kontrola logu
Napsal: 08 črc 2024 19:53
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01.07.2024
Ran by sern (administrator) on KATANA (Micro-Star International Co., Ltd. Katana 15 B12VFK) (08-07-2024 20:50:13)
Running from D:\Stažené soubory\FRST64.exe
Loaded Profiles: sern
Platform: Microsoft Windows 11 Pro Version 23H2 22631.3737 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(A225F3B5-240D-4EE9-BCF4-697A07F5E93E -> Micro-Star INT'L CO., LTD.) C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSICenter_2.0.38.0_x64__kzh8wxbdkxb8p\DCv2\DCv2.exe
(A-Volute SAS -> A-Volute) C:\Windows\System32\NhNotifSys.exe
(C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe
(C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\ui-launcher\AdskAccessUIHost.exe <4>
(C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdskIdentityManager\1.11.9.11\AdskIdentityManager.exe
(C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\92.0.1.0\crashpad_handler.exe
(C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe <6>
(C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\93.0.1.0\crashpad_handler.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(C:\Program Files\WindowsApps\MSTeams_24152.415.2975.367_x64__8wekyb3d8bbwe\ms-teams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe <15>
(C:\Users\sern\AppData\Roaming\BitTorrent Web\btweb.exe ->) (BitTorrent Inc -> BitTorrent Inc.) C:\Users\sern\AppData\Roaming\BitTorrent Web\helper\helper.exe
(D:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_helper.exe
(explorer.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe
(explorer.exe ->) (BitTorrent Inc -> BitTorrent Limited) C:\Users\sern\AppData\Roaming\BitTorrent Web\btweb.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <27>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\24.116.0609.0005\Microsoft.SharePoint.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) D:\Program Files (x86)\Steam\steam.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_24152.415.2975.367_x64__8wekyb3d8bbwe\ms-teams.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe
(services.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (CyberLink Corp. -> CyberLink) C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(services.exe ->) (Flexera Software LLC -> Flexera) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorvd.inf_amd64_346bd04e375689ec\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_6f0a892deb241071\AS\IAS\IntelAudioService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_4e93878658043b21\OneApp.IGCC.WinService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_5b1252b3763da959\IntelCpHDCPSvc.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe
(services.exe ->) (Micro-Star International CO., LTD. -> ) C:\Program Files (x86)\MSI\MSI NBFoundation Service\Sendevsvc.exe
(services.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSI NBFoundation Service\MSIAPService.exe
(services.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Windows\SysWOW64\MSIService.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Service.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmiig.inf_amd64_7bbded0afca8813b\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0def78d8fd7b6e2b\RtkAudUService64.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\Shared files\PDStyleAgent\PDStyleAgent.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\24.116.0609.0005\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.13200.30.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.TerminalServer.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Engine.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0def78d8fd7b6e2b\RtkAudUService64.exe [1974728 2024-04-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Autodesk Access] => C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe [21229344 2024-04-16] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [142414712 2023-08-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [MicrosoftEdgeAutoLaunch_8B5ED86351D1048DC4CB584E025CA08C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3883472 2024-07-01] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4905504 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [4407656 2024-06-20] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\sern\AppData\Local\Microsoft\Teams\Update.exe [2593856 2024-05-25] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45629344 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATISBE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-7710 Series" (No File)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [btweb] => C:\Users\sern\AppData\Roaming\BitTorrent Web\btweb.exe [6473736 2023-12-07] (BitTorrent Inc -> BitTorrent Limited)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [Microsoft.Lists] => C:\Program Files\Microsoft OneDrive\24.116.0609.0005\Microsoft.SharePoint.exe [1025552 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKLM\...\Print\Monitors\EPSON PC-FAX Driver2 64Monitor: C:\Windows\system32\EFXLM16A.DLL [182784 2023-07-20] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\...\Print\Monitors\EPSON WF-7710 Series 64MonitorBE: C:\Windows\system32\E_YLMBSBE.DLL [187392 2018-06-14] (Seiko Epson Corporation) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\126.0.6478.127\Installer\chrmstp.exe [2024-06-27] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {03318CC8-B53B-4496-94E0-F112EA80EFD9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {4AA4161B-8B6E-4BE6-A68C-47C164FA57A6} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "74b63197-13d5-47eb-b31a-87269d4372ec" --version "6.25.11131" --silent
Task: {4C2B9EDE-8B58-49BF-BEBA-F0AE818C996A} - System32\Tasks\CCleanerSkipUAC - sern => C:\Program Files\CCleaner\CCleaner.exe [39451552 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {7CB51A97-69A6-45DF-B459-3D7D2A497D55} - System32\Tasks\CLToast => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2317064 2024-03-14] (CyberLink Corp. -> )
Task: {3693C901-93C8-4957-8D99-2BE75CF53E8F} - System32\Tasks\CLToastRun => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2317064 2024-03-14] (CyberLink Corp. -> )
Task: {0699F10C-283A-4E68-BA0C-43593AD89AEF} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6537.0{FDD1E41C-46A5-460B-95C6-D6C0F15C8829} => C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe [4623976 2024-06-13] (Google LLC -> Google LLC)
Task: {34E478C6-E683-4786-B91C-6E261C3E8430} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28512448 2024-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {284AB1A0-D701-446A-98E2-1F56287BFB3F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28512448 2024-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {CC4B7EAA-2581-4FBC-A37F-624B1F178B1A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309696 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {40CE094F-5532-4762-9668-929EA0AA77AE} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309696 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {24524A63-2598-49F1-A258-155C3E5002F3} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [169408 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {307B857D-B82E-45F4-8385-DF01D3A20ACC} - System32\Tasks\Microsoft\Windows\Application Experience\PcaWallpaperAppDetect => C:\Windows\system32\rundll32.exe [73728 2024-05-15] (Microsoft Windows -> Microsoft Corporation) -> %windir%\system32\PcaSvc.dll,PcaWallpaperAppDetect
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {3EE6D57E-9C1E-4B1D-8C51-75670F25EC7A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3291ED3C-AA57-4C47-8489-CF6325885D37} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DD854B25-260C-44D8-917A-2D4B91981010} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9534244F-29A0-4B5B-BBC9-F9BED6E568DE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {013529CE-49C4-4E90-90BB-39344D53A855} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1277480 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {4D42E492-278D-4172-B437-A5E9F2309CE0} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3347496 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {40D80B2E-7355-4C6F-A9B0-FDC1AD7979F2} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646696 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {967F8D7A-F8AB-4F7B-99D2-DB29C1714F1C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1F35071E-526E-4635-AC51-C3F69F012F4E} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0E11980B-47C5-435B-A2CB-39D015A0C756} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7951DA52-2C18-4076-A1D6-7C8D986CE4EE} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8FEC9E67-35A6-4731-96E0-467980608BCD} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {67060935-51A9-4783-ACAC-D972464FA5BE} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {12CED94B-BE7B-4274-A5DD-028266067B8F} - System32\Tasks\OmApSvcBroker => C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe [961584 2024-07-04] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
Task: {77027A65-980C-41CE-A790-CCF5E305A3C3} - System32\Tasks\OneDC_Updater => C:\Users\sern\OneDrive\Dokumenty\temp\OneDC_Updater\OneDC_Updater.exe [657552 2023-11-30] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
Task: {4101935C-F0C0-4230-A195-A9B39E28EB5A} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4209168 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {DAAF67D8-5020-4F8F-88E0-02E1ED99E884} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2758214187-3853810005-2688088550-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4209168 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {1FA099D4-56A8-4B83-9948-D3CCECAC3F12} - System32\Tasks\PowerDirectorStyleAgent => C:\Program Files (x86)\CyberLink\Shared files\PDStyleAgent\PDStyleAgent.exe [97544 2024-03-14] (CyberLink Corp. -> CyberLink Corp.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}: [DhcpDomain] home
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\255646D69602130334: [DhcpNameServer] 192.168.147.235
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\344475966496: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\7416C61687970207163737A31323334313233343: [DhcpNameServer] 192.168.25.119
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\84F44554C41464F45544: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{444c531c-8e58-4e4f-8fe9-6ae83fad38d8}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{444c531c-8e58-4e4f-8fe9-6ae83fad38d8}: [DhcpDomain] home
Edge:
=======
Edge Profile: C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default [2024-07-08]
Edge Extension: (Dokumenty Google offline) - C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-26]
Edge Extension: (Edge relevant text changes) - C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default [2024-07-08]
CHR DownloadDir: D:\Stažené soubory
CHR Extension: (Story Space. Anonymous viewer for IG and FB) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\cicohiknlppcipjbfpoghjbncojncjgb [2024-05-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-06-20]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-06-27]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-02-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-20]
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-07-05]
CHR Extension: (Překladač Google) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-07-04]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-07-05]
CHR Extension: (NordVPN - VPN proxy for privacy and security) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa [2024-07-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-17]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-07-04]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-02-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-25]
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\System Profile [2024-07-08]
CHR HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Access Service Host; C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe [13272864 2024-04-15] (Autodesk, Inc. -> Autodesk, Inc.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1085856 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14023752 2024-06-21] (Microsoft Corporation -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\24.116.0609.0005\FileSyncHelper.exe [3518992 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
S2 Intel(R) Platform License Manager Service; C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\PlatformLicenseManagerService.exe [741488 2023-12-14] (Intel Corporation -> Intel(R) Corporation)
R2 IntelAudioService; C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_6f0a892deb241071\AS\IAS\IntelAudioService.exe [530424 2023-08-31] (Intel Corporation -> Intel)
R2 ipfsvc; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_uf.exe [3002464 2023-10-25] (Intel Corporation -> Intel Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe [1505416 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Micro Star SCM; C:\Windows\SysWOW64\MSIService.exe [171248 2023-05-11] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI NBFoundation Service\MSIAPService.exe [100496 2023-11-03] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
R2 MSI Sendevsvc; C:\Program Files (x86)\MSI\MSI NBFoundation Service\Sendevsvc.exe [311536 2023-05-11] (Micro-Star International CO., LTD. -> )
R2 MSI_Center_Service; C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe [149608 2024-01-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 MSI_VoiceControl_Service; C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Service.exe [36880 2023-04-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 NahimicService; C:\Windows\system32\NahimicService.exe [1909512 2023-11-15] (A-Volute SAS -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvmiig.inf_amd64_7bbded0afca8813b\Display.NvContainer\NVDisplay.Container.exe [1274888 2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\24.116.0609.0005\OneDriveUpdaterService.exe [3858464 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
S3 ProtonVPN Service; C:\Program Files\Proton\VPN\v3.2.10\ProtonVPNService.exe [474824 2024-02-01] (Proton AG -> ProtonVPN)
S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v3.2.10\ProtonVPN.WireGuardService.exe [474312 2024-02-01] (Proton AG -> ProtonVPN)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [625928 2024-03-14] (CyberLink Corp. -> CyberLink)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522184 2024-05-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe [3236728 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe [133704 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 googledrivefs31357; C:\Windows\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys [384712 2024-02-02] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 iaLPSS2_GPIO2_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_302e75596cffa74a\iaLPSS2_GPIO2_ADL.sys [150616 2022-10-18] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_e736c048ca307ed2\iaLPSS2_I2C_ADL.sys [220224 2022-10-18] (Intel Corporation -> Intel Corporation)
R0 iaStorVD; C:\Windows\System32\drivers\iaStorVD.sys [1605296 2023-11-19] (Intel Corporation -> Intel Corporation)
S3 IntcUSB; C:\Windows\System32\DriverStore\FileRepository\intcusb.inf_amd64_c2a06a639869c7cd\IntcUSB.sys [923128 2023-08-31] (Intel Corporation -> Intel(R) Corporation)
R3 IntelGNA; C:\Windows\System32\DriverStore\FileRepository\gna.inf_amd64_6f93b7542fd3ead9\gna.sys [88656 2023-09-26] (Intel Corporation -> Intel Corporation)
R3 ipf_acpi; C:\Windows\System32\DriverStore\FileRepository\ipf_acpi.inf_amd64_0bbfb278918dfdd5\ipf_acpi.sys [88160 2023-10-25] (Intel Corporation -> Intel Corporation)
R3 ipf_cpu; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_cpu.sys [85600 2023-10-25] (Intel Corporation -> Intel Corporation)
R3 ipf_lf; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_lf.sys [484448 2023-10-25] (Intel Corporation -> Intel Corporation)
R3 MpKsl31c17885; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BA3B5A2A-43FA-4C5C-94EB-7719E57B0A73}\MpKslDrv.sys [271648 2024-07-08] (Microsoft Windows -> Microsoft Corporation)
R3 NahimicBTLink; C:\Windows\System32\drivers\NahimicBTLink.sys [86200 2022-08-19] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
R3 Nahimic_Mirroring; C:\Windows\System32\drivers\Nahimic_Mirroring.sys [86224 2022-08-19] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
R3 NvModuleTracker; C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [47240 2024-04-03] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvpcf; C:\Windows\System32\drivers\nvpcf.sys [239256 2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v3.2.10\Resources\ProtonVPN.CalloutDriver.sys [34176 2023-11-20] (Microsoft Windows Hardware Compatibility Publisher -> Proton Technologies AG)
R3 rt68cx21; C:\Windows\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_8db01a9992cf3fbb\rt68cx21x64.sys [713152 2022-12-05] (Realtek Semiconductor Corp. -> Realtek)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22080 2024-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [602520 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105880 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2024-02-29] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WINIO; \??\C:\Program Files (x86)\MSI\MSI NBFoundation Service\KernCoreLib64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-07-08 20:50 - 2024-07-08 20:50 - 000000000 ____D C:\FRST
2024-07-07 21:40 - 2024-07-07 21:40 - 000728484 _____ C:\Windows\system32\perfh005.dat
2024-07-07 21:40 - 2024-07-07 21:40 - 000151700 _____ C:\Windows\system32\perfc005.dat
2024-07-07 20:37 - 2024-03-26 21:11 - 000059928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2024-07-07 20:37 - 2024-03-26 19:21 - 000060240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2024-06-30 19:44 - 2024-07-08 15:55 - 000000000 ____D C:\ProgramData\OmApSvcBroker
2024-06-30 19:44 - 2024-06-30 19:44 - 000003658 _____ C:\Windows\system32\Tasks\OneDC_Updater
2024-06-30 19:44 - 2024-06-30 19:44 - 000002974 _____ C:\Windows\system32\Tasks\OmApSvcBroker
2024-06-30 19:44 - 2024-06-30 19:44 - 000000000 ____D C:\Users\sern\OneDrive\Dokumenty\temp
2024-06-12 17:38 - 2024-06-12 17:38 - 000024821 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-06-12 17:37 - 2024-06-12 17:37 - 000024821 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-06-12 17:29 - 2024-06-12 17:35 - 000000000 ___HD C:\$WinREAgent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-07-08 20:46 - 2023-12-31 17:39 - 000000000 ____D C:\Users\sern\AppData\Roaming\BitTorrent Web
2024-07-08 20:12 - 2023-11-21 08:40 - 000000000 ____D C:\ProgramData\Common
2024-07-08 19:58 - 2023-11-20 22:45 - 000000000 ___SD C:\Users\sern\AppData\Roaming\Microsoft\Credentials
2024-07-08 19:35 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SystemTemp
2024-07-08 19:28 - 2023-11-20 22:39 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-07-08 18:38 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-07-08 17:30 - 2023-12-31 17:39 - 000000000 ____D C:\Users\sern\AppData\Local\BitTorrentHelper
2024-07-08 17:05 - 2023-11-20 22:52 - 000000000 ____D C:\Users\sern\AppData\Local\D3DSCache
2024-07-08 16:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\AppReadiness
2024-07-08 16:00 - 2023-11-20 22:51 - 000000000 ____D C:\ProgramData\NVIDIA
2024-07-08 15:55 - 2024-02-09 19:36 - 000000000 ____D C:\ProgramData\boost_interprocess
2024-07-08 15:55 - 2024-02-02 13:40 - 000002166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2024-07-08 15:55 - 2024-02-02 13:40 - 000002054 _____ C:\Users\sern\OneDrive\Desktop\Google Drive.lnk
2024-07-08 15:55 - 2023-11-21 18:08 - 000000000 ____D C:\Program Files\CCleaner
2024-07-08 15:55 - 2023-11-21 09:13 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Teams
2024-07-08 15:55 - 2023-11-20 22:50 - 000000000 ___RD C:\Users\sern\OneDrive
2024-07-07 21:40 - 2023-11-20 22:47 - 001718036 _____ C:\Windows\system32\PerfStringBackup.INI
2024-07-07 21:40 - 2022-05-07 07:22 - 000000000 ____D C:\Windows\INF
2024-07-07 21:35 - 2023-11-22 21:07 - 000000000 ____D C:\Users\sern\AppData\Local\CrashDumps
2024-07-07 21:32 - 2023-11-20 22:41 - 000001623 _____ C:\Windows\system32\config\VSMIDK
2024-07-07 21:32 - 2023-11-20 22:39 - 000012288 ___SH C:\DumpStack.log.tmp
2024-07-07 21:32 - 2023-11-20 22:39 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-07-07 21:32 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\ServiceState
2024-07-07 21:32 - 2022-05-07 07:17 - 000786432 _____ C:\Windows\system32\config\BBI
2024-07-07 20:38 - 2023-11-20 22:51 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2024-07-07 20:37 - 2023-11-22 19:20 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:20 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003894 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003654 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2024-07-07 20:37 - 2023-11-20 22:51 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2024-07-07 16:49 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps
2024-07-07 16:20 - 2023-11-22 18:17 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2024-07-07 16:20 - 2023-11-21 18:08 - 000000666 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2024-07-04 16:36 - 2023-11-20 22:40 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-07-03 17:04 - 2023-12-20 11:17 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Excel
2024-07-03 09:01 - 2023-12-20 10:57 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Word
2024-07-01 15:43 - 2023-11-21 18:08 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2024-07-01 15:43 - 2023-11-21 18:08 - 000003382 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2024-06-30 21:29 - 2023-11-21 09:03 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2024-06-30 21:29 - 2023-11-21 09:03 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-06-30 21:29 - 2023-11-20 22:50 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2758214187-3853810005-2688088550-1001
2024-06-30 19:44 - 2023-11-20 22:48 - 000000000 ____D C:\Program Files (x86)\MSI
2024-06-30 19:29 - 2023-11-21 08:31 - 000000000 ____D C:\Program Files\Microsoft Office
2024-06-27 17:20 - 2023-11-20 22:48 - 000000000 ____D C:\Users\sern\AppData\Local\Packages
2024-06-27 12:41 - 2023-11-20 23:55 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-06-20 19:55 - 2023-11-20 23:59 - 000000000 ____D C:\ProgramData\Package Cache
2024-06-14 04:37 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\USOPrivate
2024-06-14 04:15 - 2023-11-20 22:39 - 000594000 _____ C:\Windows\system32\FNTCACHE.DAT
2024-06-14 04:15 - 2023-11-09 18:12 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2024-06-14 04:15 - 2022-05-07 12:14 - 000000000 ____D C:\Windows\InboxApps
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ___SD C:\Windows\system32\UNP
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ___RD C:\Windows\PrintDialog
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\UUS
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SystemResources
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\WinMetadata
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\ShellExperiences
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\Sgrm
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\setup
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\oobe
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\migwiz
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\Dism
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\appraiser
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\ShellExperiences
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\ShellComponents
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\PolicyDefinitions
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\BrowserCore
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\bcastdvr
2024-06-14 04:15 - 2022-05-07 07:17 - 000000000 ____D C:\Windows\servicing
2024-06-12 17:40 - 2022-05-07 07:17 - 000000000 ____D C:\Windows\CbsTemp
2024-06-12 17:39 - 2022-05-07 12:14 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2024-06-12 17:39 - 2022-05-07 12:14 - 000024383 _____ C:\Windows\system32\OEMDefaultAssociations.xml
2024-06-12 17:38 - 2023-11-20 22:43 - 003216384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-06-12 17:27 - 2023-11-20 22:57 - 000000000 ____D C:\Windows\system32\MRT
2024-06-12 17:22 - 2023-11-20 22:57 - 199048176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-06-11 22:53 - 2023-11-22 19:20 - 002900520 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2024-06-11 22:52 - 2023-11-22 19:20 - 002231336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2024-06-11 22:52 - 2023-11-22 19:20 - 001296936 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2024-06-11 22:24 - 2023-11-22 19:20 - 000086568 _____ C:\Windows\system32\FvSDK_x64.dll
2024-06-11 22:24 - 2023-11-22 19:20 - 000075304 _____ C:\Windows\SysWOW64\FvSDK_x86.dll
2024-06-11 18:31 - 2023-11-22 19:19 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by sern (administrator) on KATANA (Micro-Star International Co., Ltd. Katana 15 B12VFK) (08-07-2024 20:50:13)
Running from D:\Stažené soubory\FRST64.exe
Loaded Profiles: sern
Platform: Microsoft Windows 11 Pro Version 23H2 22631.3737 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(A225F3B5-240D-4EE9-BCF4-697A07F5E93E -> Micro-Star INT'L CO., LTD.) C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSICenter_2.0.38.0_x64__kzh8wxbdkxb8p\DCv2\DCv2.exe
(A-Volute SAS -> A-Volute) C:\Windows\System32\NhNotifSys.exe
(C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe
(C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\ui-launcher\AdskAccessUIHost.exe <4>
(C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdskIdentityManager\1.11.9.11\AdskIdentityManager.exe
(C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\92.0.1.0\crashpad_handler.exe
(C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe <6>
(C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\93.0.1.0\crashpad_handler.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(C:\Program Files\WindowsApps\MSTeams_24152.415.2975.367_x64__8wekyb3d8bbwe\ms-teams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe <15>
(C:\Users\sern\AppData\Roaming\BitTorrent Web\btweb.exe ->) (BitTorrent Inc -> BitTorrent Inc.) C:\Users\sern\AppData\Roaming\BitTorrent Web\helper\helper.exe
(D:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_helper.exe
(explorer.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe
(explorer.exe ->) (BitTorrent Inc -> BitTorrent Limited) C:\Users\sern\AppData\Roaming\BitTorrent Web\btweb.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <27>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\24.116.0609.0005\Microsoft.SharePoint.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) D:\Program Files (x86)\Steam\steam.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_24152.415.2975.367_x64__8wekyb3d8bbwe\ms-teams.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe
(services.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (CyberLink Corp. -> CyberLink) C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(services.exe ->) (Flexera Software LLC -> Flexera) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorvd.inf_amd64_346bd04e375689ec\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_6f0a892deb241071\AS\IAS\IntelAudioService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_4e93878658043b21\OneApp.IGCC.WinService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_5b1252b3763da959\IntelCpHDCPSvc.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe
(services.exe ->) (Micro-Star International CO., LTD. -> ) C:\Program Files (x86)\MSI\MSI NBFoundation Service\Sendevsvc.exe
(services.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSI NBFoundation Service\MSIAPService.exe
(services.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Windows\SysWOW64\MSIService.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Service.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmiig.inf_amd64_7bbded0afca8813b\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0def78d8fd7b6e2b\RtkAudUService64.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\Shared files\PDStyleAgent\PDStyleAgent.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\24.116.0609.0005\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.13200.30.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.TerminalServer.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Engine.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0def78d8fd7b6e2b\RtkAudUService64.exe [1974728 2024-04-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Autodesk Access] => C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe [21229344 2024-04-16] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [142414712 2023-08-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [MicrosoftEdgeAutoLaunch_8B5ED86351D1048DC4CB584E025CA08C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3883472 2024-07-01] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4905504 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [4407656 2024-06-20] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\sern\AppData\Local\Microsoft\Teams\Update.exe [2593856 2024-05-25] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45629344 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATISBE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-7710 Series" (No File)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [btweb] => C:\Users\sern\AppData\Roaming\BitTorrent Web\btweb.exe [6473736 2023-12-07] (BitTorrent Inc -> BitTorrent Limited)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [Microsoft.Lists] => C:\Program Files\Microsoft OneDrive\24.116.0609.0005\Microsoft.SharePoint.exe [1025552 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe [61643040 2024-07-08] (Google LLC -> Google, Inc.)
HKLM\...\Print\Monitors\EPSON PC-FAX Driver2 64Monitor: C:\Windows\system32\EFXLM16A.DLL [182784 2023-07-20] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\...\Print\Monitors\EPSON WF-7710 Series 64MonitorBE: C:\Windows\system32\E_YLMBSBE.DLL [187392 2018-06-14] (Seiko Epson Corporation) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\126.0.6478.127\Installer\chrmstp.exe [2024-06-27] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {03318CC8-B53B-4496-94E0-F112EA80EFD9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {4AA4161B-8B6E-4BE6-A68C-47C164FA57A6} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "74b63197-13d5-47eb-b31a-87269d4372ec" --version "6.25.11131" --silent
Task: {4C2B9EDE-8B58-49BF-BEBA-F0AE818C996A} - System32\Tasks\CCleanerSkipUAC - sern => C:\Program Files\CCleaner\CCleaner.exe [39451552 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {7CB51A97-69A6-45DF-B459-3D7D2A497D55} - System32\Tasks\CLToast => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2317064 2024-03-14] (CyberLink Corp. -> )
Task: {3693C901-93C8-4957-8D99-2BE75CF53E8F} - System32\Tasks\CLToastRun => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2317064 2024-03-14] (CyberLink Corp. -> )
Task: {0699F10C-283A-4E68-BA0C-43593AD89AEF} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6537.0{FDD1E41C-46A5-460B-95C6-D6C0F15C8829} => C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe [4623976 2024-06-13] (Google LLC -> Google LLC)
Task: {34E478C6-E683-4786-B91C-6E261C3E8430} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28512448 2024-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {284AB1A0-D701-446A-98E2-1F56287BFB3F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28512448 2024-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {CC4B7EAA-2581-4FBC-A37F-624B1F178B1A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309696 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {40CE094F-5532-4762-9668-929EA0AA77AE} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309696 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {24524A63-2598-49F1-A258-155C3E5002F3} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [169408 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {307B857D-B82E-45F4-8385-DF01D3A20ACC} - System32\Tasks\Microsoft\Windows\Application Experience\PcaWallpaperAppDetect => C:\Windows\system32\rundll32.exe [73728 2024-05-15] (Microsoft Windows -> Microsoft Corporation) -> %windir%\system32\PcaSvc.dll,PcaWallpaperAppDetect
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {3EE6D57E-9C1E-4B1D-8C51-75670F25EC7A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3291ED3C-AA57-4C47-8489-CF6325885D37} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DD854B25-260C-44D8-917A-2D4B91981010} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9534244F-29A0-4B5B-BBC9-F9BED6E568DE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {013529CE-49C4-4E90-90BB-39344D53A855} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1277480 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {4D42E492-278D-4172-B437-A5E9F2309CE0} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3347496 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {40D80B2E-7355-4C6F-A9B0-FDC1AD7979F2} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646696 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {967F8D7A-F8AB-4F7B-99D2-DB29C1714F1C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1F35071E-526E-4635-AC51-C3F69F012F4E} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0E11980B-47C5-435B-A2CB-39D015A0C756} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7951DA52-2C18-4076-A1D6-7C8D986CE4EE} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8FEC9E67-35A6-4731-96E0-467980608BCD} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {67060935-51A9-4783-ACAC-D972464FA5BE} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {12CED94B-BE7B-4274-A5DD-028266067B8F} - System32\Tasks\OmApSvcBroker => C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe [961584 2024-07-04] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
Task: {77027A65-980C-41CE-A790-CCF5E305A3C3} - System32\Tasks\OneDC_Updater => C:\Users\sern\OneDrive\Dokumenty\temp\OneDC_Updater\OneDC_Updater.exe [657552 2023-11-30] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
Task: {4101935C-F0C0-4230-A195-A9B39E28EB5A} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4209168 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {DAAF67D8-5020-4F8F-88E0-02E1ED99E884} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2758214187-3853810005-2688088550-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4209168 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {1FA099D4-56A8-4B83-9948-D3CCECAC3F12} - System32\Tasks\PowerDirectorStyleAgent => C:\Program Files (x86)\CyberLink\Shared files\PDStyleAgent\PDStyleAgent.exe [97544 2024-03-14] (CyberLink Corp. -> CyberLink Corp.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}: [DhcpDomain] home
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\255646D69602130334: [DhcpNameServer] 192.168.147.235
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\344475966496: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\7416C61687970207163737A31323334313233343: [DhcpNameServer] 192.168.25.119
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\84F44554C41464F45544: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{444c531c-8e58-4e4f-8fe9-6ae83fad38d8}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{444c531c-8e58-4e4f-8fe9-6ae83fad38d8}: [DhcpDomain] home
Edge:
=======
Edge Profile: C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default [2024-07-08]
Edge Extension: (Dokumenty Google offline) - C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-26]
Edge Extension: (Edge relevant text changes) - C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default [2024-07-08]
CHR DownloadDir: D:\Stažené soubory
CHR Extension: (Story Space. Anonymous viewer for IG and FB) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\cicohiknlppcipjbfpoghjbncojncjgb [2024-05-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-06-20]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-06-27]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-02-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-20]
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-07-05]
CHR Extension: (Překladač Google) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-07-04]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-07-05]
CHR Extension: (NordVPN - VPN proxy for privacy and security) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa [2024-07-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-17]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-07-04]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-02-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-25]
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\System Profile [2024-07-08]
CHR HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Access Service Host; C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe [13272864 2024-04-15] (Autodesk, Inc. -> Autodesk, Inc.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1085856 2024-06-26] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14023752 2024-06-21] (Microsoft Corporation -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\24.116.0609.0005\FileSyncHelper.exe [3518992 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
S2 Intel(R) Platform License Manager Service; C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\PlatformLicenseManagerService.exe [741488 2023-12-14] (Intel Corporation -> Intel(R) Corporation)
R2 IntelAudioService; C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_6f0a892deb241071\AS\IAS\IntelAudioService.exe [530424 2023-08-31] (Intel Corporation -> Intel)
R2 ipfsvc; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_uf.exe [3002464 2023-10-25] (Intel Corporation -> Intel Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe [1505416 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Micro Star SCM; C:\Windows\SysWOW64\MSIService.exe [171248 2023-05-11] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI NBFoundation Service\MSIAPService.exe [100496 2023-11-03] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
R2 MSI Sendevsvc; C:\Program Files (x86)\MSI\MSI NBFoundation Service\Sendevsvc.exe [311536 2023-05-11] (Micro-Star International CO., LTD. -> )
R2 MSI_Center_Service; C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe [149608 2024-01-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 MSI_VoiceControl_Service; C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Service.exe [36880 2023-04-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 NahimicService; C:\Windows\system32\NahimicService.exe [1909512 2023-11-15] (A-Volute SAS -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvmiig.inf_amd64_7bbded0afca8813b\Display.NvContainer\NVDisplay.Container.exe [1274888 2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\24.116.0609.0005\OneDriveUpdaterService.exe [3858464 2024-06-30] (Microsoft Corporation -> Microsoft Corporation)
S3 ProtonVPN Service; C:\Program Files\Proton\VPN\v3.2.10\ProtonVPNService.exe [474824 2024-02-01] (Proton AG -> ProtonVPN)
S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v3.2.10\ProtonVPN.WireGuardService.exe [474312 2024-02-01] (Proton AG -> ProtonVPN)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [625928 2024-03-14] (CyberLink Corp. -> CyberLink)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522184 2024-05-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe [3236728 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe [133704 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 googledrivefs31357; C:\Windows\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys [384712 2024-02-02] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 iaLPSS2_GPIO2_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_302e75596cffa74a\iaLPSS2_GPIO2_ADL.sys [150616 2022-10-18] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_e736c048ca307ed2\iaLPSS2_I2C_ADL.sys [220224 2022-10-18] (Intel Corporation -> Intel Corporation)
R0 iaStorVD; C:\Windows\System32\drivers\iaStorVD.sys [1605296 2023-11-19] (Intel Corporation -> Intel Corporation)
S3 IntcUSB; C:\Windows\System32\DriverStore\FileRepository\intcusb.inf_amd64_c2a06a639869c7cd\IntcUSB.sys [923128 2023-08-31] (Intel Corporation -> Intel(R) Corporation)
R3 IntelGNA; C:\Windows\System32\DriverStore\FileRepository\gna.inf_amd64_6f93b7542fd3ead9\gna.sys [88656 2023-09-26] (Intel Corporation -> Intel Corporation)
R3 ipf_acpi; C:\Windows\System32\DriverStore\FileRepository\ipf_acpi.inf_amd64_0bbfb278918dfdd5\ipf_acpi.sys [88160 2023-10-25] (Intel Corporation -> Intel Corporation)
R3 ipf_cpu; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_cpu.sys [85600 2023-10-25] (Intel Corporation -> Intel Corporation)
R3 ipf_lf; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_b25cc008923a9297\ipf_lf.sys [484448 2023-10-25] (Intel Corporation -> Intel Corporation)
R3 MpKsl31c17885; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BA3B5A2A-43FA-4C5C-94EB-7719E57B0A73}\MpKslDrv.sys [271648 2024-07-08] (Microsoft Windows -> Microsoft Corporation)
R3 NahimicBTLink; C:\Windows\System32\drivers\NahimicBTLink.sys [86200 2022-08-19] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
R3 Nahimic_Mirroring; C:\Windows\System32\drivers\Nahimic_Mirroring.sys [86224 2022-08-19] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
R3 NvModuleTracker; C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [47240 2024-04-03] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvpcf; C:\Windows\System32\drivers\nvpcf.sys [239256 2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v3.2.10\Resources\ProtonVPN.CalloutDriver.sys [34176 2023-11-20] (Microsoft Windows Hardware Compatibility Publisher -> Proton Technologies AG)
R3 rt68cx21; C:\Windows\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_8db01a9992cf3fbb\rt68cx21x64.sys [713152 2022-12-05] (Realtek Semiconductor Corp. -> Realtek)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22080 2024-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [602520 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105880 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2024-02-29] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WINIO; \??\C:\Program Files (x86)\MSI\MSI NBFoundation Service\KernCoreLib64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-07-08 20:50 - 2024-07-08 20:50 - 000000000 ____D C:\FRST
2024-07-07 21:40 - 2024-07-07 21:40 - 000728484 _____ C:\Windows\system32\perfh005.dat
2024-07-07 21:40 - 2024-07-07 21:40 - 000151700 _____ C:\Windows\system32\perfc005.dat
2024-07-07 20:37 - 2024-03-26 21:11 - 000059928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2024-07-07 20:37 - 2024-03-26 19:21 - 000060240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2024-06-30 19:44 - 2024-07-08 15:55 - 000000000 ____D C:\ProgramData\OmApSvcBroker
2024-06-30 19:44 - 2024-06-30 19:44 - 000003658 _____ C:\Windows\system32\Tasks\OneDC_Updater
2024-06-30 19:44 - 2024-06-30 19:44 - 000002974 _____ C:\Windows\system32\Tasks\OmApSvcBroker
2024-06-30 19:44 - 2024-06-30 19:44 - 000000000 ____D C:\Users\sern\OneDrive\Dokumenty\temp
2024-06-12 17:38 - 2024-06-12 17:38 - 000024821 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-06-12 17:37 - 2024-06-12 17:37 - 000024821 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-06-12 17:29 - 2024-06-12 17:35 - 000000000 ___HD C:\$WinREAgent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-07-08 20:46 - 2023-12-31 17:39 - 000000000 ____D C:\Users\sern\AppData\Roaming\BitTorrent Web
2024-07-08 20:12 - 2023-11-21 08:40 - 000000000 ____D C:\ProgramData\Common
2024-07-08 19:58 - 2023-11-20 22:45 - 000000000 ___SD C:\Users\sern\AppData\Roaming\Microsoft\Credentials
2024-07-08 19:35 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SystemTemp
2024-07-08 19:28 - 2023-11-20 22:39 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-07-08 18:38 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-07-08 17:30 - 2023-12-31 17:39 - 000000000 ____D C:\Users\sern\AppData\Local\BitTorrentHelper
2024-07-08 17:05 - 2023-11-20 22:52 - 000000000 ____D C:\Users\sern\AppData\Local\D3DSCache
2024-07-08 16:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\AppReadiness
2024-07-08 16:00 - 2023-11-20 22:51 - 000000000 ____D C:\ProgramData\NVIDIA
2024-07-08 15:55 - 2024-02-09 19:36 - 000000000 ____D C:\ProgramData\boost_interprocess
2024-07-08 15:55 - 2024-02-02 13:40 - 000002166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2024-07-08 15:55 - 2024-02-02 13:40 - 000002054 _____ C:\Users\sern\OneDrive\Desktop\Google Drive.lnk
2024-07-08 15:55 - 2023-11-21 18:08 - 000000000 ____D C:\Program Files\CCleaner
2024-07-08 15:55 - 2023-11-21 09:13 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Teams
2024-07-08 15:55 - 2023-11-20 22:50 - 000000000 ___RD C:\Users\sern\OneDrive
2024-07-07 21:40 - 2023-11-20 22:47 - 001718036 _____ C:\Windows\system32\PerfStringBackup.INI
2024-07-07 21:40 - 2022-05-07 07:22 - 000000000 ____D C:\Windows\INF
2024-07-07 21:35 - 2023-11-22 21:07 - 000000000 ____D C:\Users\sern\AppData\Local\CrashDumps
2024-07-07 21:32 - 2023-11-20 22:41 - 000001623 _____ C:\Windows\system32\config\VSMIDK
2024-07-07 21:32 - 2023-11-20 22:39 - 000012288 ___SH C:\DumpStack.log.tmp
2024-07-07 21:32 - 2023-11-20 22:39 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-07-07 21:32 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\ServiceState
2024-07-07 21:32 - 2022-05-07 07:17 - 000786432 _____ C:\Windows\system32\config\BBI
2024-07-07 20:38 - 2023-11-20 22:51 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2024-07-07 20:37 - 2023-11-22 19:20 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:20 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003894 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000003654 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-07 20:37 - 2023-11-22 19:19 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2024-07-07 20:37 - 2023-11-20 22:51 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2024-07-07 16:49 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps
2024-07-07 16:20 - 2023-11-22 18:17 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2024-07-07 16:20 - 2023-11-21 18:08 - 000000666 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2024-07-04 16:36 - 2023-11-20 22:40 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-07-03 17:04 - 2023-12-20 11:17 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Excel
2024-07-03 09:01 - 2023-12-20 10:57 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Word
2024-07-01 15:43 - 2023-11-21 18:08 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2024-07-01 15:43 - 2023-11-21 18:08 - 000003382 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2024-06-30 21:29 - 2023-11-21 09:03 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2024-06-30 21:29 - 2023-11-21 09:03 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-06-30 21:29 - 2023-11-20 22:50 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2758214187-3853810005-2688088550-1001
2024-06-30 19:44 - 2023-11-20 22:48 - 000000000 ____D C:\Program Files (x86)\MSI
2024-06-30 19:29 - 2023-11-21 08:31 - 000000000 ____D C:\Program Files\Microsoft Office
2024-06-27 17:20 - 2023-11-20 22:48 - 000000000 ____D C:\Users\sern\AppData\Local\Packages
2024-06-27 12:41 - 2023-11-20 23:55 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-06-20 19:55 - 2023-11-20 23:59 - 000000000 ____D C:\ProgramData\Package Cache
2024-06-14 04:37 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\USOPrivate
2024-06-14 04:15 - 2023-11-20 22:39 - 000594000 _____ C:\Windows\system32\FNTCACHE.DAT
2024-06-14 04:15 - 2023-11-09 18:12 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2024-06-14 04:15 - 2022-05-07 12:14 - 000000000 ____D C:\Windows\InboxApps
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ___SD C:\Windows\system32\UNP
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ___RD C:\Windows\PrintDialog
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\UUS
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\SystemResources
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\WinMetadata
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\ShellExperiences
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\Sgrm
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\setup
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\oobe
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\migwiz
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\Dism
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\system32\appraiser
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\ShellExperiences
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\ShellComponents
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\PolicyDefinitions
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\BrowserCore
2024-06-14 04:15 - 2022-05-07 07:24 - 000000000 ____D C:\Windows\bcastdvr
2024-06-14 04:15 - 2022-05-07 07:17 - 000000000 ____D C:\Windows\servicing
2024-06-12 17:40 - 2022-05-07 07:17 - 000000000 ____D C:\Windows\CbsTemp
2024-06-12 17:39 - 2022-05-07 12:14 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2024-06-12 17:39 - 2022-05-07 12:14 - 000024383 _____ C:\Windows\system32\OEMDefaultAssociations.xml
2024-06-12 17:38 - 2023-11-20 22:43 - 003216384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-06-12 17:27 - 2023-11-20 22:57 - 000000000 ____D C:\Windows\system32\MRT
2024-06-12 17:22 - 2023-11-20 22:57 - 199048176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-06-11 22:53 - 2023-11-22 19:20 - 002900520 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2024-06-11 22:52 - 2023-11-22 19:20 - 002231336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2024-06-11 22:52 - 2023-11-22 19:20 - 001296936 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2024-06-11 22:24 - 2023-11-22 19:20 - 000086568 _____ C:\Windows\system32\FvSDK_x64.dll
2024-06-11 22:24 - 2023-11-22 19:20 - 000075304 _____ C:\Windows\SysWOW64\FvSDK_x86.dll
2024-06-11 18:31 - 2023-11-22 19:19 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================