Preventína kontrola FRST logu
Napsal: 11 čer 2024 01:45
Zdravím opäť po dlhšej dobe, poprosil by som miestnych odborníkov o skontrolovanie môjho logu z FRST, PC skenované s MBAM, žiadny nález...vopred veľká vďaka.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09.06.2024
Ran by Venom (administrator) on BLACKMESA (11-06-2024 02:36:26)
Running from C:\Users\Venom\Desktop\FRST64.exe
Loaded Profiles: Venom
Platform: Microsoft Windows 10 Home Version 22H2 19045.4412 (X64) Language: Slovenčina (Slovensko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe ->) (Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe <5>
(C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
(C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe ->) (Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files (x86)\Total Commander\TOTALCMD.EXE
(explorer.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <14>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3c2bd4a1ec6d228e\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (O and O Software GmbH -> O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
(services.exe ->) (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9228800 2017-06-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [750672 2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3985067572-2050150969-3629286671-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3593992 2024-05-15] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-3985067572-2050150969-3629286671-1001\...\Run: [MicrosoftEdgeAutoLaunch_4A039EEDA5C853976BEFA043AA5BAFE2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4136912 2024-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3593992 2024-05-15] (Razer USA Ltd. -> Razer Inc.)
HKLM\...\Windows x64\Print Processors\BJ Print Processor3: C:\Windows\System32\spool\prtprocs\x64\CNBPP3.DLL [83968 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\BJ Language Monitor3_2: c:\windows\system32\CNBLM3_2.DLL [211456 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\...\AppCompatFlags\Custom\game.exe: [{3f4535f8-e996-4cf1-bb6d-66eb87969155}.sdb] -> TS Compatibility Fix
HKLM\Software\...\AppCompatFlags\InstalledSDB\{3f4535f8-e996-4cf1-bb6d-66eb87969155}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{3f4535f8-e996-4cf1-bb6d-66eb87969155}.sdb [2015-09-01]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5D6C356E-ED55-4AC4-ACD4-971CD1FDEAA7} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-04-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {BF9D9EAF-5CEC-4E9D-91F3-43C7D8DD5C29} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-04-10] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "a717e580-b8bd-4e5d-ab36-0752e510b8ad" --version "6.23.11010" --silent
Task: {75096DF4-9C84-4097-B360-393811446C35} - System32\Tasks\CCleanerSkipUAC - Venom => C:\Program Files\CCleaner\CCleaner.exe [39118752 2024-04-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {86B006D6-9B4E-4FDD-8572-2A58563BB815} - System32\Tasks\CreateExplorerShellUnelevatedTask => c:\Windows\explorer.exe [5672240 2024-05-15] (Microsoft Windows -> Microsoft Corporation)
Task: {5839B385-0B04-4A4C-9521-6B64C075186F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28498912 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {58DAFC71-7F37-4813-9ABC-94C6CE3CEA93} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28498912 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {EF809197-C4AB-49D0-98FF-DB479A6420BB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [221336 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {8B017B3E-28D9-4D15-BCC1-44C007029287} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [221336 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0A795F3-CB5E-4784-8781-3A67F4062C86} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3D401ABA-CB1C-4854-93F7-01EF02C0DAE1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CE30EE75-451F-4BA5-AB2F-2330D0347038} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {419BF3F9-A87D-4850-AB99-94C3D5C2BF9C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D4303B15-CCB2-440A-B868-424E3886E86F} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (No File)
Task: {1FAC63E1-7F86-4563-8E47-6FB5FEFBF651} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (No File)
Task: {3DF5FD6D-C870-4126-9BDA-54D809EE4B3F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe (No File)
Task: {CC3BA4A2-6CA0-43A7-B9A3-1E7E54B39F1E} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33696 2024-05-29] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{73aeb62c-0040-447b-bd1f-edc735186fdc}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default [2024-06-11]
Edge HomePage: Default -> hxxp://www.google.sk/
Edge StartupUrls: Default -> "hxxp://www.google.sk/"
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-05]
Edge Extension: (Edge relevant text changes) - C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2024-06-05]
FireFox:
========
FF DefaultProfile: 5a6mqd52.default
FF ProfilePath: C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default [2024-06-11]
FF Homepage: Mozilla\Firefox\Profiles\5a6mqd52.default -> hxxps://www.google.sk/
FF NetworkProxy: Mozilla\Firefox\Profiles\5a6mqd52.default -> type", 0
FF Notifications: Mozilla\Firefox\Profiles\5a6mqd52.default -> hxxps://mkmobileupdate.com; hxxps://prekladyher.eu
FF Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2024-06-10]
FF Extension: (Firefox & Windows) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\{02f6fd6e-a416-49e0-ae4d-25ca32c9c298}.xpi [2020-09-22]
FF Extension: (Firefox Shine) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\{1370b22e-f79a-4912-8521-adfa41d2a083}.xpi [2020-09-22]
FF Extension: (Firefox suave) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\{abe35f4b-3e9a-4838-b453-324795885f27}.xpi [2020-09-22]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.411.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.411.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [2568840 2024-05-30] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14012520 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [14991976 2024-04-22] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811120 2019-11-25] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 FoxitReaderUpdateService; C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2432608 2023-08-14] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [2348880 2024-05-14] (GOG sp. z o.o -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7178064 2024-05-14] (GOG sp. z o.o -> GOG.com)
R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8887264 2024-06-11] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe [1505416 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [3051848 2011-01-25] (O and O Software GmbH -> O&O Software GmbH)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [256264 2023-02-10] (Razer USA Ltd. -> Razer Inc)
R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [298248 2024-05-14] (Razer USA Ltd. -> Razer Inc.)
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [538424 2023-11-09] (Razer USA Ltd. -> Razer Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe [3236728 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe [133704 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3c2bd4a1ec6d228e\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3c2bd4a1ec6d228e\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [42616 2017-05-14] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223184 2024-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-08-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [64168 2022-08-18] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_006e; C:\WINDOWS\System32\drivers\RzDev_006e.sys [56152 2021-03-22] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0221; C:\WINDOWS\System32\drivers\RzDev_0221.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0306; C:\WINDOWS\System32\drivers\RzDev_0306.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S2 SecDrv; C:\WINDOWS\SysWOW64\drivers\SECDRV.SYS [12400 2021-03-19] (Macrovision Europe Ltd) [File not signed]
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 VClone; C:\WINDOWS\System32\drivers\VClone.sys [44544 2020-02-22] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22080 2024-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602520 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105880 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-06-11 02:36 - 2024-06-11 02:37 - 000019978 _____ C:\Users\Venom\Desktop\FRST.txt
2024-06-11 02:36 - 2024-06-11 02:36 - 000000000 ____D C:\FRST
2024-06-11 02:35 - 2024-06-11 02:35 - 002395136 _____ (Farbar) C:\Users\Venom\Desktop\FRST64.exe
2024-06-10 19:06 - 2024-06-10 19:06 - 000197424 _____ C:\WINDOWS\system32\lc.dat
2024-05-22 22:00 - 2024-05-22 22:00 - 000000000 ____D C:\Users\Venom\AppData\Roaming\d2rmm
2024-05-15 10:58 - 2024-05-15 10:58 - 000000000 ____D C:\Users\Venom\Documents\Diablo IV
2024-05-15 10:58 - 2024-05-15 10:58 - 000000000 ____D C:\Intel
2024-05-15 10:41 - 2024-05-15 10:41 - 000000461 _____ C:\Users\Public\Desktop\Diablo IV.lnk
2024-05-15 10:41 - 2024-05-15 10:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo IV
2024-05-15 10:25 - 2024-05-15 10:25 - 000000000 ___HD C:\$WinREAgent
2024-05-14 19:54 - 2024-05-14 19:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blood - Fresh Supply [GOG.com]
2024-05-14 19:29 - 2024-05-14 19:29 - 000000000 ____D C:\Users\Venom\AppData\LocalLow\Jasozz Games
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-06-11 02:35 - 2023-08-02 15:47 - 000000000 ____D C:\Users\Venom\AppData\Local\Malwarebytes
2024-06-11 02:34 - 2022-02-09 22:29 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-06-11 02:34 - 2020-12-23 12:18 - 000239576 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2024-06-11 02:21 - 2018-10-29 13:16 - 000000000 ____D C:\Users\Venom\AppData\Local\Battle.net
2024-06-10 20:30 - 2018-10-29 10:19 - 000000000 ____D C:\Program Files (x86)\Steam
2024-06-10 19:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-06-10 19:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-06-10 19:06 - 2018-10-21 15:19 - 000000000 ____D C:\Program Files\CCleaner
2024-06-10 18:57 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-06-10 18:57 - 2018-10-20 16:34 - 000000000 ____D C:\ProgramData\Packages
2024-06-10 18:57 - 2018-10-20 16:26 - 000000000 ____D C:\Users\Venom\AppData\Local\Packages
2024-06-10 18:50 - 2023-08-15 15:16 - 000000000 ____D C:\Users\Venom\AppData\Local\D3DSCache
2024-06-10 18:46 - 2018-10-29 13:15 - 000000000 ____D C:\Program Files (x86)\Battle.net
2024-06-10 18:11 - 2020-06-03 13:27 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-06-10 18:11 - 2020-06-03 13:27 - 000002295 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-06-10 18:05 - 2020-11-06 23:30 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-06-10 18:05 - 2020-11-06 23:30 - 000003508 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-06-10 18:03 - 2022-05-11 17:47 - 000655020 _____ C:\WINDOWS\system32\perfh01B.dat
2024-06-10 18:03 - 2022-05-11 17:47 - 000126030 _____ C:\WINDOWS\system32\perfc01B.dat
2024-06-10 18:03 - 2020-11-06 23:32 - 001547408 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-06-10 18:03 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-06-10 17:56 - 2023-08-15 15:08 - 000000000 ____D C:\ProgramData\NVIDIA
2024-06-10 17:56 - 2020-11-06 23:30 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-06-10 17:56 - 2020-11-06 23:17 - 000008192 ___SH C:\DumpStack.log.tmp
2024-06-05 15:34 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-06-05 15:18 - 2020-11-06 23:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-06-05 14:31 - 2021-12-14 00:43 - 000000000 ____D C:\Users\Venom\AppData\Roaming\vlc
2024-06-05 12:02 - 2018-10-20 16:21 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-06-05 12:00 - 2018-10-20 17:43 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2024-06-05 12:00 - 2018-10-20 16:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-06-04 13:45 - 2020-12-12 15:41 - 000001295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-06-04 00:56 - 2020-11-06 22:25 - 000000000 ____D C:\Users\Venom
2024-06-02 18:55 - 2019-03-12 19:03 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2024-05-31 01:04 - 2019-02-02 17:01 - 000000906 _____ C:\Users\Venom\Desktop\Diablo II - Lord of Destruction - PlugY.lnk
2024-05-30 19:01 - 2018-10-20 16:55 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-05-29 19:35 - 2018-10-20 16:55 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-05-29 19:05 - 2023-11-21 12:22 - 000000000 ____D C:\Program Files\dotnet
2024-05-29 19:05 - 2018-10-20 18:44 - 000000000 ____D C:\ProgramData\Package Cache
2024-05-25 18:40 - 2018-11-17 11:32 - 000000000 ____D C:\Users\Venom\AppData\Local\CrashDumps
2024-05-18 18:50 - 2020-04-04 12:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2024-05-15 10:50 - 2022-05-04 08:28 - 000335520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files\Windows Portable Devices
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-05-15 10:49 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2024-05-15 10:47 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-05-15 10:38 - 2020-11-06 23:20 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-05-15 10:24 - 2023-10-16 20:26 - 000000000 ____D C:\Program Files\RUXIM
2024-05-15 10:05 - 2018-10-20 17:29 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-05-15 10:01 - 2018-10-20 17:29 - 196465576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-05-14 19:58 - 2018-12-01 13:53 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy
2024-05-14 19:52 - 2021-06-23 13:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenTTD [GOG.com]
2024-05-13 22:36 - 2023-11-08 22:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PDF Reader
==================== Files in the root of some directories ========
2019-07-11 23:02 - 2019-07-11 23:02 - 000332800 _____ () C:\Users\Venom\AppData\Roaming\patcher.dll
2018-10-21 14:24 - 2019-01-31 19:42 - 000007670 _____ () C:\Users\Venom\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09.06.2024
Ran by Venom (administrator) on BLACKMESA (11-06-2024 02:36:26)
Running from C:\Users\Venom\Desktop\FRST64.exe
Loaded Profiles: Venom
Platform: Microsoft Windows 10 Home Version 22H2 19045.4412 (X64) Language: Slovenčina (Slovensko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe ->) (Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe <5>
(C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
(C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe ->) (Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files (x86)\Total Commander\TOTALCMD.EXE
(explorer.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <14>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3c2bd4a1ec6d228e\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (O and O Software GmbH -> O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
(services.exe ->) (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9228800 2017-06-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [750672 2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3985067572-2050150969-3629286671-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3593992 2024-05-15] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-3985067572-2050150969-3629286671-1001\...\Run: [MicrosoftEdgeAutoLaunch_4A039EEDA5C853976BEFA043AA5BAFE2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4136912 2024-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3593992 2024-05-15] (Razer USA Ltd. -> Razer Inc.)
HKLM\...\Windows x64\Print Processors\BJ Print Processor3: C:\Windows\System32\spool\prtprocs\x64\CNBPP3.DLL [83968 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\BJ Language Monitor3_2: c:\windows\system32\CNBLM3_2.DLL [211456 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\...\AppCompatFlags\Custom\game.exe: [{3f4535f8-e996-4cf1-bb6d-66eb87969155}.sdb] -> TS Compatibility Fix
HKLM\Software\...\AppCompatFlags\InstalledSDB\{3f4535f8-e996-4cf1-bb6d-66eb87969155}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{3f4535f8-e996-4cf1-bb6d-66eb87969155}.sdb [2015-09-01]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5D6C356E-ED55-4AC4-ACD4-971CD1FDEAA7} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-04-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {BF9D9EAF-5CEC-4E9D-91F3-43C7D8DD5C29} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-04-10] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "a717e580-b8bd-4e5d-ab36-0752e510b8ad" --version "6.23.11010" --silent
Task: {75096DF4-9C84-4097-B360-393811446C35} - System32\Tasks\CCleanerSkipUAC - Venom => C:\Program Files\CCleaner\CCleaner.exe [39118752 2024-04-10] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {86B006D6-9B4E-4FDD-8572-2A58563BB815} - System32\Tasks\CreateExplorerShellUnelevatedTask => c:\Windows\explorer.exe [5672240 2024-05-15] (Microsoft Windows -> Microsoft Corporation)
Task: {5839B385-0B04-4A4C-9521-6B64C075186F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28498912 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {58DAFC71-7F37-4813-9ABC-94C6CE3CEA93} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28498912 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {EF809197-C4AB-49D0-98FF-DB479A6420BB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [221336 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {8B017B3E-28D9-4D15-BCC1-44C007029287} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [221336 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0A795F3-CB5E-4784-8781-3A67F4062C86} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3D401ABA-CB1C-4854-93F7-01EF02C0DAE1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CE30EE75-451F-4BA5-AB2F-2330D0347038} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {419BF3F9-A87D-4850-AB99-94C3D5C2BF9C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D4303B15-CCB2-440A-B868-424E3886E86F} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (No File)
Task: {1FAC63E1-7F86-4563-8E47-6FB5FEFBF651} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (No File)
Task: {3DF5FD6D-C870-4126-9BDA-54D809EE4B3F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe (No File)
Task: {CC3BA4A2-6CA0-43A7-B9A3-1E7E54B39F1E} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33696 2024-05-29] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{73aeb62c-0040-447b-bd1f-edc735186fdc}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default [2024-06-11]
Edge HomePage: Default -> hxxp://www.google.sk/
Edge StartupUrls: Default -> "hxxp://www.google.sk/"
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-05]
Edge Extension: (Edge relevant text changes) - C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Venom\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2024-06-05]
FireFox:
========
FF DefaultProfile: 5a6mqd52.default
FF ProfilePath: C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default [2024-06-11]
FF Homepage: Mozilla\Firefox\Profiles\5a6mqd52.default -> hxxps://www.google.sk/
FF NetworkProxy: Mozilla\Firefox\Profiles\5a6mqd52.default -> type", 0
FF Notifications: Mozilla\Firefox\Profiles\5a6mqd52.default -> hxxps://mkmobileupdate.com; hxxps://prekladyher.eu
FF Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2024-06-10]
FF Extension: (Firefox & Windows) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\{02f6fd6e-a416-49e0-ae4d-25ca32c9c298}.xpi [2020-09-22]
FF Extension: (Firefox Shine) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\{1370b22e-f79a-4912-8521-adfa41d2a083}.xpi [2020-09-22]
FF Extension: (Firefox suave) - C:\Users\Venom\AppData\Roaming\Mozilla\Firefox\Profiles\5a6mqd52.default\Extensions\{abe35f4b-3e9a-4838-b453-324795885f27}.xpi [2020-09-22]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.411.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.411.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [2568840 2024-05-30] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14012520 2024-06-02] (Microsoft Corporation -> Microsoft Corporation)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [14991976 2024-04-22] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811120 2019-11-25] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 FoxitReaderUpdateService; C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2432608 2023-08-14] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [2348880 2024-05-14] (GOG sp. z o.o -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7178064 2024-05-14] (GOG sp. z o.o -> GOG.com)
R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8887264 2024-06-11] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe [1505416 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [3051848 2011-01-25] (O and O Software GmbH -> O&O Software GmbH)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [256264 2023-02-10] (Razer USA Ltd. -> Razer Inc)
R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [298248 2024-05-14] (Razer USA Ltd. -> Razer Inc.)
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [538424 2023-11-09] (Razer USA Ltd. -> Razer Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe [3236728 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe [133704 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3c2bd4a1ec6d228e\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3c2bd4a1ec6d228e\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [42616 2017-05-14] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223184 2024-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-08-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [64168 2022-08-18] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_006e; C:\WINDOWS\System32\drivers\RzDev_006e.sys [56152 2021-03-22] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0221; C:\WINDOWS\System32\drivers\RzDev_0221.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0306; C:\WINDOWS\System32\drivers\RzDev_0306.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S2 SecDrv; C:\WINDOWS\SysWOW64\drivers\SECDRV.SYS [12400 2021-03-19] (Macrovision Europe Ltd) [File not signed]
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 VClone; C:\WINDOWS\System32\drivers\VClone.sys [44544 2020-02-22] (Microsoft Windows Hardware Compatibility Publisher -> Elaborate Bytes AG)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22080 2024-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602520 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105880 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-06-11 02:36 - 2024-06-11 02:37 - 000019978 _____ C:\Users\Venom\Desktop\FRST.txt
2024-06-11 02:36 - 2024-06-11 02:36 - 000000000 ____D C:\FRST
2024-06-11 02:35 - 2024-06-11 02:35 - 002395136 _____ (Farbar) C:\Users\Venom\Desktop\FRST64.exe
2024-06-10 19:06 - 2024-06-10 19:06 - 000197424 _____ C:\WINDOWS\system32\lc.dat
2024-05-22 22:00 - 2024-05-22 22:00 - 000000000 ____D C:\Users\Venom\AppData\Roaming\d2rmm
2024-05-15 10:58 - 2024-05-15 10:58 - 000000000 ____D C:\Users\Venom\Documents\Diablo IV
2024-05-15 10:58 - 2024-05-15 10:58 - 000000000 ____D C:\Intel
2024-05-15 10:41 - 2024-05-15 10:41 - 000000461 _____ C:\Users\Public\Desktop\Diablo IV.lnk
2024-05-15 10:41 - 2024-05-15 10:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo IV
2024-05-15 10:25 - 2024-05-15 10:25 - 000000000 ___HD C:\$WinREAgent
2024-05-14 19:54 - 2024-05-14 19:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blood - Fresh Supply [GOG.com]
2024-05-14 19:29 - 2024-05-14 19:29 - 000000000 ____D C:\Users\Venom\AppData\LocalLow\Jasozz Games
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-06-11 02:35 - 2023-08-02 15:47 - 000000000 ____D C:\Users\Venom\AppData\Local\Malwarebytes
2024-06-11 02:34 - 2022-02-09 22:29 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-06-11 02:34 - 2020-12-23 12:18 - 000239576 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2024-06-11 02:21 - 2018-10-29 13:16 - 000000000 ____D C:\Users\Venom\AppData\Local\Battle.net
2024-06-10 20:30 - 2018-10-29 10:19 - 000000000 ____D C:\Program Files (x86)\Steam
2024-06-10 19:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-06-10 19:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-06-10 19:06 - 2018-10-21 15:19 - 000000000 ____D C:\Program Files\CCleaner
2024-06-10 18:57 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-06-10 18:57 - 2018-10-20 16:34 - 000000000 ____D C:\ProgramData\Packages
2024-06-10 18:57 - 2018-10-20 16:26 - 000000000 ____D C:\Users\Venom\AppData\Local\Packages
2024-06-10 18:50 - 2023-08-15 15:16 - 000000000 ____D C:\Users\Venom\AppData\Local\D3DSCache
2024-06-10 18:46 - 2018-10-29 13:15 - 000000000 ____D C:\Program Files (x86)\Battle.net
2024-06-10 18:11 - 2020-06-03 13:27 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-06-10 18:11 - 2020-06-03 13:27 - 000002295 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-06-10 18:05 - 2020-11-06 23:30 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-06-10 18:05 - 2020-11-06 23:30 - 000003508 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-06-10 18:03 - 2022-05-11 17:47 - 000655020 _____ C:\WINDOWS\system32\perfh01B.dat
2024-06-10 18:03 - 2022-05-11 17:47 - 000126030 _____ C:\WINDOWS\system32\perfc01B.dat
2024-06-10 18:03 - 2020-11-06 23:32 - 001547408 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-06-10 18:03 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-06-10 17:56 - 2023-08-15 15:08 - 000000000 ____D C:\ProgramData\NVIDIA
2024-06-10 17:56 - 2020-11-06 23:30 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-06-10 17:56 - 2020-11-06 23:17 - 000008192 ___SH C:\DumpStack.log.tmp
2024-06-05 15:34 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-06-05 15:18 - 2020-11-06 23:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-06-05 14:31 - 2021-12-14 00:43 - 000000000 ____D C:\Users\Venom\AppData\Roaming\vlc
2024-06-05 12:02 - 2018-10-20 16:21 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-06-05 12:00 - 2018-10-20 17:43 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2024-06-05 12:00 - 2018-10-20 16:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-06-04 13:45 - 2020-12-12 15:41 - 000001295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-06-04 00:56 - 2020-11-06 22:25 - 000000000 ____D C:\Users\Venom
2024-06-02 18:55 - 2019-03-12 19:03 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2024-05-31 01:04 - 2019-02-02 17:01 - 000000906 _____ C:\Users\Venom\Desktop\Diablo II - Lord of Destruction - PlugY.lnk
2024-05-30 19:01 - 2018-10-20 16:55 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-05-29 19:35 - 2018-10-20 16:55 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-05-29 19:05 - 2023-11-21 12:22 - 000000000 ____D C:\Program Files\dotnet
2024-05-29 19:05 - 2018-10-20 18:44 - 000000000 ____D C:\ProgramData\Package Cache
2024-05-25 18:40 - 2018-11-17 11:32 - 000000000 ____D C:\Users\Venom\AppData\Local\CrashDumps
2024-05-18 18:50 - 2020-04-04 12:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2024-05-15 10:50 - 2022-05-04 08:28 - 000335520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files\Windows Portable Devices
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2024-05-15 10:49 - 2019-12-07 16:39 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2024-05-15 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-05-15 10:49 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2024-05-15 10:47 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-05-15 10:38 - 2020-11-06 23:20 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-05-15 10:24 - 2023-10-16 20:26 - 000000000 ____D C:\Program Files\RUXIM
2024-05-15 10:05 - 2018-10-20 17:29 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-05-15 10:01 - 2018-10-20 17:29 - 196465576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-05-14 19:58 - 2018-12-01 13:53 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy
2024-05-14 19:52 - 2021-06-23 13:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenTTD [GOG.com]
2024-05-13 22:36 - 2023-11-08 22:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PDF Reader
==================== Files in the root of some directories ========
2019-07-11 23:02 - 2019-07-11 23:02 - 000332800 _____ () C:\Users\Venom\AppData\Roaming\patcher.dll
2018-10-21 14:24 - 2019-01-31 19:42 - 000007670 _____ () C:\Users\Venom\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================