Stránka 1 z 1

Prosím o kontrolu

Napsal: 15 dub 2024 10:28
od mapo44
Dobrý deň,
ako aj naposledy mi nejde vložiť FRST.
Urobil som AdwClen a ani ten neviem vložiť, asi by som mal už počítač zahodiť , nie kvôli nemu ale mne. Porádíte čo s tým?
Ďakujem. Skúsil som takto.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.04.2024
Ran by Max (administrator) on NOVÉPC (15-04-2024 10:15:44)
Running from C:\Users\Max\Desktop\FRST64.exe
Loaded Profiles: Max
Platform: Microsoft Windows 10 Home Version 22H2 19045.4291 (X64) Language: Slovenčina (Slovensko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(explorer.exe ->) (609E45DF-0A4E-4EB8-A151-20E6EE0A0AA3 -> EasyAI) C:\Program Files\WindowsApps\61545TimGrabinat.EasyAI_1.2.5.0_x64__rcb0qdgx4z9ca\EasyAI.exe
(explorer.exe ->) (Disig a.s. -> Disig a.s.) C:\Program Files (x86)\Disig\Web Signer\WebSignerTray.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <10>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.363\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.363\GoogleCrashHandler64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Ministerstvo vnútra Slovenskej republiky -> ) C:\Program Files (x86)\eID_klient\eID_Client.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Digital Wave Ltd -> Digital Wave Ltd) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicShellService.exe
(services.exe ->) (Nero AG -> Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe <6>
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2414.8.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_2.7.1181.0_x86__8wekyb3d8bbwe\Jigsaw.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [196264 2024-01-24] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Family Tree Builder Update] => C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe [17935752 2021-03-21] (MyHeritage (USA) Inc. -> MyHeritage)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [eID_Client] => C:\Program Files (x86)\eID_klient\eID_Client.exe [22546288 2024-01-25] (Ministerstvo vnútra Slovenskej republiky -> )
HKLM\...\RunOnce: [msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}] => C:\Program Files (x86)\Microsoft\Edge\Application\123.0.2420.97\Installer\setup.exe [7146552 2024-04-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\Run: [vidnotifier.exe] => C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\vidnotifier\vidnotifier.exe [1814848 2019-07-16] (Digital Wave Ltd -> Digital Wave Ltd)
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45285792 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\Run: [MicrosoftEdgeAutoLaunch_0C0D5F59005A32876380EE3B976869A6] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4063800 2024-04-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\Run: [Disig Web Signer] => C:\Program Files (x86)\Disig\Web Signer\WebSignerTray.exe [268128 2023-04-05] (Disig a.s. -> Disig a.s.)
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\Run: [Viber] => C:\Users\Max\AppData\Local\Viber\Viber.exe [88525152 2024-04-04] (Viber Media S.a r.l. -> Viber Media S.à r.l.)
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [91585088 2020-03-31] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\123.0.6312.107\Installer\chrmstp.exe [2024-04-11] (Google LLC -> Google LLC)

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {6F27345F-483B-48BE-B9D3-8738BF0512F3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1547208 2024-01-31] (Adobe Inc. -> Adobe Inc.)
Task: {5B04DCFA-159E-46AF-B6D4-3D6D462DA48B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [569416 2016-02-23] (Apple Inc. -> Apple Inc.)
Task: {D994BE2B-9F89-4180-8C12-7A9DF8E54419} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {963D8354-FC2C-4BD4-87FC-752B71ED9FD2} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "db095514-bd8c-4a6e-b607-72939d3bc43b" --version "6.22.10977" --silent
Task: {DCDCED14-605B-4080-96ED-E9211BD2EBAD} - System32\Tasks\CCleanerSkipUAC - Max => C:\Program Files\CCleaner\CCleaner.exe [39024544 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {6EEE0225-9FBB-46D7-9A49-E19B52981824} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Max\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [18007968 2021-06-06] (ESET, spol. s r.o. -> ESET)
Task: {3100B341-72B3-433A-9C25-A92A1371D805} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Max\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [18007968 2021-06-06] (ESET, spol. s r.o. -> ESET)
Task: {F7210FE4-86E5-46F0-9D2F-F205F7332B37} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-2923722727-4003214351-2683229-1002 => {F063A606-6748-4B89-82A0-3D19D94CE8D3} C:\Windows\System32\VaultRoaming.dll [119808 2023-10-11] (Microsoft Windows -> Microsoft)
Task: {DE43D6A4-B630-4AF6-8402-A1AB4B062D0B} - System32\Tasks\GoogleUpdateTaskMachineCore{83A06868-E161-4A84-AD3C-BA236529E53A} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.)
Task: {9160C80C-BB95-4DEB-8A7A-CD2C1364091A} - System32\Tasks\GoogleUpdateTaskMachineUA{D6FC7FCB-6850-4AA4-A60A-1336CB4A1DD9} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.)
Task: {7D5BBE27-7E74-44CA-B779-C73C24832136} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {2DF234F8-18AF-4CE2-A895-2D39D9519357} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 217.23.254.124 217.23.254.125
Tcpip\..\Interfaces\{3cd7677d-4660-44fd-afd3-a5ba277e71e2}: [DhcpNameServer] 217.23.254.124 217.23.254.125
Tcpip\..\Interfaces\{3cd7677d-4660-44fd-afd3-a5ba277e71e2}: [DhcpDomain] chello.sk

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default [2024-04-15]
Edge HomePage: Default -> hxxp://www.google.com/
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-28]
Edge Extension: (Adblock Plus - free ad blocker) - C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2024-04-03]
Edge Extension: (Edge relevant text changes) - C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]

FireFox:
========
FF DefaultProfile: n0yoyckj.default
FF ProfilePath: C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\1jiql9zt.default-release-1-1650973172650 [2024-04-11]
FF Extension: (Slovak (SK) Language Pack) - C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\1jiql9zt.default-release-1-1650973172650\Extensions\langpack-sk@firefox.mozilla.org.xpi [2022-04-26]
FF ProfilePath: C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\n0yoyckj.default [2023-06-27]
FF ProfilePath: C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\u5mvooau.default-release [2024-04-11]
FF Extension: (Surfshark VPN Extension) - C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\u5mvooau.default-release\Extensions\{732216ec-0dab-43bb-ac85-4b5e1977599d}.xpi [2022-04-09]
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-03-31] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.12 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.14 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.15 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.18 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.20 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2022-04-09]

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default [2024-04-15]
CHR Notifications: Default -> hxxps://meet.google.com; hxxps://www.financnykompas.sk; hxxps://www.kosher.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2024-04-03]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-11-28]
CHR Profile: C:\Users\Max\AppData\Local\Google\Chrome\User Data\System Profile [2024-04-11]
CHR HKLM-x32\...\Chrome\Extension: [oombnmpbbhbakfpfgdflaajkhicgfaam]

Opera:
=======
OPR Profile: C:\Users\Max\AppData\Roaming\Opera Software\Opera Stable [2024-04-11]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=o ... utEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\Max\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-04-07]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\Max\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2022-04-07]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-01-31] (Adobe Inc. -> Adobe Inc.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1081248 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-13] (IvoSoft) [File not signed]
R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [441664 2019-07-16] (Digital Wave Ltd -> Digital Wave Ltd)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [2539384 2024-01-24] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [3890064 2024-01-24] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [3890064 2024-01-24] (ESET, spol. s r.o. -> ESET)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 NativePushService; no ImagePath

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswTap; C:\WINDOWS\system32\DRIVERS\aswTap.sys [53904 2018-09-07] (AVAST Software s.r.o. -> The OpenVPN Project)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [215616 2023-12-09] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [120032 2023-12-09] (ESET, spol. s r.o. -> ESET)
R1 edevmonm; C:\WINDOWS\System32\DRIVERS\edevmonm.sys [122664 2023-12-09] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [16336 2022-08-23] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [254344 2023-12-09] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [55528 2023-12-09] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [81824 2023-12-09] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [124168 2023-12-09] (ESET, spol. s r.o. -> ESET)
S1 HWiNFO_190; no ImagePath
R2 npf; C:\Windows\System32\Drivers\npf.sys [36600 2019-07-16] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; no ImagePath
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
R3 StnPport; C:\WINDOWS\system32\DRIVERS\StnPport.sys [97280 2010-10-26] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2022-04-01] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-04-15 10:15 - 2024-04-15 10:18 - 000019777 _____ C:\Users\Max\Desktop\FRST.txt
2024-04-15 10:09 - 2024-04-15 10:09 - 002394112 _____ (Farbar) C:\Users\Max\Desktop\FRST64.exe
2024-04-15 08:17 - 2024-04-15 10:20 - 000000000 ____D C:\Users\Max\AppData\Roaming\Microsoft\Skype for Desktop
2024-04-15 08:17 - 2024-04-15 08:17 - 000001375 _____ C:\Users\Public\Desktop\Skype.lnk
2024-04-15 08:17 - 2024-04-15 08:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2024-04-12 14:25 - 2024-04-12 14:25 - 000002333 _____ C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Inboxer.lnk
2024-04-12 11:18 - 2024-04-12 11:18 - 000000000 ____D C:\Users\Max\Desktop\PDF
2024-04-11 15:41 - 2024-04-11 15:42 - 000000000 ____D C:\Users\Max\Desktop\Word
2024-04-11 08:23 - 2024-04-11 08:50 - 000000000 ____D C:\Users\Max\Desktop\Eset licencia
2024-04-10 13:00 - 2024-04-10 13:00 - 000000000 ___HD C:\$WinREAgent
2024-04-09 17:57 - 2024-04-09 17:59 - 000000000 ____D C:\Users\Max\Desktop\produkey-x64
2024-04-09 15:58 - 2024-03-27 11:32 - 009098720 _____ (REALiX s.r.o.) C:\Users\Max\Desktop\HWiNFO64.exe
2024-04-02 13:45 - 2024-04-02 13:45 - 000002683 _____ C:\Users\Max\Desktop\Google Meet.lnk
2024-04-02 13:45 - 2024-04-02 13:45 - 000000000 ____D C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome
2024-03-30 18:20 - 2024-03-30 18:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eID Klient
2024-03-30 18:20 - 2024-03-30 18:20 - 000000000 ____D C:\Program Files (x86)\legal
2024-03-27 09:56 - 2024-03-27 09:56 - 000020861 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-27 09:51 - 2024-03-27 09:51 - 000020861 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-03-16 16:44 - 2024-03-16 16:44 - 000000000 ____D C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2024-03-16 09:33 - 2024-04-03 10:36 - 000000000 ____D C:\Users\Max\AppData\Local\CrashDumps

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-04-15 10:20 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-04-15 10:17 - 2020-10-24 08:33 - 000000000 ____D C:\FRST
2024-04-15 09:58 - 2022-09-08 05:12 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-04-15 09:58 - 2018-11-26 10:42 - 000000000 ____D C:\Program Files (x86)\Google
2024-04-15 09:49 - 2022-11-22 18:24 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-04-15 07:27 - 2022-07-14 10:11 - 000000000 ____D C:\Program Files\CCleaner
2024-04-15 07:22 - 2022-11-22 18:57 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-04-15 07:22 - 2021-07-09 14:13 - 000008192 ___SH C:\DumpStack.log.tmp
2024-04-15 07:22 - 2018-11-26 10:34 - 000000000 ____D C:\ProgramData\NVIDIA
2024-04-14 18:33 - 2021-08-17 15:36 - 000000000 ____D C:\Users\Max\Documents\ViberDownloads
2024-04-14 14:55 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-04-14 14:55 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-04-14 14:34 - 2013-05-23 14:45 - 000000000 ____D C:\Users\Max\AppData\Local\Packages
2024-04-14 11:39 - 2013-05-23 14:45 - 000000000 ___SD C:\Users\Max\AppData\Roaming\Microsoft\Credentials
2024-04-14 10:26 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-04-14 07:42 - 2023-01-17 08:42 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-04-14 07:42 - 2023-01-17 08:42 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-04-13 18:47 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-04-13 08:23 - 2021-07-10 16:11 - 000000000 ____D C:\Users\Max\AppData\Local\D3DSCache
2024-04-12 18:25 - 2023-11-23 11:53 - 000000000 ____D C:\Users\Max\AppData\Local\eID_klient
2024-04-12 18:24 - 2023-05-03 10:16 - 000000000 ____D C:\Users\Max\AppData\Roaming\Inboxer
2024-04-12 14:40 - 2018-12-03 14:06 - 000000000 ____D C:\Users\Max\AppData\Roaming\vlc
2024-04-12 14:31 - 2022-04-08 15:10 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-04-12 11:37 - 2023-04-06 10:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2024-04-12 11:37 - 2023-04-06 10:15 - 000000000 ____D C:\Program Files (x86)\Canon
2024-04-12 11:26 - 2020-04-05 18:01 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2024-04-11 16:10 - 2022-11-22 18:41 - 001625268 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-04-11 16:10 - 2022-05-11 12:54 - 000662222 _____ C:\WINDOWS\system32\perfh01B.dat
2024-04-11 16:10 - 2022-05-11 12:54 - 000127864 _____ C:\WINDOWS\system32\perfc01B.dat
2024-04-11 16:03 - 2022-11-28 16:15 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2024-04-11 16:03 - 2022-04-26 18:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-04-11 16:02 - 2022-11-22 18:30 - 000000000 ____D C:\Users\Max
2024-04-11 15:39 - 2022-04-03 10:09 - 000000000 ____D C:\Users\Max\Desktop\Deborah
2024-04-11 12:40 - 2021-03-07 18:54 - 000000000 ____D C:\Users\Max\AppData\Roaming\ViberPC
2024-04-11 12:39 - 2022-08-30 08:25 - 000000000 ____D C:\Users\Max\AppData\Local\Viber
2024-04-11 08:49 - 2022-11-28 16:15 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-04-11 08:20 - 2022-11-28 15:35 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-04-11 08:20 - 2022-11-28 15:35 - 000002272 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-04-10 15:39 - 2022-11-22 18:24 - 000491144 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-04-10 15:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-04-10 15:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2024-04-10 15:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-04-10 15:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-04-10 14:14 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-04-10 13:59 - 2022-11-22 18:28 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-04-10 12:50 - 2018-11-29 08:52 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-04-10 12:45 - 2018-11-29 08:51 - 192651728 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-04-10 11:40 - 2014-12-22 19:27 - 000000000 ____D C:\Users\Max\Desktop\Excel
2024-04-09 15:55 - 2023-12-26 15:46 - 000057936 _____ (REALiX) C:\WINDOWS\system32\Drivers\HWiNFO64A_190.SYS
2024-04-09 14:57 - 2022-11-22 18:57 - 000003580 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2923722727-4003214351-2683229-1002
2024-04-09 14:57 - 2022-11-22 18:57 - 000003352 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2923722727-4003214351-2683229-1002
2024-04-09 14:57 - 2022-11-22 18:30 - 000002393 _____ C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-04-05 08:34 - 2018-11-26 10:27 - 000000000 ____D C:\Users\Max\AppData\Roaming\Microsoft\Spelling
2024-04-04 08:34 - 2022-11-23 17:53 - 000003708 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{61073E8A-0D3E-461F-ABA5-6A0B628038F5}
2024-04-04 08:34 - 2022-11-23 17:53 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{92402B97-8CE0-4E55-A92E-C7535F860372}
2024-04-03 10:16 - 2022-11-22 18:57 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-04-03 10:14 - 2022-10-14 08:10 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-04-03 10:14 - 2022-10-14 08:10 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2024-03-31 18:37 - 2022-11-22 18:57 - 000003832 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2024-03-31 18:37 - 2022-11-22 18:57 - 000003390 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2024-03-31 18:36 - 2023-11-06 11:15 - 000001408 _____ C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2024-03-30 18:23 - 2021-06-04 15:31 - 000000985 _____ C:\Users\Max\Desktop\HandBrake.lnk
2024-03-30 18:23 - 2021-06-03 17:54 - 000001075 _____ C:\Users\Max\Desktop\Format Factory.lnk
2024-03-30 18:23 - 2021-03-07 18:53 - 000001057 _____ C:\Users\Max\Desktop\Viber.lnk
2024-03-30 18:23 - 2020-11-13 16:20 - 000001128 _____ C:\Users\Max\Desktop\AML Free Registry Cleaner.lnk
2024-03-30 18:23 - 2019-10-02 14:15 - 000000961 _____ C:\Users\Max\Desktop\Pretty Good Solitaire 2k.lnk
2024-03-30 18:23 - 2019-04-22 15:53 - 000002027 _____ C:\Users\Max\Desktop\ESET Ochrana online platieb.lnk
2024-03-30 18:23 - 2019-04-22 15:52 - 000002073 _____ C:\Users\Max\Desktop\Zoner Photo Studio 12.lnk
2024-03-30 18:23 - 2018-11-30 17:57 - 000001208 _____ C:\Users\Max\Desktop\CrystalDiskInfo.lnk
2024-03-30 18:22 - 2023-11-23 11:53 - 000000000 ____D C:\Users\Max\AppData\Roaming\eID_klient
2024-03-30 18:20 - 2023-11-23 11:52 - 000001976 _____ C:\Users\Public\Desktop\eID Klient.lnk
2024-03-30 18:20 - 2023-11-23 11:52 - 000000000 ____D C:\Program Files (x86)\eID_klient
2024-03-30 11:46 - 2020-06-20 16:46 - 000000000 ____D C:\Users\Max\AppData\Local\Windows Live
2024-03-29 13:12 - 2013-07-07 13:47 - 000000000 ____D C:\Users\Max\Documents\Nepoužívané odkazy plochy
2024-03-29 13:10 - 2023-05-08 08:59 - 000000000 ___RD C:\Users\Max\Documents\Scanned Documents
2024-03-29 12:12 - 2022-05-14 08:09 - 000000000 ____D C:\Users\Max\Desktop\výpisy VUB
2024-03-29 11:55 - 2018-11-26 16:08 - 000000000 ____D C:\Users\Max\AppData\Roaming\Microsoft\Excel
2024-03-28 09:38 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\appcompat
2024-03-27 11:33 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-03-27 11:23 - 2023-12-14 09:52 - 000000000 ____D C:\WINDOWS\InboxApps
2024-03-27 11:23 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-03-27 11:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2024-03-27 11:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-03-27 11:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2024-03-27 10:43 - 2018-11-26 14:21 - 000000000 ____D C:\Users\Max\AppData\Roaming\Microsoft\Office
2024-03-25 07:32 - 2022-11-22 18:57 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-03-24 12:19 - 2018-11-26 16:09 - 000000000 ____D C:\Users\Max\AppData\Roaming\Microsoft\Word
2024-03-22 19:38 - 2018-11-28 10:56 - 000000000 ____D C:\Users\Max\AppData\Local\ElevatedDiagnostics
2024-03-22 08:30 - 2022-09-13 08:05 - 000000000 ____D C:\Users\Max\AppData\Roaming\com.adobe.dunamis
2024-03-21 08:21 - 2023-10-12 15:20 - 000000000 ____D C:\Program Files\RUXIM
2024-03-16 16:44 - 2022-03-13 20:50 - 000001961 _____ C:\Users\Max\Desktop\Zoom.lnk
2024-03-16 16:44 - 2022-03-13 19:44 - 000000000 ____D C:\Users\Max\AppData\Roaming\Zoom

==================== Files in the root of some directories ========

2019-02-09 16:08 - 2019-02-09 16:08 - 000000000 _____ () C:\Users\Max\AppData\Roaming\AVSDVDPlayer.m3u
2019-10-22 18:41 - 2020-05-01 07:39 - 000000630 _____ () C:\Users\Max\AppData\Roaming\Safer-Networking.log
2023-12-07 09:41 - 2023-12-07 09:41 - 000004096 ____H () C:\Users\Max\AppData\Local\keyfile3.drm

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.04.2024
Ran by Max (15-04-2024 10:21:18)
Running from C:\Users\Max\Desktop
Microsoft Windows 10 Home Version 22H2 19045.4291 (X64) (2022-11-22 16:58:50)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-2923722727-4003214351-2683229-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2923722727-4003214351-2683229-503 - Limited - Disabled)
Guest (S-1-5-21-2923722727-4003214351-2683229-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2923722727-4003214351-2683229-1010 - Limited - Enabled)
Max (S-1-5-21-2923722727-4003214351-2683229-1002 - Administrator - Enabled) => C:\Users\Max
WDAGUtilityAccount (S-1-5-21-2923722727-4003214351-2683229-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Security (Enabled - Up to date) {DF8BEACB-94C9-218A-73AD-A78362A8C516}
AV: ESET Security (Enabled - Up to date) {89B55CC4-3881-78B2-11E2-479AE0371896}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
AS: ESET Security (Enabled - Up to date) {32D4BD20-1EBB-773C-2B52-7CE89BB0522B}
FW: ESET Firewall (Enabled) {E7B06BEE-DEA6-20D2-58F2-0EB69C7B826D}
FW: ESET Firewall (Enabled) {B18EDDE1-72EE-79EA-3ABD-EEAF1EE45FED}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1051-1033-7760-BC15014EA700}) (Version: 24.001.20643 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601067}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Advertising Center (HKLM-x32\...\{b2ec4a38-b545-4a00-8214-13fe0e915e6d}) (Version: 0.0.0.1 - Nero AG) Hidden
Aktualizácia Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-041B-0000-0000000FF1CE}_PROPLUS_{9A8C39B0-D27F-4F81-BE74-2FECF164707E}) (Version: - Microsoft)
Aktualizácia Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-041B-0000-0000000FF1CE}_PROPLUS_{CE23B3DC-18CC-46FC-A309-81D6670F8D3D}) (Version: - Microsoft)
Aktualizácia Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-041B-0000-0000000FF1CE}_PROPLUS_{D6DBF512-87C0-4F6A-8FB9-AC3A389D9DE5}) (Version: - Microsoft)
AML Free Registry Cleaner 4.6 (HKLM-x32\...\{315F5FFC-1A5C-4A2A-B8E7-1C5B1174C198}_is1) (Version: - AML SOFT, Inc.)
Apowersoft Video Konvertor V4.8.6.4 (HKLM-x32\...\{195E8D7F-292B-4B04-A6E7-E96CAF04C767}_is1) (Version: 4.8.6.4 - APOWERSOFT LIMITED)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Ashampoo Burning Studio 6 FREE v.6.84 (HKLM-x32\...\{91B33C97-3ED1-03EA-A67B-244AA4D7B559}_is1) (Version: 6.8.4 - Ashampoo GmbH & Co. KG)
Ashampoo WinOptimizer 2013 v.1.0.0 (HKLM-x32\...\{4209F371-7B85-60AD-E5CE-E4409D39E3DE}_is1) (Version: 1.00.00 - Ashampoo GmbH & Co. KG)
Asoftis Start Menu (HKLM\...\Asoftis Start Menu_is1) (Version: 2.5 - PS Media s.r.o.)
Balík softvéru eID (HKLM-x32\...\{d2c66c1e-5862-43e7-abe2-9c895312112c}) (Version: 1.0.0.0 - Ministerstvo vnútra Slovenskej republiky) Hidden
Bit4id - miniLector (HKLM-x32\...\Bit4id - miniLector) (Version: 3.7 - Bit4id)
Blu-ray Master Launcher 1.0.12 (HKLM-x32\...\{5ABF0C5D-5765-4535-8E09-FF777FE94A0C}_is1) (Version: 1.0.12 - Blu-ray Master)
CCleaner (HKLM\...\CCleaner) (Version: 6.22 - Piriform)
Classic Shell (HKLM\...\{7F34ADBE-77C0-47A0-BBC6-B3DA16CE8E68}) (Version: 3.6.7 - IvoSoft)
CrystalDiskInfo 8.0.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 8.0.0 - Crystal Dew World)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Disig Web Signer (HKLM-x32\...\{8DF92E56-C8C4-4FE3-AD3B-AA10AF3BF0C6}) (Version: 2.1.1 - Disig)
eID Klient (HKLM-x32\...\{1C15FC1F-2525-4FFB-B1CE-13D76FCC191E}) (Version: 4.8.0 - MV SR)
ESET Security (HKLM\...\{0813F772-F554-4DA9-9CEA-ABCE6321BDFD}) (Version: 17.0.16.0 - ESET, spol. s r.o.)
FormatFactory 4.4.1.0 (HKLM-x32\...\FormatFactory) (Version: 4.4.1.0 - Free Time)
Free Studio (HKLM-x32\...\Free Studio_is1) (Version: 6.7.0.712 - Digital Wave Ltd)
GemPcCCID (HKLM\...\{C2C14C20-A217-4FCA-B668-89B6C70B6EFF}) (Version: 2.0.7 - Gemalto)
Google Earth Pro (HKLM\...\{3470AD08-85F2-4B1D-8487-FC4750732087}) (Version: 7.3.6.9796 - Google)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 123.0.6312.107 - Google LLC)
HandBrake 1.3.3 (HKLM-x32\...\HandBrake) (Version: 1.3.3 - )
HWiNFO64 (HKLM\...\HWiNFO64_is1) (Version: 7.68 - Martin Malik, REALiX s.r.o.)
Inboxer 1.0.2 (only current user) (HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\a47eae35-cb17-53b5-bb8c-c045cf8dc5ef) (Version: 1.0.2 - Denys Dovhan)
Microlife BPA 3.2 English (HKLM-x32\...\InstallShield_{B52161A2-B3BB-429A-9A57-A74CAB6185C7}) (Version: 3.2.5 - Microlife)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 123.0.2420.97 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 123.0.2420.97 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0015-041B-0000-0000000FF1CE}_PROPLUS_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0016-041B-0000-0000000FF1CE}_PROPLUS_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0018-041B-0000-0000000FF1CE}_PROPLUS_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0019-041B-0000-0000000FF1CE}_PROPLUS_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001A-041B-0000-0000000FF1CE}_PROPLUS_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001B-041B-0000-0000000FF1CE}_PROPLUS_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-041B-1000-0000000FF1CE}_PROPLUS_{8382BA92-20E3-47B6-971B-F673F0492D4E}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0044-041B-0000-0000000FF1CE}_PROPLUS_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-006E-041B-0000-0000000FF1CE}_PROPLUS_{8382BA92-20E3-47B6-971B-F673F0492D4E}) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0015-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0016-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office InfoPath MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0044-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Slovak) 2007 (HKLM-x32\...\{90120000-001A-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0018-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2007 (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Hungarian) 2007 (HKLM-x32\...\{90120000-001F-040E-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Slovak) 2007 (HKLM-x32\...\{90120000-002C-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1039 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}_PROPLUS_{0B7A4B67-2A38-42B1-9857-662FAB361E08}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{928D7B99-2BEA-49F9-83B8-20FA57860643}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-040E-0000-0000000FF1CE}_PROPLUS_{0AD4BB83-13B4-4C9D-9BAC-7F64E0B2D5D7}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}_PROPLUS_{FDF9A959-241A-4662-A8DE-7DED9C22D160}) (Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0019-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Slovak) 2007 (HKLM\...\{90120000-002A-041B-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Slovak) 2007 (HKLM-x32\...\{90120000-006E-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Slovak) 2007 (HKLM-x32\...\{90120000-001B-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\OneDriveSetup.exe) (Version: 24.055.0317.0002 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30135 (HKLM-x32\...\{fa7f6d52-f85e-48ef-8f56-a37268aa5772}) (Version: 14.29.30135.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 (HKLM-x32\...\{41d7b770-418a-43b7-95a5-f925fff05789}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.29.30135 (HKLM\...\{34DB4181-0770-4B5A-B561-68758A077B0F}) (Version: 14.29.30135 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.29.30135 (HKLM\...\{40118CD9-A805-400C-864E-041A5B5C01B0}) (Version: 14.29.30135 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.31.31103 (HKLM-x32\...\{5720EC03-F26F-40B7-980C-50B5D420B5DE}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.31.31103 (HKLM-x32\...\{799E3FFF-705C-461F-B400-6DE27398B3E5}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
MiVue Manager (HKLM-x32\...\{123BDDDC-D02F-4C6E-A011-9CB265E2483E}) (Version: 1.0.43.1 - Mio Technology Corporation)
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 102.5.0 - Mozilla)
Mozilla Thunderbird (x64 sk) (HKLM\...\Mozilla Thunderbird 115.9.0 (x64 sk)) (Version: 115.9.0 - Mozilla)
MSVCRT (HKLM-x32\...\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}) (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (HKLM-x32\...\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}) (Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (HKLM\...\{E9FA781F-3E80-4399-825A-AD3E11C28C77}) (Version: 16.4.1109.0912 - Microsoft) Hidden
MyHeritage Family Tree Builder (HKLM-x32\...\Family Tree Builder) (Version: 8.0.0.8625 - MyHeritage.com)
Nero 9 Essentials (HKLM-x32\...\{9555bca6-84e2-437a-b3ea-0e9a16365d8f}) (Version: - Nero AG)
Nero ControlCenter (HKLM-x32\...\{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}) (Version: 9.0.0.1 - Nero AG) Hidden
Nero Installer (HKLM-x32\...\{e8a80433-302b-4ff1-815d-fcc8eac482ff}) (Version: 4.4.9.0 - Nero AG) Hidden
Nero Online Upgrade (HKLM-x32\...\{dba84796-8503-4ff0-af57-1747dd9a166d}) (Version: 1.3.0.0 - Nero AG) Hidden
Nero StartSmart (HKLM-x32\...\{7748ac8c-18e3-43bb-959b-088faea16fb2}) (Version: 9.4.12.100 - Nero AG) Hidden
Nero StartSmart OEM (HKLM-x32\...\{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}) (Version: 9.4.10.100 - Nero AG) Hidden
neroxml (HKLM-x32\...\{56C049BE-79E9-4502-BEA7-9754A3E60F9B}) (Version: 1.0.0 - Nero AG) Hidden
NVIDIA Grafický ovládač 456.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 456.71 - NVIDIA Corporation)
NVIDIA Ovládač zvuku HD 1.3.38.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.40 - NVIDIA Corporation)
Photo Gallery (HKLM-x32\...\{07AAB66E-4718-422D-9218-4AFB3C922A71}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Pretty Good Solitaire 2k (HKLM-x32\...\Pretty Good Solitaire 2k) (Version: - )
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Revo Uninstaller 2.4.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.4.5 - VS Revo Group, Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.7.43.0 - Samsung Electronics Co., Ltd.)
Skype verzia 8.58 (HKLM-x32\...\Skype_is1) (Version: 8.58 - Skype Technologies S.A.)
Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.23123.1 - Samsung Electronics Co., Ltd.) Hidden
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.23123.1 - Samsung Electronics Co., Ltd.)
TAP-Windows 9.24.2 (HKLM\...\TAP-Windows) (Version: 9.24.2 - OpenVPN Technologies, Inc.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{B9A7A138-BFD5-4C73-A269-F78CCA28150E}) (Version: 8.94.0.0 - Microsoft Corporation)
Viber (HKLM-x32\...\{230D2CE7-234D-4C10-B489-91ED518372E2}) (Version: 18.1.0.0 - 2010-2022 Viber Media S.a.r.l) Hidden
Viber (HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\{581ce85d-d156-4a7c-b991-569f59d6b6fa}) (Version: 18.1.0.0 - 2010-2022 Viber Media S.a.r.l)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Windows Kontrola stavu počítača (HKLM\...\{8D6B9DC1-A437-41E0-8DF1-9F37748394AE}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Windows Kontrola stavu počítača (HKLM\...\{995C446A-850D-44EA-BB71-156C271D9428}) (Version: 3.7.2204.15001 - Microsoft Corporation)
Windows Live Communications Platform (HKLM-x32\...\{41C61308-6CFD-4D54-AB6A-7136ED08A18E}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\{9A470EA9-FF86-4C0E-992C-572BF2B9D6FF}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Installer (HKLM-x32\...\{659CB81C-B54E-4DF1-B618-F35777393A54}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Photo Common (HKLM-x32\...\{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (HKLM-x32\...\{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE (HKLM-x32\...\{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (HKLM-x32\...\{D1893000-EA77-493C-8DDD-E262436E959B}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform (HKLM-x32\...\{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (HKLM-x32\...\{E100E2B5-F2EF-4955-AB7A-C3F2125A3BCD}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
WinRAR 6.22 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.22.0 - win.rar GmbH)
Wise Memory Optimizer (HKLM\...\Wise Memory Optimizer_is1) (Version: 4.2.0 - Lespeed Technology Co., Ltd.)
Zoner Photo Studio 12 (HKLM-x32\...\ZonerPhotoStudio12_CZ_is1) (Version: - ZONER software)
Zoom (HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\ZoomUMX) (Version: 5.17.11 (34827) - Zoom Video Communications, Inc.)

Chrome apps:
============
Google Meet (HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\755f0d733cfd0c26de7e3c65a1a23b0b) (Version: 1.0 - Google\Chrome)

Packages:
=========

Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2024-03-21] ()
Adobe Photoshop Express -> C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobePhotoshopExpress_3.12.430.0_x64__ynb6jyjzte8ga [2023-07-21] (Adobe Inc.)
Alarm Clock HD -> C:\Program Files\WindowsApps\AntaraSoftware.AlarmClockHD_7.0.0.0_x64__7jhd16s0b93qm [2023-11-15] (ANTARA SOFTWARE and CONSULTING PRIVATE LIMITED)
Alarm Clock Pro - free nightstand with facebook weather music radio news currency converter and world clock -> C:\Program Files\WindowsApps\48385AppMagic.AlarmClockPro-freenightstandwithface_1.3.0.1_neutral__w8sh846b15w3c [2022-11-23] (Alarm Clock Co)
Calculator² -> C:\Program Files\WindowsApps\61908RichardWalters.Calculator_2022.911.0.0_x64__486nvj664v5b0 [2023-04-21] (Richard Walters)
Dev Home -> C:\Program Files\WindowsApps\Microsoft.Windows.DevHome_0.1200.442.0_x64__8wekyb3d8bbwe [2024-03-22] (Microsoft Corporation)
Doplnok mediálneho nástroja pre Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-11-23] (Microsoft Corporation)
Doplnok pre Fotografie -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2022-11-23] (Microsoft Corporation)
EasyChat AI -> C:\Program Files\WindowsApps\61545TimGrabinat.EasyAI_1.2.5.0_x64__rcb0qdgx4z9ca [2024-03-19] (Tim Grabinat) [Startup Task]
Galaxy Book Smart Switch -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SmartSwitchforGalaxyBook_1.6.5.0_x64__3c1yjt4zspk6g [2024-04-04] (Samsung Electronics Co. Ltd.)
Hodiny -> C:\Program Files\WindowsApps\12199Asparion.AsparionClock_4.0.2.69_x64__f89vgcf3qm37t [2022-11-23] (Asparion) [MS Ad]
Hydro Thunder Hurricane -> C:\Program Files\WindowsApps\Microsoft.Studios.HydroThunderHurricane_1.2.0.0_x86__8wekyb3d8bbwe [2022-11-23] (Microsoft Studios)
International Space Station -> C:\Program Files\WindowsApps\Corinth.BestISS3D_1.2.0.3_x86__sa213gp990m1j [2022-11-23] (Corinth s.r.o.)
ISS Tracker -> C:\Program Files\WindowsApps\31673NikoVrdoljak.ISSTracker_1.1.0.2_x64__9t62e1techz4j [2022-11-23] (Niko Vrdoljak)
Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1809.1.0_x64__8wekyb3d8bbwe [2022-11-23] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1809.1.0_x86__8wekyb3d8bbwe [2022-11-23] (Microsoft Corporation) [MS Ad]
Microsoft Copilot -> C:\Program Files\WindowsApps\Microsoft.Windows.Ai.Copilot.Provider_1.0.3.0_neutral__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_2.7.1181.0_x86__8wekyb3d8bbwe [2024-01-24] (Microsoft Studios)
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_4.5.2130.0_x64__8wekyb3d8bbwe [2024-02-29] (Microsoft Studios) [MS Ad]
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_4.5.2151.0_x64__8wekyb3d8bbwe [2024-03-09] (Microsoft Studios)
Mini Golf Club -> C:\Program Files\WindowsApps\2724ZOLTNGUBICS.MINIGOLFCLUB_3.61.0.0_x64__d5xggy273m32g [2023-10-14] (Zoltán Gubics)
Prevodník Jednotiek -> C:\Program Files\WindowsApps\44352GadgetWE.UnitConversion_1.0.1.4_neutral__wrnqd43hr7tc6 [2022-11-23] (GadgetWE)
Telegram Desktop -> C:\Program Files\WindowsApps\TelegramMessengerLLP.TelegramDesktop_4.16.6.0_x64__t4vj0pshhgkwm [2024-04-12] (Telegram Messenger LLP) [Startup Task]
Vyhľadávanie na webe z Microsoft Bingu -> C:\Program Files\WindowsApps\Microsoft.BingSearch_1.0.91.0_x64__8wekyb3d8bbwe [2024-03-02] (Microsoft Corporation)
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2414.8.0_x64__cv1g1gvanyjgm [2024-04-13] (WhatsApp Inc.) [Startup Task]
Windows 8 videonávody -> C:\Program Files\WindowsApps\48039LuboslavLacko.Windows8videonvody_1.0.0.3_neutral__wt3dcr1qjjhxt [2022-11-23] (Luboslav Lacko)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2923722727-4003214351-2683229-1002_Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32 -> C:\Users\Max\AppData\Roaming\7zip\7-zip.dll (Igor Pavlov) [File not signed]
CustomCLSID: HKU\S-1-5-21-2923722727-4003214351-2683229-1002_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-2923722727-4003214351-2683229-1002_Classes\CLSID\{9486aaf1-0930-362a-962d-8e6908739c817}\InprocServer32 -> 0xB749D8902584DA01D055E0902584DA01010000000A00000000000000 => No File
CustomCLSID: HKU\S-1-5-21-2923722727-4003214351-2683229-1002_Classes\CLSID\{BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B}\InprocServer32 -> C:\Program Files (x86)\Zoner\Photo Studio 12\Program\SHELLEXT64.DLL (ZONER software, a.s. -> ZONER software)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2024-01-24] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-05-29] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-05-29] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2024-01-24] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2024-01-24] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-05-29] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-05-29] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1_S-1-5-21-2923722727-4003214351-2683229-1002: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Users\Max\AppData\Roaming\7zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers1_S-1-5-21-2923722727-4003214351-2683229-1002: [ZONERMenu] -> {BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B} => C:\Program Files (x86)\Zoner\Photo Studio 12\Program\SHELLEXT64.DLL [2011-03-25] (ZONER software, a.s. -> ZONER software)
ContextMenuHandlers2_S-1-5-21-2923722727-4003214351-2683229-1002: [ZONERMenu] -> {BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B} => C:\Program Files (x86)\Zoner\Photo Studio 12\Program\SHELLEXT64.DLL [2011-03-25] (ZONER software, a.s. -> ZONER software)
ContextMenuHandlers4_S-1-5-21-2923722727-4003214351-2683229-1002: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Users\Max\AppData\Roaming\7zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers4_S-1-5-21-2923722727-4003214351-2683229-1002: [ZONERMenu] -> {BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B} => C:\Program Files (x86)\Zoner\Photo Studio 12\Program\SHELLEXT64.DLL [2011-03-25] (ZONER software, a.s. -> ZONER software)
ContextMenuHandlers6_S-1-5-21-2923722727-4003214351-2683229-1002: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Users\Max\AppData\Roaming\7zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers6_S-1-5-21-2923722727-4003214351-2683229-1002: [ZONERMenu] -> {BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B} => C:\Program Files (x86)\Zoner\Photo Studio 12\Program\SHELLEXT64.DLL [2011-03-25] (ZONER software, a.s. -> ZONER software)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [msacm.voxacm160] => C:\WINDOWS\system32\vct3216.acm [82944 2003-05-21] (Voxware, Inc.) [File not signed]
HKLM\...\Drivers32: [msacm.scg726] => C:\WINDOWS\system32\scg726.acm [13239 2000-03-14] (SHARP Corporation) [File not signed]
HKLM\...\Drivers32: [msacm.alf2cd] => C:\WINDOWS\system32\alf2cd.acm [38912 2003-05-21] (NCT Company) [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\WINDOWS\system32\AC3ACM.acm [81920 2004-02-04] (fccHandler) [File not signed]
HKLM\...\Drivers32: [msacm.lame] => C:\WINDOWS\system32\lame.ax [245760 2005-08-01] () [File not signed]
HKLM\...\Drivers32: [vidc.dvsd] => C:\WINDOWS\system32\mcdvd_32.dll [261632 2003-05-21] (MainConcept) [File not signed]
HKLM\...\Drivers32: [vidc.mpg4] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp42] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp43] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.xvid] => C:\WINDOWS\system32\xvidvfw.dll [139264 2004-07-03] () [File not signed]
HKLM\...\Drivers32: [vidc.DIVX] => C:\WINDOWS\system32\DivX.dll [638976 2003-05-22] (DivXNetworks, Inc.) [File not signed]
HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP62] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.LAGS] => C:\WINDOWS\system32\lagarith.dll [216064 2011-12-07] () [File not signed]
HKLM\...\Drivers32: [msacm.voxacm160] => C:\Windows\SysWOW64\vct3216.acm [82944 2003-05-22] (Voxware, Inc.) [File not signed]
HKLM\...\Drivers32: [msacm.scg726] => C:\Windows\SysWOW64\scg726.acm [13239 2000-03-14] (SHARP Corporation) [File not signed]
HKLM\...\Drivers32: [msacm.alf2cd] => C:\Windows\SysWOW64\alf2cd.acm [38912 2003-05-22] (NCT Company) [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\AC3ACM.acm [81920 2004-02-04] (fccHandler) [File not signed]
HKLM\...\Drivers32: [vidc.dvsd] => C:\Windows\SysWOW64\mcdvd_32.dll [261632 2007-09-27] (MainConcept) [File not signed]
HKLM\...\Drivers32: [vidc.DIVX] => C:\Windows\SysWOW64\DivX.dll [638976 2007-09-27] (DivXNetworks, Inc.) [File not signed]
HKLM\...\Drivers32: [vidc.mpg4] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2007-09-27] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp42] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2007-09-27] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp43] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2007-09-27] (Microsoft Corporation) [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Max\Desktop\Google Meet.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=kjgfgldnnfoeklkmfkjfagphfepbbdan
ShortcutWithArgument: C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default\Pinned Sites\MSEdge._pin_mbfefonkpgdabgjoiopokelgkj\Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxps://www.office.com/ --profile-directory=Default
ShortcutWithArgument: C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default\Pinned Sites\MSEdge._pin_mabbogacohbobbecclmpanobce\Wikipédia.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxps://www.wikipedia.org/ --profile-directory=Default
ShortcutWithArgument: C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default\Pinned Sites\MSEdge._pin_celnaknmndgffhbhciignkeokb\Facebook.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxps://www.facebook.com/ --profile-directory=Default
ShortcutWithArgument: C:\Users\Max\AppData\Local\Microsoft\Edge\User Data\Default\Pinned Sites\MSEdge._pin_adnlfjpnmiaohpidplnoimahfh\YouTube.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxps://www.youtube.com/ --profile-directory=Default
ShortcutWithArgument: C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kjgfgldnnfoeklkmfkjfagphfepbbdan\Google Meet.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=kjgfgldnnfoeklkmfkjfagphfepbbdan
ShortcutWithArgument: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome\Google Meet.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=kjgfgldnnfoeklkmfkjfagphfepbbdan
ShortcutWithArgument: C:\Users\Max\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Meet.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=kjgfgldnnfoeklkmfkjfagphfepbbdan

==================== Loaded Modules (Whitelisted) =============

2024-01-25 19:29 - 2024-01-25 19:29 - 004277248 _____ () [File not signed] C:\Program Files (x86)\eID_klient\botan_x86.dll
2024-01-25 19:33 - 2024-01-25 19:33 - 000151552 _____ () [File not signed] C:\Program Files (x86)\eID_klient\openjpeg.dll
2024-04-15 08:17 - 2020-03-31 17:11 - 001899520 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\ffmpeg.dll
2024-04-15 08:17 - 2020-03-31 17:11 - 000115712 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libegl.dll
2024-04-15 08:17 - 2020-03-31 17:11 - 006668800 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libglesv2.dll
2023-11-20 14:25 - 2023-11-20 14:25 - 005855744 _____ (ESET, spol. s r.o. -> ESET) [File not signed] C:\Program Files\ESET\ESET Security\Modules\em045_64\1087\em045_64.dll
2023-03-01 16:09 - 2021-12-26 16:00 - 000093696 _____ (Igor Pavlov) [File not signed] C:\Users\Max\AppData\Roaming\7zip\7-zip.dll
2024-01-25 19:33 - 2024-01-25 19:33 - 002579968 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\eID_klient\libcrypto-1_1.dll
2024-01-25 19:33 - 2024-01-25 19:33 - 000535552 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\eID_klient\libssl-1_1.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO-x32: No Name -> {F9B65201-3D7F-48DA-AAB3-57A6FAD648FD} -> No File
Handler: WSKVAllmytubechrome - {91AB862D-07B8-4A85 - No File

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\123simsen.com -> www.123simsen.com

There are 7941 more sites.


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2023-06-27 19:08 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2923722727-4003214351-2683229-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 217.23.254.124 - 217.23.254.125
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "Family Tree Builder Update"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\StartupApproved\Run: => "Viber"
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\StartupApproved\Run: => "vidnotifier.exe"
HKU\S-1-5-21-2923722727-4003214351-2683229-1002\...\StartupApproved\Run: => "OneDrive"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{012A9E9A-C329-4231-9CA0-1EF6997A9BC5}] => (Allow) C:\Program Files (x86)\FormatFactory\FFModules\Package\PTInstOnline.exe (Free Time Co., Ltd. -> Free Time)
FirewallRules: [{A7B953F4-2336-4D49-8C4C-50E305CB30EE}] => (Allow) C:\Program Files (x86)\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe (Free Time Co., Ltd. -> Free Time Co., Ltd.)
FirewallRules: [{F2C2EB8B-2B0E-413D-9B41-38FD7D4CC1B8}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe (Free Time Co., Ltd. -> Free Time Co., Ltd.) [File not signed]
FirewallRules: [{34558DF8-9C8F-4C51-819C-314EA5518C22}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe (Free Time Co., Ltd. -> Free Time Co., Ltd.) [File not signed]
FirewallRules: [{6FF568C9-3110-42AB-A8BE-ABD7717FB9BE}] => (Allow) C:\Program Files (x86)\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe (Free Time Co., Ltd. -> Free Time Co., Ltd.)
FirewallRules: [{BC510E15-3119-4BB5-8208-3DE4F39AFEFF}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{829E8B81-C22B-4DCB-A59C-511A847AC7F3}] => (Allow) C:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe (Digital Wave Ltd -> DVDVideoSoft Ltd.)
FirewallRules: [{445E3408-0AD7-49EB-80DF-A6081E3E7EDB}] => (Allow) C:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe (Digital Wave Ltd -> DVDVideoSoft Ltd.)
FirewallRules: [{52F90636-0AEE-43FC-8E9B-D4B4A6F7BAD1}] => (Allow) LPort=1900
FirewallRules: [{26941D43-D9C0-4DE6-80EA-D4216F70DC87}] => (Allow) LPort=2869
FirewallRules: [{87AA83E9-7B8B-4BE8-B82C-C82D38A9D9C0}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C9569C63-33A7-4324-818A-A44A18D55BB0}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Converter Studio\Video Converter Studio.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [{D4E94E25-4C19-4078-B4DE-0792E3399F1E}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Converter Studio\Video Converter Studio.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [{90A9A32D-DF2F-43E6-A2E8-1ABE40801F57}] => (Allow) C:\Users\Max\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{5C1B95DD-846D-489B-A297-B28DC2D3A9AB}] => (Allow) C:\Users\Max\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{03B6CE6E-94C5-43B4-BB71-6977BCD75751}] => (Allow) C:\Users\Max\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{97F0F7EA-E39E-48F8-9C3F-47FAB5C78A34}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{AD334138-0358-4751-8D19-E01888ABC368}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{494C34F5-7194-47D0-B9A1-014B5BCCE208}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BDABC988-DCE0-4F06-8FCD-BA561B93D7D6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FA7B34AE-9049-4A95-A12B-0F5A2286E690}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8A9C7586-EC59-46C8-B819-66728BCB3F6A}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3980DE44-12CB-462F-AFDD-A215C6999CA4}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{16D0C125-6785-41EA-8F71-CED813DE7AB0}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

==================== Restore Points =========================

12-04-2024 11:36:18 Removed Canon PhotoRecord
12-04-2024 11:37:20 Removed Canon Utilities ZoomBrowser EX

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (04/15/2024 07:27:48 AM) (Source: SecurityCenter) (EventID: 19) (User: )
Description: The Windows Security Center Service was unable to load instances of AntiVirusProduct from datastore.

Error: (04/15/2024 07:27:48 AM) (Source: SecurityCenter) (EventID: 18) (User: )
Description: The Windows Security Center Service was unable to load instances of FirewallProduct from datastore.

Error: (04/14/2024 06:26:10 PM) (Source: ESENT) (EventID: 455) (User: )
Description: DllHost (13660,R,98) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\Max\AppData\Local\Microsoft\Windows\WebCache\V01.log.

Error: (04/14/2024 06:26:09 PM) (Source: ESENT) (EventID: 490) (User: )
Description: DllHost (13660,R,98) WebCacheLocal: An attempt to open the file "C:\Users\Max\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).

Error: (04/14/2024 10:16:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x8007001f, A device attached to the system is not functioning..

Operation:
Executing Asynchronous Operation

Context:
Current State: DoSnapshotSet

Error: (04/14/2024 10:14:40 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied..This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
Gathering Writer Data

Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {bd5a75b6-6fbd-4f88-8706-0bf3813b32d9}

Error: (04/14/2024 07:28:12 AM) (Source: SecurityCenter) (EventID: 19) (User: )
Description: The Windows Security Center Service was unable to load instances of AntiVirusProduct from datastore.

Error: (04/14/2024 07:28:12 AM) (Source: SecurityCenter) (EventID: 18) (User: )
Description: The Windows Security Center Service was unable to load instances of FirewallProduct from datastore.


System errors:
=============
Error: (04/15/2024 08:52:16 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (04/15/2024 07:29:08 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba System Guard Runtime Monitor Broker sa pri spustení zablokovala.

Error: (04/15/2024 07:22:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby NativePushService zlyhalo kvôli nasledujúcej chybe:
The system cannot find the path specified.

Error: (04/15/2024 07:22:34 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 15:20:02 on ‎14. ‎4. ‎2024 was unexpected.

Error: (04/15/2024 07:21:54 AM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221225684A fatal error occurred processing the restoration data.

Error: (04/14/2024 03:21:20 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (04/14/2024 12:17:53 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (04/14/2024 09:18:51 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4


CodeIntegrity:
===============
Date: 2024-04-15 09:51:47
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. 0906 01/10/2013
Motherboard: ASUSTeK COMPUTER INC. P8H61-M LX3 R2.0
Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 71%
Total physical RAM: 4046.48 MB
Available physical RAM: 1157.69 MB
Total Virtual: 6734.48 MB
Available Virtual: 1971.03 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:201.16 GB) (Free:92.9 GB) (Model: WDC WD5000AZRX-00A8LB0 ATA Device) NTFS
Drive d: () (Fixed) (Total:263.72 GB) (Free:262.11 GB) (Model: WDC WD5000AZRX-00A8LB0 ATA Device) NTFS
Drive g: (Nový zväzok) (Fixed) (Total:200.09 GB) (Free:199.99 GB) (Model: FUJITSU MHZ2320BH G2 SCSI Disk Device) NTFS
Drive h: (Nový zväzok) (Fixed) (Total:98 GB) (Free:97.84 GB) (Model: FUJITSU MHZ2320BH G2 SCSI Disk Device) NTFS

\\?\Volume{8b5f4091-c3a2-11e2-be71-806e6f6e6963}\ (Vyhradené systémom) (Fixed) (Total:0.34 GB) (Free:0.28 GB) NTFS
\\?\Volume{bcec8508-0000-0000-0000-606032000000}\ () (Fixed) (Total:0.54 GB) (Free:0.05 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: BCEC8508)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=201.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=549 MB) - (Type=27)
Partition 4: (Not Active) - (Size=263.7 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (Size: 298.1 GB) (Disk ID: B0AAEBCF)
Partition 1: (Not Active) - (Size=200.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=98 GB) - (Type=07 NTFS)

==================== End of Addition.txt ======================

Re: Prosím o kontrolu

Napsal: 15 dub 2024 12:28
od Rudy
Zdravím!
Co je to za nesmysl? Dal jste sem jak FRST, tak Addition. To je vše, co potřebuji ke kontrole.
ADW- když rozkliknete položku "Soubor protokolu" Nejdete ho tam.
Otevřte poznámkový blok a zkopírujte do něj
Start

CloseProcesses:
Task: {DE43D6A4-B630-4AF6-8402-A1AB4B062D0B} - System32\Tasks\GoogleUpdateTaskMachineCore{83A06868-E161-4A84-AD3C-BA236529E53A} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.)
Task: {9160C80C-BB95-4DEB-8A7A-CD2C1364091A} - System32\Tasks\GoogleUpdateTaskMachineUA{D6FC7FCB-6850-4AA4-A60A-1336CB4A1DD9} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.)
S2 NativePushService; no ImagePath
S1 HWiNFO_190; no ImagePath
S3 pwdspio; no ImagePath
CustomCLSID: HKU\S-1-5-21-2923722727-4003214351-2683229-1002_Classes\CLSID\{9486aaf1-0930-362a-962d-8e6908739c817}\InprocServer32 -> 0xB749D8902584DA01D055E0902584DA01010000000A00000000000000 => No File
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO-x32: No Name -> {F9B65201-3D7F-48DA-AAB3-57A6FAD648FD} -> No File
Handler: WSKVAllmytubechrome - {91AB862D-07B8-4A85 - No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Prosím o kontrolu

Napsal: 15 dub 2024 13:44
od mapo44
Fix result of Farbar Recovery Scan Tool (x64) Version: 10.04.2024
Ran by Max (15-04-2024 14:30:24) Run:2
Running from C:\Users\Max\Desktop
Loaded Profiles: Max
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
Task: {DE43D6A4-B630-4AF6-8402-A1AB4B062D0B} - System32\Tasks\GoogleUpdateTaskMachineCore{83A06868-E161-4A84-AD3C-BA236529E53A} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.)
Task: {9160C80C-BB95-4DEB-8A7A-CD2C1364091A} - System32\Tasks\GoogleUpdateTaskMachineUA{D6FC7FCB-6850-4AA4-A60A-1336CB4A1DD9} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-26] (Google Inc -> Google Inc.)
S2 NativePushService; no ImagePath
S1 HWiNFO_190; no ImagePath
S3 pwdspio; no ImagePath
CustomCLSID: HKU\S-1-5-21-2923722727-4003214351-2683229-1002_Classes\CLSID\{9486aaf1-0930-362a-962d-8e6908739c817}\InprocServer32 -> 0xB749D8902584DA01D055E0902584DA01010000000A00000000000000 => No File
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO-x32: No Name -> {F9B65201-3D7F-48DA-AAB3-57A6FAD648FD} -> No File
Handler: WSKVAllmytubechrome - {91AB862D-07B8-4A85 - No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DE43D6A4-B630-4AF6-8402-A1AB4B062D0B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE43D6A4-B630-4AF6-8402-A1AB4B062D0B}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore{83A06868-E161-4A84-AD3C-BA236529E53A} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore{83A06868-E161-4A84-AD3C-BA236529E53A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9160C80C-BB95-4DEB-8A7A-CD2C1364091A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9160C80C-BB95-4DEB-8A7A-CD2C1364091A}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA{D6FC7FCB-6850-4AA4-A60A-1336CB4A1DD9} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA{D6FC7FCB-6850-4AA4-A60A-1336CB4A1DD9}" => removed successfully
HKLM\System\CurrentControlSet\Services\NativePushService => removed successfully
NativePushService => service removed successfully
HKLM\System\CurrentControlSet\Services\HWiNFO_190 => removed successfully
HWiNFO_190 => service removed successfully
HKLM\System\CurrentControlSet\Services\pwdspio => removed successfully
pwdspio => service removed successfully
HKU\S-1-5-21-2923722727-4003214351-2683229-1002_Classes\CLSID\{9486aaf1-0930-362a-962d-8e6908739c817} => removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Local Page"="C:\Windows\System32\blank.htm" => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Local Page"="C:\Windows\SysWOW64\blank.htm" => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9B65201-3D7F-48DA-AAB3-57A6FAD648FD} => removed successfully
HKLM\Software\Classes\PROTOCOLS\Handler\WSKVAllmytubechrome => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 53863477 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 343749 B
Edge => 0 B
Chrome => 287648281 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 20 B
systemprofile32 => 20 B
LocalService => 33426 B
NetworkService => 33426 B
Max => 58843327 B

RecycleBin => 0 B
EmptyTemp: => 383.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 14:31:39 ====

Re: Prosím o kontrolu

Napsal: 15 dub 2024 13:59
od Rudy
Vše smazáno, log je již OK.

Re: Prosím o kontrolu

Napsal: 15 dub 2024 14:20
od mapo44
Ďakujem pekne, ospravedlňujem sa za ten úvod, príjemný podvečer prajem. :worship:

Re: Prosím o kontrolu

Napsal: 15 dub 2024 14:46
od Rudy
Nic se neděje. Hezký den! :-)