offline
- Slaven980
- Novi MyCity građanin
- Pridružio: 04 Sep 2008
- Poruke: 28
|
Napisano: 30 Apr 2025 19:35
prvenstveno se zalim na rad Chroma i programa za rad. Skinuo Malwarebytes, ocistio sta mi je rekao da ima da se ocisti, ali i dalje je sve usporeno.
Hvala unapred
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2025
Ran by slave (administrator) on SLAVEN (30-04-2025 14:08:01)
Running from C:\Users\slave\Downloads\FRST64.exe
Loaded Profiles: slave
Platform: Microsoft Windows 11 Pro Version 24H2 26100.3915 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\GXT155mon.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe InDesign 2025\Adobe Crash Processor.exe
(Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <6>
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud Helper.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Creative Cloud UI Helper.exe <4>
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <2>
(C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\107.0.3.0\crashpad_handler.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(cmd.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(cmd.exe ->) (Lenovo (Beijing) Limited -> Lenovo Group Limited) C:\Users\slave\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
(Discord Inc. -> Discord Inc.) C:\Users\slave\AppData\Local\Discord\app-1.0.9189\Discord.exe <6>
(DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\atieclxx.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <8>
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <48>
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Telegram FZ-LLC -> Telegram FZ-LLC) C:\Users\slave\AppData\Roaming\Telegram Desktop\Telegram.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (Viber Media S.a r.l. -> Viber Media S.Ã r.l.) C:\Users\slave\AppData\Local\Viber\Viber.exe
(Kilonova LLC -> Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\atiesrxx.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(services.exe ->) (Eastern Times Technology Co.,Ltd -> ) C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\ETGMSrv.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_05bfde18331c4d58\amdfendrsr.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25032.52.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(Slack Technologies, LLC -> Slack Technologies Inc.) C:\Users\slave\AppData\Local\slack\app-4.43.52\slack.exe <7>
(svchost.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\WindowsApps\AdobeNotificationClient_6.0.0.1_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(svchost.exe ->) (Adobe Systems Incorporated -> ) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(svchost.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\CPUMetricsServer.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2504.1001.26.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [455976 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [10752424 2025-01-14] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [9238408 2025-04-29] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226728 2019-07-21] (Kilonova LLC -> )
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [133128 2024-09-09] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [1145256 2025-04-12] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [GXT155gmmouseRun] => C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\GXT155mon.exe [3435520 2018-06-10] () [File not signed]
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" [89199416 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5014344 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4693600 2025-04-21] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Discord] => C:\Users\slave\AppData\Local\Discord\Update.exe [1526504 2024-09-04] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [41351584 2025-04-09] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [AMDNoiseSuppression] => C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe [164840 2024-06-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3814496 2025-04-16] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [Viber] => C:\Users\slave\AppData\Local\Viber\Viber.exe [101727064 2025-04-15] (Viber Media S.a r.l. -> Viber Media S.Ã r.l.)
HKU\S-1-5-21-2574191415-932531762-3141445119-1001\...\Run: [com.squirrel.slack.slack] => C:\Users\slave\AppData\Local\slack\slack.exe [307504 2025-04-21] (Slack Technologies, LLC -> Slack Technologies Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\107.0.3.0\GoogleDriveFS.exe [65821280 2025-04-23] (Google LLC -> Google LLC.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [203936 2024-08-08] (Adobe Inc. -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.115\Installer\chrmstp.exe [2025-04-24] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
Startup: C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk [2025-03-22]
ShortcutTarget: Telegram.lnk -> C:\Users\slave\AppData\Roaming\Telegram Desktop\Telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {9E30966E-B457-429B-A3C3-6C989BC5D905} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {63FAA669-6604-4AE3-A5DC-F8DC93B4CF00} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [10752424 2025-01-14] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {1D052E57-6DB5-40E8-9C6F-D477C1BC7B86} - System32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [11065256 2025-01-14] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {B320F0DE-1106-47DC-AF6F-A848DDCBBD29} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [191184 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {3279D5E6-697C-401C-8C76-83E8E0CFF2F1} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [8594216 2025-03-27] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {7F12FB08-3C7E-43F5-B79A-D64F474085B4} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5293864 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {1A746C7A-25AD-47FE-987B-3B84218F8324} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2564904 2024-11-20] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {9ACDDAA7-33A6-49FB-A322-C631F43D45C9} - System32\Tasks\com.amazon.kpr.ncd => C:\Users\slave\AppData\Local\Amazon\Kindle Previewer 3\KPR_NCD.exe [2110976 2025-02-22] () [File not signed] <==== ATTENTION
Task: {CB63873D-8CC5-424E-A890-482DE5DBAA19} - System32\Tasks\DropboxSystem\DropboxUpdater\DropboxUpdaterTaskSystem123.0.6299.109{7D11D58F-B00A-4DE1-B0E0-7115DF5C926E} => C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.109\updater.exe [5895032 2025-03-21] (Dropbox, Inc -> Dropbox, Inc.)
Task: {764BB0DE-B8D3-4FE2-88DF-9B586BF18394} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem137.0.7129.0{EBE383F0-3F59-4EBC-AC26-0534E493D647} => C:\Program Files (x86)\Google\GoogleUpdater\137.0.7129.0\updater.exe [7375968 2025-04-17] (Google LLC -> Google LLC)
Task: {3B4DAD8D-A83E-41DC-8C7F-199D26826751} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Users\slave\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [88584 2024-05-17] (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {18DD42D1-7E6B-4C1F-A65E-159E1F0403DC} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28609776 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {0508B5A8-8226-4CFC-8354-F04DBAD3DA0A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28609776 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {E35FD19C-596E-48D3-A5FC-5B1629A559AA} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312496 2025-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {3FDA71EE-94BC-4060-BA98-9EC0E04C00E3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312496 2025-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {A3BF75D2-B16C-46CC-B081-5E44597D11A0} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [187024 2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {A4BC5BB3-44A2-49F0-9451-922CBF3FE14B} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
Task: {31110D7F-072A-4E09-BC1A-CED57AC3FD91} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {E9C827BA-D336-4C20-AA62-9DA77B48E4F8} - System32\Tasks\Microsoft\Windows\WindowsAI\Recall\InitialConfiguration => {709FD5EF-7296-4154-BD3A-E9830FCFA60A} C:\WINDOWS\system32\ShellConfigTask.dll [274432 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
Task: {3DB47973-12DF-40A1-886A-1FF7A2602520} - System32\Tasks\Microsoft\Windows\WindowsAI\Recall\PolicyConfiguration => {0BE6820D-B667-4CB6-931B-C153A77DA895} C:\WINDOWS\system32\ShellConfigTask.dll [274432 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
Task: {49035FB4-38CC-41EB-9485-4EF706EEA4D8} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1035472 2024-11-28] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {CF51999A-6D62-410E-9D62-B6E7CFB19D4E} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223832 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {A44FB663-60DF-4DD1-A4DD-0D04A5EC8DDB} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223832 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {73811D01-6460-4142-B62A-C39B25212B4E} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Program Files\Microsoft OneDrive\25.065.0406.0002\OneDriveLauncher.exe [679232 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {1CD58D9D-BCAA-4E6E-99A7-5604DF0CA572} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [139472 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {93444334-A9DB-467E-8096-722A5529C4F1} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [309968 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
Task: {38461FA3-8FA8-4702-B242-FBB2C706D015} - System32\Tasks\update-S-1-5-21-2574191415-932531762-3141445119-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
Task: {B13E6279-CEB8-44AD-8108-5D1B924E7B0F} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\update-S-1-5-21-2574191415-932531762-3141445119-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1
Tcpip\..\Interfaces\{bd7b7a99-eaf3-494d-8be1-924251d80c94}: [DhcpNameServer] 192.168.8.1
Edge:
=======
Edge Profile: C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default [2025-04-27]
Edge Extension: (Table Capture) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cjlemjohnmihejeecaoaglgejaokmclj [2025-02-14]
Edge Extension: (GoFullPage - Full Page Screen Capture) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2024-10-28]
Edge Extension: (Google Docs Offline) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-02-04]
Edge Extension: (Adblock Plus - free ad blocker) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2025-02-26]
Edge Extension: (Auto Refresh Plus | Page Monitor) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hgeljhfekpckiiplhkigfehkdpldcggm [2024-10-28]
Edge Extension: (Feeder - RSS Feed Reader) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jlkhefogiiibhgblliimeleiiiijbkjj [2024-10-28]
Edge Extension: (Edge relevant text changes) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-09-09]
Edge Extension: (AdBlock — block ads across the web) - C:\Users\slave\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2025-02-19]
FireFox:
========
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2021-02-01]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @java.com/DTPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\dtplugin\npDeployJava1.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\plugin2\npjp2.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-04-09] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2025-04-12] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2025-04-12] (Adobe Inc. -> Adobe Systems)
Chrome:
=======
CHR Profile: C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default [2025-04-30]
CHR Notifications: Default -> [Link mogu videti samo ulogovani korisnici]
CHR HomePage: Default -> [Link mogu videti samo ulogovani korisnici]
CHR StartupUrls: Default -> "hxxps://www.fiverr.com/users/slaven980/seller_dashboard","hxxps://www.upwork.com/nx/find-work/","hxxps://www.facebook.com/","hxxps://mail.google.com/mail/u/0/#inbox","hxxps://mail.yahoo.com/d/folders/1","hxxps://medierogledelse.roxen.com/","hxxps://trello.com/b/tCs8vhW5/prelom-knjiga"
CHR Extension: (Strata) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihlahcemjcnhakkkclcohelfdleejmc [2024-09-09]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2025-04-26]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-04-30]
CHR Extension: (Free Rider HD) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\emikpifndnjfkgofoglceekhkbaicbde [2024-09-09]
CHR Extension: (GoFullPage - Full Page Screen Capture) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2025-03-23]
CHR Extension: (Causality Games) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\femoooemgmjaebeodbbikbkmhlafenpl [2024-09-09]
CHR Extension: (Readium) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\fepbnnnkkadjhjahcafoaglimekefifl [2024-09-09]
CHR Extension: (Google Docs Offline) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-24]
CHR Extension: (AdBlock — block ads across the web) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2025-04-21]
CHR Extension: (Auto Refresh Plus | Page Monitor) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgeljhfekpckiiplhkigfehkdpldcggm [2024-09-09]
CHR Extension: (Table Capture) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\iebpjdmgckacbodjpijphcplhebcmeop [2025-03-21]
CHR Extension: (Hootsuite) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2024-09-09]
CHR Extension: (Little Alchemy) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2024-09-09]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-10-01]
CHR Extension: (Google Play Books) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2024-09-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-09-09]
CHR Extension: (Volume booster - Increase Volume) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogadflejmplcdhcldlloonbiekhnlopp [2025-04-30]
CHR Extension: (RSS Feed Reader) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2025-03-25]
CHR Extension: (Canvas Rider) - C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk [2024-09-09]
CHR HKU\S-1-5-21-2574191415-932531762-3141445119-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-2574191415-932531762-3141445119-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [944040 2025-04-12] (Adobe Inc. -> Adobe Inc.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7500072 2025-04-09] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [807208 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [859432 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2024-09-09] (Avast Software s.r.o. -> AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14044936 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
R2 DbxSvc; C:\WINDOWS\System32\DbxSvc.exe [58984 2025-04-29] (Dropbox, Inc -> Dropbox, Inc.)
S3 DropboxElevationService; C:\Program Files (x86)\Dropbox\Client\223.4.4909\DropboxElevationService.exe [1659280 2025-04-29] (Dropbox, Inc -> Dropbox, Inc.)
S2 DropboxUpdaterInternalService123.0.6299.109; C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.109\updater.exe [5895032 2025-03-21] (Dropbox, Inc -> Dropbox, Inc.)
S2 DropboxUpdaterService123.0.6299.109; C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.109\updater.exe [5895032 2025-03-21] (Dropbox, Inc -> Dropbox, Inc.)
R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [18709600 2025-04-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 ETGMGlcsSrv; C:\Program Files (x86)\Trust GXT 155 Gaming Mouse\ETGMSrv.exe [1181544 2012-04-24] (Eastern Times Technology Co.,Ltd -> )
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.065.0406.0002\FileSyncHelper.exe [3587904 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9406208 2025-04-30] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-04-30] (Malwarebytes Inc. -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.065.0406.0002\OneDriveUpdaterService.exe [3841360 2025-04-29] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559320 2025-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ZTHELPER; C:\WINDOWS\System32\zthelper.dll [146096 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\WINDOWS\System32\DriverStore\FileRepository\amdfendr.inf_amd64_05bfde18331c4d58\amdfendrmgr.sys [36016 2024-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33592 2024-09-12] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
S2 AMDRyzenMasterDriverV26; C:\Windows\system32\AMDRyzenMasterDriver.sys [61264 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices)
R2 AMDRyzenMasterDriverV27; C:\WINDOWS\system32\AMDRyzenMasterDriver.sys [61264 2024-11-27] (Advanced Micro Devices -> Advanced Micro Devices)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_d4de13a10f2586d0\amdsafd.sys [112952 2024-06-15] (AMD Test Build -> Advanced Micro Devices)
R3 amduw23g; C:\WINDOWS\System32\DriverStore\FileRepository\u0410212.inf_amd64_daae2c8b5eb35aaa\B409877\amdkmdag.sys [110965144 2024-12-04] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [63008 2024-05-16] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [20536 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [248376 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [393272 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [296528 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [84560 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [28280 2024-11-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [37944 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [282680 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [553528 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [98872 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [69688 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [942672 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1427512 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [207440 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [391760 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 googledrivefs31626; C:\Program Files\Google\Drive File Stream\Drivers\31626\googledrivefs31626.sys [384096 2024-10-01] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-04-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt11.sys [241112 2025-04-30] (Malwarebytes Inc. -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [80448 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [189776 2025-04-30] (Malwarebytes Inc. -> Malwarebytes)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-03-27] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
R3 usbglcs1100302; C:\WINDOWS\system32\drivers\usbglcs1100302.sys [25600 2014-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [22080 2024-09-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [602504 2024-09-09] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105864 2024-09-09] (Microsoft Windows -> Microsoft Corporation)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_8d863c975b4367df\wini3ctarget.sys [79288 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-30 14:08 - 2025-04-30 14:08 - 000039140 _____ C:\Users\slave\Downloads\FRST.txt
2025-04-30 14:07 - 2025-04-30 14:08 - 000000000 ____D C:\FRST
2025-04-30 14:07 - 2025-04-30 14:07 - 002405376 _____ (Farbar) C:\Users\slave\Downloads\FRST64.exe
2025-04-30 13:59 - 2025-04-30 13:59 - 000241112 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt11.sys
2025-04-30 13:59 - 2025-04-30 13:59 - 000189776 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2025-04-30 13:59 - 2025-04-30 13:59 - 000000000 ____D C:\Users\slave\AppData\LocalLow\IGDump
2025-04-30 13:58 - 2025-04-30 13:58 - 002834160 _____ (Malwarebytes) C:\Users\slave\Downloads\MBSetup (1).exe
2025-04-30 13:54 - 2025-04-30 14:04 - 000000000 ____D C:\Users\slave\AppData\Local\Malwarebytes
2025-04-30 13:54 - 2025-04-30 13:54 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2025-04-30 13:54 - 2025-04-30 13:54 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-04-30 13:54 - 2025-04-30 13:54 - 000000000 ____D C:\Program Files\Malwarebytes
2025-04-30 13:53 - 2025-04-30 13:53 - 002834160 _____ (Malwarebytes) C:\Users\slave\Downloads\MBSetup.exe
2025-04-30 13:38 - 2025-04-30 13:38 - 000001026 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InCopy 2025.lnk
2025-04-30 12:02 - 2025-04-30 12:02 - 000083548 _____ C:\Users\slave\Downloads\FontsFree-Net-Bodoni-SvtyTwo-ITC-TT-Book.ttf
2025-04-30 11:59 - 2025-04-30 11:59 - 002417551 _____ C:\Users\slave\Downloads\A4.psd
2025-04-30 11:48 - 2025-04-30 11:48 - 000345129 _____ C:\Users\slave\Downloads\CASE_LAMINATE_8.250x11.000_120_PREMIUM_WHITE_en_US.zip
2025-04-29 21:09 - 2025-04-29 21:09 - 000000000 ____D C:\Users\slave\OneDrive\Documents\InDesign PDF Assets
2025-04-29 18:57 - 2025-04-29 18:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2025-04-29 13:10 - 2025-04-29 13:10 - 000058984 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2025-04-29 10:15 - 2025-04-29 10:15 - 000002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator 2024.lnk
2025-04-28 10:15 - 2025-04-28 10:15 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2024.lnk
2025-04-28 10:06 - 2025-04-28 10:06 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2025.lnk
2025-04-28 09:59 - 2025-04-28 09:59 - 000002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator 2025.lnk
2025-04-27 13:37 - 2025-04-27 13:37 - 000000000 ____D C:\Users\slave\AppData\LocalLow\BulwarkStudios
2025-04-27 12:21 - 2025-04-27 12:22 - 000000000 ____D C:\Users\slave\OneDrive\Documents\Trust GXT 155
2025-04-27 12:20 - 2025-04-27 12:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trust GXT 155 Gaming Mouse
2025-04-27 12:20 - 2025-04-27 12:20 - 000000000 ____D C:\Program Files (x86)\Trust GXT 155 Gaming Mouse
2025-04-27 12:19 - 2025-04-27 12:19 - 009397608 _____ (TRUST ) C:\Users\slave\Downloads\20411_05.exe
2025-04-27 10:35 - 2025-04-27 10:35 - 022303818 _____ C:\Users\slave\Downloads\Tekst knjige + instrukcije za pripremu.zip
2025-04-27 10:25 - 2025-04-27 10:25 - 000402464 _____ C:\WINDOWS\system32\prfh0804.dat
2025-04-27 10:25 - 2025-04-27 10:25 - 000130680 _____ C:\WINDOWS\system32\prfc0804.dat
2025-04-27 08:40 - 2025-03-26 00:09 - 011386880 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L2m.indd
2025-04-27 08:40 - 2025-03-26 00:08 - 011902976 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L1m.indd
2025-04-27 08:40 - 2025-03-25 13:41 - 009175040 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L3.indd
2025-04-26 03:33 - 2025-04-30 13:02 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-26 03:31 - 2025-04-26 03:31 - 000030998 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-26 03:31 - 2025-04-26 03:31 - 000030998 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-24 22:03 - 2025-04-24 22:03 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2025.lnk
2025-04-24 21:47 - 2025-04-24 21:47 - 000001052 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign 2025.lnk
2025-04-24 12:31 - 2025-04-24 12:31 - 000083504 _____ C:\Users\slave\Downloads\Invoice 04-2025.pdf
2025-04-24 11:37 - 2025-04-24 11:37 - 055566629 _____ C:\Users\slave\Downloads\P135606_Renholdsnytt 2 2025_Proof.pdf
2025-04-23 20:53 - 2025-04-23 20:53 - 008260984 _____ C:\Users\slave\Downloads\Corrections RH02-2025 v1 lowres.pdf
2025-04-23 16:52 - 2025-04-23 16:53 - 264759481 _____ C:\Users\slave\Downloads\Sample Folder.zip
2025-04-23 13:30 - 2025-04-23 13:30 - 001415215 _____ C:\Users\slave\Downloads\Products_Cleanroom.tif
2025-04-23 09:50 - 2025-04-23 09:50 - 034996980 _____ C:\Users\slave\Downloads\wetransfer_final-parts-for-ren-2_2025-04-23_0731.zip
2025-04-23 09:49 - 2025-04-23 09:49 - 011177715 _____ C:\Users\slave\Downloads\P46-49 Corrections to Market.pdf
2025-04-22 19:55 - 2025-04-22 19:56 - 001420980 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L5 spread_DJL.pdf
2025-04-22 12:09 - 2025-04-22 12:09 - 000362058 _____ C:\Users\slave\Downloads\2 page Sample.pdf
2025-04-20 12:28 - 2025-04-20 12:29 - 122650217 _____ C:\Users\slave\Downloads\wetransfer_3rd-shipment-for-renholdsnytt_2025-04-18_1929.zip
2025-04-20 12:27 - 2025-04-20 12:27 - 000000000 ____D C:\Users\slave\AppData\Roaming\Sun
2025-04-20 12:27 - 2025-04-20 12:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2025-04-20 12:27 - 2025-04-20 12:27 - 000000000 ____D C:\Program Files\Java
2025-04-20 12:27 - 2025-04-05 03:39 - 000213120 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2025-04-20 12:26 - 2025-04-20 12:26 - 000000000 ____D C:\Users\slave\AppData\LocalLow\Oracle
2025-04-17 15:07 - 2025-04-17 15:08 - 119167869 _____ C:\Users\slave\Downloads\wetransfer_2nd-shipment-for-ren-2_2025-04-17_1227.zip
2025-04-17 14:47 - 2025-04-17 14:48 - 054759229 _____ C:\Users\slave\Downloads\Templates and Instructions.zip
2025-04-17 14:17 - 2025-04-17 14:17 - 000259973 _____ C:\Users\slave\Downloads\clarejmartin-attachments.zip
2025-04-17 12:41 - 2025-04-17 12:41 - 000003441 _____ C:\Users\slave\Downloads\Balkan_Gambit_Chapter1_Handouts.pdf
2025-04-15 10:42 - 2025-04-15 10:45 - 330568998 _____ C:\Users\slave\Downloads\wetransfer_first-shipment-for-renholdsnytt-no-2_2025-04-14_1606.zip
2025-04-14 10:23 - 2025-04-14 10:24 - 031882050 _____ C:\Users\slave\Downloads\Original size-20250414T082339Z-001.zip
2025-04-12 17:29 - 2025-04-12 17:29 - 000001382 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2025-04-11 12:51 - 2025-04-11 12:51 - 001587626 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L4 spread.pdf
2025-04-10 12:59 - 2025-04-10 12:59 - 000000000 ____D C:\Users\slave\AppData\LocalLow\DoubleCross
2025-04-09 19:18 - 2025-04-09 19:18 - 002714457 _____ C:\Users\slave\Downloads\Hey, Can You Read This_ - Ask.epub
2025-04-09 18:55 - 2025-04-09 18:55 - 000000000 ____D C:\WINDOWS\system32\Tasks\DropboxSystem
2025-04-09 18:55 - 2025-04-09 18:55 - 000000000 ____D C:\Program Files\Dropbox
2025-04-09 03:36 - 2025-04-09 03:35 - 000316200 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2025-04-09 03:29 - 2025-04-09 03:29 - 000000000 ____D C:\inetpub
2025-04-08 11:47 - 2025-04-08 11:47 - 068236106 _____ C:\Users\slave\Downloads\P135797_Havnemagasinet 2 2025_Proof.pdf
2025-04-07 19:39 - 2025-04-07 19:40 - 080889756 _____ C:\Users\slave\Downloads\Chapter 6 - Sickness & Health-20250407T173943Z-001.zip
2025-04-07 16:55 - 2025-04-07 16:56 - 214040576 _____ C:\Users\slave\Downloads\calibre-64bit-8.2.1.msi
2025-04-07 13:03 - 2025-04-07 13:03 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Bibliography
2025-04-07 12:26 - 2025-04-07 12:26 - 000000000 ____D C:\WINDOWS\Minidump
2025-04-07 12:00 - 2025-04-07 12:00 - 000014457 _____ C:\Users\slave\Downloads\Invoice 03-2025.pdf
2025-04-07 11:04 - 2025-04-30 13:15 - 000000000 ____D C:\Users\slave\AppData\Roaming\Slack
2025-04-07 11:04 - 2025-04-21 20:24 - 000002207 _____ C:\Users\slave\OneDrive\Desktop\Slack.lnk
2025-04-07 11:04 - 2025-04-21 20:24 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies Inc
2025-04-07 11:04 - 2025-04-21 20:24 - 000000000 ____D C:\Users\slave\AppData\Local\slack
2025-04-07 11:03 - 2025-04-07 11:04 - 128985904 _____ (Slack Technologies Inc.) C:\Users\slave\Downloads\SlackSetup.exe
2025-04-05 11:44 - 2025-04-05 11:44 - 000001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2025.lnk
2025-04-04 16:26 - 2025-04-04 16:26 - 000000000 ____D C:\Users\slave\AppData\Local\TheInvincible
2025-04-04 16:04 - 2025-04-04 16:04 - 002936541 _____ C:\Users\slave\Downloads\Annonse Norkyst Havnemagasinet.pdf
2025-04-04 12:39 - 2025-04-04 13:01 - 000000000 ____D C:\Users\slave\Downloads\The Invincible [FitGirl Repack]
2025-04-04 12:12 - 2025-04-04 12:13 - 045413412 _____ C:\Users\slave\Downloads\P135478_Treindustrien 2 2025_Proof.pdf
2025-04-04 09:00 - 2025-04-04 09:00 - 011355127 _____ C:\Users\slave\Downloads\Treindustrien 02-2025 v2 lowres read.pdf
2025-04-03 11:25 - 2025-04-03 11:25 - 000106050 _____ C:\Users\slave\Downloads\Вождовац Месне Заједнице.pdf
2025-04-02 23:38 - 2025-04-02 23:38 - 010428916 _____ C:\Users\slave\Downloads\Treindustrien 02-2025 v1 lowres read.pdf
2025-04-02 13:23 - 2025-04-02 13:23 - 001040435 _____ C:\Users\slave\Downloads\Mirror 02-25.pdf
2025-04-02 12:28 - 2025-04-02 12:28 - 000066820 _____ C:\Users\slave\Downloads\bell-gothic-std (1).zip
2025-04-02 12:18 - 2025-04-02 12:18 - 002010042 _____ C:\Users\slave\Downloads\SF_Pontona (1).eps
2025-04-02 12:18 - 2025-04-02 12:18 - 001278704 _____ C:\Users\slave\Downloads\SF_Ad_Connecting_216x303_2024_print (1).pdf
2025-04-02 12:17 - 2025-04-02 12:18 - 009355080 _____ C:\Users\slave\Downloads\Kajen1c.jpg (1).jpeg
2025-03-31 14:09 - 2025-03-31 14:10 - 000000000 ____D C:\Users\slave\Downloads\Squid Game - Season 2
2025-03-31 13:31 - 2025-03-31 13:31 - 016518211 _____ C:\Users\slave\Downloads\3d-mockup-1_DJL.pdf
2025-03-31 13:26 - 2025-03-31 13:26 - 001438821 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L3m_DJL.pdf
2025-03-31 13:26 - 2025-03-31 13:26 - 001312019 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L1m_DJL.pdf
2025-03-31 13:26 - 2025-03-31 13:26 - 000899370 _____ C:\Users\slave\Downloads\Real Estate Investing for Engineers - L2m_DJL.pdf
2025-03-31 11:36 - 2025-03-31 11:36 - 000396160 _____ C:\Users\slave\Downloads\Neyemi Leve 6 - Creole - Gregory Toussaint.epub
2025-03-31 10:13 - 2025-03-31 10:15 - 213995520 _____ C:\Users\slave\Downloads\calibre-64bit-8.1.1.msi
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-30 14:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-30 14:03 - 2024-09-09 12:22 - 000000000 ____D C:\Program Files (x86)\Steam
2025-04-30 13:57 - 2024-09-16 23:13 - 000000000 ____D C:\Users\slave\AppData\Roaming\utorrent
2025-04-30 13:54 - 2024-09-09 12:28 - 000000000 ____D C:\Users\slave\AppData\Local\Discord
2025-04-30 13:54 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-04-30 13:54 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-30 13:38 - 2024-09-09 14:32 - 000000000 ___HD C:\adobeTemp
2025-04-30 13:38 - 2024-09-09 12:24 - 000000000 ____D C:\Program Files\Adobe
2025-04-30 13:09 - 2021-01-05 08:03 - 000000000 ___SD C:\Users\slave\AppData\Roaming\Microsoft\Credentials
2025-04-30 13:02 - 2024-10-18 03:43 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-04-30 13:02 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-30 12:54 - 2024-09-09 16:21 - 000000000 ____D C:\Users\slave\AppData\Local\CrashDumps
2025-04-30 12:39 - 2025-02-14 11:32 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Word
2025-04-30 10:08 - 2025-02-14 11:32 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Office
2025-04-30 09:19 - 2021-01-05 08:04 - 000000000 ____D C:\Users\slave\AppData\Local\Packages
2025-04-30 02:23 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-30 02:23 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-30 01:55 - 2024-09-09 12:28 - 000000000 ____D C:\Users\slave\AppData\Roaming\discord
2025-04-30 00:26 - 2025-02-14 11:33 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\UProof
2025-04-29 22:55 - 2025-02-14 11:41 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Excel
2025-04-29 18:58 - 2024-09-09 12:24 - 000000000 ____D C:\Users\slave\AppData\Local\Dropbox
2025-04-29 18:58 - 2024-09-09 12:23 - 000000000 ____D C:\Users\slave\AppData\Roaming\Dropbox
2025-04-29 18:57 - 2024-09-09 12:22 - 000000000 ____D C:\Program Files (x86)\Dropbox
2025-04-29 14:30 - 2025-02-15 13:51 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-04-29 14:30 - 2025-02-14 11:18 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-04-29 14:30 - 2025-02-14 11:18 - 000002132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-29 14:30 - 2025-01-27 22:02 - 000003546 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2574191415-932531762-3141445119-1001
2025-04-29 14:30 - 2024-10-18 03:47 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2574191415-932531762-3141445119-1001
2025-04-29 10:15 - 2021-01-05 08:04 - 000000000 ____D C:\Users\slave\AppData\Roaming\Adobe
2025-04-29 09:59 - 2024-09-09 14:18 - 000000000 ____D C:\Users\slave\OneDrive\Documents\ViberDownloads
2025-04-28 09:54 - 2024-10-01 12:30 - 000000000 ____D C:\Users\slave\AppData\Roaming\Telegram Desktop
2025-04-28 09:54 - 2024-09-09 14:17 - 000000000 ____D C:\Users\slave\AppData\Roaming\ViberPC
2025-04-28 01:37 - 2024-10-18 03:44 - 000000000 ____D C:\Users\slave
2025-04-27 13:26 - 2024-09-09 17:46 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-27 10:25 - 2024-10-18 03:52 - 001360668 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-27 10:18 - 2024-10-18 03:47 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-27 10:18 - 2024-10-18 03:45 - 000004526 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-27 10:18 - 2021-01-05 07:58 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-27 09:19 - 2024-09-09 12:14 - 000000000 ____D C:\Users\slave\AppData\Local\D3DSCache
2025-04-26 16:02 - 2021-01-05 07:58 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-26 12:23 - 2024-09-09 12:17 - 000000000 ____D C:\Users\slave\AppData\Local\AMD_Common
2025-04-26 12:17 - 2024-09-09 12:12 - 000002249 _____ C:\Users\slave\OneDrive\Desktop\Discord.lnk
2025-04-26 12:16 - 2021-01-05 08:04 - 000000000 ____D C:\ProgramData\Packages
2025-04-26 06:08 - 2024-10-18 03:43 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-04-26 06:08 - 2024-09-09 12:17 - 000000000 ____D C:\ProgramData\Avast Software
2025-04-26 06:08 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-04-26 06:07 - 2024-10-18 03:43 - 001339680 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-26 06:06 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-04-26 06:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-26 03:31 - 2024-10-18 03:47 - 003369984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-04-25 10:33 - 2024-09-09 19:43 - 000000000 ____D C:\Users\slave\AppData\Roaming\vlc
2025-04-24 23:00 - 2024-09-09 12:13 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-24 22:03 - 2024-09-09 12:24 - 000000000 ____D C:\ProgramData\Adobe
2025-04-24 22:03 - 2024-09-09 12:24 - 000000000 ____D C:\Program Files\Common Files\Adobe
2025-04-24 10:56 - 2024-09-09 14:15 - 000000000 ____D C:\Users\slave\AppData\Roaming\calibre
2025-04-24 10:56 - 2024-09-09 14:15 - 000000000 ____D C:\Users\slave\AppData\Local\calibre-cache
2025-04-23 14:03 - 2024-10-01 17:44 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2025-04-22 23:04 - 2024-10-18 03:47 - 000002212 _____ C:\WINDOWS\system32\Tasks\com.amazon.kpr.ncd
2025-04-22 10:19 - 2024-09-19 14:05 - 000000000 ____D C:\ProgramData\boost_interprocess
2025-04-21 20:32 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-21 20:30 - 2025-03-18 08:41 - 000378432 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_8.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 002901544 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000796224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000267840 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000243240 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000153152 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2025-04-21 20:30 - 2025-01-17 14:33 - 000124480 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2025-04-21 20:30 - 2025-01-17 14:33 - 000075304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2025-04-21 20:24 - 2024-09-09 14:17 - 000000000 ____D C:\Users\slave\AppData\Local\Viber
2025-04-21 20:22 - 2025-01-12 21:23 - 000000000 ____D C:\ProgramData\EA Desktop
2025-04-18 14:21 - 2024-10-18 03:47 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-04-18 14:21 - 2024-09-09 15:58 - 000002084 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller.lnk
2025-04-18 14:21 - 2024-09-09 15:58 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-04-17 16:44 - 2025-02-14 11:07 - 000000000 ____D C:\Program Files\Microsoft Office
2025-04-16 15:00 - 2024-09-09 12:20 - 000000000 ____D C:\Users\slave\AppData\Local\Adobe
2025-04-13 15:13 - 2024-10-01 12:37 - 000000000 ____D C:\Users\slave\Downloads\Telegram Desktop
2025-04-12 17:29 - 2024-09-09 12:24 - 000000000 ____D C:\Users\slave\AppData\LocalLow\Adobe
2025-04-12 17:29 - 2024-09-09 12:24 - 000000000 ____D C:\Program Files (x86)\Adobe
2025-04-09 13:46 - 2024-09-09 12:22 - 000393272 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2025-04-09 03:36 - 2024-10-18 03:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-04-09 03:35 - 2024-09-09 12:22 - 001427512 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSP.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000942672 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSnx.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000553528 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswNetHub.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000391760 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswVmm.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000296528 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000282680 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000248376 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswArPot.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000098872 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000084560 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000069688 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000037944 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswKbd.sys
2025-04-09 03:35 - 2024-09-09 12:22 - 000020536 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2025-04-09 03:29 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-09 03:29 - 2024-04-01 10:03 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-09 03:29 - 2024-04-01 10:03 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-04-07 19:40 - 2024-09-09 14:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2025-04-07 19:40 - 2024-09-09 14:15 - 000000000 ____D C:\Program Files\Calibre2
2025-04-07 19:30 - 2024-09-09 12:16 - 000000000 ____D C:\Users\slave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2025-04-07 12:36 - 2024-10-23 20:55 - 000000000 ____D C:\Users\slave\OneDrive\Documents\InDesign GenAI Assets
2025-04-07 12:26 - 2021-01-05 07:58 - 002793175 ____N C:\WINDOWS\Minidump\040725-8500-01.dmp
2025-04-07 11:04 - 2024-09-09 12:28 - 000000000 ____D C:\Users\slave\AppData\Local\SquirrelTemp
2025-04-06 00:57 - 2024-10-18 03:47 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-04-06 00:57 - 2024-10-18 03:47 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-04-05 11:47 - 2024-10-04 17:42 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2024.lnk
2025-04-05 11:45 - 2024-10-04 17:50 - 000001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2024.lnk
2025-04-04 14:15 - 2024-09-16 23:13 - 000000000 ____D C:\Users\slave\AppData\Local\BitTorrentHelper
2025-03-31 11:45 - 2024-09-10 13:02 - 000000000 ____D C:\Users\slave\AppData\Roaming\Amazon
==================== Files in the root of some directories ========
2024-09-09 15:46 - 2024-09-09 15:46 - 000000000 _____ () C:\Users\slave\AppData\Local\oobelibMkey.log
2024-09-09 12:24 - 2024-09-09 12:24 - 000000003 _____ () C:\Users\slave\AppData\Local\updater.log
2024-09-09 12:24 - 2024-09-10 18:12 - 000000424 _____ () C:\Users\slave\AppData\Local\UserProducts.xml
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Dopuna: 30 Apr 2025 20:34
khm, addition.txt
[Link mogu videti samo ulogovani korisnici]
Dopuna: 01 Maj 2025 8:42
uradio jos jedan scan sa malwarebytes, evo izvod
Malwarebytes
[Link mogu videti samo ulogovani korisnici]
-Log Details-
Scan Date: 01-May-25
Scan Time: 09:08
Log File: 07326017-265b-11f0-b04b-9c6b0024c5db.json
-Software Information-
Version: 5.2.11.183
Components Version: 131.0.5227
Update Package Version: 1.0.98553
License: Trial
-System Information-
OS: Windows 11 (Build 26100.3915)
CPU: x64
File System: NTFS
User: System
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Completed
Objects Scanned: 232625
Threats Detected: 22
Threats Quarantined: 0
Time Elapsed: 1 min, 22 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 0
(No malicious items detected)
Registry Value: 1
Adware.Redirector, HKU\S-1-5-21-2574191415-932531762-3141445119-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|ogadflejmplcdhcldlloonbiekhnlopp, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 3
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\OGADFLEJMPLCDHCLDLLOONBIEKHNLOPP, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
File: 18
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 665115DAAFD5A81206077B542305258C, 30F1C8EC0D4E8F519C79165337938D54B181C583E07BFBC5B39892F15D64399E
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 4040D6244534C6F8311E1C796FF35D1A, 4FA02D98C63351E53FD6F8C9E58D7FE367052D42263969D164320F88490E7C70
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\000003.log, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\CURRENT, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\LOCK, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\LOG, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 5466F308390B1F5F2C4AF2E85702111C, 27B53A9D79736CD77094EE39779F8D5AA9FEFD3BF444E3701AF35E0C892BBE82
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\LOG.old, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 37A7A0F92380686510878115EEBAFE51, 7AC46B2B0B67FDD1AA6443C337E95F134B70BB50A472687410AF987BC8CF6FC8
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogadflejmplcdhcldlloonbiekhnlopp\MANIFEST-000001, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 5AF87DFD673BA2115E2FCF5CFDB727AB, F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 4222A438DA6BCC1D56DE66B1348A211F, F7C0CB3FF882698B8341DD9232CDF2F36A7BD671FB9769386296858CCE608AA2
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000007.ldb, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 3FDA5478924259833BDF3B5FF3D148E7, AB8EA76EBE2D45329BD3784440DA22B2339187C4340927E5C5DAF88CC1795A3A
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000008.log, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 225CDADB4C4DCCF52512C92047FD580C, 5B6B30E6890BD553AE9CC8DCB72E4418B12F3EFBCC684600BC4E22BBEF91E67B
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000009.ldb, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 6C94061BDB71C26EA0BDA58DC84DA852, AD11BF2DFE3513D31734FC65DAAD7E0A38C5A44559575B043A6524661E611F0A
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, No Action By User, 9387, 1267259, 1.0.98553, , ame, , ,
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 0E6BC58BC303141EA829A3B64A045F5D, 8803243A48E65EE01CDB7D1EE7C9ABAFD68464B3FB921F326B043EE7628AB4A1
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 39D64F959E5904BE69387974BB76F72A, C8F97363AF2536B550096C409C2FF80F51B22C061D0C3BCD2CFCAFD2F3B29C2D
Adware.Redirector, C:\Users\slave\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 9B11E0F418C060647A15E606AEBD31D1, C3F7D50AFA3B4E8D218DB99F57661CA6EADD4DBFEF7D09D4374ECB4D6778C49C
Adware.Redirector, C:\USERS\SLAVE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, No Action By User, 9387, 1267259, 1.0.98553, , ame, , 4040D6244534C6F8311E1C796FF35D1A, 4FA02D98C63351E53FD6F8C9E58D7FE367052D42263969D164320F88490E7C70
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
|