Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-02-2021
Ran by tomas (administrator) on DESKTOP-CFUMU4V (Dell Inc. G5 5587) (05-03-2021 10:10:30)
Running from C:\Users\tomas\Downloads
Loaded Profiles: tomas
Platform: Windows 10 Pro Version 1909 18363.1379 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files\erl10.6\erts-10.6\bin\epmd.exe
() [File not signed] C:\Program Files\mosquitto\mosquitto.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_12.2.10.0_x86__nzyj5cx40ttqa\iCloud\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_12.2.10.0_x86__nzyj5cx40ttqa\iCloud\APSDaemon.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_12.2.10.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(Atlassian Pty Ltd -> Atlassian) [File not signed] C:\Users\tomas\AppData\Local\SourceTree\app-3.3.4\SourceTree.exe
(Atlassian Pty Ltd -> Simon Tatham) [File not signed] C:\Users\tomas\AppData\Local\SourceTree\app-3.3.4\tools\putty\pageant.exe
(Docker Inc -> ) C:\Program Files\Docker\Docker\resources\com.docker.proxy.exe
(Docker Inc -> ) C:\Program Files\Docker\Docker\resources\docker.exe
(Docker Inc -> ) C:\Program Files\Docker\Docker\resources\vpnkit.exe
(Docker Inc -> ) C:\Program Files\Docker\Docker\resources\vpnkit-bridge.exe
(Docker Inc -> Docker Inc.) C:\Program Files\Docker\Docker\com.docker.service
(Docker Inc -> Docker Inc.) C:\Program Files\Docker\Docker\Docker Desktop.exe
(Docker Inc -> Docker Inc.) C:\Program Files\Docker\Docker\resources\com.docker.backend.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\egui.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Fabio Spampinato) [File not signed] C:\Users\tomas\AppData\Local\Programs\notable\Notable.exe <4>
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <43>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler64.exe
(Hewlett Packard -> Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
(Hewlett Packard -> Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe
(Chaos Software Ltd. -> ) [File not signed] C:\Program Files\Chaos Group\V-Ray\Swarm 1.4\register-service.exe
(Chaos Software Ltd. -> ) C:\Program Files\Chaos Group\VRLService\OLS\vrol.exe
(Chaos Software Ltd.) [File not signed] C:\Program Files\Chaos Group\V-Ray\Swarm 1.4\swrm.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_efb119a73d6b56f6\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_efb119a73d6b56f6\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_577b4722c749a41f\OneApp.IGCC.WinService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_ff5b2fc3560f4482\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_ff5b2fc3560f4482\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_f881c4be237ce854\RstMwService.exe
(Intel(R) Software Development Products -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_4a7a369b84fff822\aesm_service.exe
(Intel(R) Trust Services -> Intel(R) Corporation) C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\SocketHeciServer.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(JetBrains s.r.o. -> ) C:\Users\tomas\AppData\Local\JetBrains\Toolbox\bin\jetbrains-toolbox-helper.exe <3>
(JetBrains s.r.o. -> JetBrains) C:\Users\tomas\AppData\Local\JetBrains\Toolbox\bin\jetbrains-toolbox.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\tomas\AppData\Local\Microsoft\Teams\current\Teams.exe <9>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\lxss\wslhost.exe <4>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\pacjsworker.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wsl.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Windows Hardware Compatibility Publisher -> Rivet Networks) C:\Windows\System32\drivers\RivetNetworks\Killer\KillerNetworkService.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\vmwp.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_f49f57063392e9ac\Display.NvContainer\NVDisplay.Container.exe <2>
(Open Source Developer, Maksim Moisiuk -> ConEmu-Maximus5) C:\Users\tomas\cmder\vendor\conemu-maximus5\ConEmu\ConEmuC64.exe
(Open Source Developer, Maksim Moisiuk -> ConEmu-Maximus5) C:\Users\tomas\cmder\vendor\conemu-maximus5\ConEmu64.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Popcorn Time) [File not signed] C:\Program Files (x86)\Popcorn Time\Updater.exe
(Pulse Secure, LLC -> ) C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\Pulse.exe
(Pulse Secure, LLC -> Pulse Secure, LLC) C:\Program Files (x86)\Common Files\Pulse Secure\JUNS\PulseSecureService.exe <2>
(Pulse Secure, LLC -> Pulse Secure, LLC) C:\Program Files (x86)\Pulse Secure\Common Files\dsNcService.exe
(Pulse Secure, LLC -> Pulse Secure, LLC) C:\Users\tomas\AppData\Roaming\Pulse Secure\Setup Client\PulseSetupClient.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <3>
(Slack Technologies, Inc. -> Slack Technologies Inc.) C:\Users\tomas\AppData\Local\slack\app-4.14.0-beta1\slack.exe <7>
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
(Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo.inf_amd64_043a570d84e7e965\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo.inf_amd64_043a570d84e7e965\WavesSysSvc64.exe
(WhatsApp, Inc -> WhatsApp) C:\Users\tomas\AppData\Local\WhatsApp\app-2.2106.10\WhatsApp.exe <6>

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [834336 2019-02-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\Windows\System32\DriverStore\FileRepository\wavesapo.inf_amd64_043a570d84e7e965\WavesSvc64.exe [1229072 2018-03-08] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe"
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [2109064 2019-11-27] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [Cm106Sound] => C:\Windows\Syswow64\cm106.dll [13463552 2015-08-11] (C-Media Corporation) [File not signed]
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-10-26] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [710264 2020-06-18] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [PulseSecure] => C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\Pulse.exe [4087936 2020-07-20] (Pulse Secure, LLC -> )
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [com.squirrel.WhatsApp.WhatsApp] => C:\Users\tomas\AppData\Local\WhatsApp\Update.exe [2252488 2021-02-27] (WhatsApp, Inc -> )
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50011008 2021-01-20] (Google LLC -> )
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett Packard -> Hewlett-Packard Co.)
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\tomas\AppData\Local\Microsoft\Teams\Update.exe [2453656 2021-02-22] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [com.squirrel.slack.slack] => C:\Users\tomas\AppData\Local\slack\slack.exe [308368 2021-03-02] (Slack Technologies, Inc. -> Slack Technologies Inc.)
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [Facebook.MessengerDesktop] => C:\Users\tomas\AppData\Local\Programs\Messenger\Messenger.exe [110793432 2021-01-28] (Facebook, Inc. -> Facebook, Inc.)
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [sws] => C:\Users\tomas\AppData\Local\Programs\safe-watch\resources\app\swch_go_service\swch_go_service.exe [10253872 2020-09-22] (OPEN VIDEO, TOV -> )
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32440376 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [JetBrains Toolbox] => C:\Users\tomas\AppData\Local\JetBrains\Toolbox\bin\jetbrains-toolbox.exe [7721248 2021-02-03] (JetBrains s.r.o. -> JetBrains)
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\Run: [Docker Desktop] => C:\Program Files\Docker\Docker\Docker Desktop.exe [2554816 2021-03-02] (Docker Inc -> Docker Inc.)
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\MountPoints2: {2199e05f-9616-11ea-b2b5-3c6aa7f536f5} - "E:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-434153615-1448201401-3235158447-1001\...\MountPoints2: {9abb4ff9-9800-11e9-b207-3c6aa7f536f5} - "E:\HiSuiteDownLoader.exe" 
HKU\S-1-5-18\...\Run: [Docker Desktop] => C:\Program Files\Docker\Docker\com.docker.service [16352 2021-03-02] (Docker Inc -> Docker Inc.)
HKLM\...\Print\Monitors\HP B011 Status Monitor: C:\Windows\system32\hpinkstsB011LM.dll [331664 2012-06-13] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP Deskjet 3520 series): C:\Windows\system32\HPDiscoPMB011.dll [741480 2012-10-17] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\Port pro virtualizaci Xerox: C:\Windows\system32\x5lrsl.dll [127488 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Xerox Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\88.0.4324.190\Installer\chrmstp.exe [2021-02-23] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{4B9CAC01-6732-40d0-8B8F-B5B340F9D44F}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2020-07-20] (Pulse Secure, LLC -> )
HKLM\Software\...\Authentication\Credential Providers: [{4EFD0F35-BFBA-44eb-8F25-2B3530203C1D}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2020-07-20] (Pulse Secure, LLC -> )
HKLM\Software\...\Authentication\Credential Providers: [{C1258FBC-F04F-4862-B78A-DDAAEF4A9707}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2020-07-20] (Pulse Secure, LLC -> )
HKLM\Software\...\Authentication\Credential Providers: [{EAB1A79F-DFAA-4faf-A7B9-A6652E97EE16}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2020-07-20] (Pulse Secure, LLC -> )
HKLM\Software\...\Authentication\Credential Provider Filters: [{3884BCAA-C611-4e2d-9105-E11B1203294E}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2020-07-20] (Pulse Secure, LLC -> )
HKLM\Software\...\Authentication\PLAP Providers: [{60442b50-aac2-4db7-b9b0-813d2107287d}] -> C:\Windows\system32\dsNcSmartCardProv.dll [2019-04-25] (Pulse Secure, LLC -> Pulse Secure, LLC)
HKLM\Software\...\Authentication\PLAP Providers: [{9f4a51de-92b1-483a-b717-dd7d3bb7d3db}] -> C:\Windows\system32\dsNcCredProv.dll [2019-04-25] (Pulse Secure, LLC -> Pulse Secure, LLC)
Startup: C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Poslat do aplikace OneNote.lnk [2020-11-09]
ShortcutTarget: Poslat do aplikace OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {037F220F-F229-48A8-8C99-122D9DE76158} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {0C60FDD3-F8FB-40C4-A990-8F466E57A75D} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
Task: {110A2A15-BCAE-4D85-B0BB-2DDBF162E746} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5199792 2021-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {129FEF76-39F4-468E-82BF-0369F96AFBD8} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849264 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1A9C80F8-0B8C-4F28-B69C-24B97DEADAA4} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2A0606C1-97E9-4E97-80D9-23F35ADFD011} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5199792 2021-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {3529751F-F795-45D3-8CC5-5647BE2AF0B9} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\Passport for Work alert created by enrollment client => C:\Windows\system32\deviceenroller.exe [557056 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {37ABF1C9-1C49-4B7C-8E30-B2F9DE2210C2} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4047464 2021-02-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {3EBC307D-882E-41C7-8B84-93B1D9D71215} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\CCleanerSkipUAC" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\HPCustParticipation HP Deskjet 3520 series" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(10): schtasks.exe -> /Change /TN "\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(11): schtasks.exe -> /Change /TN "\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(12): schtasks.exe -> /Change /TN "\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(13): schtasks.exe -> /Change /TN "\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(14): schtasks.exe -> /Change /TN "\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE
Task: {3FF58A10-7ABE-4023-8EDB-D6FBAEC3FE6C} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(15): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {40E1F338-233C-4062-90FF-7996617A6C77} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-06-07] (Google Inc -> Google LLC)
Task: {466AA3D4-4E6A-4E0D-9B24-10B0167FB0D7} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\Schedule to run OMADMClient by server => C:\Windows\system32\omadmclient.exe [333824 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {47B7B064-5BC6-49DF-8F8D-DC74BEF3E7A1} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\Schedule #3 created by enrollment client => C:\Windows\system32\deviceenroller.exe [557056 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {47FD5390-4D4F-4781-8E50-56DC21D4D1EA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-06-07] (Google Inc -> Google LLC)
Task: {48D36289-273E-48FA-BB31-4FDE0FE28578} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [670928 2020-11-23] (Mozilla Corporation -> Mozilla Foundation)
Task: {54681805-D9FC-4783-B9D6-40EDAB3C8203} - System32\Tasks\HPCustParticipation HP Deskjet 3520 series => C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPCustPartic.exe [4119656 2012-10-17] (Hewlett Packard -> Hewlett-Packard Co.)
Task: {6183D865-2024-400F-8738-61E621410E25} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {6257280F-C53B-4914-A0DD-456C149ED119} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142152 2021-02-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {6AD07F5A-9E5D-420E-9848-D032D4A94307} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22993800 2021-02-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {738C89B0-450D-4032-95C3-ABB3CC2B4A58} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
Task: {7E0185DC-4DCD-4994-94DB-ACA2FDC57BC7} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\Schedule to run OMADMClient by client => C:\Windows\system32\omadmclient.exe [333824 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {843FE5D9-F83B-481F-AC80-CDB1B16A3905} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8FB40832-66B2-45BF-9F56-3A8A2F2F0F95} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [590704 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9BDAA394-B094-4F54-BE20-C0CDBA76A3C2} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\Maintenance Schedule created by enrollment client => C:\Windows\system32\deviceenroller.exe [557056 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {A6B24BFC-4041-4FB8-A4E4-D6BD33E476AE} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\Win10 S Mode event listener created by enrollment client => C:\Windows\system32\deviceenroller.exe [557056 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {A9DFF382-1013-4B4D-B259-6EE3567B1D6C} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {AAB7B01A-F4CE-4737-BD08-7C5184825CAF} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B0470393-E96B-4D1F-9ADB-523EFD367CED} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: {B3AB40F1-9469-47DE-9655-50194171DDF0} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe
"C:\Windows\System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected" was unlocked. <==== ATTENTION
Task: {BD3BC7C1-2312-4361-9A96-C2FF140CE8A6} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {BD91661D-9A73-4C15-B678-3939B5914819} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C09AF7A2-42CF-4113-BB20-71D14E8D7E82} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142152 2021-02-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {C15A9294-05B2-4936-8583-E9C9AA4C5B22} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22993800 2021-02-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {E4BE9466-31CB-4AF7-BBB2-B140748F6A71} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\Provisioning initiated session => C:\Windows\system32\deviceenroller.exe [557056 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {E63B0029-3F6F-4430-9AF6-6A67A3054D31} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849264 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EE4F0DF5-3796-4191-843F-E9BD67242D2B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [26913848 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {F95129DB-F56C-42F7-A33E-67ABC2BC2C02} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\6C5A9F00-50DE-4392-8402-A5151D3CF5EC\OS Edition Upgrade event listener created by enrollment client => C:\Windows\system32\deviceenroller.exe [557056 2021-02-10] (Microsoft Windows -> Microsoft Corporation)
"C:\Windows\System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up" was unlocked. <==== ATTENTION
Task: {FB44A509-B845-445B-A99D-3DDDF20E6994} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2302168 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-434153615-1448201401-3235158447-1001] => hxxp://proxycz.oskarmobil.cz:3128
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{316d9691-0bb7-42f6-b51e-eb5326949f9a}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{896ee571-3ff5-4042-9c61-af9827dbf559}: [DhcpNameServer] 172.20.240.11 172.20.240.12
Tcpip\..\Interfaces\{9ba0ca5c-55e1-47c3-95e0-ad2cac1161b9}: [NameServer] 172.20.240.11,172.20.240.12

Edge: 
=======
Edge Profile: C:\Users\tomas\AppData\Local\Microsoft\Edge\User Data\Default [2021-03-01]

FireFox:
========
FF DefaultProfile: hu6zp8ix.default
FF ProfilePath: C:\Users\tomas\AppData\Roaming\Mozilla\Firefox\Profiles\hu6zp8ix.default [2020-03-22]
FF ProfilePath: C:\Users\tomas\AppData\Roaming\Mozilla\Firefox\Profiles\rp9qwdk3.default-release [2021-02-15]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-09-27] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-07-31] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-07-31] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1065.0\npAvastBrowserUpdate3.dll [No File]
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1065.0\npAvastBrowserUpdate3.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-09-27] (Adobe Inc. -> Adobe Systems)
FF Plugin HKU\S-1-5-21-434153615-1448201401-3235158447-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\tomas\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-14] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-434153615-1448201401-3235158447-1001: SkypeForBusinessPlugin-16.2 -> C:\Users\tomas\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-434153615-1448201401-3235158447-1001: SkypeForBusinessPlugin64-16.2 -> C:\Users\tomas\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi-x64.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2021-03-05]

Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default [2021-03-05]
CHR Notifications: Default -> hxxps://eshop.tescoma.cz; hxxps://messages.google.com; hxxps://www.4camping.cz
CHR HomePage: Default -> hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP9BC2B3EC-6B6A-4A99-9188-260E5A2BFD14&SSPV=
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP9BC2B3EC-6B6A-4A99-9188-260E5A2BFD14&SSPV=","hxxp://search.filebulldog.com/vmn/A9B459D39B2C94AD3FE8EE516875B6ED","hxxp://isearch.avg.com/?cid={43C2ACA3-B029-4EB7-9900-938928CED078}&mid=3d19c9d2e1f942d992e8438d2894e60f-89c8044967e3afe9da456fb6b273b5266464c9e5&lang=en&ds=gf011&pr=sa&d=2013-06-21%2020:03:23&v=15.2.0.5&pid=avg&sg=0&sap=hp","hxxp://search.babylon.com/?affID=112555&tt=060612_8_&babsrc=HP_ss&mntrId=7cb33e2700000000000072f06d3c1314","hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=&SSPV=","hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP853864D9-4B2D-4A20-8073-682D67B9BFF7&SSPV="
CHR DefaultSearchURL: Default -> hxxps://ssl.gstatic.com/images/branding/product/1x/messages_96dp.png
CHR Session Restore: Default -> is enabled.
CHR Extension: (Prezentace) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-05]
CHR Extension: (Bitford) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\agjcpjkkccmhfopfciohkkfolnjbbdoh [2020-03-05]
CHR Extension: (Symantec Authentication Client Extension) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahgdclgdhfeingghldkedleghekbfhef [2020-03-05]
CHR Extension: (Postman Interceptor) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aicmkgpgakddgnaphhhpliifpcfhicfo [2020-05-19]
CHR Extension: (Dokumenty) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-05]
CHR Extension: (Disk Google) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-09]
CHR Extension: (Omnibug) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bknpehncffejahipecakbfkomebjmokl [2021-02-10]
CHR Extension: (YouTube) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-05]
CHR Extension: (Modify Header Value (HTTP Headers)) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbdibdfhahmknbkkojljfncpnhmacdek [2020-05-05]
CHR Extension: (JSONView) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\chklaanhfefbnpoihckbnefhakgolnmc [2020-03-05]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2020-05-21]
CHR Extension: (User-Agent Switcher for Chrome) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\djflhoibgkdhkhhcedjiklpkjnoahfmg [2020-03-05]
CHR Extension: (Xdebug helper) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\eadndfjplgieldjbigjakmdgkmoaaaoc [2020-03-05]
CHR Extension: (Cyfe) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejcimlnjdmkgappmhhmefkloocbephjh [2020-03-05]
CHR Extension: (Tabulky) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-05]
CHR Extension: (React Developer Tools) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmkadmapgofadopljbjfkapdkoienihi [2020-12-05]
CHR Extension: (Dokumenty Google offline) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-02-27]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-02-27]
CHR Extension: (TeamGantt Project Management) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcoffgicdhbbbpdopfhaemdbdglnkcok [2020-03-05]
CHR Extension: (Messages) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpfldicfbfomlpcikngkocigghgafkph [2021-02-09]
CHR Extension: (Redux DevTools) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmhkpmbekcpmknklioeibfkpmmfibljd [2020-03-05]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-01-25]
CHR Extension: (BrowserStack Local) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfiddfehmfdojjfdpfngagldgaaafcfo [2020-03-05]
CHR Extension: (Xdebug) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhodjblplijafdpjjfhhanfmchplpfgl [2020-03-05]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31]
CHR Extension: (Gmail) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-09]
CHR Extension: (Chrome Media Router) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-02-01]
CHR Extension: (Hlídač Shopů) - C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlonggbfebcjelncogcnclagkmkikk [2021-03-04]
CHR Extension: (Vodafone VPN login) - C:\Users\tomas\vodafone [2021-03-02]
CHR Extension: (Autosedacka plugin) - C:\Users\tomas\Disk Google [2021-03-04]
CHR Profile: C:\Users\tomas\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-11-10]
CHR HKU\S-1-5-21-434153615-1448201401-3235158447-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8615864 2020-04-14] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8905608 2021-02-13] (Microsoft Corporation -> Microsoft Corporation)
R2 com.docker.service; C:\Program Files\Docker\Docker\com.docker.service [16352 2021-03-02] (Docker Inc -> Docker Inc.)
R2 dsNcService; C:\Program Files (x86)\Pulse Secure\Common Files\dsNcService.exe [657352 2019-04-25] (Pulse Secure, LLC -> Pulse Secure, LLC)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-26] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-26] (ESET, spol. s r.o. -> ESET)
R2 Killer Network Service x64; C:\Windows\System32\drivers\RivetNetworks\Killer\KillerNetworkService.exe [2327496 2018-04-02] (Microsoft Windows Hardware Compatibility Publisher -> Rivet Networks)
U2 mosquitto; C:\Program Files\mosquitto\mosquitto.exe [337920 2021-02-04] () [File not signed]
S3 OfficeSvcManagerAddons; C:\Windows\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21304 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 OfficeSvcManagerAddons; C:\Windows\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21304 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R2 PulseSecureService; C:\Program Files (x86)\Common Files\Pulse Secure\JUNS\PulseSecureService.exe [354944 2020-07-20] (Pulse Secure, LLC -> Pulse Secure, LLC)
S2 RabbitMQ; C:\Program Files\erl10.6\erts-10.6\bin\erlsrv.exe [226304 2019-12-09] () [File not signed]
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [474256 2019-11-18] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6264144 2021-01-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2020-08-27] (Popcorn Time) [File not signed]
R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [73768 2017-08-17] (Symantec Corporation -> Symantec Corporation)
R2 VRLService; C:\Program Files\Chaos Group\VRLService\OLS\vrol.exe [20464152 2019-12-02] (Chaos Software Ltd. -> )
R2 vrswrm-service; C:\Program Files\Chaos Group\V-Ray\Swarm 1.4\register-service.exe [90176 2019-12-02] (Chaos Software Ltd. -> ) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2101.9-0\NisSrv.exe [2462960 2021-02-23] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2101.9-0\MsMpEng.exe [128376 2021-02-23] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 AdobeARMservice; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [X]
S3 AGMService; "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe" [X]
S3 AGSService; "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_f49f57063392e9ac\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_f49f57063392e9ac\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\Windows\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [160992 2020-10-26] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [109360 2020-10-26] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15288 2020-10-22] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [190464 2020-10-26] (ESET, spol. s r.o. -> ESET)
S2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [43720 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [70048 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [107784 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 jnprns; C:\Windows\system32\DRIVERS\jnprns.sys [507192 2020-07-20] (Juniper Networks, Inc. -> Juniper Networks)
S4 jnprTdi_918_3143; C:\Windows\system32\Drivers\jnprTdi_918_3143.sys [98280 2020-07-20] (Pulse Secure, LLC -> Pulse Secure, LLC)
S3 jnprva; C:\Windows\System32\drivers\jnprva.sys [30072 2020-07-20] (Juniper Networks, Inc. -> Juniper Networks, Inc.)
R3 JnprVaMgr; C:\Windows\System32\drivers\jnprvamgr.sys [45352 2020-07-20] (Juniper Networks, Inc. -> Juniper Networks, Inc.)
S3 PulseSAM; C:\Windows\system32\Drivers\PulseSAM.sys [149040 2020-07-20] (Pulse Secure, LLC -> Pulse Secure, LLC)
R3 RfeCoSvc; C:\Windows\System32\drivers\RivetNetworks\Killer\RfeCo10X64.sys [141480 2018-04-02] (Rivet Networks LLC -> Rivet Networks, LLC.)
S3 SnapCameraVirtualDevice; C:\Windows\System32\drivers\SnapCameraVirtualDevice.sys [2800232 2020-10-12] (Snap Inc. -> Windows (R) Win 7 DDK provider)
S3 USBMULCD; C:\Windows\system32\drivers\CM10664.sys [4135936 2014-01-17] (C-MEDIA ELECTRONICS INC. -> C-Media Electronics Inc)
S3 VOICEMOD_Driver; C:\Windows\system32\drivers\vmdrv.sys [48136 2021-01-18] (Voicemod Sociedad Limitada -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [49552 2021-02-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [419040 2021-02-23] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [71912 2021-02-23] (Microsoft Windows -> Microsoft Corporation)
U1 aswbdisk; no ImagePath
S3 VBAudioVMVAIOMME; \SystemRoot\System32\drivers\vbaudio_vmvaio64_win10.sys [X]
S2 WIBUKEY; SYSTEM32\DRIVERS\WibuKey64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-03-05 10:10 - 2021-03-05 10:11 - 000045138 _____ C:\Users\tomas\Downloads\FRST.txt
2021-03-05 10:10 - 2021-03-05 10:11 - 000000000 ____D C:\FRST
2021-03-05 10:10 - 2021-03-05 10:10 - 002301440 _____ (Farbar) C:\Users\tomas\Downloads\FRST64.exe
2021-03-05 10:06 - 2021-03-05 10:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2021-03-05 10:06 - 2021-03-05 10:06 - 000000000 ____D C:\ProgramData\ESET
2021-03-05 10:06 - 2021-03-05 10:06 - 000000000 ____D C:\Program Files\ESET
2021-03-05 10:04 - 2021-03-05 10:04 - 006341552 _____ (ESET) C:\Users\tomas\Downloads\eset_internet_security_live_installer.exe
2021-03-04 18:02 - 2021-03-04 18:02 - 000880514 _____ C:\Users\tomas\Downloads\web-tooling-benchmark-master.zip
2021-03-04 18:02 - 2021-03-04 18:02 - 000000000 ____D C:\Users\tomas\Downloads\web-tooling-benchmark-master
2021-03-04 16:29 - 2021-03-04 16:29 - 000241385 _____ C:\Users\tomas\Downloads\332592_8502102752.pdf
2021-03-04 14:04 - 2021-03-04 16:23 - 000115394 _____ C:\Users\tomas\Desktop\Hesla Chrome.csv
2021-03-04 11:49 - 2021-03-04 11:49 - 006262527 _____ C:\Users\tomas\Downloads\wsc-spa.5.9.0.1.tgz
2021-03-04 10:54 - 2021-03-04 10:54 - 000145166 _____ C:\Users\tomas\Downloads\žádost Maturová.pdf
2021-03-04 00:11 - 2021-03-04 00:11 - 000033060 _____ C:\Users\tomas\Downloads\[TreZzoR]Utek z Pretorie _ Escape.From.Pretoria.2020.720p.BluRay.DD5.1.x264-iFT.CZ.torrent
2021-03-04 00:09 - 2021-03-04 00:09 - 000060727 _____ C:\Users\tomas\Downloads\[TreZzoR]Utek z Pretorie _ Escape.from.Pretoria.2020.1080p.BluRay.DD 5.1.x264-EDPH.CZ.torrent
2021-03-03 22:43 - 2021-03-03 22:43 - 000029290 _____ C:\Users\tomas\Desktop\vf.yaml
2021-03-03 22:41 - 2021-03-03 22:42 - 000029290 _____ C:\Users\tomas\Desktop\sw.yml
2021-03-03 22:28 - 2021-03-03 22:28 - 000000834 _____ C:\Users\tomas\Desktop\sw2.yaml
2021-03-02 20:02 - 2021-03-02 20:02 - 000002145 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Docker Desktop.lnk
2021-03-02 20:02 - 2021-03-02 20:02 - 000002139 _____ C:\Users\tomas\Desktop\Docker Desktop.lnk
2021-03-02 19:34 - 2021-03-02 19:34 - 011321472 _____ (Tim Kosse) C:\Users\tomas\Downloads\FileZilla_3.52.2_win64-setup.exe
2021-03-02 19:33 - 2021-03-02 19:33 - 003384653 _____ (GnuWin32 <gnuwin32.sourceforge.net> ) C:\Users\tomas\Downloads\make-3.81 (1).exe
2021-03-02 19:33 - 2021-03-02 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GnuWin32
2021-03-02 19:33 - 2021-03-02 19:33 - 000000000 ____D C:\Program Files (x86)\GnuWin32
2021-03-02 18:32 - 2021-03-02 18:32 - 000000509 _____ C:\Users\tomas\.gitconfig
2021-03-02 18:15 - 2021-03-02 18:18 - 000000000 ____D C:\vf
2021-03-02 17:18 - 2021-03-02 17:18 - 001728979 _____ C:\Users\tomas\Downloads\nginx-1.19.7.zip
2021-03-01 15:05 - 2021-03-01 15:29 - 000000000 ____D C:\Users\tomas\Downloads\kamera
2021-03-01 13:00 - 2021-03-01 13:00 - 000087569 _____ C:\Users\tomas\Downloads\Vypis.pdf
2021-03-01 10:29 - 2021-03-01 10:29 - 000117057 _____ C:\Users\tomas\Downloads\COVID19-okresy_-_VZOR-Formular_pro_cesty_mimo_okres_-_20210227.pdf
2021-03-01 10:29 - 2021-03-01 10:29 - 000107996 _____ C:\Users\tomas\Downloads\COVID19-okresy_-_VZOR-Cestne_prohlaseni_-_20210227.pdf
2021-02-25 15:03 - 2021-02-25 15:03 - 000141057 _____ C:\Users\tomas\Downloads\priloha_868730036_0_Inventura OSVČ.pdf
2021-02-24 17:22 - 2021-02-24 17:23 - 000000616 _____ C:\Users\tomas\Documents\Untitled.eps
2021-02-24 14:33 - 2021-02-24 14:33 - 000001004 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Affinity Photo.lnk
2021-02-24 12:35 - 2021-02-24 14:39 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Affinity
2021-02-24 12:35 - 2021-02-24 14:39 - 000000000 ____D C:\ProgramData\Affinity
2021-02-24 12:34 - 2021-02-24 14:33 - 000000000 ____D C:\Program Files\Affinity
2021-02-24 12:34 - 2021-02-24 12:34 - 000001042 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Affinity Designer.lnk
2021-02-23 12:04 - 2021-02-23 12:04 - 000438025 _____ C:\Users\tomas\Documents\Scan0031.pdf
2021-02-23 12:04 - 2021-02-23 12:04 - 000435856 _____ C:\Users\tomas\Documents\Scan0032.pdf
2021-02-22 13:31 - 2021-02-24 13:47 - 000000000 ____D C:\Users\tomas\Downloads\dub
2021-02-22 10:15 - 2020-12-03 06:55 - 026679128 _____ (Intel Corporation) C:\Windows\system32\mfxplugin64_hw.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 013521752 _____ (Intel Corporation) C:\Windows\SysWOW64\mfxplugin32_hw.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 001789712 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2021-02-22 10:15 - 2020-12-03 06:55 - 001789712 _____ C:\Windows\system32\vulkaninfo.exe
2021-02-22 10:15 - 2020-12-03 06:55 - 001385744 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-02-22 10:15 - 2020-12-03 06:55 - 001385744 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2021-02-22 10:15 - 2020-12-03 06:55 - 001096320 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 001096320 _____ C:\Windows\system32\vulkan-1.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000949384 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000949384 _____ C:\Windows\SysWOW64\vulkan-1.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000507736 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000427864 _____ C:\Windows\system32\ze_loader.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000370520 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000306584 _____ C:\Windows\system32\libmfxhw64.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000254488 _____ C:\Windows\SysWOW64\libmfxhw32.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000171544 _____ (Intel Corporation) C:\Windows\system32\intel_gfx_api-x64.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000148824 _____ C:\Windows\system32\ze_validation_layer.dll
2021-02-22 10:15 - 2020-12-03 06:55 - 000146832 _____ (Intel Corporation) C:\Windows\SysWOW64\intel_gfx_api-x86.dll
2021-02-18 14:29 - 2021-02-18 14:29 - 000036502 _____ C:\Users\tomas\Downloads\timesheet_18_02_2021.pdf
2021-02-17 19:13 - 2021-02-17 19:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Node.js
2021-02-17 19:13 - 2021-02-17 19:13 - 000000000 ____D C:\Program Files\nodejs
2021-02-17 19:09 - 2019-03-18 19:20 - 000415232 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\DXCpl.exe
2021-02-17 19:09 - 2019-03-18 18:09 - 000390656 _____ (Windows (R) Win 7 DDK provider) C:\Windows\SysWOW64\DXCpl.exe
2021-02-17 19:08 - 2021-02-17 19:08 - 000000000 ____D C:\ProgramData\Windows App Certification Kit
2021-02-17 19:07 - 2021-02-17 19:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2021-02-17 19:07 - 2021-02-17 19:07 - 000000000 ____D C:\Program Files\Application Verifier
2021-02-17 19:07 - 2021-02-17 19:07 - 000000000 ____D C:\Program Files (x86)\Application Verifier
2021-02-17 19:03 - 2021-02-17 19:11 - 000000000 ____D C:\Program Files (x86)\Microsoft SDKs
2021-02-17 19:03 - 2021-02-17 19:03 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2021-02-17 19:02 - 2021-02-17 19:12 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Visual Studio Setup
2021-02-17 19:02 - 2021-02-17 19:02 - 000001398 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio Installer.lnk
2021-02-17 19:02 - 2021-02-17 19:02 - 000000000 ____D C:\Users\tomas\AppData\Roaming\vstelemetry
2021-02-17 19:02 - 2021-02-17 19:02 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft Visual Studio
2021-02-17 19:02 - 2021-02-17 19:02 - 000000000 ____D C:\Users\tomas\AppData\Local\ServiceHub
2021-02-17 19:02 - 2021-02-17 19:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2017
2021-02-17 19:01 - 2021-02-17 19:02 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2021-02-17 19:01 - 2021-02-17 19:01 - 000000000 ____D C:\ProgramData\Microsoft Visual Studio
2021-02-17 19:00 - 2021-02-17 19:00 - 000000000 ____D C:\Users\tomas\AppData\Local\Package Cache
2021-02-17 19:00 - 2021-02-17 19:00 - 000000000 ____D C:\Python39
2021-02-17 19:00 - 2021-02-17 19:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.9
2021-02-17 18:58 - 2021-02-17 18:58 - 019664896 _____ C:\Users\tomas\Downloads\node-v12.20.2-x64.msi
2021-02-17 18:57 - 2021-02-17 18:58 - 000000000 ____D C:\ProgramData\chocolatey
2021-02-17 18:57 - 2021-02-17 18:57 - 000000000 ____D C:\Users\tomas\AppData\Roaming\NuGet
2021-02-17 18:57 - 2021-02-17 18:57 - 000000000 ____D C:\Users\tomas\AppData\Local\NuGet
2021-02-17 18:53 - 2021-02-17 18:53 - 030326784 _____ C:\Users\tomas\Downloads\node-v14.15.5-x64.msi
2021-02-16 20:51 - 2021-02-16 20:51 - 000157759 _____ C:\Users\tomas\Downloads\Rechnung4319885562.pdf
2021-02-16 20:49 - 2021-02-16 20:49 - 000079716 _____ C:\Users\tomas\Downloads\Vaše faktura 20019488131002.PDF
2021-02-16 20:49 - 2021-02-16 20:49 - 000079716 _____ C:\Users\tomas\Downloads\Vaše faktura 20019488131002 (1).PDF
2021-02-16 12:20 - 2021-02-16 12:20 - 000084666 _____ C:\Users\tomas\Downloads\vfPayRec_20202076311.pdf
2021-02-16 12:18 - 2021-02-16 12:18 - 000084258 _____ C:\Users\tomas\Downloads\vfPayRec_20210326933.pdf
2021-02-16 11:38 - 2021-02-16 11:38 - 000084286 _____ C:\Users\tomas\Downloads\vfPayRec_20204074978.pdf
2021-02-16 11:38 - 2021-02-16 11:38 - 000084286 _____ C:\Users\tomas\Downloads\vfPayRec_20204074978 (1).pdf
2021-02-16 11:38 - 2021-02-16 11:38 - 000084143 _____ C:\Users\tomas\Downloads\vfPayRec_20203658084.pdf
2021-02-16 11:38 - 2021-02-16 11:38 - 000084143 _____ C:\Users\tomas\Downloads\vfPayRec_20203658084 (2).pdf
2021-02-16 11:38 - 2021-02-16 11:38 - 000084143 _____ C:\Users\tomas\Downloads\vfPayRec_20203658084 (1).pdf
2021-02-16 11:37 - 2021-02-16 11:37 - 000084056 _____ C:\Users\tomas\Downloads\vfPayRec_20210176746 (1).pdf
2021-02-16 11:34 - 2021-02-16 11:34 - 000084056 _____ C:\Users\tomas\Downloads\vfPayRec_20210176746.pdf
2021-02-16 11:10 - 2021-02-16 11:10 - 000084258 _____ C:\Users\tomas\Downloads\vfPayRec_20210326933.pdf (1).pdf
2021-02-16 11:10 - 2021-02-16 11:10 - 000084144 _____ C:\Users\tomas\Downloads\vfPayRec_20203645484.pdf.pdf
2021-02-16 10:55 - 2021-02-16 10:55 - 000084258 _____ C:\Users\tomas\Downloads\vfPayRec_20210326933.pdf.pdf
2021-02-15 09:23 - 2021-02-15 09:25 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JetBrains Toolbox
2021-02-15 09:22 - 2021-02-15 09:23 - 365846168 _____ C:\Users\tomas\Downloads\WebStorm-2020.3.2.exe
2021-02-15 09:22 - 2021-02-15 09:22 - 080832696 _____ C:\Users\tomas\Downloads\jetbrains-toolbox-1.20.7940.exe
2021-02-15 09:18 - 2021-02-15 09:24 - 000000000 ____D C:\Program Files\JetBrains
2021-02-15 09:07 - 2021-02-15 09:07 - 000009161 _____ C:\Users\tomas\Downloads\settings.zip
2021-02-15 09:05 - 2021-02-15 09:05 - 378404808 _____ C:\Users\tomas\Downloads\PhpStorm-2020.3.2.exe
2021-02-13 20:20 - 2021-02-13 20:20 - 000080138 _____ C:\Users\tomas\Downloads\podaci_listek-2021-13-02-19-20-21.pdf
2021-02-13 20:11 - 2021-02-13 20:11 - 000504886 _____ C:\Users\tomas\Downloads\_títek pro vrácení zbo_í.pdf
2021-02-13 16:18 - 2021-02-13 16:18 - 000232752 _____ C:\Windows\system32\containerdevicemanagement.dll
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth18.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth17.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth16.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth15.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin
2021-02-13 16:18 - 2021-02-13 16:18 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin
2021-02-11 13:58 - 2021-02-11 14:14 - 000001928 _____ C:\Users\tomas\Downloads\#333333 Copy 2.svg
2021-02-11 09:58 - 2021-02-11 09:58 - 000000000 ____D C:\Users\tomas\AppData\Local\Snap
2021-02-11 09:58 - 2021-02-11 09:58 - 000000000 ____D C:\Users\tomas\AppData\Local\cache
2021-02-11 09:57 - 2020-10-12 20:08 - 002800232 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\SnapCameraVirtualDevice.sys
2021-02-11 09:56 - 2021-02-11 09:56 - 101046760 _____ (Snap Inc. ) C:\Users\tomas\Downloads\Snap Camera 1.11.0.exe
2021-02-10 22:28 - 2021-02-10 22:28 - 002755584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2021-02-10 22:28 - 2021-02-10 22:28 - 002755584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2021-02-10 14:09 - 2021-02-10 14:09 - 000737868 _____ C:\Users\tomas\Downloads\WhatsApp Unknown 2021-02-10 at 14.09.36.zip
2021-02-10 14:09 - 2021-02-10 14:09 - 000000000 ____D C:\Users\tomas\Documents\martin barak
2021-02-10 13:18 - 2021-02-10 13:18 - 000018964 _____ C:\Users\tomas\Downloads\Enabled Google authenticator - 2-Factor Authentication - Security - Binance.pdf
2021-02-10 13:07 - 2021-02-16 10:14 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Binance
2021-02-10 13:05 - 2021-02-10 13:05 - 000001959 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Binance.lnk
2021-02-10 13:05 - 2021-02-10 13:05 - 000000000 ____D C:\Users\tomas\AppData\Local\binance-updater
2021-02-10 13:05 - 2021-02-10 13:05 - 000000000 ____D C:\Program Files\Binance
2021-02-10 13:03 - 2021-02-10 13:04 - 088728600 _____ (BinanceTech) C:\Users\tomas\Downloads\binance-setup.exe
2021-02-10 12:33 - 2021-02-10 12:33 - 000001443 _____ C:\Users\tomas\Desktop\Visual Studio Code.lnk
2021-02-10 12:33 - 2021-02-10 12:33 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Studio Code
2021-02-09 18:06 - 2021-02-09 18:06 - 000067919 _____ C:\Users\tomas\Downloads\Patrick_Hand_SC.zip
2021-02-09 18:01 - 2021-02-09 18:02 - 017399184 _____ C:\Users\tomas\Downloads\graphicriver-5l779JNg-beauty-and-spa-gift-voucher-v32.zip
2021-02-09 17:40 - 2021-02-15 09:01 - 000000000 ____D C:\Program Files\mosquitto
2021-02-09 17:40 - 2021-02-09 17:40 - 001660635 _____ C:\Users\tomas\Downloads\mosquitto-2.0.7-install-windows-x64.exe
2021-02-09 17:39 - 2021-02-09 17:39 - 000000000 ____D C:\Users\tomas\Downloads\mocs16
2021-02-09 17:38 - 2021-02-09 17:38 - 001458895 _____ C:\Users\tomas\Downloads\mos16.9z
2021-02-09 17:21 - 2021-02-09 21:47 - 000000000 ____D C:\Users\tomas\AppData\Roaming\MQTT-Explorer
2021-02-09 17:20 - 2021-02-09 17:20 - 097496392 _____ (Thomas Nordquist) C:\Users\tomas\Downloads\MQTT-Explorer-0.4.0-beta1.exe
2021-02-09 17:16 - 2021-02-09 17:16 - 003866036 _____ C:\Users\tomas\Downloads\TT3-master.zip
2021-02-09 17:16 - 2021-02-09 17:16 - 000000000 ____D C:\Users\tomas\Downloads\TT3-master
2021-02-09 12:14 - 2021-02-09 12:14 - 000002728 _____ C:\Users\tomas\Desktop\Messages.lnk
2021-02-09 10:53 - 2021-02-09 10:53 - 000130315 _____ C:\Users\tomas\Documents\Scan0030.pdf
2021-02-09 00:54 - 2021-02-09 00:54 - 006473120 _____ (H-BIT, d.o.o.) C:\Users\tomas\Downloads\nhm_windows_3.0.5.6.exe
2021-02-08 12:33 - 2021-02-08 12:33 - 000003113 _____ C:\Users\tomas\Downloads\18.02.2021.txt
2021-02-08 12:31 - 2021-02-08 12:31 - 000191010 _____ C:\Users\tomas\Downloads\Zápis z prohlídky_2021001674_210118.pdf
2021-02-08 11:26 - 2021-02-08 11:26 - 001020224 _____ C:\Users\tomas\Downloads\p.Nikl.pdf
2021-02-08 09:54 - 2021-02-08 09:54 - 000000080 ___SH C:\bootTel.dat
2021-02-08 09:54 - 2021-02-08 09:54 - 000000000 __SHD C:\found.000
2021-02-07 20:36 - 2021-02-07 20:36 - 000153401 _____ C:\Users\tomas\Downloads\3d-model.STEP
2021-02-07 19:55 - 2021-02-07 19:55 - 001389071 _____ C:\Users\tomas\Downloads\montazni-navod-indize-typ23.pdf
2021-02-05 17:43 - 2021-02-05 17:43 - 000048982 _____ C:\Users\tomas\Downloads\export_20210205_1742.pdf
2021-02-05 16:43 - 2021-02-05 16:55 - 000000000 ____D C:\Users\tomas\Downloads\notebook
2021-02-05 15:29 - 2021-02-05 15:32 - 000000000 ____D C:\Users\tomas\Downloads\ovladace
2021-02-05 13:25 - 2021-02-05 13:25 - 000000066 _____ C:\Windows\SysWOW64\rufus.ini
2021-02-05 10:52 - 2021-02-05 10:52 - 000049808 _____ C:\Users\tomas\Downloads\[TreZzoR]Windows 7 SP2 (x64_x86) (05_2020)(CZ_SK_EN).torrent
2021-02-05 10:41 - 2021-02-05 10:41 - 000002638 _____ C:\Users\tomas\Desktop\Windows 7 USB DVD Download Tool.lnk
2021-02-05 10:41 - 2021-02-05 10:41 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2021-02-05 10:41 - 2021-02-05 10:41 - 000000000 ____D C:\Users\tomas\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2021-02-04 22:47 - 2021-02-05 13:46 - 000000412 __RSH C:\ProgramData\ntuser.pol
2021-02-04 22:47 - 2021-02-04 22:47 - 001156152 _____ (Akeo Consulting) C:\Users\tomas\Downloads\rufus-3.13p.exe
2021-02-04 22:47 - 2021-02-04 22:47 - 000000069 _____ C:\Users\tomas\Downloads\rufus.ini
2021-02-04 22:06 - 2021-02-04 22:07 - 000000000 ____D C:\Users\tomas\AppData\Roaming\safe-watch
2021-02-04 22:06 - 2021-02-04 22:06 - 000115858 _____ C:\Users\tomas\Downloads\[TreZzoR]Windows 7 Final version 2020 - CZ _ SK _ ENG - USB3 _ NVME _ UEFI .torrent
2021-02-04 21:33 - 2021-02-04 21:33 - 231937254 _____ C:\Users\tomas\Downloads\PassFab_4WinKey_Ultimate_7.1.0.8.rar
2021-02-04 21:30 - 2021-02-04 21:30 - 001682970 _____ C:\Users\tomas\Downloads\601c59720fc8f_PassFab-4WinKey-Ultimate-7108-.zip
2021-02-04 21:23 - 2021-02-04 21:23 - 000069580 _____ C:\Users\tomas\Downloads\iepv.zip
2021-02-04 21:22 - 2021-02-04 21:22 - 003670936 _____ C:\Users\tomas\Downloads\Windows_Password_Key_Standard_trial.exe
2021-02-04 21:17 - 2021-02-05 10:40 - 000001908 _____ C:\Windows\diagwrn.xml
2021-02-04 21:17 - 2021-02-05 10:40 - 000001908 _____ C:\Windows\diagerr.xml
2021-02-04 09:45 - 2021-02-04 09:45 - 001021107 _____ C:\Users\tomas\Downloads\podaci_listek-2021-04-02-08-45-36.pdf
2021-02-04 09:39 - 2021-02-04 09:39 - 001009729 _____ C:\Users\tomas\Downloads\podaci_listek-2021-04-02-08-39-44.pdf
2021-02-03 18:25 - 2021-02-03 18:25 - 000066202 _____ C:\Users\tomas\Downloads\WhatsApp Image 2021-02-03 at 18.17.45.jpeg

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-03-05 10:13 - 2019-06-07 13:48 - 000000600 _____ C:\Users\tomas\AppData\Local\PUTTY.RND
2021-03-05 10:06 - 2019-03-19 05:52 - 000000000 ___HD C:\Windows\ELAMBKUP
2021-03-05 10:06 - 2019-03-19 05:50 - 000000000 ____D C:\Windows\INF
2021-03-05 10:05 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-03-05 10:03 - 2019-06-07 13:38 - 000000000 ____D C:\Users\tomas\AppData\Roaming\WhatsApp
2021-03-05 10:00 - 2019-06-07 13:36 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Slack
2021-03-05 09:53 - 2019-06-07 13:42 - 000000000 ____D C:\Users\tomas\AppData\Local\Docker
2021-03-05 09:52 - 2020-09-08 13:36 - 000000448 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2021-03-05 09:52 - 2019-11-13 07:54 - 000000000 ____D C:\Program Files\CCleaner
2021-03-05 09:52 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\AppReadiness
2021-03-05 09:51 - 2019-06-07 13:21 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-03-04 23:44 - 2019-07-11 10:45 - 000000000 ____D C:\Users\tomas\AppData\Roaming\vlc
2021-03-04 18:03 - 2019-07-09 07:10 - 000000000 ____D C:\Users\tomas\AppData\Roaming\npm-cache
2021-03-04 14:56 - 2020-11-09 11:26 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Notable
2021-03-04 14:55 - 2019-06-07 13:27 - 001694640 _____ C:\Windows\system32\PerfStringBackup.INI
2021-03-04 14:55 - 2019-03-19 12:55 - 000719908 _____ C:\Windows\system32\perfh005.dat
2021-03-04 14:55 - 2019-03-19 12:55 - 000145936 _____ C:\Windows\system32\perfc005.dat
2021-03-04 14:53 - 2019-07-21 10:36 - 000000000 ___RD C:\Users\tomas\Disk Google
2021-03-04 14:51 - 2019-07-18 21:35 - 000000000 ____D C:\ProgramData\NVIDIA
2021-03-04 14:51 - 2019-06-07 13:37 - 000000000 __SHD C:\Users\tomas\IntelGraphicsProfiles
2021-03-04 14:51 - 2019-06-07 13:37 - 000000000 ____D C:\Intel
2021-03-04 14:51 - 2019-06-07 13:36 - 000000000 ____D C:\ProgramData\Goodix
2021-03-04 14:51 - 2019-06-07 13:21 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-03-04 14:51 - 2019-06-07 11:18 - 000000000 ____D C:\ProgramData\DockerDesktop
2021-03-04 14:48 - 2020-03-12 09:40 - 000000128 _____ C:\Users\tomas\AppData\Roaming\PUTTY.RND
2021-03-04 14:48 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2021-03-04 14:48 - 2019-03-19 05:37 - 000786432 _____ C:\Windows\system32\config\BBI
2021-03-04 12:23 - 2019-06-07 11:27 - 000000000 ____D C:\Users\tomas\AppData\Roaming\FileZilla
2021-03-04 10:04 - 2019-08-22 12:28 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Mockoon
2021-03-04 09:59 - 2020-06-05 23:12 - 000003584 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-03-04 09:59 - 2020-06-05 23:12 - 000003460 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-03-04 00:40 - 2019-06-07 20:34 - 000000000 ____D C:\Users\tomas\AppData\Local\CrashDumps
2021-03-04 00:40 - 2019-06-07 19:34 - 000000000 ____D C:\Users\tomas\AppData\Roaming\uTorrent
2021-03-04 00:17 - 2019-10-23 18:58 - 000000000 ____D C:\Users\tomas\AppData\Roaming\qBittorrent
2021-03-03 18:10 - 2019-06-07 14:39 - 000000000 ____D C:\Users\tomas\AppData\Roaming\JetBrains
2021-03-03 15:07 - 2020-03-26 14:44 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Docker Desktop
2021-03-03 13:51 - 2019-11-13 07:54 - 000004210 _____ C:\Windows\system32\Tasks\CCleaner Update
2021-03-02 23:27 - 2019-10-18 07:36 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies Inc
2021-03-02 23:27 - 2019-09-06 23:07 - 000000000 ____D C:\Users\tomas\AppData\Local\slack
2021-03-02 23:27 - 2019-06-07 13:36 - 000002254 _____ C:\Users\tomas\Desktop\Slack.lnk
2021-03-02 23:27 - 2019-06-07 13:36 - 000000000 ____D C:\Users\tomas\AppData\Local\SquirrelTemp
2021-03-02 21:11 - 2019-06-07 11:34 - 000000213 _____ C:\Users\tomas\.yarnrc
2021-03-02 20:06 - 2019-06-07 13:42 - 000000000 ____D C:\Users\tomas\.docker
2021-03-02 20:02 - 2019-06-07 11:15 - 000000000 ____D C:\ProgramData\docker
2021-03-02 19:34 - 2019-06-07 11:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2021-03-02 19:34 - 2019-06-07 11:27 - 000000000 ____D C:\Program Files\FileZilla FTP Client
2021-03-02 18:32 - 2019-06-07 13:26 - 000000000 ____D C:\Users\tomas
2021-03-02 18:24 - 2019-06-07 14:01 - 000000000 ____D C:\Users\tomas\.ssh
2021-03-02 17:43 - 2019-06-07 11:51 - 000000000 ____D C:\Users\tomas\AppData\Local\Composer
2021-03-02 17:14 - 2019-06-07 14:12 - 000000000 ____D C:\Users\tomas\vodafone
2021-03-01 10:26 - 2019-06-07 13:27 - 000000000 ____D C:\Users\tomas\AppData\Local\Packages
2021-02-28 21:28 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2021-02-27 17:09 - 2019-07-02 14:50 - 000000000 ____D C:\ProgramData\AVAST Software
2021-02-27 17:09 - 2019-06-07 13:43 - 000001535 _____ C:\Windows\system32\config\VSMIDK
2021-02-27 17:09 - 2019-06-07 13:21 - 000840656 _____ C:\Windows\system32\FNTCACHE.DAT
2021-02-27 17:01 - 2020-06-05 23:12 - 000002479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-02-27 17:01 - 2019-06-07 13:38 - 000000000 ____D C:\Users\tomas\AppData\Local\WhatsApp
2021-02-24 15:05 - 2020-03-05 11:41 - 000000000 ____D C:\Users\tomas\AppData\LocalLow\Mozilla
2021-02-23 13:28 - 2019-06-07 13:21 - 000000000 ____D C:\Windows\system32\Drivers\wd
2021-02-23 12:20 - 2019-06-07 19:02 - 000799104 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2021-02-23 12:19 - 2020-11-10 19:20 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2021-02-23 10:40 - 2020-11-10 19:21 - 000000000 ____D C:\Users\tomas\AppData\Local\AVAST Software
2021-02-23 10:12 - 2020-03-05 11:49 - 000002344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-02-23 10:08 - 2020-05-17 18:36 - 000002706 _____ C:\Windows\system32\Tasks\HPCustParticipation HP Deskjet 3520 series
2021-02-23 10:08 - 2019-11-13 07:54 - 000002236 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC
2021-02-23 10:08 - 2019-07-18 21:35 - 000003016 _____ C:\Windows\system32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-02-23 10:08 - 2019-07-18 21:35 - 000003016 _____ C:\Windows\system32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-02-23 10:08 - 2019-07-18 21:35 - 000003016 _____ C:\Windows\system32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-02-23 10:08 - 2019-07-18 21:35 - 000002984 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-02-23 10:08 - 2019-07-18 21:35 - 000002956 _____ C:\Windows\system32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-02-23 10:08 - 2019-07-18 21:35 - 000002838 _____ C:\Windows\system32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-02-23 10:08 - 2019-07-18 21:35 - 000002744 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-02-23 10:08 - 2019-06-07 13:29 - 000003400 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2021-02-23 10:08 - 2019-06-07 13:29 - 000003176 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2021-02-22 10:51 - 2019-06-07 13:36 - 000000000 ____D C:\ProgramData\Intel
2021-02-22 10:44 - 2020-10-14 08:44 - 000002407 _____ C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-02-22 10:44 - 2020-10-14 08:44 - 000002399 _____ C:\Users\tomas\Desktop\Microsoft Teams.lnk
2021-02-22 10:15 - 2019-06-23 21:31 - 000000000 ____D C:\Program Files\Microsoft Office
2021-02-20 01:46 - 2020-10-01 23:22 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-02-17 19:11 - 2019-03-19 05:37 - 000000000 ____D C:\Windows\CbsTemp
2021-02-17 19:07 - 2019-06-07 11:39 - 000000000 ____D C:\ProgramData\Package Cache
2021-02-17 19:02 - 2019-09-14 12:36 - 000000000 ____D C:\Program Files (x86)\MSBuild
2021-02-16 11:11 - 2019-07-18 11:07 - 000000000 ____D C:\Users\tomas\AppData\Local\Spotify
2021-02-16 10:47 - 2019-07-18 11:07 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Spotify
2021-02-15 09:33 - 2019-08-05 12:47 - 000000000 ____D C:\Users\tomas\AppData\Local\JetBrains
2021-02-15 09:26 - 2019-08-05 12:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JetBrains
2021-02-15 09:05 - 2020-07-31 12:25 - 000000000 ____D C:\Users\tomas\Ubiquiti UniFi
2021-02-15 09:01 - 2019-07-24 17:51 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MeshLab
2021-02-15 09:01 - 2019-07-24 17:51 - 000000000 ____D C:\Program Files\VCG
2021-02-15 09:00 - 2019-10-23 07:38 - 000000000 ____D C:\Users\tomas\AppData\Local\Deployment
2021-02-14 22:31 - 2020-11-10 19:11 - 000032915 _____ C:\Windows\system32\Drivers\etc\hosts-backup
2021-02-13 23:20 - 2019-06-07 13:43 - 000000000 ____D C:\Program Files\Hyper-V
2021-02-13 23:20 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\ShellExperiences
2021-02-13 23:20 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\bcastdvr
2021-02-13 21:04 - 2019-11-11 19:58 - 000000000 ____D C:\Users\tomas\Documents\Wondershare Filmora 9
2021-02-12 23:08 - 2019-06-07 13:42 - 000000000 ____D C:\Users\tomas\AppData\Local\D3DSCache
2021-02-12 08:55 - 2019-08-17 18:19 - 000000000 ____D C:\Windows\system32\appmgmt
2021-02-12 08:54 - 2019-06-07 13:42 - 000000000 ____D C:\Program Files\Docker
2021-02-12 08:52 - 2019-11-22 19:52 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2021-02-12 08:52 - 2019-07-18 19:06 - 000000000 ____D C:\Program Files\Rockstar Games
2021-02-12 08:50 - 2021-01-29 18:25 - 000000000 ____D C:\Users\tomas\AppData\Local\Bluestacks
2021-02-11 10:07 - 2020-11-27 11:32 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Messenger
2021-02-11 10:07 - 2020-11-27 11:32 - 000000000 ____D C:\Users\tomas\AppData\Local\Messenger
2021-02-11 09:51 - 2019-06-07 13:27 - 000000000 ___RD C:\Users\tomas\3D Objects
2021-02-11 02:39 - 2019-06-07 13:43 - 000000000 ___SD C:\Windows\system32\containers
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\SysWOW64\Dism
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\SystemResources
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\oobe
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\es-MX
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\Dism
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\PolicyDefinitions
2021-02-11 02:39 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\System
2021-02-10 22:34 - 2019-06-07 21:00 - 000000000 ____D C:\Windows\system32\MRT
2021-02-10 22:30 - 2019-06-07 21:00 - 130141752 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-02-10 22:30 - 2019-03-19 12:58 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2021-02-10 22:30 - 2019-03-19 12:58 - 000019469 _____ C:\Windows\system32\OEMDefaultAssociations.xml
2021-02-10 15:02 - 2019-07-23 09:48 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Code
2021-02-10 14:47 - 2019-07-23 09:48 - 000000000 ____D C:\Users\tomas\.vscode
2021-02-09 18:31 - 2020-08-13 19:59 - 000000000 ____D C:\Users\tomas\AppData\Local\Adobe
2021-02-09 13:29 - 2019-06-20 11:47 - 000000000 ____D C:\Users\tomas\AppData\Roaming\wsc-loganalyzer
2021-02-09 12:14 - 2019-06-07 13:36 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2021-02-09 10:53 - 2020-08-13 19:59 - 000000000 ____D C:\Users\tomas\AppData\Roaming\Adobe
2021-02-09 10:52 - 2021-01-26 11:56 - 000000000 ____D C:\Users\tomas\AppData\LocalLow\Adobe
2021-02-05 20:30 - 2020-10-01 23:22 - 000916288 _____ (Microsoft Corporation) C:\Windows\system32\sedplugins.dll
2021-02-05 20:30 - 2020-10-01 23:22 - 000437056 _____ (Microsoft Corporation) C:\Windows\system32\QualityUpdateAssistant.dll
2021-02-04 22:47 - 2019-03-19 05:52 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2021-02-04 22:47 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2021-02-03 15:13 - 2021-02-01 11:38 - 000000000 ____D C:\Users\tomas\Downloads\zehlicka

==================== Files in the root of some directories ========

2020-11-23 20:42 - 2020-11-23 20:42 - 498878504 _____ (Trimble, Inc.) C:\ProgramData\Setup.exe
2020-06-25 11:29 - 2020-03-23 12:51 - 000000033 _____ () C:\Users\tomas\AppData\Roaming\AdobeWLCMCache.dat
2020-03-12 09:40 - 2021-03-04 14:48 - 000000128 _____ () C:\Users\tomas\AppData\Roaming\PUTTY.RND
2019-11-07 08:44 - 2019-11-07 09:29 - 000000027 _____ () C:\Users\tomas\AppData\Local\.sdpl-system-config4
2019-12-11 08:14 - 2020-11-20 01:13 - 000001480 _____ () C:\Users\tomas\AppData\Local\Adobe Uložit pro web 13.0 Prefs
2019-06-27 11:34 - 2020-03-13 11:45 - 000003690 _____ () C:\Users\tomas\AppData\Local\oobelibMkey.log
2019-06-07 13:48 - 2021-03-05 10:13 - 000000600 _____ () C:\Users\tomas\AppData\Local\PUTTY.RND
2020-12-08 00:29 - 2020-12-08 00:29 - 000000218 _____ () C:\Users\tomas\AppData\Local\recently-used.xbel
2020-01-03 07:55 - 2020-12-13 21:17 - 000007625 _____ () C:\Users\tomas\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================