Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-10-2020
Ran by Davsa (administrator) on DESKTOP-L87B0DG (15-10-2020 22:11:40)
Running from C:\Users\Davsa\Desktop
Loaded Profiles: Davsa
Platform: Windows 10 Pro Version 2004 19041.572 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\DiscoverySrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdntwrk.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe <3>
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12009.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.504_none_e781e76525fb2269\TiWorker.exe
(Michel Krämer) [File not signed] C:\Program Files\Spamihilator\spamihilator.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-827246531-422257092-164193549-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-827246531-422257092-164193549-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> 
Startup: C:\Users\Davsa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Spamihilator.lnk [2020-01-05]
ShortcutTarget: Spamihilator.lnk -> C:\Program Files\Spamihilator\spamihilator.exe (Michel Krämer) [File not signed]

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {167AB33B-ABBA-4823-9F97-CEB2B10F390A} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [491320 2020-06-23] (Bitdefender SRL -> Bitdefender)
Task: {22F53674-9A39-4456-86EA-A6EA8226207C} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [549032 2020-06-29] (Bitdefender SRL -> Bitdefender)
Task: {726835A1-8DAD-4AF9-BDFB-893C60FC23E0} - System32\Tasks\HPCustParticipation HP DeskJet 5000 series => C:\Program Files\HP\HP DeskJet 5000 series\Bin\HPCustPartic.exe [6658184 2017-07-11] (Hewlett Packard -> HP Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9fcb1131-0d7f-4732-b70d-0524be32ffc7}: [DhcpNameServer] 192.168.0.1

Edge: 
======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Davsa\AppData\Local\Microsoft\Edge\User Data\Default [2020-10-15]

FireFox:
========
FF DefaultProfile: qewz2c4w.default
FF ProfilePath: C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default [2020-10-15]
FF Homepage: Mozilla\Firefox\Profiles\qewz2c4w.default -> www.seznam.cz
FF HomepageOverride: Mozilla\Firefox\Profiles\qewz2c4w.default -> Disabled: _65Members_@download.fromdoctopdf.com
FF NewTabOverride: Mozilla\Firefox\Profiles\qewz2c4w.default -> Disabled: _65Members_@download.fromdoctopdf.com
FF Extension: (Adblock Plus Pop-up Addon) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\adblockpopups@jessehakanen.net.xpi [2015-05-29] [Legacy]
FF Extension: (Add-on Compatibility Reporter) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\compatibility@addons.mozilla.org.xpi [2015-05-29] [Legacy]
FF Extension: (Noia 4 Theme Manager) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\Noia4Options@ArisT2.xpi [2014-05-24] [Legacy] [not signed]
FF Extension: (Noia Fox options) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2015-06-21] [Legacy]
FF Extension: (Download Manager (S3)) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\s3download@statusbar.xpi [2019-07-09]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2018-07-07]
FF Extension: (NoScript) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2020-10-12]
FF Extension: (Noia Fox) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2015-08-04] [Legacy]
FF Extension: (ImTranslator: Překladač, Slovník, Hlas) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2020-10-03]
FF Extension: (No Name) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-10-03]
FF Extension: (Download Statusbar) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2015-05-29] [Legacy]
FF Extension: (Aliexpress SuperStar česky, Historie cen a koruny) - C:\Users\Davsa\AppData\Roaming\Mozilla\Firefox\Profiles\qewz2c4w.default\Extensions\{ea692a27-4873-406e-bbc6-010c2dd9e9b5}.xpi [2020-05-11]
FF HKLM\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2020-04-06] [UpdateUrl:hxxps://download.bitdefender.com/windows/desktop/connect/wallet/updates.json ]
FF HKLM\...\Firefox\Extensions: [bdtbe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF Extension: (Bitdefender Anti-tracker) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi [2020-06-29] [UpdateUrl:hxxps://download.bitdefender.com/windows/desktop/connect/antitracker/updates.json ]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2020-05-19] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF HKLM-x32\...\Firefox\Extensions: [bdtbe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbef.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\bd_js_config.js [2020-05-22] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\bd_config.cfg [2020-05-22] <==== ATTENTION

Chrome: 
=======
CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl]
CHR HKLM-x32\...\Chrome\Extension: [khndhdhbebhaddchcgnalcjlaekbbeof]
