Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-03-2020
Ran by Eva (administrator) on DESKTOP-47MPNF7 (LENOVO 80SM) (25-03-2020 19:49:03)
Running from C:\Users\Eva\Downloads
Loaded Profiles: Eva (Available Profiles: Eva)
Platform: Windows 10 Home Version 1809 17763.973 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe
(Conexant Systems, Inc.) [File not signed] C:\Program Files\CONEXANT\SAII\CxUtilSvc.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe
(Fortemedia Inc -> ) C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Malwarebytes Inc -> Malwarebytes) C:\Users\Eva\Desktop\adwcleaner_8.0.3.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Eva\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19081.28230.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20022.81.0_x64__8wekyb3d8bbwe\YourPhoneServer\YourPhoneServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe
(Microsoft) [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\USBAppControl.exe
(Microsoft) [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\AdminService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LenovoUtility] => "C:\Program Files\Lenovo\LenovoUtility\utility.exe"
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [602968 2015-12-07] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [849920 2017-03-07] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1831768 2016-08-29] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-25] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2019-12-25] () [File not signed]
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1139041B-F6F4-4219-A41A-6037733A9177} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {23822574-5917-40F1-9E1C-A03D1D9C5F65} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-03-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {28093651-BEA9-4BBC-956B-1706706CE719} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {305E98B6-2B34-4053-A96A-F1A1DACF0CF3} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\6d37756e-628b-46d5-a4ca-a40dd0aead8b => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.)
Task: {3B3A276A-A181-47B3-973B-815EF8C3F471} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\d2c4a410-ed1a-4a98-a2e8-aeb52133e7cd => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.)
Task: {52B85F3B-A6DB-4DF2-839C-C5AB6A7531BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-25] (Google LLC -> Google LLC)
Task: {5725A494-DE1A-4E88-A6A8-3917547A2950} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-3907094637-1769742579-2507837433-1001 => C:\Users\Eva\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [122344 2019-04-04] (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {6438794C-2EEF-44F5-9839-9B6E84ADC29D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6148504 2020-03-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {6A63C522-8E67-4E6D-A971-A2521BD49E5C} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\03be25a7-c7e1-494b-b368-8ef17561acde => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.)
Task: {6E5B3033-8A98-4E3B-8A14-65A20C57B47E} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => "%windir%\system32\WindowsPowerShell\v1.0\PowerShell.exe" "powershell -executionpolicy bypass -file %ProgramData%\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\data\Maintenance.ps1"
Task: {75FFC4CD-A751-48A1-9A9D-A8DBF9BAF6B3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24707448 2020-03-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {797F8A5D-3624-477E-91D8-8FDC56E1960F} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\Windows\system32\ImController.InfInstaller.exe [54424 2020-02-11] (Lenovo -> Lenovo Group Ltd.)
Task: {91812944-F03A-4313-9FA9-38A722985996} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {A2632D8C-883D-48E8-884E-2046762C73F5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-25] (Google LLC -> Google LLC)
Task: {A57AAE03-B657-4FB4-8A05-E94B61C4BF9F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6148504 2020-03-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {CDF01B57-0470-47A6-83C0-52254DE42751} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService
Task: {DA0B873B-A309-427F-9CF4-06CEA607D93D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E072E088-D5BA-422F-ADE3-0BDA58F8544D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24707448 2020-03-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {E2DC844C-FC5E-4B3F-AD4C-98BF8AE78054} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\3e36c7bd-b3b8-4fdc-8575-38e3da7c62c0 => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.)
Task: {E7DC05BA-2ED6-4699-ADC8-47FE4061BB21} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-03-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {F3B4DAD7-C08D-4AE4-A983-F9ABD5AEF85F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{c8e6eeab-2143-42f7-a2be-d7739bc8e95d}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Internet Explorer:
==================
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-12-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-14] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-12-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-12-21] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default [2020-03-25]
CHR HomePage: Default -> hxxp://
www.seznam.cz/
CHR Extension: (Prezentace) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-28]
CHR Extension: (Dokumenty) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-28]
CHR Extension: (Disk Google) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-28]
CHR Extension: (YouTube) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-28]
CHR Extension: (Tabulky) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-28]
CHR Extension: (Dokumenty Google offline) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-02]
CHR Extension: (Gmail) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-09]
CHR Extension: (Chrome Media Router) - C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-25]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [10628888 2020-03-24] (Microsoft Corporation -> Microsoft Corporation)
R2 CxUtilSvc; C:\Program Files\Conexant\SAII\CxUtilSvc.exe [132096 2016-05-12] (Conexant Systems, Inc.) [File not signed]
R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [194048 2017-03-07] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
R2 ImControllerService; C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.)
R2 SAService; C:\Windows\system32\SAsrv.exe [431960 2015-09-15] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [258648 2018-01-06] (Synaptics Incorporated -> Synaptics Incorporated)
R2 USBAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\USBAppControl.exe [12288 2019-08-09] (Microsoft) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WorkflowAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl.exe [20480 2019-08-09] (Microsoft) [File not signed]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S2 UIUService; %SystemRoot%\system32\UIUSrv.exe [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_851a79f66682d708\nvlddmkm.sys [14482360 2017-09-29] (NVIDIA Corporation -> NVIDIA Corporation)
R3 Qcamain10x64; C:\Windows\System32\drivers\Qcamain10x64.sys [2355544 2018-07-29] (Qualcomm Atheros -> Qualcomm Atheros, Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [605696 2018-09-15] (Microsoft Windows -> Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [427520 2016-11-16] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3150336 2017-01-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-03-25 17:58 - 2020-03-25 17:59 - 000000000 ____D C:\AdwCleaner
2020-03-25 17:55 - 2020-03-25 17:56 - 008199856 _____ (Malwarebytes) C:\Users\Eva\Desktop\adwcleaner_8.0.3.exe
2020-03-25 17:48 - 2020-03-25 17:48 - 000032621 _____ C:\Users\Eva\Desktop\FRST.txt
2020-03-25 17:48 - 2020-03-25 17:48 - 000025149 _____ C:\Users\Eva\Desktop\Addition.txt
2020-03-25 17:46 - 2020-03-25 17:48 - 000025146 _____ C:\Users\Eva\Downloads\Addition.txt
2020-03-25 17:43 - 2020-03-25 19:50 - 000020346 _____ C:\Users\Eva\Downloads\FRST.txt
2020-03-25 17:42 - 2020-03-25 19:49 - 000000000 ____D C:\FRST
2020-03-25 17:42 - 2020-03-25 17:42 - 002279936 _____ (Farbar) C:\Users\Eva\Downloads\FRST64.exe
2020-03-25 17:37 - 2020-03-25 17:43 - 000003474 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-25 17:37 - 2020-03-25 17:43 - 000003350 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-25 17:37 - 2020-03-25 17:37 - 000002377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-03-25 17:37 - 2020-03-25 17:37 - 000002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-03-25 15:27 - 2020-03-25 15:37 - 000000000 ____D C:\ProgramData\HitmanPro
2020-03-25 14:58 - 2020-03-25 14:58 - 000000000 ____D C:\Users\Eva\AppData\Local\cache
2020-03-25 14:57 - 2020-03-25 14:57 - 000000000 ____D C:\Users\Eva\AppData\Local\mbamtray
2020-03-25 14:57 - 2020-03-25 14:57 - 000000000 ____D C:\Users\Eva\AppData\Local\mbam
2020-03-25 14:56 - 2020-03-25 14:56 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-03-25 14:01 - 2020-03-25 14:01 - 000000000 ____D C:\Users\Eva\AppData\Roaming\WiperSoft
2020-03-25 14:00 - 2020-03-25 16:47 - 000000000 ____D C:\Program Files\WiperSoft
2020-03-25 13:19 - 2020-03-25 13:19 - 000000000 ____D C:\Users\Eva\AppData\Roaming\WinRAR
2020-03-25 12:07 - 2020-03-25 12:07 - 000000000 ____D C:\Users\Eva\AppData\Local\ESET
2020-03-25 12:07 - 2020-03-25 12:07 - 000000000 ____D C:\Users\Eva\AppData\Local\D3DSCache
2020-03-25 11:55 - 2020-03-25 11:55 - 000000000 ____D C:\Users\Eva\AppData\Local\CEF
2020-03-25 11:53 - 2020-03-25 16:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2020-03-25 11:31 - 2020-03-25 11:31 - 000000000 ____D C:\Program Files\AVAST Software
2020-03-25 11:30 - 2020-03-25 12:26 - 000000000 ____D C:\ProgramData\AVAST Software
2020-03-25 10:51 - 2020-03-25 10:56 - 080151770 _____ C:\Users\Eva\Downloads\Office 2013 aktivátor.rar
2020-03-25 10:50 - 2020-03-25 10:50 - 000000111 _____ C:\Users\Eva\Downloads\activation key Office 2013.txt
2020-03-25 10:49 - 2020-03-25 10:49 - 000085402 _____ C:\Users\Eva\Downloads\[SkT]KMSpico_9.0.5.20131111_Final_-_Microsoft_Office_-_Windows_Activator_(2010-2013).torrent
2020-03-25 10:46 - 2020-03-25 10:46 - 000000000 ____D C:\ProgramData\Microsoft Toolkit
2020-03-25 10:43 - 2020-03-25 10:46 - 056210075 _____ C:\Users\Eva\Downloads\Office 2013 Activator.zip
2020-03-25 10:37 - 2020-03-25 10:37 - 000000000 ____D C:\Users\Eva\AppData\Local\Microsoft Help
2020-03-25 10:23 - 2020-03-25 10:24 - 003080123 _____ C:\Users\Eva\Downloads\Office 2016 instalátor + aktivátor (1).rar
2020-03-25 10:19 - 2020-03-25 17:29 - 000000000 ____D C:\Program Files (x86)\WinRAR
2020-03-25 10:19 - 2020-03-25 10:19 - 000001966 _____ C:\Users\Public\Desktop\WinRAR.lnk
2020-03-25 10:14 - 2020-03-25 10:14 - 007838463 _____ (RARLAB) C:\Users\Eva\Downloads\WinRAR 32-64bit v5.71.exe
2020-03-25 10:13 - 2020-03-25 10:13 - 003080123 _____ C:\Users\Eva\Downloads\Office 2016 instalátor + aktivátor.rar
2020-03-24 17:32 - 2020-03-24 17:32 - 000002846 _____ C:\Users\Eva\Desktop\Výkaz o provedení práce z domova za měsíc březen 2020 - VZOR.docx.html
2020-03-24 17:32 - 2020-03-24 17:32 - 000000000 ____D C:\Users\Eva\Desktop\Výkaz o provedení práce z domova za měsíc březen 2020 - VZOR.docx_files
2020-03-24 17:26 - 2020-03-24 17:26 - 000113332 _____ C:\Users\Eva\Downloads\sb045-20-AK.pdf
2020-03-24 17:22 - 2020-03-24 17:22 - 000162598 _____ C:\Users\Eva\Desktop\Výkaz o provedení práce z domova za měsíc březen 2020 - VZOR.pdf
2020-03-24 08:43 - 2020-03-24 08:43 - 000196280 _____ C:\Users\Eva\Downloads\Elektronické podepisování LD a ZPK_v02.pdf
2020-03-24 08:43 - 2020-03-24 08:43 - 000196280 _____ C:\Users\Eva\Downloads\Elektronické podepisování LD a ZPK_v02 (1).pdf
2020-03-24 08:42 - 2020-03-24 08:42 - 000244275 _____ C:\Users\Eva\Downloads\010412 Eva Hrubonova zaznam.pdf
2020-03-22 18:24 - 2020-03-22 18:25 - 000196473 _____ C:\Users\Eva\Downloads\Mimořádné-opatření-doba-pro-seniory.pdf
2020-03-19 15:20 - 2020-03-19 15:20 - 000291630 _____ C:\Users\Eva\Downloads\BV 16.3.2020 (3).pdf
2020-03-19 15:20 - 2020-03-19 15:20 - 000226466 _____ C:\Users\Eva\Downloads\Dohoda_o_vykonu_statni_sluzby_z_jineho_mista_2020_03_14 (5).pdf
2020-03-19 15:20 - 2020-03-19 15:20 - 000226466 _____ C:\Users\Eva\Downloads\Dohoda_o_vykonu_statni_sluzby_z_jineho_mista_2020_03_14 (4).pdf
2020-03-19 15:20 - 2020-03-19 15:20 - 000226466 _____ C:\Users\Eva\Downloads\Dohoda_o_vykonu_statni_sluzby_z_jineho_mista_2020_03_14 (3).pdf
2020-03-19 15:17 - 2020-03-19 15:17 - 000068443 _____ C:\Users\Eva\Downloads\30007_2020_4 (3).pdf
2020-03-19 15:16 - 2020-03-19 15:16 - 000067130 _____ C:\Users\Eva\Downloads\K181_300070002629881_20200318 (2).pdf
2020-03-19 15:15 - 2020-03-19 15:15 - 000289290 _____ C:\Users\Eva\Downloads\13288_2020-03-19_10-09-23 (1).pdf
2020-03-19 15:12 - 2020-03-19 15:12 - 000067130 _____ C:\Users\Eva\Downloads\K181_300070002629881_20200318 (1).pdf
2020-03-19 15:07 - 2020-03-19 15:07 - 000044225 _____ C:\Users\Eva\Downloads\Vaculíková.pdf
2020-03-19 15:06 - 2020-03-19 15:06 - 000067130 _____ C:\Users\Eva\Downloads\K181_300070002629881_20200318.pdf
2020-03-19 15:05 - 2020-03-19 15:05 - 000289290 _____ C:\Users\Eva\Downloads\13288_2020-03-19_10-09-23.pdf
2020-03-19 09:33 - 2020-03-19 09:33 - 000302908 _____ C:\Users\Eva\Downloads\Interni sdeleni - omezeni cinnosti 30 (1).pdf
2020-03-19 09:32 - 2020-03-19 09:32 - 000302908 _____ C:\Users\Eva\Downloads\Interni sdeleni - omezeni cinnosti 30.pdf
2020-03-19 09:31 - 2020-03-19 09:31 - 000285763 _____ C:\Users\Eva\Downloads\Interni sdeleni.pdf
2020-03-18 09:49 - 2020-03-18 09:49 - 000291630 _____ C:\Users\Eva\Downloads\BV 16.3.2020 (2).pdf
2020-03-18 09:49 - 2020-03-18 09:49 - 000014157 _____ C:\Users\Eva\Downloads\Sešit1.xlsx
2020-03-18 09:49 - 2020-03-18 09:49 - 000014157 _____ C:\Users\Eva\Downloads\Sešit1 (1).xlsx
2020-03-18 09:48 - 2020-03-18 09:48 - 001924729 _____ C:\Users\Eva\Downloads\usnesení vlády ze dne 15.3.2020.pdf
2020-03-18 09:48 - 2020-03-18 09:48 - 001924729 _____ C:\Users\Eva\Downloads\usnesení vlády ze dne 15.3.2020 (1).pdf
2020-03-18 09:48 - 2020-03-18 09:48 - 000278020 _____ C:\Users\Eva\Downloads\usnesení vlády ze dne 13.3.2020.pdf
2020-03-18 09:48 - 2020-03-18 09:48 - 000278020 _____ C:\Users\Eva\Downloads\usnesení vlády ze dne 13.3.2020 (1).pdf
2020-03-18 09:46 - 2020-03-18 09:46 - 000272104 _____ C:\Users\Eva\Downloads\Interni sdeleni (1) (4).pdf
2020-03-18 09:46 - 2020-03-18 09:46 - 000272104 _____ C:\Users\Eva\Downloads\Interni sdeleni (1) (3).pdf
2020-03-18 09:46 - 2020-03-18 09:46 - 000068443 _____ C:\Users\Eva\Downloads\30007_2020_4.pdf
2020-03-18 09:46 - 2020-03-18 09:46 - 000068443 _____ C:\Users\Eva\Downloads\30007_2020_4 (2).pdf
2020-03-18 09:46 - 2020-03-18 09:46 - 000068443 _____ C:\Users\Eva\Downloads\30007_2020_4 (1).pdf
2020-03-18 09:45 - 2020-03-18 09:45 - 000272104 _____ C:\Users\Eva\Downloads\Interni sdeleni (1).pdf
2020-03-18 09:45 - 2020-03-18 09:45 - 000272104 _____ C:\Users\Eva\Downloads\Interni sdeleni (1) (2).pdf
2020-03-18 09:45 - 2020-03-18 09:45 - 000272104 _____ C:\Users\Eva\Downloads\Interni sdeleni (1) (1).pdf
2020-03-18 09:43 - 2020-03-18 09:43 - 000291630 _____ C:\Users\Eva\Downloads\BV 16.3.2020.pdf
2020-03-18 09:43 - 2020-03-18 09:43 - 000291630 _____ C:\Users\Eva\Downloads\BV 16.3.2020 (1).pdf
2020-03-17 16:45 - 2020-03-17 16:47 - 000000000 ____D C:\Users\Eva\AppData\Local\Brother
2020-03-17 16:44 - 2020-03-17 16:44 - 000000000 ____D C:\Users\Eva\AppData\Roaming\Brother
2020-03-17 16:44 - 2020-03-17 16:44 - 000000000 ____D C:\Users\Eva\AppData\Local\Nuance
2020-03-17 16:44 - 2020-03-17 16:44 - 000000000 ____D C:\ProgramData\Nuance
2020-03-17 16:43 - 2020-03-17 16:43 - 000000964 _____ C:\Users\Public\Desktop\Brother iPrint&Scan.lnk
2020-03-17 16:43 - 2020-03-17 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
2020-03-17 16:43 - 2020-03-17 16:43 - 000000000 ____D C:\Program Files (x86)\Brother
2020-03-17 16:40 - 2020-03-17 16:40 - 000000000 ____D C:\ProgramData\Brother
2020-03-16 16:11 - 2020-03-16 16:11 - 000277580 _____ C:\Users\Eva\Downloads\7298 2020 koronavir.pdf
2020-03-16 16:11 - 2020-03-16 16:11 - 000277580 _____ C:\Users\Eva\Downloads\7298 2020 koronavir (1).pdf
2020-03-15 16:16 - 2020-03-15 16:16 - 000226466 _____ C:\Users\Eva\Downloads\Dohoda_o_vykonu_statni_sluzby_z_jineho_mista_2020_03_14 (2).pdf
2020-03-15 16:16 - 2020-03-15 16:16 - 000226466 _____ C:\Users\Eva\Downloads\Dohoda_o_vykonu_statni_sluzby_z_jineho_mista_2020_03_14 (1).pdf
2020-03-15 12:06 - 2020-03-15 12:06 - 000226466 _____ C:\Users\Eva\Downloads\Dohoda_o_vykonu_statni_sluzby_z_jineho_mista_2020_03_14.pdf
2020-03-14 18:39 - 2020-02-01 07:36 - 000801080 _____ (Microsoft Corporation) C:\Windows\system32\sedplugins.dll
2020-03-14 09:21 - 2020-03-14 09:21 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2020-03-14 09:10 - 2020-03-14 09:10 - 000001908 _____ C:\Windows\diagwrn.xml
2020-03-14 09:10 - 2020-03-14 09:10 - 000001908 _____ C:\Windows\diagerr.xml
2020-03-14 08:10 - 2020-03-14 08:10 - 000000000 ____D C:\Windows\Lenovo
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-03-25 19:47 - 2018-12-28 11:00 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-03-25 19:47 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-03-25 17:48 - 2018-09-15 08:33 - 000000000 ___HD C:\Program Files\WindowsApps
2020-03-25 17:48 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\AppReadiness
2020-03-25 17:48 - 2018-09-15 08:31 - 000000000 ____D C:\Windows\INF
2020-03-25 17:45 - 2018-12-28 11:12 - 001693640 _____ C:\Windows\system32\PerfStringBackup.INI
2020-03-25 17:45 - 2018-09-15 18:32 - 000718198 _____ C:\Windows\system32\perfh005.dat
2020-03-25 17:45 - 2018-09-15 18:32 - 000145242 _____ C:\Windows\system32\perfc005.dat
2020-03-25 17:39 - 2018-12-28 12:09 - 000000000 __SHD C:\Users\Eva\IntelGraphicsProfiles
2020-03-25 17:39 - 2018-12-28 11:40 - 000000000 ____D C:\ProgramData\NVIDIA
2020-03-25 17:39 - 2018-12-28 11:00 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-03-25 17:38 - 2018-09-15 07:09 - 000524288 _____ C:\Windows\system32\config\BBI
2020-03-25 17:37 - 2018-12-28 11:34 - 000000000 ____D C:\Program Files (x86)\Google
2020-03-25 17:31 - 2018-12-28 11:13 - 000000000 ____D C:\Users\Eva
2020-03-25 17:29 - 2018-12-30 22:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2020-03-25 17:29 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\appcompat
2020-03-25 17:29 - 2018-09-15 07:09 - 000000000 ____D C:\Windows\system32\Sysprep
2020-03-25 17:15 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\registration
2020-03-25 17:13 - 2018-12-30 22:28 - 000000000 ____D C:\Program Files\Microsoft Office
2020-03-25 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-03-25 14:55 - 2018-12-28 11:14 - 000000000 ____D C:\Users\Eva\AppData\Local\Packages
2020-03-25 13:34 - 2018-12-28 10:59 - 000000000 ____D C:\Windows\Panther
2020-03-25 12:24 - 2018-12-28 11:34 - 000000000 ____D C:\Users\Eva\AppData\Local\PlaceholderTileLogoFolder
2020-03-25 09:29 - 2018-12-28 11:00 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-03-17 16:43 - 2018-12-28 12:12 - 000000000 ____D C:\ProgramData\Package Cache
2020-03-15 09:04 - 2019-12-02 16:58 - 000002359 _____ C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-15 09:04 - 2018-12-28 11:17 - 000003376 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3907094637-1769742579-2507837433-1001
2020-03-15 09:04 - 2018-12-28 11:17 - 000000000 ___RD C:\Users\Eva\OneDrive
2020-03-14 18:39 - 2018-12-30 22:37 - 000000000 ____D C:\Windows\system32\MRT
2020-03-14 18:37 - 2018-12-30 22:37 - 121542864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2020-03-14 09:20 - 2018-09-15 07:09 - 000032768 _____ C:\Windows\system32\config\ELAM
2020-03-14 09:11 - 2019-03-19 13:27 - 000000000 ___HD C:\$WINDOWS.~BT
2020-03-14 08:12 - 2018-12-28 11:50 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2020-03-14 06:40 - 2018-09-15 08:23 - 000000000 ____D C:\Windows\CbsTemp
2020-03-14 06:39 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================