Prosím o kontrolu logu- velmi pomalý počítač.
Napsal: 16 úno 2020 09:01
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-02-2020
Ran by ondre (administrator) on DESKTOP-BG5JJNF (TOSHIBA Satellite A660) (16-02-2020 08:20:08)
Running from C:\Users\ondre\Desktop
Loaded Profiles: ondre & Janka & Ostatni (Available Profiles: ondre & Janka & Ostatni)
Platform: Windows 10 Home Version 1903 18362.356 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler64.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe
(bookingDesktopApp.) [File not signed] C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
(Ghisler Software GmbH -> Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler64.exe
(HP Printing Korea Co., Ltd.) [File not signed] C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe
(HP Printing Korea Co., Ltd.) [File not signed] C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\msoia.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Janka\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ondre\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ondre\AppData\Local\Microsoft\Teams\current\Teams.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ondre\AppData\Local\Microsoft\Teams\current\Teams.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Ostatni\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Ostatni\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\UpdateAssistant\UpdateAssistant.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\UpdateAssistant\UpdateAssistant.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20011.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DeviceCensus.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotification.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotificationUx.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotificationUx.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\usocoreworker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Samsung Electronics CO., LTD. -> ) C:\Windows\SysWOW64\SecUPDUtilSvc.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TomTom International BV -> TomTom) C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
0 C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1519016 2010-07-28] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] (Samsung Electronics CO., LTD. -> )
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [97509120 2020-01-03] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [AvastBrowserAutoLaunch_0CE231CE0ED3750FB84C2E31233425D0] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [STUISpeedLauncher] => C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe [411136 2015-02-09] () [File not signed]
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [47552040 2019-12-22] (Google LLC -> )
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [2146536 2019-04-09] (TomTom International BV -> TomTom)
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Uninstall 19.232.1124.0005\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\19.232.1124.0005\amd64"
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Uninstall 19.232.1124.0005] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\19.232.1124.0005"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\Run: [AvastBrowserAutoLaunch_5BE222AFE8AD82167FFC8C56883693CF] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Uninstall 19.232.1124.0005\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\19.232.1124.0005\amd64"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Uninstall 19.232.1124.0005] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\19.232.1124.0005"
HKU\S-1-5-21-265624995-536550331-1996926755-1003\...\Run: [AvastBrowserAutoLaunch_85C5741F884D326D2E4BC6F6DAA6B5D2] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-265624995-536550331-1996926755-1003\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --enable-audio-service-sandbox --restore-last-session --flag-switches-begin --flag-switches-end - (the data entry has 102 more characters).
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-17] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\79.0.3060.80\Installer\chrmstp.exe [2020-02-13] (AVAST Software s.r.o. -> AVAST Software)
BootExecute: autocheck autochk /m /P \Device\HarddiskVolume2autocheck autochk /p \??\C:autocheck autochk *
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1FC6EE4A-7E7F-425D-B771-6057E4CE9417} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {283D59D4-C616-4D36-BED5-32F405A99285} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2018-12-31] (Google Inc -> Google Inc.)
Task: {2B223DFB-966D-44BD-A441-149F1495D803} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
Task: {2CF24D9D-6FFC-46FB-BF1F-0A043CD33033} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
Task: {34FA4FC1-F4CA-4AE8-BA44-A8AEBD02B183} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {42B5AF8D-E159-473C-AFF5-69022B776410} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {5098F203-E287-4F8C-AAB9-B213E6D07605} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2167704 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5C70E92D-CBF6-47A1-AFA4-DE035FE688AA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2167704 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5F8C75FA-096A-411C-B6B3-177F30C42673} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2349960 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {6CDF9DD5-1174-43EB-B926-DFF12745EAF5} - System32\Tasks\EPM Preload => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [1333472 2016-01-28] (Samsung Electronics CO., LTD. -> )
Task: {7116DD0A-78FA-403A-991B-16D6E244EF39} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [149840 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {95919C76-C864-4D66-9D91-396C8E36898F} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
Task: {96B9EC73-A0E8-4615-97D1-E401BCEF587F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6292336 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {A8B574FF-857E-4FCA-B621-45FD7F11E7FE} - System32\Tasks\bookingDesktopAppUpdateTaskMachineCore => C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
Task: {AA130AD9-02D2-44EC-B696-6DECF1E61B6A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6292336 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AEA9AC64-AD7A-40D3-B287-2F827DB39C3C} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
Task: {B13E92A9-1472-410E-802C-7EFF11581334} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2018-12-31] (Google Inc -> Google Inc.)
Task: {B97DA5D8-5967-4CE9-813C-E4C153479B5B} - System32\Tasks\bookingDesktopAppUpdateTaskMachineUA => C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
Task: {C014CE2E-D590-4DCD-A149-572A5122BFB7} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [149840 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {D00BB801-251C-4A09-BCA1-9AE64E56EC4C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1236048 2019-07-24] (Adobe Inc. -> Adobe Systems)
Task: {EAACCFAA-B853-4E12-B871-7CFC032F6521} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{19c5cd92-1ab0-47af-bacf-3409add47b07}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{32d9ef43-4b60-4379-8728-c3febed71be2}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=3 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2020-01-02] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=9 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2020-01-02] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-07-31] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default [2020-02-16]
CHR Notifications: Default -> hxxps://en.softonic.com; hxxps://peetube.cc; hxxps://www.tipsport.cz; hxxps://www.tomtom.com
CHR DefaultSearchURL: Default -> hxxps://search.seznam.cz/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSuggestURL: Default -> hxxps://suggest.fulltext.seznam.cz/fulltext_ff?phrase={searchTerms}
CHR Extension: (Prezentace) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-31]
CHR Extension: (No-Script Suite Lite) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahnanjpbkghcdgmlchbcfoiefnifjeni [2019-07-16]
CHR Extension: (Dokumenty) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-31]
CHR Extension: (Disk Google) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-31]
CHR Extension: (YouTube) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-31]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-10-31]
CHR Extension: (Tabulky) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-31]
CHR Extension: (Dokumenty Google offline) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-01-15]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-02-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-13]
CHR Extension: (Gmail) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-18]
CHR Extension: (Chrome Media Router) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-01-15]
CHR Profile: C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-21]
CHR Profile: C:\Users\ondre\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-21]
CHR HKU\S-1-5-21-265624995-536550331-1996926755-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6259592 2019-12-19] (AVAST Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\79.0.3060.80\elevation_service.exe [968552 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
S2 bookingdesktopapp; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
S3 bookingdesktopappm; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11597176 2020-02-05] (Microsoft Corporation -> Microsoft Corporation)
R2 Samsung Network Fax Server; C:\WINDOWS\system32\spool\drivers\x64\3\NetFaxServer64.exe [700928 2018-05-29] (HP Printing Korea Co., Ltd.) [File not signed]
R2 SamsungUPDUtilSvc; C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe [143664 2019-01-07] (Samsung Electronics CO., LTD. -> )
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-05-04] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-01-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-01-11] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37616 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-03] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [276952 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [161544 2019-11-02] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R3 DVB7700ALL; C:\WINDOWS\System32\Drivers\dvb7700all.sys [711168 2013-07-31] (Microsoft Windows Hardware Compatibility Publisher -> DiBcom)
R3 enecir; C:\WINDOWS\system32\DRIVERS\enecir.sys [71168 2013-11-03] (Microsoft Windows Hardware Compatibility Publisher -> ENE TECHNOLOGY INC.)
R3 enecirhid; C:\WINDOWS\system32\DRIVERS\enecirhid.sys [24064 2013-11-03] (Microsoft Windows Hardware Compatibility Publisher -> ENE TECHNOLOGY INC.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [711968 2019-06-04] (Realtek Semiconductor Corp. -> Realtek )
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [44952 2017-04-27] (Toshiba Client Solutions Co.,Ltd. -> Toshiba Client Solutions Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-01-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-01-11] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-01-11] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-02-16 08:20 - 2020-02-16 08:29 - 000034556 _____ C:\Users\ondre\Desktop\FRST.txt
2020-02-16 08:01 - 2020-02-16 08:01 - 000000000 ____D C:\Users\ondre\AppData\Roaming\Microsoft Teams
2020-02-16 08:00 - 2020-02-16 08:00 - 002279424 _____ (Farbar) C:\Users\ondre\Downloads\FRST64 (2).exe
2020-02-16 08:00 - 2020-02-16 08:00 - 002279424 _____ (Farbar) C:\Users\ondre\Desktop\FRST64 (1).exe
2020-02-14 15:12 - 2020-02-14 15:12 - 000000000 ____D C:\Users\Ostatni\AppData\Local\Microsoft Help
2020-02-14 14:55 - 2020-02-14 14:55 - 000000000 ____D C:\Program Files (x86)\Teams Installer
2020-02-14 14:26 - 2020-02-14 14:26 - 000002522 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002499 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002420 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002416 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2020-02-14 14:26 - 2020-02-14 12:29 - 000066696 _____ C:\WINDOWS\VIVALDII.tt2
2020-02-14 14:26 - 2020-02-14 12:29 - 000056596 _____ C:\WINDOWS\HARLOWSI.tt2
2020-02-14 14:25 - 2020-02-14 12:28 - 000076588 _____ C:\WINDOWS\ALGER.tt2
2020-02-14 14:25 - 2020-02-14 12:28 - 000047644 _____ C:\WINDOWS\BAUHS93.tt2
2020-02-14 10:52 - 2020-02-14 10:52 - 000000000 ____D C:\Program Files\Microsoft Office 15
2020-02-14 10:46 - 2020-02-14 10:48 - 005509624 _____ (Microsoft Corporation) C:\Users\Ostatni\Downloads\Setup.Def.cs-cz_O365ProPlusRetail_0d1242d3-080d-4a41-9ea3-ab07e22b22d9_TX_DB_Platform_def_b_64_.exe
2020-02-14 10:45 - 2020-02-14 10:45 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2020-02-13 12:55 - 2020-02-13 12:55 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-02-12 07:36 - 2020-01-16 06:07 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-02-12 07:36 - 2020-01-16 05:23 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-02-03 15:04 - 2020-02-14 15:16 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2020-02-03 14:11 - 2020-02-03 14:11 - 000000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2020-02-03 14:11 - 2020-02-03 14:11 - 000000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2020-02-03 13:10 - 2020-02-03 13:10 - 000013634 _____ C:\Users\Janka\Downloads\Evidence pracovní doby 2020 - pedagogové.xlsx
2020-02-03 12:22 - 2020-02-03 12:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtectionPlatform
2020-02-03 11:54 - 2020-02-14 15:16 - 000000000 ____D C:\Program Files\Microsoft Office
2020-02-03 11:54 - 2020-02-03 11:54 - 000000000 ____D C:\Users\ondre\AppData\Local\Microsoft Help
2020-02-03 11:36 - 2020-02-03 11:50 - 633319536 _____ (Microsoft Corporation) C:\Users\ondre\Downloads\microsoft-office-2010_MSOffice201064bit (1).exe
2020-02-03 10:55 - 2020-02-03 11:05 - 633319536 _____ (Microsoft Corporation) C:\Users\ondre\Downloads\microsoft-office-2010_MSOffice201064bit.exe
2020-01-31 16:41 - 2020-01-31 16:42 - 035299688 _____ (Microsoft Corporation) C:\Users\Janka\Downloads\OneDriveSetup.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-02-16 08:30 - 2019-10-08 06:30 - 000003462 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-02-16 08:30 - 2019-10-08 06:30 - 000003238 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-02-16 08:30 - 2019-09-23 23:34 - 000002914 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-265624995-536550331-1996926755-1003
2020-02-16 08:30 - 2019-09-23 23:34 - 000002914 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-265624995-536550331-1996926755-1002
2020-02-16 08:30 - 2019-09-23 23:34 - 000002914 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-265624995-536550331-1996926755-1001
2020-02-16 08:30 - 2019-09-23 23:34 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2020-02-16 08:26 - 2019-06-28 10:14 - 000000000 ____D C:\FRST
2020-02-16 08:25 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-02-16 08:02 - 2019-02-09 15:54 - 000000000 ____D C:\Users\ondre\AppData\Local\SquirrelTemp
2020-02-16 07:57 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-02-16 07:56 - 2018-12-31 15:41 - 000000000 ___RD C:\Users\ondre\OneDrive
2020-02-16 07:56 - 2018-12-31 15:41 - 000000000 ___RD C:\Users\ondre\OneDrive
2020-02-16 07:56 - 2018-12-31 15:41 - 000000000 ___RD C:\Users\ondre\OneDrive
2020-02-16 07:44 - 2019-03-11 11:24 - 000000000 ____D C:\Users\ondre\AppData\Local\CrashDumps
2020-02-16 07:40 - 2019-12-03 09:00 - 000000000 ___HD C:\OneDriveTemp
2020-02-16 07:40 - 2018-12-31 16:31 - 000000000 ___RD C:\Users\Janka\OneDrive
2020-02-16 07:40 - 2018-12-31 16:31 - 000000000 ___RD C:\Users\Janka\OneDrive
2020-02-16 07:40 - 2018-12-31 16:31 - 000000000 ___RD C:\Users\Janka\OneDrive
2020-02-16 07:39 - 2019-09-23 22:42 - 000000000 ____D C:\Users\ondre
2020-02-16 07:35 - 2019-09-23 22:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-02-14 17:00 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-02-14 15:16 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-02-14 15:12 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\System
2020-02-14 11:56 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-02-14 10:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2020-02-14 09:46 - 2019-09-23 23:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-02-14 09:46 - 2018-12-31 16:10 - 000073232 _____ (Absolute Software Corp.) C:\WINDOWS\SysWOW64\rpcnet.dll
2020-02-14 09:46 - 2018-12-31 15:04 - 000017920 _____ C:\WINDOWS\system32\rpcnetp.exe
2020-02-13 19:24 - 2018-12-31 15:06 - 000017920 _____ C:\WINDOWS\SysWOW64\rpcnetp.dll
2020-02-13 19:23 - 2018-12-31 15:04 - 000017920 _____ C:\WINDOWS\SysWOW64\rpcnetp.exe
2020-02-13 19:22 - 2019-03-19 05:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-02-13 17:20 - 2019-09-23 23:34 - 000003856 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2020-02-13 17:20 - 2019-09-23 23:34 - 000003272 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2020-02-13 17:20 - 2018-12-31 16:08 - 000002509 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2020-02-13 17:20 - 2018-12-31 16:08 - 000002474 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2020-02-13 17:09 - 2019-02-02 16:51 - 000000000 ____D C:\Install
2020-02-13 12:30 - 2019-09-23 22:42 - 000000000 ____D C:\Users\Janka
2020-02-13 12:09 - 2019-01-02 14:48 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-02-13 12:08 - 2019-01-02 14:47 - 120407888 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-02-12 07:09 - 2019-09-23 23:34 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-02-10 19:55 - 2019-09-23 22:42 - 000000000 ____D C:\Users\Ostatni
2020-02-09 18:47 - 2019-07-25 07:27 - 000000000 ____D C:\Users\ondre\AppData\Roaming\vlc
2020-02-07 15:17 - 2019-09-08 11:55 - 000000000 ____D C:\Users\ondre\AppData\Local\ElevatedDiagnostics
2020-02-05 07:19 - 2019-01-07 19:47 - 000000000 ___RD C:\Users\Ostatni\OneDrive
2020-02-05 07:19 - 2019-01-07 19:47 - 000000000 ___RD C:\Users\Ostatni\OneDrive
2020-02-05 07:19 - 2019-01-07 19:47 - 000000000 ___RD C:\Users\Ostatni\OneDrive
2020-02-03 21:56 - 2019-03-19 05:56 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-02-03 21:56 - 2019-03-19 05:56 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-02-03 19:57 - 2019-01-14 16:31 - 000000000 ____D C:\Users\Ostatni\AppData\Local\CrashDumps
2020-02-03 19:25 - 2019-09-23 22:30 - 000399560 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-02-03 15:42 - 2018-12-31 10:41 - 000000167 _____ C:\WINDOWS\win.ini
2020-02-03 14:27 - 2019-04-30 09:00 - 000000000 ____D C:\Janka
2020-01-31 16:54 - 2018-12-31 16:14 - 000000000 ____D C:\Users\Janka\AppData\Local\ConnectedDevicesPlatform
2020-01-31 16:50 - 2019-01-19 13:02 - 000000000 ____D C:\Users\Janka\AppData\Local\PlaceholderTileLogoFolder
2020-01-31 16:50 - 2018-12-31 16:15 - 000000000 ____D C:\Users\Janka\AppData\Local\Packages
2020-01-30 13:14 - 2019-03-01 17:59 - 000000000 ____D C:\Users\Janka\AppData\Local\CrashDumps
2020-01-26 17:32 - 2019-02-06 14:18 - 000002084 _____ C:\Users\Public\Desktop\Google Slides.lnk
2020-01-26 17:32 - 2019-02-06 14:18 - 000002082 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2020-01-26 17:32 - 2019-02-06 14:18 - 000002072 _____ C:\Users\Public\Desktop\Google Docs.lnk
2020-01-26 17:32 - 2019-02-06 14:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2020-01-18 13:31 - 2019-02-06 14:26 - 000000000 ___RD C:\Users\ondre\Disk Google
2020-01-18 13:31 - 2019-02-06 14:26 - 000000000 ___RD C:\Users\ondre\Disk Google
2020-01-18 13:31 - 2019-02-06 14:26 - 000000000 ___RD C:\Users\ondre\Disk Google
2020-01-17 16:14 - 2018-12-31 15:41 - 000002312 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-17 16:14 - 2018-12-31 15:41 - 000002271 _____ C:\Users\Public\Desktop\Google Chrome.lnk
==================== Files in the root of some directories ========
2020-01-10 11:48 - 2020-01-10 11:48 - 000000153 _____ () C:\Users\ondre\AppData\Local\{01150414-5402-4C85-8619-1922B8314B75}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by ondre (administrator) on DESKTOP-BG5JJNF (TOSHIBA Satellite A660) (16-02-2020 08:20:08)
Running from C:\Users\ondre\Desktop
Loaded Profiles: ondre & Janka & Ostatni (Available Profiles: ondre & Janka & Ostatni)
Platform: Windows 10 Home Version 1903 18362.356 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler64.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe
(bookingDesktopApp.) [File not signed] C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe
(Ghisler Software GmbH -> Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler64.exe
(HP Printing Korea Co., Ltd.) [File not signed] C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe
(HP Printing Korea Co., Ltd.) [File not signed] C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\msoia.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Janka\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ondre\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ondre\AppData\Local\Microsoft\Teams\current\Teams.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\ondre\AppData\Local\Microsoft\Teams\current\Teams.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Ostatni\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Ostatni\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\UpdateAssistant\UpdateAssistant.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\UpdateAssistant\UpdateAssistant.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20011.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DeviceCensus.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotification.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotificationUx.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotificationUx.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\usocoreworker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Samsung Electronics CO., LTD. -> ) C:\Windows\SysWOW64\SecUPDUtilSvc.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TomTom International BV -> TomTom) C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
0 C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1519016 2010-07-28] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] (Samsung Electronics CO., LTD. -> )
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [97509120 2020-01-03] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [AvastBrowserAutoLaunch_0CE231CE0ED3750FB84C2E31233425D0] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [STUISpeedLauncher] => C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe [411136 2015-02-09] () [File not signed]
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [47552040 2019-12-22] (Google LLC -> )
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [2146536 2019-04-09] (TomTom International BV -> TomTom)
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Uninstall 19.232.1124.0005\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\19.232.1124.0005\amd64"
HKU\S-1-5-21-265624995-536550331-1996926755-1001\...\RunOnce: [Uninstall 19.232.1124.0005] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ondre\AppData\Local\Microsoft\OneDrive\19.232.1124.0005"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\Run: [AvastBrowserAutoLaunch_5BE222AFE8AD82167FFC8C56883693CF] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Uninstall 19.232.1124.0005\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\19.232.1124.0005\amd64"
HKU\S-1-5-21-265624995-536550331-1996926755-1002\...\RunOnce: [Uninstall 19.232.1124.0005] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Janka\AppData\Local\Microsoft\OneDrive\19.232.1124.0005"
HKU\S-1-5-21-265624995-536550331-1996926755-1003\...\Run: [AvastBrowserAutoLaunch_85C5741F884D326D2E4BC6F6DAA6B5D2] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-265624995-536550331-1996926755-1003\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --enable-audio-service-sandbox --restore-last-session --flag-switches-begin --flag-switches-end - (the data entry has 102 more characters).
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-17] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\79.0.3060.80\Installer\chrmstp.exe [2020-02-13] (AVAST Software s.r.o. -> AVAST Software)
BootExecute: autocheck autochk /m /P \Device\HarddiskVolume2autocheck autochk /p \??\C:autocheck autochk *
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1FC6EE4A-7E7F-425D-B771-6057E4CE9417} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {283D59D4-C616-4D36-BED5-32F405A99285} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2018-12-31] (Google Inc -> Google Inc.)
Task: {2B223DFB-966D-44BD-A441-149F1495D803} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
Task: {2CF24D9D-6FFC-46FB-BF1F-0A043CD33033} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
Task: {34FA4FC1-F4CA-4AE8-BA44-A8AEBD02B183} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {42B5AF8D-E159-473C-AFF5-69022B776410} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {5098F203-E287-4F8C-AAB9-B213E6D07605} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2167704 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5C70E92D-CBF6-47A1-AFA4-DE035FE688AA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2167704 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5F8C75FA-096A-411C-B6B3-177F30C42673} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2349960 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {6CDF9DD5-1174-43EB-B926-DFF12745EAF5} - System32\Tasks\EPM Preload => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [1333472 2016-01-28] (Samsung Electronics CO., LTD. -> )
Task: {7116DD0A-78FA-403A-991B-16D6E244EF39} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [149840 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {95919C76-C864-4D66-9D91-396C8E36898F} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
Task: {96B9EC73-A0E8-4615-97D1-E401BCEF587F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6292336 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {A8B574FF-857E-4FCA-B621-45FD7F11E7FE} - System32\Tasks\bookingDesktopAppUpdateTaskMachineCore => C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
Task: {AA130AD9-02D2-44EC-B696-6DECF1E61B6A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6292336 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AEA9AC64-AD7A-40D3-B287-2F827DB39C3C} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1858536 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
Task: {B13E92A9-1472-410E-802C-7EFF11581334} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2018-12-31] (Google Inc -> Google Inc.)
Task: {B97DA5D8-5967-4CE9-813C-E4C153479B5B} - System32\Tasks\bookingDesktopAppUpdateTaskMachineUA => C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
Task: {C014CE2E-D590-4DCD-A149-572A5122BFB7} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [149840 2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {D00BB801-251C-4A09-BCA1-9AE64E56EC4C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1236048 2019-07-24] (Adobe Inc. -> Adobe Systems)
Task: {EAACCFAA-B853-4E12-B871-7CFC032F6521} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{19c5cd92-1ab0-47af-bacf-3409add47b07}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{32d9ef43-4b60-4379-8728-c3febed71be2}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=3 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2020-01-02] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @bookingdesktopapp.com/bookingDesktopApp Update;version=9 -> C:\Program Files (x86)\bookingDesktopApp\Update\1.3.99.0\npbookingDesktopAppUpdate3.dll [2020-01-02] (bookingDesktopApp.) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-02-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-07-31] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default [2020-02-16]
CHR Notifications: Default -> hxxps://en.softonic.com; hxxps://peetube.cc; hxxps://www.tipsport.cz; hxxps://www.tomtom.com
CHR DefaultSearchURL: Default -> hxxps://search.seznam.cz/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSuggestURL: Default -> hxxps://suggest.fulltext.seznam.cz/fulltext_ff?phrase={searchTerms}
CHR Extension: (Prezentace) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-31]
CHR Extension: (No-Script Suite Lite) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahnanjpbkghcdgmlchbcfoiefnifjeni [2019-07-16]
CHR Extension: (Dokumenty) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-31]
CHR Extension: (Disk Google) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-31]
CHR Extension: (YouTube) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-31]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-10-31]
CHR Extension: (Tabulky) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-31]
CHR Extension: (Dokumenty Google offline) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-01-15]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-02-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-13]
CHR Extension: (Gmail) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-18]
CHR Extension: (Chrome Media Router) - C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-01-15]
CHR Profile: C:\Users\ondre\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-21]
CHR Profile: C:\Users\ondre\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-21]
CHR HKU\S-1-5-21-265624995-536550331-1996926755-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6259592 2019-12-19] (AVAST Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-12-31] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\79.0.3060.80\elevation_service.exe [968552 2020-01-08] (AVAST Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
S2 bookingdesktopapp; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
S3 bookingdesktopappm; C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe [102400 2020-01-02] (bookingDesktopApp.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11597176 2020-02-05] (Microsoft Corporation -> Microsoft Corporation)
R2 Samsung Network Fax Server; C:\WINDOWS\system32\spool\drivers\x64\3\NetFaxServer64.exe [700928 2018-05-29] (HP Printing Korea Co., Ltd.) [File not signed]
R2 SamsungUPDUtilSvc; C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe [143664 2019-01-07] (Samsung Electronics CO., LTD. -> )
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-05-04] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-01-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-01-11] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37616 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-03] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [276952 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [161544 2019-11-02] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-03] (AVAST Software s.r.o. -> AVAST Software)
R3 DVB7700ALL; C:\WINDOWS\System32\Drivers\dvb7700all.sys [711168 2013-07-31] (Microsoft Windows Hardware Compatibility Publisher -> DiBcom)
R3 enecir; C:\WINDOWS\system32\DRIVERS\enecir.sys [71168 2013-11-03] (Microsoft Windows Hardware Compatibility Publisher -> ENE TECHNOLOGY INC.)
R3 enecirhid; C:\WINDOWS\system32\DRIVERS\enecirhid.sys [24064 2013-11-03] (Microsoft Windows Hardware Compatibility Publisher -> ENE TECHNOLOGY INC.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [711968 2019-06-04] (Realtek Semiconductor Corp. -> Realtek )
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [44952 2017-04-27] (Toshiba Client Solutions Co.,Ltd. -> Toshiba Client Solutions Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-01-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-01-11] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-01-11] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-02-16 08:20 - 2020-02-16 08:29 - 000034556 _____ C:\Users\ondre\Desktop\FRST.txt
2020-02-16 08:01 - 2020-02-16 08:01 - 000000000 ____D C:\Users\ondre\AppData\Roaming\Microsoft Teams
2020-02-16 08:00 - 2020-02-16 08:00 - 002279424 _____ (Farbar) C:\Users\ondre\Downloads\FRST64 (2).exe
2020-02-16 08:00 - 2020-02-16 08:00 - 002279424 _____ (Farbar) C:\Users\ondre\Desktop\FRST64 (1).exe
2020-02-14 15:12 - 2020-02-14 15:12 - 000000000 ____D C:\Users\Ostatni\AppData\Local\Microsoft Help
2020-02-14 14:55 - 2020-02-14 14:55 - 000000000 ____D C:\Program Files (x86)\Teams Installer
2020-02-14 14:26 - 2020-02-14 14:26 - 000002522 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002499 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002420 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000002416 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2020-02-14 14:26 - 2020-02-14 14:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2020-02-14 14:26 - 2020-02-14 12:29 - 000066696 _____ C:\WINDOWS\VIVALDII.tt2
2020-02-14 14:26 - 2020-02-14 12:29 - 000056596 _____ C:\WINDOWS\HARLOWSI.tt2
2020-02-14 14:25 - 2020-02-14 12:28 - 000076588 _____ C:\WINDOWS\ALGER.tt2
2020-02-14 14:25 - 2020-02-14 12:28 - 000047644 _____ C:\WINDOWS\BAUHS93.tt2
2020-02-14 10:52 - 2020-02-14 10:52 - 000000000 ____D C:\Program Files\Microsoft Office 15
2020-02-14 10:46 - 2020-02-14 10:48 - 005509624 _____ (Microsoft Corporation) C:\Users\Ostatni\Downloads\Setup.Def.cs-cz_O365ProPlusRetail_0d1242d3-080d-4a41-9ea3-ab07e22b22d9_TX_DB_Platform_def_b_64_.exe
2020-02-14 10:45 - 2020-02-14 10:45 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2020-02-13 12:55 - 2020-02-13 12:55 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-02-12 07:36 - 2020-01-16 06:07 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-02-12 07:36 - 2020-01-16 05:23 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-02-03 15:04 - 2020-02-14 15:16 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2020-02-03 14:11 - 2020-02-03 14:11 - 000000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2020-02-03 14:11 - 2020-02-03 14:11 - 000000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2020-02-03 13:10 - 2020-02-03 13:10 - 000013634 _____ C:\Users\Janka\Downloads\Evidence pracovní doby 2020 - pedagogové.xlsx
2020-02-03 12:22 - 2020-02-03 12:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtectionPlatform
2020-02-03 11:54 - 2020-02-14 15:16 - 000000000 ____D C:\Program Files\Microsoft Office
2020-02-03 11:54 - 2020-02-03 11:54 - 000000000 ____D C:\Users\ondre\AppData\Local\Microsoft Help
2020-02-03 11:36 - 2020-02-03 11:50 - 633319536 _____ (Microsoft Corporation) C:\Users\ondre\Downloads\microsoft-office-2010_MSOffice201064bit (1).exe
2020-02-03 10:55 - 2020-02-03 11:05 - 633319536 _____ (Microsoft Corporation) C:\Users\ondre\Downloads\microsoft-office-2010_MSOffice201064bit.exe
2020-01-31 16:41 - 2020-01-31 16:42 - 035299688 _____ (Microsoft Corporation) C:\Users\Janka\Downloads\OneDriveSetup.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-02-16 08:30 - 2019-10-08 06:30 - 000003462 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-02-16 08:30 - 2019-10-08 06:30 - 000003238 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-02-16 08:30 - 2019-09-23 23:34 - 000002914 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-265624995-536550331-1996926755-1003
2020-02-16 08:30 - 2019-09-23 23:34 - 000002914 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-265624995-536550331-1996926755-1002
2020-02-16 08:30 - 2019-09-23 23:34 - 000002914 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-265624995-536550331-1996926755-1001
2020-02-16 08:30 - 2019-09-23 23:34 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2020-02-16 08:26 - 2019-06-28 10:14 - 000000000 ____D C:\FRST
2020-02-16 08:25 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-02-16 08:02 - 2019-02-09 15:54 - 000000000 ____D C:\Users\ondre\AppData\Local\SquirrelTemp
2020-02-16 07:57 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-02-16 07:56 - 2018-12-31 15:41 - 000000000 ___RD C:\Users\ondre\OneDrive
2020-02-16 07:56 - 2018-12-31 15:41 - 000000000 ___RD C:\Users\ondre\OneDrive
2020-02-16 07:56 - 2018-12-31 15:41 - 000000000 ___RD C:\Users\ondre\OneDrive
2020-02-16 07:44 - 2019-03-11 11:24 - 000000000 ____D C:\Users\ondre\AppData\Local\CrashDumps
2020-02-16 07:40 - 2019-12-03 09:00 - 000000000 ___HD C:\OneDriveTemp
2020-02-16 07:40 - 2018-12-31 16:31 - 000000000 ___RD C:\Users\Janka\OneDrive
2020-02-16 07:40 - 2018-12-31 16:31 - 000000000 ___RD C:\Users\Janka\OneDrive
2020-02-16 07:40 - 2018-12-31 16:31 - 000000000 ___RD C:\Users\Janka\OneDrive
2020-02-16 07:39 - 2019-09-23 22:42 - 000000000 ____D C:\Users\ondre
2020-02-16 07:35 - 2019-09-23 22:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-02-14 17:00 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-02-14 15:16 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-02-14 15:12 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\System
2020-02-14 11:56 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-02-14 10:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2020-02-14 09:46 - 2019-09-23 23:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-02-14 09:46 - 2018-12-31 16:10 - 000073232 _____ (Absolute Software Corp.) C:\WINDOWS\SysWOW64\rpcnet.dll
2020-02-14 09:46 - 2018-12-31 15:04 - 000017920 _____ C:\WINDOWS\system32\rpcnetp.exe
2020-02-13 19:24 - 2018-12-31 15:06 - 000017920 _____ C:\WINDOWS\SysWOW64\rpcnetp.dll
2020-02-13 19:23 - 2018-12-31 15:04 - 000017920 _____ C:\WINDOWS\SysWOW64\rpcnetp.exe
2020-02-13 19:22 - 2019-03-19 05:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-02-13 17:20 - 2019-09-23 23:34 - 000003856 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2020-02-13 17:20 - 2019-09-23 23:34 - 000003272 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2020-02-13 17:20 - 2018-12-31 16:08 - 000002509 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2020-02-13 17:20 - 2018-12-31 16:08 - 000002474 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2020-02-13 17:09 - 2019-02-02 16:51 - 000000000 ____D C:\Install
2020-02-13 12:30 - 2019-09-23 22:42 - 000000000 ____D C:\Users\Janka
2020-02-13 12:09 - 2019-01-02 14:48 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-02-13 12:08 - 2019-01-02 14:47 - 120407888 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-02-12 07:09 - 2019-09-23 23:34 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-02-10 19:55 - 2019-09-23 22:42 - 000000000 ____D C:\Users\Ostatni
2020-02-09 18:47 - 2019-07-25 07:27 - 000000000 ____D C:\Users\ondre\AppData\Roaming\vlc
2020-02-07 15:17 - 2019-09-08 11:55 - 000000000 ____D C:\Users\ondre\AppData\Local\ElevatedDiagnostics
2020-02-05 07:19 - 2019-01-07 19:47 - 000000000 ___RD C:\Users\Ostatni\OneDrive
2020-02-05 07:19 - 2019-01-07 19:47 - 000000000 ___RD C:\Users\Ostatni\OneDrive
2020-02-05 07:19 - 2019-01-07 19:47 - 000000000 ___RD C:\Users\Ostatni\OneDrive
2020-02-03 21:56 - 2019-03-19 05:56 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-02-03 21:56 - 2019-03-19 05:56 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-02-03 19:57 - 2019-01-14 16:31 - 000000000 ____D C:\Users\Ostatni\AppData\Local\CrashDumps
2020-02-03 19:25 - 2019-09-23 22:30 - 000399560 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-02-03 15:42 - 2018-12-31 10:41 - 000000167 _____ C:\WINDOWS\win.ini
2020-02-03 14:27 - 2019-04-30 09:00 - 000000000 ____D C:\Janka
2020-01-31 16:54 - 2018-12-31 16:14 - 000000000 ____D C:\Users\Janka\AppData\Local\ConnectedDevicesPlatform
2020-01-31 16:50 - 2019-01-19 13:02 - 000000000 ____D C:\Users\Janka\AppData\Local\PlaceholderTileLogoFolder
2020-01-31 16:50 - 2018-12-31 16:15 - 000000000 ____D C:\Users\Janka\AppData\Local\Packages
2020-01-30 13:14 - 2019-03-01 17:59 - 000000000 ____D C:\Users\Janka\AppData\Local\CrashDumps
2020-01-26 17:32 - 2019-02-06 14:18 - 000002084 _____ C:\Users\Public\Desktop\Google Slides.lnk
2020-01-26 17:32 - 2019-02-06 14:18 - 000002082 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2020-01-26 17:32 - 2019-02-06 14:18 - 000002072 _____ C:\Users\Public\Desktop\Google Docs.lnk
2020-01-26 17:32 - 2019-02-06 14:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2020-01-18 13:31 - 2019-02-06 14:26 - 000000000 ___RD C:\Users\ondre\Disk Google
2020-01-18 13:31 - 2019-02-06 14:26 - 000000000 ___RD C:\Users\ondre\Disk Google
2020-01-18 13:31 - 2019-02-06 14:26 - 000000000 ___RD C:\Users\ondre\Disk Google
2020-01-17 16:14 - 2018-12-31 15:41 - 000002312 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-01-17 16:14 - 2018-12-31 15:41 - 000002271 _____ C:\Users\Public\Desktop\Google Chrome.lnk
==================== Files in the root of some directories ========
2020-01-10 11:48 - 2020-01-10 11:48 - 000000153 _____ () C:\Users\ondre\AppData\Local\{01150414-5402-4C85-8619-1922B8314B75}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================