Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-01-2021
Ran by zsako (administrator) on LAPTOP-725JTKII (LENOVO 80T3) (19-01-2021 16:56:21)
Running from C:\Users\zsako\Downloads
Loaded Profiles: zsako
Platform: Windows 10 Pro Version 2004 19041.746 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Facebook Inc) C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_860.5.119.0_x64__8xx8rvfyw5nnt\app\Messenger.exe <6>
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <8>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_01ee1299f4982efe\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_01ee1299f4982efe\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_01ee1299f4982efe\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_01ee1299f4982efe\IntelCpHeciSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\zsako\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2011.16.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Program Files\Synaptics\SynFP\Shared\SensorDBSynch.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated) C:\Windows\System32\valWbioSyncSvc.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2011.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2011.6-0\NisSrv.exe
(Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\AdminService.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TomTom International B.V. -> TomTom) C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696832 2016-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1467400 2016-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1467400 2016-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1467400 2016-09-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1845353984-864646607-3520784098-1001\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [2155992 2020-01-22] (TomTom International B.V. -> TomTom)
HKLM\...\Windows x64\Print Processors\BJ Print Processor4: C:\Windows\System32\spool\prtprocs\x64\CNBPP4.DLL [84992 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\BJ Language Monitor4: C:\WINDOWS\system32\CNBLM4.DLL [267776 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\Installer\chrmstp.exe [2021-01-12] (Google LLC -> Google LLC)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01BBBFA6-7F18-4111-801F-2D2FCD452343} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23061920 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {08C6088E-AFBA-4900-8E25-18A38937D934} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1EDD7408-DE66-4B03-B0B0-773582C5EA86} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116584 2021-01-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {2E7946D1-DB86-48E5-8CDE-0099C97CE004} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23061920 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {6DED6D72-E59F-492A-8235-033D14B5CD71} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6FA43506-7CEE-491E-92A8-EB0ACDE8F5B3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B5BB2641-C2C3-48D8-BC37-D809584B225B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {BAE6C3AC-9748-47C8-AE2C-DDA83F0227CB} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1161112 2021-01-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {C61B44B2-4E0F-41BA-AE2B-73AE60738318} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116584 2021-01-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {CD73382B-2E68-46DB-B608-7FF080FCB1B1} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe
Task: {F085F0D8-4EF7-472B-AAC9-6A8FDE8D5B80} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 213.194.204.126 85.142.148.70
Tcpip\..\Interfaces\{121e6f3b-b15b-4456-9d08-65b494e3e9a5}: [DhcpNameServer] 213.194.204.126 85.142.148.70
Tcpip\..\Interfaces\{2c6a8494-6c9b-4b75-afcf-cd3af9c0d02b}: [DhcpNameServer] 213.194.204.126 85.132.148.70

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\zsako\AppData\Local\Microsoft\Edge\User Data\Default [2021-01-19]

FireFox:
========
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-12-07] (Adobe Inc. -> Adobe Systems Inc.)

Chrome: 
=======
CHR Profile: C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default [2021-01-19]
CHR Notifications: Default -> hxxps://www.dedoles.cz
CHR Extension: (Prezentace) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-03-22]
CHR Extension: (Disk Google) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (YouTube) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-03-22]
CHR Extension: (Tabulky) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-03-22]
CHR Extension: (Dokumenty Google offline) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\zsako\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-08]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8960904 2020-12-25] (Microsoft Corporation -> Microsoft Corporation)
R2 DAX2API; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [154816 2016-07-18] (Dolby Laboratories, Inc. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5198064 2021-01-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 valWBFPolicyService; C:\WINDOWS\system32\valWBFPolicyService.exe [77792 2018-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated)
R2 valWbioSyncSvc; C:\WINDOWS\system32\valWbioSyncSvc.exe [48608 2018-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 ImControllerService; %SystemRoot%\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AsusVBus; C:\WINDOWS\System32\drivers\AsusVBus.sys [39704 2016-11-03] (ASUSTeK Computer Inc. -> Windows (R) Win 7 DDK provider)
S3 ATP; C:\WINDOWS\System32\drivers\AsusTP.sys [84472 2016-11-03] (ASUSTeK Computer Inc. -> ASUS Corporation)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R1 SMIDriverGen; C:\WINDOWS\system32\DRIVERS\smi.sys [31440 2018-04-25] (Synaptics Inc. -> Synaptics Incorporated)
R3 SPUVCbv; C:\WINDOWS\System32\Drivers\SPUVCbv64.sys [899672 2017-10-19] (SUNPLUS INNOVATION TECHNOLOGY INC. -> Sunplus Innovation Technology Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2020-11-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [429296 2020-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [70896 2020-11-20] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-01-19 16:55 - 2021-01-19 16:55 - 000000000 ____D C:\Users\zsako\Downloads\FRST-OlderVersion
2021-01-19 15:50 - 2021-01-19 15:50 - 005048224 _____ C:\Users\zsako\Downloads\doc (3).pdf
2021-01-18 18:01 - 2021-01-18 18:01 - 000470065 _____ C:\Users\zsako\Downloads\LU-DasOdeHaus-losungen.pdf
2021-01-16 16:07 - 2021-01-16 16:07 - 000095744 _____ C:\WINDOWS\system32\VirtualMonitorManager.dll
2021-01-16 16:06 - 2021-01-16 16:06 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2021-01-16 16:06 - 2021-01-16 16:06 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2021-01-16 16:06 - 2021-01-16 16:06 - 000467968 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2021-01-16 16:06 - 2021-01-16 16:06 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2021-01-16 16:06 - 2021-01-16 16:06 - 000157184 _____ C:\WINDOWS\system32\uwfcsp.dll
2021-01-16 16:06 - 2021-01-16 16:06 - 000138056 _____ C:\WINDOWS\system32\HvsiManagementApi.dll
2021-01-16 16:06 - 2021-01-16 16:06 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VBICodec.ax
2021-01-16 16:06 - 2021-01-16 16:06 - 000101704 _____ C:\WINDOWS\SysWOW64\HvsiManagementApi.dll
2021-01-16 16:06 - 2021-01-16 16:06 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2021-01-16 16:05 - 2021-01-16 16:05 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2021-01-16 16:05 - 2021-01-16 16:05 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2021-01-16 16:05 - 2021-01-16 16:05 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2021-01-16 16:05 - 2021-01-16 16:05 - 000053760 _____ C:\WINDOWS\SysWOW64\BWContextHandler.dll
2021-01-16 16:04 - 2021-01-16 16:04 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2021-01-16 16:04 - 2021-01-16 16:04 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\VBICodec.ax
2021-01-16 16:04 - 2021-01-16 16:04 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2021-01-16 16:03 - 2021-01-16 16:03 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2021-01-16 16:03 - 2021-01-16 16:03 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2021-01-16 16:03 - 2021-01-16 16:03 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2021-01-16 16:03 - 2021-01-16 16:03 - 000067072 _____ C:\WINDOWS\system32\BWContextHandler.dll
2021-01-16 16:03 - 2021-01-16 16:03 - 000010894 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-01-16 16:02 - 2021-01-16 16:02 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2021-01-16 16:01 - 2021-01-16 16:01 - 000455680 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2021-01-16 16:01 - 2021-01-16 16:01 - 000446976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2021-01-16 16:00 - 2021-01-16 16:00 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-01-16 16:00 - 2021-01-16 16:00 - 000235520 _____ C:\WINDOWS\SysWOW64\HeatCore.dll
2021-01-16 15:59 - 2021-01-16 15:59 - 001162240 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-01-16 15:59 - 2021-01-16 15:59 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-01-16 15:59 - 2021-01-16 15:59 - 000330752 _____ C:\WINDOWS\SysWOW64\ssdm.dll
2021-01-16 15:59 - 2021-01-16 15:59 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timedate.cpl
2021-01-16 15:57 - 2021-01-16 15:57 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2021-01-16 15:56 - 2021-01-16 15:56 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll
2021-01-16 15:56 - 2021-01-16 15:56 - 000544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2021-01-16 15:56 - 2021-01-16 15:56 - 000190976 _____ C:\WINDOWS\system32\BthpanContextHandler.dll
2021-01-16 15:56 - 2021-01-16 15:56 - 000152064 _____ C:\WINDOWS\system32\EoAExperiences.exe
2021-01-16 15:55 - 2021-01-16 15:55 - 000643072 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2021-01-16 15:54 - 2021-01-16 15:54 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-01-16 15:54 - 2021-01-16 15:54 - 000306688 _____ C:\WINDOWS\system32\HeatCore.dll
2021-01-16 15:53 - 2021-01-16 15:53 - 000165888 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-01-16 15:52 - 2021-01-16 15:52 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-01-16 15:52 - 2021-01-16 15:52 - 000243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
2021-01-16 15:52 - 2021-01-16 15:52 - 000074240 _____ C:\WINDOWS\system32\rdsxvmaudio.dll
2021-01-16 15:51 - 2021-01-16 15:51 - 000455168 _____ C:\WINDOWS\system32\ssdm.dll
2021-01-16 15:08 - 2021-01-16 15:32 - 2975774339 _____ C:\Users\zsako\Downloads\Ve Stínu 2012 CZ, Drama, Krimi, Thriller CSFD-79% (Top Quality) .mkv
2021-01-16 15:05 - 2021-01-16 15:06 - 289311988 _____ C:\Users\zsako\Downloads\Ulice 3972.mp4
2021-01-15 16:01 - 2021-01-15 16:03 - 285037139 _____ C:\Users\zsako\Downloads\ulice 3971.mp4
2021-01-15 16:00 - 2021-01-15 16:03 - 409418508 _____ C:\Users\zsako\Downloads\Ulice 3970.díl.mp4
2021-01-14 16:56 - 2021-01-14 16:57 - 004491481 _____ C:\Users\zsako\Downloads\Reading.pdf
2021-01-13 20:23 - 2021-01-13 20:23 - 000290897 _____ C:\Users\zsako\Downloads\Animals Farm Crossword.pdf
2021-01-13 20:21 - 2021-01-13 20:21 - 000450048 _____ C:\Users\zsako\Downloads\Animals_Farm_Cards.ppt
2021-01-13 19:03 - 2021-01-13 19:03 - 000234501 _____ C:\Users\zsako\Downloads\food-crossword-2012.pdf
2021-01-13 18:42 - 2021-01-13 23:12 - 000000000 ____D C:\Users\zsako\Desktop\Angličtina
2021-01-13 18:34 - 2021-01-13 18:35 - 377791091 _____ C:\Users\zsako\Downloads\Ulice- 3969.mp4
2021-01-13 18:33 - 2021-01-13 18:35 - 269407051 _____ C:\Users\zsako\Downloads\Ulice 3968.mp4
2021-01-12 18:15 - 2021-01-12 18:16 - 100641720 _____ C:\Users\zsako\Downloads\Proficiency 2013 Listening Test Audio (1).7z
2021-01-11 18:37 - 2021-01-11 18:38 - 245824514 _____ C:\Users\zsako\Downloads\25.zip
2021-01-11 18:37 - 2021-01-11 18:38 - 137558916 _____ C:\Users\zsako\Downloads\Krystof-best_of.zip
2021-01-11 18:27 - 2021-01-11 18:29 - 405710619 _____ C:\Users\zsako\Downloads\Ulice 3966 díl.mp4
2021-01-11 18:27 - 2021-01-11 18:29 - 261145696 _____ C:\Users\zsako\Downloads\Ulice 3967.mp4
2021-01-08 16:50 - 2021-01-08 16:51 - 100641720 _____ C:\Users\zsako\Downloads\Proficiency 2013 Listening Test Audio.7z
2021-01-03 12:28 - 2021-01-03 12:28 - 007643327 _____ C:\Users\zsako\Downloads\Advanced-Language-Practice-C1-C2 (1).pdf
2021-01-03 12:28 - 2021-01-03 12:28 - 003210013 _____ C:\Users\zsako\Downloads\168194-c2-proficiency-teachers-handbook (1).pdf
2021-01-01 19:06 - 2021-01-01 19:19 - 2233711470 _____ C:\Users\zsako\Downloads\Mary.Poppins.Returns.2018.1080p.BluRay.x264.mp4
2021-01-01 16:51 - 2021-01-01 16:52 - 000015671 _____ C:\Users\zsako\Downloads\Narozeniny - diář.xlsx
2020-12-28 21:43 - 2020-12-28 21:43 - 001985363 _____ C:\Users\zsako\Downloads\Návod-chrastítko-srneček.pdf
2020-12-28 21:43 - 2020-12-28 21:43 - 001119483 _____ C:\Users\zsako\Downloads\Návod-chrastítko-liška-a-vlk.pdf
2020-12-28 21:43 - 2020-12-28 21:43 - 001106936 _____ C:\Users\zsako\Downloads\Návod-chrastítko-zajíček.pdf
2020-12-28 19:44 - 2020-12-28 19:44 - 002896504 _____ C:\Users\zsako\Downloads\Šátkomaniačky- čtverečková deka.pdf
2020-12-21 17:00 - 2020-12-21 17:01 - 376617535 _____ C:\Users\zsako\Downloads\Zden.zip

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-01-19 17:01 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-19 16:58 - 2020-12-15 18:19 - 000014612 _____ C:\Users\zsako\Downloads\FRST.txt
2021-01-19 16:57 - 2020-12-15 18:18 - 000000000 ____D C:\FRST
2021-01-19 16:55 - 2020-12-15 18:17 - 002295808 _____ (Farbar) C:\Users\zsako\Downloads\FRST64.exe
2021-01-19 16:22 - 2020-01-17 22:12 - 000000000 ____D C:\Users\zsako\AppData\Roaming\Messenger
2021-01-19 16:21 - 2017-09-19 18:56 - 000000000 ___RD C:\Users\zsako\OneDrive
2021-01-19 16:18 - 2020-08-30 16:21 - 000000000 ____D C:\Users\zsako
2021-01-19 16:18 - 2017-09-19 18:51 - 000000000 __SHD C:\Users\zsako\IntelGraphicsProfiles
2021-01-19 16:17 - 2020-08-30 18:08 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-01-19 16:17 - 2020-08-30 17:36 - 000008192 ___SH C:\DumpStack.log.tmp
2021-01-19 16:17 - 2020-08-30 17:36 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-01-19 16:17 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-01-19 16:17 - 2019-03-22 23:02 - 000000000 ____D C:\ProgramData\Synaptics
2021-01-17 15:42 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2021-01-16 17:21 - 2020-08-30 17:50 - 001693136 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-01-16 17:21 - 2019-12-07 15:43 - 000717960 _____ C:\WINDOWS\system32\perfh005.dat
2021-01-16 17:21 - 2019-12-07 15:43 - 000145102 _____ C:\WINDOWS\system32\perfc005.dat
2021-01-16 17:19 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-01-16 17:19 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-01-16 17:14 - 2020-08-30 17:36 - 000437912 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-01-16 17:12 - 2019-12-07 10:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2021-01-16 17:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-01-16 17:08 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2021-01-16 17:08 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-01-16 17:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2021-01-16 17:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-01-16 17:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-01-16 17:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Com
2021-01-16 17:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2021-01-16 17:07 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2021-01-16 17:07 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-01-16 17:07 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\IME
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-01-16 17:07 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-01-16 16:29 - 2019-07-07 09:35 - 000000000 ____D C:\Users\zsako\Downloads\Němčina - Franta
2021-01-16 16:22 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-01-16 15:51 - 2020-08-30 17:46 - 002877952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2021-01-16 15:10 - 2020-08-30 18:08 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-01-16 15:10 - 2020-08-30 18:08 - 000003460 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-01-15 17:27 - 2019-03-23 20:51 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-01-15 17:25 - 2019-03-23 20:51 - 135062968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-01-14 18:21 - 2019-03-22 23:36 - 000000000 ____D C:\Users\zsako\AppData\Local\Packages
2021-01-12 17:30 - 2019-03-22 23:43 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-01-12 17:30 - 2019-03-22 23:43 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-01-12 17:30 - 2019-03-22 23:43 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-01-11 18:52 - 2020-09-16 17:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2021-01-11 18:51 - 2019-04-12 21:52 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-01-11 18:50 - 2020-06-08 19:31 - 000002426 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-01-11 18:50 - 2020-06-08 19:31 - 000002264 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-01-11 18:50 - 2020-06-08 19:31 - 000002264 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================