 2023-12-27 10:38 - 000256952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000219168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000200936 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000197560 _____ C:\WINDOWS\system32\mantle64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000186400 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000176560 _____ C:\WINDOWS\system32\mantleaxl64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000174624 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000166328 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000164960 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000155968 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000155968 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000155680 _____ C:\WINDOWS\SysWOW64\mantle32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000146064 _____ C:\WINDOWS\system32\atidxx64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000141272 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000139296 _____ C:\WINDOWS\SysWOW64\mantleaxl32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000138784 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000132528 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000129056 _____ C:\WINDOWS\system32\amdxc64.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000127440 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000127328 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000119984 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000108464 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000104888 _____ C:\WINDOWS\SysWOW64\amdxc32.dll
2023-12-27 10:38 - 2023-12-27 10:38 - 000064944 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2023-12-25 10:22 - 2023-12-25 10:22 - 000187338 _____ C:\Users\PC1\Downloads\[TreZzoR]BeamNG.drive [Alpha v0.30.6].torrent
2023-12-23 09:04 - 2024-01-13 20:03 - 004562448 _____ C:\Users\PC1\Desktop\Launcher.exe
2023-12-23 09:04 - 2023-12-29 17:30 - 004276752 _____ C:\Users\PC1\Desktop\Launcher15.exe
2023-12-23 05:02 - 2023-12-23 05:02 - 000033255 _____ C:\WINDOWS\system32\prfc0003.dat.tmp
2023-12-22 18:13 - 2023-12-22 18:13 - 004497936 _____ C:\Users\PC1\Downloads\Launcher14.exe
2023-12-22 11:31 - 2023-12-22 11:31 - 006527872 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2023-12-21 20:39 - 2023-12-23 09:02 - 004276752 _____ C:\WINDOWS\system32\Launcher.exe
2023-12-21 14:44 - 2023-12-21 14:44 - 001376304 _____ (Google LLC) C:\Users\PC1\Downloads\ChromeSetup.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-01-14 12:53 - 2020-12-19 10:48 - 000000000 ____D C:\FRST
2024-01-14 12:52 - 2021-03-09 15:44 - 000000000 ____D C:\Users\PC1\AppData\Local\CrashDumps
2024-01-14 12:50 - 2020-12-20 10:32 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-01-14 12:28 - 2021-12-16 21:47 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-01-14 12:28 - 2020-12-20 11:00 - 000000000 ____D C:\Program Files (x86)\Google
2024-01-13 22:18 - 2021-06-26 12:26 - 000000000 ____D C:\Program Files (x86)\Steam
2024-01-13 22:05 - 2020-12-20 10:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-01-13 20:42 - 2022-10-07 07:39 - 000000282 _____ C:\Users\PC1\Desktop\imgui.ini
2024-01-13 20:04 - 2022-10-12 06:10 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Atlas
2024-01-13 20:03 - 2023-10-14 06:47 - 000000113 _____ C:\WINDOWS\AUTH
2024-01-13 19:10 - 2020-12-20 10:55 - 000000000 ____D C:\Users\PC1\AppData\Local\D3DSCache
2024-01-13 17:07 - 2022-05-22 13:05 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Word
2024-01-13 14:05 - 2020-12-20 10:44 - 000000000 ____D C:\Users\PC1
2024-01-13 11:21 - 2023-04-05 07:10 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-01-13 11:18 - 2023-09-03 07:06 - 000001134 _____ C:\WINDOWS\system32\config\VSMIDK
2024-01-13 11:18 - 2021-01-02 12:33 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2024-01-13 11:18 - 2020-12-20 10:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-01-13 11:18 - 2020-11-07 10:27 - 000008192 ___SH C:\DumpStack.log.tmp
2024-01-13 10:52 - 2020-12-20 10:32 - 000000000 ___HD C:\Program Files\WindowsApps
2024-01-13 10:52 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-01-13 08:21 - 2020-12-23 17:30 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-01-13 08:21 - 2020-12-20 14:09 - 000918944 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2024-01-13 08:21 - 2020-12-20 11:00 - 000002259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-01-13 08:21 - 2020-12-20 11:00 - 000002218 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-01-13 08:21 - 2020-06-10 20:36 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-01-11 19:13 - 2020-12-20 11:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-01-11 19:10 - 2020-12-20 11:41 - 189718008 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-01-07 08:02 - 2020-04-13 19:05 - 000000000 ____D C:\Users\PC1\AppData\LocalLow\Adobe
2024-01-06 11:02 - 2022-04-03 10:14 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-01-06 11:01 - 2022-10-14 12:10 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-01-06 11:01 - 2022-10-14 12:10 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2024-01-05 17:17 - 2022-10-04 08:35 - 000000660 _____ C:\Users\PC1\Downloads\imgui.ini
2024-01-05 14:05 - 2021-03-29 05:02 - 000000000 ____D C:\ProgramData\IObit
2024-01-04 16:11 - 2019-12-30 14:00 - 000000000 ____D C:\Users\PC1\AppData\LocalLow\Mozilla
2024-01-04 16:08 - 2021-02-09 15:56 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2024-01-04 12:40 - 2020-12-20 10:41 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2024-01-04 12:40 - 2020-12-20 10:27 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-01-04 12:39 - 2020-12-20 10:32 - 000000000 __RSD C:\WINDOWS\Media
2024-01-04 12:38 - 2020-12-20 10:31 - 000000000 ____D C:\WINDOWS\INF
2024-01-04 12:31 - 2021-11-13 11:01 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Wise Uninstaller
2024-01-03 17:10 - 2020-12-20 10:59 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Spelling
2024-01-03 10:07 - 2020-12-20 10:28 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-01-03 09:57 - 2020-12-20 10:34 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2024-01-03 09:57 - 2020-12-20 10:34 - 000000000 ____D C:\WINDOWS\system32\WCN
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\WINDOWS\IME
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files\Windows Defender
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files\Common Files\System
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2024-01-03 09:57 - 2020-12-20 10:32 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2024-01-03 09:57 - 2020-12-20 10:27 - 000000000 ____D C:\WINDOWS\servicing
2024-01-03 09:55 - 2020-12-20 10:57 - 000000000 ____D C:\Users\PC1\AppData\Local\PlaceholderTileLogoFolder
2024-01-03 09:55 - 2020-12-20 10:55 - 000000000 ____D C:\Users\PC1\AppData\Local\Packages
2024-01-03 09:55 - 2020-12-20 10:35 - 000000000 ____D C:\WINDOWS\OCR
2024-01-02 12:37 - 2022-08-10 18:07 - 000000000 ____D C:\Users\Public\Documents\EMPRESS
2023-12-31 13:15 - 2023-05-16 16:02 - 004562448 _____ C:\Users\PC1\Downloads\Launcher.exe
2023-12-27 21:00 - 2021-06-27 06:43 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2023-12-27 20:39 - 2021-10-17 12:09 - 000000000 ____D C:\ProgramData\Package Cache
2023-12-27 17:35 - 2023-05-16 16:02 - 004276752 _____ C:\Users\PC1\Downloads\Launcher15.exe
2023-12-27 16:23 - 2020-01-08 09:46 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-12-27 10:44 - 2021-03-29 05:02 - 000000000 ____D C:\Program Files (x86)\IObit
2023-12-27 10:43 - 2023-04-05 07:10 - 000000000 ____D C:\Program Files\CCleaner
2023-12-27 10:43 - 2021-09-17 19:29 - 000000000 ____D C:\ProgramData\ProductData
2023-12-27 10:38 - 2022-01-30 14:10 - 000177856 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
2023-12-27 10:38 - 2021-01-08 09:29 - 000222688 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
2023-12-27 10:30 - 2022-01-30 17:11 - 000000000 ____D C:\Users\PC1\AppData\Roaming\IObit
2023-12-27 10:25 - 2022-02-06 14:04 - 000000000 ____D C:\Users\PC1\AppData\Roaming\uTorrent
2023-12-25 20:53 - 2021-12-07 12:48 - 000000000 ____D C:\Users\PC1\AppData\Local\BeamNG.drive
2023-12-23 17:31 - 2021-01-22 21:06 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-12-23 16:54 - 2022-11-26 06:18 - 000000187 _____ C:\WINDOWS\system32\imgui.ini
2023-12-23 09:01 - 2021-06-26 12:27 - 000000000 ____D C:\Users\PC1\AppData\Local\Steam
2023-12-22 18:15 - 2023-10-21 14:58 - 004497936 _____ C:\WINDOWS\system32\Launcher14.exe
2023-12-22 11:33 - 2023-04-05 07:10 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2023-12-22 09:18 - 2020-12-20 10:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2023-12-22 09:08 - 2023-04-05 07:10 - 000003382 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2023-12-21 20:45 - 2023-05-23 20:38 - 000000000 ____D C:\Users\PC1\AppData\Local\ElevatedDiagnostics
2023-12-21 20:31 - 2021-01-03 15:05 - 000000000 ____D C:\Program Files\Rockstar Games
2023-12-21 20:31 - 2021-01-03 15:05 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2023-12-21 14:43 - 2022-04-24 19:02 - 000003828 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA{DF0D55E6-D4D6-4216-AF10-109ABF22750F}
2023-12-21 14:43 - 2022-04-24 19:02 - 000003704 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore{05E95706-AA36-4A71-B668-2969215B9D40}
2023-12-21 14:41 - 2021-10-08 18:04 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Kodi
2023-12-21 14:38 - 2022-05-12 19:30 - 000655014 _____ C:\WINDOWS\system32\perfh01B.dat
2023-12-21 14:38 - 2022-05-12 19:30 - 000126024 _____ C:\WINDOWS\system32\perfc01B.dat
2023-12-21 14:38 - 2022-02-10 22:30 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2023-12-21 14:38 - 2022-01-22 13:11 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2023-12-21 14:38 - 2020-12-20 10:53 - 001547404 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-12-21 14:38 - 2020-12-20 10:44 - 000002365 _____ C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
==================== Files in the root of some directories ========
2023-04-17 18:04 - 2023-04-17 18:04 - 000000255 _____ () C:\ProgramData\fontcacheev1.dat
2021-06-06 09:33 - 2021-07-21 20:43 - 000000055 _____ () C:\Users\PC1\AppData\Roaming\EHWID.txt
2022-08-12 16:55 - 2023-09-16 19:35 - 000208896 _____ () C:\Users\PC1\AppData\Roaming\emp.bin
2021-06-06 09:33 - 2021-12-12 18:52 - 000000011 _____ () C:\Users\PC1\AppData\Roaming\EPW.txt
2021-06-06 09:33 - 2021-07-21 20:43 - 000000009 _____ () C:\Users\PC1\AppData\Roaming\ERole.txt
2021-06-06 09:33 - 2021-12-12 18:52 - 000000012 _____ () C:\Users\PC1\AppData\Roaming\EUser.txt
2021-03-07 19:58 - 2021-03-07 19:58 - 000016438 _____ () C:\Users\PC1\AppData\Local\partner.bmp
==================== FCheck ================================
(If an entry is included in the fixlist, the file/folder will be moved.)
FCheck: C:\WINDOWS\SysWOW64\version_IObitDel.dll [2023-04-04] <==== ATTENTION (zero byte File/Folder)
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================