Spomalene PC. Poprosim o kontrolu FRST.
Napsal: 26 led 2020 12:11
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-01-2020
Ran by brunkowski (administrator) on DESKTOP-3QKQD4S (Dell Inc. Inspiron 11 - 3147) (26-01-2020 11:43:20)
Running from C:\Users\brunkowski\Desktop
Loaded Profiles: brunkowski (Available Profiles: brunkowski)
Platform: Windows 10 Home Version 1903 18362.535 (X64) Language: Čeština (Česko)
Default browser: Opera
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(bookingDesktopApp.) [File not signed] C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\NisSrv.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Western Digital Techologies -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8510680 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1394392 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\...\Run: [WDDriveAgent] => C:\Program Files (x86)\Western Digital\WD Drive Agent\WDDriveAgent.exe [2379096 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
HKU\S-1-5-21-2809947898-3707831389-441220471-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2809947898-3707831389-441220471-1001\...\Run: [MiPhoneManager] => C:\Users\brunkowski\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-03-11] (Xiaomi Technology Inc -> )
HKU\S-1-5-18\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-19] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {14936660-F235-4FAC-9A96-E1AFFFE50E73} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {18F80753-0B3E-4AD9-A8CF-923175F1BC81} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software)
Task: {3CC76DE9-7299-4E32-BCAA-963574B67974} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
Task: {3F2D9D8C-1A16-4365-9EDB-726C37778464} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4396AA49-E615-43D8-9749-E1AF4047F4B3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4D2FD196-1324-485E-9C56-FC90353EA92B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {55193ED3-5782-4EEF-8359-0ADF94F3234F} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1394392 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {563F875D-FFC3-4E70-8951-0733DAAE3DD4} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_154_pepper.exe [1449472 2018-08-30] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {57690D8C-8AB0-41A9-BFAB-2C0E7BD89E4B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-20] (Google Inc -> Google Inc.)
Task: {6589400F-ED3D-48CF-8B0D-37C7A75CCC62} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {810951DA-A642-4823-8C8D-4BBCA67817B4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {88D41F58-B93D-41B5-9B71-6CADBB06388E} - System32\Tasks\WD Discovery Service Task brunkowski => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [67048 2019-02-05] (Western Digital Technologies, Inc. -> )
Task: {96E872FC-25B4-4197-B82E-ACF7DECCFBC5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
Task: {C0B7C729-BD71-4952-B57E-4154AB84976D} - System32\Tasks\Opera scheduled Autoupdate 1493409860 => C:\Program Files\Opera\launcher.exe [1528344 2019-12-19] (Opera Software AS -> Opera Software)
Task: {D541E0DE-9184-47F2-9B7D-2D16D3574D9D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-20] (Google Inc -> Google Inc.)
Task: {E41E5E2C-4AB2-4E30-88C8-C9B6263B809B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3403ee2b-6b47-498a-a1e8-d3360adae0f1}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{449df088-69d8-49f3-8e59-908d3a5ce723}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6c5b98a1-d3be-434f-b562-2ce1e91028ea}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{7e2fd5c4-cb13-4c6e-875b-e2f0223549b8}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{c5f83ec7-8a49-468f-899f-532285a8a24d}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKU\S-1-5-21-2809947898-3707831389-441220471-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2809947898-3707831389-441220471-1001 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
BHO: No Name -> {4F76702D-3AAF-4BDD-B096-926E9434CBAE}' -> No File
FireFox:
========
FF DefaultProfile: 63q2hn96.default
FF ProfilePath: C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default [2020-01-26]
FF Extension: (Ant Video downloader) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\anttoolbar@ant.com.xpi [2017-12-03]
FF Extension: (uBlock Origin) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\uBlock0@raymondhill.net.xpi [2017-12-03]
FF Extension: (Avast Online Security) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\wrc@avast.com.xpi [2018-08-29]
FF Extension: (DownThemAll!) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2017-02-04] [Legacy]
FF HKLM-x32\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files (x86)\RelevantKnowledge\firefox => not found
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=3 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2019-12-31] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=9 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2019-12-31] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-14] (Google LLC -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-14] (Google LLC -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-16] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default [2019-11-29]
CHR Notifications: Default -> hxxps://fastshare.cz; hxxps://www.facebook.com
CHR HomePage: Default -> hxxp://www.google.sk/
CHR StartupUrls: Default -> "hxxp://google.sk/"
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Extension: (Prezentácie) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-25]
CHR Extension: (Dokumenty) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-25]
CHR Extension: (Disk Google) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-20]
CHR Extension: (YouTube) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-20]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-09-27]
CHR Extension: (ABA English - Online English Course) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpnkfkmdhgomemhogjdianppfjkaddcc [2017-01-20]
CHR Extension: (Adobe Acrobat) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-08-24]
CHR Extension: (Video Downloader professional) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2019-09-27]
CHR Extension: (Tabuľky) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-25]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-09-27]
CHR Extension: (Avast Online Security) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-09-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Adblock Pro) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2017-01-20]
CHR Extension: (Gmail) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-09-27]
CHR Extension: (Chrome Media Router) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-27]
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
CHR HKU\S-1-5-21-2809947898-3707831389-441220471-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
Opera:
=======
OPR Extension: (SaveFrom.net helper) - C:\Users\brunkowski\AppData\Roaming\Opera Software\Opera Stable\Extensions\npdpplbicnmpoigidfdjadamgfkilaak [2020-01-26]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6259592 2019-12-20] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [417536 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
S2 bookingdesktopapp; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2019-12-31] (bookingDesktopApp.) [File not signed]
S3 bookingdesktopappm; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2019-12-31] (bookingDesktopApp.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel(R) pGFX -> Intel Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [298200 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [524632 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-04] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [161544 2019-11-02] (AVAST Software s.r.o. -> AVAST Software)
R1 aswNetSec; C:\WINDOWS\System32\drivers\aswNetSec.sys [552848 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
S2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R3 athr; C:\WINDOWS\System32\drivers\athw8x.sys [4233728 2019-03-19] (Microsoft Windows -> Qualcomm Atheros Communications, Inc.)
R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [601616 2016-05-19] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> OSR Open Systems Resources, Inc.)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc. -> CACE Technologies, Inc.)
R0 stdcfltn; C:\WINDOWS\System32\DRIVERS\stdcfltn.sys [22168 2012-07-13] (STMicroelectronics -> ST Microelectronics)
R3 ST_Accel; C:\WINDOWS\system32\DRIVERS\ST_Accel.sys [83968 2013-11-21] (Microsoft Windows Hardware Compatibility Publisher -> STMicroelectronics)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation - Client Components Group -> Intel Corporation)
R3 VirtualButtons; C:\WINDOWS\System32\drivers\VirtualButtons.sys [41992 2017-03-31] (Intel(R) Software -> Intel Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45664 2019-12-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [355760 2019-12-14] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-14] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-01-26 11:43 - 2020-01-26 11:47 - 000025597 _____ C:\Users\brunkowski\Desktop\FRST.txt
2020-01-26 11:41 - 2020-01-26 11:41 - 002581504 _____ (Farbar) C:\Users\brunkowski\Desktop\FRST64.exe
2020-01-26 01:23 - 2019-10-04 18:49 - 000355720 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2020-01-25 21:16 - 2020-01-26 11:46 - 000000000 ____D C:\FRST
2020-01-24 21:47 - 2020-01-24 22:05 - 1973158406 _____ C:\Users\brunkowski\Downloads\MissaX - Elena Koshka 1080p.mp4
2020-01-24 21:44 - 2020-01-24 21:55 - 518665840 _____ C:\Users\brunkowski\Downloads\MissaX.17.06.23.Natalia.Starr.Solicitation.XXX.SD.MP4-KLEENEX.mp4
2020-01-24 21:38 - 2020-01-24 21:45 - 1295473211 _____ C:\Users\brunkowski\Downloads\FuckStudies - Olivia Westsun 720p.mp4
2020-01-24 21:36 - 2020-01-24 21:53 - 731238022 _____ C:\Users\brunkowski\Downloads\Ava Haze.mp4
2020-01-24 19:06 - 2020-01-24 19:17 - 1353570568 _____ C:\Users\brunkowski\Downloads\Quien a hierro mata (2019) CZ titulky NOVINKA.avi
2020-01-24 18:58 - 2020-01-24 19:15 - 1830924536 _____ C:\Users\brunkowski\Downloads\Přes prsty (2019).avi
2020-01-19 20:42 - 2020-01-19 20:52 - 1426919267 _____ C:\Users\brunkowski\Downloads\Dronningen (2019) 1080p SK.TITULKY.mkv
2020-01-19 20:37 - 2020-01-19 20:58 - 2074554307 _____ C:\Users\brunkowski\Downloads\Anna (2019) CZdabing + forced ,BluRay,1080p,.mkv
2020-01-12 22:34 - 2020-01-12 22:39 - 658003062 _____ C:\Users\brunkowski\Downloads\bu_elena_koshka_cl112917_720p_2600_Self-Love.mp4
2020-01-12 22:33 - 2020-01-12 22:51 - 1157591663 _____ C:\Users\brunkowski\Downloads\MofosBSides - Elena Koshka 1080p.mp4
2020-01-12 22:33 - 2020-01-12 22:43 - 874688134 _____ C:\Users\brunkowski\Downloads\Elena Koshka, Paige Owens, Lily LaBeau, Khloe Kapri.mp4
2020-01-12 22:19 - 2020-01-12 22:26 - 333268248 _____ C:\Users\brunkowski\Downloads\BlackedRaw - Elena Koshka - Last Night In LA.mp4
2020-01-12 22:19 - 2020-01-12 22:24 - 733731313 _____ C:\Users\brunkowski\Downloads\Vixen - Elena Koshka 480p.mp4
2020-01-12 21:57 - 2020-01-12 22:17 - 1474373315 _____ C:\Users\brunkowski\Downloads\40 432__XXX__[NaughtyAmerica] Elena Koshka - Diary of a Nanny (14.04.2018)_Part__03.mp4
2020-01-12 21:56 - 2020-01-12 22:11 - 604576219 _____ C:\Users\brunkowski\Downloads\Elena Koshka (Tonight's Girlfriend).mp4
2020-01-12 21:39 - 2020-01-12 21:55 - 1996163379 _____ C:\Users\brunkowski\Downloads\PureTaboo - Sarah Vandella & Elena Koshka 1080vp
2020-01-12 11:15 - 2020-01-19 23:06 - 000000000 ____D C:\Users\brunkowski\Downloads\Ulozto
2020-01-05 21:55 - 2020-01-05 22:13 - 1763431180 _____ C:\Users\brunkowski\Downloads\ODVÁŽNÁ VAIANA Legenga o konci sv_ta 2016 480p BDRip DD5.1 SK dabing.avi
2020-01-05 19:14 - 2020-01-05 19:25 - 1453412884 _____ C:\Users\brunkowski\Downloads\Ten, kdo tě miloval (2018) cz.film.avi
2020-01-04 20:59 - 2020-01-04 21:05 - 648382116 _____ C:\Users\brunkowski\Downloads\Sorjonen S01E03 CZtit V OBRAZE.avi
2020-01-04 20:19 - 2020-01-26 11:31 - 000000000 ____D C:\Users\brunkowski\AppData\Local\Spotify
2020-01-04 20:19 - 2020-01-04 20:19 - 000001877 _____ C:\Users\brunkowski\Desktop\Spotify.lnk
2020-01-04 20:19 - 2020-01-04 20:19 - 000001863 _____ C:\Users\brunkowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2020-01-04 20:18 - 2020-01-26 11:30 - 000000000 ____D C:\Users\brunkowski\AppData\Roaming\Spotify
2019-12-31 21:54 - 2019-12-31 21:54 - 000003200 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Booking.lnk
2019-12-31 21:52 - 2019-12-31 21:54 - 000000000 ____D C:\Program Files (x86)\Booking
2019-12-31 21:50 - 2019-12-31 21:50 - 000000000 ____D C:\WINDOWS\SysWOW64\nllc
2019-12-27 08:24 - 2019-12-27 08:24 - 000139412 _____ C:\Users\brunkowski\Downloads\spusu_kuendigungsschreiben.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-01-26 11:43 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-01-26 11:37 - 2017-04-28 21:02 - 000000000 ____D C:\Program Files\Opera
2020-01-26 11:34 - 2019-11-09 12:21 - 000001152 _____ C:\Users\brunkowski\Desktop\Prohlížeč Opera.lnk
2020-01-26 11:34 - 2019-09-28 22:08 - 001606106 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-01-26 11:34 - 2019-03-19 12:55 - 000673444 _____ C:\WINDOWS\system32\perfh005.dat
2020-01-26 11:34 - 2019-03-19 12:55 - 000137332 _____ C:\WINDOWS\system32\perfc005.dat
2020-01-26 11:34 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-01-26 11:31 - 2018-08-29 18:29 - 000000000 ____D C:\Users\brunkowski\AppData\Local\AVAST Software
2020-01-26 11:30 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-01-26 11:29 - 2017-01-20 14:37 - 000000000 __SHD C:\Users\brunkowski\IntelGraphicsProfiles
2020-01-26 11:15 - 2019-09-28 22:33 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-01-26 11:15 - 2019-09-28 22:33 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-01-26 11:10 - 2019-09-28 22:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-01-26 11:09 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-01-26 11:07 - 2019-09-28 21:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-01-26 06:56 - 2019-09-28 21:55 - 000000000 ____D C:\Users\brunkowski
2020-01-26 01:24 - 2019-09-18 19:12 - 000002090 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premium Security.lnk
2020-01-26 01:24 - 2019-09-18 19:12 - 000002078 _____ C:\Users\Public\Desktop\Avast Premium Security.lnk
2020-01-26 01:23 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-01-26 01:08 - 2019-09-28 22:00 - 000000000 ____D C:\WINDOWS\system32\sk
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files\Windows Portable Devices
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2020-01-26 01:08 - 2019-03-19 12:56 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2020-01-26 01:08 - 2019-03-19 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\cs
2020-01-26 01:08 - 2019-03-19 12:55 - 000000000 ____D C:\WINDOWS\system32\cs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\UNP
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\F12
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\dsc
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\TextInput
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\downlevel
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\DDFs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Com
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\Provisioning
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\IME
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\System
2020-01-26 01:08 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\servicing
2020-01-26 01:03 - 2019-10-06 20:28 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-01-26 01:03 - 2019-09-16 19:59 - 000000000 ____D C:\Users\brunkowski\AppData\Roaming\doublecmd
2020-01-26 01:03 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\Containers
2020-01-26 00:22 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-01-26 00:07 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\registration
2020-01-24 20:34 - 2017-01-20 20:02 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-01-24 20:26 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-01-24 19:17 - 2017-04-30 08:01 - 000000000 ____D C:\Program Files (x86)\FastShare
2020-01-24 19:03 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-01-19 19:03 - 2017-01-20 18:51 - 000002315 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-19 19:03 - 2017-01-20 18:51 - 000002274 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-01-12 22:01 - 2019-09-28 22:34 - 000003306 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1493409860
2020-01-12 22:01 - 2019-09-28 22:33 - 000003386 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-01-12 22:01 - 2019-09-28 22:33 - 000003162 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-01-12 22:01 - 2019-09-28 22:33 - 000002218 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-01-12 22:01 - 2019-09-28 22:33 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2019-12-31 21:54 - 2019-11-23 19:31 - 000000000 ____D C:\Program Files (x86)\bookingDesktopApp
2019-12-31 21:51 - 2018-10-20 12:29 - 000001020 _____ C:\Users\Public\Desktop\PotPlayer 64 bit.lnk
2019-12-27 12:02 - 2019-12-23 20:21 - 000000000 ____D C:\Users\brunkowski\Downloads\xXiaomi
==================== Files in the root of some directories ========
2017-01-27 14:07 - 2017-06-02 17:25 - 000000201 _____ () C:\Users\brunkowski\AppData\Roaming\WB.CFG
2018-09-05 19:55 - 2018-09-05 19:55 - 000000017 _____ () C:\Users\brunkowski\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by brunkowski (administrator) on DESKTOP-3QKQD4S (Dell Inc. Inspiron 11 - 3147) (26-01-2020 11:43:20)
Running from C:\Users\brunkowski\Desktop
Loaded Profiles: brunkowski (Available Profiles: brunkowski)
Platform: Windows 10 Home Version 1903 18362.535 (X64) Language: Čeština (Česko)
Default browser: Opera
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(bookingDesktopApp.) [File not signed] C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\NisSrv.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Western Digital Techologies -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8510680 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1394392 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\...\Run: [WDDriveAgent] => C:\Program Files (x86)\Western Digital\WD Drive Agent\WDDriveAgent.exe [2379096 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
HKU\S-1-5-21-2809947898-3707831389-441220471-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2809947898-3707831389-441220471-1001\...\Run: [MiPhoneManager] => C:\Users\brunkowski\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-03-11] (Xiaomi Technology Inc -> )
HKU\S-1-5-18\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-19] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {14936660-F235-4FAC-9A96-E1AFFFE50E73} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {18F80753-0B3E-4AD9-A8CF-923175F1BC81} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software)
Task: {3CC76DE9-7299-4E32-BCAA-963574B67974} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
Task: {3F2D9D8C-1A16-4365-9EDB-726C37778464} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4396AA49-E615-43D8-9749-E1AF4047F4B3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4D2FD196-1324-485E-9C56-FC90353EA92B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {55193ED3-5782-4EEF-8359-0ADF94F3234F} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1394392 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {563F875D-FFC3-4E70-8951-0733DAAE3DD4} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_154_pepper.exe [1449472 2018-08-30] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {57690D8C-8AB0-41A9-BFAB-2C0E7BD89E4B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-20] (Google Inc -> Google Inc.)
Task: {6589400F-ED3D-48CF-8B0D-37C7A75CCC62} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {810951DA-A642-4823-8C8D-4BBCA67817B4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {88D41F58-B93D-41B5-9B71-6CADBB06388E} - System32\Tasks\WD Discovery Service Task brunkowski => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [67048 2019-02-05] (Western Digital Technologies, Inc. -> )
Task: {96E872FC-25B4-4197-B82E-ACF7DECCFBC5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
Task: {C0B7C729-BD71-4952-B57E-4154AB84976D} - System32\Tasks\Opera scheduled Autoupdate 1493409860 => C:\Program Files\Opera\launcher.exe [1528344 2019-12-19] (Opera Software AS -> Opera Software)
Task: {D541E0DE-9184-47F2-9B7D-2D16D3574D9D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-20] (Google Inc -> Google Inc.)
Task: {E41E5E2C-4AB2-4E30-88C8-C9B6263B809B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3403ee2b-6b47-498a-a1e8-d3360adae0f1}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{449df088-69d8-49f3-8e59-908d3a5ce723}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6c5b98a1-d3be-434f-b562-2ce1e91028ea}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{7e2fd5c4-cb13-4c6e-875b-e2f0223549b8}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{c5f83ec7-8a49-468f-899f-532285a8a24d}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKU\S-1-5-21-2809947898-3707831389-441220471-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2809947898-3707831389-441220471-1001 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxps://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wcg_fremkfs_17_04¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dat%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0AyE0FtAtBzy0FtA0D0AyD0FzytC0CtN0D0Tzu0StCzzyDtBtN1L2XzutAtFtByCtFtBtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StAzztCtC0B0E0C0BtGtAyEzytBtG0BzztAyDtGyC0C0AyDtG0FzzyCzyyEyC0AyEzztBtCtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0ByCzzyC0AtBtGtD0Azz0BtGyEyC0CtDtGzytDtBtAtG0E0CyEzyyD0D0E0A0DyE0AtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCyBzzyB%26cr%3D10677582%26a%3Dwcg_fremkfs_17_04%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
BHO: No Name -> {4F76702D-3AAF-4BDD-B096-926E9434CBAE}' -> No File
FireFox:
========
FF DefaultProfile: 63q2hn96.default
FF ProfilePath: C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default [2020-01-26]
FF Extension: (Ant Video downloader) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\anttoolbar@ant.com.xpi [2017-12-03]
FF Extension: (uBlock Origin) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\uBlock0@raymondhill.net.xpi [2017-12-03]
FF Extension: (Avast Online Security) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\wrc@avast.com.xpi [2018-08-29]
FF Extension: (DownThemAll!) - C:\Users\brunkowski\AppData\Roaming\Mozilla\Firefox\Profiles\63q2hn96.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2017-02-04] [Legacy]
FF HKLM-x32\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files (x86)\RelevantKnowledge\firefox => not found
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=3 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2019-12-31] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=9 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2019-12-31] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-14] (Google LLC -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-14] (Google LLC -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-16] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default [2019-11-29]
CHR Notifications: Default -> hxxps://fastshare.cz; hxxps://www.facebook.com
CHR HomePage: Default -> hxxp://www.google.sk/
CHR StartupUrls: Default -> "hxxp://google.sk/"
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Extension: (Prezentácie) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-25]
CHR Extension: (Dokumenty) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-25]
CHR Extension: (Disk Google) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-20]
CHR Extension: (YouTube) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-20]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-09-27]
CHR Extension: (ABA English - Online English Course) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpnkfkmdhgomemhogjdianppfjkaddcc [2017-01-20]
CHR Extension: (Adobe Acrobat) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-08-24]
CHR Extension: (Video Downloader professional) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2019-09-27]
CHR Extension: (Tabuľky) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-25]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-09-27]
CHR Extension: (Avast Online Security) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-09-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Adblock Pro) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2017-01-20]
CHR Extension: (Gmail) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-09-27]
CHR Extension: (Chrome Media Router) - C:\Users\brunkowski\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-27]
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
CHR HKU\S-1-5-21-2809947898-3707831389-441220471-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
Opera:
=======
OPR Extension: (SaveFrom.net helper) - C:\Users\brunkowski\AppData\Roaming\Opera Software\Opera Stable\Extensions\npdpplbicnmpoigidfdjadamgfkilaak [2020-01-26]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6259592 2019-12-20] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [417536 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
S2 bookingdesktopapp; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2019-12-31] (bookingDesktopApp.) [File not signed]
S3 bookingdesktopappm; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2019-12-31] (bookingDesktopApp.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel(R) pGFX -> Intel Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [298200 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [524632 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-14] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-04] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [161544 2019-11-02] (AVAST Software s.r.o. -> AVAST Software)
R1 aswNetSec; C:\WINDOWS\System32\drivers\aswNetSec.sys [552848 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
S2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-04] (AVAST Software s.r.o. -> AVAST Software)
R3 athr; C:\WINDOWS\System32\drivers\athw8x.sys [4233728 2019-03-19] (Microsoft Windows -> Qualcomm Atheros Communications, Inc.)
R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [601616 2016-05-19] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> OSR Open Systems Resources, Inc.)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc. -> CACE Technologies, Inc.)
R0 stdcfltn; C:\WINDOWS\System32\DRIVERS\stdcfltn.sys [22168 2012-07-13] (STMicroelectronics -> ST Microelectronics)
R3 ST_Accel; C:\WINDOWS\system32\DRIVERS\ST_Accel.sys [83968 2013-11-21] (Microsoft Windows Hardware Compatibility Publisher -> STMicroelectronics)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation - Client Components Group -> Intel Corporation)
R3 VirtualButtons; C:\WINDOWS\System32\drivers\VirtualButtons.sys [41992 2017-03-31] (Intel(R) Software -> Intel Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45664 2019-12-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [355760 2019-12-14] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-14] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-01-26 11:43 - 2020-01-26 11:47 - 000025597 _____ C:\Users\brunkowski\Desktop\FRST.txt
2020-01-26 11:41 - 2020-01-26 11:41 - 002581504 _____ (Farbar) C:\Users\brunkowski\Desktop\FRST64.exe
2020-01-26 01:23 - 2019-10-04 18:49 - 000355720 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2020-01-25 21:16 - 2020-01-26 11:46 - 000000000 ____D C:\FRST
2020-01-24 21:47 - 2020-01-24 22:05 - 1973158406 _____ C:\Users\brunkowski\Downloads\MissaX - Elena Koshka 1080p.mp4
2020-01-24 21:44 - 2020-01-24 21:55 - 518665840 _____ C:\Users\brunkowski\Downloads\MissaX.17.06.23.Natalia.Starr.Solicitation.XXX.SD.MP4-KLEENEX.mp4
2020-01-24 21:38 - 2020-01-24 21:45 - 1295473211 _____ C:\Users\brunkowski\Downloads\FuckStudies - Olivia Westsun 720p.mp4
2020-01-24 21:36 - 2020-01-24 21:53 - 731238022 _____ C:\Users\brunkowski\Downloads\Ava Haze.mp4
2020-01-24 19:06 - 2020-01-24 19:17 - 1353570568 _____ C:\Users\brunkowski\Downloads\Quien a hierro mata (2019) CZ titulky NOVINKA.avi
2020-01-24 18:58 - 2020-01-24 19:15 - 1830924536 _____ C:\Users\brunkowski\Downloads\Přes prsty (2019).avi
2020-01-19 20:42 - 2020-01-19 20:52 - 1426919267 _____ C:\Users\brunkowski\Downloads\Dronningen (2019) 1080p SK.TITULKY.mkv
2020-01-19 20:37 - 2020-01-19 20:58 - 2074554307 _____ C:\Users\brunkowski\Downloads\Anna (2019) CZdabing + forced ,BluRay,1080p,.mkv
2020-01-12 22:34 - 2020-01-12 22:39 - 658003062 _____ C:\Users\brunkowski\Downloads\bu_elena_koshka_cl112917_720p_2600_Self-Love.mp4
2020-01-12 22:33 - 2020-01-12 22:51 - 1157591663 _____ C:\Users\brunkowski\Downloads\MofosBSides - Elena Koshka 1080p.mp4
2020-01-12 22:33 - 2020-01-12 22:43 - 874688134 _____ C:\Users\brunkowski\Downloads\Elena Koshka, Paige Owens, Lily LaBeau, Khloe Kapri.mp4
2020-01-12 22:19 - 2020-01-12 22:26 - 333268248 _____ C:\Users\brunkowski\Downloads\BlackedRaw - Elena Koshka - Last Night In LA.mp4
2020-01-12 22:19 - 2020-01-12 22:24 - 733731313 _____ C:\Users\brunkowski\Downloads\Vixen - Elena Koshka 480p.mp4
2020-01-12 21:57 - 2020-01-12 22:17 - 1474373315 _____ C:\Users\brunkowski\Downloads\40 432__XXX__[NaughtyAmerica] Elena Koshka - Diary of a Nanny (14.04.2018)_Part__03.mp4
2020-01-12 21:56 - 2020-01-12 22:11 - 604576219 _____ C:\Users\brunkowski\Downloads\Elena Koshka (Tonight's Girlfriend).mp4
2020-01-12 21:39 - 2020-01-12 21:55 - 1996163379 _____ C:\Users\brunkowski\Downloads\PureTaboo - Sarah Vandella & Elena Koshka 1080vp
2020-01-12 11:15 - 2020-01-19 23:06 - 000000000 ____D C:\Users\brunkowski\Downloads\Ulozto
2020-01-05 21:55 - 2020-01-05 22:13 - 1763431180 _____ C:\Users\brunkowski\Downloads\ODVÁŽNÁ VAIANA Legenga o konci sv_ta 2016 480p BDRip DD5.1 SK dabing.avi
2020-01-05 19:14 - 2020-01-05 19:25 - 1453412884 _____ C:\Users\brunkowski\Downloads\Ten, kdo tě miloval (2018) cz.film.avi
2020-01-04 20:59 - 2020-01-04 21:05 - 648382116 _____ C:\Users\brunkowski\Downloads\Sorjonen S01E03 CZtit V OBRAZE.avi
2020-01-04 20:19 - 2020-01-26 11:31 - 000000000 ____D C:\Users\brunkowski\AppData\Local\Spotify
2020-01-04 20:19 - 2020-01-04 20:19 - 000001877 _____ C:\Users\brunkowski\Desktop\Spotify.lnk
2020-01-04 20:19 - 2020-01-04 20:19 - 000001863 _____ C:\Users\brunkowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2020-01-04 20:18 - 2020-01-26 11:30 - 000000000 ____D C:\Users\brunkowski\AppData\Roaming\Spotify
2019-12-31 21:54 - 2019-12-31 21:54 - 000003200 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Booking.lnk
2019-12-31 21:52 - 2019-12-31 21:54 - 000000000 ____D C:\Program Files (x86)\Booking
2019-12-31 21:50 - 2019-12-31 21:50 - 000000000 ____D C:\WINDOWS\SysWOW64\nllc
2019-12-27 08:24 - 2019-12-27 08:24 - 000139412 _____ C:\Users\brunkowski\Downloads\spusu_kuendigungsschreiben.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-01-26 11:43 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-01-26 11:37 - 2017-04-28 21:02 - 000000000 ____D C:\Program Files\Opera
2020-01-26 11:34 - 2019-11-09 12:21 - 000001152 _____ C:\Users\brunkowski\Desktop\Prohlížeč Opera.lnk
2020-01-26 11:34 - 2019-09-28 22:08 - 001606106 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-01-26 11:34 - 2019-03-19 12:55 - 000673444 _____ C:\WINDOWS\system32\perfh005.dat
2020-01-26 11:34 - 2019-03-19 12:55 - 000137332 _____ C:\WINDOWS\system32\perfc005.dat
2020-01-26 11:34 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-01-26 11:31 - 2018-08-29 18:29 - 000000000 ____D C:\Users\brunkowski\AppData\Local\AVAST Software
2020-01-26 11:30 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-01-26 11:29 - 2017-01-20 14:37 - 000000000 __SHD C:\Users\brunkowski\IntelGraphicsProfiles
2020-01-26 11:15 - 2019-09-28 22:33 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-01-26 11:15 - 2019-09-28 22:33 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-01-26 11:10 - 2019-09-28 22:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-01-26 11:09 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-01-26 11:07 - 2019-09-28 21:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-01-26 06:56 - 2019-09-28 21:55 - 000000000 ____D C:\Users\brunkowski
2020-01-26 01:24 - 2019-09-18 19:12 - 000002090 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premium Security.lnk
2020-01-26 01:24 - 2019-09-18 19:12 - 000002078 _____ C:\Users\Public\Desktop\Avast Premium Security.lnk
2020-01-26 01:23 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-01-26 01:08 - 2019-09-28 22:00 - 000000000 ____D C:\WINDOWS\system32\sk
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files\Windows Portable Devices
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-01-26 01:08 - 2019-03-19 12:58 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2020-01-26 01:08 - 2019-03-19 12:56 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2020-01-26 01:08 - 2019-03-19 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\cs
2020-01-26 01:08 - 2019-03-19 12:55 - 000000000 ____D C:\WINDOWS\system32\cs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\UNP
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\F12
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\dsc
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\TextInput
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\downlevel
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\DDFs
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Com
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\Provisioning
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\IME
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-01-26 01:08 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\System
2020-01-26 01:08 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\servicing
2020-01-26 01:03 - 2019-10-06 20:28 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-01-26 01:03 - 2019-09-16 19:59 - 000000000 ____D C:\Users\brunkowski\AppData\Roaming\doublecmd
2020-01-26 01:03 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\Containers
2020-01-26 00:22 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-01-26 00:07 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\registration
2020-01-24 20:34 - 2017-01-20 20:02 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-01-24 20:26 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-01-24 19:17 - 2017-04-30 08:01 - 000000000 ____D C:\Program Files (x86)\FastShare
2020-01-24 19:03 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-01-19 19:03 - 2017-01-20 18:51 - 000002315 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-19 19:03 - 2017-01-20 18:51 - 000002274 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-01-12 22:01 - 2019-09-28 22:34 - 000003306 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1493409860
2020-01-12 22:01 - 2019-09-28 22:33 - 000003386 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-01-12 22:01 - 2019-09-28 22:33 - 000003162 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-01-12 22:01 - 2019-09-28 22:33 - 000002218 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-01-12 22:01 - 2019-09-28 22:33 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2019-12-31 21:54 - 2019-11-23 19:31 - 000000000 ____D C:\Program Files (x86)\bookingDesktopApp
2019-12-31 21:51 - 2018-10-20 12:29 - 000001020 _____ C:\Users\Public\Desktop\PotPlayer 64 bit.lnk
2019-12-27 12:02 - 2019-12-23 20:21 - 000000000 ____D C:\Users\brunkowski\Downloads\xXiaomi
==================== Files in the root of some directories ========
2017-01-27 14:07 - 2017-06-02 17:25 - 000000201 _____ () C:\Users\brunkowski\AppData\Roaming\WB.CFG
2018-09-05 19:55 - 2018-09-05 19:55 - 000000017 _____ () C:\Users\brunkowski\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================