poprosim kontrolu logu (spomaleny až zasekany PC)
Napsal: 23 srp 2024 18:30
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-08.2024
Ran by PC1 (administrator) on DESKTOP-NORVJE6 (MSI MS-7A39) (23-08-2024 19:28:17)
Running from C:\Users\PC1\Desktop\FRST64 (1).exe
Loaded Profiles: PC1
Platform: Microsoft Windows 10 Home Version 22H2 19045.4780 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe ->) (Reaction Software Limited -> Weather Zero) C:\Program Files (x86)\WeatherZero\WeatherZero.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.125.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(cmd.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Discord Inc. -> Discord Inc.) C:\Users\PC1\AppData\Local\Discord\app-1.0.9159\Discord.exe <6>
(DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\atieclxx.exe
(explorer.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files (x86)\Adguard\Adguard.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.125.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe <6>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <17>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(services.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files (x86)\Adguard\AdguardSvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\atiesrxx.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe
(services.exe ->) (Reaction Software Limited -> Weather Information Service) C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\CPUMetricsServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102816 2022-01-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [ACUW17EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\acdIDInTouch2.exe [3508784 2024-01-13] (ACD Systems International Inc. -> ACD Systems International Inc.) [File not signed]
HKLM\...\Run: [Adguard] => C:\Program Files (x86)\Adguard\Adguard.exe [7233056 2024-07-08] (Adguard Software Limited -> Adguard Software Limited)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [235624 2015-01-09] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36733928 2024-08-17] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4407656 2024-07-17] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [PC1] => cmd.exe /c start www.exinariuminix.info (No File) <==== ATTENTION
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [482128 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44970408 2024-07-16] (Gen Digital Inc. -> Piriform Software Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [MicrosoftEdgeAutoLaunch_3ED1524B1F1362DAB86361CACD0A8016] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3814952 2024-08-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [ACDSeeCommanderUltimate17] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\ACDSeeCommanderUltimate17.exe [8257104 2024-01-13] (ACD Systems International Inc. -> ) [File not signed]
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Discord] => C:\Users\PC1\AppData\Local\Discord\Update.exe [1526552 2024-04-29] (Discord Inc. -> GitHub)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [AMDNoiseSuppression] => C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe [145336 2023-08-10] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Adguard] => C:\Program Files (x86)\Adguard\Adguard.exe [7233056 2024-07-08] (Adguard Software Limited -> Adguard Software Limited)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3380328 2024-08-23] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\MountPoints2: {283cab94-2c81-11ea-925c-309c239b7301} - "F:\setup.exe"
HKLM\...\Windows x64\Print Processors\Canon MG3600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDCT.DLL [30208 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3600 series: C:\WINDOWS\system32\CNMLMCT.DLL [406528 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [375296 2015-03-17] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\128.0.6613.84\Installer\chrmstp.exe [2024-08-23] (Google LLC -> Google LLC)
IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll
IFEO\SppExtComObj.Exe: [VerifierDlls] SppExtComObjHook.dll
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5D40A70B-906F-47F3-ADB4-826F898DC794} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {EB38D2D3-9854-401B-BDFF-D9F93529BCCE} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1030872 2024-05-09] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {21CC9769-D945-4977-B5C7-308113D41473} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1030872 2024-05-09] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {398E64A3-B801-4BE2-ABFB-0CA8B59F0647} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [184024 2024-05-08] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {C9EE2F49-9A35-4606-8064-C015B14D20E1} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-08-05] (Avast Software s.r.o. -> Avast Software)
Task: {EA3A7B73-9018-48A2-B9A9-ACE08C2DCBCB} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [829408 2024-07-16] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {FDC29122-722C-4EB3-8FD0-285260CD7859} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-07-16] (Gen Digital Inc. -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "f629c2c0-113b-48e0-87af-a975de79342f" --version "6.26.11169" --silent
Task: {8A4A45D0-D188-4B76-B6A7-55090433182C} - System32\Tasks\CCleanerSkipUAC - PC1 => C:\Program Files\CCleaner\CCleaner.exe [38931368 2024-07-16] (Gen Digital Inc. -> Piriform Software Ltd)
Task: {93A99B83-4F2A-4BD8-8C22-25FA2926AA64} - System32\Tasks\Google Play Games Notifier => C:\Program Files\Google\Play Games\Bootstrapper.exe [374376 2024-08-17] (Google LLC -> Google LLC)
Task: {12326B1B-153A-478E-81F7-A984DA02CFD1} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem129.0.6651.0{1BE8927B-63D8-40E7-83EA-C0722ACFD7B2} => C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe [4906600 2024-08-11] (Google LLC -> Google LLC)
Task: {7EE7F7E0-3F0F-4093-9B95-D073D3BF70A0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {9A172CAE-E594-4004-8274-80EA84D69601} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {A689333B-D9AD-4A1E-BE3E-5A99BCA6022A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {3C9669D7-9BE7-4E1F-A396-4BA2DF95DED3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {DC7F1F62-2A22-455E-BD63-3A83557D2C67} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [65448 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {8487B275-D178-4E77-88A7-78C1BF6695FF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {C2C716A0-254D-4164-84C2-6810D9A8B11F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {3F6AE67B-B3ED-4923-9B36-C6AE40B44271} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {126EE5FF-146B-406A-BF81-EBF5EF264BE3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {235F13E8-6F65-4DF9-BB95-E1FE168A0ED0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {945B61AB-1DE3-4C92-B180-CB5DF8381D40} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0A869273-4468-4DF8-9C3D-F068C3BC02D8} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1030872 2024-05-09] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {4FB3A957-445C-4EFB-A0F8-0C00CB583A0E} - System32\Tasks\PC1 => C:\WINDOWS\system32\cmd.exe [289792 2024-05-17] (Microsoft Windows -> Microsoft Corporation) -> /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v PC1 /t REG_SZ /d "cmd.exe /c start www.exinariuminix.info" <==== ATTENTION
Task: {29C18D88-BE9E-4778-A260-6328474FB1D1} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [60632 2024-05-08] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {49E5F8B1-AF76-4BC3-A669-A999B860A808} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [324312 2024-05-08] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-31] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{a3cfb294-eb5a-46bb-8e56-15ac18209a18}: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{a3cfb294-eb5a-46bb-8e56-15ac18209a18}: [DhcpDomain] home
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default [2024-08-18]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-12]
Edge Extension: (Edge relevant text changes) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-04-07]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-06-27] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default [2024-08-23]
CHR DownloadDir: E:\Downloads\Filmy
CHR Notifications: Default -> hxxps://jutes.ru; hxxps://sibirem.ru; hxxps://slo.wikiwiex.com; hxxps://www.giveawayoftheday.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-08-23]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-08-17]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4 [2024-08-17]
CHR Extension: (Torrent Scanner) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2024-04-28]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-12]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-04-28]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\System Profile [2024-08-23]
CHR HKLM\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
Opera:
=======
OPR Profile: C:\Users\PC1\AppData\Roaming\Opera Software\Opera Stable [2024-08-17]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Adguard Service; C:\Program Files (x86)\Adguard\AdguardSvc.exe [806944 2024-07-08] (Adguard Software Limited -> Adguard Software Limited)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [15737128 2024-05-11] (BattlEye Innovations e.K. -> )
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1085864 2024-07-16] (Gen Digital Inc. -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12477392 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4976976 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [13902952 2024-08-23] (Electronic Arts, Inc. -> Electronic Arts)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-10] (Epic Games Inc. -> Epic Games, Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460488 2024-04-03] (Canon Inc. -> )
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [6537200 2024-08-17] (Rockstar Games, Inc. -> Rockstar Games)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13353768 2021-09-15] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe [5084200 2024-05-11] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WeatherZeroSvc; C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe [3256744 2022-06-12] (Reaction Software Limited -> Weather Information Service)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [12486496 2024-06-28] (KRAFTON, Inc. -> KRAFTON, Inc)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 2C50ECBD; C:\WINDOWS\System32\drivers\2C50ECBD.sys [478392 2021-04-14] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 adgnetworkwfpdrv; C:\WINDOWS\System32\drivers\adgnetworkwfpdrv.sys [88744 2024-05-23] (Microsoft Windows Hardware Compatibility Publisher -> Adguard Software Limited)
S3 AIDA64Driver; C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [68376 2021-03-29] (FinalWire Kft. -> )
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [25688 2024-02-22] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33504 2024-08-11] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R2 AMDRyzenMasterDriverV20; C:\WINDOWS\system32\AMDRyzenMasterDriver.sys [58952 2024-05-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_54807f69fe156f14\amdsafd.sys [113088 2023-04-13] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 amduw23g; C:\WINDOWS\System32\DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\amdkmdag.sys [106157352 2024-08-11] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [61888 2023-05-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2020-11-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [63696 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 MpKsl3026d0ab; C:\WINDOWS\system32\MpEngineStore\MpKslDrv.sys [271640 2024-08-17] (Microsoft Windows -> Microsoft Corporation)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2022-07-04] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22080 2024-08-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602504 2024-08-02] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105864 2024-08-02] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2022-10-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [215864 2024-05-24] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 amdwddmg; \SystemRoot\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [X]
S3 MpKsl7cd804ff; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4EE50D74-840B-42B0-9A5C-A4FA3FF166BB}\MpKslDrv.sys [X]
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-08-23 19:29 - 2024-08-23 19:29 - 002397184 _____ (Farbar) C:\Users\PC1\Desktop\FRST64.exe
2024-08-23 19:28 - 2024-08-23 19:28 - 000027084 _____ C:\Users\PC1\Desktop\FRST.txt
2024-08-23 19:28 - 2024-08-23 19:28 - 000000000 ____D C:\Users\PC1\Desktop\FRST-OlderVersion
2024-08-17 19:16 - 2024-08-17 19:16 - 000000000 ___HD C:\$WinREAgent
2024-08-17 09:04 - 2024-08-17 09:04 - 000000000 ____D C:\WINDOWS\system32\MpEngineStore
2024-08-11 15:22 - 2024-08-11 15:22 - 007598784 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdadlx64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 007373616 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdadlx32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 002921768 _____ C:\WINDOWS\system32\amd-smi.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 002287912 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsasrv64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 002152744 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 002101032 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 002101032 _____ C:\WINDOWS\system32\vulkaninfo.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 001797008 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001797008 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001726552 _____ (AMD) C:\WINDOWS\system32\amf-mft-mjpeg-decoder64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001659288 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 001659288 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 001466168 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001466168 _____ C:\WINDOWS\system32\vulkan-1.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001400912 _____ (AMD) C:\WINDOWS\SysWOW64\amf-mft-mjpeg-decoder32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001347768 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsacli64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001307624 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001307624 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001254808 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001077280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdsacli32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001055528 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001031464 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000632208 _____ C:\WINDOWS\system32\GameManager64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000591248 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000558888 _____ C:\WINDOWS\system32\atieah64.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000552888 _____ C:\WINDOWS\system32\amdmiracast.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000526232 _____ C:\WINDOWS\system32\EEURestart.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000479640 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000473488 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000449424 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000421680 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000280360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000236848 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000196392 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000190768 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000178872 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000168656 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000168552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000161808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000154152 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000150312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000142632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000140648 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000140648 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000140080 _____ C:\WINDOWS\system32\amdxc64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000134312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000117040 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000116520 _____ C:\WINDOWS\SysWOW64\amdxc32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000075160 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2024-08-11 15:21 - 2024-08-11 15:21 - 113329392 _____ C:\WINDOWS\system32\amdxc64.so
2024-08-11 15:21 - 2024-08-11 15:21 - 001344456 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 006160840 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 000052344 _____ (Advanced Micro Devices, Inc) C:\WINDOWS\system32\Drivers\amdgpio2.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 000039048 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\AMDPCIDev.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 000033504 _____ (Advanced Micro Devices, Inc) C:\WINDOWS\system32\Drivers\amdgpio3.sys
2024-08-11 15:14 - 2024-08-17 14:34 - 000000000 ____D C:\ProgramData\ProductData
2024-08-11 15:13 - 2024-08-17 14:34 - 000000000 ____D C:\Program Files (x86)\IObit
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-08-23 19:28 - 2024-01-14 13:52 - 002397184 _____ (Farbar) C:\Users\PC1\Desktop\FRST64 (1).exe
2024-08-23 19:28 - 2021-06-26 13:26 - 000000000 ____D C:\Program Files (x86)\Steam
2024-08-23 19:28 - 2020-12-19 11:48 - 000000000 ____D C:\FRST
2024-08-23 19:26 - 2024-05-05 12:00 - 000000000 ____D C:\Users\PC1\AppData\Roaming\discord
2024-08-23 19:25 - 2024-07-07 21:18 - 000000000 ____D C:\ProgramData\EA Desktop
2024-08-23 19:25 - 2024-05-05 12:00 - 000000000 ____D C:\Users\PC1\AppData\Local\Discord
2024-08-23 19:24 - 2024-06-30 14:52 - 000000000 ____D C:\ProgramData\Adguard
2024-08-23 19:24 - 2024-06-14 18:50 - 000003114 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2024-08-23 19:24 - 2024-06-14 18:50 - 000003106 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2024-08-23 19:24 - 2021-03-09 16:44 - 000000000 ____D C:\Users\PC1\AppData\Local\CrashDumps
2024-08-23 19:24 - 2020-12-20 11:32 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-08-23 19:23 - 2021-01-02 13:33 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2024-08-23 19:23 - 2020-12-20 11:44 - 000000000 ____D C:\Users\PC1
2024-08-23 19:23 - 2020-12-20 11:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-08-23 19:23 - 2020-12-20 11:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-08-23 19:23 - 2020-11-07 11:27 - 000008192 ___SH C:\DumpStack.log.tmp
2024-08-23 19:15 - 2020-12-20 11:32 - 000000000 ___HD C:\Program Files\WindowsApps
2024-08-23 19:14 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-08-23 19:13 - 2022-02-10 23:30 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2024-08-23 19:13 - 2022-01-22 14:11 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2024-08-23 19:13 - 2020-12-20 11:44 - 000002365 _____ C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-08-23 19:10 - 2021-12-16 22:47 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-08-23 19:10 - 2020-12-20 12:00 - 000002259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-08-23 19:10 - 2020-12-20 12:00 - 000002218 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-08-23 19:09 - 2024-05-05 12:00 - 000002237 _____ C:\Users\PC1\Desktop\Discord.lnk
2024-08-23 19:08 - 2024-06-30 14:52 - 000000000 ____D C:\Program Files (x86)\Adguard
2024-08-19 04:48 - 2020-12-20 11:27 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-08-19 04:22 - 2020-12-20 11:55 - 000000000 ____D C:\Users\PC1\AppData\Local\D3DSCache
2024-08-18 20:41 - 2024-05-25 12:43 - 000000000 ____D C:\Users\PC1\Desktop\Mody
2024-08-18 20:40 - 2024-04-13 16:14 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Atlas
2024-08-18 16:50 - 2022-05-12 20:30 - 000655020 _____ C:\WINDOWS\system32\perfh01B.dat
2024-08-18 16:50 - 2022-05-12 20:30 - 000126030 _____ C:\WINDOWS\system32\perfc01B.dat
2024-08-18 16:50 - 2020-12-20 11:53 - 001547408 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-08-18 16:50 - 2020-12-20 11:31 - 000000000 ____D C:\WINDOWS\INF
2024-08-18 12:38 - 2022-05-05 20:54 - 000306624 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SystemResources
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\setup
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\Provisioning
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-08-18 10:19 - 2020-12-20 11:28 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-08-17 15:10 - 2024-03-31 14:40 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Ovix
2024-08-17 15:02 - 2021-10-08 19:04 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Kodi
2024-08-17 14:42 - 2023-05-17 18:09 - 000000000 ____D C:\WINDOWS\Minidump
2024-08-17 14:42 - 2023-04-05 08:10 - 000000000 ____D C:\Program Files\CCleaner
2024-08-17 14:34 - 2022-01-30 18:11 - 000000000 ____D C:\Users\PC1\AppData\Roaming\IObit
2024-08-17 10:45 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\schemas
2024-08-17 09:29 - 2020-12-20 11:43 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-08-17 09:02 - 2020-12-20 12:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-08-17 09:01 - 2020-12-20 12:41 - 197093640 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-08-17 08:58 - 2020-12-23 18:30 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-08-17 08:58 - 2020-06-10 21:36 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-08-17 08:46 - 2022-04-03 11:14 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-08-11 17:41 - 2023-04-05 08:10 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-08-11 15:25 - 2024-04-20 14:27 - 000000000 ____D C:\ProgramData\Package Cache
2024-08-09 20:46 - 2024-06-14 18:30 - 000000000 ____D C:\Users\PC1\AppData\Local\AMD_Common
2024-08-04 14:57 - 2020-12-20 11:55 - 000000000 ____D C:\Users\PC1\AppData\Local\Packages
2024-08-03 08:37 - 2023-05-23 21:38 - 000000000 ____D C:\Users\PC1\AppData\Local\ElevatedDiagnostics
2024-08-03 08:13 - 2023-04-05 08:10 - 000002824 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-08-03 08:13 - 2023-04-05 08:10 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-08-02 22:51 - 2024-07-05 08:51 - 000000000 ____D C:\ProgramData\CanonIJPLM
2024-08-02 19:09 - 2020-12-20 11:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-07-28 13:44 - 2022-01-30 15:15 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-07-28 13:44 - 2022-01-30 15:15 - 000003508 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
==================== Files in the root of some directories ========
2024-05-16 23:47 - 2024-05-16 23:47 - 000000255 _____ () C:\ProgramData\fontcacheev1.dat
2021-06-06 10:33 - 2021-07-21 21:43 - 000000055 _____ () C:\Users\PC1\AppData\Roaming\EHWID.txt
2022-08-12 17:55 - 2023-09-16 20:35 - 000208896 _____ () C:\Users\PC1\AppData\Roaming\emp.bin
2021-06-06 10:33 - 2021-12-12 19:52 - 000000011 _____ () C:\Users\PC1\AppData\Roaming\EPW.txt
2021-06-06 10:33 - 2021-07-21 21:43 - 000000009 _____ () C:\Users\PC1\AppData\Roaming\ERole.txt
2021-06-06 10:33 - 2021-12-12 19:52 - 000000012 _____ () C:\Users\PC1\AppData\Roaming\EUser.txt
2021-03-07 20:58 - 2021-03-07 20:58 - 000016438 _____ () C:\Users\PC1\AppData\Local\partner.bmp
==================== FCheck ================================
(If an entry is included in the fixlist, the file/folder will be moved.)
FCheck: C:\WINDOWS\SysWOW64\version_IObitDel.dll [2023-04-04] <==== ATTENTION (zero byte File/Folder)
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by PC1 (administrator) on DESKTOP-NORVJE6 (MSI MS-7A39) (23-08-2024 19:28:17)
Running from C:\Users\PC1\Desktop\FRST64 (1).exe
Loaded Profiles: PC1
Platform: Microsoft Windows 10 Home Version 22H2 19045.4780 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe ->) (Reaction Software Limited -> Weather Zero) C:\Program Files (x86)\WeatherZero\WeatherZero.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.125.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(cmd.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Discord Inc. -> Discord Inc.) C:\Users\PC1\AppData\Local\Discord\app-1.0.9159\Discord.exe <6>
(DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\atieclxx.exe
(explorer.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files (x86)\Adguard\Adguard.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.125.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe <6>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <17>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(services.exe ->) (Adguard Software Limited -> Adguard Software Limited) C:\Program Files (x86)\Adguard\AdguardSvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\atiesrxx.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe
(services.exe ->) (Reaction Software Limited -> Weather Information Service) C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\CPUMetricsServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102816 2022-01-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [ACUW17EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\acdIDInTouch2.exe [3508784 2024-01-13] (ACD Systems International Inc. -> ACD Systems International Inc.) [File not signed]
HKLM\...\Run: [Adguard] => C:\Program Files (x86)\Adguard\Adguard.exe [7233056 2024-07-08] (Adguard Software Limited -> Adguard Software Limited)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [235624 2015-01-09] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36733928 2024-08-17] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4407656 2024-07-17] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [PC1] => cmd.exe /c start www.exinariuminix.info (No File) <==== ATTENTION
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [482128 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44970408 2024-07-16] (Gen Digital Inc. -> Piriform Software Ltd)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [MicrosoftEdgeAutoLaunch_3ED1524B1F1362DAB86361CACD0A8016] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3814952 2024-08-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [ACDSeeCommanderUltimate17] => C:\Program Files\ACD Systems\ACDSee Ultimate\17.0\ACDSeeCommanderUltimate17.exe [8257104 2024-01-13] (ACD Systems International Inc. -> ) [File not signed]
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Discord] => C:\Users\PC1\AppData\Local\Discord\Update.exe [1526552 2024-04-29] (Discord Inc. -> GitHub)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [AMDNoiseSuppression] => C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe [145336 2023-08-10] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [Adguard] => C:\Program Files (x86)\Adguard\Adguard.exe [7233056 2024-07-08] (Adguard Software Limited -> Adguard Software Limited)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3380328 2024-08-23] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3805889190-2908880830-1705731779-1001\...\MountPoints2: {283cab94-2c81-11ea-925c-309c239b7301} - "F:\setup.exe"
HKLM\...\Windows x64\Print Processors\Canon MG3600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDCT.DLL [30208 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3600 series: C:\WINDOWS\system32\CNMLMCT.DLL [406528 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [375296 2015-03-17] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\128.0.6613.84\Installer\chrmstp.exe [2024-08-23] (Google LLC -> Google LLC)
IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll
IFEO\SppExtComObj.Exe: [VerifierDlls] SppExtComObjHook.dll
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5D40A70B-906F-47F3-ADB4-826F898DC794} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {EB38D2D3-9854-401B-BDFF-D9F93529BCCE} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1030872 2024-05-09] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {21CC9769-D945-4977-B5C7-308113D41473} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1030872 2024-05-09] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {398E64A3-B801-4BE2-ABFB-0CA8B59F0647} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [184024 2024-05-08] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {C9EE2F49-9A35-4606-8064-C015B14D20E1} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-08-05] (Avast Software s.r.o. -> Avast Software)
Task: {EA3A7B73-9018-48A2-B9A9-ACE08C2DCBCB} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [829408 2024-07-16] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {FDC29122-722C-4EB3-8FD0-285260CD7859} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-07-16] (Gen Digital Inc. -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "f629c2c0-113b-48e0-87af-a975de79342f" --version "6.26.11169" --silent
Task: {8A4A45D0-D188-4B76-B6A7-55090433182C} - System32\Tasks\CCleanerSkipUAC - PC1 => C:\Program Files\CCleaner\CCleaner.exe [38931368 2024-07-16] (Gen Digital Inc. -> Piriform Software Ltd)
Task: {93A99B83-4F2A-4BD8-8C22-25FA2926AA64} - System32\Tasks\Google Play Games Notifier => C:\Program Files\Google\Play Games\Bootstrapper.exe [374376 2024-08-17] (Google LLC -> Google LLC)
Task: {12326B1B-153A-478E-81F7-A984DA02CFD1} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem129.0.6651.0{1BE8927B-63D8-40E7-83EA-C0722ACFD7B2} => C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe [4906600 2024-08-11] (Google LLC -> Google LLC)
Task: {7EE7F7E0-3F0F-4093-9B95-D073D3BF70A0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {9A172CAE-E594-4004-8274-80EA84D69601} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {A689333B-D9AD-4A1E-BE3E-5A99BCA6022A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {3C9669D7-9BE7-4E1F-A396-4BA2DF95DED3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143248 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {DC7F1F62-2A22-455E-BD63-3A83557D2C67} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [65448 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {8487B275-D178-4E77-88A7-78C1BF6695FF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {C2C716A0-254D-4164-84C2-6810D9A8B11F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8502776 2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {3F6AE67B-B3ED-4923-9B36-C6AE40B44271} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {126EE5FF-146B-406A-BF81-EBF5EF264BE3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {235F13E8-6F65-4DF9-BB95-E1FE168A0ED0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {945B61AB-1DE3-4C92-B180-CB5DF8381D40} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0A869273-4468-4DF8-9C3D-F068C3BC02D8} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1030872 2024-05-09] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {4FB3A957-445C-4EFB-A0F8-0C00CB583A0E} - System32\Tasks\PC1 => C:\WINDOWS\system32\cmd.exe [289792 2024-05-17] (Microsoft Windows -> Microsoft Corporation) -> /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v PC1 /t REG_SZ /d "cmd.exe /c start www.exinariuminix.info" <==== ATTENTION
Task: {29C18D88-BE9E-4778-A260-6328474FB1D1} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [60632 2024-05-08] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {49E5F8B1-AF76-4BC3-A669-A999B860A808} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [324312 2024-05-08] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-31] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{a3cfb294-eb5a-46bb-8e56-15ac18209a18}: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{a3cfb294-eb5a-46bb-8e56-15ac18209a18}: [DhcpDomain] home
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default [2024-08-18]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-12]
Edge Extension: (Edge relevant text changes) - C:\Users\PC1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-04-07]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-06-27] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-06] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default [2024-08-23]
CHR DownloadDir: E:\Downloads\Filmy
CHR Notifications: Default -> hxxps://jutes.ru; hxxps://sibirem.ru; hxxps://slo.wikiwiex.com; hxxps://www.giveawayoftheday.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (AdBlock - najlepší blokovač reklám) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-08-23]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-08-17]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4 [2024-08-17]
CHR Extension: (Torrent Scanner) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2024-04-28]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-12]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC1\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-04-28]
CHR Profile: C:\Users\PC1\AppData\Local\Google\Chrome\User Data\System Profile [2024-08-23]
CHR HKLM\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [joiapjkjgbcljoopaenlplkfapolkdhp]
Opera:
=======
OPR Profile: C:\Users\PC1\AppData\Roaming\Opera Software\Opera Stable [2024-08-17]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Adguard Service; C:\Program Files (x86)\Adguard\AdguardSvc.exe [806944 2024-07-08] (Adguard Software Limited -> Adguard Software Limited)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [15737128 2024-05-11] (BattlEye Innovations e.K. -> )
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1085864 2024-07-16] (Gen Digital Inc. -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12477392 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4976976 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [13902952 2024-08-23] (Electronic Arts, Inc. -> Electronic Arts)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-10] (Epic Games Inc. -> Epic Games, Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460488 2024-04-03] (Canon Inc. -> )
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [6537200 2024-08-17] (Rockstar Games, Inc. -> Rockstar Games)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13353768 2021-09-15] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe [5084200 2024-05-11] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WeatherZeroSvc; C:\Program Files (x86)\WeatherZero\WeatherZeroService.exe [3256744 2022-06-12] (Reaction Software Limited -> Weather Information Service)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-08-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [12486496 2024-06-28] (KRAFTON, Inc. -> KRAFTON, Inc)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 2C50ECBD; C:\WINDOWS\System32\drivers\2C50ECBD.sys [478392 2021-04-14] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 adgnetworkwfpdrv; C:\WINDOWS\System32\drivers\adgnetworkwfpdrv.sys [88744 2024-05-23] (Microsoft Windows Hardware Compatibility Publisher -> Adguard Software Limited)
S3 AIDA64Driver; C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [68376 2021-03-29] (FinalWire Kft. -> )
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [25688 2024-02-22] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33504 2024-08-11] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R2 AMDRyzenMasterDriverV20; C:\WINDOWS\system32\AMDRyzenMasterDriver.sys [58952 2024-05-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_54807f69fe156f14\amdsafd.sys [113088 2023-04-13] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 amduw23g; C:\WINDOWS\System32\DriverStore\FileRepository\u0405203.inf_amd64_f475de4b004ff0ca\B405281\amdkmdag.sys [106157352 2024-08-11] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [61888 2023-05-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2020-11-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [63696 2023-04-04] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 MpKsl3026d0ab; C:\WINDOWS\system32\MpEngineStore\MpKslDrv.sys [271640 2024-08-17] (Microsoft Windows -> Microsoft Corporation)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2022-07-04] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22080 2024-08-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602504 2024-08-02] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105864 2024-08-02] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2022-10-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [215864 2024-05-24] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 amdwddmg; \SystemRoot\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [X]
S3 MpKsl7cd804ff; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4EE50D74-840B-42B0-9A5C-A4FA3FF166BB}\MpKslDrv.sys [X]
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-08-23 19:29 - 2024-08-23 19:29 - 002397184 _____ (Farbar) C:\Users\PC1\Desktop\FRST64.exe
2024-08-23 19:28 - 2024-08-23 19:28 - 000027084 _____ C:\Users\PC1\Desktop\FRST.txt
2024-08-23 19:28 - 2024-08-23 19:28 - 000000000 ____D C:\Users\PC1\Desktop\FRST-OlderVersion
2024-08-17 19:16 - 2024-08-17 19:16 - 000000000 ___HD C:\$WinREAgent
2024-08-17 09:04 - 2024-08-17 09:04 - 000000000 ____D C:\WINDOWS\system32\MpEngineStore
2024-08-11 15:22 - 2024-08-11 15:22 - 007598784 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdadlx64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 007373616 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdadlx32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 002921768 _____ C:\WINDOWS\system32\amd-smi.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 002287912 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsasrv64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 002152744 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 002101032 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 002101032 _____ C:\WINDOWS\system32\vulkaninfo.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 001797008 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001797008 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001726552 _____ (AMD) C:\WINDOWS\system32\amf-mft-mjpeg-decoder64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001659288 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 001659288 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 001466168 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001466168 _____ C:\WINDOWS\system32\vulkan-1.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001400912 _____ (AMD) C:\WINDOWS\SysWOW64\amf-mft-mjpeg-decoder32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001347768 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdsacli64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001307624 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001307624 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001254808 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001077280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdsacli32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001055528 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 001031464 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000632208 _____ C:\WINDOWS\system32\GameManager64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000591248 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000558888 _____ C:\WINDOWS\system32\atieah64.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000552888 _____ C:\WINDOWS\system32\amdmiracast.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000526232 _____ C:\WINDOWS\system32\EEURestart.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000479640 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000473488 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000449424 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000421680 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2024-08-11 15:22 - 2024-08-11 15:22 - 000280360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000236848 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000196392 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000190768 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000178872 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000168656 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000168552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000161808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000154152 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000150312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000142632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000140648 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000140648 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000140080 _____ C:\WINDOWS\system32\amdxc64.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000134312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000117040 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000116520 _____ C:\WINDOWS\SysWOW64\amdxc32.dll
2024-08-11 15:22 - 2024-08-11 15:22 - 000075160 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2024-08-11 15:21 - 2024-08-11 15:21 - 113329392 _____ C:\WINDOWS\system32\amdxc64.so
2024-08-11 15:21 - 2024-08-11 15:21 - 001344456 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 006160840 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 000052344 _____ (Advanced Micro Devices, Inc) C:\WINDOWS\system32\Drivers\amdgpio2.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 000039048 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\AMDPCIDev.sys
2024-08-11 15:20 - 2024-08-11 15:20 - 000033504 _____ (Advanced Micro Devices, Inc) C:\WINDOWS\system32\Drivers\amdgpio3.sys
2024-08-11 15:14 - 2024-08-17 14:34 - 000000000 ____D C:\ProgramData\ProductData
2024-08-11 15:13 - 2024-08-17 14:34 - 000000000 ____D C:\Program Files (x86)\IObit
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-08-23 19:28 - 2024-01-14 13:52 - 002397184 _____ (Farbar) C:\Users\PC1\Desktop\FRST64 (1).exe
2024-08-23 19:28 - 2021-06-26 13:26 - 000000000 ____D C:\Program Files (x86)\Steam
2024-08-23 19:28 - 2020-12-19 11:48 - 000000000 ____D C:\FRST
2024-08-23 19:26 - 2024-05-05 12:00 - 000000000 ____D C:\Users\PC1\AppData\Roaming\discord
2024-08-23 19:25 - 2024-07-07 21:18 - 000000000 ____D C:\ProgramData\EA Desktop
2024-08-23 19:25 - 2024-05-05 12:00 - 000000000 ____D C:\Users\PC1\AppData\Local\Discord
2024-08-23 19:24 - 2024-06-30 14:52 - 000000000 ____D C:\ProgramData\Adguard
2024-08-23 19:24 - 2024-06-14 18:50 - 000003114 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2024-08-23 19:24 - 2024-06-14 18:50 - 000003106 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2024-08-23 19:24 - 2021-03-09 16:44 - 000000000 ____D C:\Users\PC1\AppData\Local\CrashDumps
2024-08-23 19:24 - 2020-12-20 11:32 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-08-23 19:23 - 2021-01-02 13:33 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2024-08-23 19:23 - 2020-12-20 11:44 - 000000000 ____D C:\Users\PC1
2024-08-23 19:23 - 2020-12-20 11:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-08-23 19:23 - 2020-12-20 11:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-08-23 19:23 - 2020-11-07 11:27 - 000008192 ___SH C:\DumpStack.log.tmp
2024-08-23 19:15 - 2020-12-20 11:32 - 000000000 ___HD C:\Program Files\WindowsApps
2024-08-23 19:14 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-08-23 19:13 - 2022-02-10 23:30 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2024-08-23 19:13 - 2022-01-22 14:11 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3805889190-2908880830-1705731779-1001
2024-08-23 19:13 - 2020-12-20 11:44 - 000002365 _____ C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-08-23 19:10 - 2021-12-16 22:47 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-08-23 19:10 - 2020-12-20 12:00 - 000002259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-08-23 19:10 - 2020-12-20 12:00 - 000002218 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-08-23 19:09 - 2024-05-05 12:00 - 000002237 _____ C:\Users\PC1\Desktop\Discord.lnk
2024-08-23 19:08 - 2024-06-30 14:52 - 000000000 ____D C:\Program Files (x86)\Adguard
2024-08-19 04:48 - 2020-12-20 11:27 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-08-19 04:22 - 2020-12-20 11:55 - 000000000 ____D C:\Users\PC1\AppData\Local\D3DSCache
2024-08-18 20:41 - 2024-05-25 12:43 - 000000000 ____D C:\Users\PC1\Desktop\Mody
2024-08-18 20:40 - 2024-04-13 16:14 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Atlas
2024-08-18 16:50 - 2022-05-12 20:30 - 000655020 _____ C:\WINDOWS\system32\perfh01B.dat
2024-08-18 16:50 - 2022-05-12 20:30 - 000126030 _____ C:\WINDOWS\system32\perfc01B.dat
2024-08-18 16:50 - 2020-12-20 11:53 - 001547408 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-08-18 16:50 - 2020-12-20 11:31 - 000000000 ____D C:\WINDOWS\INF
2024-08-18 12:38 - 2022-05-05 20:54 - 000306624 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\SystemResources
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\setup
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\Provisioning
2024-08-18 12:36 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-08-18 10:19 - 2020-12-20 11:28 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-08-17 15:10 - 2024-03-31 14:40 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Ovix
2024-08-17 15:02 - 2021-10-08 19:04 - 000000000 ____D C:\Users\PC1\AppData\Roaming\Kodi
2024-08-17 14:42 - 2023-05-17 18:09 - 000000000 ____D C:\WINDOWS\Minidump
2024-08-17 14:42 - 2023-04-05 08:10 - 000000000 ____D C:\Program Files\CCleaner
2024-08-17 14:34 - 2022-01-30 18:11 - 000000000 ____D C:\Users\PC1\AppData\Roaming\IObit
2024-08-17 10:45 - 2020-12-20 11:32 - 000000000 ____D C:\WINDOWS\schemas
2024-08-17 09:29 - 2020-12-20 11:43 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-08-17 09:02 - 2020-12-20 12:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-08-17 09:01 - 2020-12-20 12:41 - 197093640 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-08-17 08:58 - 2020-12-23 18:30 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-08-17 08:58 - 2020-06-10 21:36 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-08-17 08:46 - 2022-04-03 11:14 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-08-11 17:41 - 2023-04-05 08:10 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-08-11 15:25 - 2024-04-20 14:27 - 000000000 ____D C:\ProgramData\Package Cache
2024-08-09 20:46 - 2024-06-14 18:30 - 000000000 ____D C:\Users\PC1\AppData\Local\AMD_Common
2024-08-04 14:57 - 2020-12-20 11:55 - 000000000 ____D C:\Users\PC1\AppData\Local\Packages
2024-08-03 08:37 - 2023-05-23 21:38 - 000000000 ____D C:\Users\PC1\AppData\Local\ElevatedDiagnostics
2024-08-03 08:13 - 2023-04-05 08:10 - 000002824 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-08-03 08:13 - 2023-04-05 08:10 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-08-02 22:51 - 2024-07-05 08:51 - 000000000 ____D C:\ProgramData\CanonIJPLM
2024-08-02 19:09 - 2020-12-20 11:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-07-28 13:44 - 2022-01-30 15:15 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-07-28 13:44 - 2022-01-30 15:15 - 000003508 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
==================== Files in the root of some directories ========
2024-05-16 23:47 - 2024-05-16 23:47 - 000000255 _____ () C:\ProgramData\fontcacheev1.dat
2021-06-06 10:33 - 2021-07-21 21:43 - 000000055 _____ () C:\Users\PC1\AppData\Roaming\EHWID.txt
2022-08-12 17:55 - 2023-09-16 20:35 - 000208896 _____ () C:\Users\PC1\AppData\Roaming\emp.bin
2021-06-06 10:33 - 2021-12-12 19:52 - 000000011 _____ () C:\Users\PC1\AppData\Roaming\EPW.txt
2021-06-06 10:33 - 2021-07-21 21:43 - 000000009 _____ () C:\Users\PC1\AppData\Roaming\ERole.txt
2021-06-06 10:33 - 2021-12-12 19:52 - 000000012 _____ () C:\Users\PC1\AppData\Roaming\EUser.txt
2021-03-07 20:58 - 2021-03-07 20:58 - 000016438 _____ () C:\Users\PC1\AppData\Local\partner.bmp
==================== FCheck ================================
(If an entry is included in the fixlist, the file/folder will be moved.)
FCheck: C:\WINDOWS\SysWOW64\version_IObitDel.dll [2023-04-04] <==== ATTENTION (zero byte File/Folder)
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================