Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-08-2022
Ran by Jana a Ivo (administrator) on DESKTOP-P1SMD4A (LENOVO 90DA00AJCK) (05-08-2022 17:50:32)
Running from C:\Users\Jana a Ivo\Desktop
Loaded Profiles: Jana a Ivo
Platform: Microsoft Windows 10 Home Version 21H2 19044.1826 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\CGMSERVER\bin\pgsql\bin\pg_ctl.exe ->) (CompuGROUP Medical Česká republika s.r.o. -> PostgreSQL Global Development Group) [File not signed] C:\CGMSERVER\bin\pgsql\bin\postgres.exe <53>
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(explorer.exe ->) (Hewlett Packard -> HP Inc.) C:\Program Files\HP\HP OfficeJet Pro 8710\Bin\ScanToPCActivationApp.exe
(explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <14>
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (CompuGroup Medical Česká republika s.r.o. -> CompuGroup Medical Česká republika s.r.o.) [File not signed] C:\CGMSERVER\bin\etrzby-1\cgm.etrzby-1.exe
(services.exe ->) (CompuGroup Medical Česká republika s.r.o. -> CompuGroup Medical Česká republika s.r.o.) C:\CGMSERVER\bin\ecommunication-1\cgm.ecommunication-1.exe
(services.exe ->) (CompuGroup Medical Česká republika s.r.o. -> CompuGroup Medical Èeská republika s.r.o.) C:\CGMSERVER\bin\erepository-1\cgm.erepository-1.exe
(services.exe ->) (CompuGroup Medical Česká republika s.r.o. -> Microsoft) C:\CGMSERVER\bin\core\cgm.servercore.exe
(services.exe ->) (CompuGroup Medical Česká republika s.r.o. -> Microsoft) C:\CGMSERVER\bin\ebooking-1\cgm.ebooking-1.exe
(services.exe ->) (CompuGroup Medical Česká republika s.r.o. -> PostgreSQL Global Development Group) [File not signed] C:\CGMSERVER\bin\pgsql\bin\pg_ctl.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (HCS GmbH) [File not signed] C:\CGMSERVER\bin\medical-net\MedConnect.ServiceManager\HCS.MedConnect.ServiceManager.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (The Apache Software Foundation -> Apache Software Foundation) C:\CGMSERVER\cgm.jetty.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19677472 2020-03-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1803848 2016-08-31] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [194736 2022-06-29] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM-x32\...\Run: [ICAMaintenance_ICAPKIService_RegKeysRefresh] =>  -mode loader -op refreshICAPKIServiceRegistryKeys (No File)
HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Run: [HP OfficeJet Pro 8710 (NET)] => C:\Program Files\HP\HP OfficeJet Pro 8710\Bin\ScanToPCActivationApp.exe [3770504 2018-04-06] (Hewlett Packard -> HP Inc.)
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Run: [MicrosoftEdgeAutoLaunch_BC1E55B6C2D66D9E0B8605D51DB7D860] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3601840 2022-07-28] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\Users\Jana a Ivo\AppData\Local\Programs\Zoner\ZPS X\binary\Program32\ZPSTRAY.EXE [777504 2019-12-10] (ZONER software, a.s. -> ZONER software)
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\Explorer: [NoPreviewPane] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\Explorer: [HideSCANetwork] 0
HKU\S-1-5-21-3178504301-1335594183-2692845351-1001\...\Policies\Explorer: [HideSCAVolume] 0
HKLM\...\Windows x64\Print Processors\hpzpplhn: C:\Windows\System32\spool\prtprocs\x64\hpzpplhn.dll [109080 2018-12-06] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\PrinterPlusPlus: C:\WINDOWS\system32\mfilemon.dll [972000 2019-10-17] (Open Source Developer, Lorenzo Monti -> Monti Lorenzo)
HKLM\...\Print\Monitors\Software602 XPS port monitor: C:\WINDOWS\system32\602localmon.dll [47896 2021-09-23] (Software602 a.s. -> Windows (R) Win 7 DDK provider)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2017-07-26]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation -> Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0F09712B-8C2A-4454-952C-4883F2703A5B} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116648 2022-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {15C569FB-21AF-4941-B941-0B6BC6DFF4A9} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378864 2022-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {2B63C760-7C0A-4E3C-B76A-2298618A14B3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6563280 2022-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {39C73C9B-AB96-4C76-9CE4-03021D676431} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [28048 2022-05-19] (Garmin International, Inc. -> )
Task: {3A594B1F-A805-4EE1-A403-769DC2B89816} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {3B011604-C654-4191-A9CA-4F706AEE4FDD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [136304 2021-03-30] (HP Inc. -> HP Inc.)
Task: {3BAC8E77-9340-49A0-B809-2FF65A15C837} - System32\Tasks\Zoner.Updater.S-1-5-21-3178504301-1335594183-2692845351-1001 => C:\ProgramData\Zoner\Zoner.Installer.Core\Updater.exe [1609080 2022-06-30] (ZONER software, a.s. -> ZONER a.s.)
Task: {471A2079-CEDE-4D4C-B15E-1A3104D4335E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378864 2022-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {558749D7-38D9-4819-A04A-65DF46CA2D42} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {6E0869C1-EA3E-4281-8B89-81A4CEA80BDB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116648 2022-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {713B1499-DC8C-44FA-B2D7-729E01A1F95A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 9DED23DF4360B491 => C:\Program Files\mozilla firefox\default-browser-agent.exe do-task "9DED23DF4360B491"
Task: {9E2BBCB8-F2F7-4582-999B-86C50C57DE33} - System32\Tasks\HPCustPartic.exe_{E0222514-8E27-4CB3-ABB0-BA7D455CDC5A} => C:\Program Files\HP\HP OfficeJet Pro 8710\Bin\HPCustPartic.exe [6439048 2018-04-06] (Hewlett Packard -> HP Inc.)
Task: {A22F6BDF-9B54-4B5D-90C4-A9172E55BABB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.)
Task: {D582C582-7673-4ED1-A70A-9C8888F5C094} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [43096 2022-07-12] (HP Inc. -> HP Inc.)
Task: {DE84368F-ECC8-4BBC-BB87-387DCD7BC367} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [43096 2022-07-12] (HP Inc. -> HP Inc.)
Task: {DEC90019-996B-4941-8F7A-F584F7C565F8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6563280 2022-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {F45335DB-063F-4762-B9E0-42A531D1E8C0} - System32\Tasks\HPCustParticipation HP OfficeJet Pro 8710 => C:\Program Files\HP\HP OfficeJet Pro 8710\Bin\HPCustPartic.exe [6439048 2018-04-06] (Hewlett Packard -> HP Inc.)
Task: {F6982815-A712-4205-B89C-E73C6177F326} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [930960 2022-05-11] (HP Inc. -> HP Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{c88b0fbf-08b9-4c32-b1a0-42a591513cc3}: [DhcpNameServer] 10.0.0.138

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Jana a Ivo\AppData\Local\Microsoft\Edge\User Data\Default [2022-08-05]
Edge Notifications: Default -> hxxps://fastshare.cz

FireFox:
========
FF DefaultProfile: rcwkdnwj.default
FF ProfilePath: C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1 [2022-08-05]
FF Homepage: Mozilla\Firefox\Profiles\z127unu2.default-release-1 -> hxxp://www.seznam.cz/
FF Extension: (Podepisovací komponenta Signer) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\ace.nmsigner@asseco.cz.xpi [2021-06-05]
FF Extension: (AdBlocker Ultimate) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\adblockultimate@adblockultimate.net.xpi [2022-06-05]
FF Extension: (Komponenta I.CA PKI Service) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\icapkiservice@ica.cz.xpi [2021-07-24]
FF Extension: (Google Translator for Firefox) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\translator@zoli.bod.xpi [2021-06-05]
FF Extension: (Gesturefy) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\{506e023c-7f2b-40a3-8066-bc5deb40aebe}.xpi [2022-04-12]
FF Extension: (FormApps Extension) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\{69F080C9-A1D8-42F8-BD83-3D54D4BC81B3}.xpi [2022-03-09]
FF Extension: (Video DownloadHelper) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-07-02]
FF Extension: (No Name) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\z127unu2.default-release-1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-07-06]
FF ProfilePath: C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default [2022-07-31]
FF Homepage: Mozilla\Firefox\Profiles\rcwkdnwj.default -> hxxp://www.seznam.cz/
FF Extension: (Podepisovací komponenta Signer) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\ace.nmsigner@asseco.cz.xpi [2018-07-18]
FF Extension: (AdBlocker Ultimate) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\adblockultimate@adblockultimate.net.xpi [2021-04-04]
FF Extension: (Komponenta I.CA PKI Service) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\icapkiservice@ica.cz.xpi [2018-06-28] [UpdateUrl:hxxps://s.ica.cz/ica_pkiservice/firefox_extension/ICAPKIServiceExtension_ICA_Firefox_update_manifest.json]
FF Extension: (Google Translator for Firefox) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\translator@zoli.bod.xpi [2018-12-02]
FF Extension: (Gesturefy) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\{506e023c-7f2b-40a3-8066-bc5deb40aebe}.xpi [2021-04-02]
FF Extension: (FormApps Extension) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\{69F080C9-A1D8-42F8-BD83-3D54D4BC81B3}.xpi [2017-10-03]
FF Extension: (Video DownloadHelper) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-12-16]
FF Extension: (No Name) - C:\Users\Jana a Ivo\AppData\Roaming\Mozilla\Firefox\Profiles\rcwkdnwj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2021-05-20]
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-07-05] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.321.2 -> C:\Program Files (x86)\Java\jre1.8.0_321\bin\dtplugin\npDeployJava1.dll [2022-03-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.321.2 -> C:\Program Files (x86)\Java\jre1.8.0_321\bin\plugin2\npjp2.dll [2022-03-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2022-08-05]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2021-06-04]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.)
R2 cgm.ebooking-1; C:\CGMSERVER\bin\ebooking-1\cgm.ebooking-1.exe [35680 2019-06-21] (CompuGroup Medical Česká republika s.r.o. -> Microsoft)
R2 cgm.ecommunication-1; C:\CGMSERVER\bin\ecommunication-1\cgm.ecommunication-1.exe [93304 2021-11-12] (CompuGroup Medical Česká republika s.r.o. -> CompuGroup Medical Česká republika s.r.o.)
R2 cgm.erepository-1; C:\CGMSERVER\bin\erepository-1\cgm.erepository-1.exe [24928 2019-02-10] (CompuGroup Medical Česká republika s.r.o. -> CompuGroup Medical Èeská republika s.r.o.)
R2 cgm.etrzby-1; C:\CGMSERVER\bin\etrzby-1\cgm.etrzby-1.exe [22112 2017-05-19] (CompuGroup Medical Česká republika s.r.o. -> CompuGroup Medical Česká republika s.r.o.) [File not signed]
R2 cgm.jetty; C:\CGMSERVER\cgm.jetty.exe [110080 2020-01-22] (The Apache Software Foundation -> Apache Software Foundation)
R2 cgm.servercore; C:\CGMSERVER\bin\core\cgm.servercore.exe [30328 2021-12-15] (CompuGroup Medical Česká republika s.r.o. -> Microsoft)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12111288 2022-07-21] (Microsoft Corporation -> Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [3342536 2022-06-29] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [3342536 2022-06-29] (ESET, spol. s r.o. -> ESET)
S3 HCS.MedConnect.Service; C:\CGMSERVER\bin\medical-net\MedConnect\HCS.MedConnect.Service.exe [46080 2016-11-03] (HCS GmbH) [File not signed]
R2 HCS.MEDCONNECT.SERVICEMANAGER; C:\CGMSERVER\bin\medical-net\MedConnect.ServiceManager\HCS.MedConnect.ServiceManager.exe [91648 2016-11-03] (HCS GmbH) [File not signed]
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [225368 2022-07-12] (HP Inc. -> HP Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [379736 2020-08-20] (HP Inc. -> HP Inc.)
S3 I.CA Maintenance Service2; C:\Program Files (x86)\I.CA\I.CA Maintenance2\ICAMaintenance.exe [299336 2021-02-08] (Prvni certifikacni autorita, a.s. -> I.CA, a.s.)
S2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [69656 2018-12-06] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe [2467088 2020-12-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe [128376 2020-12-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 cgm.postgres; C:/CGMSERVER/bin/pgsql/bin/pg_ctl.exe runservice -N "cgm.postgres" -D "C:/CGMSERVER/data/pgsql" [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [146856 2015-03-10] (BoiseTest -> Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [21928 2015-03-10] (BoiseTest -> Windows (R) Win 7 DDK provider)
S3 Dot4Scan; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [14760 2015-03-10] (BoiseTest -> Microsoft Corporation)
S3 dot4usb; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [43944 2015-03-10] (BoiseTest -> Microsoft Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [192880 2022-06-29] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [116960 2022-06-29] (ESET, spol. s r.o. -> ESET)
R1 edevmonm; C:\WINDOWS\System32\DRIVERS\edevmonm.sys [119008 2022-06-29] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15824 2021-03-10] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [234192 2022-06-29] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [52880 2022-06-29] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [79216 2022-06-29] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [119528 2022-06-29] (ESET, spol. s r.o. -> ESET)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-12-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [429288 2020-12-02] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [71912 2020-12-02] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-08-05 17:50 - 2022-08-05 17:52 - 000022807 _____ C:\Users\Jana a Ivo\Desktop\FRST.txt
2022-08-05 17:50 - 2022-08-05 17:51 - 000000000 ____D C:\FRST
2022-08-05 17:48 - 2022-08-05 17:48 - 002370048 _____ (Farbar) C:\Users\Jana a Ivo\Desktop\FRST64.exe
2022-08-04 20:17 - 2022-08-04 22:25 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2022-08-04 10:40 - 2022-08-04 10:40 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Roaming\Software602
2022-08-04 10:40 - 2021-09-23 12:18 - 000047896 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\602localmon.dll
2022-08-04 10:39 - 2022-08-04 10:39 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Roaming\602XML
2022-08-04 10:39 - 2022-08-04 10:39 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Roaming\602Installer
2022-08-02 09:36 - 2022-08-02 14:39 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-08-01 14:54 - 2022-08-01 14:54 - 000209905 _____ C:\Users\Jana a Ivo\Downloads\ankefort_2022-07_122134889-1.pdf
2022-08-01 09:56 - 2022-08-01 09:56 - 000209905 _____ C:\Users\Jana a Ivo\Downloads\ankefort_2022-07_122134889.pdf
2022-07-30 18:16 - 2022-07-30 18:16 - 000000134 _____ C:\Users\Jana a Ivo\Desktop\forum viry.url
2022-07-27 14:25 - 2022-07-27 14:25 - 000001963 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2022-07-13 20:59 - 2022-07-13 20:59 - 000470528 _____ (curl, hxxps://curl.se/) C:\WINDOWS\SysWOW64\curl.exe
2022-07-13 20:59 - 2022-07-13 20:59 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mode.com
2022-07-13 20:59 - 2022-07-13 20:59 - 000018944 _____ C:\WINDOWS\SysWOW64\WsdProviderUtil.dll
2022-07-13 20:59 - 2022-07-13 20:59 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tree.com
2022-07-13 20:59 - 2022-07-13 20:59 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chcp.com
2022-07-13 20:58 - 2022-07-13 20:58 - 000693248 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2022-07-13 20:58 - 2022-07-13 20:58 - 000530944 _____ (curl, hxxps://curl.se/) C:\WINDOWS\system32\curl.exe
2022-07-13 20:58 - 2022-07-13 20:58 - 000270848 _____ C:\WINDOWS\system32\EsclScan.dll
2022-07-13 20:58 - 2022-07-13 20:58 - 000152064 _____ C:\WINDOWS\system32\EsclProtocol.dll
2022-07-13 20:58 - 2022-07-13 20:58 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mode.com
2022-07-13 20:58 - 2022-07-13 20:58 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tree.com
2022-07-13 20:58 - 2022-07-13 20:58 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\chcp.com
2022-07-13 20:58 - 2022-07-13 20:58 - 000011811 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-07-13 20:57 - 2022-07-13 20:57 - 000061952 _____ C:\WINDOWS\system32\printticketvalidation.dll
2022-07-13 20:57 - 2022-07-13 20:57 - 000057344 _____ C:\WINDOWS\system32\APMonUI.dll
2022-07-13 20:56 - 2022-07-13 20:56 - 002260480 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-07-13 20:56 - 2022-07-13 20:56 - 000640512 _____ C:\WINDOWS\system32\SettingSyncDownloadHelper.dll
2022-07-13 20:56 - 2022-07-13 20:56 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-07-13 20:56 - 2022-07-13 20:56 - 000024576 _____ C:\WINDOWS\system32\WsdProviderUtil.dll
2022-07-13 20:03 - 2022-07-13 20:03 - 000000000 ___HD C:\$WinREAgent

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-08-05 17:48 - 2022-02-10 11:39 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-08-05 17:47 - 2021-06-17 09:42 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-08-05 17:47 - 2017-07-25 17:16 - 000000000 ____D C:\Users\Jana a Ivo\AppData\LocalLow\Mozilla
2022-08-05 17:45 - 2019-02-04 11:34 - 000000000 ____D C:\ProgramData\Mozilla
2022-08-05 17:45 - 2017-07-25 14:41 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Local\ClassicShell
2022-08-05 17:44 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-08-05 17:24 - 2020-06-12 16:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-08-05 14:53 - 2018-06-18 18:45 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Local\D3DSCache
2022-08-05 11:17 - 2017-08-31 17:45 - 000000000 ____D C:\ProgramData\NVIDIA
2022-08-05 08:31 - 2017-07-25 20:12 - 000000000 ____D C:\Users\Jana a Ivo\Documents\Vlastní šablony Office
2022-08-05 08:28 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-08-05 08:28 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-08-04 22:25 - 2017-07-25 17:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-08-04 15:52 - 2022-05-06 23:22 - 000440704 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-08-04 15:52 - 2020-06-12 17:03 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-08-04 15:52 - 2020-06-12 16:42 - 000008192 ___SH C:\DumpStack.log.tmp
2022-08-04 15:51 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-08-04 15:45 - 2017-07-30 19:33 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Local\CrashDumps
2022-08-04 07:37 - 2017-07-25 16:54 - 000000000 ____D C:\IDOS
2022-08-03 20:49 - 2018-07-23 14:34 - 000000000 ____D C:\stažené soubory
2022-08-03 20:39 - 2021-06-20 17:21 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Roaming\vlc
2022-08-03 16:30 - 2017-07-30 17:36 - 000000000 ____D C:\VYPAL
2022-08-02 14:35 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-08-02 09:37 - 2021-06-04 23:59 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-08-02 09:15 - 2017-11-23 17:14 - 000000000 ____D C:\Users\Jana a Ivo\AppData\Local\Packages
2022-08-01 17:15 - 2017-07-25 18:14 - 000000000 ____D C:\MP3
2022-08-01 16:50 - 2017-07-25 16:23 - 000000000 ____D C:\Users\Jana a Ivo\Documents\Ivo
2022-08-01 15:20 - 2018-02-20 18:31 - 000000000 ____D C:\Users\Jana a Ivo\Documents\recepty
2022-07-30 22:12 - 2017-08-28 11:10 - 000000000 ____D C:\Users\Jana a Ivo\AppData\LocalLow\Temp
2022-07-30 22:06 - 2020-06-12 17:03 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG
2022-07-30 22:01 - 2020-06-03 16:33 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-07-28 08:37 - 2021-12-13 16:35 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3178504301-1335594183-2692845351-1001
2022-07-28 08:37 - 2020-06-12 17:03 - 000003390 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3178504301-1335594183-2692845351-1001
2022-07-28 08:37 - 2020-06-12 16:15 - 000002441 _____ C:\Users\Jana a Ivo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-07-27 15:02 - 2017-07-25 17:53 - 000000000 ____D C:\Users\Jana a Ivo\Documents\hesla
2022-07-27 15:00 - 2017-08-16 17:44 - 000000000 ____D C:\Users\Jana a Ivo\Documents\Provozní řád
2022-07-27 14:43 - 2017-07-26 16:31 - 000000000 ____D C:\ZALOHY
2022-07-27 14:26 - 2017-07-25 20:39 - 000000000 ____D C:\ProgramData\Garmin
2022-07-27 14:26 - 2017-07-25 14:15 - 000000000 ____D C:\ProgramData\Package Cache
2022-07-27 14:25 - 2020-06-12 17:03 - 000003624 _____ C:\WINDOWS\system32\Tasks\GarminUpdaterTask
2022-07-27 14:25 - 2017-07-25 20:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2022-07-27 14:25 - 2017-07-25 20:39 - 000000000 ____D C:\Program Files (x86)\Garmin
2022-07-26 22:31 - 2017-07-25 17:54 - 000000000 ____D C:\FOTOGRAFIE
2022-07-25 15:50 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-07-21 09:11 - 2017-07-25 14:21 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-07-20 19:46 - 2020-06-12 17:03 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-07-20 19:46 - 2020-06-12 17:03 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-07-18 15:57 - 2017-11-22 21:08 - 000000000 ____D C:\Users\Jana a Ivo\Documents\nesouhlas se zvýšením nájemného
2022-07-18 09:34 - 2017-07-25 15:45 - 000000000 ____D C:\Program Files (x86)\Dialog MIS
2022-07-17 18:27 - 2019-06-12 10:29 - 000000000 ____D C:\ALFIS2G2019J
2022-07-16 20:22 - 2017-07-26 17:03 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-07-16 20:16 - 2017-07-26 17:03 - 146546848 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-07-14 08:19 - 2022-05-11 15:49 - 000713078 _____ C:\WINDOWS\system32\perfh005.dat
2022-07-14 08:19 - 2022-05-11 15:49 - 000143796 _____ C:\WINDOWS\system32\perfc005.dat
2022-07-14 08:19 - 2020-06-12 16:55 - 001683936 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-07-14 08:19 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2022-07-13 21:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-07-13 20:55 - 2020-06-12 16:47 - 003010560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-07-13 15:22 - 2020-06-12 17:03 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-07-13 15:21 - 2021-12-15 10:59 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2022-07-13 15:21 - 2021-12-15 10:59 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
2022-07-12 19:40 - 2022-03-21 20:07 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2022-07-12 19:40 - 2021-09-03 09:25 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2022-07-09 09:55 - 2017-08-16 17:44 - 000000000 ____D C:\Users\Jana a Ivo\Documents\CERTIFIKÁT
2022-07-07 15:24 - 2019-09-04 18:07 - 000000000 ____D C:\ProgramData\Zoner

==================== Files in the root of some directories ========

2018-03-22 16:23 - 2018-03-22 16:23 - 000000600 _____ () C:\Users\Jana a Ivo\AppData\Roaming\winscp.rnd

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================