Kako piše u naslovu, u Win 10 koristio sam brauzer Edge do večeras. Postojao je Avast Free, ali sam ga jutros bio deinstalirao, a sada neće da primi novu instalaciju jer veli da su ostali delovi programa i da se najpre moraju oni očistiti da bi se postavio novi Avast. A ne vidim ga među programima da bi ih deinstalirao.
Otvaranje Edge se odjednom pretvorilo u otvaranje nekog programa FIND IT, a kažu mi da je virus-trojan ili u svakom slučaju, rekao bih, štetan. Pomagajte!
Kada Windows defender skenira on tvrdi da je našao pretnju, ali ne pokazuje kakvu i ne daje opcije da se ona očisti.
ADW Cleaner nađe neke "potencijalno neželjene programe" ali i kad se oni uklone FIND IT ostaje.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-01-2023
Ran by Radovan (administrator) on DESKTOP-QHE25B4 (Gigabyte Technology Co., Ltd. H81M-DS2) (08-01-2023 21:51:11)
Running from C:\Users\Radovan\OneDrive\Desktop
Loaded Profiles: Radovan
Platform: Microsoft Windows 10 IoT Enterprise LTSC Version 21H2 19044.2364 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\FormatFactory\net_updater64.exe ->) (Bright Data Ltd -> BrightData Ltd. (certified)) C:\ProgramData\BrightData\d71ae678248c6f808fef312e7563ca8a3655c744\brightdata.exe
(C:\Program Files\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\McAfee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(cmd.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(explorer.exe ->) () [File not signed] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <39>
(explorer.exe ->) (Microsoft Corporation) [File not signed] [File is in use] C:\Program Files\Windows Sidebar\sidebar.exe
(explorer.exe ->) (VS Revo Group Ltd. -> VS Revo Group) C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <9>
(services.exe ->) (Bright Data Ltd -> BrightData Ltd. (certified)) C:\Program Files (x86)\FormatFactory\net_updater64.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe
(svchost.exe ->) (Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626440 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626440 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [AtomicAlarmClock6] => C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe [5321728 2016-08-16] () [File not signed]
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [Viber] => C:\Users\Radovan\AppData\Local\Viber\Viber.exe [60743376 2022-12-13] (Viber Media S.à r.l. -> Viber Media S.Ã r.l.)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626440 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [Software Informer] => C:\Program Files\Software Informer\softinfo.exe [1689600 2022-07-30] (Informer Technologies, Inc.) [File not signed]
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [7223248 2022-11-14] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\...\Run: [MicrosoftEdgeAutoLaunch_257AA465338D314A2D2F3ADBEBB84D5B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3879368 2023-01-05] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2226373433-464874539-114592448-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssText3d.scr [224768 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\108.0.5359.125\Installer\chrmstp.exe [2022-12-16] (Google LLC -> Google LLC)
Startup: C:\Users\Radovan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar519.lnk [2022-11-26]
ShortcutTarget: Sidebar519.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) [File not signed] [File is in use]
BootExecute: autocheck autochk * aswBoot.exe /M:16289edb /dir:"C:\Program Files\Avast Software\Avast"
GroupPolicy: Restriction - Chrome <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01C0C9EF-D7BC-445D-A1BE-AD7A1E7BEA90} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {056FE5D8-389B-4E75-958A-BB25F6C3F1A3} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe /from_scheduler:1 (No File)
Task: {10D0820D-DBDE-4584-88A6-62DEE956762D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {1D2C8226-4E5C-42E9-A439-D1A00A778015} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NoUACCheck
Task: {270485DB-1F32-435B-A2FC-75D4A2DBEABA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2BA730EF-5865-4DF0-8E4B-39C055E7173C} - System32\Tasks\Online_KMS_Activation_Script-Renewal => %ProgramData%\Online_KMS_Activation\Activate.cmd Task
Task: {452981B1-4D48-4659-9FBB-7BC5A5B923C9} - System32\Tasks\CCleanerSkipUAC - Radovan => C:\Program Files\CCleaner\CCleaner.exe [32472400 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {49692194-5D7D-41EE-B980-81664F4BE4AB} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2022-11-28] () [File not signed]
Task: {52178561-EB5B-44AE-8F3E-35200428BD8C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {56DB71AE-1AC5-4EAA-8275-E761DAF5F74D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {571B61D1-B283-4BCF-8666-9DFF87A21D13} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {5811F2AF-6BDC-4375-BFCE-592C325F2D5D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8509392 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {60815AA5-CFB8-4A61-AAE7-57D8C978E21A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {626EFF37-19FD-45B1-9A1A-75F348ADAC03} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {65888DCB-39DC-4869-9E55-5AF24499F66E} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [146816 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {92062F27-2007-4316-A7A9-340BE06DB36E} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {9DA43D03-793A-4328-AC1D-C0BEA972C41E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-10-20] (Piriform Software Ltd -> Piriform)
Task: {A291E604-1C41-4795-9B75-3155415BFD78} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "ca5d4853-2b28-455f-ad31-9342d5211014" --version "6.05.10110" --silent
Task: {C8C85472-9D99-4B12-998B-7EAD4F4A9D18} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189064 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {CE99322B-A625-447C-8C61-B97C9523CEC0} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {D1A4DA0F-0479-466E-AC30-1CBA40AAB4B2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2226373433-464874539-114592448-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189064 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {EB135B37-EDAB-4975-BE59-CAAA0844ECE3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8509392 2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {F5BF5DFE-090D-41C4-ABEB-60D6D8295DB4} - System32\Tasks\SoftwareInformerService => C:\Program Files\Software Informer\softinfo.exe [1689600 2022-07-30] (Informer Technologies, Inc.) [File not signed]
Task: {FC404022-1397-4F25-ADDB-A4E4E7D9F6D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Tcpip\..\Interfaces\{63c3661e-c4e1-47fd-bcb5-c30199942196}: [DhcpNameServer] 89.216.1.30 89.216.1.40 89.216.1.50
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default [2023-01-08]
Edge DownloadDir: Default -> D:\01 D DOWNLOAD
Edge Notifications: Default -> hxxps://best-loan-info.com; hxxps://ccleaner-download.xyz; hxxps://mail-notification.info; hxxps://mail.google.com; hxxps://mnthor.xyz; hxxps://pinghauz.xyz; hxxps://s-tracking.xyz; hxxps://supertopfreegames.com; hxxps://www.facebook.com; hxxps://zarabotok-online.xyz
Edge HomePage: Default -> about:tabs
Edge StartupUrls: Default -> "hxxps://find-it.pro/?utm_source=distr_m"
Edge DefaultSearchURL: Default -> hxxp://search-cdn.net/fip/?q={searchTerms}
Edge DefaultSearchKeyword: Default -> cdn
Edge DefaultSuggestURL: Default -> hxxps://www.google.ru/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&q={searchTerms}
Edge Extension: (Mailtrack - Email Tracker for Gmail) - C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cemhcpmgfkheedjjbgflkldmkoiappji [2022-11-25]
Edge Extension: (Adblocker for Youtube™) - C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ggnchfknjkebijkdlbddehcpgfebapdc [2023-01-07] [UpdateUrl:hxxps://clients35.google.com/service/update2/crx] <==== ATTENTION
Edge Extension: (OneNote Web Clipper) - C:\Users\Radovan\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oogbnpmeihfgnccdnmmlgicknopghhma [2022-11-16]
FireFox:
========
FF DefaultProfile: p9ju1wtj.default
FF ProfilePath: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\p9ju1wtj.default [2023-01-07]
FF SearchPlugin: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\p9ju1wtj.default\searchplugins\cdnsearch.xml [2023-01-07]
FF ProfilePath: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\g73xp1r0.default-release [2023-01-08]
FF Homepage: Mozilla\Firefox\Profiles\g73xp1r0.default-release -> hxxps://www.google.com/
FF Notifications: Mozilla\Firefox\Profiles\g73xp1r0.default-release -> hxxps://mail-notification.info; hxxps://zarabotok-online.xyz; hxxps://supertopfreegames.com; hxxps://best-loan-info.com; hxxps://ccleaner-download.xyz; hxxps://pinghauz.xyz; hxxps://s-tracking.xyz; hxxps://mnthor.xyz
FF SearchPlugin: C:\Users\Radovan\AppData\Roaming\Mozilla\Firefox\Profiles\g73xp1r0.default-release\searchplugins\cdnsearch.xml [2023-01-07]
FF Extension: (No Name) - C:\Program Files\Mozilla Firefox\browser\features\{A5735E22-7BD8-4CED-A24E-FBBD2D9CABB9}.xpi [2023-01-07] [not signed]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-11-14] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-12-30] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default [2023-01-08]
CHR DownloadDir: D:\01 D DOWNLOAD
CHR Notifications: Default -> hxxps://best-loan-info.com; hxxps://ccleaner-download.xyz; hxxps://mail-notification.info; hxxps://mnthor.xyz; hxxps://pinghauz.xyz; hxxps://s-tracking.xyz; hxxps://supertopfreegames.com; hxxps://zarabotok-online.xyz
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR Extension: (Torrent Search) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee [2023-01-08]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-12-08]
CHR Extension: (Google News) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllkocilcinkggkchnjgegijklcililc [2022-11-15]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-12-28]
CHR Extension: (Google Docs Offline) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-12-08]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-12-27]
CHR Extension: (Adblocker for Youtube™) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe [2023-01-07] [UpdateUrl:hxxps://clients24.google.com/service/update2/crx] <==== ATTENTION
CHR Extension: (Google Mail Checker) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2022-11-15]
CHR Extension: (SmoothScroll) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbokbjkabcmbfdlbddjidfmibcpneigj [2022-11-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-11-15]
CHR Extension: (AIO Search) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhijjefkkokfaiffkcemldacdabpeei [2022-11-15]
CHR Extension: (Send from Gmail (by Google)) - C:\Users\Radovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2022-11-15]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [dhancbnhabhandieicagelcddkdfgoif] - C:\Program Files (x86)\Allavsoft\Video Downloader Converter\extensions\3.25.0.8302\BVDChromeExt.crx [2022-12-17]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
S2 AtomicAlarmClock; C:\Program Files\Atomic Alarm Clock\timeserv.exe [2007040 2013-04-24] () [File not signed]
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1185616 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12540928 2022-12-18] (Microsoft Corporation -> Microsoft Corporation)
S2 Everything; C:\Program Files (x86)\Everything\Everything.exe [1778184 2022-10-10] (voidtools -> voidtools)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.248.1127.0001\FileSyncHelper.exe [3478912 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
R2 luminati_net_updater_win_formatfactory_pcfreetime_com; C:\Program Files (x86)\FormatFactory\net_updater64.exe [9872976 2023-01-03] (Bright Data Ltd -> BrightData Ltd. (certified))
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [849744 2022-12-09] (McAfee, LLC -> McAfee, LLC)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.248.1127.0001\OneDriveUpdaterService.exe [3845000 2023-01-07] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [224184 2022-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe [3191264 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe [133592 2022-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [31424 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [229208 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [391272 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [297832 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [95960 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [25576 2023-01-07] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [39648 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [267888 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [555560 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [105248 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [80376 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [852000 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [695496 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [212632 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [318456 2023-01-07] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 MpKsld312544d; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{197F1380-2033-4248-AA4C-8F95F2DA77A6}\MpKslDrv.sys [214280 2023-01-08] (Microsoft Windows -> Microsoft Corporation)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2020-10-14] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49568 2022-12-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [473376 2022-12-11] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99616 2022-12-11] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-01-08 21:50 - 2023-01-08 21:51 - 000000000 ____D C:\FRST
2023-01-07 15:56 - 2023-01-08 18:56 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2023-01-07 15:55 - 2023-01-07 15:55 - 000273816 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2023-01-07 15:55 - 2023-01-07 15:55 - 000000000 ____D C:\Program Files\Avast Software
2023-01-07 14:56 - 2023-01-07 14:56 - 006008628 _____ C:\Users\Radovan\OneDrive\Documents\KMSAuto-Net-Portable_EBlJNpwe.exe
2023-01-07 12:53 - 2023-01-07 12:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-01-07 12:53 - 2023-01-07 12:53 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-01-07 12:53 - 2023-01-07 12:53 - 000000000 ____D C:\Program Files\WinRAR
2023-01-07 12:51 - 2023-01-07 15:57 - 000000004 _____ C:\ProgramData\rc.dat
2023-01-07 12:50 - 2023-01-07 15:57 - 000000004 _____ C:\ProgramData\lock.dat
2023-01-07 12:50 - 2023-01-07 13:14 - 000000016 _____ C:\ProgramData\lir.bats
2023-01-07 12:50 - 2023-01-07 12:50 - 000000008 _____ C:\ProgramData\ts.dat
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\xzQPDMqrQnZyvJJzPrR
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\UeOGQDGbBgTU2
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\KfBVaxxIqNosC
2023-01-07 12:46 - 2023-01-07 16:00 - 000000000 ____D C:\Program Files (x86)\cnWDCNXmU
2023-01-07 12:46 - 2023-01-07 15:59 - 000000000 ____D C:\ProgramData\mvBWwLwMpQYvllVB
2023-01-07 12:46 - 2023-01-07 12:46 - 000000000 ____D C:\Program Files (x86)\qZmJDUQbSwUn
2023-01-07 12:45 - 2023-01-07 15:59 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Win32Sync
2023-01-07 12:45 - 2023-01-07 15:57 - 000000000 ____D C:\ProgramData\PrintManager
2023-01-07 12:45 - 2023-01-07 12:58 - 032726866 _____ C:\Users\Radovan\OneDrive\Documents\kmsauto-net-portable-zip
2023-01-07 12:45 - 2023-01-07 12:46 - 000004740 __RSH C:\ProgramData\ntuser.pol
2023-01-07 12:45 - 2023-01-07 12:45 - 006867456 _____ C:\Users\Radovan\AppData\Roaming\Z4Ros270.exe
2023-01-07 12:45 - 2023-01-07 12:45 - 000684984 _____ (Mozilla Foundation) C:\Users\Radovan\AppData\LocalLow\freebl3.dll
2023-01-07 12:45 - 2023-01-07 12:45 - 000627128 _____ (Mozilla Foundation) C:\Users\Radovan\AppData\LocalLow\mozglue.dll
2023-01-07 12:45 - 2023-01-07 12:45 - 000254392 _____ (Mozilla Foundation) C:\Users\Radovan\AppData\LocalLow\softokn3.dll
2023-01-07 12:45 - 2023-01-07 12:45 - 000000014 _____ C:\ProgramData\wefwegge.txt
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\ZCqer9KRKR6
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\hRxnsq3mr
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\dwtjgei1
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\8ZeDrl
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Users\Radovan\AppData\Local\Yandex
2023-01-07 12:45 - 2023-01-07 12:45 - 000000000 ____D C:\Program Files (x86)\Nitter
2023-01-07 12:33 - 2023-01-07 12:35 - 000000000 ____D C:\Program Files\Office 2019 KMS Activator Ultimate 1.7
2023-01-07 12:18 - 2023-01-07 13:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico
2023-01-07 12:18 - 2023-01-07 13:17 - 000000000 ____D C:\Program Files\KMSpico
2023-01-07 12:18 - 2023-01-07 12:18 - 000004608 _____ C:\WINDOWS\SECOH-QAD.exe
2023-01-07 12:18 - 2010-12-06 03:16 - 000090112 _____ (Vestris Inc.) C:\WINDOWS\system32\Vestris.ResourceLib.dll
2023-01-01 19:33 - 2023-01-01 19:53 - 000000000 ____D C:\Users\Radovan\.Icecream Ebook Reader
2023-01-01 19:33 - 2023-01-01 19:33 - 000001224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream Ebook Reader 6.lnk
2023-01-01 19:33 - 2023-01-01 19:33 - 000000000 ____D C:\Users\Radovan\AppData\Local\Icecream
2023-01-01 19:33 - 2023-01-01 19:33 - 000000000 ____D C:\Users\Radovan\AppData\Local\CrashRpt
2023-01-01 19:33 - 2023-01-01 19:33 - 000000000 ____D C:\Program Files (x86)\Icecream Ebook Reader 6
2022-12-29 21:24 - 2022-12-29 21:24 - 000002079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2022-12-29 21:24 - 2022-12-29 21:24 - 000000000 ____D C:\Program Files\Common Files\Adobe
2022-12-29 21:24 - 2022-12-29 21:24 - 000000000 ____D C:\Program Files\Adobe
2022-12-29 18:28 - 2022-12-29 18:28 - 000000000 ____D C:\Program Files (x86)\Korektor
2022-12-28 23:15 - 2022-12-28 23:15 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2022-12-28 21:42 - 2022-12-28 21:42 - 000000000 ____D C:\ProgramData\VS Revo Group
2022-12-28 21:32 - 2022-12-28 21:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\MEGA
2022-12-28 18:44 - 2022-12-28 18:44 - 000002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2022-12-28 18:44 - 2022-12-28 18:44 - 000002467 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project.lnk
2022-12-28 18:44 - 2022-12-28 18:44 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio.lnk
2022-12-28 18:44 - 2022-12-28 18:44 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2022-12-28 18:27 - 2022-12-29 21:25 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\com.adobe.dunamis
2022-12-28 18:27 - 2022-12-28 18:27 - 000000000 ____D C:\Users\Radovan\AppData\Local\SolidDocuments
2022-12-28 18:27 - 2022-12-28 18:27 - 000000000 ____D C:\Users\Radovan\.ms-ad
2022-12-28 17:53 - 2022-12-28 17:54 - 000000000 ____D C:\ProgramData\WinZip
2022-12-28 17:53 - 2022-12-28 17:53 - 000002163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2022-12-28 17:53 - 2022-12-28 17:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2022-12-28 17:53 - 2022-12-28 17:53 - 000000000 ____D C:\Program Files (x86)\WinZip
2022-12-27 02:57 - 2022-12-27 02:57 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Macromedia
2022-12-23 19:55 - 2022-12-23 19:55 - 000000000 ____D C:\Users\Radovan\AppData\Local\ElevatedDiagnostics
2022-12-19 01:30 - 2022-12-30 21:20 - 000000000 ____D C:\Users\Radovan\OneDrive\Documents\FormatFactory
2022-12-17 15:08 - 2022-12-17 15:12 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Allavsoft
2022-12-17 15:08 - 2022-12-17 15:08 - 000000000 ____D C:\Users\Radovan\OneDrive\Documents\Allavsoft
2022-12-17 15:08 - 2022-12-17 15:08 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Allavsoft
2022-12-17 15:08 - 2022-12-17 15:08 - 000000000 ____D C:\Program Files (x86)\Allavsoft
2022-12-15 18:03 - 2022-12-15 18:03 - 000000000 ____D C:\ProgramData\Informer Technologies, Inc
2022-12-15 18:02 - 2023-01-08 21:15 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Software Informer
2022-12-15 18:02 - 2023-01-08 18:56 - 000002556 _____ C:\WINDOWS\system32\Tasks\SoftwareInformerService
2022-12-15 18:02 - 2022-12-15 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software Informer
2022-12-15 18:02 - 2022-12-15 18:02 - 000000000 ____D C:\Program Files\Software Informer
2022-12-14 13:28 - 2022-12-14 13:28 - 000000000 ____D C:\ProgramData\Piriform
2022-12-14 11:34 - 2022-12-14 11:34 - 000000000 ___HD C:\$WinREAgent
2022-12-12 17:20 - 2022-12-18 20:01 - 000000000 ____D C:\ProgramData\Online_KMS_Activation
2022-12-10 20:51 - 2022-12-10 20:52 - 000000000 ____D C:\AdwCleaner
2022-12-10 12:54 - 2022-12-10 12:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magoshare Data Recovery 2.1
2022-12-10 12:54 - 2022-12-10 12:54 - 000000000 ____D C:\Program Files (x86)\Magoshare
2022-12-09 22:33 - 2022-12-09 22:33 - 000000016 _____ C:\ProgramData\mntemp
2022-12-09 22:33 - 2022-12-09 22:33 - 000000000 ____D C:\Program Files\Wondershare
2022-12-09 16:21 - 2022-12-09 16:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Office Tab
2022-12-09 16:21 - 2022-12-09 16:21 - 000000000 ____D C:\Program Files (x86)\ExtendOffice
2022-12-09 16:03 - 2022-12-09 16:03 - 000000000 ___HD C:\$AV_ASW
2022-12-09 15:57 - 2022-12-09 15:57 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\NCH Software
2022-12-09 15:57 - 2022-12-09 15:57 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\D4E0ADC434598A5D
2022-12-09 11:49 - 2022-12-09 18:12 - 000000000 ____D C:\WINDOWS\Panther
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-01-08 21:05 - 2022-11-14 20:21 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\qBittorrent
2023-01-08 21:02 - 2022-11-14 17:59 - 000002516 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-01-08 21:00 - 2022-11-15 01:59 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Everything
2023-01-08 20:52 - 2022-11-15 17:38 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-01-08 20:52 - 2022-11-14 19:31 - 000000000 ____D C:\Users\Radovan\AppData\LocalLow\Mozilla
2023-01-08 20:52 - 2022-11-14 19:31 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-01-08 20:50 - 2022-11-26 17:58 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-01-08 19:39 - 2022-11-26 18:01 - 000003416 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2023-01-08 19:39 - 2022-11-14 19:39 - 000000760 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2023-01-08 19:39 - 2022-11-14 19:39 - 000000000 ____D C:\Program Files\CCleaner
2023-01-08 19:17 - 2022-11-26 18:04 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-01-08 19:17 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2023-01-08 19:12 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-01-08 19:11 - 2022-11-14 18:58 - 000000000 ___RD C:\Users\Radovan\OneDrive
2023-01-08 19:10 - 2022-11-26 18:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-01-08 19:10 - 2022-11-14 18:14 - 000000000 __SHD C:\Users\Radovan\IntelGraphicsProfiles
2023-01-08 19:10 - 2022-11-14 18:11 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2023-01-08 19:10 - 2022-11-14 17:59 - 000008192 ___SH C:\DumpStack.log.tmp
2023-01-08 19:10 - 2019-12-07 10:03 - 000065536 _____ C:\WINDOWS\system32\config\BBI
2023-01-08 19:09 - 2022-11-23 17:20 - 000000000 ____D C:\ProgramData\Avast Software
2023-01-08 18:56 - 2022-11-26 18:01 - 000004056 _____ C:\WINDOWS\system32\Tasks\Online_KMS_Activation_Script-Renewal
2023-01-08 18:56 - 2022-11-26 18:01 - 000003488 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-01-08 18:56 - 2022-11-26 18:01 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2023-01-08 18:56 - 2022-11-26 18:01 - 000003264 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-01-08 18:56 - 2022-11-26 18:01 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2023-01-08 18:56 - 2022-11-26 18:01 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2226373433-464874539-114592448-1001
2023-01-08 18:56 - 2022-11-26 18:01 - 000003024 _____ C:\WINDOWS\system32\Tasks\klcp_update
2023-01-08 18:56 - 2022-11-26 18:01 - 000002716 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2023-01-08 18:56 - 2022-11-26 18:01 - 000002586 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2023-01-08 18:56 - 2022-11-26 18:01 - 000002254 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Radovan
2023-01-08 11:04 - 2022-12-08 19:49 - 000000000 ____D C:\Users\Radovan\OneDrive\Documents\ViberDownloads
2023-01-07 21:36 - 2022-11-14 19:38 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\vlc
2023-01-07 20:16 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-01-07 20:16 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-01-07 15:58 - 2022-11-24 18:22 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2023-01-07 15:55 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-01-07 13:12 - 2022-11-24 18:22 - 000002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-01-07 13:10 - 2022-11-15 02:17 - 000000000 ____D C:\Users\Radovan\AppData\Local\Everything
2023-01-07 12:58 - 2022-11-23 18:14 - 000000000 ____D C:\Users\Radovan\AppData\Local\CrashDumps
2023-01-07 12:46 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2023-01-07 11:49 - 2022-11-15 17:44 - 000000000 ____D C:\Program Files (x86)\Google
2023-01-05 19:27 - 2022-11-14 19:49 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\ImageGlass
2023-01-05 19:26 - 2022-11-29 21:16 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\MPC-HC
2023-01-03 09:53 - 2022-11-22 16:24 - 000000000 ____D C:\Program Files (x86)\FormatFactory
2023-01-01 19:33 - 2022-11-26 17:51 - 000000000 ____D C:\Users\Radovan
2022-12-30 18:47 - 2022-11-14 21:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atomic Alarm Clock
2022-12-30 18:47 - 2022-11-14 21:12 - 000000000 ____D C:\Program Files\Atomic Alarm Clock
2022-12-30 04:34 - 2022-11-14 18:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2022-12-30 04:34 - 2022-11-14 18:56 - 000000000 ____D C:\Program Files\Microsoft Office
2022-12-29 21:25 - 2022-11-14 20:09 - 000000000 ____D C:\Users\Radovan\AppData\Local\Adobe
2022-12-29 21:25 - 2022-11-14 18:15 - 000000000 ____D C:\ProgramData\Packages
2022-12-29 21:25 - 2022-11-14 18:14 - 000000000 ____D C:\Users\Radovan\AppData\Local\Packages
2022-12-29 21:23 - 2022-11-14 20:08 - 000000000 ____D C:\ProgramData\Adobe
2022-12-29 21:20 - 2022-11-26 17:58 - 000467712 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-12-29 21:19 - 2022-11-14 19:31 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-12-29 21:18 - 2022-11-14 20:12 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2022-12-29 21:15 - 2022-11-26 18:01 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-12-29 21:15 - 2022-11-14 19:31 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-12-29 18:28 - 2022-11-14 20:24 - 000000000 ____D C:\ProgramData\Package Cache
2022-12-28 23:14 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2022-12-28 22:26 - 2022-11-22 16:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2022-12-28 22:07 - 2022-11-22 20:38 - 000000000 ____D C:\Program Files (x86)\7-Zip
2022-12-28 22:07 - 2022-11-14 19:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2022-12-28 18:27 - 2022-11-14 20:09 - 000000000 ____D C:\Users\Radovan\AppData\LocalLow\Adobe
2022-12-28 18:27 - 2022-11-14 18:14 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Adobe
2022-12-26 11:14 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2022-12-19 21:23 - 2022-11-22 16:29 - 000007596 _____ C:\Users\Radovan\AppData\Local\resmon.resmoncfg
2022-12-18 19:57 - 2022-11-17 17:49 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\ViberPC
2022-12-18 19:57 - 2022-11-17 17:49 - 000000000 ____D C:\Users\Radovan\AppData\Local\Viber
2022-12-16 01:22 - 2022-11-15 17:45 - 000002253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-12-16 01:22 - 2022-11-15 17:45 - 000002212 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-12-14 12:28 - 2019-12-07 10:51 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-12-14 12:28 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2022-12-14 11:42 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2022-12-14 11:42 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-12-14 11:40 - 2022-11-26 17:59 - 003014656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-12-14 11:33 - 2022-11-14 19:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-12-14 11:30 - 2022-11-14 19:07 - 148633544 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-12-11 20:33 - 2022-11-14 17:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-12-09 22:34 - 2022-11-22 21:06 - 000000000 ____D C:\ProgramData\Wondershare
2022-12-09 22:33 - 2022-11-23 18:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2022-12-09 22:33 - 2022-11-22 21:07 - 000000000 ____D C:\Users\Radovan\AppData\Roaming\Wondershare
2022-12-09 12:28 - 2022-11-15 16:09 - 000000000 ____D C:\Users\Radovan\AppData\Local\D3DSCache
==================== Files in the root of some directories ========
2023-01-07 12:50 - 2023-01-07 15:57 - 000000004 _____ () C:\ProgramData\lock.dat
2023-01-07 12:51 - 2023-01-07 15:57 - 000000004 _____ () C:\ProgramData\rc.dat
2023-01-07 12:50 - 2023-01-07 12:50 - 000000008 _____ () C:\ProgramData\ts.dat
2023-01-07 12:45 - 2023-01-07 12:45 - 006867456 _____ () C:\Users\Radovan\AppData\Roaming\Z4Ros270.exe
2022-11-14 20:08 - 2022-12-29 21:18 - 000000615 _____ () C:\Users\Radovan\AppData\Local\oobelibMkey.log
2022-11-22 16:29 - 2022-12-19 21:23 - 000007596 _____ () C:\Users\Radovan\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
mycity.rs/must-login.png
|