Prosim o kontrolu pomalé PC
Napsal: 01 čer 2020 15:19
FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-05-2020 01
Ran by Marsal (administrator) on POHRS (Dell Inc. Latitude E6530) (01-06-2020 16:07:43)
Running from C:\Users\Marsal\Desktop
Loaded Profiles: Marsal
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\hapi64\pbadrvsvc.exe
() [File not signed] C:\Windows\SysWOW64\srvany.exe
(ActMask Group Co., Ltd -> ActMask Co.,Ltd - hxxp://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Group Co., Ltd -> ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe <2>
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidMonitorSvc.exe
(AuthenTec, Inc. -> Authentec Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Dell Inc -> Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
(ELDES UAB -> ) C:\Program Files\Common Files\Eldes\ELDES Service.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation-Mobile Wireless Group -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Maxim Deminov -> @MAX Software) C:\Program Files (x86)\MaxSyncUp\MaxSyncUp.exe
(Maxim Deminov -> @MAX Software) C:\Program Files (x86)\MaxSyncUp\msusvc.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <6>
(O2Micro Inc. -> O2Micro International) C:\Windows\System32\o2flash.exe
(O2Micro Inc. -> O2Micro.) C:\Windows\SysWOW64\SDIOAssist.exe
(SafeNet, Inc. -> SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Siemens AG) [File not signed] C:\Siemens_EA\TBII\EMII\BIN\prl.exe
(Siemens AG) [File not signed] C:\Siemens_EA\TBII\EMII\BIN\rmd.exe
(Softland SRL -> Microsoft) C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Wave Systems Corp. -> ) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
(Wave Systems Corp. -> Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
(Wave Systems Corp. -> Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
(Wave Systems Corp.) [File not signed] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [736552 2015-05-29] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
HKLM\...\Run: [TdmNotify] => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [370584 2012-11-09] (Wave Systems Corp. -> Wave Systems Corp.)
HKLM\...\Run: [DFEPApplication] => C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077432 2012-08-15] (Dell Inc. -> Dell Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4148664 2013-10-07] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4791024 2013-07-17] (Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation)
HKLM\...\Run: [PrintDisp] => C:\Windows\system32\PrintDisp.exe [588936 2015-08-18] (ActMask Group Co., Ltd -> ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-10-16] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [462974 2011-12-16] (Creative Technology Ltd) [File not signed]
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [104528 2013-02-26] (VMware, Inc. -> VMware, Inc.)
HKLM-x32\...\Run: [TBII-PRELOADER] => C:\Siemens_EA\TBII\EMII\BIN\PRL.EXE [97280 2014-02-27] (Siemens AG) [File not signed]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [77824 2018-10-04] (Apple Computer, Inc.) [File not signed]
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133216 2017-03-23] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM\...\Windows x64\Print Processors\ActMask: C:\Windows\System32\spool\prtprocs\x64\ActPrint.dll [51336 2017-02-19] (ActMask Group Co., Ltd -> ActMask Co.,Ltd)
HKLM\...\Windows x64\Print Processors\HP1005PrintProc: C:\Windows\System32\spool\prtprocs\x64\HP1005PP.dll [65024 2013-04-01] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Windows x64\Print Processors\hpzpplhn: C:\Windows\System32\spool\prtprocs\x64\hpzpplhn.dll [99840 2008-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\HP1005LM: C:\Windows\system32\HP1005LM.DLL [178688 2013-04-01] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\novaPDF Port Monitor: C:\Windows\system32\novamn8.dll [18944 2016-12-16] (Softland) [File not signed]
HKLM\...\Print\Monitors\PDF-XChange V6 Printer Port Monitor (Lite): C:\Windows\system32\pxcpm5L.dll [150208 2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
HKLM\...\Print\Monitors\WSD Port: C:\Windows\system32\WSDMon.dll [224768 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.61\Installer\chrmstp.exe [2020-05-22] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\...\Authentication\Credential Providers: [{18CBEEAA-6708-41A1-9379-D08915333CF2}] -> C:\Program Files\Common Files\SPBA\provider.dll [2012-08-17] (AuthenTec, Inc. -> Authentec Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\\BtwCP.dll [2012-02-22] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{D28973E5-8630-41af-8831-50A15FEB396B}] -> C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll [2012-02-22] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
HKLM\Software\...\Authentication\Credential Provider Filters: [{AE583D93-8D1B-424F-9858-5623FB7824EE}] -> C:\Program Files\Common Files\SPBA\provider.dll [2012-08-17] (AuthenTec, Inc. -> Authentec Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-03-22]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
Startup: C:\Users\Eng_TBII\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
Startup: C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {009BA484-6FA4-409E-928C-373BAF7AFF4E} - System32\Tasks\GoogleUpdateTaskMachineCore1d12e50ffd0952d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {00FB573A-5990-49FD-BBEB-50570EAAC154} - System32\Tasks\GoogleUpdateTaskMachineUA1d002f2d42d6254 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {095E7A76-8B84-4161-A1BF-99A75EFF7B9B} - System32\Tasks\GoogleUpdateTaskMachineCore1d0f10475820c0d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {0C40A0A5-D478-4A63-B215-EF22991645DD} - System32\Tasks\GoogleUpdateTaskMachineUA1d15e3f4dd45b57 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {0C82E3E5-CD05-461D-A916-7C745877714D} - System32\Tasks\{D5ABCAC2-019B-48CF-B60F-A8D3EC0BDC5C} => C:\Windows\system32\pcalua.exe -a C:\Users\Eng_TBII\Desktop\SALAMAND.EXE -d C:\Users\Eng_TBII\Desktop
Task: {0FB6737A-91AD-4071-9FC0-C010C75B2C84} - System32\Tasks\WinThruster64-Marsal-Startup => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION
Task: {18FD6ED4-2E3D-4C5D-A491-101DE862E032} - System32\Tasks\{DDFDF8E6-9FC9-41F1-A9AF-9A34AF3026BD} => C:\Windows\system32\pcalua.exe -a C:\Windows\iun6002.exe -c "E:\Portable\WYSIWYG Web Builder 10\irunin.ini" <==== ATTENTION
Task: {1975B8DF-3B3A-4688-9EDA-5B7F031528E7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {1975B8DF-3B3A-4688-9EDA-5B7F031528E7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {19FC6C74-65FD-40EE-8761-3DAEB32DF832} - System32\Tasks\GoogleUpdateTaskMachineCore1d0442c6483cad6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {1BE61B9A-7F11-42AE-80BF-368C94890E7A} - System32\Tasks\GoogleUpdateTaskMachineCore1d1eb5c84a67257 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {1F87D442-12D5-4A60-B685-9DA31E969E58} - System32\Tasks\GoogleUpdateTaskMachineUA1d091e7d41a9630 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {2A67726F-3893-427A-8250-BB44B3D4EEA8} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e3f4dbed736 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {3381E415-0A77-4CE0-942C-694F6D0AC7FA} - System32\Tasks\{D6842B4B-4CEF-46FF-88CE-2406810A73E4} => C:\Windows\system32\pcalua.exe -a C:\Windows\unvise32qt.exe -c C:\Windows\system32\QuickTime\Uninstall.log
Task: {35AFFA54-F29D-4CBB-97D1-500B293D36CC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {43E11D12-2102-426D-8EBE-B718E0FB43EB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {50065D99-36D9-4A1E-963F-41328AA996CF} - System32\Tasks\GoogleUpdateTaskMachineUA1d12e50ffe99bcb => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {52BEBEB5-FC96-4450-BC04-90F52E8549D4} - System32\Tasks\doPDF Update => C:\Program Files\Softland\novaPDF 8\Driver\UpdateApplication.exe [682408 2016-12-16] (Softland SRL -> )
Task: {61104FFA-67A1-4611-A529-E14D95770740} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {61104FFA-67A1-4611-A529-E14D95770740} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {6D6025F1-A47C-430D-B94E-174FECA78470} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(1): %windir%\system32\GWX\GWXUXWorker.exe -> /ScheduleUpgradeReminderTime
Task: {6D6025F1-A47C-430D-B94E-174FECA78470} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {7101F7DB-2222-448B-B463-C26870634176} - \SpyHunter4Startup -> No File <==== ATTENTION
Task: {8448F66F-5F55-4695-B7ED-4B299C9122BA} - System32\Tasks\GoogleUpdateTaskMachineUA1d0bf2f446dca70 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {8644D8AA-53DD-4FB7-9C14-16692C9A3203} - System32\Tasks\GoogleUpdateTaskMachineUA1d1eb5c84bc6ba9 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {964EC295-9A62-47FC-9582-7601E5EB54FD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {964EC295-9A62-47FC-9582-7601E5EB54FD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent
Task: {964EC295-9A62-47FC-9582-7601E5EB54FD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {A6899650-D6AE-410A-9F1A-1CF5345FB6AA} - System32\Tasks\GoogleUpdateTaskMachineCore1d0bf2f444cd475 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {ABF29991-41D5-4248-AB94-F12FDBC1975F} - System32\Tasks\Ashampoo Privacy Protector Weekly Security Scan => C:\Program Files (x86)\Ashampoo\Ashampoo Privacy Protector\PrivacyProtector.exe
Task: {AD38CD45-93B1-4D32-8EC0-11B16EA7E1C8} - System32\Tasks\{4C24CC4B-EC99-4779-ABE4-E4E8277CDE60} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Altap Salamander\remove\remove.exe"
Task: {AE7FCAAB-F6D1-4852-9B39-9F354A60EE5D} - System32\Tasks\GoogleUpdateTaskMachineCore1d091e7d3ff6caa => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {BC48C21B-4F43-4D58-BF0D-D5676AC274F1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {C185CA7E-36F4-495C-88BD-8153675CD0E3} - System32\Tasks\GoogleUpdateTaskMachineUA1d0f104759fa69c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {C777EF2D-6D0E-4AD3-977D-48C583B82F73} - System32\Tasks\GoogleUpdateTaskMachineUA1d1ab39f5bc091d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {DE647C46-284E-4EC5-9A3D-5318FEBDD71B} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ab39f59ce7e8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {E5FAB1D4-4573-4487-BAA0-B8C24310AC5B} - System32\Tasks\GoogleUpdateTaskMachineUA1d0442c649ef45c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {E73A29F6-ACB6-4C99-B952-8FFC7ED50D88} - System32\Tasks\GoogleUpdateTaskMachineCore1d0e25af61709a4 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {EFA8B190-43B0-4D76-B6E9-5338D07FB661} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [855352 2016-02-19] (Intel(R) Trusted Connect Service -> Intel(R) Corporation)
Task: {FFFFA652-CABF-46FC-83C8-896E03FC9F94} - System32\Tasks\GoogleUpdateTaskMachineUA1d0e25af634f254 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0442c6483cad6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d091e7d3ff6caa.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bf2f444cd475.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e25af61709a4.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f10475820c0d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12e50ffd0952d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e3f4dbed736.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab39f59ce7e8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d002f2d42d6254.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0442c649ef45c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d091e7d41a9630.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0bf2f446dca70.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0e25af634f254.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0f104759fa69c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d12e50ffe99bcb.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15e3f4dd45b57.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1ab39f5bc091d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{05CC11B1-09F3-4C3D-BEB8-9A43A1940489}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
Tcpip\..\Interfaces\{13D67E57-6A65-4784-84E4-2F9931E10815}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{DF801C61-BF64-4798-AE02-C0F6FEE5BBAB}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,192.168.71.1,1]
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3879696279-2694623716-4221884656-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {3965D173-40FC-424F-9703-F831D32C8393} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {62694250-03A8-4440-96F1-3F6DC0B864AF} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... kSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&r ... {startPage}
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {7C791268-4AF8-4919-9304-07B755B8A557} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {923B92C4-B653-4002-8D98-F6A77810DEBD} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... kSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {B352A849-9513-44A9-B119-CED8E358CF4F} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {C0054516-41EE-4ABF-853D-3D301DC05C2A} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {C7851CF3-22CC-4B91-8736-07D868E1B4CE} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... kSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {D70ACB0B-5D3F-43EB-94CA-5127B0180311} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/CZ/Core/Player/2020PlayerAX_IKEA_Win32.cab
FireFox:
========
FF DefaultProfile: 2wmfnqiv.default-1441599875080
FF ProfilePath: C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 [2020-06-01]
FF DownloadDir: C:
FF NewTab: Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 -> C:\\ProgramData\\Medlights\\ff.NT
FF Notifications: Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 -> hxxps://dashboard.zopim.com; hxxp://dashboard.zopim.com; hxxp://dashboard.smartsupp.com; hxxps://dashboard.smartsupp.com; hxxps://calendar.google.com; hxxps://web.whatsapp.com; hxxps://sofe.ladesk.com; hxxps://www.exasoft.cz; hxxps://www.smartsupp.com; hxxps://forum.chronomag.cz
FF NewTabOverride: Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 -> Disabled: {ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: (Firebug) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\firebug@software.joehewitt.com.xpi [2017-03-01] [Legacy]
FF Extension: (MEGA) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\firefox@mega.co.nz.xpi [2020-05-30] [UpdateUrl:hxxps://mega.nz/firefox-web-extension-updates.json]
FF Extension: (Youtube to MP3 Plugin) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\flv2mp3@hotger.com.xpi [2017-11-17]
FF Extension: (SafeInCloud Password Manager) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\info@safe-in-cloud.com.xpi [2020-05-30]
FF Extension: (Add to Wunderlist) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\jid1-3gu11JeYBiIuJA@jetpack.xpi [2017-03-29] [Legacy]
FF Extension: (To Google Translate) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2019-11-25]
FF Extension: (Seznam doplněk - Esko) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\sko-extension@firma.seznam.cz.xpi [2020-04-28]
FF Extension: (Session Manager) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2017-01-31] [Legacy]
FF Extension: (ePub Reader) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{323353ee-cfbd-4178-9676-85566d98c8b1}.xpi [2020-01-30]
FF Extension: (gtranslate) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi [2016-11-30] [Legacy]
FF Extension: (Zoom Scheduler) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{bf855ead-d7c3-4c7b-9f88-9a7e75c0efdf}.xpi [2020-04-30]
FF Extension: (No Name) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-04-01]
FF Extension: (Seznam doplněk - Email) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}.xpi [2020-04-28]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Extension: (ESET Endpoint Security Extension) - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird [2014-07-17] [Legacy] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=1.1.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: JFGuide -> C:\Program Files (x86)\NetSurveillance\CMS\npGuide.dll [2019-07-16] () [File not signed]
FF Plugin-x32: JFWeb -> C:\Program Files (x86)\NetSurveillance\CMS\npWebPlugin.dll [2019-07-16] () [File not signed]
FF Plugin-x32: Web Components -> C:\Program Files (x86)\Web Components\npWebVideoPlugin.dll [2018-12-10] (HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3879696279-2694623716-4221884656-1006: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3879696279-2694623716-4221884656-1006: www.wansview.com/HYPlayer -> C:\Program Files (x86)\HYPlayer\npHYPlayer.dll [No File]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default [2020-06-01]
CHR Notifications: Default -> hxxps://calendar.google.com
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxps://isearch.avg.co ... 2012-09-28 09:40:19&v=12.2.5.34&sap=hp","hxxp://www.google.com"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Dokumenty) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Disk Google) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
CHR Extension: (SEO META in 1 CLICK) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjogjfinolnhfhkbipphpdlldadpnmhc [2019-07-23]
CHR Extension: (YouTube) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-27]
CHR Extension: (History 2) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\cahejgbbfgmlmjgdjlibphdjeldhagkp [2017-05-07]
CHR Extension: (Wondershare Video Converter Ultimate) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp [2017-09-02]
CHR Extension: (Aliexpress SuperStar česky, Historie cen a koruny) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciclollkolafellcaolgccmfjldgpolo [2020-04-24]
CHR Extension: (Vyhledávání Google) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-06-01]
CHR Extension: (Snip it! button for eBay) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhaoojkpcgaobmnnphdpdokcgdiibblh [2019-02-10]
CHR Extension: (SafeInCloud Password Manager) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lchdigjbcmdgcfeijpfkpadacbijihjl [2020-04-24]
CHR Extension: (Rozšíření Google Keep pro Chrome) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2020-05-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
CHR Extension: (Simple EPUB Reader) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhbgcchcbdjdenibfmjofobklkkhofc [2017-06-07]
CHR Extension: (Downloader for Instagram™ + Direct Message) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpikmlhoaojbbmmpejnimiglejmboe [2020-05-19]
CHR Extension: (Gmail) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-04]
CHR Extension: (Chrome Media Router) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-05-23]
CHR Profile: C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-23]
CHR HKU\S-1-5-21-3879696279-2694623716-4221884656-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKU\S-1-5-21-3879696279-2694623716-4221884656-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [96000 2015-09-25] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation -> Microsoft Corporation)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [36544 2020-04-17] (Dell Inc -> )
R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280504 2012-08-15] (Dell Inc. -> Dell Inc.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [42048 2013-10-07] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [1025584 2013-10-07] (ESET, spol. s r.o. -> ESET)
R2 EldesService; C:\Program Files\Common Files\Eldes\ELDES Service.exe [201416 2018-08-01] (ELDES UAB -> )
R2 EmbassyService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [225720 2012-11-20] (Wave Systems Corp. -> )
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [191368 2013-10-07] (ESET, spol. s r.o. -> ESET)
R2 hasplms; C:\Windows\system32\hasplms.exe [4180576 2010-09-27] (SafeNet, Inc. -> SafeNet Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [317416 2018-09-24] (Intel Corporation -> Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [209184 2016-05-10] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MaxSyncUpService; C:\Program Files (x86)\MaxSyncUp\msusvc.exe [2340912 2018-05-07] (Maxim Deminov -> @MAX Software)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-07-17] (Intel Corporation-Mobile Wireless Group -> )
R2 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [51112 2016-12-16] (Softland SRL -> Microsoft)
R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro Inc. -> O2Micro International)
R2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] () [File not signed]
S2 OracleServiceTBII; C:\Siemens_EA\TBII\DB\ORANT\BIN\oracle.exe [156133376 2013-10-09] (Oracle Corporation) [File not signed]
S2 OracleTBIIORA11R2TNSListener; C:\Siemens_EA\TBII\DB\ORANT\BIN\TNSLSNR.EXE [552960 2013-10-08] (Oracle Corporation) [File not signed]
R2 PbaDrvSvc_x64; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\hapi64\pbadrvsvc.exe [20480 2012-11-23] () [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S2 tcsd_win32.exe; C:\Program Files (x86)\Security Innovation\SI TSS\bin\tcsd_win32.exe [1643520 2012-05-11] () [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13255184 2020-05-19] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [13242960 2013-02-26] (VMware, Inc. -> )
R2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1758720 2012-11-19] (Wave Systems Corp.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2286976 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
S2 WvPCR; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [254384 2012-11-08] (Wave Systems Corp. -> Wave Systems Corp.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3377904 2013-07-17] (Intel Corporation-Mobile Wireless Group -> Intel® Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aksdf; C:\Windows\system32\drivers\aksdf.sys [75648 2010-07-27] (Microsoft Windows Hardware Compatibility Publisher -> SafeNet Inc.)
R2 aksfridge; C:\Windows\system32\drivers\aksfridge.sys [131072 2010-09-27] (Microsoft Windows Hardware Compatibility Publisher -> SafeNet Inc.)
S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [53760 2009-03-13] (Microsoft Windows Hardware Compatibility Publisher -> Aladdin Knowledge Systems Ltd.)
S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [25344 2009-03-13] (Microsoft Windows Hardware Compatibility Publisher -> Aladdin Knowledge Systems Ltd.)
S3 ASPI; C:\Windows\SysWOW64\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed]
R3 CtClsFlt; C:\Windows\System32\DRIVERS\CtClsFlt.sys [176096 2010-09-11] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.)
R3 dcdbas; C:\Windows\System32\DRIVERS\dcdbas64.sys [39016 2012-09-23] (Dell Inc. -> Dell Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [219184 2013-10-25] (ESET, spol. s r.o. -> ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [185224 2013-09-09] (ESET, spol. s r.o. -> ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [155896 2013-09-09] (ESET, spol. s r.o. -> ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [147096 2013-09-09] (ESET, spol. s r.o. -> ESET)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-12] (Enigma Software Group USA, LLC -> )
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2017-04-11] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [94704 2014-01-31] (Future Technology Devices International Ltd -> FTDI Ltd.)
S3 FTSER2K; C:\Windows\System32\drivers\ftser2k.sys [86896 2014-01-31] (Future Technology Devices International Ltd -> FTDI Ltd.)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [318464 2009-03-13] (Microsoft Windows Hardware Compatibility Publisher -> Aladdin Knowledge Systems Ltd.)
S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (3am.com(Test) -> HTC, Corporation)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2017-04-11] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [190032 2016-04-04] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R3 STHDA; C:\Windows\System32\DRIVERS\stwrt64.sys [551936 2013-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [68208 2012-05-21] (STMicroelectronics -> STMicroelectronics)
R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [47072 2012-10-10] (Intel Wireless Display -> Windows (R) Win 7 DDK provider)
S1 vflt; C:\Windows\System32\DRIVERS\vfilter.sys [24064 2013-04-16] (Shrew Soft Inc) [File not signed]
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31824 2013-02-26] (VMware, Inc. -> VMware, Inc.)
S3 vnet; C:\Windows\System32\DRIVERS\virtualnet.sys [17408 2013-04-16] (Shrew Soft Inc) [File not signed]
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70296 2012-10-24] (VMware, Inc. -> VMware, Inc.)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64.sys [14464 2008-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
R3 XHCIPort; C:\Windows\System32\DRIVERS\XHCIPort.sys [188896 2012-10-10] (Intel Wireless Display -> Windows (R) Win 7 DDK provider)
S3 RHDISK_AMD64; \??\E:\_rohos\RHDISK_AMD64.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-06-01 16:07 - 2020-06-01 16:09 - 000050046 _____ C:\Users\Marsal\Desktop\FRST.txt
2020-06-01 16:07 - 2020-06-01 16:09 - 000000000 ____D C:\FRST
2020-06-01 16:05 - 2020-06-01 16:05 - 002289152 _____ (Farbar) C:\Users\Marsal\Desktop\FRST64.exe
2020-06-01 15:52 - 2020-06-01 15:52 - 000003134 _____ C:\Windows\system32\Tasks\{D6842B4B-4CEF-46FF-88CE-2406810A73E4}
2020-06-01 15:14 - 2020-06-01 15:14 - 000000000 ____D C:\Users\Eng_TBII\AppData\Roaming\audacity
2020-06-01 15:14 - 2020-06-01 15:14 - 000000000 ____D C:\Users\Eng_TBII\AppData\Local\Audacity
2020-05-29 06:29 - 2020-05-29 06:29 - 000089495 _____ C:\Základní škola, Znojmo, náměstí Republiky 9_V1.pdf
2020-05-26 18:59 - 2020-05-26 18:59 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2020-05-25 20:19 - 2020-05-25 20:19 - 000000000 _____ C:\Windows\invcol.tmp
2020-05-24 13:12 - 2020-05-24 13:12 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\ProcessKO
2020-05-24 09:27 - 2020-06-01 16:08 - 000005014 _____ C:\Windows\system32\Tasks\WSCEAA
2020-05-23 19:02 - 2020-05-23 19:02 - 000001016 _____ C:\Users\Marsal\Desktop\IrfanView 64.lnk
2020-05-23 19:01 - 2020-05-23 19:01 - 000000000 ____D C:\Program Files\IrfanView
2020-05-23 12:18 - 2020-05-23 18:18 - 000001740 _____ C:\Users\Marsal\Desktop\MPC-HC x64.lnk
2020-05-23 12:18 - 2020-05-23 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
2020-05-23 12:18 - 2020-05-23 12:18 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\MPC-HC
2020-05-23 12:17 - 2020-05-23 18:18 - 000000000 ____D C:\Program Files\MPC-HC
2020-05-23 10:40 - 2020-05-23 10:40 - 519571494 _____ C:\Temna stranka lodni dopravy 2016.avi
2020-05-23 07:12 - 2020-05-31 13:17 - 000000000 ____D C:\SHROMAZDENI
2020-05-12 07:34 - 2020-05-12 07:34 - 000000969 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk
2020-05-12 07:34 - 2020-05-12 07:34 - 000000957 _____ C:\Users\Public\Desktop\TeamViewer.lnk
2020-05-12 07:34 - 2020-05-12 07:34 - 000000957 _____ C:\ProgramData\Desktop\TeamViewer.lnk
2020-05-12 06:04 - 2020-05-12 14:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-05-11 06:01 - 2020-05-11 06:01 - 000000000 ____D C:\Windows\{7DA24A28-C923-41B7-A761-BD12300E8634}
2020-05-05 08:45 - 2020-05-05 08:58 - 000000000 ____D C:\Users\Marsal\AppData\Local\Bluestacks
2020-05-05 08:45 - 2020-05-05 08:50 - 000000000 ____D C:\Users\Public\BlueStacks
2020-05-02 17:13 - 2020-05-02 17:13 - 020385120 _____ (Famatech Corp. ) C:\Advanced_IP_Scanner_2.5.3850.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-06-01 16:07 - 2016-02-03 06:56 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15e3f4dd45b57.job
2020-06-01 16:07 - 2015-09-17 06:51 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0f104759fa69c.job
2020-06-01 16:07 - 2015-07-15 20:51 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0bf2f446dca70.job
2020-06-01 16:03 - 2016-11-18 14:55 - 000000000 ____D C:\Users\Marsal\AppData\LocalLow\Mozilla
2020-06-01 16:01 - 2015-12-04 07:02 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d12e50ffe99bcb.job
2020-06-01 16:01 - 2015-02-09 07:51 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0442c649ef45c.job
2020-06-01 15:59 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-06-01 15:59 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-06-01 15:58 - 2015-02-14 23:04 - 000000000 ____D C:\Program Files (x86)\Online TV
2020-06-01 15:57 - 2018-02-13 09:26 - 000692616 _____ C:\Windows\system32\perfh007.dat
2020-06-01 15:57 - 2018-02-13 09:26 - 000151114 _____ C:\Windows\system32\perfc007.dat
2020-06-01 15:57 - 2015-05-15 09:36 - 000000000 ____D C:\Program Files (x86)\OpenOffice 4
2020-06-01 15:57 - 2013-05-30 13:48 - 000673472 _____ C:\Windows\system32\perfh005.dat
2020-06-01 15:57 - 2013-05-30 13:48 - 000143602 _____ C:\Windows\system32\perfc005.dat
2020-06-01 15:57 - 2009-07-14 07:13 - 002435084 _____ C:\Windows\system32\PerfStringBackup.INI
2020-06-01 15:57 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2020-06-01 15:56 - 2016-05-11 06:02 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1ab39f5bc091d.job
2020-06-01 15:56 - 2015-08-29 15:02 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0e25af634f254.job
2020-06-01 15:56 - 2015-05-19 05:56 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d091e7d41a9630.job
2020-06-01 15:56 - 2014-11-18 07:45 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d002f2d42d6254.job
2020-06-01 15:52 - 2018-10-04 08:19 - 000000000 ____D C:\Windows\SysWOW64\QuickTime
2020-06-01 15:52 - 2018-10-04 08:19 - 000000000 ____D C:\Program Files (x86)\QuickTime
2020-06-01 15:51 - 2015-07-18 15:34 - 000000000 __SHD C:\Users\Marsal\IntelGraphicsProfiles
2020-06-01 15:51 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\registration
2020-06-01 15:50 - 2013-12-10 12:10 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2020-06-01 15:49 - 2018-10-04 08:19 - 000054156 ____H C:\Windows\QTFont.qfn
2020-06-01 15:49 - 2017-02-22 10:24 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-06-01 15:49 - 2016-05-11 06:02 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab39f59ce7e8.job
2020-06-01 15:49 - 2016-02-03 06:56 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e3f4dbed736.job
2020-06-01 15:49 - 2015-12-04 07:02 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12e50ffd0952d.job
2020-06-01 15:49 - 2015-09-17 06:51 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f10475820c0d.job
2020-06-01 15:49 - 2015-08-29 15:02 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e25af61709a4.job
2020-06-01 15:49 - 2015-07-15 20:51 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bf2f444cd475.job
2020-06-01 15:49 - 2015-05-19 05:56 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d091e7d3ff6caa.job
2020-06-01 15:49 - 2015-02-09 07:51 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0442c6483cad6.job
2020-06-01 15:49 - 2013-12-10 12:10 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2020-06-01 15:49 - 2013-05-30 16:41 - 000000000 ____D C:\ProgramData\VMware
2020-06-01 15:49 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-06-01 15:43 - 2013-09-20 06:41 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\VMware
2020-06-01 15:43 - 2013-09-20 06:41 - 000000000 ____D C:\Users\Marsal\AppData\Local\VMware
2020-06-01 15:42 - 2013-05-31 09:27 - 000000000 ____D C:\Program Files\Windows XP Mode
2020-06-01 15:38 - 2013-03-22 02:28 - 000000000 ___HD C:\Windows\system32\WLANProfiles
2020-06-01 15:37 - 2013-10-10 09:29 - 000000000 ____D C:\Program Files (x86)\UltraVNC
2020-06-01 15:33 - 2014-06-04 12:30 - 000000000 ____D C:\Users\Marsal\AppData\Local\CrashDumps
2020-06-01 15:28 - 2020-04-29 09:56 - 000000000 ____D C:\Program Files (x86)\Icecream Ebook Reader
2020-06-01 15:21 - 2013-05-31 15:48 - 000000000 ____D C:\Program Files (x86)\FreeCommander
2020-06-01 15:14 - 2016-06-08 11:20 - 000000000 ____D C:\Program Files (x86)\Audacity
2020-06-01 15:13 - 2013-03-22 02:16 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2020-06-01 15:13 - 2013-03-22 02:16 - 000000000 ____D C:\Windows\system32\Macromed
2020-06-01 15:11 - 2015-08-14 10:09 - 000000000 __SHD C:\Users\Eng_TBII\IntelGraphicsProfiles
2020-06-01 15:11 - 2013-04-08 12:23 - 000110096 _____ C:\Users\Eng_TBII\AppData\Local\GDIPFONTCACHEV1.DAT
2020-06-01 14:04 - 2015-10-26 21:06 - 000173274 _____ C:\Users\Marsal\Desktop\Nový textový dokument.txt
2020-05-31 18:35 - 2015-11-09 10:52 - 000000000 ____D C:\Temp2
2020-05-30 19:16 - 2014-06-26 10:40 - 000000000 ____D C:\Users\Marsal\AppData\Local\Deployment
2020-05-30 08:04 - 2019-10-10 22:33 - 000000000 ____D C:\Zaloha USB
2020-05-30 07:40 - 2015-04-01 17:35 - 000000000 ____D C:\Temp1
2020-05-29 10:09 - 2016-12-03 12:33 - 000000000 ____D C:\Temp
2020-05-27 06:36 - 2014-05-02 09:49 - 000015872 _____ C:\Users\Marsal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-05-26 18:59 - 2020-03-20 21:21 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Zoom
2020-05-25 11:32 - 2016-03-10 09:19 - 000000000 ____D C:\WinBox
2020-05-24 15:31 - 2013-10-17 13:44 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\TeamViewer
2020-05-24 11:40 - 2020-02-13 07:54 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Cryptomator
2020-05-24 11:37 - 2020-02-13 07:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cryptomator
2020-05-24 11:37 - 2020-02-13 07:49 - 000000000 ____D C:\Program Files\Cryptomator
2020-05-24 07:05 - 2019-01-24 14:54 - 000000000 ____D C:\Temp3
2020-05-23 19:02 - 2013-09-26 08:33 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2020-05-23 19:02 - 2013-09-26 08:33 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\IrfanView
2020-05-23 18:59 - 2017-05-24 14:20 - 000000000 ___RD C:\Users\Marsal\OneDrive
2020-05-23 17:11 - 2018-04-12 09:45 - 000000000 ____D C:\ProgramData\MaxSyncUp
2020-05-23 08:41 - 2019-03-25 19:32 - 000000000 ____D C:\Temp4
2020-05-23 07:03 - 2020-01-18 12:29 - 000000000 ____D C:\Temp9
2020-05-22 09:46 - 2013-09-19 11:52 - 000000000 ____D C:\Users\Marsal
2020-05-22 06:04 - 2013-07-19 10:13 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-05-21 11:41 - 2020-01-15 14:42 - 000000000 ____D C:\Temp7
2020-05-19 06:04 - 2017-07-25 08:14 - 000002317 _____ C:\Users\Marsal\Desktop\Google Chrome.lnk
2020-05-18 08:26 - 2013-07-19 11:05 - 000000000 ____D C:\Windows\system32\MRT
2020-05-18 08:19 - 2013-05-30 11:59 - 120636720 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2020-05-18 06:17 - 2020-03-30 14:51 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\WhatsApp
2020-05-18 06:17 - 2020-03-30 14:51 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2020-05-18 06:17 - 2020-03-30 14:51 - 000000000 ____D C:\Users\Marsal\AppData\Local\WhatsApp
2020-05-17 09:14 - 2020-01-16 13:29 - 000000000 ____D C:\Temp8
2020-05-16 17:18 - 2019-06-18 07:40 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\fontconfig
2020-05-13 05:56 - 2013-07-19 10:11 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-05-12 14:55 - 2009-07-14 06:45 - 000427760 _____ C:\Windows\system32\FNTCACHE.DAT
2020-05-12 09:33 - 2013-09-19 11:53 - 000110096 _____ C:\Users\Marsal\AppData\Local\GDIPFONTCACHEV1.DAT
2020-05-12 07:41 - 2015-10-13 13:08 - 000000000 ____D C:\Users\Marsal\AppData\Local\TeamViewer
2020-05-11 12:44 - 2014-06-19 11:19 - 000001057 _____ C:\Users\Public\Desktop\Rawet Studio.lnk
2020-05-11 12:44 - 2014-06-19 11:19 - 000001057 _____ C:\ProgramData\Desktop\Rawet Studio.lnk
2020-05-11 12:44 - 2014-06-19 11:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rawet Studio
2020-05-11 12:44 - 2014-06-19 11:19 - 000000000 ____D C:\Program Files (x86)\Rawet Studio
2020-05-07 06:12 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2020-05-05 06:20 - 2018-12-31 16:19 - 000000000 ____D C:\Vzum
2020-05-04 15:32 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2020-05-04 07:59 - 2009-07-14 07:08 - 000032616 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories ========
2019-06-18 07:43 - 2019-06-18 07:44 - 000002319 _____ () C:\Users\Marsal\AppData\Roaming\ASSDraw3.cfg
2020-05-01 08:35 - 2020-05-01 08:35 - 000000474 _____ () C:\Users\Marsal\AppData\Roaming\buttrc
2013-11-15 10:57 - 2013-11-15 10:57 - 000000130 _____ () C:\Users\Marsal\AppData\Roaming\hlsigset.log
2014-12-17 07:54 - 2018-03-01 10:17 - 000099384 _____ () C:\Users\Marsal\AppData\Roaming\inst.exe
2013-09-20 08:31 - 2014-04-07 08:24 - 000001725 _____ () C:\Users\Marsal\AppData\Roaming\mainhst.zgh
2014-12-17 07:54 - 2018-03-01 10:17 - 000007859 _____ () C:\Users\Marsal\AppData\Roaming\pcouffin.cat
2014-12-17 07:54 - 2018-03-01 10:17 - 000001167 _____ () C:\Users\Marsal\AppData\Roaming\pcouffin.inf
2014-12-17 07:54 - 2018-03-01 10:17 - 000000055 _____ () C:\Users\Marsal\AppData\Roaming\pcouffin.log
2014-12-17 07:54 - 2018-03-01 10:17 - 000082816 _____ (VSO Software) C:\Users\Marsal\AppData\Roaming\pcouffin.sys
2014-07-02 06:19 - 2019-04-15 22:00 - 000000600 _____ () C:\Users\Marsal\AppData\Roaming\winscp.rnd
2014-05-02 09:49 - 2020-05-27 06:36 - 000015872 _____ () C:\Users\Marsal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2019-10-10 11:34 - 2019-10-10 11:40 - 000000600 _____ () C:\Users\Marsal\AppData\Local\PUTTY.RND
2015-11-14 17:55 - 2015-11-14 17:55 - 000000017 _____ () C:\Users\Marsal\AppData\Local\resmon.resmoncfg
2015-11-28 21:53 - 2015-11-28 21:53 - 000000000 _____ () C:\Users\Marsal\AppData\Local\{AF216E47-AA6F-463E-89E2-FCA0A8233B35}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2020-05-28 10:52
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-05-2020 01
Ran by Marsal (administrator) on POHRS (Dell Inc. Latitude E6530) (01-06-2020 16:07:43)
Running from C:\Users\Marsal\Desktop
Loaded Profiles: Marsal
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\hapi64\pbadrvsvc.exe
() [File not signed] C:\Windows\SysWOW64\srvany.exe
(ActMask Group Co., Ltd -> ActMask Co.,Ltd - hxxp://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Group Co., Ltd -> ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe <2>
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidMonitorSvc.exe
(AuthenTec, Inc. -> Authentec Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Dell Inc -> Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
(ELDES UAB -> ) C:\Program Files\Common Files\Eldes\ELDES Service.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation-Mobile Wireless Group -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Maxim Deminov -> @MAX Software) C:\Program Files (x86)\MaxSyncUp\MaxSyncUp.exe
(Maxim Deminov -> @MAX Software) C:\Program Files (x86)\MaxSyncUp\msusvc.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <6>
(O2Micro Inc. -> O2Micro International) C:\Windows\System32\o2flash.exe
(O2Micro Inc. -> O2Micro.) C:\Windows\SysWOW64\SDIOAssist.exe
(SafeNet, Inc. -> SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Siemens AG) [File not signed] C:\Siemens_EA\TBII\EMII\BIN\prl.exe
(Siemens AG) [File not signed] C:\Siemens_EA\TBII\EMII\BIN\rmd.exe
(Softland SRL -> Microsoft) C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Wave Systems Corp. -> ) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
(Wave Systems Corp. -> Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
(Wave Systems Corp. -> Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
(Wave Systems Corp.) [File not signed] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [736552 2015-05-29] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
HKLM\...\Run: [TdmNotify] => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [370584 2012-11-09] (Wave Systems Corp. -> Wave Systems Corp.)
HKLM\...\Run: [DFEPApplication] => C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077432 2012-08-15] (Dell Inc. -> Dell Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4148664 2013-10-07] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4791024 2013-07-17] (Intel Corporation-Mobile Wireless Group -> Intel(R) Corporation)
HKLM\...\Run: [PrintDisp] => C:\Windows\system32\PrintDisp.exe [588936 2015-08-18] (ActMask Group Co., Ltd -> ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-10-16] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [462974 2011-12-16] (Creative Technology Ltd) [File not signed]
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [104528 2013-02-26] (VMware, Inc. -> VMware, Inc.)
HKLM-x32\...\Run: [TBII-PRELOADER] => C:\Siemens_EA\TBII\EMII\BIN\PRL.EXE [97280 2014-02-27] (Siemens AG) [File not signed]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [77824 2018-10-04] (Apple Computer, Inc.) [File not signed]
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133216 2017-03-23] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM\...\Windows x64\Print Processors\ActMask: C:\Windows\System32\spool\prtprocs\x64\ActPrint.dll [51336 2017-02-19] (ActMask Group Co., Ltd -> ActMask Co.,Ltd)
HKLM\...\Windows x64\Print Processors\HP1005PrintProc: C:\Windows\System32\spool\prtprocs\x64\HP1005PP.dll [65024 2013-04-01] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Windows x64\Print Processors\hpzpplhn: C:\Windows\System32\spool\prtprocs\x64\hpzpplhn.dll [99840 2008-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\HP1005LM: C:\Windows\system32\HP1005LM.DLL [178688 2013-04-01] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\novaPDF Port Monitor: C:\Windows\system32\novamn8.dll [18944 2016-12-16] (Softland) [File not signed]
HKLM\...\Print\Monitors\PDF-XChange V6 Printer Port Monitor (Lite): C:\Windows\system32\pxcpm5L.dll [150208 2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
HKLM\...\Print\Monitors\WSD Port: C:\Windows\system32\WSDMon.dll [224768 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.61\Installer\chrmstp.exe [2020-05-22] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\...\Authentication\Credential Providers: [{18CBEEAA-6708-41A1-9379-D08915333CF2}] -> C:\Program Files\Common Files\SPBA\provider.dll [2012-08-17] (AuthenTec, Inc. -> Authentec Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\\BtwCP.dll [2012-02-22] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{D28973E5-8630-41af-8831-50A15FEB396B}] -> C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll [2012-02-22] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
HKLM\Software\...\Authentication\Credential Provider Filters: [{AE583D93-8D1B-424F-9858-5623FB7824EE}] -> C:\Program Files\Common Files\SPBA\provider.dll [2012-08-17] (AuthenTec, Inc. -> Authentec Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-03-22]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
Startup: C:\Users\Eng_TBII\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
Startup: C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-03-22]
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.)
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {009BA484-6FA4-409E-928C-373BAF7AFF4E} - System32\Tasks\GoogleUpdateTaskMachineCore1d12e50ffd0952d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {00FB573A-5990-49FD-BBEB-50570EAAC154} - System32\Tasks\GoogleUpdateTaskMachineUA1d002f2d42d6254 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {095E7A76-8B84-4161-A1BF-99A75EFF7B9B} - System32\Tasks\GoogleUpdateTaskMachineCore1d0f10475820c0d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {0C40A0A5-D478-4A63-B215-EF22991645DD} - System32\Tasks\GoogleUpdateTaskMachineUA1d15e3f4dd45b57 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {0C82E3E5-CD05-461D-A916-7C745877714D} - System32\Tasks\{D5ABCAC2-019B-48CF-B60F-A8D3EC0BDC5C} => C:\Windows\system32\pcalua.exe -a C:\Users\Eng_TBII\Desktop\SALAMAND.EXE -d C:\Users\Eng_TBII\Desktop
Task: {0FB6737A-91AD-4071-9FC0-C010C75B2C84} - System32\Tasks\WinThruster64-Marsal-Startup => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION
Task: {18FD6ED4-2E3D-4C5D-A491-101DE862E032} - System32\Tasks\{DDFDF8E6-9FC9-41F1-A9AF-9A34AF3026BD} => C:\Windows\system32\pcalua.exe -a C:\Windows\iun6002.exe -c "E:\Portable\WYSIWYG Web Builder 10\irunin.ini" <==== ATTENTION
Task: {1975B8DF-3B3A-4688-9EDA-5B7F031528E7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {1975B8DF-3B3A-4688-9EDA-5B7F031528E7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {19FC6C74-65FD-40EE-8761-3DAEB32DF832} - System32\Tasks\GoogleUpdateTaskMachineCore1d0442c6483cad6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {1BE61B9A-7F11-42AE-80BF-368C94890E7A} - System32\Tasks\GoogleUpdateTaskMachineCore1d1eb5c84a67257 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {1F87D442-12D5-4A60-B685-9DA31E969E58} - System32\Tasks\GoogleUpdateTaskMachineUA1d091e7d41a9630 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {2A67726F-3893-427A-8250-BB44B3D4EEA8} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e3f4dbed736 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {3381E415-0A77-4CE0-942C-694F6D0AC7FA} - System32\Tasks\{D6842B4B-4CEF-46FF-88CE-2406810A73E4} => C:\Windows\system32\pcalua.exe -a C:\Windows\unvise32qt.exe -c C:\Windows\system32\QuickTime\Uninstall.log
Task: {35AFFA54-F29D-4CBB-97D1-500B293D36CC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {43E11D12-2102-426D-8EBE-B718E0FB43EB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {50065D99-36D9-4A1E-963F-41328AA996CF} - System32\Tasks\GoogleUpdateTaskMachineUA1d12e50ffe99bcb => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {52BEBEB5-FC96-4450-BC04-90F52E8549D4} - System32\Tasks\doPDF Update => C:\Program Files\Softland\novaPDF 8\Driver\UpdateApplication.exe [682408 2016-12-16] (Softland SRL -> )
Task: {61104FFA-67A1-4611-A529-E14D95770740} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {61104FFA-67A1-4611-A529-E14D95770740} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {6D6025F1-A47C-430D-B94E-174FECA78470} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(1): %windir%\system32\GWX\GWXUXWorker.exe -> /ScheduleUpgradeReminderTime
Task: {6D6025F1-A47C-430D-B94E-174FECA78470} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {7101F7DB-2222-448B-B463-C26870634176} - \SpyHunter4Startup -> No File <==== ATTENTION
Task: {8448F66F-5F55-4695-B7ED-4B299C9122BA} - System32\Tasks\GoogleUpdateTaskMachineUA1d0bf2f446dca70 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {8644D8AA-53DD-4FB7-9C14-16692C9A3203} - System32\Tasks\GoogleUpdateTaskMachineUA1d1eb5c84bc6ba9 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {964EC295-9A62-47FC-9582-7601E5EB54FD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {964EC295-9A62-47FC-9582-7601E5EB54FD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent
Task: {964EC295-9A62-47FC-9582-7601E5EB54FD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [358400 [358400 2016-05-20]] (Microsoft Windows -> Microsoft Corporation)
Task: {A6899650-D6AE-410A-9F1A-1CF5345FB6AA} - System32\Tasks\GoogleUpdateTaskMachineCore1d0bf2f444cd475 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {ABF29991-41D5-4248-AB94-F12FDBC1975F} - System32\Tasks\Ashampoo Privacy Protector Weekly Security Scan => C:\Program Files (x86)\Ashampoo\Ashampoo Privacy Protector\PrivacyProtector.exe
Task: {AD38CD45-93B1-4D32-8EC0-11B16EA7E1C8} - System32\Tasks\{4C24CC4B-EC99-4779-ABE4-E4E8277CDE60} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Altap Salamander\remove\remove.exe"
Task: {AE7FCAAB-F6D1-4852-9B39-9F354A60EE5D} - System32\Tasks\GoogleUpdateTaskMachineCore1d091e7d3ff6caa => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {BC48C21B-4F43-4D58-BF0D-D5676AC274F1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {C185CA7E-36F4-495C-88BD-8153675CD0E3} - System32\Tasks\GoogleUpdateTaskMachineUA1d0f104759fa69c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {C777EF2D-6D0E-4AD3-977D-48C583B82F73} - System32\Tasks\GoogleUpdateTaskMachineUA1d1ab39f5bc091d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {DE647C46-284E-4EC5-9A3D-5318FEBDD71B} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ab39f59ce7e8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {E5FAB1D4-4573-4487-BAA0-B8C24310AC5B} - System32\Tasks\GoogleUpdateTaskMachineUA1d0442c649ef45c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {E73A29F6-ACB6-4C99-B952-8FFC7ED50D88} - System32\Tasks\GoogleUpdateTaskMachineCore1d0e25af61709a4 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {EFA8B190-43B0-4D76-B6E9-5338D07FB661} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [855352 2016-02-19] (Intel(R) Trusted Connect Service -> Intel(R) Corporation)
Task: {FFFFA652-CABF-46FC-83C8-896E03FC9F94} - System32\Tasks\GoogleUpdateTaskMachineUA1d0e25af634f254 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0442c6483cad6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d091e7d3ff6caa.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bf2f444cd475.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e25af61709a4.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f10475820c0d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12e50ffd0952d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e3f4dbed736.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab39f59ce7e8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d002f2d42d6254.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0442c649ef45c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d091e7d41a9630.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0bf2f446dca70.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0e25af634f254.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0f104759fa69c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d12e50ffe99bcb.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15e3f4dd45b57.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1ab39f5bc091d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{05CC11B1-09F3-4C3D-BEB8-9A43A1940489}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
Tcpip\..\Interfaces\{13D67E57-6A65-4784-84E4-2F9931E10815}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{DF801C61-BF64-4798-AE02-C0F6FEE5BBAB}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,192.168.71.1,1]
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3879696279-2694623716-4221884656-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {3965D173-40FC-424F-9703-F831D32C8393} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {62694250-03A8-4440-96F1-3F6DC0B864AF} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... kSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&r ... {startPage}
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {7C791268-4AF8-4919-9304-07B755B8A557} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {923B92C4-B653-4002-8D98-F6A77810DEBD} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... kSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {B352A849-9513-44A9-B119-CED8E358CF4F} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {C0054516-41EE-4ABF-853D-3D301DC05C2A} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {C7851CF3-22CC-4B91-8736-07D868E1B4CE} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... kSearch_12
SearchScopes: HKU\S-1-5-21-3879696279-2694623716-4221884656-1006 -> {D70ACB0B-5D3F-43EB-94CA-5127B0180311} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/CZ/Core/Player/2020PlayerAX_IKEA_Win32.cab
FireFox:
========
FF DefaultProfile: 2wmfnqiv.default-1441599875080
FF ProfilePath: C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 [2020-06-01]
FF DownloadDir: C:
FF NewTab: Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 -> C:\\ProgramData\\Medlights\\ff.NT
FF Notifications: Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 -> hxxps://dashboard.zopim.com; hxxp://dashboard.zopim.com; hxxp://dashboard.smartsupp.com; hxxps://dashboard.smartsupp.com; hxxps://calendar.google.com; hxxps://web.whatsapp.com; hxxps://sofe.ladesk.com; hxxps://www.exasoft.cz; hxxps://www.smartsupp.com; hxxps://forum.chronomag.cz
FF NewTabOverride: Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080 -> Disabled: {ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: (Firebug) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\firebug@software.joehewitt.com.xpi [2017-03-01] [Legacy]
FF Extension: (MEGA) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\firefox@mega.co.nz.xpi [2020-05-30] [UpdateUrl:hxxps://mega.nz/firefox-web-extension-updates.json]
FF Extension: (Youtube to MP3 Plugin) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\flv2mp3@hotger.com.xpi [2017-11-17]
FF Extension: (SafeInCloud Password Manager) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\info@safe-in-cloud.com.xpi [2020-05-30]
FF Extension: (Add to Wunderlist) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\jid1-3gu11JeYBiIuJA@jetpack.xpi [2017-03-29] [Legacy]
FF Extension: (To Google Translate) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2019-11-25]
FF Extension: (Seznam doplněk - Esko) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\sko-extension@firma.seznam.cz.xpi [2020-04-28]
FF Extension: (Session Manager) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2017-01-31] [Legacy]
FF Extension: (ePub Reader) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{323353ee-cfbd-4178-9676-85566d98c8b1}.xpi [2020-01-30]
FF Extension: (gtranslate) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi [2016-11-30] [Legacy]
FF Extension: (Zoom Scheduler) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{bf855ead-d7c3-4c7b-9f88-9a7e75c0efdf}.xpi [2020-04-30]
FF Extension: (No Name) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-04-01]
FF Extension: (Seznam doplněk - Email) - C:\Users\Marsal\AppData\Roaming\Mozilla\Firefox\Profiles\2wmfnqiv.default-1441599875080\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}.xpi [2020-04-28]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Extension: (ESET Endpoint Security Extension) - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird [2014-07-17] [Legacy] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=1.1.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: JFGuide -> C:\Program Files (x86)\NetSurveillance\CMS\npGuide.dll [2019-07-16] () [File not signed]
FF Plugin-x32: JFWeb -> C:\Program Files (x86)\NetSurveillance\CMS\npWebPlugin.dll [2019-07-16] () [File not signed]
FF Plugin-x32: Web Components -> C:\Program Files (x86)\Web Components\npWebVideoPlugin.dll [2018-12-10] (HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3879696279-2694623716-4221884656-1006: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-02-07] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3879696279-2694623716-4221884656-1006: www.wansview.com/HYPlayer -> C:\Program Files (x86)\HYPlayer\npHYPlayer.dll [No File]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default [2020-06-01]
CHR Notifications: Default -> hxxps://calendar.google.com
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxps://isearch.avg.co ... 2012-09-28 09:40:19&v=12.2.5.34&sap=hp","hxxp://www.google.com"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Dokumenty) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Disk Google) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
CHR Extension: (SEO META in 1 CLICK) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjogjfinolnhfhkbipphpdlldadpnmhc [2019-07-23]
CHR Extension: (YouTube) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-27]
CHR Extension: (History 2) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\cahejgbbfgmlmjgdjlibphdjeldhagkp [2017-05-07]
CHR Extension: (Wondershare Video Converter Ultimate) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp [2017-09-02]
CHR Extension: (Aliexpress SuperStar česky, Historie cen a koruny) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciclollkolafellcaolgccmfjldgpolo [2020-04-24]
CHR Extension: (Vyhledávání Google) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-06-01]
CHR Extension: (Snip it! button for eBay) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhaoojkpcgaobmnnphdpdokcgdiibblh [2019-02-10]
CHR Extension: (SafeInCloud Password Manager) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lchdigjbcmdgcfeijpfkpadacbijihjl [2020-04-24]
CHR Extension: (Rozšíření Google Keep pro Chrome) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2020-05-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
CHR Extension: (Simple EPUB Reader) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhbgcchcbdjdenibfmjofobklkkhofc [2017-06-07]
CHR Extension: (Downloader for Instagram™ + Direct Message) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpikmlhoaojbbmmpejnimiglejmboe [2020-05-19]
CHR Extension: (Gmail) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-04]
CHR Extension: (Chrome Media Router) - C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-05-23]
CHR Profile: C:\Users\Marsal\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-23]
CHR HKU\S-1-5-21-3879696279-2694623716-4221884656-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKU\S-1-5-21-3879696279-2694623716-4221884656-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [96000 2015-09-25] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation -> Microsoft Corporation)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [36544 2020-04-17] (Dell Inc -> )
R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280504 2012-08-15] (Dell Inc. -> Dell Inc.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [42048 2013-10-07] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [1025584 2013-10-07] (ESET, spol. s r.o. -> ESET)
R2 EldesService; C:\Program Files\Common Files\Eldes\ELDES Service.exe [201416 2018-08-01] (ELDES UAB -> )
R2 EmbassyService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [225720 2012-11-20] (Wave Systems Corp. -> )
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [191368 2013-10-07] (ESET, spol. s r.o. -> ESET)
R2 hasplms; C:\Windows\system32\hasplms.exe [4180576 2010-09-27] (SafeNet, Inc. -> SafeNet Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [317416 2018-09-24] (Intel Corporation -> Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [209184 2016-05-10] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MaxSyncUpService; C:\Program Files (x86)\MaxSyncUp\msusvc.exe [2340912 2018-05-07] (Maxim Deminov -> @MAX Software)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-07-17] (Intel Corporation-Mobile Wireless Group -> )
R2 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [51112 2016-12-16] (Softland SRL -> Microsoft)
R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro Inc. -> O2Micro International)
R2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] () [File not signed]
S2 OracleServiceTBII; C:\Siemens_EA\TBII\DB\ORANT\BIN\oracle.exe [156133376 2013-10-09] (Oracle Corporation) [File not signed]
S2 OracleTBIIORA11R2TNSListener; C:\Siemens_EA\TBII\DB\ORANT\BIN\TNSLSNR.EXE [552960 2013-10-08] (Oracle Corporation) [File not signed]
R2 PbaDrvSvc_x64; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\hapi64\pbadrvsvc.exe [20480 2012-11-23] () [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S2 tcsd_win32.exe; C:\Program Files (x86)\Security Innovation\SI TSS\bin\tcsd_win32.exe [1643520 2012-05-11] () [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13255184 2020-05-19] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [13242960 2013-02-26] (VMware, Inc. -> )
R2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1758720 2012-11-19] (Wave Systems Corp.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2286976 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
S2 WvPCR; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [254384 2012-11-08] (Wave Systems Corp. -> Wave Systems Corp.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3377904 2013-07-17] (Intel Corporation-Mobile Wireless Group -> Intel® Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aksdf; C:\Windows\system32\drivers\aksdf.sys [75648 2010-07-27] (Microsoft Windows Hardware Compatibility Publisher -> SafeNet Inc.)
R2 aksfridge; C:\Windows\system32\drivers\aksfridge.sys [131072 2010-09-27] (Microsoft Windows Hardware Compatibility Publisher -> SafeNet Inc.)
S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [53760 2009-03-13] (Microsoft Windows Hardware Compatibility Publisher -> Aladdin Knowledge Systems Ltd.)
S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [25344 2009-03-13] (Microsoft Windows Hardware Compatibility Publisher -> Aladdin Knowledge Systems Ltd.)
S3 ASPI; C:\Windows\SysWOW64\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed]
R3 CtClsFlt; C:\Windows\System32\DRIVERS\CtClsFlt.sys [176096 2010-09-11] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.)
R3 dcdbas; C:\Windows\System32\DRIVERS\dcdbas64.sys [39016 2012-09-23] (Dell Inc. -> Dell Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [219184 2013-10-25] (ESET, spol. s r.o. -> ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [185224 2013-09-09] (ESET, spol. s r.o. -> ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [155896 2013-09-09] (ESET, spol. s r.o. -> ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [147096 2013-09-09] (ESET, spol. s r.o. -> ESET)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-12] (Enigma Software Group USA, LLC -> )
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2017-04-11] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [94704 2014-01-31] (Future Technology Devices International Ltd -> FTDI Ltd.)
S3 FTSER2K; C:\Windows\System32\drivers\ftser2k.sys [86896 2014-01-31] (Future Technology Devices International Ltd -> FTDI Ltd.)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [318464 2009-03-13] (Microsoft Windows Hardware Compatibility Publisher -> Aladdin Knowledge Systems Ltd.)
S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (3am.com(Test) -> HTC, Corporation)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2017-04-11] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [190032 2016-04-04] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R3 STHDA; C:\Windows\System32\DRIVERS\stwrt64.sys [551936 2013-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [68208 2012-05-21] (STMicroelectronics -> STMicroelectronics)
R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [47072 2012-10-10] (Intel Wireless Display -> Windows (R) Win 7 DDK provider)
S1 vflt; C:\Windows\System32\DRIVERS\vfilter.sys [24064 2013-04-16] (Shrew Soft Inc) [File not signed]
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31824 2013-02-26] (VMware, Inc. -> VMware, Inc.)
S3 vnet; C:\Windows\System32\DRIVERS\virtualnet.sys [17408 2013-04-16] (Shrew Soft Inc) [File not signed]
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70296 2012-10-24] (VMware, Inc. -> VMware, Inc.)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64.sys [14464 2008-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
R3 XHCIPort; C:\Windows\System32\DRIVERS\XHCIPort.sys [188896 2012-10-10] (Intel Wireless Display -> Windows (R) Win 7 DDK provider)
S3 RHDISK_AMD64; \??\E:\_rohos\RHDISK_AMD64.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-06-01 16:07 - 2020-06-01 16:09 - 000050046 _____ C:\Users\Marsal\Desktop\FRST.txt
2020-06-01 16:07 - 2020-06-01 16:09 - 000000000 ____D C:\FRST
2020-06-01 16:05 - 2020-06-01 16:05 - 002289152 _____ (Farbar) C:\Users\Marsal\Desktop\FRST64.exe
2020-06-01 15:52 - 2020-06-01 15:52 - 000003134 _____ C:\Windows\system32\Tasks\{D6842B4B-4CEF-46FF-88CE-2406810A73E4}
2020-06-01 15:14 - 2020-06-01 15:14 - 000000000 ____D C:\Users\Eng_TBII\AppData\Roaming\audacity
2020-06-01 15:14 - 2020-06-01 15:14 - 000000000 ____D C:\Users\Eng_TBII\AppData\Local\Audacity
2020-05-29 06:29 - 2020-05-29 06:29 - 000089495 _____ C:\Základní škola, Znojmo, náměstí Republiky 9_V1.pdf
2020-05-26 18:59 - 2020-05-26 18:59 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2020-05-25 20:19 - 2020-05-25 20:19 - 000000000 _____ C:\Windows\invcol.tmp
2020-05-24 13:12 - 2020-05-24 13:12 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\ProcessKO
2020-05-24 09:27 - 2020-06-01 16:08 - 000005014 _____ C:\Windows\system32\Tasks\WSCEAA
2020-05-23 19:02 - 2020-05-23 19:02 - 000001016 _____ C:\Users\Marsal\Desktop\IrfanView 64.lnk
2020-05-23 19:01 - 2020-05-23 19:01 - 000000000 ____D C:\Program Files\IrfanView
2020-05-23 12:18 - 2020-05-23 18:18 - 000001740 _____ C:\Users\Marsal\Desktop\MPC-HC x64.lnk
2020-05-23 12:18 - 2020-05-23 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
2020-05-23 12:18 - 2020-05-23 12:18 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\MPC-HC
2020-05-23 12:17 - 2020-05-23 18:18 - 000000000 ____D C:\Program Files\MPC-HC
2020-05-23 10:40 - 2020-05-23 10:40 - 519571494 _____ C:\Temna stranka lodni dopravy 2016.avi
2020-05-23 07:12 - 2020-05-31 13:17 - 000000000 ____D C:\SHROMAZDENI
2020-05-12 07:34 - 2020-05-12 07:34 - 000000969 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk
2020-05-12 07:34 - 2020-05-12 07:34 - 000000957 _____ C:\Users\Public\Desktop\TeamViewer.lnk
2020-05-12 07:34 - 2020-05-12 07:34 - 000000957 _____ C:\ProgramData\Desktop\TeamViewer.lnk
2020-05-12 06:04 - 2020-05-12 14:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-05-11 06:01 - 2020-05-11 06:01 - 000000000 ____D C:\Windows\{7DA24A28-C923-41B7-A761-BD12300E8634}
2020-05-05 08:45 - 2020-05-05 08:58 - 000000000 ____D C:\Users\Marsal\AppData\Local\Bluestacks
2020-05-05 08:45 - 2020-05-05 08:50 - 000000000 ____D C:\Users\Public\BlueStacks
2020-05-02 17:13 - 2020-05-02 17:13 - 020385120 _____ (Famatech Corp. ) C:\Advanced_IP_Scanner_2.5.3850.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-06-01 16:07 - 2016-02-03 06:56 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15e3f4dd45b57.job
2020-06-01 16:07 - 2015-09-17 06:51 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0f104759fa69c.job
2020-06-01 16:07 - 2015-07-15 20:51 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0bf2f446dca70.job
2020-06-01 16:03 - 2016-11-18 14:55 - 000000000 ____D C:\Users\Marsal\AppData\LocalLow\Mozilla
2020-06-01 16:01 - 2015-12-04 07:02 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d12e50ffe99bcb.job
2020-06-01 16:01 - 2015-02-09 07:51 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0442c649ef45c.job
2020-06-01 15:59 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-06-01 15:59 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-06-01 15:58 - 2015-02-14 23:04 - 000000000 ____D C:\Program Files (x86)\Online TV
2020-06-01 15:57 - 2018-02-13 09:26 - 000692616 _____ C:\Windows\system32\perfh007.dat
2020-06-01 15:57 - 2018-02-13 09:26 - 000151114 _____ C:\Windows\system32\perfc007.dat
2020-06-01 15:57 - 2015-05-15 09:36 - 000000000 ____D C:\Program Files (x86)\OpenOffice 4
2020-06-01 15:57 - 2013-05-30 13:48 - 000673472 _____ C:\Windows\system32\perfh005.dat
2020-06-01 15:57 - 2013-05-30 13:48 - 000143602 _____ C:\Windows\system32\perfc005.dat
2020-06-01 15:57 - 2009-07-14 07:13 - 002435084 _____ C:\Windows\system32\PerfStringBackup.INI
2020-06-01 15:57 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2020-06-01 15:56 - 2016-05-11 06:02 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1ab39f5bc091d.job
2020-06-01 15:56 - 2015-08-29 15:02 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0e25af634f254.job
2020-06-01 15:56 - 2015-05-19 05:56 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d091e7d41a9630.job
2020-06-01 15:56 - 2014-11-18 07:45 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d002f2d42d6254.job
2020-06-01 15:52 - 2018-10-04 08:19 - 000000000 ____D C:\Windows\SysWOW64\QuickTime
2020-06-01 15:52 - 2018-10-04 08:19 - 000000000 ____D C:\Program Files (x86)\QuickTime
2020-06-01 15:51 - 2015-07-18 15:34 - 000000000 __SHD C:\Users\Marsal\IntelGraphicsProfiles
2020-06-01 15:51 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\registration
2020-06-01 15:50 - 2013-12-10 12:10 - 000000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2020-06-01 15:49 - 2018-10-04 08:19 - 000054156 ____H C:\Windows\QTFont.qfn
2020-06-01 15:49 - 2017-02-22 10:24 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-06-01 15:49 - 2016-05-11 06:02 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab39f59ce7e8.job
2020-06-01 15:49 - 2016-02-03 06:56 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e3f4dbed736.job
2020-06-01 15:49 - 2015-12-04 07:02 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12e50ffd0952d.job
2020-06-01 15:49 - 2015-09-17 06:51 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f10475820c0d.job
2020-06-01 15:49 - 2015-08-29 15:02 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e25af61709a4.job
2020-06-01 15:49 - 2015-07-15 20:51 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bf2f444cd475.job
2020-06-01 15:49 - 2015-05-19 05:56 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d091e7d3ff6caa.job
2020-06-01 15:49 - 2015-02-09 07:51 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0442c6483cad6.job
2020-06-01 15:49 - 2013-12-10 12:10 - 000000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2020-06-01 15:49 - 2013-05-30 16:41 - 000000000 ____D C:\ProgramData\VMware
2020-06-01 15:49 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-06-01 15:43 - 2013-09-20 06:41 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\VMware
2020-06-01 15:43 - 2013-09-20 06:41 - 000000000 ____D C:\Users\Marsal\AppData\Local\VMware
2020-06-01 15:42 - 2013-05-31 09:27 - 000000000 ____D C:\Program Files\Windows XP Mode
2020-06-01 15:38 - 2013-03-22 02:28 - 000000000 ___HD C:\Windows\system32\WLANProfiles
2020-06-01 15:37 - 2013-10-10 09:29 - 000000000 ____D C:\Program Files (x86)\UltraVNC
2020-06-01 15:33 - 2014-06-04 12:30 - 000000000 ____D C:\Users\Marsal\AppData\Local\CrashDumps
2020-06-01 15:28 - 2020-04-29 09:56 - 000000000 ____D C:\Program Files (x86)\Icecream Ebook Reader
2020-06-01 15:21 - 2013-05-31 15:48 - 000000000 ____D C:\Program Files (x86)\FreeCommander
2020-06-01 15:14 - 2016-06-08 11:20 - 000000000 ____D C:\Program Files (x86)\Audacity
2020-06-01 15:13 - 2013-03-22 02:16 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2020-06-01 15:13 - 2013-03-22 02:16 - 000000000 ____D C:\Windows\system32\Macromed
2020-06-01 15:11 - 2015-08-14 10:09 - 000000000 __SHD C:\Users\Eng_TBII\IntelGraphicsProfiles
2020-06-01 15:11 - 2013-04-08 12:23 - 000110096 _____ C:\Users\Eng_TBII\AppData\Local\GDIPFONTCACHEV1.DAT
2020-06-01 14:04 - 2015-10-26 21:06 - 000173274 _____ C:\Users\Marsal\Desktop\Nový textový dokument.txt
2020-05-31 18:35 - 2015-11-09 10:52 - 000000000 ____D C:\Temp2
2020-05-30 19:16 - 2014-06-26 10:40 - 000000000 ____D C:\Users\Marsal\AppData\Local\Deployment
2020-05-30 08:04 - 2019-10-10 22:33 - 000000000 ____D C:\Zaloha USB
2020-05-30 07:40 - 2015-04-01 17:35 - 000000000 ____D C:\Temp1
2020-05-29 10:09 - 2016-12-03 12:33 - 000000000 ____D C:\Temp
2020-05-27 06:36 - 2014-05-02 09:49 - 000015872 _____ C:\Users\Marsal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-05-26 18:59 - 2020-03-20 21:21 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Zoom
2020-05-25 11:32 - 2016-03-10 09:19 - 000000000 ____D C:\WinBox
2020-05-24 15:31 - 2013-10-17 13:44 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\TeamViewer
2020-05-24 11:40 - 2020-02-13 07:54 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Cryptomator
2020-05-24 11:37 - 2020-02-13 07:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cryptomator
2020-05-24 11:37 - 2020-02-13 07:49 - 000000000 ____D C:\Program Files\Cryptomator
2020-05-24 07:05 - 2019-01-24 14:54 - 000000000 ____D C:\Temp3
2020-05-23 19:02 - 2013-09-26 08:33 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2020-05-23 19:02 - 2013-09-26 08:33 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\IrfanView
2020-05-23 18:59 - 2017-05-24 14:20 - 000000000 ___RD C:\Users\Marsal\OneDrive
2020-05-23 17:11 - 2018-04-12 09:45 - 000000000 ____D C:\ProgramData\MaxSyncUp
2020-05-23 08:41 - 2019-03-25 19:32 - 000000000 ____D C:\Temp4
2020-05-23 07:03 - 2020-01-18 12:29 - 000000000 ____D C:\Temp9
2020-05-22 09:46 - 2013-09-19 11:52 - 000000000 ____D C:\Users\Marsal
2020-05-22 06:04 - 2013-07-19 10:13 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-05-21 11:41 - 2020-01-15 14:42 - 000000000 ____D C:\Temp7
2020-05-19 06:04 - 2017-07-25 08:14 - 000002317 _____ C:\Users\Marsal\Desktop\Google Chrome.lnk
2020-05-18 08:26 - 2013-07-19 11:05 - 000000000 ____D C:\Windows\system32\MRT
2020-05-18 08:19 - 2013-05-30 11:59 - 120636720 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2020-05-18 06:17 - 2020-03-30 14:51 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\WhatsApp
2020-05-18 06:17 - 2020-03-30 14:51 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2020-05-18 06:17 - 2020-03-30 14:51 - 000000000 ____D C:\Users\Marsal\AppData\Local\WhatsApp
2020-05-17 09:14 - 2020-01-16 13:29 - 000000000 ____D C:\Temp8
2020-05-16 17:18 - 2019-06-18 07:40 - 000000000 ____D C:\Users\Marsal\AppData\Roaming\fontconfig
2020-05-13 05:56 - 2013-07-19 10:11 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-05-12 14:55 - 2009-07-14 06:45 - 000427760 _____ C:\Windows\system32\FNTCACHE.DAT
2020-05-12 09:33 - 2013-09-19 11:53 - 000110096 _____ C:\Users\Marsal\AppData\Local\GDIPFONTCACHEV1.DAT
2020-05-12 07:41 - 2015-10-13 13:08 - 000000000 ____D C:\Users\Marsal\AppData\Local\TeamViewer
2020-05-11 12:44 - 2014-06-19 11:19 - 000001057 _____ C:\Users\Public\Desktop\Rawet Studio.lnk
2020-05-11 12:44 - 2014-06-19 11:19 - 000001057 _____ C:\ProgramData\Desktop\Rawet Studio.lnk
2020-05-11 12:44 - 2014-06-19 11:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rawet Studio
2020-05-11 12:44 - 2014-06-19 11:19 - 000000000 ____D C:\Program Files (x86)\Rawet Studio
2020-05-07 06:12 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2020-05-05 06:20 - 2018-12-31 16:19 - 000000000 ____D C:\Vzum
2020-05-04 15:32 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2020-05-04 07:59 - 2009-07-14 07:08 - 000032616 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories ========
2019-06-18 07:43 - 2019-06-18 07:44 - 000002319 _____ () C:\Users\Marsal\AppData\Roaming\ASSDraw3.cfg
2020-05-01 08:35 - 2020-05-01 08:35 - 000000474 _____ () C:\Users\Marsal\AppData\Roaming\buttrc
2013-11-15 10:57 - 2013-11-15 10:57 - 000000130 _____ () C:\Users\Marsal\AppData\Roaming\hlsigset.log
2014-12-17 07:54 - 2018-03-01 10:17 - 000099384 _____ () C:\Users\Marsal\AppData\Roaming\inst.exe
2013-09-20 08:31 - 2014-04-07 08:24 - 000001725 _____ () C:\Users\Marsal\AppData\Roaming\mainhst.zgh
2014-12-17 07:54 - 2018-03-01 10:17 - 000007859 _____ () C:\Users\Marsal\AppData\Roaming\pcouffin.cat
2014-12-17 07:54 - 2018-03-01 10:17 - 000001167 _____ () C:\Users\Marsal\AppData\Roaming\pcouffin.inf
2014-12-17 07:54 - 2018-03-01 10:17 - 000000055 _____ () C:\Users\Marsal\AppData\Roaming\pcouffin.log
2014-12-17 07:54 - 2018-03-01 10:17 - 000082816 _____ (VSO Software) C:\Users\Marsal\AppData\Roaming\pcouffin.sys
2014-07-02 06:19 - 2019-04-15 22:00 - 000000600 _____ () C:\Users\Marsal\AppData\Roaming\winscp.rnd
2014-05-02 09:49 - 2020-05-27 06:36 - 000015872 _____ () C:\Users\Marsal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2019-10-10 11:34 - 2019-10-10 11:40 - 000000600 _____ () C:\Users\Marsal\AppData\Local\PUTTY.RND
2015-11-14 17:55 - 2015-11-14 17:55 - 000000017 _____ () C:\Users\Marsal\AppData\Local\resmon.resmoncfg
2015-11-28 21:53 - 2015-11-28 21:53 - 000000000 _____ () C:\Users\Marsal\AppData\Local\{AF216E47-AA6F-463E-89E2-FCA0A8233B35}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2020-05-28 10:52
==================== End of FRST.txt ========================