Samovolný pohyb myši a samovolné otvírání prohlížeče
Napsal: 10 bře 2024 18:26
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.03.2024
Ran by Boss (administrator) on KACKA (10-03-2024 18:19:06)
Running from C:\Users\Boss\Desktop\FRST64.exe
Loaded Profiles: Boss
Platform: Microsoft Windows 10 Pro Version 22H2 19045.4046 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\WindowsApps\MSTeams_24004.1309.2689.2246_x64__8wekyb3d8bbwe\ms-teams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.80\msedgewebview2.exe <6>
(cmd.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(conhost.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\atieclxx.exe
(explorer.exe ->) (3369D7DB-FC10-4DBB-A701-31D053DEF758 -> The NW.js Community) C:\Program Files\WindowsApps\63685TenBrowser.TenBrowser_1.7.78.0_neutral__q4wt7ke8hpbsc\VFS\AppData\TenBrowser\TenBrowser.exe <8>
(explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(explorer.exe ->) (Scarlet.Crush Productions) [File not signed] C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_24004.1309.2689.2246_x64__8wekyb3d8bbwe\ms-teams.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\atiesrxx.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\NisSrv.exe
(services.exe ->) (Scarlet.Crush Productions) [File not signed] [File is in use] C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [739448 2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [138214768 2022-11-03] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" [66220968 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2598928 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [MicrosoftEdgeAutoLaunch_B14DBBE1EF03929244E921C90BE13BF3] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060608 2024-03-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [AMDNoiseSuppression] => "C:\Windows\system32\AMD\ANR\AMDNoiseSuppression.exe" (No File)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Boss\AppData\Local\Microsoft\Teams\Update.exe [2613704 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4388712 2024-02-29] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\MountPoints2: {560a23a1-0ce9-11ee-8d96-107b447c800e} - "F:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\122.0.6261.112\Installer\chrmstp.exe [2024-03-10] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScpToolkit Tray Notifications.lnk [2023-11-16]
ShortcutTarget: ScpToolkit Tray Notifications.lnk -> C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe (Scarlet.Crush Productions) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4A8F6895-275D-411C-8DE7-F2E4E1F6455B} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {0191411E-5E15-4461-AAA1-F78A6AA41DAC} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {D8D4AE93-6C2B-4AEC-8A70-CA52B75704E7} - System32\Tasks\GoogleUpdateTaskMachineCore{90BD869D-AEFD-4B37-97E2-E09EF29912CC} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162072 2023-05-23] (Google LLC -> Google LLC)
Task: {57D7A0C9-C9C3-415B-94BD-20C722858903} - System32\Tasks\GoogleUpdateTaskMachineUA{C8824E64-E38E-482D-98E3-556E7BDC451D} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162072 2023-05-23] (Google LLC -> Google LLC)
Task: {F47AA8C2-369F-48BF-A8B2-4805FCE6D29E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491856 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {9A418831-81E3-413B-B532-E16F0AEFA1B2} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491856 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {E2F8FB0D-1AEF-44E1-AC68-4115778E6A4B} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309320 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {864F3A59-9063-4D91-9E83-6B60F4764706} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309320 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {0C27CB30-0792-4BD1-85E9-424ADF68C7D9} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [170024 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {96EAC646-4CBC-47B5-9834-43DD7B8BCC3B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B90388C9-CF94-4650-892F-08CF0FF408BD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5BD5AA28-D015-43EC-B115-7E89C43D922A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B6DED1D1-3AEB-4FD8-8CF7-6A577A66B9DB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CB5C9A94-1D11-4198-B84D-717C42035532} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {D02BC8F4-4DB1-4744-BB50-8E20F43811A3} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671136 2024-02-24] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {563A8251-AD39-433F-A7C7-AC7C2AA1B402} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34720 2024-02-24] (Mozilla Corporation -> Mozilla Foundation)
Task: {20615B0A-257E-4FB6-9EF1-87BFEBACCBFE} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {D1100223-0CF2-4641-A2AB-7B402662D20F} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4194677476-3627657768-3988829947-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {58A22B38-D1DD-451C-932F-4539AF07AC81} - System32\Tasks\Opera scheduled Autoupdate 1685954649 => C:\Users\Boss\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {217A2C3A-2339-4A5C-84E7-76358C50F2FE} - System32\Tasks\Opera scheduled Autoupdate 1701959593 => C:\Users\Boss\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {914A219D-7963-4543-9885-1F16CF4AF0BA} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [59832 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {4EC054BD-ADF2-4CA5-A888-591C366F8B6F} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [291768 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {02776A18-1449-41A4-85BD-EA589F8FC419} - System32\Tasks\updater => C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [464384 2016-01-10] (Nefarius Software Solutions) [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{2c1f5d8d-c472-4be5-bf65-1aa1ea30054c}: [DhcpNameServer] 192.168.2.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Boss\AppData\Local\Microsoft\Edge\User Data\Default [2024-02-27]
Edge Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-09]
Edge Extension: (Edge relevant text changes) - C:\Users\Boss\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-24]
FireFox:
========
FF DefaultProfile: 5og8wrwc.default
FF ProfilePath: C:\Users\Boss\AppData\Roaming\Mozilla\Firefox\Profiles\5og8wrwc.default [2023-09-10]
FF ProfilePath: C:\Users\Boss\AppData\Roaming\Mozilla\Firefox\Profiles\wl6337xl.default-release [2024-02-06]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-02-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @java.com/DTPlugin,version=11.371.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.371.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-02-05] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Default [2024-03-10]
CHR Notifications: Default -> hxxps://mail.google.com; hxxps://www.filehorse.com; hxxps://www.youtube.com
CHR Session Restore: Default -> is enabled.
CHR Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-02-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-05-23]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-01-27]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-03-10]
CHR Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-10]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-09-16]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 2 [2024-02-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-02-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-13]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\System Profile [2024-03-10]
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14097992 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
R2 Ds3Service; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [389632 2016-01-10] (Scarlet.Crush Productions) [File not signed] [File is in use] <==== ATTENTION
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\24.025.0204.0003\FileSyncHelper.exe [3516848 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\24.025.0204.0003\OneDriveUpdaterService.exe [3853744 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [534472 2023-12-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 updater; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [464384 2016-01-10] (Nefarius Software Solutions) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\NisSrv.exe [3191256 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MsMpEng.exe [133576 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [25560 2023-04-12] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\Windows\System32\DriverStore\FileRepository\amdsafd.inf_amd64_1a1a381a2c0e293c\amdsafd.sys [113056 2022-08-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 AmdTools64; C:\Windows\System32\drivers\AmdTools64.sys [77240 2022-07-18] (Advanced Micro Devices Inc. -> AMD)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\amdkmdag.sys [100296072 2023-05-23] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\Windows\System32\drivers\amdxe.sys [59920 2022-05-31] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 libusbK; C:\Windows\System32\drivers\libusbK.sys [47200 2023-11-16] (Travis Lee Robinson -> hxxp://libusb-win32.sourceforge.net)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2023-05-23] (ASUSTeK Computer Inc. -> )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21040 2024-02-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [608648 2024-02-29] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105752 2024-02-29] (Microsoft Windows -> Microsoft Corporation)
S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-10 18:19 - 2024-03-10 18:20 - 000021465 _____ C:\Users\Boss\Desktop\FRST.txt
2024-03-10 18:17 - 2024-03-10 18:19 - 000000000 ____D C:\FRST
2024-03-10 18:15 - 2024-03-10 18:15 - 002390016 _____ (Farbar) C:\Users\Boss\Desktop\FRST64.exe
2024-03-10 17:40 - 2024-03-10 17:40 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-02-24 22:04 - 2024-02-24 23:37 - 000000000 ____D C:\Users\Boss\Desktop\Chlapec
2024-02-24 16:43 - 2024-02-24 16:53 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\PowerPoint
2024-02-16 21:11 - 2024-02-16 21:11 - 000019697 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-02-16 21:10 - 2024-02-16 21:10 - 000019697 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-02-16 21:01 - 2024-02-16 21:01 - 000000000 ___HD C:\$WinREAgent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-10 18:16 - 2023-05-23 13:03 - 000000000 ____D C:\Program Files (x86)\Google
2024-03-10 18:16 - 2022-09-08 04:11 - 000000000 ____D C:\Windows\SystemTemp
2024-03-10 18:12 - 2021-05-22 23:09 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-03-10 18:08 - 2023-12-28 19:04 - 000000000 ____D C:\Program Files (x86)\Steam
2024-03-10 17:53 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-03-10 17:53 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2024-03-10 17:52 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-03-10 17:45 - 2023-05-23 13:02 - 000000000 ____D C:\Users\Boss\AppData\Local\D3DSCache
2024-03-10 17:43 - 2023-10-30 20:23 - 000002398 _____ C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams classic.lnk
2024-03-10 17:43 - 2023-10-30 20:22 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\Teams
2024-03-10 17:43 - 2023-10-30 20:22 - 000000000 ____D C:\Users\Boss\AppData\Local\SquirrelTemp
2024-03-10 17:40 - 2023-12-17 18:06 - 000000000 ____D C:\Program Files\Microsoft Office
2024-03-10 17:34 - 2021-05-22 23:09 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-03-10 17:31 - 2023-05-23 12:53 - 000000000 ____D C:\Users\Boss\AppData\Local\AMD_Common
2024-03-10 17:28 - 2023-12-18 20:05 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2024-03-10 17:28 - 2023-12-17 17:55 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2024-03-10 17:28 - 2023-12-17 17:55 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-03-10 17:28 - 2023-05-23 12:47 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4194677476-3627657768-3988829947-1001
2024-03-10 17:28 - 2021-05-22 23:09 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-03-10 17:28 - 2021-05-22 23:09 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-03-10 17:27 - 2023-05-23 13:04 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-03-10 17:27 - 2023-05-23 13:04 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-03-10 17:25 - 2023-06-05 09:11 - 000003096 _____ C:\Windows\system32\Tasks\AMDInstallLauncher
2024-03-10 17:25 - 2023-06-05 09:11 - 000003088 _____ C:\Windows\system32\Tasks\AMDLinkUpdate
2024-02-29 20:52 - 2023-05-23 13:07 - 000000000 ____D C:\Users\Boss\AppData\Local\ClassicShell
2024-02-29 18:09 - 2021-05-22 23:09 - 000000000 ____D C:\Windows\system32\Drivers\wd
2024-02-27 17:02 - 2023-06-05 09:34 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\Word
2024-02-27 17:02 - 2023-06-05 09:34 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\Excel
2024-02-27 16:50 - 2023-09-16 18:09 - 000000000 ____D C:\Users\Boss\AppData\Local\CrashDumps
2024-02-25 22:39 - 2023-05-23 12:49 - 001605602 _____ C:\Windows\system32\PerfStringBackup.INI
2024-02-25 22:39 - 2019-12-07 15:43 - 000682184 _____ C:\Windows\system32\perfh005.dat
2024-02-25 22:39 - 2019-12-07 15:43 - 000137000 _____ C:\Windows\system32\perfc005.dat
2024-02-25 22:39 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2024-02-25 14:12 - 2024-01-13 17:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-02-25 14:12 - 2023-09-09 13:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-02-25 14:12 - 2021-05-22 23:09 - 000454096 _____ C:\Windows\system32\FNTCACHE.DAT
2024-02-25 14:12 - 2021-05-22 23:09 - 000008192 ___SH C:\DumpStack.log.tmp
2024-02-25 14:12 - 2021-05-22 23:09 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-02-25 00:31 - 2023-05-23 12:57 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2024-02-25 00:31 - 2019-12-07 10:03 - 000262144 _____ C:\Windows\system32\config\BBI
2024-02-25 00:30 - 2019-12-07 15:47 - 000000000 ___SD C:\Windows\system32\AppV
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\setup
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\migwiz
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellComponents
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2024-02-24 15:20 - 2023-09-10 12:20 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-02-16 21:16 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2024-02-16 21:10 - 2021-05-22 23:13 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-02-16 21:00 - 2023-05-23 13:01 - 000000000 ____D C:\Windows\system32\MRT
2024-02-16 20:58 - 2023-05-23 13:00 - 191155960 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-02-16 20:23 - 2019-12-07 10:03 - 000032768 _____ C:\Windows\system32\config\ELAM
2024-02-11 16:16 - 2021-05-22 23:12 - 000000000 ____D C:\Users\Boss\AppData\Local\Packages
==================== Files in the root of some directories ========
2023-11-15 16:58 - 2023-11-15 16:58 - 010571443 _____ () C:\Program Files (x86)\SCP-DS-Driver-Package-1.2.0.160.7z
2023-06-02 10:04 - 2023-06-02 10:04 - 000000001 _____ () C:\Users\Boss\AppData\Local\llftool.4.40.agreement
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by Boss (administrator) on KACKA (10-03-2024 18:19:06)
Running from C:\Users\Boss\Desktop\FRST64.exe
Loaded Profiles: Boss
Platform: Microsoft Windows 10 Pro Version 22H2 19045.4046 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\WindowsApps\MSTeams_24004.1309.2689.2246_x64__8wekyb3d8bbwe\ms-teams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.80\msedgewebview2.exe <6>
(cmd.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(conhost.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\atieclxx.exe
(explorer.exe ->) (3369D7DB-FC10-4DBB-A701-31D053DEF758 -> The NW.js Community) C:\Program Files\WindowsApps\63685TenBrowser.TenBrowser_1.7.78.0_neutral__q4wt7ke8hpbsc\VFS\AppData\TenBrowser\TenBrowser.exe <8>
(explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(explorer.exe ->) (Scarlet.Crush Productions) [File not signed] C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_24004.1309.2689.2246_x64__8wekyb3d8bbwe\ms-teams.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\atiesrxx.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\NisSrv.exe
(services.exe ->) (Scarlet.Crush Productions) [File not signed] [File is in use] C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [739448 2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [138214768 2022-11-03] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" [66220968 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2598928 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [MicrosoftEdgeAutoLaunch_B14DBBE1EF03929244E921C90BE13BF3] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060608 2024-03-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [AMDNoiseSuppression] => "C:\Windows\system32\AMD\ANR\AMDNoiseSuppression.exe" (No File)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Boss\AppData\Local\Microsoft\Teams\Update.exe [2613704 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4388712 2024-02-29] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-4194677476-3627657768-3988829947-1001\...\MountPoints2: {560a23a1-0ce9-11ee-8d96-107b447c800e} - "F:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\122.0.6261.112\Installer\chrmstp.exe [2024-03-10] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScpToolkit Tray Notifications.lnk [2023-11-16]
ShortcutTarget: ScpToolkit Tray Notifications.lnk -> C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe (Scarlet.Crush Productions) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4A8F6895-275D-411C-8DE7-F2E4E1F6455B} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {0191411E-5E15-4461-AAA1-F78A6AA41DAC} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {D8D4AE93-6C2B-4AEC-8A70-CA52B75704E7} - System32\Tasks\GoogleUpdateTaskMachineCore{90BD869D-AEFD-4B37-97E2-E09EF29912CC} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162072 2023-05-23] (Google LLC -> Google LLC)
Task: {57D7A0C9-C9C3-415B-94BD-20C722858903} - System32\Tasks\GoogleUpdateTaskMachineUA{C8824E64-E38E-482D-98E3-556E7BDC451D} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162072 2023-05-23] (Google LLC -> Google LLC)
Task: {F47AA8C2-369F-48BF-A8B2-4805FCE6D29E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491856 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {9A418831-81E3-413B-B532-E16F0AEFA1B2} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491856 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {E2F8FB0D-1AEF-44E1-AC68-4115778E6A4B} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309320 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {864F3A59-9063-4D91-9E83-6B60F4764706} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309320 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {0C27CB30-0792-4BD1-85E9-424ADF68C7D9} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [170024 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {96EAC646-4CBC-47B5-9834-43DD7B8BCC3B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B90388C9-CF94-4650-892F-08CF0FF408BD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5BD5AA28-D015-43EC-B115-7E89C43D922A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B6DED1D1-3AEB-4FD8-8CF7-6A577A66B9DB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MpCmdRun.exe [1646000 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CB5C9A94-1D11-4198-B84D-717C42035532} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {D02BC8F4-4DB1-4744-BB50-8E20F43811A3} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671136 2024-02-24] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {563A8251-AD39-433F-A7C7-AC7C2AA1B402} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34720 2024-02-24] (Mozilla Corporation -> Mozilla Foundation)
Task: {20615B0A-257E-4FB6-9EF1-87BFEBACCBFE} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {D1100223-0CF2-4641-A2AB-7B402662D20F} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4194677476-3627657768-3988829947-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {58A22B38-D1DD-451C-932F-4539AF07AC81} - System32\Tasks\Opera scheduled Autoupdate 1685954649 => C:\Users\Boss\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {217A2C3A-2339-4A5C-84E7-76358C50F2FE} - System32\Tasks\Opera scheduled Autoupdate 1701959593 => C:\Users\Boss\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {914A219D-7963-4543-9885-1F16CF4AF0BA} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [59832 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {4EC054BD-ADF2-4CA5-A888-591C366F8B6F} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [291768 2023-05-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {02776A18-1449-41A4-85BD-EA589F8FC419} - System32\Tasks\updater => C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [464384 2016-01-10] (Nefarius Software Solutions) [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{2c1f5d8d-c472-4be5-bf65-1aa1ea30054c}: [DhcpNameServer] 192.168.2.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Boss\AppData\Local\Microsoft\Edge\User Data\Default [2024-02-27]
Edge Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-09]
Edge Extension: (Edge relevant text changes) - C:\Users\Boss\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-24]
FireFox:
========
FF DefaultProfile: 5og8wrwc.default
FF ProfilePath: C:\Users\Boss\AppData\Roaming\Mozilla\Firefox\Profiles\5og8wrwc.default [2023-09-10]
FF ProfilePath: C:\Users\Boss\AppData\Roaming\Mozilla\Firefox\Profiles\wl6337xl.default-release [2024-02-06]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-02-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @java.com/DTPlugin,version=11.371.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.371.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-02-05] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Default [2024-03-10]
CHR Notifications: Default -> hxxps://mail.google.com; hxxps://www.filehorse.com; hxxps://www.youtube.com
CHR Session Restore: Default -> is enabled.
CHR Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-02-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-05-23]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-01-27]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-03-10]
CHR Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-10]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-09-16]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 2 [2024-02-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-02-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Boss\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-13]
CHR Profile: C:\Users\Boss\AppData\Local\Google\Chrome\User Data\System Profile [2024-03-10]
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14097992 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
R2 Ds3Service; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [389632 2016-01-10] (Scarlet.Crush Productions) [File not signed] [File is in use] <==== ATTENTION
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\24.025.0204.0003\FileSyncHelper.exe [3516848 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\24.025.0204.0003\OneDriveUpdaterService.exe [3853744 2024-03-10] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [534472 2023-12-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 updater; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [464384 2016-01-10] (Nefarius Software Solutions) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\NisSrv.exe [3191256 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MsMpEng.exe [133576 2024-02-29] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [25560 2023-04-12] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\Windows\System32\DriverStore\FileRepository\amdsafd.inf_amd64_1a1a381a2c0e293c\amdsafd.sys [113056 2022-08-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 AmdTools64; C:\Windows\System32\drivers\AmdTools64.sys [77240 2022-07-18] (Advanced Micro Devices Inc. -> AMD)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0392064.inf_amd64_f5afb73c644105f0\B392017\amdkmdag.sys [100296072 2023-05-23] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\Windows\System32\drivers\amdxe.sys [59920 2022-05-31] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 libusbK; C:\Windows\System32\drivers\libusbK.sys [47200 2023-11-16] (Travis Lee Robinson -> hxxp://libusb-win32.sourceforge.net)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2023-05-23] (ASUSTeK Computer Inc. -> )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21040 2024-02-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [608648 2024-02-29] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105752 2024-02-29] (Microsoft Windows -> Microsoft Corporation)
S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-10 18:19 - 2024-03-10 18:20 - 000021465 _____ C:\Users\Boss\Desktop\FRST.txt
2024-03-10 18:17 - 2024-03-10 18:19 - 000000000 ____D C:\FRST
2024-03-10 18:15 - 2024-03-10 18:15 - 002390016 _____ (Farbar) C:\Users\Boss\Desktop\FRST64.exe
2024-03-10 17:40 - 2024-03-10 17:40 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-02-24 22:04 - 2024-02-24 23:37 - 000000000 ____D C:\Users\Boss\Desktop\Chlapec
2024-02-24 16:43 - 2024-02-24 16:53 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\PowerPoint
2024-02-16 21:11 - 2024-02-16 21:11 - 000019697 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-02-16 21:10 - 2024-02-16 21:10 - 000019697 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-02-16 21:01 - 2024-02-16 21:01 - 000000000 ___HD C:\$WinREAgent
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-03-10 18:16 - 2023-05-23 13:03 - 000000000 ____D C:\Program Files (x86)\Google
2024-03-10 18:16 - 2022-09-08 04:11 - 000000000 ____D C:\Windows\SystemTemp
2024-03-10 18:12 - 2021-05-22 23:09 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-03-10 18:08 - 2023-12-28 19:04 - 000000000 ____D C:\Program Files (x86)\Steam
2024-03-10 17:53 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-03-10 17:53 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2024-03-10 17:52 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-03-10 17:45 - 2023-05-23 13:02 - 000000000 ____D C:\Users\Boss\AppData\Local\D3DSCache
2024-03-10 17:43 - 2023-10-30 20:23 - 000002398 _____ C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams classic.lnk
2024-03-10 17:43 - 2023-10-30 20:22 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\Teams
2024-03-10 17:43 - 2023-10-30 20:22 - 000000000 ____D C:\Users\Boss\AppData\Local\SquirrelTemp
2024-03-10 17:40 - 2023-12-17 18:06 - 000000000 ____D C:\Program Files\Microsoft Office
2024-03-10 17:34 - 2021-05-22 23:09 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-03-10 17:31 - 2023-05-23 12:53 - 000000000 ____D C:\Users\Boss\AppData\Local\AMD_Common
2024-03-10 17:28 - 2023-12-18 20:05 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2024-03-10 17:28 - 2023-12-17 17:55 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2024-03-10 17:28 - 2023-12-17 17:55 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-03-10 17:28 - 2023-05-23 12:47 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4194677476-3627657768-3988829947-1001
2024-03-10 17:28 - 2021-05-22 23:09 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-03-10 17:28 - 2021-05-22 23:09 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-03-10 17:27 - 2023-05-23 13:04 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-03-10 17:27 - 2023-05-23 13:04 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-03-10 17:25 - 2023-06-05 09:11 - 000003096 _____ C:\Windows\system32\Tasks\AMDInstallLauncher
2024-03-10 17:25 - 2023-06-05 09:11 - 000003088 _____ C:\Windows\system32\Tasks\AMDLinkUpdate
2024-02-29 20:52 - 2023-05-23 13:07 - 000000000 ____D C:\Users\Boss\AppData\Local\ClassicShell
2024-02-29 18:09 - 2021-05-22 23:09 - 000000000 ____D C:\Windows\system32\Drivers\wd
2024-02-27 17:02 - 2023-06-05 09:34 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\Word
2024-02-27 17:02 - 2023-06-05 09:34 - 000000000 ____D C:\Users\Boss\AppData\Roaming\Microsoft\Excel
2024-02-27 16:50 - 2023-09-16 18:09 - 000000000 ____D C:\Users\Boss\AppData\Local\CrashDumps
2024-02-25 22:39 - 2023-05-23 12:49 - 001605602 _____ C:\Windows\system32\PerfStringBackup.INI
2024-02-25 22:39 - 2019-12-07 15:43 - 000682184 _____ C:\Windows\system32\perfh005.dat
2024-02-25 22:39 - 2019-12-07 15:43 - 000137000 _____ C:\Windows\system32\perfc005.dat
2024-02-25 22:39 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2024-02-25 14:12 - 2024-01-13 17:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-02-25 14:12 - 2023-09-09 13:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-02-25 14:12 - 2021-05-22 23:09 - 000454096 _____ C:\Windows\system32\FNTCACHE.DAT
2024-02-25 14:12 - 2021-05-22 23:09 - 000008192 ___SH C:\DumpStack.log.tmp
2024-02-25 14:12 - 2021-05-22 23:09 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-02-25 00:31 - 2023-05-23 12:57 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2024-02-25 00:31 - 2019-12-07 10:03 - 000262144 _____ C:\Windows\system32\config\BBI
2024-02-25 00:30 - 2019-12-07 15:47 - 000000000 ___SD C:\Windows\system32\AppV
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\setup
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\migwiz
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellComponents
2024-02-25 00:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2024-02-24 15:20 - 2023-09-10 12:20 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-02-16 21:16 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2024-02-16 21:10 - 2021-05-22 23:13 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-02-16 21:00 - 2023-05-23 13:01 - 000000000 ____D C:\Windows\system32\MRT
2024-02-16 20:58 - 2023-05-23 13:00 - 191155960 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-02-16 20:23 - 2019-12-07 10:03 - 000032768 _____ C:\Windows\system32\config\ELAM
2024-02-11 16:16 - 2021-05-22 23:12 - 000000000 ____D C:\Users\Boss\AppData\Local\Packages
==================== Files in the root of some directories ========
2023-11-15 16:58 - 2023-11-15 16:58 - 010571443 _____ () C:\Program Files (x86)\SCP-DS-Driver-Package-1.2.0.160.7z
2023-06-02 10:04 - 2023-06-02 10:04 - 000000001 _____ () C:\Users\Boss\AppData\Local\llftool.4.40.agreement
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================