Prosím o kontrolu LOGu
Napsal: 11 říj 2024 11:53
Ahoj prosím o kontrolu LOGU asi měsíc z5 mi začal počítač pomaleji nabíhat. Plocha s ikonami celkem hned, ale spodní řádek někdy naběhne po delší chvilce a jindy ne.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-09-2024
Ran by David (administrator) on DAVID-PC (11-10-2024 12:34:27)
Running from C:\Users\David\Downloads\FRST64.exe
Loaded Profiles: David & DefaultAppPool
Platform: Microsoft Windows 10 Pro Version 22H2 19045.5011 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe ->) (ASUSTeK Computer Inc. -> TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe
(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avpui.exe
(C:\Windows\SysWOW64\ASGT.exe ->) (ASUSTeK Computer Inc. -> TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
(C:\Windows\SysWOW64\cmd.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\plugins_nms.exe
(DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atieclxx.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Gen Digital Inc. -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <8>
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) () [File not signed] C:\Windows\SysWOW64\ASGT.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(services.exe ->) (Gen Digital Inc. -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinService.exe
(services.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2405.2.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (AO Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696840 2016-09-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [369504 2024-08-21] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [RemoteControl] => C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-11-02] (Cyberlink Corp.) [File not signed]
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4407656 2024-06-20] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45125936 2024-09-18] (Gen Digital Inc. -> Piriform Software Ltd)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [563416 2015-07-12] (ZONER software, a.s. -> ZONER software)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [MicrosoftEdgeAutoLaunch_32628329D6ABECAB6CD57130DDFBAC4F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3795008 2024-10-03] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-234310202-639468230-1125350010-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [39936 2024-05-15] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [6937552 2016-03-25] (ASUSTeK Computer Inc. -> TODO: <Company name>)
HKU\S-1-5-18\...\RunOnce: [Application Restart #2] => C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe [2756560 2016-03-25] (ASUSTeK Computer Inc. -> TODO: <Company name>)
HKU\S-1-5-18\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [6937552 2016-03-25] (ASUSTeK Computer Inc. -> TODO: <Company name>)
HKLM\...\Windows x64\Print Processors\Canon iP7200 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBA.DLL [30208 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\cx21msPC: C:\Windows\System32\spool\prtprocs\x64\cx21mspc.dll [33792 2007-02-23] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\CX21SPC: C:\Windows\System32\spool\prtprocs\x64\cx21spc.dll [33792 2007-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\spd__PC: C:\Windows\System32\spool\prtprocs\x64\spd__pc.dll [36864 2011-04-19] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\us016PC: C:\Windows\System32\spool\prtprocs\x64\us016pc.dll [61736 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Windows x64\Print Processors\xrhr1apps: C:\Windows\System32\spool\prtprocs\x64\xrhr1apps.dll [33280 2012-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Xerox)
HKLM\...\Print\Monitors\Canon BJ Language Monitor iP7200 series: C:\Windows\system32\CNMLMBA.DLL [389120 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor iP7200 series XPS: C:\Windows\system32\CNMXLMBA.DLL [392192 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\system32\CNMN6PPM.DLL [359936 2012-06-14] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\CX21S Langmon: C:\Windows\system32\cx21sl6.dll [22016 2007-01-26] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\novaPDF Port Monitor: C:\Windows\system32\novamn8.dll [18944 2016-03-03] (Softland) [File not signed]
HKLM\...\Print\Monitors\Software602 XPS port monitor: C:\Windows\system32\602localmon.dll [54864 2018-05-31] (Software602 a.s. -> Windows (R) Win 7 DDK provider)
HKLM\...\Print\Monitors\spd__ Langmon: C:\Windows\system32\spd__l.dll [34304 2011-04-11] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\us008 Langmon: us008lm.dll (No File)
HKLM\...\Print\Monitors\us016 Langmon: C:\Windows\system32\us016lm.dll [40744 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\Xerox Phaser 3010 Language Monitor: C:\Windows\system32\xrhr1aLM.DLL [22528 2012-03-09] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\129.0.6668.70\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\129.0.6668.90\Installer\chrmstp.exe [2024-10-05] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
HKLM\Software\...\Winlogon\GPExtensions: [{6cfb9c5c-138e-4bb3-8a3d-d5383e910e57}] -> %SystemRoot%\System32\RdpGroupPolicyExtension.dll
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
GroupPolicy: Restriction - Chrome <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {2AC90F88-9A57-42C8-AC78-4B6CF5043895} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {37ED89C6-4DA3-4BCC-8F33-731514F3FD67} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {6C6927D2-05C0-4FDD-8398-5469BF5EEA6B} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {6DD5873F-E02B-438B-8086-34F4229256FD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7039BE31-E3FC-4BAC-B61C-81B1A8CF0CAF} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {8042A09E-D2AF-40EE-8375-D25569DD37D6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {88604EBF-A126-4DC5-9AA4-F69EF67D5329} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {88DF0971-40EF-4D61-841A-C611901CB1AB} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {8FB6DBA0-D524-4155-B3FC-92C7D53F4EF2} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {A2C8EEB5-3815-4E06-B051-C35F9111CE07} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {AA5EC927-DFEB-4E7C-AD95-D4138F85E040} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {B1D82B51-4180-4CC3-9430-4F1A7BCCBE65} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {C49B6673-C8E4-442D-A1C3-A616DDAE3047} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {DFF0689F-3CF6-46EC-AD00-22A0B7B04FCD} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {FE1AD95F-6CCF-4627-A59D-E7B958CDFEF0} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {FFFFFE56-AA4D-4CFF-BA0B-A25F48D87EC1} - System32\Tasks\{00A2910E-9883-4060-A579-397DC8EAC8DC} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Program Files (x86)\sweetpacks bundle uninstaller\uninstaller.exe" -c "/appName=Video Converter Bundle by SweetPacks"
Task: {904BAFAF-9950-4B86-A5FC-9BCB2D01AC5A} - System32\Tasks\{4784CB87-D4A5-491E-89C2-8EA7C3EC4675} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Program Files (x86)\Samsung\Samsung CLX-216x Series\Install\Setup.exe" -d "C:\Program Files (x86)\Samsung\Samsung CLX-216x Series\Install" -c /R
Task: {42AAF426-1915-401A-B9E2-22573F109C2C} - System32\Tasks\{515A693B-7236-4045-BE8F-ED36467694F1} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a E:\David\podnikatel\Krosplus\setup.exe -d E:\David\podnikatel\Krosplus
Task: {AA3CB2D7-E7A0-4163-85F3-4B73FC37F97A} - System32\Tasks\{B495744B-EDBE-48E3-8F31-7B01495F131C} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Program Files (x86)\sweetpacks bundle uninstaller\uninstaller.exe" -d "C:\Program Files (x86)\sweetpacks bundle uninstaller"
Task: {18A2AA2C-6D9E-483E-86DC-554A7FFBE29D} - System32\Tasks\{C24E80EE-48B2-4882-932B-E3D1F14FEB0E} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\David\Desktop\setup.exe -d C:\Users\David\Desktop
Task: {7B6D9C83-277B-4D92-AC11-86E96C53FDFB} - System32\Tasks\2fd443a4-a045-4174-b2c4-f1820e73a1d0 => C:\Program Files (x86)\App Lid\2fd443a4-a045-4174-b2c4-f1820e73a1d0.exe 000820 00B9CD6C67EF4CBF9D04EBB665B3BFEAIE 65743 1416254269 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 App Lid (No File) <==== ATTENTION
Task: {5344E45D-C48C-476D-85C0-D2C23B729613} - System32\Tasks\6853298a-8b0c-402f-a7fd-d260c142247a => C:\Program Files (x86)\App Lid\6853298a-8b0c-402f-a7fd-d260c142247a.exe -> /agentregpath='App Lid' /appid=65743 /srcid='000820' /subid='0' /zdata='appshatmadness' /bic=00B9CD6C67EF4CBF9D04EBB665B3BFEAIE /verifier=ef2bdfa8da72bad89893f622bd3d1814 /installerversion=1_35_09_29 /installationtime=1416254269 /statsdomain=hxxp://stats.newonlinedatastack.com /errorsdomain=hxxp://e (the data entry has 240 more characters). <==== ATTENTION
Task: {E68FAA27-D527-4F1B-A4B1-084DEAB8D9E3} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe -> C:\PROGRA~2\AD-AWA~1\--scan=full
Task: {E9BEF7A1-77D1-431C-A7CD-90B44FE1DE98} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe -> C:\Program Files (x86)\Lavasoft\Ad-Aware\\update all silent repair
Task: {BCC82C02-63FB-4ADC-AADA-8BEBD5497AF4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {029826BA-8951-406F-A862-563BD194E79D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {BE99DFE2-E67F-41FB-A7B1-AF48EB2F8547} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [829408 2024-09-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {CFB7B590-2910-47A4-9247-8D6435D4D5F0} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5937456 2024-09-18] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "e347d9a0-b6a7-48c9-8f41-648f619f4556" --version "6.28.11297" --silent
Task: {69477C37-F9FC-40A6-931E-170615502F53} - System32\Tasks\CCleanerSkipUAC - David => C:\Program Files\CCleaner\CCleaner.exe [39012144 2024-09-18] (Gen Digital Inc. -> Piriform Software Ltd)
Task: {E1D4050E-998B-49B9-B61B-5AC2B8FBEFA3} - System32\Tasks\CorelUpdateHelperTask-B04F3EEB88A98EA1BE397AA9B1F1CA60 => C:\Program Files (x86)\Corel\CUH\v2\CUH.EXE [3834384 2024-01-24] (Corel Corporation -> Corel Corporation)
Task: {FC2E731C-A8C5-4D08-859F-85DED12519CD} - System32\Tasks\CorelUpdateHelperTaskCore => C:\Program Files (x86)\Corel\CUH\v2\CUH.EXE [3834384 2024-01-24] (Corel Corporation -> Corel Corporation)
Task: {38DDF377-04CD-41AA-9AA4-B0EE949B1AE2} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3660232 2020-02-17] (Easeware Technology Limited -> Easeware) -> C:\Program Files\Easeware\DriverEasy\--scan
Task: {A62EE96E-E9B3-49E9-B645-F6B91CB53302} - System32\Tasks\Fekutain Renew => C:\Program Files (x86)\Ckerhryanutash\jiule.exe [779416 2016-10-22] (Glarysoft LTD -> Glarysoft Ltd)
Task: {8F949EBB-0E35-4A6C-90B8-F20BAD0BDB02} - System32\Tasks\FOSCAMVMS => C:\Program Files (x86)\FoscamVMS\VMSClient.exe [1686464 2018-11-15] (Shenzhen Foscam Intelligent Technology Co., Ltd. -> Shenzhen Foscam Intelligent Technology Co., Ltd.)
Task: {C4ED8497-7ABA-450E-9D02-E880A8863B13} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [29464 2023-02-22] (Garmin International, Inc. -> )
Task: {FE3EC57F-624E-4803-8D09-9296B9D3F795} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{87BB2AE4-A3D5-4EFE-91FB-95BC2E00E3AB} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
Task: {09843AB4-8BC6-4952-8821-8AA799B9BC48} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\IntelPTTEKRecertification.exe [855664 2023-12-14] (Intel Corporation -> Intel(R) Corporation)
Task: {5B12D0E1-AC22-4189-B4DB-F2E07EFE3B4A} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1328392 2016-03-17] (Intel(R) Software -> Intel Corporation)
Task: {8C268EF6-BB0F-4E89-9E50-CC1B3B9FEAD4} - System32\Tasks\Kaspersky_Product_Update_{20C91119-626A-4305-906C-90F5A4B77B67}_KSDE => C:\ProgramData\Kaspersky Lab\KSDE1.0.0\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe [2677080 2024-01-26] (AO Kaspersky Lab -> Kaspersky) -> /u -newverwelcome /rSoftware\KasperskyLab\KSDE1.0.0\ProductUpdate /rSoftware\KasperskyLab\ProductUpdate_ksde -old_prod_data_dir="C:\ProgramData\Kaspersky Lab\KSDE1.0.0\Data" /p"INSTALLED_BY_TFU_CAMPAIGN_ID=F62ACB26-306E-C100-A9FF-4CF4F2E89D35" /lcs-CZ <==== ATTENTION
Task: {389962A0-6A36-4171-AC31-FD34F8F55606} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [743488 2021-04-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
Task: {EBBB7239-4DFA-4C06-93AA-28D2F717BFD5} - System32\Tasks\kpm_tray.exe => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe [631704 2024-07-25] (AO Kaspersky Lab -> AO Kaspersky Lab)
Task: {6C9E5DA9-74DA-4082-A69F-F08BA3046058} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe -> C:\Program Files (x86)\HTC\HTC Sync 3.0\\-startup
Task: {CD63DEF8-6A27-4CD1-A330-D2476DF7B301} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {7D2EC5E1-B587-4E58-8D8D-7EA1CEE05582} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => C:\WINDOWS\system32\clipesu.exe [221680 2024-10-01] (Microsoft Windows -> Microsoft Corporation)
Task: {FCBADFB2-5ED7-4CED-9102-72B20992E0FE} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File)
Task: {293F5798-A38E-445C-A0C4-8859C0DB1C66} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File)
Task: {2DDE4D9F-12CE-4D11-AAB4-9968C43733E5} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File)
Task: {14D67678-895A-44C4-B845-223C7D9E3596} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe /DRMInit (No File)
Task: {DEBAC7EC-A137-49EB-8858-DE64D511483F} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-DAVID-PC => %systemroot%\ehome\McxTask.exe -acl S-1-5-21-234310202-639468230-1125350010-1260 (No File)
Task: {31C1FC34-6A68-4619-B192-03D418523B90} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File)
Task: {4A665B29-B9B2-4DC9-A2AB-FB3D1F69A896} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate $(Arg0) (No File)
Task: {85BC120A-8062-44F8-B90C-F4AAC2A72E0C} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15 (No File)
Task: {8EA066F3-022B-4A81-851A-B73D6433CEBC} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask (No File)
Task: {AA43CB9E-2C41-46F7-935B-BF7321BA5D4D} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File)
Task: {5DE5A09A-C871-46C0-BBDD-B8BE531C4D95} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate (No File)
Task: {05277711-0A78-4D0D-B331-32B88F240EE9} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File)
Task: {A74FA460-CFCA-404F-9AC1-73E494A1BAAA} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery (No File)
Task: {CE1DAEF1-2350-4133-AE3D-7FAE54553EED} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File)
Task: {3EFB9CF6-FF9F-4137-9752-B093E7596A54} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File)
Task: {7CAABAEB-E8EE-444E-A4E4-CE4B62892F4B} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe -pscn 0 (No File)
Task: {81145E73-EE27-4C67-8A1D-91D36FD6A386} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask (No File)
Task: {55CF3F02-17AD-42F7-ADC2-DEA3794D34CA} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe -PvrSchedule (No File)
Task: {E1760C62-0555-4EB9-AE7B-3ABE25CB6DDA} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec /RestartRecording (No File)
Task: {ED163B34-B890-407B-B1B5-8465A99AD77F} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File)
Task: {25D2B6BD-09F1-4D2B-AE72-F2B6F01F0132} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File)
Task: {F6658C5D-0205-406A-83A5-1A88A87340FE} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File)
Task: {B925F356-B440-4628-A80B-9A13C63F63CB} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec /StartRecording (No File)
Task: {AE1BFED4-717F-4013-A640-ECDB27135FF1} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File)
Task: {EFFAC042-7727-4087-958D-1378CD23B0A6} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {5C486C2A-C970-443E-90AB-9513721A10C4} - System32\Tasks\Microsoft\Windows\rempl\shell-usoscan => %ProgramFiles%\rempl\remsh.exe /RunUsoScanOnly (No File)
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {2063DEC9-B62F-4FD4-91E5-4FF87CAF82D9} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {AFF7687A-628C-45C1-A911-69D1A0E828FD} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {D085D0EC-B970-40AB-A761-E7017A709139} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {9B859B95-004D-41CB-B687-FA18A2CAB224} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {49B59051-6F81-44A7-9E19-FA8C07BF5D3B} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-08-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {F1FD3F64-E18B-4425-BE90-FC86CB1854B0} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [850928 2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {5C855462-673F-4476-BA02-585A12CAF509} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [850928 2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {F9A5B545-1628-4EA8-A471-08083F7997F1} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3293168 2020-04-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {802E59FB-3592-4152-966A-60503DE9E9E6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {923794DC-0CDA-448E-8525-715E8DA68354} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C58C2297-25AA-4CEE-997C-234AA46AAD85} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DC82CFBD-1291-4CAD-83DB-4A4D40C01557} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0C2A5BF4-68D5-47B2-91D2-45782B26F875} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C83324EB-CDAA-4442-9D3B-A1F1082658B8} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FA1EF938-1033-4017-A4F0-FB1EBD955D92} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9BBDD627-BE60-4684-B35E-A7A9BE1F0D35} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63960 2021-08-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {1F712B79-A8A2-44EC-9F3E-67F625937E11} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-08-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\2fd443a4-a045-4174-b2c4-f1820e73a1d0.job => C:\Program Files (x86)\App Lid\2fd443a4-a045-4174-b2c4-f1820e73a1d0.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\6853298a-8b0c-402f-a7fd-d260c142247a.job => C:\Program Files (x86)\App Lid\6853298a-8b0c-402f-a7fd-d260c142247a.exeȝ/agentregpath='App Lid' /appid=65743 /srcid='000820' /subid='0' /zdata='appshatmadness' /bic=00B9CD6C67EF4CBF9D04EBB665B3BFEAIE /verifier=ef2bdfa8da72bad89893f622bd3d1814 /installerversion=1_35_09_29 /installationtime=1416254269 /statsdomain=hxxp:/stats.newonlinedatastack.com /errorsdomain=hxxp:/errors.newonlinedatastack.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=hxxp:/logs.newonlinedatastack.com <==== ATTENTION
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-234310202-639468230-1125350010-1000] => 10.0.1.15:5000
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63f25f19-61de-41d1-91f2-ffed16c70de1}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{d7045652-7fee-445e-90db-6c4d79232915}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default [2024-10-11]
Edge HomePage: Default -> hxxp://www.seznam.cz/
Edge StartupUrls: Default -> "hxxps://seznam.cz/"
Edge Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2024-05-27]
Edge Extension: (Dokumenty Google offline) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-11]
Edge Extension: (Edge relevant text changes) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge HKU\S-1-5-21-234310202-639468230-1125350010-1000\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
Edge HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
FireFox:
========
FF ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default [2024-10-11]
FF Homepage: Mozilla\Firefox\Profiles\uaym47la.default -> www.seznam.cz
FF Extension: (Video AdBlock for Firefox) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\Extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92} [2016-01-05] [Legacy] [not signed]
FF Extension: (No Name) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [not found]
FF Extension: (No Name) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\extensions\sko-extension@firma.seznam.cz [not found]
FF SearchPlugin: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\searchplugins\a9sd1koa.xml [2016-10-22]
FF HKLM\...\Firefox\Extensions: [light_plugin_F363A72DD7B6435783A76E5F612C9006@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F363A72DD7B6435783A76E5F612C9006@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => not found
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-10-01] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2014-11-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2018-01-08] (Software602 a.s. -> Software602 a.s.)
FF Plugin-x32: synology.com/SurveillanceHelper -> C:\Program Files (x86)\Synology\SurveillanceHelper\1.0.0.3\npSurveillanceHelper.dll [2013-11-11] (Synology Inc. -> Synology)
FF Plugin-x32: synology.com/SurveillancePlugin -> C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.429\npSurveillancePlugin.dll [2014-10-30] (Synology Inc. -> Synology)
FF Plugin HKU\S-1-5-21-234310202-639468230-1125350010-1000: @foscam.com/npWebPlugin -> C:\Program Files (x86)\FoscamVMS\WebPlugin\npWebPlugin.dll [No File]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Default [2024-10-11]
CHR Notifications: Default -> hxxps://mail.google.com
CHR HomePage: Default -> hxxp://www.google.cz/
CHR StartupUrls: Default -> "hxxp://www.google.cz/"
CHR Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2024-05-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-10-11]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\System Profile [2024-10-11]
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s. -> Software602 a.s.)
R4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [48640 2015-08-18] () [File not signed]
R2 AVP21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe [184768 2021-06-17] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8615864 2020-05-20] (BattlEye Innovations e.K. -> )
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1087792 2024-09-18] (Gen Digital Inc. -> Piriform Software Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [784512 2018-09-13] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S4 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] (Canon Inc. -> )
S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 klvssbridge64_21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\vssbridge64.exe [479280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [382360 2024-07-25] (AO Kaspersky Lab -> AO Kaspersky Lab)
S3 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab)
S4 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [50600 2016-03-03] (Softland SRL -> Microsoft)
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S4 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S3 Samsung UPD Service2; C:\WINDOWS\System32\SUPDSvc2.exe [165456 2011-12-02] (Samsung Electronics CO., LTD. -> Samsung Electronics)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [530488 2024-09-20] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [183816 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
S4 Synology Drive VSS Service x64; C:\Program Files (x86)\Synology\SynologyDrive\bin\vss-service-x64.exe [371672 2020-05-08] (Synology Inc. -> )
S4 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [253912 2019-10-30] (Synology Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
S4 ZoomCptService; "C:\Program Files (x86)\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\David\AppData\Roaming\Zoom"
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_d4de13a10f2586d0\amdsafd.sys [112952 2024-06-15] (AMD Test Build -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\amdkmdag.sys [106596128 2024-09-04] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [65168 2021-08-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 busenum; C:\WINDOWS\System32\drivers\busenum.sys [57824 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [237288 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-10-22] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-10-22] (Disc Soft Ltd -> Disc Soft Ltd)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_dded470da430edc1\e1d.sys [612960 2024-06-19] (Intel Corporation -> Intel Corporation)
R0 gfibto; C:\WINDOWS\System32\drivers\gfibto.sys [14456 2012-12-15] (GFI Software Development Ltd. -> GFI Software)
S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2016-08-21] (Sony Mobile Communications AB -> Sony Mobile Communications)
S3 htcnprot; C:\WINDOWS\System32\DRIVERS\htcnprot.sys [36928 2012-12-07] (HTC Corp. -> Windows (R) Win 7 DDK provider)
R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [24824 2014-10-23] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [105280 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [206600 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [119568 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [41656 2021-02-19] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [533040 2024-04-04] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [857416 2024-08-23] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [2102600 2024-08-23] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.3\Bases\klids.sys [236440 2024-07-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1051184 2024-04-04] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [90896 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [104728 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [107328 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [78088 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [88328 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [396040 2024-07-23] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [362464 2024-08-13] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [198720 2024-07-30] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [265416 2024-07-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [150280 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [325400 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [294680 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 NTIOLib_1_0_1; C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [14136 2009-10-06] (Micro-Star Int'l Co. Ltd. -> MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v130\NTIOLib_X64.sys [11888 2011-01-06] (Micro-Star Int'l Co. Ltd. -> MSI) [File not signed]
S3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 pccsmcfd; C:\WINDOWS\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-10-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 ROCKEYNT; C:\WINDOWS\system32\DRIVERS\Rockey4.sys [36904 2015-10-13] (Feitian Technologies Co., Ltd. -> Feitian Technologies Co., Ltd.)
S3 Rockey_USB; C:\WINDOWS\system32\DRIVERS\Rockey4USB.sys [23592 2015-10-13] (Feitian Technologies Co., Ltd. -> Feitian Technologies Co., Ltd.)
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 STHFK; C:\WINDOWS\System32\Drivers\stw1064.sys [56120 2017-03-28] (QUALCOMM Incorporated -> QTI Ltd)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2017-11-27] (Apple, Inc.) [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-10-11 12:34 - 2024-10-11 12:35 - 000052529 _____ C:\Users\David\Downloads\FRST.txt
2024-10-11 12:34 - 2024-10-11 12:34 - 000000000 ____D C:\FRST
2024-10-11 12:33 - 2024-10-11 12:33 - 002397696 _____ (Farbar) C:\Users\David\Downloads\FRST64.exe
2024-10-11 06:17 - 2024-10-11 06:17 - 000000000 ____D C:\Users\David\AppData\Local\{E8118928-1853-4120-9CAF-B9E6FE09AF25}
2024-10-10 16:51 - 2024-10-10 16:53 - 000000000 ___HD C:\$WinREAgent
2024-10-10 16:37 - 2024-10-10 16:37 - 000000000 ____D C:\Users\David\AppData\Local\{D5F8B2BD-5F2E-4412-A7AD-AC6E22408ED9}
2024-10-09 09:49 - 2024-10-09 09:49 - 000000000 ____D C:\Users\David\AppData\Local\{85E65443-D25B-466A-942C-43B484844D86}
2024-10-08 22:01 - 2024-10-08 22:01 - 000000000 ____D C:\Users\David\AppData\Local\{9935FB11-5E85-473E-BFFF-9A848F6C1B19}
2024-10-08 09:42 - 2024-10-08 09:42 - 000000000 ____D C:\Users\David\AppData\Local\{65876707-707D-42EA-9CD7-4853309F64C6}
2024-10-07 09:33 - 2024-10-07 09:31 - 001106794 _____ C:\Users\David\Desktop\vypoved tmobile.jpeg
2024-10-07 08:57 - 2024-10-07 08:57 - 000000000 ____D C:\Users\David\AppData\Local\{8A8C7FB5-44C3-44A3-9EB1-968F84DB7452}
2024-10-06 12:04 - 2024-10-06 12:04 - 000000000 ____D C:\Users\David\AppData\Local\{5C1F0473-593D-4BCE-849E-BECFCB5A63F0}
2024-10-05 12:54 - 2024-10-05 12:54 - 000000000 ____D C:\Users\David\AppData\Local\{768903B2-5BFF-462D-849C-5E39093B6C50}
2024-10-03 12:01 - 2024-10-03 12:01 - 001087215 _____ C:\Users\David\Desktop\toitoi.jpeg
2024-10-03 10:51 - 2024-10-03 10:51 - 000000000 ____D C:\Users\David\AppData\Local\{ACE0432C-B227-4213-9E42-0C0A296417E1}
2024-10-02 12:06 - 2024-10-02 12:06 - 000000000 ____D C:\Users\David\AppData\Local\{04561F26-3716-45F5-9044-F780DA9DE77B}
2024-10-01 14:05 - 2024-10-01 14:05 - 000001383 _____ C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2024-10-01 14:05 - 2024-10-01 14:05 - 000000000 ____D C:\Users\David\AppData\Local\PCHealthCheck
2024-10-01 12:21 - 2024-10-03 11:01 - 000001415 _____ C:\Users\Public\Desktop\Skype.lnk
2024-10-01 12:21 - 2024-10-03 11:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2024-10-01 12:20 - 2024-10-01 12:20 - 000001852 _____ C:\Users\Public\Desktop\iTunes.lnk
2024-10-01 12:20 - 2024-10-01 12:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2024-10-01 12:20 - 2024-10-01 12:20 - 000000000 ____D C:\Program Files\iTunes
2024-10-01 12:19 - 2024-10-01 12:19 - 000000000 ____D C:\Program Files\Bonjour
2024-10-01 12:19 - 2024-10-01 12:19 - 000000000 ____D C:\Program Files (x86)\Bonjour
2024-10-01 12:18 - 2024-10-01 12:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoom
2024-10-01 12:18 - 2024-10-01 12:18 - 000000000 ____D C:\Program Files (x86)\Zoom
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\UC.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\RAR.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\PKZIP.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\PKUNZIP.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\LHA.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\ARJ.PIF
2024-10-01 11:26 - 2024-10-01 11:26 - 000000000 ____D C:\Users\David\AppData\Local\{A29F9C9E-9254-44B7-BA41-A35981FB2964}
2024-09-30 09:00 - 2024-09-30 09:00 - 000000000 ____D C:\Users\David\AppData\Local\{D3588663-D00F-4970-BBAD-D0A857C370F5}
2024-09-27 04:57 - 2024-09-27 04:57 - 000000000 ____D C:\Users\David\AppData\Local\{60B223EA-59E7-4F99-8893-F70746CF4FCB}
2024-09-26 16:57 - 2024-09-26 16:57 - 000000000 ____D C:\Users\David\AppData\Local\{AFAC2BD1-F3AC-4028-B5B4-FCC387A8723F}
2024-09-25 08:54 - 2024-09-25 08:54 - 000000000 ____D C:\Users\David\AppData\Local\{AB14004C-29ED-433F-A804-A46272A6E640}
2024-09-24 11:12 - 2024-09-24 11:12 - 000000000 ____D C:\Users\David\AppData\Local\{0E3530EB-F41F-43E8-BF27-667029A39521}
2024-09-23 09:30 - 2024-09-23 09:30 - 000000000 ____D C:\Users\David\AppData\Local\{FC642EC7-A10B-48AC-B6B2-F9D65B1FFFEE}
2024-09-22 13:25 - 2024-09-22 13:25 - 000000000 ____D C:\Users\David\AppData\Local\{79EA8DAF-7F63-4A4A-BA58-AA74994B15D7}
2024-09-20 10:04 - 2024-09-20 10:04 - 000000000 ____D C:\Users\David\AppData\Local\{8F8DDF4A-6278-467A-9CA0-747649E12AE1}
2024-09-19 09:32 - 2024-09-19 09:32 - 000000000 ____D C:\Users\David\AppData\Local\{882FC137-FFD5-4E82-B6F1-A6E42B7AAC49}
2024-09-18 10:20 - 2024-09-18 10:20 - 000000000 ____D C:\Users\David\AppData\Local\{43D7013B-D351-4EEB-9624-9D17C701FAA6}
2024-09-17 10:04 - 2024-09-17 10:04 - 000065528 _____ C:\Users\David\Desktop\Benq.pdf
2024-09-17 09:55 - 2024-09-17 09:55 - 000000000 ____D C:\Users\David\AppData\Local\{BD03B4D5-C217-4EA1-B694-F066F1549E25}
2024-09-13 11:17 - 2024-09-13 11:17 - 000000000 ____D C:\Users\David\AppData\Local\{61662EAC-BBB0-4C6D-B6E6-1A4CCACA153B}
2024-09-11 10:36 - 2024-09-11 10:36 - 000325722 _____ C:\Users\David\Downloads\962153273.pdf
2024-09-11 10:31 - 2024-09-11 10:31 - 000000000 ____D C:\Users\David\AppData\Local\{25CEEB94-E231-4396-8AAD-44EA681CDD3C}
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-10-11 12:28 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-10-11 12:28 - 2016-12-16 13:54 - 000000000 ____D C:\Program Files\CCleaner
2024-10-11 12:25 - 2017-08-20 19:23 - 000000000 ____D C:\ProgramData\NVIDIA
2024-10-11 12:23 - 2018-09-13 16:11 - 000000000 ____D C:\Users\David\AppData\Local\D3DSCache
2024-10-11 12:17 - 2022-02-18 10:54 - 000000000 ____D C:\Program Files\RUXIM
2024-10-11 06:25 - 2020-09-24 08:55 - 000003542 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-10-10 17:53 - 2024-04-04 10:08 - 000003444 _____ C:\WINDOWS\system32\Tasks\CorelUpdateHelperTask-B04F3EEB88A98EA1BE397AA9B1F1CA60
2024-10-10 17:01 - 2020-09-24 08:56 - 001875976 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-10-10 17:01 - 2019-12-07 16:43 - 000781868 _____ C:\WINDOWS\system32\perfh005.dat
2024-10-10 17:01 - 2019-12-07 16:43 - 000172602 _____ C:\WINDOWS\system32\perfc005.dat
2024-10-10 17:01 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-10-10 16:55 - 2020-11-16 12:43 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2024-10-10 16:55 - 2020-09-24 08:55 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-10-10 16:55 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-10-10 16:55 - 2012-06-13 01:01 - 000000000 ____D C:\Intel
2024-10-10 16:53 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-10-10 16:51 - 2013-08-14 22:31 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-10-10 16:48 - 2022-10-13 11:46 - 000002109 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-10-10 16:48 - 2022-10-13 11:46 - 000002097 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2024-10-10 16:46 - 2014-05-01 08:36 - 201324920 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-10-10 16:40 - 2012-06-14 14:14 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\Word
2024-10-10 16:36 - 2018-08-31 07:38 - 000000000 ____D C:\Users\David\Desktop\faktury z plochy
2024-10-10 16:35 - 2020-09-24 08:55 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-10-10 16:35 - 2020-09-24 08:55 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-10-09 15:18 - 2012-06-13 21:27 - 000000000 ___RD C:\Users\David\Documents\Scanned Documents
2024-10-09 15:13 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-10-09 12:23 - 2021-12-16 08:21 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-10-09 12:23 - 2020-09-24 08:41 - 000654384 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-10-09 12:23 - 2019-12-07 16:44 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2024-10-09 12:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-10-09 12:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-10-09 12:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-10-09 12:16 - 2012-06-14 14:16 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\Excel
2024-10-09 11:57 - 2020-09-24 08:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-10-09 11:46 - 2020-09-24 08:41 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-10-08 22:10 - 2012-08-21 16:37 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\PowerPoint
2024-10-08 21:28 - 2012-06-14 14:14 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\Office
2024-10-08 19:00 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-10-08 18:23 - 2016-07-20 18:03 - 000000000 ____D C:\Users\David\AppData\Roaming\vlc
2024-10-08 18:19 - 2021-12-13 08:43 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-234310202-639468230-1125350010-1000
2024-10-08 18:19 - 2020-09-24 08:55 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-234310202-639468230-1125350010-1000
2024-10-08 18:19 - 2020-09-24 08:43 - 000002415 _____ C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-10-07 14:03 - 2013-03-29 12:04 - 000000000 ____D C:\Users\David\AppData\Local\CrashDumps
2024-10-07 08:54 - 2024-01-26 13:52 - 000004284 _____ C:\WINDOWS\system32\Tasks\Kaspersky_Product_Update_{20C91119-626A-4305-906C-90F5A4B77B67}_KSDE
2024-10-06 12:06 - 2012-06-14 14:11 - 000000000 ____D C:\Users\David\AppData\Local\GHISLER
2024-10-05 12:58 - 2016-11-06 00:02 - 000002337 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-10-05 12:54 - 2020-06-05 06:21 - 000002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-10-05 12:54 - 2020-06-05 06:21 - 000002310 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-10-03 11:04 - 2020-10-19 12:47 - 000000424 _____ C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-10-01 14:21 - 2021-10-11 12:51 - 000002262 _____ C:\WINDOWS\system32\Tasks\StartCN
2024-10-01 14:21 - 2021-10-11 12:51 - 000002182 _____ C:\WINDOWS\system32\Tasks\StartDVR
2024-10-01 12:25 - 2020-10-19 12:47 - 000003608 _____ C:\WINDOWS\system32\Tasks\Driver Easy Scheduled Scan
2024-10-01 12:25 - 2020-09-24 08:55 - 000004934 _____ C:\WINDOWS\system32\Tasks\Fekutain Renew
2024-10-01 12:25 - 2020-09-24 08:55 - 000003212 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003044 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000002804 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:23 - 2020-11-16 12:43 - 000000000 ____D C:\Users\David\AppData\Local\AMD
2024-10-01 12:23 - 2020-10-22 16:09 - 000000000 ____D C:\Users\David\AppData\Roaming\Zoom
2024-10-01 12:19 - 2018-01-30 08:11 - 000000952 _____ C:\Users\Public\Desktop\VLC media player.lnk
2024-10-01 12:19 - 2013-05-07 15:09 - 000000000 ____D C:\ProgramData\Package Cache
2024-10-01 12:18 - 2013-11-25 22:22 - 000001084 _____ C:\Users\Public\Desktop\Winamp.lnk
2024-10-01 12:18 - 2013-11-25 22:22 - 000000000 ____D C:\Program Files (x86)\Winamp
2024-10-01 12:17 - 2012-06-14 21:45 - 000000000 ____D C:\totalcmd
2024-10-01 11:30 - 2021-01-27 13:27 - 000000000 ____D C:\Users\David\AppData\Local\AMD_Common
2024-09-20 17:06 - 2022-09-21 19:51 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-09-20 17:05 - 2019-12-07 16:47 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2024-09-20 17:05 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-09-20 17:05 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-09-20 10:20 - 2022-11-13 10:01 - 000003378 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-09-20 10:20 - 2020-09-24 08:55 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-09-18 19:35 - 2020-09-24 08:43 - 000000000 ____D C:\Users\David
2024-09-17 10:00 - 2022-09-12 08:15 - 000000000 ____D C:\Users\David\AppData\Roaming\com.adobe.dunamis
2024-09-17 10:00 - 2012-06-13 22:46 - 000000000 ____D C:\Users\David\AppData\Local\Adobe
2024-09-17 10:00 - 2012-06-13 01:27 - 000000000 ____D C:\Users\David\AppData\Roaming\Adobe
==================== Files in the root of some directories ========
2016-09-19 15:32 - 2016-11-30 18:38 - 000001419 _____ () C:\Users\David\AppData\Roaming\DAVID-PC.MTBF.txt
2014-09-01 10:18 - 2016-01-03 14:15 - 000000365 _____ () C:\Users\David\AppData\Roaming\KBOEPUQ
2015-11-30 14:44 - 2015-11-30 14:44 - 000000038 ___SH () C:\Users\David\AppData\Local\69ff07055291669bb2b218.72821112
2014-08-20 18:43 - 2014-09-29 22:18 - 000007602 _____ () C:\Users\David\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-09-2024
Ran by David (administrator) on DAVID-PC (11-10-2024 12:34:27)
Running from C:\Users\David\Downloads\FRST64.exe
Loaded Profiles: David & DefaultAppPool
Platform: Microsoft Windows 10 Pro Version 22H2 19045.5011 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe ->) (ASUSTeK Computer Inc. -> TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe
(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avpui.exe
(C:\Windows\SysWOW64\ASGT.exe ->) (ASUSTeK Computer Inc. -> TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
(C:\Windows\SysWOW64\cmd.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\plugins_nms.exe
(DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atieclxx.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Gen Digital Inc. -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <8>
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) () [File not signed] C:\Windows\SysWOW64\ASGT.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(services.exe ->) (Gen Digital Inc. -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinService.exe
(services.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2405.2.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (AO Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696840 2016-09-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [369504 2024-08-21] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [RemoteControl] => C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-11-02] (Cyberlink Corp.) [File not signed]
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4407656 2024-06-20] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45125936 2024-09-18] (Gen Digital Inc. -> Piriform Software Ltd)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [563416 2015-07-12] (ZONER software, a.s. -> ZONER software)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Run: [MicrosoftEdgeAutoLaunch_32628329D6ABECAB6CD57130DDFBAC4F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3795008 2024-10-03] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-234310202-639468230-1125350010-1000\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-234310202-639468230-1125350010-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [39936 2024-05-15] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [6937552 2016-03-25] (ASUSTeK Computer Inc. -> TODO: <Company name>)
HKU\S-1-5-18\...\RunOnce: [Application Restart #2] => C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe [2756560 2016-03-25] (ASUSTeK Computer Inc. -> TODO: <Company name>)
HKU\S-1-5-18\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [6937552 2016-03-25] (ASUSTeK Computer Inc. -> TODO: <Company name>)
HKLM\...\Windows x64\Print Processors\Canon iP7200 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBA.DLL [30208 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\cx21msPC: C:\Windows\System32\spool\prtprocs\x64\cx21mspc.dll [33792 2007-02-23] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\CX21SPC: C:\Windows\System32\spool\prtprocs\x64\cx21spc.dll [33792 2007-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\spd__PC: C:\Windows\System32\spool\prtprocs\x64\spd__pc.dll [36864 2011-04-19] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\us016PC: C:\Windows\System32\spool\prtprocs\x64\us016pc.dll [61736 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Windows x64\Print Processors\xrhr1apps: C:\Windows\System32\spool\prtprocs\x64\xrhr1apps.dll [33280 2012-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Xerox)
HKLM\...\Print\Monitors\Canon BJ Language Monitor iP7200 series: C:\Windows\system32\CNMLMBA.DLL [389120 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor iP7200 series XPS: C:\Windows\system32\CNMXLMBA.DLL [392192 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\system32\CNMN6PPM.DLL [359936 2012-06-14] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\CX21S Langmon: C:\Windows\system32\cx21sl6.dll [22016 2007-01-26] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\novaPDF Port Monitor: C:\Windows\system32\novamn8.dll [18944 2016-03-03] (Softland) [File not signed]
HKLM\...\Print\Monitors\Software602 XPS port monitor: C:\Windows\system32\602localmon.dll [54864 2018-05-31] (Software602 a.s. -> Windows (R) Win 7 DDK provider)
HKLM\...\Print\Monitors\spd__ Langmon: C:\Windows\system32\spd__l.dll [34304 2011-04-11] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\us008 Langmon: us008lm.dll (No File)
HKLM\...\Print\Monitors\us016 Langmon: C:\Windows\system32\us016lm.dll [40744 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\Xerox Phaser 3010 Language Monitor: C:\Windows\system32\xrhr1aLM.DLL [22528 2012-03-09] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\129.0.6668.70\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\129.0.6668.90\Installer\chrmstp.exe [2024-10-05] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
HKLM\Software\...\Winlogon\GPExtensions: [{6cfb9c5c-138e-4bb3-8a3d-d5383e910e57}] -> %SystemRoot%\System32\RdpGroupPolicyExtension.dll
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
GroupPolicy: Restriction - Chrome <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {2AC90F88-9A57-42C8-AC78-4B6CF5043895} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {37ED89C6-4DA3-4BCC-8F33-731514F3FD67} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {6C6927D2-05C0-4FDD-8398-5469BF5EEA6B} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {6DD5873F-E02B-438B-8086-34F4229256FD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7039BE31-E3FC-4BAC-B61C-81B1A8CF0CAF} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {8042A09E-D2AF-40EE-8375-D25569DD37D6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {88604EBF-A126-4DC5-9AA4-F69EF67D5329} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {88DF0971-40EF-4D61-841A-C611901CB1AB} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {8FB6DBA0-D524-4155-B3FC-92C7D53F4EF2} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {A2C8EEB5-3815-4E06-B051-C35F9111CE07} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {AA5EC927-DFEB-4E7C-AD95-D4138F85E040} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {B1D82B51-4180-4CC3-9430-4F1A7BCCBE65} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {C49B6673-C8E4-442D-A1C3-A616DDAE3047} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {DFF0689F-3CF6-46EC-AD00-22A0B7B04FCD} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {FE1AD95F-6CCF-4627-A59D-E7B958CDFEF0} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {FFFFFE56-AA4D-4CFF-BA0B-A25F48D87EC1} - System32\Tasks\{00A2910E-9883-4060-A579-397DC8EAC8DC} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Program Files (x86)\sweetpacks bundle uninstaller\uninstaller.exe" -c "/appName=Video Converter Bundle by SweetPacks"
Task: {904BAFAF-9950-4B86-A5FC-9BCB2D01AC5A} - System32\Tasks\{4784CB87-D4A5-491E-89C2-8EA7C3EC4675} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Program Files (x86)\Samsung\Samsung CLX-216x Series\Install\Setup.exe" -d "C:\Program Files (x86)\Samsung\Samsung CLX-216x Series\Install" -c /R
Task: {42AAF426-1915-401A-B9E2-22573F109C2C} - System32\Tasks\{515A693B-7236-4045-BE8F-ED36467694F1} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a E:\David\podnikatel\Krosplus\setup.exe -d E:\David\podnikatel\Krosplus
Task: {AA3CB2D7-E7A0-4163-85F3-4B73FC37F97A} - System32\Tasks\{B495744B-EDBE-48E3-8F31-7B01495F131C} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Program Files (x86)\sweetpacks bundle uninstaller\uninstaller.exe" -d "C:\Program Files (x86)\sweetpacks bundle uninstaller"
Task: {18A2AA2C-6D9E-483E-86DC-554A7FFBE29D} - System32\Tasks\{C24E80EE-48B2-4882-932B-E3D1F14FEB0E} => C:\Windows\System32\pcalua.exe [90624 2024-10-01] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\David\Desktop\setup.exe -d C:\Users\David\Desktop
Task: {7B6D9C83-277B-4D92-AC11-86E96C53FDFB} - System32\Tasks\2fd443a4-a045-4174-b2c4-f1820e73a1d0 => C:\Program Files (x86)\App Lid\2fd443a4-a045-4174-b2c4-f1820e73a1d0.exe 000820 00B9CD6C67EF4CBF9D04EBB665B3BFEAIE 65743 1416254269 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 App Lid (No File) <==== ATTENTION
Task: {5344E45D-C48C-476D-85C0-D2C23B729613} - System32\Tasks\6853298a-8b0c-402f-a7fd-d260c142247a => C:\Program Files (x86)\App Lid\6853298a-8b0c-402f-a7fd-d260c142247a.exe -> /agentregpath='App Lid' /appid=65743 /srcid='000820' /subid='0' /zdata='appshatmadness' /bic=00B9CD6C67EF4CBF9D04EBB665B3BFEAIE /verifier=ef2bdfa8da72bad89893f622bd3d1814 /installerversion=1_35_09_29 /installationtime=1416254269 /statsdomain=hxxp://stats.newonlinedatastack.com /errorsdomain=hxxp://e (the data entry has 240 more characters). <==== ATTENTION
Task: {E68FAA27-D527-4F1B-A4B1-084DEAB8D9E3} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe -> C:\PROGRA~2\AD-AWA~1\--scan=full
Task: {E9BEF7A1-77D1-431C-A7CD-90B44FE1DE98} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe -> C:\Program Files (x86)\Lavasoft\Ad-Aware\\update all silent repair
Task: {BCC82C02-63FB-4ADC-AADA-8BEBD5497AF4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {029826BA-8951-406F-A862-563BD194E79D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {BE99DFE2-E67F-41FB-A7B1-AF48EB2F8547} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [829408 2024-09-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {CFB7B590-2910-47A4-9247-8D6435D4D5F0} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5937456 2024-09-18] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "e347d9a0-b6a7-48c9-8f41-648f619f4556" --version "6.28.11297" --silent
Task: {69477C37-F9FC-40A6-931E-170615502F53} - System32\Tasks\CCleanerSkipUAC - David => C:\Program Files\CCleaner\CCleaner.exe [39012144 2024-09-18] (Gen Digital Inc. -> Piriform Software Ltd)
Task: {E1D4050E-998B-49B9-B61B-5AC2B8FBEFA3} - System32\Tasks\CorelUpdateHelperTask-B04F3EEB88A98EA1BE397AA9B1F1CA60 => C:\Program Files (x86)\Corel\CUH\v2\CUH.EXE [3834384 2024-01-24] (Corel Corporation -> Corel Corporation)
Task: {FC2E731C-A8C5-4D08-859F-85DED12519CD} - System32\Tasks\CorelUpdateHelperTaskCore => C:\Program Files (x86)\Corel\CUH\v2\CUH.EXE [3834384 2024-01-24] (Corel Corporation -> Corel Corporation)
Task: {38DDF377-04CD-41AA-9AA4-B0EE949B1AE2} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3660232 2020-02-17] (Easeware Technology Limited -> Easeware) -> C:\Program Files\Easeware\DriverEasy\--scan
Task: {A62EE96E-E9B3-49E9-B645-F6B91CB53302} - System32\Tasks\Fekutain Renew => C:\Program Files (x86)\Ckerhryanutash\jiule.exe [779416 2016-10-22] (Glarysoft LTD -> Glarysoft Ltd)
Task: {8F949EBB-0E35-4A6C-90B8-F20BAD0BDB02} - System32\Tasks\FOSCAMVMS => C:\Program Files (x86)\FoscamVMS\VMSClient.exe [1686464 2018-11-15] (Shenzhen Foscam Intelligent Technology Co., Ltd. -> Shenzhen Foscam Intelligent Technology Co., Ltd.)
Task: {C4ED8497-7ABA-450E-9D02-E880A8863B13} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [29464 2023-02-22] (Garmin International, Inc. -> )
Task: {FE3EC57F-624E-4803-8D09-9296B9D3F795} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{87BB2AE4-A3D5-4EFE-91FB-95BC2E00E3AB} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
Task: {09843AB4-8BC6-4952-8821-8AA799B9BC48} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\IntelPTTEKRecertification.exe [855664 2023-12-14] (Intel Corporation -> Intel(R) Corporation)
Task: {5B12D0E1-AC22-4189-B4DB-F2E07EFE3B4A} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1328392 2016-03-17] (Intel(R) Software -> Intel Corporation)
Task: {8C268EF6-BB0F-4E89-9E50-CC1B3B9FEAD4} - System32\Tasks\Kaspersky_Product_Update_{20C91119-626A-4305-906C-90F5A4B77B67}_KSDE => C:\ProgramData\Kaspersky Lab\KSDE1.0.0\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe [2677080 2024-01-26] (AO Kaspersky Lab -> Kaspersky) -> /u -newverwelcome /rSoftware\KasperskyLab\KSDE1.0.0\ProductUpdate /rSoftware\KasperskyLab\ProductUpdate_ksde -old_prod_data_dir="C:\ProgramData\Kaspersky Lab\KSDE1.0.0\Data" /p"INSTALLED_BY_TFU_CAMPAIGN_ID=F62ACB26-306E-C100-A9FF-4CF4F2E89D35" /lcs-CZ <==== ATTENTION
Task: {389962A0-6A36-4171-AC31-FD34F8F55606} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [743488 2021-04-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
Task: {EBBB7239-4DFA-4C06-93AA-28D2F717BFD5} - System32\Tasks\kpm_tray.exe => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe [631704 2024-07-25] (AO Kaspersky Lab -> AO Kaspersky Lab)
Task: {6C9E5DA9-74DA-4082-A69F-F08BA3046058} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe -> C:\Program Files (x86)\HTC\HTC Sync 3.0\\-startup
Task: {CD63DEF8-6A27-4CD1-A330-D2476DF7B301} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {7D2EC5E1-B587-4E58-8D8D-7EA1CEE05582} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => C:\WINDOWS\system32\clipesu.exe [221680 2024-10-01] (Microsoft Windows -> Microsoft Corporation)
Task: {FCBADFB2-5ED7-4CED-9102-72B20992E0FE} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File)
Task: {293F5798-A38E-445C-A0C4-8859C0DB1C66} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File)
Task: {2DDE4D9F-12CE-4D11-AAB4-9968C43733E5} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File)
Task: {14D67678-895A-44C4-B845-223C7D9E3596} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe /DRMInit (No File)
Task: {DEBAC7EC-A137-49EB-8858-DE64D511483F} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-DAVID-PC => %systemroot%\ehome\McxTask.exe -acl S-1-5-21-234310202-639468230-1125350010-1260 (No File)
Task: {31C1FC34-6A68-4619-B192-03D418523B90} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File)
Task: {4A665B29-B9B2-4DC9-A2AB-FB3D1F69A896} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate $(Arg0) (No File)
Task: {85BC120A-8062-44F8-B90C-F4AAC2A72E0C} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15 (No File)
Task: {8EA066F3-022B-4A81-851A-B73D6433CEBC} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask (No File)
Task: {AA43CB9E-2C41-46F7-935B-BF7321BA5D4D} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File)
Task: {5DE5A09A-C871-46C0-BBDD-B8BE531C4D95} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate (No File)
Task: {05277711-0A78-4D0D-B331-32B88F240EE9} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File)
Task: {A74FA460-CFCA-404F-9AC1-73E494A1BAAA} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery (No File)
Task: {CE1DAEF1-2350-4133-AE3D-7FAE54553EED} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File)
Task: {3EFB9CF6-FF9F-4137-9752-B093E7596A54} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File)
Task: {7CAABAEB-E8EE-444E-A4E4-CE4B62892F4B} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe -pscn 0 (No File)
Task: {81145E73-EE27-4C67-8A1D-91D36FD6A386} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask (No File)
Task: {55CF3F02-17AD-42F7-ADC2-DEA3794D34CA} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe -PvrSchedule (No File)
Task: {E1760C62-0555-4EB9-AE7B-3ABE25CB6DDA} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec /RestartRecording (No File)
Task: {ED163B34-B890-407B-B1B5-8465A99AD77F} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File)
Task: {25D2B6BD-09F1-4D2B-AE72-F2B6F01F0132} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File)
Task: {F6658C5D-0205-406A-83A5-1A88A87340FE} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File)
Task: {B925F356-B440-4628-A80B-9A13C63F63CB} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec /StartRecording (No File)
Task: {AE1BFED4-717F-4013-A640-ECDB27135FF1} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File)
Task: {EFFAC042-7727-4087-958D-1378CD23B0A6} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {5C486C2A-C970-443E-90AB-9513721A10C4} - System32\Tasks\Microsoft\Windows\rempl\shell-usoscan => %ProgramFiles%\rempl\remsh.exe /RunUsoScanOnly (No File)
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {2063DEC9-B62F-4FD4-91E5-4FF87CAF82D9} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {AFF7687A-628C-45C1-A911-69D1A0E828FD} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {D085D0EC-B970-40AB-A761-E7017A709139} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {9B859B95-004D-41CB-B687-FA18A2CAB224} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {49B59051-6F81-44A7-9E19-FA8C07BF5D3B} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-08-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {F1FD3F64-E18B-4425-BE90-FC86CB1854B0} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [850928 2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {5C855462-673F-4476-BA02-585A12CAF509} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [850928 2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {F9A5B545-1628-4EA8-A471-08083F7997F1} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3293168 2020-04-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {802E59FB-3592-4152-966A-60503DE9E9E6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {923794DC-0CDA-448E-8525-715E8DA68354} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C58C2297-25AA-4CEE-997C-234AA46AAD85} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DC82CFBD-1291-4CAD-83DB-4A4D40C01557} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0C2A5BF4-68D5-47B2-91D2-45782B26F875} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C83324EB-CDAA-4442-9D3B-A1F1082658B8} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FA1EF938-1033-4017-A4F0-FB1EBD955D92} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9BBDD627-BE60-4684-B35E-A7A9BE1F0D35} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63960 2021-08-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {1F712B79-A8A2-44EC-9F3E-67F625937E11} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-08-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\2fd443a4-a045-4174-b2c4-f1820e73a1d0.job => C:\Program Files (x86)\App Lid\2fd443a4-a045-4174-b2c4-f1820e73a1d0.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\6853298a-8b0c-402f-a7fd-d260c142247a.job => C:\Program Files (x86)\App Lid\6853298a-8b0c-402f-a7fd-d260c142247a.exeȝ/agentregpath='App Lid' /appid=65743 /srcid='000820' /subid='0' /zdata='appshatmadness' /bic=00B9CD6C67EF4CBF9D04EBB665B3BFEAIE /verifier=ef2bdfa8da72bad89893f622bd3d1814 /installerversion=1_35_09_29 /installationtime=1416254269 /statsdomain=hxxp:/stats.newonlinedatastack.com /errorsdomain=hxxp:/errors.newonlinedatastack.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=hxxp:/logs.newonlinedatastack.com <==== ATTENTION
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-234310202-639468230-1125350010-1000] => 10.0.1.15:5000
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63f25f19-61de-41d1-91f2-ffed16c70de1}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{d7045652-7fee-445e-90db-6c4d79232915}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default [2024-10-11]
Edge HomePage: Default -> hxxp://www.seznam.cz/
Edge StartupUrls: Default -> "hxxps://seznam.cz/"
Edge Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2024-05-27]
Edge Extension: (Dokumenty Google offline) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-11]
Edge Extension: (Edge relevant text changes) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge HKU\S-1-5-21-234310202-639468230-1125350010-1000\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
Edge HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
FireFox:
========
FF ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default [2024-10-11]
FF Homepage: Mozilla\Firefox\Profiles\uaym47la.default -> www.seznam.cz
FF Extension: (Video AdBlock for Firefox) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\Extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92} [2016-01-05] [Legacy] [not signed]
FF Extension: (No Name) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [not found]
FF Extension: (No Name) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\extensions\sko-extension@firma.seznam.cz [not found]
FF SearchPlugin: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\uaym47la.default\searchplugins\a9sd1koa.xml [2016-10-22]
FF HKLM\...\Firefox\Extensions: [light_plugin_F363A72DD7B6435783A76E5F612C9006@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F363A72DD7B6435783A76E5F612C9006@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => not found
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-10-01] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2014-11-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2018-01-08] (Software602 a.s. -> Software602 a.s.)
FF Plugin-x32: synology.com/SurveillanceHelper -> C:\Program Files (x86)\Synology\SurveillanceHelper\1.0.0.3\npSurveillanceHelper.dll [2013-11-11] (Synology Inc. -> Synology)
FF Plugin-x32: synology.com/SurveillancePlugin -> C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.429\npSurveillancePlugin.dll [2014-10-30] (Synology Inc. -> Synology)
FF Plugin HKU\S-1-5-21-234310202-639468230-1125350010-1000: @foscam.com/npWebPlugin -> C:\Program Files (x86)\FoscamVMS\WebPlugin\npWebPlugin.dll [No File]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Default [2024-10-11]
CHR Notifications: Default -> hxxps://mail.google.com
CHR HomePage: Default -> hxxp://www.google.cz/
CHR StartupUrls: Default -> "hxxp://www.google.cz/"
CHR Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2024-05-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-10-11]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\System Profile [2024-10-11]
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s. -> Software602 a.s.)
R4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [48640 2015-08-18] () [File not signed]
R2 AVP21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe [184768 2021-06-17] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8615864 2020-05-20] (BattlEye Innovations e.K. -> )
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1087792 2024-09-18] (Gen Digital Inc. -> Piriform Software Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [784512 2018-09-13] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S4 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] (Canon Inc. -> )
S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 klvssbridge64_21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\vssbridge64.exe [479280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [382360 2024-07-25] (AO Kaspersky Lab -> AO Kaspersky Lab)
S3 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab)
S4 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [50600 2016-03-03] (Softland SRL -> Microsoft)
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S4 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S3 Samsung UPD Service2; C:\WINDOWS\System32\SUPDSvc2.exe [165456 2011-12-02] (Samsung Electronics CO., LTD. -> Samsung Electronics)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [530488 2024-09-20] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [183816 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
S4 Synology Drive VSS Service x64; C:\Program Files (x86)\Synology\SynologyDrive\bin\vss-service-x64.exe [371672 2020-05-08] (Synology Inc. -> )
S4 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [253912 2019-10-30] (Synology Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
S4 ZoomCptService; "C:\Program Files (x86)\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\David\AppData\Roaming\Zoom"
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_d4de13a10f2586d0\amdsafd.sys [112952 2024-06-15] (AMD Test Build -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\amdkmdag.sys [106596128 2024-09-04] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [65168 2021-08-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 busenum; C:\WINDOWS\System32\drivers\busenum.sys [57824 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [237288 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-10-22] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-10-22] (Disc Soft Ltd -> Disc Soft Ltd)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_dded470da430edc1\e1d.sys [612960 2024-06-19] (Intel Corporation -> Intel Corporation)
R0 gfibto; C:\WINDOWS\System32\drivers\gfibto.sys [14456 2012-12-15] (GFI Software Development Ltd. -> GFI Software)
S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2016-08-21] (Sony Mobile Communications AB -> Sony Mobile Communications)
S3 htcnprot; C:\WINDOWS\System32\DRIVERS\htcnprot.sys [36928 2012-12-07] (HTC Corp. -> Windows (R) Win 7 DDK provider)
R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [24824 2014-10-23] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [105280 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [206600 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [119568 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [41656 2021-02-19] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [533040 2024-04-04] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [857416 2024-08-23] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [2102600 2024-08-23] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.3\Bases\klids.sys [236440 2024-07-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1051184 2024-04-04] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [90896 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [104728 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [107328 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [78088 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [88328 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [396040 2024-07-23] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [362464 2024-08-13] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [198720 2024-07-30] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [265416 2024-07-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [150280 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [325400 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [294680 2022-02-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 NTIOLib_1_0_1; C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [14136 2009-10-06] (Micro-Star Int'l Co. Ltd. -> MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7758v130\NTIOLib_X64.sys [11888 2011-01-06] (Micro-Star Int'l Co. Ltd. -> MSI) [File not signed]
S3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 pccsmcfd; C:\WINDOWS\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-10-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 ROCKEYNT; C:\WINDOWS\system32\DRIVERS\Rockey4.sys [36904 2015-10-13] (Feitian Technologies Co., Ltd. -> Feitian Technologies Co., Ltd.)
S3 Rockey_USB; C:\WINDOWS\system32\DRIVERS\Rockey4USB.sys [23592 2015-10-13] (Feitian Technologies Co., Ltd. -> Feitian Technologies Co., Ltd.)
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 STHFK; C:\WINDOWS\System32\Drivers\stw1064.sys [56120 2017-03-28] (QUALCOMM Incorporated -> QTI Ltd)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2017-11-27] (Apple, Inc.) [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-10-11 12:34 - 2024-10-11 12:35 - 000052529 _____ C:\Users\David\Downloads\FRST.txt
2024-10-11 12:34 - 2024-10-11 12:34 - 000000000 ____D C:\FRST
2024-10-11 12:33 - 2024-10-11 12:33 - 002397696 _____ (Farbar) C:\Users\David\Downloads\FRST64.exe
2024-10-11 06:17 - 2024-10-11 06:17 - 000000000 ____D C:\Users\David\AppData\Local\{E8118928-1853-4120-9CAF-B9E6FE09AF25}
2024-10-10 16:51 - 2024-10-10 16:53 - 000000000 ___HD C:\$WinREAgent
2024-10-10 16:37 - 2024-10-10 16:37 - 000000000 ____D C:\Users\David\AppData\Local\{D5F8B2BD-5F2E-4412-A7AD-AC6E22408ED9}
2024-10-09 09:49 - 2024-10-09 09:49 - 000000000 ____D C:\Users\David\AppData\Local\{85E65443-D25B-466A-942C-43B484844D86}
2024-10-08 22:01 - 2024-10-08 22:01 - 000000000 ____D C:\Users\David\AppData\Local\{9935FB11-5E85-473E-BFFF-9A848F6C1B19}
2024-10-08 09:42 - 2024-10-08 09:42 - 000000000 ____D C:\Users\David\AppData\Local\{65876707-707D-42EA-9CD7-4853309F64C6}
2024-10-07 09:33 - 2024-10-07 09:31 - 001106794 _____ C:\Users\David\Desktop\vypoved tmobile.jpeg
2024-10-07 08:57 - 2024-10-07 08:57 - 000000000 ____D C:\Users\David\AppData\Local\{8A8C7FB5-44C3-44A3-9EB1-968F84DB7452}
2024-10-06 12:04 - 2024-10-06 12:04 - 000000000 ____D C:\Users\David\AppData\Local\{5C1F0473-593D-4BCE-849E-BECFCB5A63F0}
2024-10-05 12:54 - 2024-10-05 12:54 - 000000000 ____D C:\Users\David\AppData\Local\{768903B2-5BFF-462D-849C-5E39093B6C50}
2024-10-03 12:01 - 2024-10-03 12:01 - 001087215 _____ C:\Users\David\Desktop\toitoi.jpeg
2024-10-03 10:51 - 2024-10-03 10:51 - 000000000 ____D C:\Users\David\AppData\Local\{ACE0432C-B227-4213-9E42-0C0A296417E1}
2024-10-02 12:06 - 2024-10-02 12:06 - 000000000 ____D C:\Users\David\AppData\Local\{04561F26-3716-45F5-9044-F780DA9DE77B}
2024-10-01 14:05 - 2024-10-01 14:05 - 000001383 _____ C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2024-10-01 14:05 - 2024-10-01 14:05 - 000000000 ____D C:\Users\David\AppData\Local\PCHealthCheck
2024-10-01 12:21 - 2024-10-03 11:01 - 000001415 _____ C:\Users\Public\Desktop\Skype.lnk
2024-10-01 12:21 - 2024-10-03 11:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2024-10-01 12:20 - 2024-10-01 12:20 - 000001852 _____ C:\Users\Public\Desktop\iTunes.lnk
2024-10-01 12:20 - 2024-10-01 12:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2024-10-01 12:20 - 2024-10-01 12:20 - 000000000 ____D C:\Program Files\iTunes
2024-10-01 12:19 - 2024-10-01 12:19 - 000000000 ____D C:\Program Files\Bonjour
2024-10-01 12:19 - 2024-10-01 12:19 - 000000000 ____D C:\Program Files (x86)\Bonjour
2024-10-01 12:18 - 2024-10-01 12:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoom
2024-10-01 12:18 - 2024-10-01 12:18 - 000000000 ____D C:\Program Files (x86)\Zoom
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\UC.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\RAR.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\PKZIP.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\PKUNZIP.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\LHA.PIF
2024-10-01 12:17 - 2024-02-21 11:03 - 000000545 _____ C:\WINDOWS\ARJ.PIF
2024-10-01 11:26 - 2024-10-01 11:26 - 000000000 ____D C:\Users\David\AppData\Local\{A29F9C9E-9254-44B7-BA41-A35981FB2964}
2024-09-30 09:00 - 2024-09-30 09:00 - 000000000 ____D C:\Users\David\AppData\Local\{D3588663-D00F-4970-BBAD-D0A857C370F5}
2024-09-27 04:57 - 2024-09-27 04:57 - 000000000 ____D C:\Users\David\AppData\Local\{60B223EA-59E7-4F99-8893-F70746CF4FCB}
2024-09-26 16:57 - 2024-09-26 16:57 - 000000000 ____D C:\Users\David\AppData\Local\{AFAC2BD1-F3AC-4028-B5B4-FCC387A8723F}
2024-09-25 08:54 - 2024-09-25 08:54 - 000000000 ____D C:\Users\David\AppData\Local\{AB14004C-29ED-433F-A804-A46272A6E640}
2024-09-24 11:12 - 2024-09-24 11:12 - 000000000 ____D C:\Users\David\AppData\Local\{0E3530EB-F41F-43E8-BF27-667029A39521}
2024-09-23 09:30 - 2024-09-23 09:30 - 000000000 ____D C:\Users\David\AppData\Local\{FC642EC7-A10B-48AC-B6B2-F9D65B1FFFEE}
2024-09-22 13:25 - 2024-09-22 13:25 - 000000000 ____D C:\Users\David\AppData\Local\{79EA8DAF-7F63-4A4A-BA58-AA74994B15D7}
2024-09-20 10:04 - 2024-09-20 10:04 - 000000000 ____D C:\Users\David\AppData\Local\{8F8DDF4A-6278-467A-9CA0-747649E12AE1}
2024-09-19 09:32 - 2024-09-19 09:32 - 000000000 ____D C:\Users\David\AppData\Local\{882FC137-FFD5-4E82-B6F1-A6E42B7AAC49}
2024-09-18 10:20 - 2024-09-18 10:20 - 000000000 ____D C:\Users\David\AppData\Local\{43D7013B-D351-4EEB-9624-9D17C701FAA6}
2024-09-17 10:04 - 2024-09-17 10:04 - 000065528 _____ C:\Users\David\Desktop\Benq.pdf
2024-09-17 09:55 - 2024-09-17 09:55 - 000000000 ____D C:\Users\David\AppData\Local\{BD03B4D5-C217-4EA1-B694-F066F1549E25}
2024-09-13 11:17 - 2024-09-13 11:17 - 000000000 ____D C:\Users\David\AppData\Local\{61662EAC-BBB0-4C6D-B6E6-1A4CCACA153B}
2024-09-11 10:36 - 2024-09-11 10:36 - 000325722 _____ C:\Users\David\Downloads\962153273.pdf
2024-09-11 10:31 - 2024-09-11 10:31 - 000000000 ____D C:\Users\David\AppData\Local\{25CEEB94-E231-4396-8AAD-44EA681CDD3C}
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-10-11 12:28 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-10-11 12:28 - 2016-12-16 13:54 - 000000000 ____D C:\Program Files\CCleaner
2024-10-11 12:25 - 2017-08-20 19:23 - 000000000 ____D C:\ProgramData\NVIDIA
2024-10-11 12:23 - 2018-09-13 16:11 - 000000000 ____D C:\Users\David\AppData\Local\D3DSCache
2024-10-11 12:17 - 2022-02-18 10:54 - 000000000 ____D C:\Program Files\RUXIM
2024-10-11 06:25 - 2020-09-24 08:55 - 000003542 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-10-10 17:53 - 2024-04-04 10:08 - 000003444 _____ C:\WINDOWS\system32\Tasks\CorelUpdateHelperTask-B04F3EEB88A98EA1BE397AA9B1F1CA60
2024-10-10 17:01 - 2020-09-24 08:56 - 001875976 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-10-10 17:01 - 2019-12-07 16:43 - 000781868 _____ C:\WINDOWS\system32\perfh005.dat
2024-10-10 17:01 - 2019-12-07 16:43 - 000172602 _____ C:\WINDOWS\system32\perfc005.dat
2024-10-10 17:01 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-10-10 16:55 - 2020-11-16 12:43 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2024-10-10 16:55 - 2020-09-24 08:55 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-10-10 16:55 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-10-10 16:55 - 2012-06-13 01:01 - 000000000 ____D C:\Intel
2024-10-10 16:53 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-10-10 16:51 - 2013-08-14 22:31 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-10-10 16:48 - 2022-10-13 11:46 - 000002109 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-10-10 16:48 - 2022-10-13 11:46 - 000002097 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2024-10-10 16:46 - 2014-05-01 08:36 - 201324920 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-10-10 16:40 - 2012-06-14 14:14 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\Word
2024-10-10 16:36 - 2018-08-31 07:38 - 000000000 ____D C:\Users\David\Desktop\faktury z plochy
2024-10-10 16:35 - 2020-09-24 08:55 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-10-10 16:35 - 2020-09-24 08:55 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-10-09 15:18 - 2012-06-13 21:27 - 000000000 ___RD C:\Users\David\Documents\Scanned Documents
2024-10-09 15:13 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-10-09 12:23 - 2021-12-16 08:21 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-10-09 12:23 - 2020-09-24 08:41 - 000654384 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-10-09 12:23 - 2019-12-07 16:44 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2024-10-09 12:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-10-09 12:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-10-09 12:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-10-09 12:16 - 2012-06-14 14:16 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\Excel
2024-10-09 11:57 - 2020-09-24 08:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-10-09 11:46 - 2020-09-24 08:41 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-10-08 22:10 - 2012-08-21 16:37 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\PowerPoint
2024-10-08 21:28 - 2012-06-14 14:14 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\Office
2024-10-08 19:00 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-10-08 18:23 - 2016-07-20 18:03 - 000000000 ____D C:\Users\David\AppData\Roaming\vlc
2024-10-08 18:19 - 2021-12-13 08:43 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-234310202-639468230-1125350010-1000
2024-10-08 18:19 - 2020-09-24 08:55 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-234310202-639468230-1125350010-1000
2024-10-08 18:19 - 2020-09-24 08:43 - 000002415 _____ C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-10-07 14:03 - 2013-03-29 12:04 - 000000000 ____D C:\Users\David\AppData\Local\CrashDumps
2024-10-07 08:54 - 2024-01-26 13:52 - 000004284 _____ C:\WINDOWS\system32\Tasks\Kaspersky_Product_Update_{20C91119-626A-4305-906C-90F5A4B77B67}_KSDE
2024-10-06 12:06 - 2012-06-14 14:11 - 000000000 ____D C:\Users\David\AppData\Local\GHISLER
2024-10-05 12:58 - 2016-11-06 00:02 - 000002337 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-10-05 12:54 - 2020-06-05 06:21 - 000002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-10-05 12:54 - 2020-06-05 06:21 - 000002310 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-10-03 11:04 - 2020-10-19 12:47 - 000000424 _____ C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-10-03 11:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-10-01 14:21 - 2021-10-11 12:51 - 000002262 _____ C:\WINDOWS\system32\Tasks\StartCN
2024-10-01 14:21 - 2021-10-11 12:51 - 000002182 _____ C:\WINDOWS\system32\Tasks\StartDVR
2024-10-01 12:25 - 2020-10-19 12:47 - 000003608 _____ C:\WINDOWS\system32\Tasks\Driver Easy Scheduled Scan
2024-10-01 12:25 - 2020-09-24 08:55 - 000004934 _____ C:\WINDOWS\system32\Tasks\Fekutain Renew
2024-10-01 12:25 - 2020-09-24 08:55 - 000003212 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003044 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000003008 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:25 - 2020-09-24 08:55 - 000002804 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-01 12:23 - 2020-11-16 12:43 - 000000000 ____D C:\Users\David\AppData\Local\AMD
2024-10-01 12:23 - 2020-10-22 16:09 - 000000000 ____D C:\Users\David\AppData\Roaming\Zoom
2024-10-01 12:19 - 2018-01-30 08:11 - 000000952 _____ C:\Users\Public\Desktop\VLC media player.lnk
2024-10-01 12:19 - 2013-05-07 15:09 - 000000000 ____D C:\ProgramData\Package Cache
2024-10-01 12:18 - 2013-11-25 22:22 - 000001084 _____ C:\Users\Public\Desktop\Winamp.lnk
2024-10-01 12:18 - 2013-11-25 22:22 - 000000000 ____D C:\Program Files (x86)\Winamp
2024-10-01 12:17 - 2012-06-14 21:45 - 000000000 ____D C:\totalcmd
2024-10-01 11:30 - 2021-01-27 13:27 - 000000000 ____D C:\Users\David\AppData\Local\AMD_Common
2024-09-20 17:06 - 2022-09-21 19:51 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-09-20 17:05 - 2019-12-07 16:47 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2024-09-20 17:05 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-09-20 17:05 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-09-20 10:20 - 2022-11-13 10:01 - 000003378 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-09-20 10:20 - 2020-09-24 08:55 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-09-18 19:35 - 2020-09-24 08:43 - 000000000 ____D C:\Users\David
2024-09-17 10:00 - 2022-09-12 08:15 - 000000000 ____D C:\Users\David\AppData\Roaming\com.adobe.dunamis
2024-09-17 10:00 - 2012-06-13 22:46 - 000000000 ____D C:\Users\David\AppData\Local\Adobe
2024-09-17 10:00 - 2012-06-13 01:27 - 000000000 ____D C:\Users\David\AppData\Roaming\Adobe
==================== Files in the root of some directories ========
2016-09-19 15:32 - 2016-11-30 18:38 - 000001419 _____ () C:\Users\David\AppData\Roaming\DAVID-PC.MTBF.txt
2014-09-01 10:18 - 2016-01-03 14:15 - 000000365 _____ () C:\Users\David\AppData\Roaming\KBOEPUQ
2015-11-30 14:44 - 2015-11-30 14:44 - 000000038 ___SH () C:\Users\David\AppData\Local\69ff07055291669bb2b218.72821112
2014-08-20 18:43 - 2014-09-29 22:18 - 000007602 _____ () C:\Users\David\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================