Prosím o preventivní kontrolu logu
Napsal: 28 bře 2024 17:47
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28.03.2024
Ran by marti (administrator) on DESKTOP-8VOP8FR (Hewlett-Packard p6521cs-m) (28-03-2024 17:39:34)
Running from C:\Portableapps\PortableApps\FRST64\FRST64.exe
Loaded Profiles: marti
Platform: Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGUI.exe <4>
(C:\Program Files\AVG\Antivirus\AVGSvc.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\marti\AppData\Local\Microsoft\OneDrive\24.045.0303.0003\Microsoft.SharePoint.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (VideoLAN -> VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <19>
(nvvsvc.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(services.exe ->) (AnyDesk Software GmbH -> AnyDesk Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe <2>
(services.exe ->) (Ashampoo GmbH & Co. KG -> ) C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTunerService.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\afwServ.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19572536 2022-12-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [460216 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
HKLM\...\Run: [Ashampoo WinOptimizer Live-Tuner2] => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTuner2.exe [6378720 2022-01-14] (Ashampoo GmbH & Co. KG -> )
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [748624 2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45018016 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [f.lux] => C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe [1528952 2024-02-22] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [GoogleChromeAutoLaunch_5F88CFF07A6B0239025DD2C7ABAE8BA7] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [2773280 2024-03-18] (Google LLC -> Google LLC)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [MicrosoftEdgeAutoLaunch_4A886EB596DDE810C696BFE47BAAC943] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060712 2024-03-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [Microsoft.Lists] => C:\Users\marti\AppData\Local\Microsoft\OneDrive\24.045.0303.0003\Microsoft.SharePoint.exe [547768 2024-03-23] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\MountPoints2: {1a21ebfe-9d74-11e8-9923-806e6f6e6963} - "F:\startdvd.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\shj2mPC: C:\Windows\System32\spool\prtprocs\x64\shj2mpc.dll [91216 2022-01-24] (联想图像(天津)科技有限公司 -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\HP BA11 Status Monitor: C:\WINDOWS\system32\hpinkstsBA11LM.dll [331664 2012-06-12] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\shj2m Langmon: C:\WINDOWS\system32\shj2mlm.dll [44264 2019-03-31] (联想图像(天津)科技有限公司 -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{48F69C39-1356-4A7B-A899-70E3539D4982}] -> C:\Program Files (x86)\AVG\Browser\Application\122.0.24368.130\Installer\chrmstp.exe [2024-03-21] (AVG Technologies USA, LLC -> AVG Technologies)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\123.0.6312.59\Installer\chrmstp.exe [2024-03-26] (Google LLC -> Google LLC)
Startup: C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Start.exe.lnk [2023-04-25]
ShortcutTarget: Start.exe.lnk -> C:\Portableapps\Start.exe (RARE IDEAS, LLC -> PortableApps.com)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2023-01-16]
ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {E67418B5-9AD2-417A-B70A-88683B4C6E66} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [5204416 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
Task: {B3D3674D-A914-4336-A4D8-1564F78A98B6} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [3136432 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {D5FB62FB-12DB-4B5F-83CF-A852B03B2EDC} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [3136432 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {C1175E6A-6015-4965-8CDC-C3BB761457E5} - System32\Tasks\AVG\AVG Antivirus Patcher => C:\Program Files\Common Files\AVG\Icarus\avg-av\icarus.exe [7811512 2024-03-05] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {88AE53BB-F7F6-45C9-8970-5DCB9E1E8044} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2181560 2023-08-01] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {9D1A7E54-9584-4486-9324-6E52E3026893} - System32\Tasks\AVGBrowserProtectS-1-5-21-909500843-76453422-3379895302-1001 => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowserProtect.exe [1690560 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {36227EEB-4515-4C0A-BDA3-E26A93C5270B} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {9984CF99-D1AB-4490-BA76-D07A36560C3D} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {8E9B6585-CDAA-462E-AE41-762B4BD9E58B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {1D52E76C-1A73-421B-9C3C-3BC20344C7C4} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "0aadb7e4-1ad8-4f1f-b936-6e1a1dcfe210" --version "6.21.10918" --silent
Task: {C73B90AF-8BA0-407A-9394-4083886F7135} - System32\Tasks\CCleanerSkipUAC - marti => C:\Program Files\CCleaner\CCleaner.exe [38778272 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {AEC4FB71-3197-4A79-AB5B-611AB2FADA47} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [5610344 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
Task: {3FF1D48B-BF23-4603-90B9-7DBD328CD8CF} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem124.0.6359.0{79D02D85-66E8-4B79-B635-CC613E941224} => C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
Task: {2ADAA7CB-9A95-4DE1-B234-48FAF1D71BB7} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64464 2024-03-09] (HP Inc. -> HP Inc.)
Task: {1DFC10D4-809F-4ECF-8808-046ECFC5143E} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64464 2024-03-09] (HP Inc. -> HP Inc.)
Task: {D89136DA-81C6-4AF7-B5ED-BE5996D554A1} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [748624 2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
Task: {A7F671F8-6666-40BE-97A7-6E7F5E8602A8} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491744 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {7A765E38-48E7-4E56-B967-0FED88A2A3D0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491744 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {57A23AD6-D0FF-4304-980F-27CD9F3556E0} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309184 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {46B7342F-B46A-4920-A025-D28643770B4A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309184 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {E7183C1B-4D53-486F-A17C-11FB3D78252B} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [170136 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {9906AE47-AD70-42CC-9C61-69836AC0CD24} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4446400 2024-03-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {0AE9067C-3D70-4491-B0F5-B1CFBE266441} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe [526944 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {AC720F10-815D-4F54-A236-3FC1283E00A2} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671136 2024-03-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {394D9E02-D083-4D1B-94B5-45D5FEC4888B} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-909500843-76453422-3379895302-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671136 2024-03-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {88BD3502-B7A2-43E5-A118-A174F9B44C99} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34720 2024-03-23] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e62b3bb6-bf1d-4b4b-bf4e-179c945db085}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default [2024-03-12]
Edge Extension: (Avira Safe Shopping) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caiblelclndcckfafdaggpephhgfpoip [2022-04-16]
Edge Extension: (Avira Password Manager) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\emgfgdclgfeldebanedpihppahgngnle [2023-11-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-08]
Edge Extension: (Edge relevant text changes) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-08]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
FireFox:
========
FF DefaultProfile: 7927ltx3.default-1540227861642
FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\h2oul36n.default-release [2024-03-19]
FF user.js: detected! => C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\h2oul36n.default-release\user.js [2023-05-17]
FF Homepage: Mozilla\Firefox\Profiles\h2oul36n.default-release -> hxxps://www.google.com/
FF SearchPlugin: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\h2oul36n.default-release\searchplugins\mybingsearch.xml [2022-01-28]
FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642 [2024-03-28]
FF user.js: detected! => C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\user.js [2023-05-17]
FF DownloadDir: E:\Downloads
FF Homepage: Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642 -> hxxps://www.seznam.cz/
FF Extension: (AVG Online Security) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\aos@avg.com.xpi [2023-11-12]
FF Extension: (Save as PDF) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\save-as-pdf-ff@pdfcrowd.com.xpi [2022-12-17]
FF Extension: (Gesturefy) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{506e023c-7f2b-40a3-8066-bc5deb40aebe}.xpi [2024-01-09]
FF Extension: (Copy/Paste and Save tabs list) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{a596357b-5d1f-4e04-ba81-4013c6d7d34e}.xpi [2022-01-28]
FF Extension: (Video DownloadHelper) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2024-03-22]
FF Extension: (No Name) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-03-11]
FF Extension: (DownThemAll!) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2024-02-01]
FF SearchPlugin: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\searchplugins\mybingsearch.xml [2022-01-28]
FF Plugin: @java.com/DTPlugin,version=11.381.2 -> C:\Program Files\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.381.2 -> C:\Program Files\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2024-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=3 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\npAvgBrowserUpdate3.dll [2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=9 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\npAvgBrowserUpdate3.dll [2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
Chrome:
=======
CHR Profile: C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default [2024-03-24]
CHR Notifications: Default -> hxxps://www.youtube.com
CHR Extension: (Překladač Google) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-31]
CHR Extension: (Avira Password Manager) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2024-02-23]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2021-06-01]
CHR Extension: (Google+) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2018-08-11]
CHR Extension: (Legacy MindMup (discontinued)) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnenaecjcgeppfpaokiifokeieopppej [2018-08-11]
CHR Extension: (Avira Browser Safety) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2022-10-31]
CHR Extension: (Dokumenty Google offline) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-01]
CHR Extension: (Atavi bookmarks) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfephclnnkjfkfnmmcjampphpfgijgae [2018-08-11]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2024-03-01]
CHR Extension: (Chrome Remote Desktop) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2022-12-11]
CHR Extension: (Dropbox) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2018-08-11]
CHR Extension: (CrxMouse Chrome™ Gestures) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgkpaicikihijadgifklkbpdajbkhjo [2022-12-11]
CHR Extension: (uExport - Export Youtube Playlist) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lejaffghgmobbadpemdfahpemdppddmf [2022-01-29]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-08-26]
CHR Extension: (Video DownloadHelper) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2024-02-23]
CHR Extension: (Mapy Google) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2018-08-11]
CHR Extension: (AVG SafePrice | Srovnání, výhodné nabídky, kupóny) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2023-05-29]
CHR Extension: (OneDrive) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2018-08-11]
CHR Extension: (Save to Pocket) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2022-11-10]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-01]
CHR Extension: (Picasa) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2018-08-11]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-909500843-76453422-3379895302-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [5216584 2024-02-11] (AnyDesk Software GmbH -> AnyDesk Software GmbH)
S2 avg; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [802232 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R2 AVG Firewall; C:\Program Files\AVG\Antivirus\afwServ.exe [2316728 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [1217464 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [9162680 2024-03-19] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 avgm; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
S3 AVGSecureBrowserElevationService; C:\Program Files (x86)\AVG\Browser\Application\122.0.24368.130\elevation_service.exe [1753240 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480 2021-05-31] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1082784 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14097992 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
R2 FoxitReaderUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2358800 2022-05-20] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S2 GoogleUpdaterInternalService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
S2 GoogleUpdaterService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [234968 2024-03-09] (HP Inc. -> HP Inc.)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2019-12-27] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9410296 2024-01-27] (Malwarebytes Inc. -> Malwarebytes)
S3 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4490376 2020-09-18] (Logitech Inc -> Logitech)
S3 OfficeSvcManagerAddons; C:\WINDOWS\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [22384 2023-11-15] (Microsoft Windows -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [18273080 2024-03-05] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 TeraCopyService; C:\Program Files\TeraCopy\TeraCopyService.exe [112944 2020-08-15] (Code Sector -> )
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [802752 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\NisSrv.exe [3116904 2023-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\MsMpEng.exe [133584 2023-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WO_LiveService2; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTunerService.exe [307936 2022-01-14] (Ashampoo GmbH & Co. KG -> )
S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [493792 2017-10-24] (Wondershare Technology Co.,Ltd -> Wondershare)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AmUStor; C:\WINDOWS\system32\drivers\AmUStorU.sys [135296 2022-12-19] (Alcorlink Corp. -> )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R3 AVER_H193; C:\WINDOWS\system32\drivers\AVer888RC_64.sys [543616 2009-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [230968 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [379960 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [292920 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [84536 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [27760 2024-02-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [28728 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [264760 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [548920 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [93752 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [69176 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [935480 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [694728 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [201680 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [306120 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 cpuz145; no ImagePath
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 DSI_SiUSBXp_3_1; C:\WINDOWS\system32\drivers\DSI_SiUSBXp_3_1.sys [16384 2007-09-06] (Silicon Laboratories) [File not signed]
R1 googledrivefs31357; C:\WINDOWS\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys [384712 2023-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
R2 LiveTuner2PM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTuner64.sys [24200 2022-01-28] (Ashampoo GmbH & Co. KG -> )
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-02-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MDA_NTDRV; C:\WINDOWS\system32\MDA_NTDRV.sys [21208 2018-09-02] (北京铠信神州科技有限责任公司 -> )
R3 pikbd; C:\WINDOWS\System32\drivers\pikbd.sys [26088 2016-04-09] (Christian Gulden -> Christian Gulden)
R3 pimou; C:\WINDOWS\System32\drivers\pimou.sys [24600 2015-09-13] (Christian Gulden -> Christian Gulden)
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2018-03-02] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2019-04-21] (Shenzhen Wondershare Information Technology Co., Ltd. -> Apple, Inc.)
S3 usbscan; C:\WINDOWS\System32\drivers\usbscan.sys [49152 2020-08-31] (Microsoft Corporation) [File not signed]
R3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [251776 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [262648 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
R1 VBoxSup; C:\WINDOWS\system32\DRIVERS\VBoxSup.sys [1060600 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
S3 VBoxUSB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [187752 2023-07-12] (Oracle Corporation -> Oracle and/or its affiliates)
S3 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-10-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572712 2023-10-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105872 2023-10-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-23 06:40 - 2024-03-24 15:57 - 000002850 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-909500843-76453422-3379895302-1001
2024-03-23 06:40 - 2024-03-23 06:40 - 000002422 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-03-23 06:31 - 2024-03-24 11:04 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-03-19 17:54 - 2024-03-24 15:57 - 000003044 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2024-03-19 17:54 - 2024-03-19 05:48 - 000314296 _____ (Gen Digital Inc.) C:\WINDOWS\system32\avgBoot.exe
2024-03-16 06:48 - 2024-03-16 06:48 - 000873148 _____ C:\WINDOWS\Minidump\031624-46796-01.dmp
2024-03-16 06:47 - 2024-03-25 19:38 - 000008192 ___SH C:\DumpStack.log.tmp
2024-03-13 06:07 - 2024-03-13 06:07 - 000019530 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-13 06:07 - 2024-03-13 06:07 - 000019530 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-03-13 05:57 - 2024-03-13 05:57 - 000000000 ___HD C:\$WinREAgent
2024-03-08 16:53 - 2024-03-08 16:53 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-03-03 18:12 - 2024-03-03 18:12 - 000050976 _____ (Avast Software) C:\WINDOWS\system32\icarus_rvrt.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-28 17:40 - 2022-12-16 17:36 - 000000000 ____D C:\FRST
2024-03-28 17:33 - 2023-01-16 20:05 - 000000000 ____D C:\Program Files (x86)\AnyDesk
2024-03-28 17:29 - 2021-02-09 16:23 - 000000000 ____D C:\Users\marti\AppData\Roaming\vlc
2024-03-28 17:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-03-28 17:27 - 2020-08-31 21:13 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-03-28 17:27 - 2020-08-31 21:13 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-03-26 20:52 - 2020-08-31 21:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-03-26 20:52 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-03-26 17:55 - 2018-08-11 14:47 - 000000000 ____D C:\Users\marti\AppData\Local\Avg
2024-03-26 17:26 - 2021-12-18 00:28 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-03-26 17:26 - 2018-08-11 14:50 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-03-25 22:10 - 2018-08-11 19:23 - 000000000 ____D C:\Users\marti\.VirtualBox
2024-03-25 19:46 - 2019-01-30 20:14 - 000000000 ____D C:\ProgramData\VirtualBox
2024-03-25 19:42 - 2020-08-31 21:14 - 001847486 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-03-25 19:42 - 2019-12-07 15:41 - 000779128 _____ C:\WINDOWS\system32\perfh005.dat
2024-03-25 19:42 - 2019-12-07 15:41 - 000168364 _____ C:\WINDOWS\system32\perfc005.dat
2024-03-25 19:42 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2024-03-25 19:40 - 2021-09-22 17:27 - 000002140 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2024-03-25 19:38 - 2024-02-21 18:18 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-03-25 19:38 - 2020-12-21 20:50 - 000000000 ____D C:\ProgramData\AVG
2024-03-25 19:38 - 2020-08-31 21:13 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-03-25 19:38 - 2018-08-12 11:34 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2024-03-25 06:21 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-03-24 20:27 - 2020-11-25 11:25 - 000000000 ____D C:\Users\marti\AppData\Roaming\TeraCopy
2024-03-24 15:57 - 2024-02-21 18:18 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-03-24 15:57 - 2024-02-21 18:18 - 000002948 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-03-24 15:57 - 2022-12-27 16:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2024-03-24 15:57 - 2022-06-05 05:07 - 000002248 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - marti
2024-03-24 15:57 - 2022-02-15 21:26 - 000002584 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2024-03-24 15:57 - 2021-12-14 17:58 - 000003054 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-909500843-76453422-3379895302-1001
2024-03-24 15:57 - 2020-08-31 21:13 - 000003094 _____ C:\WINDOWS\system32\Tasks\Java Platform SE Auto Updater
2024-03-24 15:48 - 2018-12-16 17:44 - 000000000 ____D C:\Users\marti\AppData\Roaming\avidemux
2024-03-24 11:18 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-03-24 11:04 - 2018-08-11 16:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-03-23 06:00 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-03-21 20:24 - 2018-09-27 18:06 - 000000000 ____D C:\Users\marti\AppData\Local\CrashDumps
2024-03-21 18:29 - 2022-01-04 17:51 - 000002381 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Secure Browser.lnk
2024-03-21 18:25 - 2023-05-24 06:16 - 000000000 ____D C:\Program Files\RUXIM
2024-03-19 17:54 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2024-03-19 05:57 - 2021-01-30 09:34 - 000000000 ____D C:\Program Files\CCleaner
2024-03-16 17:19 - 2020-08-10 04:47 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-03-16 06:57 - 2018-08-11 16:11 - 000000000 ____D C:\Program Files\Microsoft Office
2024-03-16 06:49 - 2021-07-11 16:08 - 000000000 ____D C:\WINDOWS\Minidump
2024-03-16 06:48 - 2023-11-03 17:01 - 775277454 _____ C:\WINDOWS\MEMORY.DMP
2024-03-14 17:36 - 2023-11-04 11:05 - 000002205 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk
2024-03-14 17:34 - 2023-11-21 06:06 - 000446096 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-03-14 08:17 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2024-03-14 08:10 - 2018-08-11 14:44 - 000000000 ____D C:\Users\marti\AppData\Local\Packages
2024-03-13 06:11 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-03-13 06:07 - 2020-08-31 21:05 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-13 05:57 - 2018-08-11 16:13 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-03-13 05:50 - 2018-08-11 16:13 - 190470136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-03-12 23:18 - 2018-08-12 11:30 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\PowerPoint
2024-03-11 17:00 - 2018-09-07 16:58 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Excel
2024-03-11 17:00 - 2018-08-12 08:11 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Word
2024-03-10 06:32 - 2018-09-08 11:39 - 000000000 ____D C:\Users\marti\AppData\Roaming\foobar2000
2024-03-09 15:10 - 2022-03-24 18:15 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2024-03-09 15:10 - 2022-01-26 17:22 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2024-03-05 06:02 - 2018-08-11 14:49 - 000000000 ____D C:\Program Files (x86)\Google
2024-03-03 18:13 - 2021-06-16 05:23 - 000002029 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Internet Security.lnk
2024-03-03 18:13 - 2020-08-31 21:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG
2024-03-03 18:12 - 2018-09-24 18:52 - 000000000 ____D C:\Program Files\AVG
2024-03-03 18:12 - 2018-09-16 10:16 - 000000000 ____D C:\Program Files\Common Files\AVG
==================== Files in the root of some directories ========
2023-04-07 21:30 - 2023-07-22 08:44 - 000000000 _____ () C:\Users\marti\yt-dlp.exe
2023-12-02 15:11 - 2023-12-02 15:11 - 000000012 _____ () C:\Users\marti\AppData\Roaming\2457fe3357cbf1220231e8917326f70f
2020-03-18 13:55 - 2020-03-18 13:55 - 000000017 _____ () C:\Users\marti\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by marti (administrator) on DESKTOP-8VOP8FR (Hewlett-Packard p6521cs-m) (28-03-2024 17:39:34)
Running from C:\Portableapps\PortableApps\FRST64\FRST64.exe
Loaded Profiles: marti
Platform: Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGUI.exe <4>
(C:\Program Files\AVG\Antivirus\AVGSvc.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\marti\AppData\Local\Microsoft\OneDrive\24.045.0303.0003\Microsoft.SharePoint.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (VideoLAN -> VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <19>
(nvvsvc.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(services.exe ->) (AnyDesk Software GmbH -> AnyDesk Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe <2>
(services.exe ->) (Ashampoo GmbH & Co. KG -> ) C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTunerService.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\afwServ.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19572536 2022-12-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [460216 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
HKLM\...\Run: [Ashampoo WinOptimizer Live-Tuner2] => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTuner2.exe [6378720 2022-01-14] (Ashampoo GmbH & Co. KG -> )
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [748624 2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45018016 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [f.lux] => C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe [1528952 2024-02-22] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [GoogleChromeAutoLaunch_5F88CFF07A6B0239025DD2C7ABAE8BA7] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [2773280 2024-03-18] (Google LLC -> Google LLC)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [MicrosoftEdgeAutoLaunch_4A886EB596DDE810C696BFE47BAAC943] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060712 2024-03-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Run: [Microsoft.Lists] => C:\Users\marti\AppData\Local\Microsoft\OneDrive\24.045.0303.0003\Microsoft.SharePoint.exe [547768 2024-03-23] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-909500843-76453422-3379895302-1001\...\MountPoints2: {1a21ebfe-9d74-11e8-9923-806e6f6e6963} - "F:\startdvd.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\89.0.2.0\GoogleDriveFS.exe [60206368 2024-03-25] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\shj2mPC: C:\Windows\System32\spool\prtprocs\x64\shj2mpc.dll [91216 2022-01-24] (联想图像(天津)科技有限公司 -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\HP BA11 Status Monitor: C:\WINDOWS\system32\hpinkstsBA11LM.dll [331664 2012-06-12] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\shj2m Langmon: C:\WINDOWS\system32\shj2mlm.dll [44264 2019-03-31] (联想图像(天津)科技有限公司 -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{48F69C39-1356-4A7B-A899-70E3539D4982}] -> C:\Program Files (x86)\AVG\Browser\Application\122.0.24368.130\Installer\chrmstp.exe [2024-03-21] (AVG Technologies USA, LLC -> AVG Technologies)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\123.0.6312.59\Installer\chrmstp.exe [2024-03-26] (Google LLC -> Google LLC)
Startup: C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Start.exe.lnk [2023-04-25]
ShortcutTarget: Start.exe.lnk -> C:\Portableapps\Start.exe (RARE IDEAS, LLC -> PortableApps.com)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2023-01-16]
ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {E67418B5-9AD2-417A-B70A-88683B4C6E66} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [5204416 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
Task: {B3D3674D-A914-4336-A4D8-1564F78A98B6} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [3136432 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {D5FB62FB-12DB-4B5F-83CF-A852B03B2EDC} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [3136432 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {C1175E6A-6015-4965-8CDC-C3BB761457E5} - System32\Tasks\AVG\AVG Antivirus Patcher => C:\Program Files\Common Files\AVG\Icarus\avg-av\icarus.exe [7811512 2024-03-05] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {88AE53BB-F7F6-45C9-8970-5DCB9E1E8044} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2181560 2023-08-01] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {9D1A7E54-9584-4486-9324-6E52E3026893} - System32\Tasks\AVGBrowserProtectS-1-5-21-909500843-76453422-3379895302-1001 => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowserProtect.exe [1690560 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {36227EEB-4515-4C0A-BDA3-E26A93C5270B} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {9984CF99-D1AB-4490-BA76-D07A36560C3D} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {8E9B6585-CDAA-462E-AE41-762B4BD9E58B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {1D52E76C-1A73-421B-9C3C-3BC20344C7C4} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "0aadb7e4-1ad8-4f1f-b936-6e1a1dcfe210" --version "6.21.10918" --silent
Task: {C73B90AF-8BA0-407A-9394-4083886F7135} - System32\Tasks\CCleanerSkipUAC - marti => C:\Program Files\CCleaner\CCleaner.exe [38778272 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {AEC4FB71-3197-4A79-AB5B-611AB2FADA47} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [5610344 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
Task: {3FF1D48B-BF23-4603-90B9-7DBD328CD8CF} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem124.0.6359.0{79D02D85-66E8-4B79-B635-CC613E941224} => C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
Task: {2ADAA7CB-9A95-4DE1-B234-48FAF1D71BB7} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64464 2024-03-09] (HP Inc. -> HP Inc.)
Task: {1DFC10D4-809F-4ECF-8808-046ECFC5143E} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64464 2024-03-09] (HP Inc. -> HP Inc.)
Task: {D89136DA-81C6-4AF7-B5ED-BE5996D554A1} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [748624 2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
Task: {A7F671F8-6666-40BE-97A7-6E7F5E8602A8} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491744 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {7A765E38-48E7-4E56-B967-0FED88A2A3D0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491744 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {57A23AD6-D0FF-4304-980F-27CD9F3556E0} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309184 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {46B7342F-B46A-4920-A025-D28643770B4A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309184 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {E7183C1B-4D53-486F-A17C-11FB3D78252B} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [170136 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {9906AE47-AD70-42CC-9C61-69836AC0CD24} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4446400 2024-03-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {0AE9067C-3D70-4491-B0F5-B1CFBE266441} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe [526944 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {AC720F10-815D-4F54-A236-3FC1283E00A2} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671136 2024-03-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {394D9E02-D083-4D1B-94B5-45D5FEC4888B} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-909500843-76453422-3379895302-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671136 2024-03-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {88BD3502-B7A2-43E5-A118-A174F9B44C99} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34720 2024-03-23] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e62b3bb6-bf1d-4b4b-bf4e-179c945db085}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default [2024-03-12]
Edge Extension: (Avira Safe Shopping) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caiblelclndcckfafdaggpephhgfpoip [2022-04-16]
Edge Extension: (Avira Password Manager) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\emgfgdclgfeldebanedpihppahgngnle [2023-11-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-08]
Edge Extension: (Edge relevant text changes) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-08]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
FireFox:
========
FF DefaultProfile: 7927ltx3.default-1540227861642
FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\h2oul36n.default-release [2024-03-19]
FF user.js: detected! => C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\h2oul36n.default-release\user.js [2023-05-17]
FF Homepage: Mozilla\Firefox\Profiles\h2oul36n.default-release -> hxxps://www.google.com/
FF SearchPlugin: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\h2oul36n.default-release\searchplugins\mybingsearch.xml [2022-01-28]
FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642 [2024-03-28]
FF user.js: detected! => C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\user.js [2023-05-17]
FF DownloadDir: E:\Downloads
FF Homepage: Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642 -> hxxps://www.seznam.cz/
FF Extension: (AVG Online Security) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\aos@avg.com.xpi [2023-11-12]
FF Extension: (Save as PDF) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\save-as-pdf-ff@pdfcrowd.com.xpi [2022-12-17]
FF Extension: (Gesturefy) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{506e023c-7f2b-40a3-8066-bc5deb40aebe}.xpi [2024-01-09]
FF Extension: (Copy/Paste and Save tabs list) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{a596357b-5d1f-4e04-ba81-4013c6d7d34e}.xpi [2022-01-28]
FF Extension: (Video DownloadHelper) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2024-03-22]
FF Extension: (No Name) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-03-11]
FF Extension: (DownThemAll!) - C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2024-02-01]
FF SearchPlugin: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\7927ltx3.default-1540227861642\searchplugins\mybingsearch.xml [2022-01-28]
FF Plugin: @java.com/DTPlugin,version=11.381.2 -> C:\Program Files\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.381.2 -> C:\Program Files\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-06-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2024-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=3 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\npAvgBrowserUpdate3.dll [2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=9 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\npAvgBrowserUpdate3.dll [2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
Chrome:
=======
CHR Profile: C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default [2024-03-24]
CHR Notifications: Default -> hxxps://www.youtube.com
CHR Extension: (Překladač Google) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-31]
CHR Extension: (Avira Password Manager) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2024-02-23]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2021-06-01]
CHR Extension: (Google+) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2018-08-11]
CHR Extension: (Legacy MindMup (discontinued)) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnenaecjcgeppfpaokiifokeieopppej [2018-08-11]
CHR Extension: (Avira Browser Safety) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2022-10-31]
CHR Extension: (Dokumenty Google offline) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-01]
CHR Extension: (Atavi bookmarks) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfephclnnkjfkfnmmcjampphpfgijgae [2018-08-11]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2024-03-01]
CHR Extension: (Chrome Remote Desktop) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2022-12-11]
CHR Extension: (Dropbox) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2018-08-11]
CHR Extension: (CrxMouse Chrome™ Gestures) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgkpaicikihijadgifklkbpdajbkhjo [2022-12-11]
CHR Extension: (uExport - Export Youtube Playlist) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lejaffghgmobbadpemdfahpemdppddmf [2022-01-29]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-08-26]
CHR Extension: (Video DownloadHelper) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2024-02-23]
CHR Extension: (Mapy Google) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2018-08-11]
CHR Extension: (AVG SafePrice | Srovnání, výhodné nabídky, kupóny) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2023-05-29]
CHR Extension: (OneDrive) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2018-08-11]
CHR Extension: (Save to Pocket) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2022-11-10]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-01]
CHR Extension: (Picasa) - C:\Users\marti\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2018-08-11]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-909500843-76453422-3379895302-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [5216584 2024-02-11] (AnyDesk Software GmbH -> AnyDesk Software GmbH)
S2 avg; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [802232 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R2 AVG Firewall; C:\Program Files\AVG\Antivirus\afwServ.exe [2316728 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [1217464 2024-03-19] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [9162680 2024-03-19] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 avgm; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2022-12-13] (AVG Technologies USA, LLC -> AVG Technologies)
S3 AVGSecureBrowserElevationService; C:\Program Files (x86)\AVG\Browser\Application\122.0.24368.130\elevation_service.exe [1753240 2024-03-14] (AVG Technologies USA, LLC -> AVG Technologies)
R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480 2021-05-31] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1082784 2024-02-05] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14097992 2024-03-16] (Microsoft Corporation -> Microsoft Corporation)
R2 FoxitReaderUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2358800 2022-05-20] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S2 GoogleUpdaterInternalService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
S2 GoogleUpdaterService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [234968 2024-03-09] (HP Inc. -> HP Inc.)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2019-12-27] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9410296 2024-01-27] (Malwarebytes Inc. -> Malwarebytes)
S3 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4490376 2020-09-18] (Logitech Inc -> Logitech)
S3 OfficeSvcManagerAddons; C:\WINDOWS\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [22384 2023-11-15] (Microsoft Windows -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [18273080 2024-03-05] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 TeraCopyService; C:\Program Files\TeraCopy\TeraCopyService.exe [112944 2020-08-15] (Code Sector -> )
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [802752 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\NisSrv.exe [3116904 2023-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\MsMpEng.exe [133584 2023-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WO_LiveService2; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTunerService.exe [307936 2022-01-14] (Ashampoo GmbH & Co. KG -> )
S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [493792 2017-10-24] (Wondershare Technology Co.,Ltd -> Wondershare)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AmUStor; C:\WINDOWS\system32\drivers\AmUStorU.sys [135296 2022-12-19] (Alcorlink Corp. -> )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R3 AVER_H193; C:\WINDOWS\system32\drivers\AVer888RC_64.sys [543616 2009-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [230968 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [379960 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [292920 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [84536 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [27760 2024-02-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [28728 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [264760 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [548920 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [93752 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [69176 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [935480 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [694728 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [201680 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [306120 2024-03-19] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 cpuz145; no ImagePath
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 DSI_SiUSBXp_3_1; C:\WINDOWS\system32\drivers\DSI_SiUSBXp_3_1.sys [16384 2007-09-06] (Silicon Laboratories) [File not signed]
R1 googledrivefs31357; C:\WINDOWS\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys [384712 2023-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
R2 LiveTuner2PM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 19\LiveTuner64.sys [24200 2022-01-28] (Ashampoo GmbH & Co. KG -> )
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-02-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MDA_NTDRV; C:\WINDOWS\system32\MDA_NTDRV.sys [21208 2018-09-02] (北京铠信神州科技有限责任公司 -> )
R3 pikbd; C:\WINDOWS\System32\drivers\pikbd.sys [26088 2016-04-09] (Christian Gulden -> Christian Gulden)
R3 pimou; C:\WINDOWS\System32\drivers\pimou.sys [24600 2015-09-13] (Christian Gulden -> Christian Gulden)
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2018-03-02] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2019-04-21] (Shenzhen Wondershare Information Technology Co., Ltd. -> Apple, Inc.)
S3 usbscan; C:\WINDOWS\System32\drivers\usbscan.sys [49152 2020-08-31] (Microsoft Corporation) [File not signed]
R3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [251776 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [262648 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
R1 VBoxSup; C:\WINDOWS\system32\DRIVERS\VBoxSup.sys [1060600 2023-10-12] (Oracle Corporation -> Oracle and/or its affiliates)
S3 VBoxUSB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [187752 2023-07-12] (Oracle Corporation -> Oracle and/or its affiliates)
S3 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-10-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572712 2023-10-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105872 2023-10-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-23 06:40 - 2024-03-24 15:57 - 000002850 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-909500843-76453422-3379895302-1001
2024-03-23 06:40 - 2024-03-23 06:40 - 000002422 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-03-23 06:31 - 2024-03-24 11:04 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-03-19 17:54 - 2024-03-24 15:57 - 000003044 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2024-03-19 17:54 - 2024-03-19 05:48 - 000314296 _____ (Gen Digital Inc.) C:\WINDOWS\system32\avgBoot.exe
2024-03-16 06:48 - 2024-03-16 06:48 - 000873148 _____ C:\WINDOWS\Minidump\031624-46796-01.dmp
2024-03-16 06:47 - 2024-03-25 19:38 - 000008192 ___SH C:\DumpStack.log.tmp
2024-03-13 06:07 - 2024-03-13 06:07 - 000019530 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-13 06:07 - 2024-03-13 06:07 - 000019530 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-03-13 05:57 - 2024-03-13 05:57 - 000000000 ___HD C:\$WinREAgent
2024-03-08 16:53 - 2024-03-08 16:53 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-03-03 18:12 - 2024-03-03 18:12 - 000050976 _____ (Avast Software) C:\WINDOWS\system32\icarus_rvrt.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-28 17:40 - 2022-12-16 17:36 - 000000000 ____D C:\FRST
2024-03-28 17:33 - 2023-01-16 20:05 - 000000000 ____D C:\Program Files (x86)\AnyDesk
2024-03-28 17:29 - 2021-02-09 16:23 - 000000000 ____D C:\Users\marti\AppData\Roaming\vlc
2024-03-28 17:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-03-28 17:27 - 2020-08-31 21:13 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-03-28 17:27 - 2020-08-31 21:13 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-03-26 20:52 - 2020-08-31 21:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-03-26 20:52 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-03-26 17:55 - 2018-08-11 14:47 - 000000000 ____D C:\Users\marti\AppData\Local\Avg
2024-03-26 17:26 - 2021-12-18 00:28 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-03-26 17:26 - 2018-08-11 14:50 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-03-25 22:10 - 2018-08-11 19:23 - 000000000 ____D C:\Users\marti\.VirtualBox
2024-03-25 19:46 - 2019-01-30 20:14 - 000000000 ____D C:\ProgramData\VirtualBox
2024-03-25 19:42 - 2020-08-31 21:14 - 001847486 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-03-25 19:42 - 2019-12-07 15:41 - 000779128 _____ C:\WINDOWS\system32\perfh005.dat
2024-03-25 19:42 - 2019-12-07 15:41 - 000168364 _____ C:\WINDOWS\system32\perfc005.dat
2024-03-25 19:42 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2024-03-25 19:40 - 2021-09-22 17:27 - 000002140 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2024-03-25 19:38 - 2024-02-21 18:18 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-03-25 19:38 - 2020-12-21 20:50 - 000000000 ____D C:\ProgramData\AVG
2024-03-25 19:38 - 2020-08-31 21:13 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-03-25 19:38 - 2018-08-12 11:34 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2024-03-25 06:21 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-03-24 20:27 - 2020-11-25 11:25 - 000000000 ____D C:\Users\marti\AppData\Roaming\TeraCopy
2024-03-24 15:57 - 2024-02-21 18:18 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-03-24 15:57 - 2024-02-21 18:18 - 000002948 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-03-24 15:57 - 2022-12-27 16:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2024-03-24 15:57 - 2022-06-05 05:07 - 000002248 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - marti
2024-03-24 15:57 - 2022-02-15 21:26 - 000002584 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2024-03-24 15:57 - 2021-12-14 17:58 - 000003054 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-909500843-76453422-3379895302-1001
2024-03-24 15:57 - 2020-08-31 21:13 - 000003094 _____ C:\WINDOWS\system32\Tasks\Java Platform SE Auto Updater
2024-03-24 15:48 - 2018-12-16 17:44 - 000000000 ____D C:\Users\marti\AppData\Roaming\avidemux
2024-03-24 11:18 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-03-24 11:04 - 2018-08-11 16:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-03-23 06:00 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-03-21 20:24 - 2018-09-27 18:06 - 000000000 ____D C:\Users\marti\AppData\Local\CrashDumps
2024-03-21 18:29 - 2022-01-04 17:51 - 000002381 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Secure Browser.lnk
2024-03-21 18:25 - 2023-05-24 06:16 - 000000000 ____D C:\Program Files\RUXIM
2024-03-19 17:54 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2024-03-19 05:57 - 2021-01-30 09:34 - 000000000 ____D C:\Program Files\CCleaner
2024-03-16 17:19 - 2020-08-10 04:47 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-03-16 06:57 - 2018-08-11 16:11 - 000000000 ____D C:\Program Files\Microsoft Office
2024-03-16 06:49 - 2021-07-11 16:08 - 000000000 ____D C:\WINDOWS\Minidump
2024-03-16 06:48 - 2023-11-03 17:01 - 775277454 _____ C:\WINDOWS\MEMORY.DMP
2024-03-14 17:36 - 2023-11-04 11:05 - 000002205 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk
2024-03-14 17:34 - 2023-11-21 06:06 - 000446096 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-03-14 08:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-03-14 08:17 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2024-03-14 08:10 - 2018-08-11 14:44 - 000000000 ____D C:\Users\marti\AppData\Local\Packages
2024-03-13 06:11 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-03-13 06:07 - 2020-08-31 21:05 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-13 05:57 - 2018-08-11 16:13 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-03-13 05:50 - 2018-08-11 16:13 - 190470136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-03-12 23:18 - 2018-08-12 11:30 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\PowerPoint
2024-03-11 17:00 - 2018-09-07 16:58 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Excel
2024-03-11 17:00 - 2018-08-12 08:11 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Word
2024-03-10 06:32 - 2018-09-08 11:39 - 000000000 ____D C:\Users\marti\AppData\Roaming\foobar2000
2024-03-09 15:10 - 2022-03-24 18:15 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2024-03-09 15:10 - 2022-01-26 17:22 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2024-03-05 06:02 - 2018-08-11 14:49 - 000000000 ____D C:\Program Files (x86)\Google
2024-03-03 18:13 - 2021-06-16 05:23 - 000002029 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Internet Security.lnk
2024-03-03 18:13 - 2020-08-31 21:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG
2024-03-03 18:12 - 2018-09-24 18:52 - 000000000 ____D C:\Program Files\AVG
2024-03-03 18:12 - 2018-09-16 10:16 - 000000000 ____D C:\Program Files\Common Files\AVG
==================== Files in the root of some directories ========
2023-04-07 21:30 - 2023-07-22 08:44 - 000000000 _____ () C:\Users\marti\yt-dlp.exe
2023-12-02 15:11 - 2023-12-02 15:11 - 000000012 _____ () C:\Users\marti\AppData\Roaming\2457fe3357cbf1220231e8917326f70f
2020-03-18 13:55 - 2020-03-18 13:55 - 000000017 _____ () C:\Users\marti\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================