usporen rad svega.

usporen rad svega.

offline
  • Pridružio: 04 Sep 2008
  • Poruke: 28

Napisano: 30 Apr 2025 19:35

prvenstveno se zalim na rad Chroma i programa za rad. Skinuo Malwarebytes, ocistio sta mi je rekao da ima da se ocisti, ali i dalje je sve usporeno.

Hvala unapred

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2025
Ran by slave (administrator) on SLAVEN (30-04-2025 14:08:01)
Running from C:\Users\slave\Downloads\FRST64.exe
Loaded Profiles: slave
Platform: Microsoft Windows 11 Pro Version 24H2 26100.3915 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\GXT155mon.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe InDesign 2025\Adobe Crash Processor.exe
(Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <6>
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud Helper.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Creative Cloud UI Helper.exe <4>
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <2>
(C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\107.0.3.0\crashpad_handler.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(cmd.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(cmd.exe ->) (Lenovo (Beijing) Limited -> Lenovo Group Limited) C:\Users\slave\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
(Discord Inc. -> Discord Inc.) C:\Users\slave\AppData\Local\Discord\app-1.0.9189\Discord.exe <6>
(DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\atieclxx.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <8>
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <48>
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Telegram FZ-LLC -> Telegram FZ-LLC) C:\Users\slave\AppData\Roaming\Telegram Desktop\Telegram.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (Viber Media S.a r.l. -> Viber Media S.à r.l.) C:\Users\slave\AppData\Local\Viber\Viber.exe
(Kilonova LLC -> Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\atiesrxx.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(services.exe ->) (Eastern Times Technology Co.,Ltd -> ) C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\ETGMSrv.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_05bfde18331c4d58\amdfendrsr.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25032.52.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(Slack Technologies, LLC -> Slack Technologies Inc.) C:\Users\slave\AppData\Local\slack\app-4.43.52\slack.exe <7>
(svchost.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\WindowsApps\AdobeNotificationClient_6.0.0.1_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(svchost.exe ->) (Adobe Systems Incorporated -> ) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(svchost.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\CPUMetricsServer.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2504.1001.26.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [455976 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [10752424 2025-01-14] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [9238408 2025-04-29] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226728 2019-07-21] (Kilonova LLC -> )
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [133128 2024-09-09] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [1145256 2025-04-12] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [GXT155gmmouseRun] => C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\GXT155mon.exe [3435520 2018-06-10] () [File not signed]
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" [89199416 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5014344 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4693600 2025-04-21] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Discord] => C:\Users\slave\AppData\Local\Discord\Update.exe [1526504 2024-09-04] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [41351584 2025-04-09] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [AMDNoiseSuppression] => C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe [164840 2024-06-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3814496 2025-04-16] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Viber] => C:\Users\slave\AppData\Local\Viber\Viber.exe [101727064 2025-04-15] (Viber Media S.a r.l. -> Viber Media S.à r.l.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [com.squirrel.slack.slack] => C:\Users\slave\AppData\Local\slack\slack.exe [307504 2025-04-21] (Slack Technologies, LLC -> Slack Technologies Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [203936 2024-08-08] (Adobe Inc. -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.115\Installer\chrmstp.exe [2025-04-24] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
Startup: C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk [2025-03-22]
ShortcutTarget: Telegram.lnk -> C:\Users\slave\AppData\Roaming\Telegram Desktop\Telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {9E30966E-B457-429B-A3C3-6C989BC5D905} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {63FAA669-6604-4AE3-A5DC-F8DC93B4CF00} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [10752424 2025-01-14] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {1D052E57-6DB5-40E8-9C6F-D477C1BC7B86} - System32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [11065256 2025-01-14] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {B320F0DE-1106-47DC-AF6F-A848DDCBBD29} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [191184 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {3279D5E6-697C-401C-8C76-83E8E0CFF2F1} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [8594216 2025-03-27] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {7F12FB08-3C7E-43F5-B79A-D64F474085B4} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5293864 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {1A746C7A-25AD-47FE-987B-3B84218F8324} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2564904 2024-11-20] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {9ACDDAA7-33A6-49FB-A322-C631F43D45C9} - System32\Tasks\com.amazon.kpr.ncd => C:\Users\slave\AppData\Local\Amazon\Kindle Previewer 3\KPR_NCD.exe [2110976 2025-02-22] () [File not signed] <==== ATTENTION
Task: {CB63873D-8CC5-424E-A890-482DE5DBAA19} - System32\Tasks\DropboxSystem\DropboxUpdater\DropboxUpdaterTaskSystem123.0.6299.109{7D11D58F-B00A-4DE1-B0E0-7115DF5C926E} => C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.109\updater.exe [5895032 2025-03-21] (Dropbox, Inc -> Dropbox, Inc.)
Task: {764BB0DE-B8D3-4FE2-88DF-9B586BF18394} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem137.0.7129.0{EBE383F0-3F59-4EBC-AC26-0534E493D647} => C:\Program Files (x86)\Google\GoogleUpdater\137.0.7129.0\updater.exe [7375968 2025-04-17] (Google LLC -> Google LLC)
Task: {3B4DAD8D-A83E-41DC-8C7F-199D26826751} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Users\slave\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [88584 2024-05-17] (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {18DD42D1-7E6B-4C1F-A65E-159E1F0403DC} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28609776 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {0508B5A8-8226-4CFC-8354-F04DBAD3DA0A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28609776 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {E35FD19C-596E-48D3-A5FC-5B1629A559AA} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312496 2025-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {3FDA71EE-94BC-4060-BA98-9EC0E04C00E3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312496 2025-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {A3BF75D2-B16C-46CC-B081-5E44597D11A0} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [187024 2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {A4BC5BB3-44A2-49F0-9451-922CBF3FE14B} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
Task: {31110D7F-072A-4E09-BC1A-CED57AC3FD91} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {E9C827BA-D336-4C20-AA62-9DA77B48E4F8} - System32\Tasks\Microsoft\Windows\WindowsAI\Recall\InitialConfiguration => {709FD5EF-7296-4154-BD3A-E9830FCFA60A} C:\WINDOWS\system32\ShellConfigTask.dll [274432 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
Task: {3DB47973-12DF-40A1-886A-1FF7A2602520} - System32\Tasks\Microsoft\Windows\WindowsAI\Recall\PolicyConfiguration => {0BE6820D-B667-4CB6-931B-C153A77DA895} C:\WINDOWS\system32\ShellConfigTask.dll [274432 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
Task: {49035FB4-38CC-41EB-9485-4EF706EEA4D8} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1035472 2024-11-28] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {CF51999A-6D62-410E-9D62-B6E7CFB19D4E} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223832 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {A44FB663-60DF-4DD1-A4DD-0D04A5EC8DDB} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223832 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {73811D01-6460-4142-B62A-C39B25212B4E} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Program Files\Microsoft OneDrive\25.065.0406.0002\OneDriveLauncher.exe [679232 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {1CD58D9D-BCAA-4E6E-99A7-5604DF0CA572} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [139472 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {93444334-A9DB-467E-8096-722A5529C4F1} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [309968 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {38461FA3-8FA8-4702-B242-FBB2C706D015} - System32\Tasks\update-S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
Task: {B13E6279-CEB8-44AD-8108-5D1B924E7B0F} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\update-S-1-5-21-2574191415-932531762-3141445119-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1
Tcpip\..\Interfaces\{bd7b7a99-eaf3-494d-8be1-924251d80c94}: [DhcpNameServer] 192.168.8.1

Edge:
=======
Edge Profile: C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default [2025-04-27]
Edge Extension: (Table Capture) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cjlemjohnmihejeecaoaglgejaokmclj [2025-02-14]
Edge Extension: (GoFullPage - Full Page Screen Capture) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2024-10-28]
Edge Extension: (Google Docs Offline) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-02-04]
Edge Extension: (Adblock Plus - free ad blocker) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2025-02-26]
Edge Extension: (Auto Refresh Plus | Page Monitor) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hgeljhfekpckiiplhkigfehkdpldcggm [2024-10-28]
Edge Extension: (Feeder - RSS Feed Reader) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jlkhefogiiibhgblliimeleiiiijbkjj [2024-10-28]
Edge Extension: (Edge relevant text changes) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-09-09]
Edge Extension: (AdBlock — block ads across the web) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2025-02-19]

FireFox:
========
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2021-02-01]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @java.com/DTPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\dtplugin\npDeployJava1.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\plugin2\npjp2.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-04-09] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2025-04-12] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2025-04-12] (Adobe Inc. -> Adobe Systems)

Chrome:
=======
CHR Profile: C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default [2025-04-30]
CHR Notifications: Default -> [Link mogu videti samo ulogovani korisnici]
CHR HomePage: Default -> [Link mogu videti samo ulogovani korisnici]
CHR StartupUrls: Default -> "hxxps://www.fiverr.com/users/slaven980/seller_dashboard","hxxps://www.upwork.com/nx/find-work/","hxxps://www.facebook.com/","hxxps://mail.google.com/mail/u/0/#inbox","hxxps://mail.yahoo.com/d/folders/1","hxxps://medierogledelse.roxen.com/","hxxps://trello.com/b/tCs8vhW5/prelom-knjiga"
CHR Extension: (Strata) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihlahcemjcnhakkkclcohelfdleejmc [2024-09-09]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2025-04-26]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-04-30]
CHR Extension: (Free Rider HD) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\emikpifndnjfkgofoglceekhkbaicbde [2024-09-09]
CHR Extension: (GoFullPage - Full Page Screen Capture) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2025-03-23]
CHR Extension: (Causality Games) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\femoooemgmjaebeodbbikbkmhlafenpl [2024-09-09]
CHR Extension: (Readium) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\fepbnnnkkadjhjahcafoaglimekefifl [2024-09-09]
CHR Extension: (Google Docs Offline) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-24]
CHR Extension: (AdBlock — block ads across the web) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2025-04-21]
CHR Extension: (Auto Refresh Plus | Page Monitor) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgeljhfekpckiiplhkigfehkdpldcggm [2024-09-09]
CHR Extension: (Table Capture) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\iebpjdmgckacbodjpijphcplhebcmeop [2025-03-21]
CHR Extension: (Hootsuite) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2024-09-09]
CHR Extension: (Little Alchemy) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2024-09-09]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-10-01]
CHR Extension: (Google Play Books) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2024-09-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-09-09]
CHR Extension: (Volume booster - Increase Volume) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogadflejmplcdhcldlloonbiekhnlopp [2025-04-30]
CHR Extension: (RSS Feed Reader) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2025-03-25]
CHR Extension: (Canvas Rider) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk [2024-09-09]
CHR HKU\S-1-5-21-2574191415-932531762-3141445119-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-2574191415-932531762-3141445119-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [944040 2025-04-12] (Adobe Inc. -> Adobe Inc.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7500072 2025-04-09] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [807208 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [859432 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2024-09-09] (Avast Software s.r.o. -> AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14044936 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
R2 DbxSvc; C:\WINDOWS\System32\DbxSvc.exe [58984 2025-04-29] (Dropbox, Inc -> Dropbox, Inc.)
S3 DropboxElevationService; C:\Program Files (x86)\Dropbox\Client\223.4.4909\DropboxElevationService.exe [1659280 2025-04-29] (Dropbox, Inc -> Dropbox, Inc.)
S2 DropboxUpdaterInternalService123.0.6299.109; C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.109\updater.exe [5895032 2025-03-21] (Dropbox, Inc -> Dropbox, Inc.)
S2 DropboxUpdaterService123.0.6299.109; C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.109\updater.exe [5895032 2025-03-21] (Dropbox, Inc -> Dropbox, Inc.)
R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [18709600 2025-04-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 ETGMGlcsSrv; C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\ETGMSrv.exe [1181544 2012-04-24] (Eastern Times Technology Co.,Ltd -> )
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.065.0406.0002\FileSyncHelper.exe [3587904 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9406208 2025-04-30] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-04-30] (Malwarebytes Inc. -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.065.0406.0002\OneDriveUpdaterService.exe [3841360 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559320 2025-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ZTHELPER; C:\WINDOWS\System32\zthelper.dll [146096 2025-04-26] (Microsoft Windows -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdfendrmgr; C:\WINDOWS\System32\DriverStore\FileRepository\amdfendr.inf_amd64_05bfde18331c4d58\amdfendrmgr.sys [36016 2024-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33592 2024-09-12] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
S2 AMDRyzenMasterDriverV26; C:\Windows\system32\AMDRyzenMasterDriver.sys [61264 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices)
R2 AMDRyzenMasterDriverV27; C:\WINDOWS\system32\AMDRyzenMasterDriver.sys [61264 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_d4de13a10f2586d0\amdsafd.sys [112952 2024-06-15] (AMD Test Build -> Advanced Micro Devices)
R3 amduw23g; C:\WINDOWS\System32\DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\amdkmdag.sys [110965144 2024-12-04] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [63008 2024-05-16] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [20536 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [248376 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [393272 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [296528 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [84560 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [28280 2024-11-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [37944 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [282680 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [553528 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [98872 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [69688 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [942672 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1427512 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [207440 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [391760 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 googledrivefs31626; C:\Program Files\Google\Drive File Stream\Drivers\31626\googledrivefs31626.sys [384096 2024-10-01] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-04-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt11.sys [241112 2025-04-30] (Malwarebytes Inc. -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [80448 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [189776 2025-04-30] (Malwarebytes Inc. -> Malwarebytes)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-03-27] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
R3 usbglcs1100302; C:\WINDOWS\system32\drivers\usbglcs1100302.sys [25600 2014-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [22080 2024-09-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [602504 2024-09-09] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105864 2024-09-09] (Microsoft Windows -> Microsoft Corporation)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_8d863c975b4367df\wini3ctarget.sys [79288 2025-04-26] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-04-30 14:08 - 2025-04-30 14:08 - 000039140 _____ C:\Users\slave\Downloads\FRST.txt
2025-04-30 14:07 - 2025-04-30 14:08 - 000000000 ____D C:\FRST
2025-04-30 14:07 - 2025-04-30 14:07 - 002405376 _____ (Farbar) C:\Users\slave\Downloads\FRST64.exe
2025-04-30 13:59 - 2025-04-30 13:59 - 000241112 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt11.sys
2025-04-30 13:59 - 2025-04-30 13:59 - 000189776 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2025-04-30 13:59 - 2025-04-30 13:59 - 000000000 ____D C:\Users\slave\AppData\LocalLow\IGDump
2025-04-30 13:58 - 2025-04-30 13:58 - 002834160 _____ (Malwarebytes) C:\Users\slave\Downloads\MBSetup (1).exe
2025-04-30 13:54 - 2025-04-30 14:04 - 000000000 ____D C:\Users\slave\AppData\Local\Malwarebytes
2025-04-30 13:54 - 2025-04-30 13:54 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2025-04-30 13:54 - 2025-04-30 13:54 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-04-30 13:54 - 2025-04-30 13:54 - 000000000 ____D C:\Program Files\Malwarebytes
2025-04-30 13:53 - 2025-04-30 13:53 - 002834160 _____ (Malwarebytes) C:\Users\slave\Downloads\MBSetup.exe
2025-04-30 13:38 - 2025-04-30 13:38 - 000001026 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InCopy 2025.lnk
2025-04-30 12:02 - 2025-04-30 12:02 - 000083548 _____ C:\Users\slave\Downloads\FontsFree-Net-Bodoni-SvtyTwo-ITC-TT-Book.ttf
2025-04-30 11:59 - 2025-04-30 11:59 - 002417551 _____ C:\Users\slave\Downloads\A4.psd
2025-04-30 11:48 - 2025-04-30 11:48 - 000345129 _____ C:\Users\slave\Downloads\CASE_LAMINATE_8.250x11.000_120_PREMIUM_WHITE_en_US.zip
2025-04-29 21:09 - 2025-04-29 21:09 - 000000000 ____D C:\Users\slave\OneDrive\Documents\InDesign PDF Assets
2025-04-29 18:57 - 2025-04-29 18:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2025-04-29 13:10 - 2025-04-29 13:10 - 000058984 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2025-04-29 10:15 - 2025-04-29 10:15 - 000002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator 2024.lnk
2025-04-28 10:15 - 2025-04-28 10:15 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2024.lnk
2025-04-28 10:06 - 2025-04-28 10:06 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2025.lnk
2025-04-28 09:59 - 2025-04-28 09:59 - 000002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator 2025.lnk
2025-04-27 13:37 - 2025-04-27 13:37 - 000000000 ____D C:\Users\slave\AppData\LocalLow\BulwarkStudios
2025-04-27 12:21 - 2025-04-27 12:22 - 000000000 ____D C:\Users\slave\OneDrive\Documents\Trust GXT 155
2025-04-27 12:20 - 2025-04-27 12:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trust GXT 155 Gaming Mouse
2025-04-27 12:20 - 2025-04-27 12:20 - 000000000 ____D C:\Program Files (x86)\Trust GXT 155 Gaming Mouse
2025-04-27 12:19 - 2025-04-27 12:19 - 009397608 _____ (TRUST ) C:\Users\slave\Downloads\20411_05.exe
2025-04-27 10:35 - 2025-04-27 10:35 - 022303818 _____ C:\Users\slave\Downloads\Tekst knjige + instrukcije za pripremu.zip
2025-04-27 10:25 - 2025-04-27 10:25 - 000402464 _____ C:\WINDOWS\system32\prfh0804.dat
2025-04-27 10:25 - 2025-04-27 10:25 - 000130680 _____ C:\WINDOWS\system32\prfc0804.dat
2025-04-27 08:40 - 2025-03-26 00:09 - 011386880 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L2m.indd
2025-04-27 08:40 - 2025-03-26 00:08 - 011902976 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L1m.indd
2025-04-27 08:40 - 2025-03-25 13:41 - 009175040 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L3.indd
2025-04-26 03:33 - 2025-04-30 13:02 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-26 03:31 - 2025-04-26 03:31 - 000030998 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-26 03:31 - 2025-04-26 03:31 - 000030998 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-24 22:03 - 2025-04-24 22:03 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2025.lnk
2025-04-24 21:47 - 2025-04-24 21:47 - 000001052 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign 2025.lnk
2025-04-24 12:31 - 2025-04-24 12:31 - 000083504 _____ C:\Users\slave\Downloads\Invoice 04-2025.pdf
2025-04-24 11:37 - 2025-04-24 11:37 - 055566629 _____ C:\Users\slave\Downloads\P135606_Renholdsnytt 2 2025_Proof.pdf
2025-04-23 20:53 - 2025-04-23 20:53 - 008260984 _____ C:\Users\slave\Downloads\Corrections RH02-2025 v1 lowres.pdf
2025-04-23 16:52 - 2025-04-23 16:53 - 264759481 _____ C:\Users\slave\Downloads\Sample Folder.zip
2025-04-23 13:30 - 2025-04-23 13:30 - 001415215 _____ C:\Users\slave\Downloads\Products_Cleanroom.tif
2025-04-23 09:50 - 2025-04-23 09:50 - 034996980 _____ C:\Users\slave\Downloads\wetransfer_final-parts-for-ren-2_2025-04-23_0731.zip
2025-04-23 09:49 - 2025-04-23 09:49 - 011177715 _____ C:\Users\slave\Downloads\P46-49 Corrections to Market.pdf
2025-04-22 19:55 - 2025-04-22 19:56 - 001420980 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L5 spread_DJL.pdf
2025-04-22 12:09 - 2025-04-22 12:09 - 000362058 _____ C:\Users\slave\Downloads\2 page Sample.pdf
2025-04-20 12:28 - 2025-04-20 12:29 - 122650217 _____ C:\Users\slave\Downloads\wetransfer_3rd-shipment-for-renholdsnytt_2025-04-18_1929.zip
2025-04-20 12:27 - 2025-04-20 12:27 - 000000000 ____D C:\Users\slave\AppData\Roaming\Sun
2025-04-20 12:27 - 2025-04-20 12:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2025-04-20 12:27 - 2025-04-20 12:27 - 000000000 ____D C:\Program Files\Java
2025-04-20 12:27 - 2025-04-05 03:39 - 000213120 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2025-04-20 12:26 - 2025-04-20 12:26 - 000000000 ____D C:\Users\slave\AppData\LocalLow\Oracle
2025-04-17 15:07 - 2025-04-17 15:08 - 119167869 _____ C:\Users\slave\Downloads\wetransfer_2nd-shipment-for-ren-2_2025-04-17_1227.zip
2025-04-17 14:47 - 2025-04-17 14:48 - 054759229 _____ C:\Users\slave\Downloads\Templates and Instructions.zip
2025-04-17 14:17 - 2025-04-17 14:17 - 000259973 _____ C:\Users\slave\Downloads\clarejmartin-attachments.zip
2025-04-17 12:41 - 2025-04-17 12:41 - 000003441 _____ C:\Users\slave\Downloads\Balkan_Gambit_Chapter1_Handouts.pdf
2025-04-15 10:42 - 2025-04-15 10:45 - 330568998 _____ C:\Users\slave\Downloads\wetransfer_first-shipment-for-renholdsnytt-no-2_2025-04-14_1606.zip
2025-04-14 10:23 - 2025-04-14 10:24 - 031882050 _____ C:\Users\slave\Downloads\Original size-20250414T082339Z-001.zip
2025-04-12 17:29 - 2025-04-12 17:29 - 000001382 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2025-04-11 12:51 - 2025-04-11 12:51 - 001587626 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L4 spread.pdf
2025-04-10 12:59 - 2025-04-10 12:59 - 000000000 ____D C:\Users\slave\AppData\LocalLow\DoubleCross
2025-04-09 19:18 - 2025-04-09 19:18 - 002714457 _____ C:\Users\slave\Downloads\Hey, Can You Read This_ - Ask.epub
2025-04-09 18:55 - 2025-04-09 18:55 - 000000000 ____D C:\WINDOWS\system32\Tasks\DropboxSystem
2025-04-09 18:55 - 2025-04-09 18:55 - 000000000 ____D C:\Program Files\Dropbox
2025-04-09 03:36 - 2025-04-09 03:35 - 000316200 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2025-04-09 03:29 - 2025-04-09 03:29 - 000000000 ____D C:\inetpub
2025-04-08 11:47 - 2025-04-08 11:47 - 068236106 _____ C:\Users\slave\Downloads\P135797_Havnemagasinet 2 2025_Proof.pdf
2025-04-07 19:39 - 2025-04-07 19:40 - 080889756 _____ C:\Users\slave\Downloads\Chapter 6 - Sickness & Health-20250407T173943Z-001.zip
2025-04-07 16:55 - 2025-04-07 16:56 - 214040576 _____ C:\Users\slave\Downloads\calibre-64bit-8.2.1.msi
2025-04-07 13:03 - 2025-04-07 13:03 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Bibliography
2025-04-07 12:26 - 2025-04-07 12:26 - 000000000 ____D C:\WINDOWS\Minidump
2025-04-07 12:00 - 2025-04-07 12:00 - 000014457 _____ C:\Users\slave\Downloads\Invoice 03-2025.pdf
2025-04-07 11:04 - 2025-04-30 13:15 - 000000000 ____D C:\Users\slave\AppData\Roaming\Slack
2025-04-07 11:04 - 2025-04-21 20:24 - 000002207 _____ C:\Users\slave\OneDrive\Desktop\Slack.lnk
2025-04-07 11:04 - 2025-04-21 20:24 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies Inc
2025-04-07 11:04 - 2025-04-21 20:24 - 000000000 ____D C:\Users\slave\AppData\Local\slack
2025-04-07 11:03 - 2025-04-07 11:04 - 128985904 _____ (Slack Technologies Inc.) C:\Users\slave\Downloads\SlackSetup.exe
2025-04-05 11:44 - 2025-04-05 11:44 - 000001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2025.lnk
2025-04-04 16:26 - 2025-04-04 16:26 - 000000000 ____D C:\Users\slave\AppData\Local\TheInvincible
2025-04-04 16:04 - 2025-04-04 16:04 - 002936541 _____ C:\Users\slave\Downloads\Annonse Norkyst Havnemagasinet.pdf
2025-04-04 12:39 - 2025-04-04 13:01 - 000000000 ____D C:\Users\slave\Downloads\The Invincible [FitGirl Repack]
2025-04-04 12:12 - 2025-04-04 12:13 - 045413412 _____ C:\Users\slave\Downloads\P135478_Treindustrien 2 2025_Proof.pdf
2025-04-04 09:00 - 2025-04-04 09:00 - 011355127 _____ C:\Users\slave\Downloads\Treindustrien 02-2025 v2 lowres read.pdf
2025-04-03 11:25 - 2025-04-03 11:25 - 000106050 _____ C:\Users\slave\Downloads\Вождовац Месне Заједнице.pdf
2025-04-02 23:38 - 2025-04-02 23:38 - 010428916 _____ C:\Users\slave\Downloads\Treindustrien 02-2025 v1 lowres read.pdf
2025-04-02 13:23 - 2025-04-02 13:23 - 001040435 _____ C:\Users\slave\Downloads\Mirror 02-25.pdf
2025-04-02 12:28 - 2025-04-02 12:28 - 000066820 _____ C:\Users\slave\Downloads\bell-gothic-std (1).zip
2025-04-02 12:18 - 2025-04-02 12:18 - 002010042 _____ C:\Users\slave\Downloads\SF_Pontona (1).eps
2025-04-02 12:18 - 2025-04-02 12:18 - 001278704 _____ C:\Users\slave\Downloads\SF_Ad_Connecting_216x303_2024_print (1).pdf
2025-04-02 12:17 - 2025-04-02 12:18 - 009355080 _____ C:\Users\slave\Downloads\Kajen1c.jpg (1).jpeg
2025-03-31 14:09 - 2025-03-31 14:10 - 000000000 ____D C:\Users\slave\Downloads\Squid Game - Season 2
2025-03-31 13:31 - 2025-03-31 13:31 - 016518211 _____ C:\Users\slave\Downloads\3d-mockup-1_DJL.pdf
2025-03-31 13:26 - 2025-03-31 13:26 - 001438821 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L3m_DJL.pdf
2025-03-31 13:26 - 2025-03-31 13:26 - 001312019 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L1m_DJL.pdf
2025-03-31 13:26 - 2025-03-31 13:26 - 000899370 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L2m_DJL.pdf
2025-03-31 11:36 - 2025-03-31 11:36 - 000396160 _____ C:\Users\slave\Downloads\Neyemi Leve 6 - Creole - Gregory Toussaint.epub
2025-03-31 10:13 - 2025-03-31 10:15 - 213995520 _____ C:\Users\slave\Downloads\calibre-64bit-8.1.1.msi

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-04-30 14:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-30 14:03 - 2024-09-09 12:22 - 000000000 ____D C:\Program Files (x86)\Steam
2025-04-30 13:57 - 2024-09-16 23:13 - 000000000 ____D C:\Users\slave\AppData\Roaming\utorrent
2025-04-30 13:54 - 2024-09-09 12:28 - 000000000 ____D C:\Users\slave\AppData\Local\Discord
2025-04-30 13:54 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-04-30 13:54 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-30 13:38 - 2024-09-09 14:32 - 000000000 ___HD C:\adobeTemp
2025-04-30 13:38 - 2024-09-09 12:24 - 000000000 ____D C:\Program Files\Adobe
2025-04-30 13:09 - 2021-01-05 08:03 - 000000000 ___SD C:\Users\slave\AppData\Roaming\Microsoft\Credentials
2025-04-30 13:02 - 2024-10-18 03:43 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-04-30 13:02 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-30 12:54 - 2024-09-09 16:21 - 000000000 ____D C:\Users\slave\AppData\Local\CrashDumps
2025-04-30 12:39 - 2025-02-14 11:32 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Word
2025-04-30 10:08 - 2025-02-14 11:32 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Office
2025-04-30 09:19 - 2021-01-05 08:04 - 000000000 ____D C:\Users\slave\AppData\Local\Packages
2025-04-30 02:23 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-30 02:23 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-30 01:55 - 2024-09-09 12:28 - 000000000 ____D C:\Users\slave\AppData\Roaming\discord
2025-04-30 00:26 - 2025-02-14 11:33 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\UProof
2025-04-29 22:55 - 2025-02-14 11:41 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Excel
2025-04-29 18:58 - 2024-09-09 12:24 - 000000000 ____D C:\Users\slave\AppData\Local\Dropbox
2025-04-29 18:58 - 2024-09-09 12:23 - 000000000 ____D C:\Users\slave\AppData\Roaming\Dropbox
2025-04-29 18:57 - 2024-09-09 12:22 - 000000000 ____D C:\Program Files (x86)\Dropbox
2025-04-29 14:30 - 2025-02-15 13:51 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-04-29 14:30 - 2025-02-14 11:18 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-04-29 14:30 - 2025-02-14 11:18 - 000002132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-29 14:30 - 2025-01-27 22:02 - 000003546 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2574191415-932531762-3141445119-1001
2025-04-29 14:30 - 2024-10-18 03:47 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2574191415-932531762-3141445119-1001
2025-04-29 10:15 - 2021-01-05 08:04 - 000000000 ____D C:\Users\slave\AppData\Roaming\Adobe
2025-04-29 09:59 - 2024-09-09 14:18 - 000000000 ____D C:\Users\slave\OneDrive\Documents\ViberDownloads
2025-04-28 09:54 - 2024-10-01 12:30 - 000000000 ____D C:\Users\slave\AppData\Roaming\Telegram Desktop
2025-04-28 09:54 - 2024-09-09 14:17 - 000000000 ____D C:\Users\slave\AppData\Roaming\ViberPC
2025-04-28 01:37 - 2024-10-18 03:44 - 000000000 ____D C:\Users\slave
2025-04-27 13:26 - 2024-09-09 17:46 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-27 10:25 - 2024-10-18 03:52 - 001360668 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-27 10:18 - 2024-10-18 03:47 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-27 10:18 - 2024-10-18 03:45 - 000004526 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-27 10:18 - 2021-01-05 07:58 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-27 09:19 - 2024-09-09 12:14 - 000000000 ____D C:\Users\slave\AppData\Local\D3DSCache
2025-04-26 16:02 - 2021-01-05 07:58 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-26 12:23 - 2024-09-09 12:17 - 000000000 ____D C:\Users\slave\AppData\Local\AMD_Common
2025-04-26 12:17 - 2024-09-09 12:12 - 000002249 _____ C:\Users\slave\OneDrive\Desktop\Discord.lnk
2025-04-26 12:16 - 2021-01-05 08:04 - 000000000 ____D C:\ProgramData\Packages
2025-04-26 06:08 - 2024-10-18 03:43 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-04-26 06:08 - 2024-09-09 12:17 - 000000000 ____D C:\ProgramData\Avast Software
2025-04-26 06:08 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-04-26 06:07 - 2024-10-18 03:43 - 001339680 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-26 06:06 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-26 03:31 - 2024-10-18 03:47 - 003369984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-04-25 10:33 - 2024-09-09 19:43 - 000000000 ____D C:\Users\slave\AppData\Roaming\vlc
2025-04-24 23:00 - 2024-09-09 12:13 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-24 22:03 - 2024-09-09 12:24 - 000000000 ____D C:\ProgramData\Adobe
2025-04-24 22:03 - 2024-09-09 12:24 - 000000000 ____D C:\Program Files\Common Files\Adobe
2025-04-24 10:56 - 2024-09-09 14:15 - 000000000 ____D C:\Users\slave\AppData\Roaming\calibre
2025-04-24 10:56 - 2024-09-09 14:15 - 000000000 ____D C:\Users\slave\AppData\Local\calibre-cache
2025-04-23 14:03 - 2024-10-01 17:44 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2025-04-22 23:04 - 2024-10-18 03:47 - 000002212 _____ C:\WINDOWS\system32\Tasks\com.amazon.kpr.ncd
2025-04-22 10:19 - 2024-09-19 14:05 - 000000000 ____D C:\ProgramData\boost_interprocess
2025-04-21 20:32 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-21 20:30 - 2025-03-18 08:41 - 000378432 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_8.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 002901544 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000796224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000267840 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000243240 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000153152 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000124480 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2025-04-21 20:30 - 2025-01-17 14:33 - 000075304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2025-04-21 20:24 - 2024-09-09 14:17 - 000000000 ____D C:\Users\slave\AppData\Local\Viber
2025-04-21 20:22 - 2025-01-12 21:23 - 000000000 ____D C:\ProgramData\EA Desktop
2025-04-18 14:21 - 2024-10-18 03:47 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-04-18 14:21 - 2024-09-09 15:58 - 000002084 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller.lnk
2025-04-18 14:21 - 2024-09-09 15:58 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-04-17 16:44 - 2025-02-14 11:07 - 000000000 ____D C:\Program Files\Microsoft Office
2025-04-16 15:00 - 2024-09-09 12:20 - 000000000 ____D C:\Users\slave\AppData\Local\Adobe
2025-04-13 15:13 - 2024-10-01 12:37 - 000000000 ____D C:\Users\slave\Downloads\Telegram Desktop
2025-04-12 17:29 - 2024-09-09 12:24 - 000000000 ____D C:\Users\slave\AppData\LocalLow\Adobe
2025-04-12 17:29 - 2024-09-09 12:24 - 000000000 ____D C:\Program Files (x86)\Adobe
2025-04-09 13:46 - 2024-09-09 12:22 - 000393272 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2025-04-09 03:36 - 2024-10-18 03:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-04-09 03:35 - 2024-09-09 12:22 - 001427512 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSP.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000942672 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSnx.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000553528 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswNetHub.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000391760 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswVmm.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000296528 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000282680 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000248376 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswArPot.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000098872 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000084560 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000069688 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000037944 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswKbd.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000020536 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2025-04-09 03:29 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-09 03:29 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-09 03:29 - 2024-04-01 10:03 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-04-07 19:40 - 2024-09-09 14:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2025-04-07 19:40 - 2024-09-09 14:15 - 000000000 ____D C:\Program Files\Calibre2
2025-04-07 19:30 - 2024-09-09 12:16 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2025-04-07 12:36 - 2024-10-23 20:55 - 000000000 ____D C:\Users\slave\OneDrive\Documents\InDesign GenAI Assets
2025-04-07 12:26 - 2021-01-05 07:58 - 002793175 ____N C:\WINDOWS\Minidump\040725-8500-01.dmp
2025-04-07 11:04 - 2024-09-09 12:28 - 000000000 ____D C:\Users\slave\AppData\Local\SquirrelTemp
2025-04-06 00:57 - 2024-10-18 03:47 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-04-06 00:57 - 2024-10-18 03:47 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-04-05 11:47 - 2024-10-04 17:42 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2024.lnk
2025-04-05 11:45 - 2024-10-04 17:50 - 000001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2024.lnk
2025-04-04 14:15 - 2024-09-16 23:13 - 000000000 ____D C:\Users\slave\AppData\Local\BitTorrentHelper
2025-03-31 11:45 - 2024-09-10 13:02 - 000000000 ____D C:\Users\slave\AppData\Roaming\Amazon

==================== Files in the root of some directories ========

2024-09-09 15:46 - 2024-09-09 15:46 - 000000000 _____ () C:\Users\slave\AppData\Local\oobelibMkey.log
2024-09-09 12:24 - 2024-09-09 12:24 - 000000003 _____ () C:\Users\slave\AppData\Local\updater.log
2024-09-09 12:24 - 2024-09-10 18:12 - 000000424 _____ () C:\Users\slave\AppData\Local\UserProducts.xml

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Dopuna: 30 Apr 2025 20:34

khm, addition.txt


[Link mogu videti samo ulogovani korisnici]

Dopuna: 01 Maj 2025 8:42

uradio jos jedan scan sa malwarebytes, evo izvod

Malwarebytes
[Link mogu videti samo ulogovani korisnici]

-Log Details-
Scan Date: 01-May-25
Scan Time: 09:08
Log File: 07326017-265b-11f0-b04b-9c6b0024c5db.json

-Software Information-
Version: 5.2.11.183
Components Version: 131.0.5227
Update Package Version: 1.0.98553
License: Trial

-System Information-
OS: Windows 11 (Build 26100.3915)
CPU: x64
File System: NTFS
User: System

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Completed
Objects Scanned: 232625
Threats Detected: 22
Threats Quarantined: 0
Time Elapsed: 1 min, 22 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 1
Adware.Redirector, HKU\S-1-5-21-2574191415-932531762-3141445119-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|ogadflejmplcdhcldlloonbiekhnlopp, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 3
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\OGADFLEJMPLCDHCLDLLOONBIEKHNLOPP, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,

File: 18
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 665115DAAFD5A81206077B542305258C, 30F1C8EC0D4E8F519C79165337938D54B181C583E07BFBC5B39892F15D64399E
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 4040D6244534C6F8311E1C796FF35D1A, 4FA02D98C63351E53FD6F8C9E58D7FE367052D42263969D164320F88490E7C70
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\000003.log, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\CURRENT, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\LOCK, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\LOG, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 5466F308390B1F5F2C4AF2E85702111C, 27B53A9D79736CD77094EE39779F8D5AA9FEFD3BF444E3701AF35E0C892BBE82
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\LOG.old, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 37A7A0F92380686510878115EEBAFE51, 7AC46B2B0B67FDD1AA6443C337E95F134B70BB50A472687410AF987BC8CF6FC8
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\MANIFEST-000001, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 5AF87DFD673BA2115E2FCF5CFDB727AB, F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 4222A438DA6BCC1D56DE66B1348A211F, F7C0CB3FF882698B8341DD9232CDF2F36A7BD671FB9769386296858CCE608AA2
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000007.ldb, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 3FDA5478924259833BDF3B5FF3D148E7, AB8EA76EBE2D45329BD3784440DA22B2339187C4340927E5C5DAF88CC1795A3A
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000008.log, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 225CDADB4C4DCCF52512C92047FD580C, 5B6B30E6890BD553AE9CC8DCB72E4418B12F3EFBCC684600BC4E22BBEF91E67B
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000009.ldb, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 6C94061BDB71C26EA0BDA58DC84DA852, AD11BF2DFE3513D31734FC65DAAD7E0A38C5A44559575B043A6524661E611F0A
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 0E6BC58BC303141EA829A3B64A045F5D, 8803243A48E65EE01CDB7D1EE7C9ABAFD68464B3FB921F326B043EE7628AB4A1
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 39D64F959E5904BE69387974BB76F72A, C8F97363AF2536B550096C409C2FF80F51B22C061D0C3BCD2CFCAFD2F3B29C2D
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 9B11E0F418C060647A15E606AEBD31D1, C3F7D50AFA3B4E8D218DB99F57661CA6EADD4DBFEF7D09D4374ECB4D6778C49C
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 4040D6244534C6F8311E1C796FF35D1A, 4FA02D98C63351E53FD6F8C9E58D7FE367052D42263969D164320F88490E7C70

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)



Ko je trenutno na forumu
 

Ukupno su 1172 korisnika na forumu :: 79 registrovanih, 9 sakrivenih i 1084 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 015, A.R.Chafee.Jr., alberto, AleksSE, Asteker, bestguarder, Bickoooo, blue, bobomicek, Bojan198527, bojan_t, bojanM84, cavatina, ccoogg123, coaa, cuvarkuca, cvrle312, debeli, DeerHunter, Dekanovic, Desmond, dexteroza, Djole3621, Djota1, dolinalima, dragisa dragisa, Dukelander, Feller, flash12, goranjovic, GrobarPovratak, HrcAk47, icemilos, IQ116, Istman, jon istvan, Kajzer Soze, koneks, Krusarac, lacko, lcc, Lošmi, MarijaC84, Maruti, mercedesamg, mikrimaus, milanovic, milenko1980, Mis uz pusku, Mitogna, moldway, N95, nelezele, Nomica, ObelixSRB, Paklenica, pein, PrincipL, Pv123, radoznao, Resad76, rovac, sekretar, SlaKoj, sonico, stagezin, stalja, stibium51, suton, Token, Tribal, Tumansky, Vanderx, VekiJ, voja64, Zanimljivo, Zdilar, Zoran1959, ZZtop