Pomalý Chrome
Napsal: 21 pro 2024 14:01
Můžu poprosit o kontrolu --- pomalý prohlížeč Chrome
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-12-2024 01
Ran by rossu (administrator) on DESKTOP-20BP8MR (Acer Aspire ES1-731G) (21-12-2024 13:45:38)
Running from C:\Users\rossu\Desktop\FRST64 (1).exe
Loaded Profiles: rossu
Platform: Microsoft Windows 11 Home Version 23H2 22631.4602 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\101.0.3.0\crashpad_handler.exe
(C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <10>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe <7>
(RuntimeBroker.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(RuntimeBroker.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_6.1.4.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.200.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1982769764-3492556622-4078228296-1000\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1982769764-3492556622-4078228296-1000\...\Run: [qBittorrent] => D:\program\qBittorrent\qbittorrent.exe [36657664 2024-11-17] (The qBittorrent Project) [File not signed]
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\131.0.6778.205\Installer\chrmstp.exe [2024-12-20] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction ? <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {8863E00E-ED58-4F3D-8660-BFDA754B3711} - System32\Tasks\2BrightSparks\SyncBackFree\DESKTOP-20BP8MR-rossu\SyncBackFree dok => D:\program\SyncBackFree\SyncBackFree.exe [152831944 2024-08-26] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte. Ltd.) -> D:\program\SyncBackFree\-m -sched "dok"
Task: {B0F20476-7FE7-4AE4-9788-5B0FC731F75E} - System32\Tasks\2BrightSparks\SyncBackFree\DESKTOP-20BP8MR-rossu\SyncBackFree dok2 => D:\program\SyncBackFree\SyncBackFree.exe [152831944 2024-08-26] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte. Ltd.) -> D:\program\SyncBackFree\-m -sched "dok2"
Task: {BE4A4203-A31D-4658-B380-C2D9483C59FB} - System32\Tasks\2BrightSparks\SyncBackFree\DESKTOP-20BP8MR-rossu\SyncBackFree foto => D:\program\SyncBackFree\SyncBackFree.exe [152831944 2024-08-26] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte. Ltd.) -> D:\program\SyncBackFree\-m -sched "foto"
Task: {0F413C9E-2CC9-4F5B-9814-F743DF6EC762} - System32\Tasks\CCleanerCrashReporting => E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\CCleanerBugReport.exe -> --product 90 --send dumps|report --path "E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\LOG" --programpath "E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner" --guid "沤ƶ" --version "6.29.11342" --silent
Task: {A9F8A1F7-33BF-41F7-89EF-5E54141F94B2} - System32\Tasks\Driver Booster SkipUAC (rossu) => "E:\torrent\IObit Driver Booster Pro 12.0.0.356\App\DriverBooster\DriverBooster.exe" /skipuac (No File)
Task: {D025C887-4C9D-4E64-8812-2314E040D9C4} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\rossu\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-10-18] (ESET, spol. s r.o. -> ESET)
Task: {BA2A7C66-4307-4A20-A1D4-03032D099453} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\rossu\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-10-18] (ESET, spol. s r.o. -> ESET)
Task: {8B144456-05B4-40AF-9F08-396AB6B6130C} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem129.0.6651.0{00BD69EB-9B74-4946-A1AD-01AEED7C7DE7} => C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe [4906600 2024-08-11] (Google LLC -> Google LLC)
Task: {FD038491-A30D-4686-BB6F-6B6DA48AE3BA} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{06594B9B-B0AF-46D7-A639-A3F9AD9461A2} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
Task: {1C4B02E2-E221-4AD2-AD8C-C4BAFA1B4E56} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6833.0{46D7CD13-D769-4EEE-9C42-77EABF3FA9CC} => C:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\updater.exe [5591136 2024-11-11] (Google LLC -> Google LLC)
Task: {215BE1DF-4636-4FF3-8075-B9EC28B4C9B1} - System32\Tasks\Launch Adobe CCXProcess => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [194056 2024-07-08] (Adobe Inc. -> Adobe Inc.)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {D8F59FB5-2823-448C-AFF5-A0B18EFBC128} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AA491216-8DAE-4CFA-B1E1-82CF5DCC50FA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C30F7A47-2A9C-46B3-9FA2-D5F511313DFA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1EE7D424-D715-44D3-8D1F-EB64B628E72C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {47AC11F3-BE71-4C48-8C08-B0E138C1D1F6} - System32\Tasks\Trojan Remover => "D:\program\Loaris Trojan Remover\ltr.exe" (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\CCleanerBugReport.exe
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{6dbce492-6c9f-4351-8da0-0b17b0f80c55}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{e44ed55f-8c92-4c79-b7b9-fc31d0698e7e}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Edge:
=======
Edge Profile: C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default [2024-11-25]
Edge HomePage: Default -> hxxp://www.seznam.cz/
Edge StartupUrls: Default -> "hxxps://www.seznam.cz/"
Edge Extension: (Překladač Google) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-11-17]
Edge Extension: (Seznam Doplněk – Email) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2024-11-17]
Edge Extension: (Pomocník pro Google Calendar ™) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bmjejnfomomknbjkohfhekplmndpannk [2024-11-17]
Edge Extension: (Plasma Integration) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cimiefiiaegbelhefglklhhakcgmhkai [2024-11-17]
Edge Extension: (Ochrana procházení internetu F-Secure) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cpikpibllpjmpnchjajlibnmmomnnhnm [2024-11-17]
Edge Extension: (AddToAny: Share Anywhere) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ffpgijchhhkhnokafdeklpllijgnbche [2024-11-17]
Edge Extension: (Dokumenty Google offline) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-17]
Edge Extension: (DeftPDF) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hghnkoikialmacnjlibfmlnhhihndepb [2024-11-17]
Edge Extension: (Edge relevant text changes) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-11-17]
Edge Extension: (Ochrana procházení internetu F-Secure) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2024-11-17]
Edge Extension: (Button for Google Calendar) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lfjnmopldodmmdhddmeacgjnjeakjpki [2024-11-17]
Edge Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-11-17]
Edge Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2024-11-23]
Edge Extension: (SearchGPT - ChatGPT for Chrome) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ninecedhhpccjifamhafbdelibdjibgd [2024-11-17]
Edge Extension: (Nástroj na obnovení Chromebooku) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pocpnlppkickgojjlmhdmidojbmbodfm [2024-11-17]
FireFox:
========
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default [2024-12-21]
CHR Notifications: Default -> hxxps://www.facebook.com; hxxps://www.holokolo.cz
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/"
CHR Extension: (Překladač Google) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-10-25]
CHR Extension: (Pomocník pro Google Calendar ™) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmjejnfomomknbjkohfhekplmndpannk [2024-10-25]
CHR Extension: (Plasma Integration) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\cimiefiiaegbelhefglklhhakcgmhkai [2024-10-25]
CHR Extension: (AddToAny: Share Anywhere) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffpgijchhhkhnokafdeklpllijgnbche [2024-10-25]
CHR Extension: (Dokumenty Google offline) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-12-17]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-12-17]
CHR Extension: (Ochrana procházení internetu F-Secure) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2024-12-04]
CHR Extension: (Button for Google Calendar) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfjnmopldodmmdhddmeacgjnjeakjpki [2024-11-12]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-10-20]
CHR Extension: (SearchGPT - ChatGPT for Chrome) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ninecedhhpccjifamhafbdelibdjibgd [2024-10-25]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-10-20]
CHR Extension: (Nástroj na obnovení Chromebooku) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pocpnlppkickgojjlmhdmidojbmbodfm [2024-10-25]
CHR Profile: C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-11-23]
CHR DefaultSearchURL: Guest Profile -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Guest Profile -> duckduckgo.com
CHR DefaultNewTabURL: Guest Profile -> hxxps://duckduckgo.com/chrome_newtab
CHR DefaultSuggestURL: Guest Profile -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR HKU\S-1-5-21-1982769764-3492556622-4078228296-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 FoxitReaderUpdateService; C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2489328 2024-05-22] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 CCleanerPerformanceOptimizerService; "E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\CCleanerPerformanceOptimizerService.exe" [X]
S3 MBAMService; "D:\program\malwarebites\MBAMService.exe" [X]
S3 MBVpnTunnelService; "D:\program\malwarebites\MBVpnTunnelService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
S2 SpybotAntiBeaconInterceptor; C:\Program Files (x86)\Safer-Networking Ltd\Spybot Anti-Beacon\x64\Spybot3AntiBeaconService.exe --run [X]
S2 USBSafelyRemoveService; "C:\Users\rossu\Desktop\USB Safely Remove 7.0.5.1320 (x64) portable\App\USBSafelyRemove\USBSRService.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [544768 2024-08-29] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [188416 2024-08-28] (Microsoft Corporation) [File not signed]
R2 googledrivefs31626; C:\Program Files\Google\Drive File Stream\Drivers\31626\googledrivefs31626.sys [384096 2024-08-29] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [231504 2024-10-20] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2024-10-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239568 2024-10-20] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 Revoflt; C:\Windows\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 rt68cx21; C:\Windows\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_fd79c26dfafbe776\rt68cx21x64.sys [831320 2024-09-01] (Realtek Semiconductor Corp. -> Realtek)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22104 2024-10-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [606624 2024-10-16] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105888 2024-10-16] (Microsoft Windows -> Microsoft Corporation)
S4 IObitUnlocker; \??\D:\program\IObit Unlocker\IObitUnlocker.sys [X]
U0 Partizan; system32\drivers\Partizan.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-12-21 13:45 - 2024-12-21 13:48 - 000021147 _____ C:\Users\rossu\Desktop\FRST.txt
2024-12-21 13:45 - 2024-12-21 13:45 - 000000000 ____D C:\Users\rossu\Desktop\FRST-OlderVersion
2024-12-21 13:44 - 2024-12-21 13:44 - 000727012 _____ C:\Windows\system32\perfh005.dat
2024-12-21 13:44 - 2024-12-21 13:44 - 000151244 _____ C:\Windows\system32\perfc005.dat
2024-12-21 13:41 - 2024-12-21 13:41 - 000034806 _____ C:\Users\rossu\Downloads\[SkT]CCleaner_Professional_6.31.11415_CZ_ _SK_(x64)_portable.torrent
2024-12-21 13:38 - 2024-12-21 13:40 - 000001413 _____ C:\Users\rossu\Desktop\Rebůt.lnk
2024-12-21 11:20 - 2024-12-21 11:20 - 050423232 _____ C:\Users\rossu\Downloads\miflash_unlock-en-4.5.707.49.zip
2024-12-20 21:47 - 2024-12-20 21:47 - 000027231 _____ C:\Users\rossu\Downloads\(Modern Classical, Industrial, Ambient) Skrol - Dances And Marches For The Orphan Age - 2005, FLAC (image+.cue), lossless [rutracker-2260508].torrent
2024-12-20 19:02 - 2024-12-20 19:02 - 000031716 _____ C:\Users\rossu\Downloads\ops021-121455-technicky-nakres-0.pdf
2024-12-20 18:00 - 2024-12-20 18:02 - 053655000 _____ (K7 Computing Pvt Ltd) C:\Users\rossu\Desktop\K7RansomwareScn.exe
2024-12-20 17:48 - 2024-12-20 17:48 - 000000926 _____ C:\Users\rossu\Downloads\[SkT]IcoFX3_(v.3.9)(2023)(CZ).torrent
2024-12-20 17:40 - 2024-12-20 17:40 - 000015442 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E08_(CZ_EN)[WEB-DL][1080p]_=_CSFD_75%.torrent
2024-12-20 17:36 - 2024-12-20 17:36 - 000017052 _____ C:\Users\rossu\Downloads\(Industrial Rock) Marilyn Manson - One Assassination Under God Chapter 1 - 2024, MP3, 320 kbps [rutracker-6602538].torrent
2024-12-19 17:46 - 2024-12-19 17:46 - 002244741 _____ C:\Users\rossu\Downloads\Brožura Čas Vánoc 2024.pdf
2024-12-19 17:37 - 2024-12-19 17:37 - 000000000 _____ C:\Users\rossu\Desktop\zelí nemecek.txt
2024-12-17 21:32 - 2024-12-17 21:32 - 000022202 _____ C:\Users\rossu\Downloads\[TR24][OF][LDR] The Cure - Songs Of A Lost World + Songs Of A Live World Troxy London MMXXIV - 2024 (Alternative Rock, Pop Rock, [rutracker-6614986].torrent
2024-12-17 21:14 - 2024-12-17 21:14 - 000060912 _____ C:\Users\rossu\Downloads\[SkT]Vlny_(2024)(CZ)_=_CSFD_89%.torrent
2024-12-15 14:43 - 2024-12-15 16:54 - 2314013265 _____ C:\Users\rossu\Downloads\Zápisník alkoholičky (2024).mkv
2024-12-15 10:28 - 2024-12-15 10:28 - 000016747 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E07_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-15 10:22 - 2024-12-15 10:23 - 295344856 _____ C:\Users\rossu\Desktop\z5l1y642.exe
2024-12-15 10:10 - 2024-12-15 10:10 - 000000000 ____D C:\Users\rossu\CrossDevice
2024-12-09 20:20 - 2024-12-09 20:20 - 000214258 _____ C:\Users\rossu\Downloads\467259_3D.STEP
2024-12-09 19:55 - 2024-12-09 19:56 - 295037168 _____ C:\Users\rossu\Downloads\2h65k7iv.exe
2024-12-09 18:14 - 2024-12-09 18:14 - 000015738 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E03_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:14 - 2024-12-09 18:14 - 000014704 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E06_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:14 - 2024-12-09 18:14 - 000014055 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E04_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:14 - 2024-12-09 18:14 - 000013718 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E05_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:13 - 2024-12-09 18:13 - 000013897 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E02_(CZ_EN)[WEB-DL][1080p]_=_CSFD_73%.torrent
2024-12-09 18:13 - 2024-12-09 18:13 - 000013066 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E01_(CZ)[WEB-DL][1080p]_=_CSFD_73%.torrent
2024-12-06 18:37 - 2024-12-06 18:37 - 000022902 _____ C:\Users\rossu\Downloads\[SkT]Marie___Mary_(2024)(CZ_EN)[WEB-DL][1080p].torrent
2024-12-06 17:45 - 2024-12-06 17:45 - 000010650 _____ C:\Users\rossu\Downloads\(Rock Gothic Post Punk) The Cure - A Fragile Thing [Single] - 2024, MP3, 320 kbps [rutracker-6609248].torrent
2024-11-23 21:34 - 2024-11-23 21:34 - 000000000 ____D C:\Users\rossu\AppData\Roaming\OpenOffice
2024-11-23 21:33 - 2024-11-23 21:33 - 000000000 ___SD C:\Users\rossu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.15
2024-11-23 21:31 - 2024-11-23 21:32 - 000000000 ____D C:\Program Files (x86)\OpenOffice 4
2024-11-23 21:20 - 2024-11-25 17:20 - 000002444 _____ C:\Windows\system32\Tasks\Trojan Remover
2024-11-23 21:06 - 2024-11-23 21:06 - 000000000 ____D C:\Users\rossu\Documents\Simply Super Software
2024-11-23 18:42 - 2024-11-23 18:42 - 000388608 _____ (Trend Micro Inc.) C:\Users\rossu\Desktop\hijackthis.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-12-21 13:49 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SystemTemp
2024-12-21 13:47 - 2024-11-17 10:36 - 000000000 ____D C:\FRST
2024-12-21 13:45 - 2024-11-17 10:32 - 002403840 _____ (Farbar) C:\Users\rossu\Desktop\FRST64 (1).exe
2024-12-21 13:44 - 2024-08-28 19:48 - 001718036 _____ C:\Windows\system32\PerfStringBackup.INI
2024-12-21 13:44 - 2022-05-07 06:22 - 000000000 ____D C:\Windows\INF
2024-12-21 13:43 - 2024-08-29 18:10 - 000000000 ____D C:\Users\rossu\AppData\Roaming\qBittorrent
2024-12-21 13:39 - 2024-08-28 19:55 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2024-12-21 13:39 - 2024-08-28 19:55 - 000000000 __SHD C:\Users\rossu\IntelGraphicsProfiles
2024-12-21 13:39 - 2024-08-28 19:29 - 000012288 ___SH C:\DumpStack.log.tmp
2024-12-21 13:39 - 2024-08-28 19:29 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-12-21 13:38 - 2022-05-07 06:17 - 000786432 _____ C:\Windows\system32\config\BBI
2024-12-21 12:51 - 2024-08-28 19:29 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-12-21 12:50 - 2024-08-28 19:41 - 000000000 ___SD C:\Users\rossu\AppData\Roaming\Microsoft\Credentials
2024-12-21 09:14 - 2024-08-28 19:30 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-12-21 09:14 - 2024-08-28 19:30 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-12-20 18:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\AppReadiness
2024-12-20 17:50 - 2022-05-07 06:24 - 000000000 ___HD C:\Program Files\WindowsApps
2024-12-20 17:43 - 2024-08-28 19:30 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-12-19 19:00 - 2024-09-02 16:11 - 000000000 ____D C:\Users\rossu\AppData\Local\CrashDumps
2024-12-19 18:14 - 2024-10-18 18:34 - 000001382 _____ C:\Users\rossu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2024-12-19 18:14 - 2024-10-18 18:34 - 000001276 _____ C:\Users\rossu\Desktop\ESET Online Scanner.lnk
2024-12-17 21:21 - 2024-08-28 19:41 - 000000000 ____D C:\Users\rossu\AppData\Local\Packages
2024-12-15 22:21 - 2024-08-28 19:41 - 000000000 ____D C:\Users\rossu
2024-12-15 10:38 - 2024-08-28 19:29 - 000446528 _____ C:\Windows\system32\FNTCACHE.DAT
2024-12-15 10:37 - 2023-10-01 08:01 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SystemResources
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\Sgrm
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\setup
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\bcastdvr
2024-12-11 20:18 - 2022-05-07 06:17 - 000000000 ____D C:\Windows\CbsTemp
2024-12-11 19:29 - 2024-08-29 18:09 - 000002048 _____ C:\Users\rossu\Desktop\Google Drive.lnk
2024-12-09 23:21 - 2024-08-28 19:43 - 000000000 ____D C:\Users\rossu\AppData\Local\D3DSCache
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ___SD C:\Windows\system32\UNP
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\ShellExperiences
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\oobe
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\Dism
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\appraiser
2024-11-29 22:25 - 2022-05-07 06:24 - 000000000 ___RD C:\Windows\PrintDialog
2024-11-29 22:25 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\ShellExperiences
2024-11-29 22:25 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\ShellComponents
2024-11-29 20:07 - 2022-05-07 06:25 - 000077312 _____ (Khronos Group) C:\Windows\SysWOW64\opencl.dll
2024-11-29 20:07 - 2022-05-07 06:24 - 000118784 _____ (Khronos Group) C:\Windows\system32\opencl.dll
2024-11-29 20:00 - 2024-08-28 19:31 - 003212800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-11-25 19:38 - 2024-10-07 15:28 - 000000000 ____D C:\Users\rossu\AppData\Roaming\Microsoft\MMC
2024-11-23 21:23 - 2024-11-04 18:37 - 000000000 ____D C:\Users\rossu\AppData\Roaming\USBSafelyRemove
2024-11-23 20:44 - 2024-11-02 18:04 - 000000972 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2024-11-23 18:43 - 2024-09-02 15:26 - 000000000 ____D C:\Users\rossu\AppData\Local\VirtualStore
2024-11-23 17:52 - 2024-11-02 18:04 - 000003320 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2024-11-23 17:52 - 2024-11-02 17:21 - 000002840 _____ C:\Windows\system32\Tasks\Driver Booster SkipUAC (rossu)
==================== Files in the root of some directories ========
2024-09-08 13:28 - 2024-09-08 13:28 - 000004097 _____ () C:\Users\rossu\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-12-2024 01
Ran by rossu (administrator) on DESKTOP-20BP8MR (Acer Aspire ES1-731G) (21-12-2024 13:45:38)
Running from C:\Users\rossu\Desktop\FRST64 (1).exe
Loaded Profiles: rossu
Platform: Microsoft Windows 11 Home Version 23H2 22631.4602 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\101.0.3.0\crashpad_handler.exe
(C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <10>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe <7>
(RuntimeBroker.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(RuntimeBroker.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_6.1.4.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.200.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1982769764-3492556622-4078228296-1000\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1982769764-3492556622-4078228296-1000\...\Run: [qBittorrent] => D:\program\qBittorrent\qbittorrent.exe [36657664 2024-11-17] (The qBittorrent Project) [File not signed]
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\101.0.3.0\GoogleDriveFS.exe [61998176 2024-12-11] (Google LLC -> Google, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\131.0.6778.205\Installer\chrmstp.exe [2024-12-20] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction ? <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {8863E00E-ED58-4F3D-8660-BFDA754B3711} - System32\Tasks\2BrightSparks\SyncBackFree\DESKTOP-20BP8MR-rossu\SyncBackFree dok => D:\program\SyncBackFree\SyncBackFree.exe [152831944 2024-08-26] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte. Ltd.) -> D:\program\SyncBackFree\-m -sched "dok"
Task: {B0F20476-7FE7-4AE4-9788-5B0FC731F75E} - System32\Tasks\2BrightSparks\SyncBackFree\DESKTOP-20BP8MR-rossu\SyncBackFree dok2 => D:\program\SyncBackFree\SyncBackFree.exe [152831944 2024-08-26] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte. Ltd.) -> D:\program\SyncBackFree\-m -sched "dok2"
Task: {BE4A4203-A31D-4658-B380-C2D9483C59FB} - System32\Tasks\2BrightSparks\SyncBackFree\DESKTOP-20BP8MR-rossu\SyncBackFree foto => D:\program\SyncBackFree\SyncBackFree.exe [152831944 2024-08-26] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte. Ltd.) -> D:\program\SyncBackFree\-m -sched "foto"
Task: {0F413C9E-2CC9-4F5B-9814-F743DF6EC762} - System32\Tasks\CCleanerCrashReporting => E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\CCleanerBugReport.exe -> --product 90 --send dumps|report --path "E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\LOG" --programpath "E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner" --guid "沤ƶ" --version "6.29.11342" --silent
Task: {A9F8A1F7-33BF-41F7-89EF-5E54141F94B2} - System32\Tasks\Driver Booster SkipUAC (rossu) => "E:\torrent\IObit Driver Booster Pro 12.0.0.356\App\DriverBooster\DriverBooster.exe" /skipuac (No File)
Task: {D025C887-4C9D-4E64-8812-2314E040D9C4} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\rossu\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-10-18] (ESET, spol. s r.o. -> ESET)
Task: {BA2A7C66-4307-4A20-A1D4-03032D099453} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\rossu\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-10-18] (ESET, spol. s r.o. -> ESET)
Task: {8B144456-05B4-40AF-9F08-396AB6B6130C} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem129.0.6651.0{00BD69EB-9B74-4946-A1AD-01AEED7C7DE7} => C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe [4906600 2024-08-11] (Google LLC -> Google LLC)
Task: {FD038491-A30D-4686-BB6F-6B6DA48AE3BA} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{06594B9B-B0AF-46D7-A639-A3F9AD9461A2} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
Task: {1C4B02E2-E221-4AD2-AD8C-C4BAFA1B4E56} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6833.0{46D7CD13-D769-4EEE-9C42-77EABF3FA9CC} => C:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\updater.exe [5591136 2024-11-11] (Google LLC -> Google LLC)
Task: {215BE1DF-4636-4FF3-8075-B9EC28B4C9B1} - System32\Tasks\Launch Adobe CCXProcess => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [194056 2024-07-08] (Adobe Inc. -> Adobe Inc.)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {D8F59FB5-2823-448C-AFF5-A0B18EFBC128} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AA491216-8DAE-4CFA-B1E1-82CF5DCC50FA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C30F7A47-2A9C-46B3-9FA2-D5F511313DFA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1EE7D424-D715-44D3-8D1F-EB64B628E72C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {47AC11F3-BE71-4C48-8C08-B0E138C1D1F6} - System32\Tasks\Trojan Remover => "D:\program\Loaris Trojan Remover\ltr.exe" (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\CCleanerBugReport.exe
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{6dbce492-6c9f-4351-8da0-0b17b0f80c55}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{e44ed55f-8c92-4c79-b7b9-fc31d0698e7e}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Edge:
=======
Edge Profile: C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default [2024-11-25]
Edge HomePage: Default -> hxxp://www.seznam.cz/
Edge StartupUrls: Default -> "hxxps://www.seznam.cz/"
Edge Extension: (Překladač Google) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-11-17]
Edge Extension: (Seznam Doplněk – Email) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2024-11-17]
Edge Extension: (Pomocník pro Google Calendar ™) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bmjejnfomomknbjkohfhekplmndpannk [2024-11-17]
Edge Extension: (Plasma Integration) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cimiefiiaegbelhefglklhhakcgmhkai [2024-11-17]
Edge Extension: (Ochrana procházení internetu F-Secure) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cpikpibllpjmpnchjajlibnmmomnnhnm [2024-11-17]
Edge Extension: (AddToAny: Share Anywhere) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ffpgijchhhkhnokafdeklpllijgnbche [2024-11-17]
Edge Extension: (Dokumenty Google offline) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-17]
Edge Extension: (DeftPDF) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hghnkoikialmacnjlibfmlnhhihndepb [2024-11-17]
Edge Extension: (Edge relevant text changes) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-11-17]
Edge Extension: (Ochrana procházení internetu F-Secure) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2024-11-17]
Edge Extension: (Button for Google Calendar) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lfjnmopldodmmdhddmeacgjnjeakjpki [2024-11-17]
Edge Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-11-17]
Edge Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2024-11-23]
Edge Extension: (SearchGPT - ChatGPT for Chrome) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ninecedhhpccjifamhafbdelibdjibgd [2024-11-17]
Edge Extension: (Nástroj na obnovení Chromebooku) - C:\Users\rossu\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pocpnlppkickgojjlmhdmidojbmbodfm [2024-11-17]
FireFox:
========
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> D:\program\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default [2024-12-21]
CHR Notifications: Default -> hxxps://www.facebook.com; hxxps://www.holokolo.cz
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/"
CHR Extension: (Překladač Google) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-10-25]
CHR Extension: (Pomocník pro Google Calendar ™) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmjejnfomomknbjkohfhekplmndpannk [2024-10-25]
CHR Extension: (Plasma Integration) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\cimiefiiaegbelhefglklhhakcgmhkai [2024-10-25]
CHR Extension: (AddToAny: Share Anywhere) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffpgijchhhkhnokafdeklpllijgnbche [2024-10-25]
CHR Extension: (Dokumenty Google offline) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-12-17]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-12-17]
CHR Extension: (Ochrana procházení internetu F-Secure) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2024-12-04]
CHR Extension: (Button for Google Calendar) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfjnmopldodmmdhddmeacgjnjeakjpki [2024-11-12]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-10-20]
CHR Extension: (SearchGPT - ChatGPT for Chrome) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ninecedhhpccjifamhafbdelibdjibgd [2024-10-25]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-10-20]
CHR Extension: (Nástroj na obnovení Chromebooku) - C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pocpnlppkickgojjlmhdmidojbmbodfm [2024-10-25]
CHR Profile: C:\Users\rossu\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-11-23]
CHR DefaultSearchURL: Guest Profile -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Guest Profile -> duckduckgo.com
CHR DefaultNewTabURL: Guest Profile -> hxxps://duckduckgo.com/chrome_newtab
CHR DefaultSuggestURL: Guest Profile -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR HKU\S-1-5-21-1982769764-3492556622-4078228296-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 FoxitReaderUpdateService; C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2489328 2024-05-22] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2024-10-16] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 CCleanerPerformanceOptimizerService; "E:\torrent\CCleaner Professional 6.29.11342 CZ + SK (x64) portable\program\App\CCleaner\CCleanerPerformanceOptimizerService.exe" [X]
S3 MBAMService; "D:\program\malwarebites\MBAMService.exe" [X]
S3 MBVpnTunnelService; "D:\program\malwarebites\MBVpnTunnelService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
S2 SpybotAntiBeaconInterceptor; C:\Program Files (x86)\Safer-Networking Ltd\Spybot Anti-Beacon\x64\Spybot3AntiBeaconService.exe --run [X]
S2 USBSafelyRemoveService; "C:\Users\rossu\Desktop\USB Safely Remove 7.0.5.1320 (x64) portable\App\USBSafelyRemove\USBSRService.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [544768 2024-08-29] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [188416 2024-08-28] (Microsoft Corporation) [File not signed]
R2 googledrivefs31626; C:\Program Files\Google\Drive File Stream\Drivers\31626\googledrivefs31626.sys [384096 2024-08-29] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [231504 2024-10-20] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2024-10-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239568 2024-10-20] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 Revoflt; C:\Windows\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 rt68cx21; C:\Windows\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_fd79c26dfafbe776\rt68cx21x64.sys [831320 2024-09-01] (Realtek Semiconductor Corp. -> Realtek)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22104 2024-10-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [606624 2024-10-16] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105888 2024-10-16] (Microsoft Windows -> Microsoft Corporation)
S4 IObitUnlocker; \??\D:\program\IObit Unlocker\IObitUnlocker.sys [X]
U0 Partizan; system32\drivers\Partizan.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-12-21 13:45 - 2024-12-21 13:48 - 000021147 _____ C:\Users\rossu\Desktop\FRST.txt
2024-12-21 13:45 - 2024-12-21 13:45 - 000000000 ____D C:\Users\rossu\Desktop\FRST-OlderVersion
2024-12-21 13:44 - 2024-12-21 13:44 - 000727012 _____ C:\Windows\system32\perfh005.dat
2024-12-21 13:44 - 2024-12-21 13:44 - 000151244 _____ C:\Windows\system32\perfc005.dat
2024-12-21 13:41 - 2024-12-21 13:41 - 000034806 _____ C:\Users\rossu\Downloads\[SkT]CCleaner_Professional_6.31.11415_CZ_ _SK_(x64)_portable.torrent
2024-12-21 13:38 - 2024-12-21 13:40 - 000001413 _____ C:\Users\rossu\Desktop\Rebůt.lnk
2024-12-21 11:20 - 2024-12-21 11:20 - 050423232 _____ C:\Users\rossu\Downloads\miflash_unlock-en-4.5.707.49.zip
2024-12-20 21:47 - 2024-12-20 21:47 - 000027231 _____ C:\Users\rossu\Downloads\(Modern Classical, Industrial, Ambient) Skrol - Dances And Marches For The Orphan Age - 2005, FLAC (image+.cue), lossless [rutracker-2260508].torrent
2024-12-20 19:02 - 2024-12-20 19:02 - 000031716 _____ C:\Users\rossu\Downloads\ops021-121455-technicky-nakres-0.pdf
2024-12-20 18:00 - 2024-12-20 18:02 - 053655000 _____ (K7 Computing Pvt Ltd) C:\Users\rossu\Desktop\K7RansomwareScn.exe
2024-12-20 17:48 - 2024-12-20 17:48 - 000000926 _____ C:\Users\rossu\Downloads\[SkT]IcoFX3_(v.3.9)(2023)(CZ).torrent
2024-12-20 17:40 - 2024-12-20 17:40 - 000015442 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E08_(CZ_EN)[WEB-DL][1080p]_=_CSFD_75%.torrent
2024-12-20 17:36 - 2024-12-20 17:36 - 000017052 _____ C:\Users\rossu\Downloads\(Industrial Rock) Marilyn Manson - One Assassination Under God Chapter 1 - 2024, MP3, 320 kbps [rutracker-6602538].torrent
2024-12-19 17:46 - 2024-12-19 17:46 - 002244741 _____ C:\Users\rossu\Downloads\Brožura Čas Vánoc 2024.pdf
2024-12-19 17:37 - 2024-12-19 17:37 - 000000000 _____ C:\Users\rossu\Desktop\zelí nemecek.txt
2024-12-17 21:32 - 2024-12-17 21:32 - 000022202 _____ C:\Users\rossu\Downloads\[TR24][OF][LDR] The Cure - Songs Of A Lost World + Songs Of A Live World Troxy London MMXXIV - 2024 (Alternative Rock, Pop Rock, [rutracker-6614986].torrent
2024-12-17 21:14 - 2024-12-17 21:14 - 000060912 _____ C:\Users\rossu\Downloads\[SkT]Vlny_(2024)(CZ)_=_CSFD_89%.torrent
2024-12-15 14:43 - 2024-12-15 16:54 - 2314013265 _____ C:\Users\rossu\Downloads\Zápisník alkoholičky (2024).mkv
2024-12-15 10:28 - 2024-12-15 10:28 - 000016747 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E07_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-15 10:22 - 2024-12-15 10:23 - 295344856 _____ C:\Users\rossu\Desktop\z5l1y642.exe
2024-12-15 10:10 - 2024-12-15 10:10 - 000000000 ____D C:\Users\rossu\CrossDevice
2024-12-09 20:20 - 2024-12-09 20:20 - 000214258 _____ C:\Users\rossu\Downloads\467259_3D.STEP
2024-12-09 19:55 - 2024-12-09 19:56 - 295037168 _____ C:\Users\rossu\Downloads\2h65k7iv.exe
2024-12-09 18:14 - 2024-12-09 18:14 - 000015738 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E03_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:14 - 2024-12-09 18:14 - 000014704 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E06_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:14 - 2024-12-09 18:14 - 000014055 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E04_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:14 - 2024-12-09 18:14 - 000013718 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E05_(CZ_EN)[WEB-DL][1080p]_=_CSFD_74%.torrent
2024-12-09 18:13 - 2024-12-09 18:13 - 000013897 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E02_(CZ_EN)[WEB-DL][1080p]_=_CSFD_73%.torrent
2024-12-09 18:13 - 2024-12-09 18:13 - 000013066 _____ C:\Users\rossu\Downloads\[SkT]Special_Ops__Lioness_S02E01_(CZ)[WEB-DL][1080p]_=_CSFD_73%.torrent
2024-12-06 18:37 - 2024-12-06 18:37 - 000022902 _____ C:\Users\rossu\Downloads\[SkT]Marie___Mary_(2024)(CZ_EN)[WEB-DL][1080p].torrent
2024-12-06 17:45 - 2024-12-06 17:45 - 000010650 _____ C:\Users\rossu\Downloads\(Rock Gothic Post Punk) The Cure - A Fragile Thing [Single] - 2024, MP3, 320 kbps [rutracker-6609248].torrent
2024-11-23 21:34 - 2024-11-23 21:34 - 000000000 ____D C:\Users\rossu\AppData\Roaming\OpenOffice
2024-11-23 21:33 - 2024-11-23 21:33 - 000000000 ___SD C:\Users\rossu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.15
2024-11-23 21:31 - 2024-11-23 21:32 - 000000000 ____D C:\Program Files (x86)\OpenOffice 4
2024-11-23 21:20 - 2024-11-25 17:20 - 000002444 _____ C:\Windows\system32\Tasks\Trojan Remover
2024-11-23 21:06 - 2024-11-23 21:06 - 000000000 ____D C:\Users\rossu\Documents\Simply Super Software
2024-11-23 18:42 - 2024-11-23 18:42 - 000388608 _____ (Trend Micro Inc.) C:\Users\rossu\Desktop\hijackthis.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-12-21 13:49 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SystemTemp
2024-12-21 13:47 - 2024-11-17 10:36 - 000000000 ____D C:\FRST
2024-12-21 13:45 - 2024-11-17 10:32 - 002403840 _____ (Farbar) C:\Users\rossu\Desktop\FRST64 (1).exe
2024-12-21 13:44 - 2024-08-28 19:48 - 001718036 _____ C:\Windows\system32\PerfStringBackup.INI
2024-12-21 13:44 - 2022-05-07 06:22 - 000000000 ____D C:\Windows\INF
2024-12-21 13:43 - 2024-08-29 18:10 - 000000000 ____D C:\Users\rossu\AppData\Roaming\qBittorrent
2024-12-21 13:39 - 2024-08-28 19:55 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2024-12-21 13:39 - 2024-08-28 19:55 - 000000000 __SHD C:\Users\rossu\IntelGraphicsProfiles
2024-12-21 13:39 - 2024-08-28 19:29 - 000012288 ___SH C:\DumpStack.log.tmp
2024-12-21 13:39 - 2024-08-28 19:29 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-12-21 13:38 - 2022-05-07 06:17 - 000786432 _____ C:\Windows\system32\config\BBI
2024-12-21 12:51 - 2024-08-28 19:29 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-12-21 12:50 - 2024-08-28 19:41 - 000000000 ___SD C:\Users\rossu\AppData\Roaming\Microsoft\Credentials
2024-12-21 09:14 - 2024-08-28 19:30 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-12-21 09:14 - 2024-08-28 19:30 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-12-20 18:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\AppReadiness
2024-12-20 17:50 - 2022-05-07 06:24 - 000000000 ___HD C:\Program Files\WindowsApps
2024-12-20 17:43 - 2024-08-28 19:30 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-12-19 19:00 - 2024-09-02 16:11 - 000000000 ____D C:\Users\rossu\AppData\Local\CrashDumps
2024-12-19 18:14 - 2024-10-18 18:34 - 000001382 _____ C:\Users\rossu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2024-12-19 18:14 - 2024-10-18 18:34 - 000001276 _____ C:\Users\rossu\Desktop\ESET Online Scanner.lnk
2024-12-17 21:21 - 2024-08-28 19:41 - 000000000 ____D C:\Users\rossu\AppData\Local\Packages
2024-12-15 22:21 - 2024-08-28 19:41 - 000000000 ____D C:\Users\rossu
2024-12-15 10:38 - 2024-08-28 19:29 - 000446528 _____ C:\Windows\system32\FNTCACHE.DAT
2024-12-15 10:37 - 2023-10-01 08:01 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SystemResources
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\Sgrm
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\setup
2024-12-15 10:37 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\bcastdvr
2024-12-11 20:18 - 2022-05-07 06:17 - 000000000 ____D C:\Windows\CbsTemp
2024-12-11 19:29 - 2024-08-29 18:09 - 000002048 _____ C:\Users\rossu\Desktop\Google Drive.lnk
2024-12-09 23:21 - 2024-08-28 19:43 - 000000000 ____D C:\Users\rossu\AppData\Local\D3DSCache
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ___SD C:\Windows\system32\UNP
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\ShellExperiences
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\oobe
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\Dism
2024-11-29 22:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\appraiser
2024-11-29 22:25 - 2022-05-07 06:24 - 000000000 ___RD C:\Windows\PrintDialog
2024-11-29 22:25 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\ShellExperiences
2024-11-29 22:25 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\ShellComponents
2024-11-29 20:07 - 2022-05-07 06:25 - 000077312 _____ (Khronos Group) C:\Windows\SysWOW64\opencl.dll
2024-11-29 20:07 - 2022-05-07 06:24 - 000118784 _____ (Khronos Group) C:\Windows\system32\opencl.dll
2024-11-29 20:00 - 2024-08-28 19:31 - 003212800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-11-25 19:38 - 2024-10-07 15:28 - 000000000 ____D C:\Users\rossu\AppData\Roaming\Microsoft\MMC
2024-11-23 21:23 - 2024-11-04 18:37 - 000000000 ____D C:\Users\rossu\AppData\Roaming\USBSafelyRemove
2024-11-23 20:44 - 2024-11-02 18:04 - 000000972 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2024-11-23 18:43 - 2024-09-02 15:26 - 000000000 ____D C:\Users\rossu\AppData\Local\VirtualStore
2024-11-23 17:52 - 2024-11-02 18:04 - 000003320 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2024-11-23 17:52 - 2024-11-02 17:21 - 000002840 _____ C:\Windows\system32\Tasks\Driver Booster SkipUAC (rossu)
==================== Files in the root of some directories ========
2024-09-08 13:28 - 2024-09-08 13:28 - 000004097 _____ () C:\Users\rossu\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================