Velké zatížení HDD a RAM
Napsal: 03 lis 2024 13:03
Dobrý den,
prosím o kontrolu. Notebook je téměř nepoužitelný, ve správci úloh je velké zatížení HDD a RAM. Chtěl bych se ujistit, zda to je HW problém, nebo jestli tam je nějaká breberka.
Děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2024
Ran by David Lukáš (administrator) on DESKTOP-FOK2JQQ (Sony Corporation VPCF13M1E) (03-11-2024 12:45:45)
Running from C:\Users\David Lukáš\Desktop\FRST64.exe
Loaded Profiles: David Lukáš
Platform: Microsoft Windows 10 Home Version 22H2 19045.5011 (X64) Language: Čeština (Česko)
Default browser not detected!
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe <2>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (AltisikDevLM Group LM -> ) [File not signed] [File is in use] C:\Program Files (x86)\AltisikApplication\AltisikService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Reason Cybersecurity Inc. -> Reason Software Company Inc.) C:\Program Files\ReasonLabs\VPN\rsVPNClientSvc.exe
(services.exe ->) (Reason Cybersecurity Inc. -> Reason Software Company Inc.) C:\Program Files\ReasonLabs\VPN\rsVPNSvc.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe <3>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.5071_none_7e3c4e707c6a2679\TiWorker.exe
(wuauclt.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\AM_Delta.exe
(wuauclt.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752216 2024-09-30] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4406632 2024-09-17] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36764120 2024-10-09] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3386464 2024-10-09] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [Walliant] => C:\Users\David Lukáš\AppData\Local\Programs\Walliant\Walliant.exe [388664 2024-07-12] (Cleversort FZ-LLC -> Globalhop) <==== ATTENTION
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\MountPoints2: {4f1e6804-2c15-11ef-b859-c0cb38ebc569} - "E:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\130.0.6723.92\Installer\chrmstp.exe [2024-10-31] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {9153E68C-1804-4AA6-9798-3BC8624ACA77} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {6D807B7B-0A73-468E-A13E-08AD13094F13} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe (No File)
Task: {6E71BA94-1295-4E96-9E20-786E1E3EE170} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe /from_scheduler:1 (No File)
Task: {C4DB7A3D-3162-40F1-9A60-053ED41B8275} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem131.0.6776.0{398A1135-D1F9-4886-96FB-DA14354E12F5} => C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe [5507168 2024-10-14] (Google LLC -> Google LLC)
Task: {78336780-0620-4C0C-AC04-E0E2B02EF045} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64472 2024-08-16] (HP Inc. -> HP Inc.)
Task: {D2C3E31A-1CF5-4A5E-BD98-C76D3C861FAA} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64472 2024-08-16] (HP Inc. -> HP Inc.)
Task: {A89C2F56-45A8-4189-AB6E-B0217CFEE2FF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28617448 2024-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {949F339C-1299-44A4-9F50-6BFFA97AA0B4} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28617448 2024-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {7FBC21F3-D45A-4F92-A66D-EE937BD815D9} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312520 2024-10-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {765E29DD-5896-42C7-AF42-573734BBFE0C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312520 2024-10-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {C4F656C2-9A0D-4325-867F-41538512C5DE} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [187328 2024-09-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {C7FAB741-4725-4495-A439-348C088A7EEC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {64348A54-5C6F-4B92-AF6B-5E1ED803AE96} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C3606D57-592D-4938-B023-6115FF2DC728} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {09305478-A698-4992-83B3-1F20968A0586} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5C40FB74-C5FC-4FFA-9AC6-4E947A596529} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1588777837-2161469333-1616248303-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {6361EB4B-6C9E-49CD-A5F0-D981C26E3FAB} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" (No File)
Task: {C3654091-3A3D-4B44-9604-B17AA1C68BD4} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [469952 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvContainer\-d "C:\Program Files (x86)\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {B0C7E519-7061-4431-9710-3E9A3D226C67} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {718CE76C-E432-4D31-A951-97DF7868E0C3} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2069952 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2AFB4A29-510C-4894-AC6D-5EA1EB77BECB} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [976832 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {F1486865-9DCA-4781-B547-D3DE1BEFBA9C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [662464 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EAEE72C4-9A7A-41F4-841E-6C8763EBD26D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [662464 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {319C26D2-5595-46AA-A4FF-056F43833356} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [510912 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AD4F36F9-D3AA-4ACB-8F9B-83DE65B176FF} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [757184 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}: [DhcpDomain] home
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}\A74656C657B6: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}\A74656C657B6: [DhcpDomain] docsis.vodafone.cz
Tcpip\..\Interfaces\{c89a7e43-3283-4f3a-b1e4-6b9e806dda05}: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{c89a7e43-3283-4f3a-b1e4-6b9e806dda05}: [DhcpDomain] docsis.vodafone.cz
Edge:
=======
Edge Profile: C:\Users\David Lukáš\AppData\Local\Microsoft\Edge\User Data\Default [2024-08-26]
Edge Extension: (Dokumenty Google offline) - C:\Users\David Lukáš\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-19]
Edge Extension: (Edge relevant text changes) - C:\Users\David Lukáš\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-04-19]
FireFox:
========
FF DefaultProfile: nav76ln4.default
FF ProfilePath: C:\Users\David Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\nav76ln4.default [2024-06-22]
FF ProfilePath: C:\Users\David Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\cpgti450.default-release [2024-10-17]
FF Plugin: @java.com/DTPlugin,version=11.431.2 -> C:\Program Files\Java\jre1.8.0_431\bin\dtplugin\npDeployJava1.dll [2024-09-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.431.2 -> C:\Program Files\Java\jre1.8.0_431\bin\plugin2\npjp2.dll [2024-09-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-08-23] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-03-24] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-03-24] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
Chrome:
=======
CHR Profile: C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default [2024-10-31]
CHR Notifications: Default -> hxxps://www.talkie-ai.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Extension: (Dokumenty Google offline) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-09-02]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-10-08]
CHR Extension: (SteamDB) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdbmhfkmnlmbkgbabkdealhhbfhlmmon [2024-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-02-25]
CHR Profile: C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\System Profile [2024-09-19]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
R2 AltisikService; C:\Program Files (x86)\AltisikApplication\AltisikService.exe [71937664 2024-06-17] (AltisikDevLM Group LM -> ) [File not signed] [File is in use] <==== ATTENTION
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [18663720 2024-09-15] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13861080 2024-10-05] (Microsoft Corporation -> Microsoft Corporation)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [14037088 2024-10-09] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2024-08-30] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [375248 2024-02-13] (Epic Games Inc. -> Epic Games, Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [241104 2024-08-16] (HP Inc. -> HP Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 rsVPNClientSvc; C:\Program Files\ReasonLabs\VPN\rsVPNClientSvc.exe [672400 2024-10-10] (Reason Cybersecurity Inc. -> Reason Software Company Inc.)
R2 rsVPNSvc; C:\Program Files\ReasonLabs\VPN\rsVPNSvc.exe [231048 2024-10-10] (Reason Cybersecurity Inc. -> Reason Software Company Inc.)
S3 TavernWorker_1_1; C:\Program Files\IRONMACE\Tavern\Steam\TavernApp_1_1\TavernWorker.exe [20841904 2024-07-20] (IRONMACE Co., Ltd. -> IRONMACE Co., Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEDaisy; C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys [5148848 2024-09-15] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R2 rimspci; C:\Windows\system32\DRIVERS\rimspe64.sys [57344 2009-02-12] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R2 risdpcie; C:\Windows\system32\DRIVERS\risdpe64.sys [80384 2009-03-30] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R3 SFEP; C:\Windows\System32\drivers\SFEP.sys [12032 2024-02-25] (Microsoft Windows Hardware Compatibility Publisher -> Sony Corporation)
R3 SteamStreamingMicrophone; C:\Windows\system32\drivers\SteamStreamingMicrophone.sys [40736 2020-06-01] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\Windows\system32\drivers\SteamStreamingSpeakers.sys [40736 2020-06-01] (Valve Corp. -> )
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22080 2024-08-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [602504 2024-08-09] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2024-08-09] (Microsoft Windows -> Microsoft Corporation)
R3 yukonw8; C:\Windows\System32\drivers\yk63x64.sys [288768 2019-12-07] (Microsoft Windows -> Marvell)
S3 NEProtect; \??\C:\Program Files (x86)\Steam\steamapps\common\Lost Light\Engine\Binaries\Win64\NEProtect.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-11-03 12:45 - 2024-11-03 12:53 - 000021068 _____ C:\Users\David Lukáš\Desktop\FRST.txt
2024-11-03 12:43 - 2024-11-03 12:51 - 000000000 ____D C:\FRST
2024-11-03 12:42 - 2024-11-03 12:37 - 002397696 _____ (Farbar) C:\Users\David Lukáš\Desktop\FRST64.exe
2024-11-03 11:47 - 2024-11-03 11:47 - 000000000 ___HD C:\$WinREAgent
2024-11-03 11:38 - 2024-11-03 11:38 - 000007605 _____ C:\Users\David Lukáš\AppData\Local\Resmon.ResmonCfg
2024-11-03 11:28 - 2024-11-03 11:28 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Sun
2024-11-03 11:28 - 2024-11-03 11:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2024-11-03 11:28 - 2024-09-30 08:34 - 000213120 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2024-11-03 11:26 - 2024-11-03 11:29 - 000000000 ____D C:\Program Files\Java
2024-10-31 17:56 - 2024-10-31 17:56 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2024-10-31 17:55 - 2024-10-31 18:00 - 000243056 _____ C:\Windows\ntbtlog.txt
2024-10-14 18:35 - 2024-10-14 18:35 - 000000222 _____ C:\Users\David Lukáš\Desktop\Assassin's Creed Rogue.url
2024-10-14 18:16 - 2024-10-14 18:16 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-10-14 18:05 - 2024-10-14 18:05 - 000000030 _____ C:\Windows\system32\.HQargq
2024-10-13 20:32 - 2024-10-13 20:32 - 000000000 ____D C:\Users\David Lukáš\Documents\Vlastní šablony Office
2024-10-13 19:28 - 2024-10-13 19:29 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\UProof
2024-10-13 19:28 - 2024-10-13 19:28 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Proof
2024-10-13 18:35 - 2024-10-14 18:36 - 000000000 ____D C:\Users\David Lukáš\Documents\Assassin's Creed Rogue
2024-10-13 14:14 - 2024-10-13 14:14 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\HTML Help
2024-10-11 19:46 - 2024-10-11 19:46 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\rsappui
2024-10-11 14:01 - 2024-10-13 11:31 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\ReasonLabs
2024-10-11 13:46 - 2024-10-11 13:46 - 000001248 _____ C:\Users\David Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RAV VPN.lnk
2024-10-10 21:34 - 2024-10-10 21:34 - 000000000 ____D C:\ProgramData\VPNBackup
2024-10-10 21:30 - 2024-10-13 11:32 - 000000000 ____D C:\ProgramData\ReasonLabs
2024-10-10 21:24 - 2024-10-13 11:36 - 000000000 ____D C:\Program Files\ReasonLabs
2024-10-10 21:16 - 2024-10-10 21:16 - 000000000 ____D C:\Program Files (x86)\rsStubActivator-1.1.1
2024-10-10 21:15 - 2024-10-10 21:15 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Walliant
2024-10-10 21:13 - 2024-10-10 21:13 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Midnight Commander
2024-10-10 21:12 - 2024-10-10 21:12 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\AgreementlwfTool
2024-10-10 21:12 - 2024-10-10 21:12 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\AgreementixvTool
2024-10-10 21:11 - 2024-10-10 21:11 - 000000000 ____D C:\Program Files (x86)\AgreementjpsTool
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-11-03 12:51 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2024-11-03 12:50 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-11-03 12:47 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2024-11-03 12:34 - 2024-02-23 22:10 - 000000000 ____D C:\ProgramData\NVIDIA
2024-11-03 12:33 - 2024-02-23 21:37 - 000008192 ___SH C:\DumpStack.log.tmp
2024-11-03 12:33 - 2024-02-23 21:37 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-11-03 12:32 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2024-11-03 12:12 - 2024-06-17 21:37 - 000000000 ____D C:\ProgramData\AltisikApplication
2024-11-03 12:01 - 2024-02-23 21:37 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-11-03 11:39 - 2024-02-23 21:38 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-11-03 11:39 - 2024-02-23 21:38 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-10-31 19:36 - 2024-02-23 21:47 - 000000000 ____D C:\Users\David Lukáš
2024-10-31 19:14 - 2024-02-23 21:39 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-10-31 18:52 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-10-31 18:23 - 2024-02-25 11:54 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-10-31 18:23 - 2023-05-05 13:27 - 000000000 ____D C:\Windows\SystemTemp
2024-10-31 18:10 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2024-10-31 18:03 - 2024-09-05 16:07 - 000000000 ____D C:\ProgramData\Avast Software
2024-10-31 18:01 - 2024-09-05 16:52 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\Avast Software
2024-10-31 18:00 - 2024-06-22 23:04 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-10-31 17:46 - 2024-02-23 22:09 - 000000000 ____D C:\Program Files\RUXIM
2024-10-31 17:38 - 2024-04-01 12:33 - 000000000 ____D C:\Program Files (x86)\Steam
2024-10-31 17:37 - 2024-02-23 21:49 - 000005858 _____ C:\Windows\system32\PerfStringBackup.INI
2024-10-31 17:37 - 2019-12-07 15:41 - 002898546 _____ C:\Windows\system32\perfh005.dat
2024-10-31 17:37 - 2019-12-07 15:41 - 000791128 _____ C:\Windows\system32\perfc005.dat
2024-10-31 17:23 - 2024-05-29 17:08 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\D3DSCache
2024-10-18 18:57 - 2024-06-17 21:37 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\AltisikApplication
2024-10-18 18:37 - 2024-04-01 20:37 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\CrashDumps
2024-10-17 21:15 - 2024-09-05 16:14 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2024-10-17 21:04 - 2024-04-01 12:35 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\.minecraft
2024-10-17 20:49 - 2024-04-01 12:35 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\.tlauncher
2024-10-17 20:20 - 2024-04-01 13:24 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2024-10-17 20:00 - 2024-04-02 13:16 - 000000000 ____D C:\Program Files\Epic Games
2024-10-15 18:58 - 2024-04-02 18:48 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\SpaceEngineers
2024-10-14 21:26 - 2024-04-05 14:48 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\RenPy
2024-10-14 18:35 - 2024-04-05 17:54 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\Ubisoft Game Launcher
2024-10-14 18:18 - 2024-02-25 12:47 - 000000000 ____D C:\Program Files\Microsoft Office
2024-10-14 18:18 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-10-14 18:07 - 2024-02-23 21:37 - 000438968 _____ C:\Windows\system32\FNTCACHE.DAT
2024-10-14 18:04 - 2019-12-07 15:42 - 000000000 ____D C:\Windows\system32\OpenSSH
2024-10-14 18:04 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2024-10-14 18:03 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2024-10-14 18:03 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2024-10-14 16:50 - 2024-02-25 13:14 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Word
2024-10-14 16:19 - 2024-02-23 21:40 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-10-13 15:02 - 2024-02-25 12:28 - 000000000 ____D C:\ProgramData\Package Cache
2024-10-13 15:01 - 2024-04-01 21:40 - 000000000 ____D C:\Program Files\dotnet
2024-10-13 14:38 - 2024-02-23 22:13 - 000000000 ____D C:\Windows\system32\MRT
2024-10-13 14:25 - 2024-02-23 22:12 - 201324920 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-10-13 11:56 - 2024-06-17 21:37 - 000000000 ____D C:\Program Files (x86)\AltisikApplication
2024-10-12 23:05 - 2024-05-24 14:16 - 000000000 ____D C:\ProgramData\EA Desktop
2024-10-11 22:57 - 2024-09-17 06:48 - 000000000 ____D C:\Users\David Lukáš\Documents\My Games
2024-10-11 22:56 - 2024-09-16 22:57 - 000000000 ____D C:\Users\David Lukáš\Documents\Hry
2024-10-11 22:51 - 2024-04-15 16:39 - 000000000 ____D C:\Windows\Minidump
2024-10-11 22:51 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\LiveKernelReports
2024-10-10 21:13 - 2024-02-23 21:48 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\VirtualStore
2024-10-08 16:43 - 2024-06-22 23:04 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2024-10-08 16:22 - 2024-02-25 11:33 - 000003126 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1588777837-2161469333-1616248303-1001
2024-10-08 16:22 - 2024-02-23 22:02 - 000002922 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1588777837-2161469333-1616248303-1001
==================== Files in the root of some directories ========
2024-11-03 11:38 - 2024-11-03 11:38 - 000007605 _____ () C:\Users\David Lukáš\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
prosím o kontrolu. Notebook je téměř nepoužitelný, ve správci úloh je velké zatížení HDD a RAM. Chtěl bych se ujistit, zda to je HW problém, nebo jestli tam je nějaká breberka.
Děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2024
Ran by David Lukáš (administrator) on DESKTOP-FOK2JQQ (Sony Corporation VPCF13M1E) (03-11-2024 12:45:45)
Running from C:\Users\David Lukáš\Desktop\FRST64.exe
Loaded Profiles: David Lukáš
Platform: Microsoft Windows 10 Home Version 22H2 19045.5011 (X64) Language: Čeština (Česko)
Default browser not detected!
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe <2>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (AltisikDevLM Group LM -> ) [File not signed] [File is in use] C:\Program Files (x86)\AltisikApplication\AltisikService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Reason Cybersecurity Inc. -> Reason Software Company Inc.) C:\Program Files\ReasonLabs\VPN\rsVPNClientSvc.exe
(services.exe ->) (Reason Cybersecurity Inc. -> Reason Software Company Inc.) C:\Program Files\ReasonLabs\VPN\rsVPNSvc.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe <3>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.5071_none_7e3c4e707c6a2679\TiWorker.exe
(wuauclt.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\AM_Delta.exe
(wuauclt.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752216 2024-09-30] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4406632 2024-09-17] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36764120 2024-10-09] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3386464 2024-10-09] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\Run: [Walliant] => C:\Users\David Lukáš\AppData\Local\Programs\Walliant\Walliant.exe [388664 2024-07-12] (Cleversort FZ-LLC -> Globalhop) <==== ATTENTION
HKU\S-1-5-21-1588777837-2161469333-1616248303-1001\...\MountPoints2: {4f1e6804-2c15-11ef-b859-c0cb38ebc569} - "E:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\130.0.6723.92\Installer\chrmstp.exe [2024-10-31] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {9153E68C-1804-4AA6-9798-3BC8624ACA77} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {6D807B7B-0A73-468E-A13E-08AD13094F13} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe (No File)
Task: {6E71BA94-1295-4E96-9E20-786E1E3EE170} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe /from_scheduler:1 (No File)
Task: {C4DB7A3D-3162-40F1-9A60-053ED41B8275} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem131.0.6776.0{398A1135-D1F9-4886-96FB-DA14354E12F5} => C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe [5507168 2024-10-14] (Google LLC -> Google LLC)
Task: {78336780-0620-4C0C-AC04-E0E2B02EF045} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64472 2024-08-16] (HP Inc. -> HP Inc.)
Task: {D2C3E31A-1CF5-4A5E-BD98-C76D3C861FAA} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64472 2024-08-16] (HP Inc. -> HP Inc.)
Task: {A89C2F56-45A8-4189-AB6E-B0217CFEE2FF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28617448 2024-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {949F339C-1299-44A4-9F50-6BFFA97AA0B4} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28617448 2024-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {7FBC21F3-D45A-4F92-A66D-EE937BD815D9} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312520 2024-10-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {765E29DD-5896-42C7-AF42-573734BBFE0C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312520 2024-10-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {C4F656C2-9A0D-4325-867F-41538512C5DE} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [187328 2024-09-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {C7FAB741-4725-4495-A439-348C088A7EEC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {64348A54-5C6F-4B92-AF6B-5E1ED803AE96} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C3606D57-592D-4938-B023-6115FF2DC728} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {09305478-A698-4992-83B3-1F20968A0586} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5C40FB74-C5FC-4FFA-9AC6-4E947A596529} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1588777837-2161469333-1616248303-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {6361EB4B-6C9E-49CD-A5F0-D981C26E3FAB} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" (No File)
Task: {C3654091-3A3D-4B44-9604-B17AA1C68BD4} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [469952 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvContainer\-d "C:\Program Files (x86)\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {B0C7E519-7061-4431-9710-3E9A3D226C67} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {718CE76C-E432-4D31-A951-97DF7868E0C3} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2069952 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2AFB4A29-510C-4894-AC6D-5EA1EB77BECB} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [976832 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {F1486865-9DCA-4781-B547-D3DE1BEFBA9C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [662464 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EAEE72C4-9A7A-41F4-841E-6C8763EBD26D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [662464 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {319C26D2-5595-46AA-A4FF-056F43833356} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [510912 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AD4F36F9-D3AA-4ACB-8F9B-83DE65B176FF} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [757184 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}: [DhcpDomain] home
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}\A74656C657B6: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{17e620e5-d07f-4f74-81c6-56b2569dd682}\A74656C657B6: [DhcpDomain] docsis.vodafone.cz
Tcpip\..\Interfaces\{c89a7e43-3283-4f3a-b1e4-6b9e806dda05}: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{c89a7e43-3283-4f3a-b1e4-6b9e806dda05}: [DhcpDomain] docsis.vodafone.cz
Edge:
=======
Edge Profile: C:\Users\David Lukáš\AppData\Local\Microsoft\Edge\User Data\Default [2024-08-26]
Edge Extension: (Dokumenty Google offline) - C:\Users\David Lukáš\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-19]
Edge Extension: (Edge relevant text changes) - C:\Users\David Lukáš\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-04-19]
FireFox:
========
FF DefaultProfile: nav76ln4.default
FF ProfilePath: C:\Users\David Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\nav76ln4.default [2024-06-22]
FF ProfilePath: C:\Users\David Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\cpgti450.default-release [2024-10-17]
FF Plugin: @java.com/DTPlugin,version=11.431.2 -> C:\Program Files\Java\jre1.8.0_431\bin\dtplugin\npDeployJava1.dll [2024-09-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.431.2 -> C:\Program Files\Java\jre1.8.0_431\bin\plugin2\npjp2.dll [2024-09-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-08-23] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-03-24] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-03-24] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
Chrome:
=======
CHR Profile: C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default [2024-10-31]
CHR Notifications: Default -> hxxps://www.talkie-ai.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Extension: (Dokumenty Google offline) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-09-02]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-10-08]
CHR Extension: (SteamDB) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdbmhfkmnlmbkgbabkdealhhbfhlmmon [2024-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-02-25]
CHR Profile: C:\Users\David Lukáš\AppData\Local\Google\Chrome\User Data\System Profile [2024-09-19]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
R2 AltisikService; C:\Program Files (x86)\AltisikApplication\AltisikService.exe [71937664 2024-06-17] (AltisikDevLM Group LM -> ) [File not signed] [File is in use] <==== ATTENTION
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [18663720 2024-09-15] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13861080 2024-10-05] (Microsoft Corporation -> Microsoft Corporation)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [14037088 2024-10-09] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2024-08-30] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [375248 2024-02-13] (Epic Games Inc. -> Epic Games, Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [241104 2024-08-16] (HP Inc. -> HP Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 rsVPNClientSvc; C:\Program Files\ReasonLabs\VPN\rsVPNClientSvc.exe [672400 2024-10-10] (Reason Cybersecurity Inc. -> Reason Software Company Inc.)
R2 rsVPNSvc; C:\Program Files\ReasonLabs\VPN\rsVPNSvc.exe [231048 2024-10-10] (Reason Cybersecurity Inc. -> Reason Software Company Inc.)
S3 TavernWorker_1_1; C:\Program Files\IRONMACE\Tavern\Steam\TavernApp_1_1\TavernWorker.exe [20841904 2024-07-20] (IRONMACE Co., Ltd. -> IRONMACE Co., Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEDaisy; C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys [5148848 2024-09-15] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R2 rimspci; C:\Windows\system32\DRIVERS\rimspe64.sys [57344 2009-02-12] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R2 risdpcie; C:\Windows\system32\DRIVERS\risdpe64.sys [80384 2009-03-30] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R3 SFEP; C:\Windows\System32\drivers\SFEP.sys [12032 2024-02-25] (Microsoft Windows Hardware Compatibility Publisher -> Sony Corporation)
R3 SteamStreamingMicrophone; C:\Windows\system32\drivers\SteamStreamingMicrophone.sys [40736 2020-06-01] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\Windows\system32\drivers\SteamStreamingSpeakers.sys [40736 2020-06-01] (Valve Corp. -> )
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22080 2024-08-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [602504 2024-08-09] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2024-08-09] (Microsoft Windows -> Microsoft Corporation)
R3 yukonw8; C:\Windows\System32\drivers\yk63x64.sys [288768 2019-12-07] (Microsoft Windows -> Marvell)
S3 NEProtect; \??\C:\Program Files (x86)\Steam\steamapps\common\Lost Light\Engine\Binaries\Win64\NEProtect.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-11-03 12:45 - 2024-11-03 12:53 - 000021068 _____ C:\Users\David Lukáš\Desktop\FRST.txt
2024-11-03 12:43 - 2024-11-03 12:51 - 000000000 ____D C:\FRST
2024-11-03 12:42 - 2024-11-03 12:37 - 002397696 _____ (Farbar) C:\Users\David Lukáš\Desktop\FRST64.exe
2024-11-03 11:47 - 2024-11-03 11:47 - 000000000 ___HD C:\$WinREAgent
2024-11-03 11:38 - 2024-11-03 11:38 - 000007605 _____ C:\Users\David Lukáš\AppData\Local\Resmon.ResmonCfg
2024-11-03 11:28 - 2024-11-03 11:28 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Sun
2024-11-03 11:28 - 2024-11-03 11:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2024-11-03 11:28 - 2024-09-30 08:34 - 000213120 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2024-11-03 11:26 - 2024-11-03 11:29 - 000000000 ____D C:\Program Files\Java
2024-10-31 17:56 - 2024-10-31 17:56 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2024-10-31 17:55 - 2024-10-31 18:00 - 000243056 _____ C:\Windows\ntbtlog.txt
2024-10-14 18:35 - 2024-10-14 18:35 - 000000222 _____ C:\Users\David Lukáš\Desktop\Assassin's Creed Rogue.url
2024-10-14 18:16 - 2024-10-14 18:16 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-10-14 18:05 - 2024-10-14 18:05 - 000000030 _____ C:\Windows\system32\.HQargq
2024-10-13 20:32 - 2024-10-13 20:32 - 000000000 ____D C:\Users\David Lukáš\Documents\Vlastní šablony Office
2024-10-13 19:28 - 2024-10-13 19:29 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\UProof
2024-10-13 19:28 - 2024-10-13 19:28 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Proof
2024-10-13 18:35 - 2024-10-14 18:36 - 000000000 ____D C:\Users\David Lukáš\Documents\Assassin's Creed Rogue
2024-10-13 14:14 - 2024-10-13 14:14 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\HTML Help
2024-10-11 19:46 - 2024-10-11 19:46 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\rsappui
2024-10-11 14:01 - 2024-10-13 11:31 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\ReasonLabs
2024-10-11 13:46 - 2024-10-11 13:46 - 000001248 _____ C:\Users\David Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RAV VPN.lnk
2024-10-10 21:34 - 2024-10-10 21:34 - 000000000 ____D C:\ProgramData\VPNBackup
2024-10-10 21:30 - 2024-10-13 11:32 - 000000000 ____D C:\ProgramData\ReasonLabs
2024-10-10 21:24 - 2024-10-13 11:36 - 000000000 ____D C:\Program Files\ReasonLabs
2024-10-10 21:16 - 2024-10-10 21:16 - 000000000 ____D C:\Program Files (x86)\rsStubActivator-1.1.1
2024-10-10 21:15 - 2024-10-10 21:15 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Walliant
2024-10-10 21:13 - 2024-10-10 21:13 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Midnight Commander
2024-10-10 21:12 - 2024-10-10 21:12 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\AgreementlwfTool
2024-10-10 21:12 - 2024-10-10 21:12 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\AgreementixvTool
2024-10-10 21:11 - 2024-10-10 21:11 - 000000000 ____D C:\Program Files (x86)\AgreementjpsTool
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-11-03 12:51 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2024-11-03 12:50 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-11-03 12:47 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2024-11-03 12:34 - 2024-02-23 22:10 - 000000000 ____D C:\ProgramData\NVIDIA
2024-11-03 12:33 - 2024-02-23 21:37 - 000008192 ___SH C:\DumpStack.log.tmp
2024-11-03 12:33 - 2024-02-23 21:37 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-11-03 12:32 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2024-11-03 12:12 - 2024-06-17 21:37 - 000000000 ____D C:\ProgramData\AltisikApplication
2024-11-03 12:01 - 2024-02-23 21:37 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-11-03 11:39 - 2024-02-23 21:38 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-11-03 11:39 - 2024-02-23 21:38 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-10-31 19:36 - 2024-02-23 21:47 - 000000000 ____D C:\Users\David Lukáš
2024-10-31 19:14 - 2024-02-23 21:39 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-10-31 18:52 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-10-31 18:23 - 2024-02-25 11:54 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-10-31 18:23 - 2023-05-05 13:27 - 000000000 ____D C:\Windows\SystemTemp
2024-10-31 18:10 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2024-10-31 18:03 - 2024-09-05 16:07 - 000000000 ____D C:\ProgramData\Avast Software
2024-10-31 18:01 - 2024-09-05 16:52 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\Avast Software
2024-10-31 18:00 - 2024-06-22 23:04 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-10-31 17:46 - 2024-02-23 22:09 - 000000000 ____D C:\Program Files\RUXIM
2024-10-31 17:38 - 2024-04-01 12:33 - 000000000 ____D C:\Program Files (x86)\Steam
2024-10-31 17:37 - 2024-02-23 21:49 - 000005858 _____ C:\Windows\system32\PerfStringBackup.INI
2024-10-31 17:37 - 2019-12-07 15:41 - 002898546 _____ C:\Windows\system32\perfh005.dat
2024-10-31 17:37 - 2019-12-07 15:41 - 000791128 _____ C:\Windows\system32\perfc005.dat
2024-10-31 17:23 - 2024-05-29 17:08 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\D3DSCache
2024-10-18 18:57 - 2024-06-17 21:37 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\AltisikApplication
2024-10-18 18:37 - 2024-04-01 20:37 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\CrashDumps
2024-10-17 21:15 - 2024-09-05 16:14 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2024-10-17 21:04 - 2024-04-01 12:35 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\.minecraft
2024-10-17 20:49 - 2024-04-01 12:35 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\.tlauncher
2024-10-17 20:20 - 2024-04-01 13:24 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2024-10-17 20:00 - 2024-04-02 13:16 - 000000000 ____D C:\Program Files\Epic Games
2024-10-15 18:58 - 2024-04-02 18:48 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\SpaceEngineers
2024-10-14 21:26 - 2024-04-05 14:48 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\RenPy
2024-10-14 18:35 - 2024-04-05 17:54 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\Ubisoft Game Launcher
2024-10-14 18:18 - 2024-02-25 12:47 - 000000000 ____D C:\Program Files\Microsoft Office
2024-10-14 18:18 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-10-14 18:07 - 2024-02-23 21:37 - 000438968 _____ C:\Windows\system32\FNTCACHE.DAT
2024-10-14 18:04 - 2019-12-07 15:42 - 000000000 ____D C:\Windows\system32\OpenSSH
2024-10-14 18:04 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2024-10-14 18:03 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2024-10-14 18:03 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2024-10-14 16:50 - 2024-02-25 13:14 - 000000000 ____D C:\Users\David Lukáš\AppData\Roaming\Microsoft\Word
2024-10-14 16:19 - 2024-02-23 21:40 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-10-13 15:02 - 2024-02-25 12:28 - 000000000 ____D C:\ProgramData\Package Cache
2024-10-13 15:01 - 2024-04-01 21:40 - 000000000 ____D C:\Program Files\dotnet
2024-10-13 14:38 - 2024-02-23 22:13 - 000000000 ____D C:\Windows\system32\MRT
2024-10-13 14:25 - 2024-02-23 22:12 - 201324920 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-10-13 11:56 - 2024-06-17 21:37 - 000000000 ____D C:\Program Files (x86)\AltisikApplication
2024-10-12 23:05 - 2024-05-24 14:16 - 000000000 ____D C:\ProgramData\EA Desktop
2024-10-11 22:57 - 2024-09-17 06:48 - 000000000 ____D C:\Users\David Lukáš\Documents\My Games
2024-10-11 22:56 - 2024-09-16 22:57 - 000000000 ____D C:\Users\David Lukáš\Documents\Hry
2024-10-11 22:51 - 2024-04-15 16:39 - 000000000 ____D C:\Windows\Minidump
2024-10-11 22:51 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\LiveKernelReports
2024-10-10 21:13 - 2024-02-23 21:48 - 000000000 ____D C:\Users\David Lukáš\AppData\Local\VirtualStore
2024-10-08 16:43 - 2024-06-22 23:04 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2024-10-08 16:22 - 2024-02-25 11:33 - 000003126 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1588777837-2161469333-1616248303-1001
2024-10-08 16:22 - 2024-02-23 22:02 - 000002922 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1588777837-2161469333-1616248303-1001
==================== Files in the root of some directories ========
2024-11-03 11:38 - 2024-11-03 11:38 - 000007605 _____ () C:\Users\David Lukáš\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================