Trojský kůň
Napsal: 06 říj 2025 17:26
Prosím o kontrolu logu,,Chrom se chová podezřele,,dekuji
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by PC (05-10-2025 10:25:22)
Running from C:\Users\PC\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) (2025-08-28 17:07:31)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-3053447137-874728891-481791925-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3053447137-874728891-481791925-503 - Limited - Disabled)
Guest (S-1-5-21-3053447137-874728891-481791925-501 - Limited - Disabled)
PC (S-1-5-21-3053447137-874728891-481791925-1001 - Administrator - Enabled) => C:\Users\PC
WDAGUtilityAccount (S-1-5-21-3053447137-874728891-481791925-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.134 - Advanced Micro Devices, Inc.) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.)
AMD Interface Driver (HKLM-x32\...\{6118E908-9B3B-4258-B7C2-7DEEA5A65A85}) (Version: 2.0.0.23 - Advanced Micro Devices, Inc.) Hidden
AMD PPM Provisioning File Driver (HKLM-x32\...\{3665A5DE-D07C-46D7-9207-713E8E9FEF32}) (Version: 8.0.0.53 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.39.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{43ab2cfd-3f71-4aa8-ab15-5f517f620c41}) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.) Hidden
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 25.9.10453.3120 - Gen Digital Inc.)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 139.0.31974.157 - Autoři prohlížeče Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1995.6 - AVAST Software) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 141.0.7390.55 - Google LLC)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.57 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 140.0.3485.94 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\OneDriveSetup.exe) (Version: 25.174.0907.0003 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30156 (HKLM-x32\...\{692e16a0-c886-466d-91db-706f6f99ac96}) (Version: 14.29.30156.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33130 (HKLM-x32\...\{1de5e707-82da-4db6-b810-5d140cc4cbb3}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.29.30156 (HKLM-x32\...\{7ACE9888-9B5B-4041-90BA-6A5B470B21EB}) (Version: 14.29.30156 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.29.30156 (HKLM-x32\...\{1F91919D-04A6-4A8C-8B81-FAF84FDB93F0}) (Version: 14.29.30156 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33130 (HKLM\...\{C31777DB-51C1-4B19-9F80-38EF5C1D7C89}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33130 (HKLM\...\{1CA7421F-A225-4A9C-B320-A36981A2B789}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
NVIDIA Ovladače grafiky 560.94 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 560.94 - NVIDIA Corporation)
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.3.0 - Advanced Micro Devices, Inc.) Hidden
Roblox Player for PC (HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\roblox-player) (Version: - Roblox Corporation)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.968.0_x64__56jybvy8sckqj [2025-08-28] (NVIDIA Corp.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3053447137-874728891-481791925-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3053447137-874728891-481791925-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\nvshext.dll [2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 10.0.0.138
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rtcx21x64.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\PC\Pictures\Screenshots\Snímek obrazovky 2025-10-02 203821.png
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{BDC1B6F5-EB9B-438C-8D56-985A6B88EE8B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{BDCFA21E-0154-439F-8401-B3947F08914D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{EEBE1BF4-DF4B-433E-B7E2-93BACCA2ECA1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{7260B144-B5CB-4C79-8B81-FA8F64AB527C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F255DC24-3073-45EB-A8DC-348031DBEDA9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{CF73E0BD-78F3-408C-9513-00F8EA79F749}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Farming Simulator 25\FarmingSimulator2025.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{86F9A3D3-67D0-4AB9-BF82-02062EE1CF83}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Farming Simulator 25\FarmingSimulator2025.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [TCP Query User{75C765CD-3703-4729-B77B-29149E0F13FD}C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [UDP Query User{F2ED1DAA-DD37-4C08-B69B-E3B5EABD54BA}C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{FC065558-7A43-4A8E-BB46-F39A9CF383C8}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{7158B5D4-BE2F-4657-A572-2EBE0A3C3EC4}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{C9EF0C0F-02F1-47E1-8071-1DB75F764385}] => (Allow) C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)
==================== Restore Points =========================
02-10-2025 20:27:11 Windows Update
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/05/2025 10:11:30 AM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/05/2025 10:11:30 AM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/05/2025 10:11:29 AM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/03/2025 12:29:42 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-QMA3SMA$ přes https://AMD-KeyId-46b5830189da66c5bd44f ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(828ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/03/2025 12:29:42 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/03/2025 12:29:11 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-QMA3SMA$ přes https://AMD-KeyId-46b5830189da66c5bd44f ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(735ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/03/2025 12:29:11 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/02/2025 06:22:14 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-QMA3SMA$ přes https://AMD-KeyId-46b5830189da66c5bd44f ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(297ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
System errors:
=============
Error: (10/05/2025 10:16:20 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
Error: (10/05/2025 10:16:20 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
Error: (10/05/2025 10:10:52 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 10:10:52 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:50:10 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:50:10 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:37:59 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:37:59 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Windows Defender:
================
Date: 2025-10-05 10:00:05
Description:
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win64/Malgent!MSR
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\PC\Downloads\FRST64.exe; webfile:_C:\Users\PC\Downloads\FRST64.exe|https://download.bleepingcomputer.com/d ... 8041126414
Původ detekce: Internet
Typ detekce: Konkrétní
Zdroj detekce: Soubory ke stažení a přílohy
Uživatel: DESKTOP-QMA3SMA\PC
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.437.333.0, AS: 1.437.333.0, NIS: 1.437.333.0
Verze modulu: AM: 1.1.25080.5, NIS: 1.1.25080.5
Date: 2025-10-02 21:04:30
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{B9480995-C066-43EC-89E3-C2A439AEB553}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
Date: 2025-10-02 20:57:24
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{3D4CF8D2-D326-4475-8EE5-F1214BAB7D6C}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
Date: 2025-10-02 20:27:03
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{53D0FC81-9988-41EF-9DB8-9041CFEC0D0A}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
Date: 2025-10-02 20:02:31
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{B0A45BA8-9A78-43C8-A3FF-92CB60CE131B}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
CodeIntegrity:
===============
Date: 2025-08-28 19:42:01
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\fcon.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
BIOS: American Megatrends Inc. 3283 09/16/2025
Motherboard: ASUSTeK COMPUTER INC. PRIME A620M-K
Processor: AMD Ryzen 5 8400F 6-Core Processor
Percentage of memory in use: 28%
Total physical RAM: 32426.56 MB
Available physical RAM: 23167.15 MB
Total Virtual: 34474.56 MB
Available Virtual: 24219.39 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.68 GB) (Free:768.04 GB) (Model: ADATA LEGEND 860) NTFS
\\?\Volume{b9a9ad53-a709-49d4-85a0-0aa4bdf791c8}\ () (Fixed) (Total:0.71 GB) (Free:0.11 GB) NTFS
\\?\Volume{c60cd929-29e3-44e3-9937-7bb38f7fff8e}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-10-2025
Ran by PC (administrator) on DESKTOP-QMA3SMA (ASUS System Product Name) (05-10-2025 10:24:42)
Running from C:\Users\PC\Downloads\FRST64 (16).exe
Loaded Profiles: PC
Platform: Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <11>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2507.26.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe <3>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2509.58021.0_x64__8wekyb3d8bbwe\WebViewHost.exe
(services.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc) C:\Windows\System32\DriverStore\FileRepository\amdppkg.inf_amd64_2e5ec3779d1804d1\AmdPpkgSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Copilot_1.25093.144.0_x64__8wekyb3d8bbwe\Copilot.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.140.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [845992 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\Run: [MicrosoftEdgeAutoLaunch_B47356396DDD0FAAE76D0ED141F5CEA2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4699288 2025-10-03] (Valve Corp. -> Valve Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\141.0.7390.55\Installer\chrmstp.exe [2025-10-02] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files\AVAST Software\Browser\Application\139.0.31974.157\Installer\chrmstp.exe [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {13AF7A56-B8F1-4E2A-A369-473C9DA97D6B} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3595344 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {5A633AEF-1F8C-4BE3-82F9-D05C35D57DC4} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3595344 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {AAB6C386-D5D8-4898-BCAC-33966CC64CB2} - System32\Tasks\Avast Secure Browser VPS Differential Update S-1-5-21-3053447137-874728891-481791925-1001 => C:\Program Files\AVAST Software\Browser\Application\vps_helper.exe [1676528 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9622AC2C-0F2B-4895-8E92-FAEC3850E647} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [9072352 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3E87C89A-E336-49D8-9876-67CF65EE4C68} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5573800 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {7947FEEB-0420-42DA-8E0E-F04FB4283913} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2977504 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {EDEC4B34-EE4C-48FC-8B80-EE82DAAF9535} - System32\Tasks\AvastBrowserProtectS-1-5-21-3053447137-874728891-481791925-1001 => C:\Program Files\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1762528 2025-09-11] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B4FF09C8-1701-4D32-BCFB-359DBD99B381} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {51E988FC-C5FC-4BB3-B6AF-8AE576BFFEA4} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {24EEF767-F9C7-4884-94C4-6DCB77727E65} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem142.0.7416.0{7D85734A-DAB9-4C75-A45C-9A85C23F00E6} => C:\Program Files (x86)\Google\GoogleUpdater\142.0.7416.0\updater.exe [5990040 2025-09-15] (Google LLC -> Google LLC)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {0A783215-9178-4653-9811-29EAF5A53009} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3053447137-874728891-481791925-1001 => C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDriveLauncher.exe [725880 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{2ea00ea2-a579-4732-ab07-b6e083b0a8d7}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{2ea00ea2-a579-4732-ab07-b6e083b0a8d7}: [DhcpDomain] Home
Tcpip\..\Interfaces\{bf99dcd4-db10-4d83-ab95-6f9a4e8c7b17}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{bf99dcd4-db10-4d83-ab95-6f9a4e8c7b17}: [DhcpDomain] home
Edge:
=======
Edge Profile: C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-10-01]
Edge Extension: (Edge relevant text changes) - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-08-28]
FireFox:
========
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1995.6\npAvastBrowserUpdate3.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1995.6\npAvastBrowserUpdate3.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default [2025-10-05]
CHR Notifications: Default -> hxxps://ngemqi.subericanthiled.com; hxxps://www.youtube.com
CHR Extension: (Dokumenty Google offline) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-10-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-10-02]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AmdPpkgSvc; C:\WINDOWS\System32\DriverStore\FileRepository\amdppkg.inf_amd64_2e5ec3779d1804d1\AmdPpkgSvc.exe [518984 2025-05-15] (Advanced Micro Devices -> Advanced Micro Devices, Inc)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [884568 2025-10-05] (ASUSTeK COMPUTER INC. -> )
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7785640 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [1036456 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2598568 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1089704 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
S3 AvastSecureBrowserElevationService; C:\Program Files\AVAST Software\Browser\Application\139.0.31974.157\elevation_service.exe [2436304 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2025-10-05] (Avast Software s.r.o. -> AVAST Software)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe [2009656 2025-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe [1275000 2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-08-28] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\NisSrv.exe [4414464 2025-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe [282480 2025-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33592 2024-09-12] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 AmdPpkg; C:\WINDOWS\System32\DriverStore\FileRepository\amdppkg.inf_amd64_2e5ec3779d1804d1\AmdPpkg.sys [35120 2025-05-15] (Advanced Micro Devices -> Advanced Micro Devices)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [21088 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [244832 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [390752 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [299616 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [85600 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [29144 2025-10-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [29792 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [284768 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [574048 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [92232 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [71240 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [876104 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1282632 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [201824 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [391776 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [200704 2024-10-05] (Microsoft Corporation) [File not signed]
S3 HWiNFO_204; C:\Users\PC\AppData\Local\Temp\HWiNFO_x64_204.sys [58024 2025-10-01] (Microsoft Windows Hardware Compatibility Publisher -> REALiX) <==== ATTENTION
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333216 2025-10-01] (Microsoft Windows -> Microsoft Corporation)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [12435144 2024-10-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20880 2025-10-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [627104 2025-10-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102816 2025-10-01] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsl7fc46a12; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3FBA9E4F-9BD8-480E-A08A-1F425B5ECC5C}\MpKslDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-05 10:18 - 2025-10-05 10:18 - 000677108 _____ C:\WINDOWS\system32\perfh005.dat
2025-10-05 10:18 - 2025-10-05 10:18 - 000144960 _____ C:\WINDOWS\system32\perfc005.dat
2025-10-05 10:17 - 2025-10-05 10:24 - 000020126 _____ C:\Users\PC\Downloads\Addition.txt
2025-10-05 10:16 - 2025-10-05 10:24 - 000017402 _____ C:\Users\PC\Downloads\FRST.txt
2025-10-05 10:16 - 2025-10-05 10:24 - 000000000 ____D C:\FRST
2025-10-05 10:01 - 2025-10-05 10:01 - 002442752 _____ (Farbar) C:\Users\PC\Downloads\FRST64 (16).exe
2025-10-05 09:59 - 2025-10-05 10:00 - 002442752 _____ (Farbar) C:\Users\PC\Downloads\FRST64.exe
2025-10-05 08:49 - 2025-10-05 08:49 - 000002516 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2025-10-05 08:49 - 2025-10-05 08:49 - 000002481 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2025-10-05 08:49 - 2025-10-05 08:49 - 000000000 ____D C:\Users\PC\AppData\Roaming\Avast Software
2025-10-05 08:47 - 2025-10-05 08:51 - 000000000 ____D C:\Users\PC\AppData\Local\AVAST Software
2025-10-05 08:47 - 2025-10-05 08:47 - 000003844 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2025-10-05 08:47 - 2025-10-05 08:47 - 000003796 _____ C:\WINDOWS\system32\Tasks\AvastBrowserProtectS-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:47 - 2025-10-05 08:47 - 000003716 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser VPS Differential Update S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:47 - 2025-10-05 08:47 - 000003260 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2025-10-05 08:33 - 2025-10-05 08:33 - 000003510 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineUA
2025-10-05 08:33 - 2025-10-05 08:33 - 000003386 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineCore
2025-10-05 08:33 - 2025-10-05 08:33 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2025-10-05 08:32 - 2025-10-05 08:32 - 000002202 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2025-10-05 08:32 - 2025-10-05 08:32 - 000002190 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2025-10-05 08:31 - 2025-10-05 08:49 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-10-05 08:31 - 2025-10-05 08:01 - 000322216 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2025-10-05 08:21 - 2025-10-05 08:21 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-10-05 07:52 - 2025-10-05 08:47 - 000000000 ____D C:\Program Files\Avast Software
2025-10-05 07:52 - 2025-10-05 07:52 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-10-05 07:52 - 2025-10-05 07:51 - 000056128 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2025-10-05 07:49 - 2025-10-05 10:11 - 000000000 ____D C:\ProgramData\Avast Software
2025-10-05 07:49 - 2025-10-05 07:49 - 000249080 _____ (Gen Digital Inc.) C:\Users\PC\Downloads\online_instalační_soubor_aplikace_avast_free_antivirus.exe
2025-10-03 16:04 - 2025-10-03 16:04 - 000000219 _____ C:\Users\PC\Desktop\Counter-Strike 2.url
2025-10-03 16:00 - 2025-10-03 16:00 - 000004032 _____ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-3053447137-874728891-481791925-1001_0
2025-10-03 12:33 - 2025-10-03 12:33 - 000000000 ____D C:\Users\PC\AppData\Local\GIANTS Crash Reporter
2025-10-03 12:29 - 2025-10-03 12:29 - 000000000 ____D C:\Users\PC\AppData\Local\Backup
2025-10-02 19:13 - 2025-10-02 19:13 - 018669136 _____ (Martin Malik, REALiX s.r.o. ) C:\Users\PC\Downloads\hwi64_830.exe
2025-10-02 19:09 - 2025-10-02 19:09 - 000000000 ____D C:\Users\PC\Documents\FrameView
2025-10-02 19:08 - 2025-10-02 19:08 - 011969248 _____ (NVIDIA Corporation) C:\Users\PC\Downloads\FrameViewSetup.exe
2025-10-02 19:03 - 2025-10-02 19:03 - 000000000 ____D C:\Users\PC\Documents\My Games
2025-10-02 19:02 - 2025-10-03 16:04 - 000000000 ____D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-10-02 19:02 - 2025-10-02 19:02 - 000000223 _____ C:\Users\PC\Desktop\Farming Simulator 25.url
2025-10-02 18:56 - 2025-10-02 18:56 - 000000000 ____D C:\Users\PC\AppData\Local\CEF
2025-10-02 18:55 - 2025-10-02 19:01 - 000000000 ____D C:\Users\PC\AppData\Local\Steam
2025-10-02 18:54 - 2025-10-05 10:25 - 000000000 ____D C:\Program Files (x86)\Steam
2025-10-02 18:54 - 2025-10-02 18:54 - 002380800 _____ C:\Users\PC\Downloads\SteamSetup.exe
2025-10-02 18:54 - 2025-10-02 18:54 - 000001032 _____ C:\Users\Public\Desktop\Steam.lnk
2025-10-02 18:54 - 2025-10-02 18:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2025-10-02 18:53 - 2025-10-02 18:53 - 000000000 ____D C:\Users\PC\AppData\Local\OneDrive
2025-10-02 18:30 - 2025-10-02 18:30 - 000001388 _____ C:\Users\PC\Desktop\Roblox Player.lnk
2025-10-02 18:29 - 2025-10-03 16:19 - 000000000 ____D C:\Users\PC\AppData\Local\Roblox
2025-10-02 18:29 - 2025-10-02 18:30 - 000000000 ____D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2025-10-02 18:29 - 2025-10-02 18:29 - 008278480 _____ (Roblox Corporation) C:\Users\PC\Downloads\RobloxPlayerInstaller.exe
2025-10-02 18:27 - 2025-10-02 18:27 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-10-02 18:27 - 2025-10-02 18:27 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-10-02 18:27 - 2025-10-02 18:27 - 000000000 ____D C:\Users\PC\AppData\Local\Google
2025-10-02 18:27 - 2025-10-02 18:27 - 000000000 ____D C:\Program Files\Google
2025-10-02 18:26 - 2025-10-02 18:26 - 010869176 _____ (Google LLC) C:\Users\PC\Downloads\ChromeSetup.exe
2025-10-02 18:26 - 2025-10-02 18:26 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-10-02 18:26 - 2025-10-02 18:26 - 000000000 ____D C:\Program Files (x86)\Google
2025-10-01 22:27 - 2025-10-01 22:27 - 000000000 ____D C:\Users\PC\AppData\Local\PeerDistRepub
2025-10-01 22:00 - 2025-10-01 22:00 - 000077233 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-10-01 22:00 - 2025-10-01 22:00 - 000077233 _____ C:\WINDOWS\system32\ctac.json
2025-10-01 22:00 - 2025-10-01 22:00 - 000001681 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-10-01 21:28 - 2025-10-01 21:28 - 000000000 ____D C:\Users\PC\AppData\Roaming\NVIDIA
2025-10-01 21:28 - 2025-10-01 21:28 - 000000000 ____D C:\Users\PC\AppData\Local\NVIDIA
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-05 10:21 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-05 10:18 - 2025-08-28 19:11 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-10-05 10:18 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-10-05 10:11 - 2025-08-28 20:02 - 000000000 ____D C:\ProgramData\NVIDIA
2025-10-05 10:11 - 2025-08-28 19:39 - 000001898 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-10-05 10:11 - 2025-08-28 19:05 - 000945760 _____ () C:\WINDOWS\system32\wpbbin.exe
2025-10-05 10:11 - 2025-08-28 19:05 - 000884568 _____ C:\WINDOWS\system32\AsusUpdateCheck.exe
2025-10-05 10:11 - 2025-08-28 19:05 - 000012288 ___SH C:\DumpStack.log.tmp
2025-10-05 10:11 - 2025-08-28 19:05 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2025-10-05 10:11 - 2025-08-28 19:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-05 10:11 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-05 10:11 - 2024-04-01 09:21 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2025-10-05 10:08 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC\AppData\Local\Packages
2025-10-05 08:51 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC\AppData\Local\D3DSCache
2025-10-05 08:39 - 2025-08-28 19:05 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-05 08:31 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-10-05 08:14 - 2025-08-28 19:40 - 000003558 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:14 - 2025-08-28 19:39 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:14 - 2025-08-28 19:39 - 000003370 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:14 - 2025-08-28 19:39 - 000002370 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-10-04 18:34 - 2025-08-28 19:06 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-10-04 18:34 - 2025-08-28 19:06 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-10-04 12:51 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-04 12:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-03 12:45 - 2025-08-28 19:07 - 000000000 ____D C:\ProgramData\Packages
2025-10-03 12:29 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC\AppData\Local\ConnectedDevicesPlatform
2025-10-02 21:10 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC
2025-10-02 20:42 - 2025-08-28 19:39 - 000000000 ____D C:\Users\PC\AppData\Local\PlaceholderTileLogoFolder
2025-10-02 20:22 - 2025-08-28 20:02 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-10-02 19:27 - 2025-08-28 19:37 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-10-02 19:11 - 2025-08-28 20:02 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-10-01 22:28 - 2025-08-28 19:05 - 000297176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-10-01 22:27 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-10-01 22:27 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-10-01 22:27 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-10-01 22:27 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-10-01 22:25 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-10-01 22:25 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2025-10-01 22:00 - 2025-08-28 19:09 - 003270656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-10-01 21:38 - 2025-08-28 19:05 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-10-01 21:27 - 2025-08-28 19:05 - 000003716 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{E0B78D81-D492-4F53-A483-25257F0EEC2E}
2025-10-01 21:27 - 2025-08-28 19:05 - 000003590 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{31240395-7FA8-4E35-B6FC-B8A922D2FF2E}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
==================== End of Addition.txt =======================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by PC (05-10-2025 10:25:22)
Running from C:\Users\PC\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) (2025-08-28 17:07:31)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-3053447137-874728891-481791925-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3053447137-874728891-481791925-503 - Limited - Disabled)
Guest (S-1-5-21-3053447137-874728891-481791925-501 - Limited - Disabled)
PC (S-1-5-21-3053447137-874728891-481791925-1001 - Administrator - Enabled) => C:\Users\PC
WDAGUtilityAccount (S-1-5-21-3053447137-874728891-481791925-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.134 - Advanced Micro Devices, Inc.) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.)
AMD Interface Driver (HKLM-x32\...\{6118E908-9B3B-4258-B7C2-7DEEA5A65A85}) (Version: 2.0.0.23 - Advanced Micro Devices, Inc.) Hidden
AMD PPM Provisioning File Driver (HKLM-x32\...\{3665A5DE-D07C-46D7-9207-713E8E9FEF32}) (Version: 8.0.0.53 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.39.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{43ab2cfd-3f71-4aa8-ab15-5f517f620c41}) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.) Hidden
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 25.9.10453.3120 - Gen Digital Inc.)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 139.0.31974.157 - Autoři prohlížeče Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1995.6 - AVAST Software) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 141.0.7390.55 - Google LLC)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.57 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 140.0.3485.94 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\OneDriveSetup.exe) (Version: 25.174.0907.0003 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30156 (HKLM-x32\...\{692e16a0-c886-466d-91db-706f6f99ac96}) (Version: 14.29.30156.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33130 (HKLM-x32\...\{1de5e707-82da-4db6-b810-5d140cc4cbb3}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.29.30156 (HKLM-x32\...\{7ACE9888-9B5B-4041-90BA-6A5B470B21EB}) (Version: 14.29.30156 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.29.30156 (HKLM-x32\...\{1F91919D-04A6-4A8C-8B81-FAF84FDB93F0}) (Version: 14.29.30156 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33130 (HKLM\...\{C31777DB-51C1-4B19-9F80-38EF5C1D7C89}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33130 (HKLM\...\{1CA7421F-A225-4A9C-B320-A36981A2B789}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
NVIDIA Ovladače grafiky 560.94 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 560.94 - NVIDIA Corporation)
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.3.0 - Advanced Micro Devices, Inc.) Hidden
Roblox Player for PC (HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\roblox-player) (Version: - Roblox Corporation)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.968.0_x64__56jybvy8sckqj [2025-08-28] (NVIDIA Corp.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3053447137-874728891-481791925-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3053447137-874728891-481791925-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\nvshext.dll [2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 10.0.0.138
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rtcx21x64.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\PC\Pictures\Screenshots\Snímek obrazovky 2025-10-02 203821.png
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{BDC1B6F5-EB9B-438C-8D56-985A6B88EE8B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{BDCFA21E-0154-439F-8401-B3947F08914D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{EEBE1BF4-DF4B-433E-B7E2-93BACCA2ECA1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{7260B144-B5CB-4C79-8B81-FA8F64AB527C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F255DC24-3073-45EB-A8DC-348031DBEDA9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{CF73E0BD-78F3-408C-9513-00F8EA79F749}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Farming Simulator 25\FarmingSimulator2025.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{86F9A3D3-67D0-4AB9-BF82-02062EE1CF83}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Farming Simulator 25\FarmingSimulator2025.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [TCP Query User{75C765CD-3703-4729-B77B-29149E0F13FD}C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [UDP Query User{F2ED1DAA-DD37-4C08-B69B-E3B5EABD54BA}C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\farming simulator 25\x64\farmingsimulator2025game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{FC065558-7A43-4A8E-BB46-F39A9CF383C8}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{7158B5D4-BE2F-4657-A572-2EBE0A3C3EC4}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{C9EF0C0F-02F1-47E1-8071-1DB75F764385}] => (Allow) C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)
==================== Restore Points =========================
02-10-2025 20:27:11 Windows Update
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/05/2025 10:11:30 AM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/05/2025 10:11:30 AM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/05/2025 10:11:29 AM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/03/2025 12:29:42 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-QMA3SMA$ přes https://AMD-KeyId-46b5830189da66c5bd44f ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(828ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/03/2025 12:29:42 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/03/2025 12:29:11 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-QMA3SMA$ přes https://AMD-KeyId-46b5830189da66c5bd44f ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(735ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/03/2025 12:29:11 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: Zprostředkovatel Microsoft Pluton Cryptographic Provider nebyl načten, protože se nezdařila inicializace.
Error: (10/02/2025 06:22:14 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-QMA3SMA$ přes https://AMD-KeyId-46b5830189da66c5bd44f ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(297ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
System errors:
=============
Error: (10/05/2025 10:16:20 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
Error: (10/05/2025 10:16:20 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
Error: (10/05/2025 10:10:52 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 10:10:52 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:50:10 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:50:10 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:37:59 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (10/05/2025 09:37:59 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMA3SMA)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Windows Defender:
================
Date: 2025-10-05 10:00:05
Description:
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win64/Malgent!MSR
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\PC\Downloads\FRST64.exe; webfile:_C:\Users\PC\Downloads\FRST64.exe|https://download.bleepingcomputer.com/d ... 8041126414
Původ detekce: Internet
Typ detekce: Konkrétní
Zdroj detekce: Soubory ke stažení a přílohy
Uživatel: DESKTOP-QMA3SMA\PC
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.437.333.0, AS: 1.437.333.0, NIS: 1.437.333.0
Verze modulu: AM: 1.1.25080.5, NIS: 1.1.25080.5
Date: 2025-10-02 21:04:30
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{B9480995-C066-43EC-89E3-C2A439AEB553}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
Date: 2025-10-02 20:57:24
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{3D4CF8D2-D326-4475-8EE5-F1214BAB7D6C}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
Date: 2025-10-02 20:27:03
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{53D0FC81-9988-41EF-9DB8-9041CFEC0D0A}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
Date: 2025-10-02 20:02:31
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{B0A45BA8-9A78-43C8-A3FF-92CB60CE131B}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
CodeIntegrity:
===============
Date: 2025-08-28 19:42:01
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\fcon.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
BIOS: American Megatrends Inc. 3283 09/16/2025
Motherboard: ASUSTeK COMPUTER INC. PRIME A620M-K
Processor: AMD Ryzen 5 8400F 6-Core Processor
Percentage of memory in use: 28%
Total physical RAM: 32426.56 MB
Available physical RAM: 23167.15 MB
Total Virtual: 34474.56 MB
Available Virtual: 24219.39 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.68 GB) (Free:768.04 GB) (Model: ADATA LEGEND 860) NTFS
\\?\Volume{b9a9ad53-a709-49d4-85a0-0aa4bdf791c8}\ () (Fixed) (Total:0.71 GB) (Free:0.11 GB) NTFS
\\?\Volume{c60cd929-29e3-44e3-9937-7bb38f7fff8e}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-10-2025
Ran by PC (administrator) on DESKTOP-QMA3SMA (ASUS System Product Name) (05-10-2025 10:24:42)
Running from C:\Users\PC\Downloads\FRST64 (16).exe
Loaded Profiles: PC
Platform: Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <11>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2507.26.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe <3>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2509.58021.0_x64__8wekyb3d8bbwe\WebViewHost.exe
(services.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc) C:\Windows\System32\DriverStore\FileRepository\amdppkg.inf_amd64_2e5ec3779d1804d1\AmdPpkgSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Copilot_1.25093.144.0_x64__8wekyb3d8bbwe\Copilot.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.140.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [845992 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\Run: [MicrosoftEdgeAutoLaunch_B47356396DDD0FAAE76D0ED141F5CEA2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3053447137-874728891-481791925-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4699288 2025-10-03] (Valve Corp. -> Valve Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\141.0.7390.55\Installer\chrmstp.exe [2025-10-02] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files\AVAST Software\Browser\Application\139.0.31974.157\Installer\chrmstp.exe [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {13AF7A56-B8F1-4E2A-A369-473C9DA97D6B} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3595344 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {5A633AEF-1F8C-4BE3-82F9-D05C35D57DC4} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe [3595344 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {AAB6C386-D5D8-4898-BCAC-33966CC64CB2} - System32\Tasks\Avast Secure Browser VPS Differential Update S-1-5-21-3053447137-874728891-481791925-1001 => C:\Program Files\AVAST Software\Browser\Application\vps_helper.exe [1676528 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9622AC2C-0F2B-4895-8E92-FAEC3850E647} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [9072352 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3E87C89A-E336-49D8-9876-67CF65EE4C68} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5573800 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {7947FEEB-0420-42DA-8E0E-F04FB4283913} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2977504 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {EDEC4B34-EE4C-48FC-8B80-EE82DAAF9535} - System32\Tasks\AvastBrowserProtectS-1-5-21-3053447137-874728891-481791925-1001 => C:\Program Files\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1762528 2025-09-11] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B4FF09C8-1701-4D32-BCFB-359DBD99B381} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {51E988FC-C5FC-4BB3-B6AF-8AE576BFFEA4} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {24EEF767-F9C7-4884-94C4-6DCB77727E65} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem142.0.7416.0{7D85734A-DAB9-4C75-A45C-9A85C23F00E6} => C:\Program Files (x86)\Google\GoogleUpdater\142.0.7416.0\updater.exe [5990040 2025-09-15] (Google LLC -> Google LLC)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {0A783215-9178-4653-9811-29EAF5A53009} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3053447137-874728891-481791925-1001 => C:\Users\PC\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDriveLauncher.exe [725880 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{2ea00ea2-a579-4732-ab07-b6e083b0a8d7}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{2ea00ea2-a579-4732-ab07-b6e083b0a8d7}: [DhcpDomain] Home
Tcpip\..\Interfaces\{bf99dcd4-db10-4d83-ab95-6f9a4e8c7b17}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{bf99dcd4-db10-4d83-ab95-6f9a4e8c7b17}: [DhcpDomain] home
Edge:
=======
Edge Profile: C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-10-01]
Edge Extension: (Edge relevant text changes) - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-08-28]
FireFox:
========
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1995.6\npAvastBrowserUpdate3.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1995.6\npAvastBrowserUpdate3.dll [2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default [2025-10-05]
CHR Notifications: Default -> hxxps://ngemqi.subericanthiled.com; hxxps://www.youtube.com
CHR Extension: (Dokumenty Google offline) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-10-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-10-02]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AmdPpkgSvc; C:\WINDOWS\System32\DriverStore\FileRepository\amdppkg.inf_amd64_2e5ec3779d1804d1\AmdPpkgSvc.exe [518984 2025-05-15] (Advanced Micro Devices -> Advanced Micro Devices, Inc)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [884568 2025-10-05] (ASUSTeK COMPUTER INC. -> )
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7785640 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [1036456 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2598568 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1089704 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194016 2025-10-05] (Gen Digital Inc. -> Gen Digital Inc.)
S3 AvastSecureBrowserElevationService; C:\Program Files\AVAST Software\Browser\Application\139.0.31974.157\elevation_service.exe [2436304 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2025-10-05] (Avast Software s.r.o. -> AVAST Software)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe [2009656 2025-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe [1275000 2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-08-28] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\NisSrv.exe [4414464 2025-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe [282480 2025-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33592 2024-09-12] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 AmdPpkg; C:\WINDOWS\System32\DriverStore\FileRepository\amdppkg.inf_amd64_2e5ec3779d1804d1\AmdPpkg.sys [35120 2025-05-15] (Advanced Micro Devices -> Advanced Micro Devices)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [21088 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [244832 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [390752 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [299616 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [85600 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [29144 2025-10-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [29792 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [284768 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [574048 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [92232 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [71240 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [876104 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1282632 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [201824 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [391776 2025-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [200704 2024-10-05] (Microsoft Corporation) [File not signed]
S3 HWiNFO_204; C:\Users\PC\AppData\Local\Temp\HWiNFO_x64_204.sys [58024 2025-10-01] (Microsoft Windows Hardware Compatibility Publisher -> REALiX) <==== ATTENTION
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333216 2025-10-01] (Microsoft Windows -> Microsoft Corporation)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [12435144 2024-10-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20880 2025-10-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [627104 2025-10-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102816 2025-10-01] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsl7fc46a12; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3FBA9E4F-9BD8-480E-A08A-1F425B5ECC5C}\MpKslDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-05 10:18 - 2025-10-05 10:18 - 000677108 _____ C:\WINDOWS\system32\perfh005.dat
2025-10-05 10:18 - 2025-10-05 10:18 - 000144960 _____ C:\WINDOWS\system32\perfc005.dat
2025-10-05 10:17 - 2025-10-05 10:24 - 000020126 _____ C:\Users\PC\Downloads\Addition.txt
2025-10-05 10:16 - 2025-10-05 10:24 - 000017402 _____ C:\Users\PC\Downloads\FRST.txt
2025-10-05 10:16 - 2025-10-05 10:24 - 000000000 ____D C:\FRST
2025-10-05 10:01 - 2025-10-05 10:01 - 002442752 _____ (Farbar) C:\Users\PC\Downloads\FRST64 (16).exe
2025-10-05 09:59 - 2025-10-05 10:00 - 002442752 _____ (Farbar) C:\Users\PC\Downloads\FRST64.exe
2025-10-05 08:49 - 2025-10-05 08:49 - 000002516 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2025-10-05 08:49 - 2025-10-05 08:49 - 000002481 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2025-10-05 08:49 - 2025-10-05 08:49 - 000000000 ____D C:\Users\PC\AppData\Roaming\Avast Software
2025-10-05 08:47 - 2025-10-05 08:51 - 000000000 ____D C:\Users\PC\AppData\Local\AVAST Software
2025-10-05 08:47 - 2025-10-05 08:47 - 000003844 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2025-10-05 08:47 - 2025-10-05 08:47 - 000003796 _____ C:\WINDOWS\system32\Tasks\AvastBrowserProtectS-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:47 - 2025-10-05 08:47 - 000003716 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser VPS Differential Update S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:47 - 2025-10-05 08:47 - 000003260 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2025-10-05 08:33 - 2025-10-05 08:33 - 000003510 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineUA
2025-10-05 08:33 - 2025-10-05 08:33 - 000003386 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineCore
2025-10-05 08:33 - 2025-10-05 08:33 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2025-10-05 08:32 - 2025-10-05 08:32 - 000002202 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2025-10-05 08:32 - 2025-10-05 08:32 - 000002190 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2025-10-05 08:31 - 2025-10-05 08:49 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-10-05 08:31 - 2025-10-05 08:01 - 000322216 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2025-10-05 08:21 - 2025-10-05 08:21 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-10-05 07:52 - 2025-10-05 08:47 - 000000000 ____D C:\Program Files\Avast Software
2025-10-05 07:52 - 2025-10-05 07:52 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-10-05 07:52 - 2025-10-05 07:51 - 000056128 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2025-10-05 07:49 - 2025-10-05 10:11 - 000000000 ____D C:\ProgramData\Avast Software
2025-10-05 07:49 - 2025-10-05 07:49 - 000249080 _____ (Gen Digital Inc.) C:\Users\PC\Downloads\online_instalační_soubor_aplikace_avast_free_antivirus.exe
2025-10-03 16:04 - 2025-10-03 16:04 - 000000219 _____ C:\Users\PC\Desktop\Counter-Strike 2.url
2025-10-03 16:00 - 2025-10-03 16:00 - 000004032 _____ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-3053447137-874728891-481791925-1001_0
2025-10-03 12:33 - 2025-10-03 12:33 - 000000000 ____D C:\Users\PC\AppData\Local\GIANTS Crash Reporter
2025-10-03 12:29 - 2025-10-03 12:29 - 000000000 ____D C:\Users\PC\AppData\Local\Backup
2025-10-02 19:13 - 2025-10-02 19:13 - 018669136 _____ (Martin Malik, REALiX s.r.o. ) C:\Users\PC\Downloads\hwi64_830.exe
2025-10-02 19:09 - 2025-10-02 19:09 - 000000000 ____D C:\Users\PC\Documents\FrameView
2025-10-02 19:08 - 2025-10-02 19:08 - 011969248 _____ (NVIDIA Corporation) C:\Users\PC\Downloads\FrameViewSetup.exe
2025-10-02 19:03 - 2025-10-02 19:03 - 000000000 ____D C:\Users\PC\Documents\My Games
2025-10-02 19:02 - 2025-10-03 16:04 - 000000000 ____D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-10-02 19:02 - 2025-10-02 19:02 - 000000223 _____ C:\Users\PC\Desktop\Farming Simulator 25.url
2025-10-02 18:56 - 2025-10-02 18:56 - 000000000 ____D C:\Users\PC\AppData\Local\CEF
2025-10-02 18:55 - 2025-10-02 19:01 - 000000000 ____D C:\Users\PC\AppData\Local\Steam
2025-10-02 18:54 - 2025-10-05 10:25 - 000000000 ____D C:\Program Files (x86)\Steam
2025-10-02 18:54 - 2025-10-02 18:54 - 002380800 _____ C:\Users\PC\Downloads\SteamSetup.exe
2025-10-02 18:54 - 2025-10-02 18:54 - 000001032 _____ C:\Users\Public\Desktop\Steam.lnk
2025-10-02 18:54 - 2025-10-02 18:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2025-10-02 18:53 - 2025-10-02 18:53 - 000000000 ____D C:\Users\PC\AppData\Local\OneDrive
2025-10-02 18:30 - 2025-10-02 18:30 - 000001388 _____ C:\Users\PC\Desktop\Roblox Player.lnk
2025-10-02 18:29 - 2025-10-03 16:19 - 000000000 ____D C:\Users\PC\AppData\Local\Roblox
2025-10-02 18:29 - 2025-10-02 18:30 - 000000000 ____D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2025-10-02 18:29 - 2025-10-02 18:29 - 008278480 _____ (Roblox Corporation) C:\Users\PC\Downloads\RobloxPlayerInstaller.exe
2025-10-02 18:27 - 2025-10-02 18:27 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-10-02 18:27 - 2025-10-02 18:27 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-10-02 18:27 - 2025-10-02 18:27 - 000000000 ____D C:\Users\PC\AppData\Local\Google
2025-10-02 18:27 - 2025-10-02 18:27 - 000000000 ____D C:\Program Files\Google
2025-10-02 18:26 - 2025-10-02 18:26 - 010869176 _____ (Google LLC) C:\Users\PC\Downloads\ChromeSetup.exe
2025-10-02 18:26 - 2025-10-02 18:26 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-10-02 18:26 - 2025-10-02 18:26 - 000000000 ____D C:\Program Files (x86)\Google
2025-10-01 22:27 - 2025-10-01 22:27 - 000000000 ____D C:\Users\PC\AppData\Local\PeerDistRepub
2025-10-01 22:00 - 2025-10-01 22:00 - 000077233 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-10-01 22:00 - 2025-10-01 22:00 - 000077233 _____ C:\WINDOWS\system32\ctac.json
2025-10-01 22:00 - 2025-10-01 22:00 - 000001681 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-10-01 21:28 - 2025-10-01 21:28 - 000000000 ____D C:\Users\PC\AppData\Roaming\NVIDIA
2025-10-01 21:28 - 2025-10-01 21:28 - 000000000 ____D C:\Users\PC\AppData\Local\NVIDIA
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-05 10:21 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-05 10:18 - 2025-08-28 19:11 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-10-05 10:18 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-10-05 10:11 - 2025-08-28 20:02 - 000000000 ____D C:\ProgramData\NVIDIA
2025-10-05 10:11 - 2025-08-28 19:39 - 000001898 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-10-05 10:11 - 2025-08-28 19:05 - 000945760 _____ () C:\WINDOWS\system32\wpbbin.exe
2025-10-05 10:11 - 2025-08-28 19:05 - 000884568 _____ C:\WINDOWS\system32\AsusUpdateCheck.exe
2025-10-05 10:11 - 2025-08-28 19:05 - 000012288 ___SH C:\DumpStack.log.tmp
2025-10-05 10:11 - 2025-08-28 19:05 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2025-10-05 10:11 - 2025-08-28 19:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-05 10:11 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-05 10:11 - 2024-04-01 09:21 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2025-10-05 10:08 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC\AppData\Local\Packages
2025-10-05 08:51 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC\AppData\Local\D3DSCache
2025-10-05 08:39 - 2025-08-28 19:05 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-05 08:31 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-10-05 08:14 - 2025-08-28 19:40 - 000003558 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:14 - 2025-08-28 19:39 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:14 - 2025-08-28 19:39 - 000003370 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3053447137-874728891-481791925-1001
2025-10-05 08:14 - 2025-08-28 19:39 - 000002370 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-10-04 18:34 - 2025-08-28 19:06 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-10-04 18:34 - 2025-08-28 19:06 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-10-04 12:51 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-04 12:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-03 12:45 - 2025-08-28 19:07 - 000000000 ____D C:\ProgramData\Packages
2025-10-03 12:29 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC\AppData\Local\ConnectedDevicesPlatform
2025-10-02 21:10 - 2025-08-28 19:37 - 000000000 ____D C:\Users\PC
2025-10-02 20:42 - 2025-08-28 19:39 - 000000000 ____D C:\Users\PC\AppData\Local\PlaceholderTileLogoFolder
2025-10-02 20:22 - 2025-08-28 20:02 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-10-02 19:27 - 2025-08-28 19:37 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-10-02 19:11 - 2025-08-28 20:02 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-10-01 22:28 - 2025-08-28 19:05 - 000297176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-10-01 22:27 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-10-01 22:27 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-10-01 22:27 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-10-01 22:27 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-10-01 22:27 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-10-01 22:25 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-10-01 22:25 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2025-10-01 22:00 - 2025-08-28 19:09 - 003270656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-10-01 21:38 - 2025-08-28 19:05 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-10-01 21:27 - 2025-08-28 19:05 - 000003716 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{E0B78D81-D492-4F53-A483-25257F0EEC2E}
2025-10-01 21:27 - 2025-08-28 19:05 - 000003590 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{31240395-7FA8-4E35-B6FC-B8A922D2FF2E}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
==================== End of Addition.txt =======================