Notebook se přehřívá
Napsal: 17 lis 2020 18:25
Dobrý den,
ráda bych poprosila o pomoc. V poslední době se mi při sledování filmů ( ale i při jiných činnostech, např. při práci s gimpem) začne přehřívat notebook a chlazení jede nepřetržitě a velmi hlasitě, jako když startuje dron.
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-11-2020
Ran by Líba (administrator) on LÍBA (HP HP Laptop 14-bp1xx) (17-11-2020 18:02:06)
Running from C:\Users\croft\Downloads
Loaded Profiles: Líba
Platform: Windows 10 Home Version 1909 18363.1139 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <58>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\hpservice.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHeciSvc.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [ACUW10EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\acdIDInTouch2.exe [2157000 2017-04-21] (ACD Systems International -> ACD Systems)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3674720 2018-05-11] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-10-29] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5866032 2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [ACDSeeCommanderUltimate10] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\ACDSeeCommanderUltimate10.exe [3427272 2017-04-25] (ACD Systems International -> )
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5491248 2020-10-22] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [29271224 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\...\Windows x64\Print Processors\hpcpp101: C:\Windows\System32\spool\prtprocs\x64\hpcpp101.dll [323584 2010-09-23] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\HP C411 Status Monitor: C:\WINDOWS\system32\hpinkstsC411LM.dll [333496 2013-02-04] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-12] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08393777-2384-440D-91E4-AEBC7CB6ED0A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24770744 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3321AC99-6979-4ADA-B63C-90A8469281F4} - System32\Tasks\GoogleUpdateTaskMachineCore1d5ff7dc8e0a443 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {4DC24594-1BA1-45EC-9939-FFEBCD1CAD3B} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3723532541-349634963-3060968088-500 => C:\Users\croft\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {6821FE11-081E-4D55-8806-9D4B3DEC6A8C} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {892F5E2F-A0EC-4EBB-AFC1-CE247EE87C0E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
Task: {989B7C29-748C-483A-898E-12FDE1FE5C06} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {B4EF7188-3BC3-47C3-A0CF-8312A44C8780} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C23CA36A-F7C9-4E42-9761-4A7AE2A2EAC4} - System32\Tasks\GoogleUpdateTaskMachineUA1d57dbef5a66ad0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {C71BBFD2-11D4-4C98-BE85-499A63738AE6} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269296 2018-10-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {C791C6D2-BA93-4234-AF14-816A47B4DE09} - System32\Tasks\GoogleUpdateTaskMachineCore1d57dbef58d7204 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {CA125255-6F8A-48EF-BD5B-4A8AF0C5121B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {D07DA521-5711-4294-B45F-9112A1BABCDD} - System32\Tasks\GoogleUpdateTaskMachineUA1d5ff7dc90708cf => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {DCA8ABD7-A530-428C-B2BA-DE5250B23511} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [660688 2020-11-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {DDB512BA-0014-491C-A822-3E5B7C2B1542} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61112 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {DEBB26FF-7B21-4D1E-9658-B4A2F3DFE592} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {FACE49CD-51CC-4B22-860A-013ED31E0D0B} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [68280 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.38 213.46.172.39
Tcpip\..\Interfaces\{01d9789d-5705-45b7-962a-a2adffa4a1ce}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{0cee5351-1667-498a-8c34-0a45e0c35c49}: [DhcpNameServer] 213.46.172.38 213.46.172.39
Edge:
======
DownloadDir: C:\Users\croft\Downloads
Edge DefaultProfile: Default
Edge Profile: C:\Users\croft\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-05]
FireFox:
========
FF DefaultProfile: 8yk82u7g.default
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\0blfb8qd.default-release-1 [2020-11-05]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\8yk82u7g.default [2020-01-22]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release [2020-11-17]
FF Extension: (Video DownloadHelper) - C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-08-04]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-11-15]
Chrome:
=======
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default [2020-11-17]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://cs.nex-software.com; hxxps://dev1security.blogspot.com; hxxps://dp32.ru; hxxps://drive.google.com; hxxps://et.piratihk.cz; hxxps://m.facebook.com; hxxps://mrak.pirati.cz; hxxps://trycracksoftware.com; hxxps://upload.facebook.com; hxxps://vk.com; hxxps://www.dreamstime.com; hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.reddit.com; hxxps://www.viry.cz; hxxps://www.vitalia.cz; hxxps://www.wondershare.com; hxxps://zulip.pirati.cz
CHR NewTab: Default -> Active:"chrome-extension://llaficoajjainaijghjlofdfmbjpebpa/newtab.html"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Prezentace) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-09]
CHR Extension: (Dokumenty) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-09]
CHR Extension: (Disk Google) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-22]
CHR Extension: (YouTube) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-09]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-09-11]
CHR Extension: (Tabulky) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-16]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2020-09-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Switch to Classic design on Facebook™) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\oancckmjgaoejmbedngcoiakblhacbog [2020-11-15]
CHR Extension: (Video & Audio Downloader) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchlfebelfohhojoomlngjbkcjponfha [2020-03-19]
CHR Extension: (Gmail) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-15]
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\System Profile [2020-11-05]
CHR HKU\S-1-5-21-3723532541-349634963-3060968088-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1369432 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-19] (Malwarebytes Inc -> Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\NisSrv.exe [2372048 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe [128376 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [493792 2017-10-24] (Wondershare Technology Co.,Ltd -> Wondershare)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R0 C981D415; C:\WINDOWS\System32\drivers\C981D415.sys [478392 2020-08-06] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47160 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-27] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-27] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-27] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-27] (ESET, spol. s r.o. -> ESET)
S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-10-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [428264 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [69864 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35392 2020-06-08] (HP Inc. -> HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:02 - 2020-11-17 18:04 - 000021958 _____ C:\Users\croft\Downloads\FRST.txt
2020-11-17 17:59 - 2020-11-17 17:59 - 002294784 _____ (Farbar) C:\Users\croft\Downloads\FRST64.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-11-09 09:12 - 2020-11-09 09:12 - 003648128 _____ C:\Users\croft\Downloads\ratzfatz-muetze-in-vielen-varianten-gr-39-bis-60.zip
2020-11-09 09:12 - 2019-10-28 15:23 - 004286813 _____ C:\Users\croft\Downloads\Anleitung_RatzFatz_Textilsucht.pdf
2020-11-09 09:12 - 2019-10-28 15:23 - 000152420 _____ C:\Users\croft\Downloads\Schnittmuster RatzFatz Muetze.pdf
2020-11-06 20:12 - 2020-11-06 20:12 - 000012756 _____ C:\Users\croft\Documents\adresy.xlsx
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ C:\Users\croft\AppData\Local\recently-used.xbel
2020-11-06 12:26 - 2020-11-06 12:26 - 000099723 _____ C:\Users\croft\Downloads\stanovy MS.pdf
2020-11-06 07:22 - 2020-11-06 07:22 - 000458853 ____H C:\Users\croft\Downloads\~WRL0004.tmp
2020-11-05 18:14 - 2020-11-05 18:14 - 000020282 _____ C:\Users\croft\Documents\cc_20201105_181449.reg
2020-11-03 13:08 - 2020-11-03 13:08 - 000579771 _____ C:\Users\croft\Downloads\Vítej_u_pirátů_královehradecky.pdf
2020-11-03 09:56 - 2020-11-03 09:56 - 000000000 ____D C:\Users\croft\AppData\Roaming\DataRecommendations
2020-11-03 09:55 - 2020-11-03 09:55 - 000000000 ____D C:\Users\croft\AppData\Local\Microsoft_Corporation
2020-11-02 17:53 - 2020-11-02 17:53 - 000408944 _____ C:\Users\croft\Downloads\damska-kapsa-do-svu.pdf
2020-11-02 12:55 - 2020-11-02 12:55 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-10-30 08:10 - 2017-12-29 14:52 - 208430445 _____ C:\Users\croft\Downloads\Earth - Den na zázračné planetě (2017) CZ dabing 4K HD(MOJEFILMY.XYZ).mkv
2020-10-25 17:54 - 2020-10-25 17:54 - 000310002 _____ C:\Users\croft\Downloads\201025_Shrnutí-voleb-pro-krajskou-schůzi.pdf
2020-10-24 14:49 - 2020-10-24 14:50 - 000000000 ____D C:\Users\croft\Downloads\z flešky
2020-10-24 14:40 - 2020-10-24 14:40 - 000042541 _____ C:\Users\croft\Downloads\proformaInvoice_2020011130.pdf
2020-10-22 23:42 - 2020-10-22 23:42 - 000065496 _____ (Adobe Systems Inc) C:\WINDOWS\system32\AdobePDF.dll
2020-10-22 23:42 - 2020-10-22 23:42 - 000036312 _____ (Adobe Systems Inc.) C:\WINDOWS\system32\AdobePDFUI.dll
2020-10-20 10:24 - 2020-10-20 10:24 - 002474437 _____ C:\Users\croft\Downloads\návod.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:03 - 2019-05-21 07:35 - 000000000 ____D C:\FRST
2020-11-17 18:02 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-17 17:07 - 2020-03-31 18:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-11-17 10:10 - 2020-03-31 18:22 - 001606106 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-17 10:10 - 2019-03-19 12:55 - 000685252 _____ C:\WINDOWS\system32\perfh005.dat
2020-11-17 10:10 - 2019-03-19 12:55 - 000137918 _____ C:\WINDOWS\system32\perfc005.dat
2020-11-17 10:10 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-11-17 09:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-16 15:43 - 2019-04-10 16:58 - 000000000 ____D C:\Users\Líba záloha
2020-11-16 15:07 - 2019-04-11 09:02 - 000000000 ____D C:\Users\Pracovní\Piráti
2020-11-16 15:02 - 2020-10-09 13:36 - 000000000 ____D C:\Users\croft\Downloads\inspirace
2020-11-16 15:01 - 2019-04-09 12:42 - 000000000 ____D C:\Users\croft\AppData\Local\Packages
2020-11-16 14:45 - 2019-10-13 08:29 - 000000000 ____D C:\Users\croft\AppData\Roaming\vlc
2020-11-15 14:12 - 2020-06-02 23:28 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-14 19:03 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-13 20:33 - 2019-10-29 11:16 - 000000000 ____D C:\Users\croft\AppData\LocalLow\Mozilla
2020-11-12 10:00 - 2019-04-09 12:45 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-11 12:19 - 2020-08-06 15:34 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-11-11 11:08 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-11 11:06 - 2019-03-08 15:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-11 11:03 - 2019-03-08 15:39 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-11-06 20:11 - 2019-04-09 21:08 - 000000000 ____D C:\Users\croft\AppData\Local\gtk-2.0
2020-11-06 20:11 - 2019-04-09 18:48 - 000000000 ____D C:\Users\croft\AppData\Local\babl-0.1
2020-11-06 18:33 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-11-06 17:51 - 2019-05-05 07:39 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2020-11-06 17:51 - 2019-05-05 07:39 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2020-11-05 16:57 - 2020-03-31 18:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-05 16:57 - 2019-11-05 14:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-11-05 16:55 - 2020-03-31 18:11 - 000000000 ____D C:\Users\croft
2020-11-05 16:55 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-11-05 16:35 - 2020-08-06 15:34 - 000000000 ____D C:\Program Files\CCleaner
2020-11-03 14:33 - 2020-07-15 15:36 - 000000000 ___HD C:\Users\croft\Downloads\[Originals]
2020-11-02 12:55 - 2019-10-30 18:20 - 000001273 _____ C:\Users\croft\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-02 12:55 - 2019-10-29 11:16 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-01 09:18 - 2020-06-02 23:28 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-01 09:18 - 2020-06-02 23:28 - 000003460 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-29 11:55 - 2019-04-09 12:44 - 000000000 ____D C:\Users\croft\AppData\Local\PlaceholderTileLogoFolder
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\ProgramData\Desktop\VLC media player.lnk
2020-10-27 17:34 - 2020-02-01 13:24 - 000000000 ____D C:\Users\croft\AppData\Roaming\uTorrent
2020-10-27 16:04 - 2020-04-02 12:43 - 000190464 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000160992 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000109360 _____ (ESET) C:\WINDOWS\system32\Drivers\edevmon.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000107784 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000070048 _____ (ESET) C:\WINDOWS\system32\Drivers\epfw.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000043720 _____ (ESET) C:\WINDOWS\system32\Drivers\ekbdflt.sys
2020-10-19 14:27 - 2019-11-21 15:21 - 000000000 ____D C:\Users\croft\Downloads\šití
2020-10-19 13:24 - 2020-03-30 15:58 - 000000000 ____D C:\Users\Pracovní\spolek
2020-10-19 13:23 - 2020-05-05 09:30 - 000000000 ____D C:\Users\Pracovní\Sika
==================== Files in the root of some directories ========
2019-04-10 21:09 - 2019-04-10 21:09 - 000000000 _____ () C:\Users\croft\AppData\Local\oobelibMkey.log
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ () C:\Users\croft\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Addition:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-11-2020
Ran by Líba (administrator) on LÍBA (HP HP Laptop 14-bp1xx) (17-11-2020 18:02:06)
Running from C:\Users\croft\Downloads
Loaded Profiles: Líba
Platform: Windows 10 Home Version 1909 18363.1139 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <58>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\hpservice.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHeciSvc.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [ACUW10EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\acdIDInTouch2.exe [2157000 2017-04-21] (ACD Systems International -> ACD Systems)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3674720 2018-05-11] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-10-29] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5866032 2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [ACDSeeCommanderUltimate10] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\ACDSeeCommanderUltimate10.exe [3427272 2017-04-25] (ACD Systems International -> )
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5491248 2020-10-22] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [29271224 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\...\Windows x64\Print Processors\hpcpp101: C:\Windows\System32\spool\prtprocs\x64\hpcpp101.dll [323584 2010-09-23] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\HP C411 Status Monitor: C:\WINDOWS\system32\hpinkstsC411LM.dll [333496 2013-02-04] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-12] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08393777-2384-440D-91E4-AEBC7CB6ED0A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24770744 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3321AC99-6979-4ADA-B63C-90A8469281F4} - System32\Tasks\GoogleUpdateTaskMachineCore1d5ff7dc8e0a443 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {4DC24594-1BA1-45EC-9939-FFEBCD1CAD3B} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3723532541-349634963-3060968088-500 => C:\Users\croft\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {6821FE11-081E-4D55-8806-9D4B3DEC6A8C} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {892F5E2F-A0EC-4EBB-AFC1-CE247EE87C0E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
Task: {989B7C29-748C-483A-898E-12FDE1FE5C06} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {B4EF7188-3BC3-47C3-A0CF-8312A44C8780} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C23CA36A-F7C9-4E42-9761-4A7AE2A2EAC4} - System32\Tasks\GoogleUpdateTaskMachineUA1d57dbef5a66ad0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {C71BBFD2-11D4-4C98-BE85-499A63738AE6} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269296 2018-10-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {C791C6D2-BA93-4234-AF14-816A47B4DE09} - System32\Tasks\GoogleUpdateTaskMachineCore1d57dbef58d7204 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {CA125255-6F8A-48EF-BD5B-4A8AF0C5121B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {D07DA521-5711-4294-B45F-9112A1BABCDD} - System32\Tasks\GoogleUpdateTaskMachineUA1d5ff7dc90708cf => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {DCA8ABD7-A530-428C-B2BA-DE5250B23511} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [660688 2020-11-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {DDB512BA-0014-491C-A822-3E5B7C2B1542} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61112 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {DEBB26FF-7B21-4D1E-9658-B4A2F3DFE592} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {FACE49CD-51CC-4B22-860A-013ED31E0D0B} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [68280 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.38 213.46.172.39
Tcpip\..\Interfaces\{01d9789d-5705-45b7-962a-a2adffa4a1ce}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{0cee5351-1667-498a-8c34-0a45e0c35c49}: [DhcpNameServer] 213.46.172.38 213.46.172.39
Edge:
======
DownloadDir: C:\Users\croft\Downloads
Edge DefaultProfile: Default
Edge Profile: C:\Users\croft\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-05]
FireFox:
========
FF DefaultProfile: 8yk82u7g.default
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\0blfb8qd.default-release-1 [2020-11-05]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\8yk82u7g.default [2020-01-22]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release [2020-11-17]
FF Extension: (Video DownloadHelper) - C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-08-04]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-11-15]
Chrome:
=======
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default [2020-11-17]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://cs.nex-software.com; hxxps://dev1security.blogspot.com; hxxps://dp32.ru; hxxps://drive.google.com; hxxps://et.piratihk.cz; hxxps://m.facebook.com; hxxps://mrak.pirati.cz; hxxps://trycracksoftware.com; hxxps://upload.facebook.com; hxxps://vk.com; hxxps://www.dreamstime.com; hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.reddit.com; hxxps://www.viry.cz; hxxps://www.vitalia.cz; hxxps://www.wondershare.com; hxxps://zulip.pirati.cz
CHR NewTab: Default -> Active:"chrome-extension://llaficoajjainaijghjlofdfmbjpebpa/newtab.html"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Prezentace) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-09]
CHR Extension: (Dokumenty) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-09]
CHR Extension: (Disk Google) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-22]
CHR Extension: (YouTube) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-09]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-09-11]
CHR Extension: (Tabulky) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-16]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2020-09-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Switch to Classic design on Facebook™) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\oancckmjgaoejmbedngcoiakblhacbog [2020-11-15]
CHR Extension: (Video & Audio Downloader) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchlfebelfohhojoomlngjbkcjponfha [2020-03-19]
CHR Extension: (Gmail) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-15]
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\System Profile [2020-11-05]
CHR HKU\S-1-5-21-3723532541-349634963-3060968088-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1369432 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-19] (Malwarebytes Inc -> Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\NisSrv.exe [2372048 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe [128376 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [493792 2017-10-24] (Wondershare Technology Co.,Ltd -> Wondershare)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R0 C981D415; C:\WINDOWS\System32\drivers\C981D415.sys [478392 2020-08-06] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47160 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-27] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-27] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-27] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-27] (ESET, spol. s r.o. -> ESET)
S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-10-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [428264 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [69864 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35392 2020-06-08] (HP Inc. -> HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:02 - 2020-11-17 18:04 - 000021958 _____ C:\Users\croft\Downloads\FRST.txt
2020-11-17 17:59 - 2020-11-17 17:59 - 002294784 _____ (Farbar) C:\Users\croft\Downloads\FRST64.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-11-09 09:12 - 2020-11-09 09:12 - 003648128 _____ C:\Users\croft\Downloads\ratzfatz-muetze-in-vielen-varianten-gr-39-bis-60.zip
2020-11-09 09:12 - 2019-10-28 15:23 - 004286813 _____ C:\Users\croft\Downloads\Anleitung_RatzFatz_Textilsucht.pdf
2020-11-09 09:12 - 2019-10-28 15:23 - 000152420 _____ C:\Users\croft\Downloads\Schnittmuster RatzFatz Muetze.pdf
2020-11-06 20:12 - 2020-11-06 20:12 - 000012756 _____ C:\Users\croft\Documents\adresy.xlsx
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ C:\Users\croft\AppData\Local\recently-used.xbel
2020-11-06 12:26 - 2020-11-06 12:26 - 000099723 _____ C:\Users\croft\Downloads\stanovy MS.pdf
2020-11-06 07:22 - 2020-11-06 07:22 - 000458853 ____H C:\Users\croft\Downloads\~WRL0004.tmp
2020-11-05 18:14 - 2020-11-05 18:14 - 000020282 _____ C:\Users\croft\Documents\cc_20201105_181449.reg
2020-11-03 13:08 - 2020-11-03 13:08 - 000579771 _____ C:\Users\croft\Downloads\Vítej_u_pirátů_královehradecky.pdf
2020-11-03 09:56 - 2020-11-03 09:56 - 000000000 ____D C:\Users\croft\AppData\Roaming\DataRecommendations
2020-11-03 09:55 - 2020-11-03 09:55 - 000000000 ____D C:\Users\croft\AppData\Local\Microsoft_Corporation
2020-11-02 17:53 - 2020-11-02 17:53 - 000408944 _____ C:\Users\croft\Downloads\damska-kapsa-do-svu.pdf
2020-11-02 12:55 - 2020-11-02 12:55 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-10-30 08:10 - 2017-12-29 14:52 - 208430445 _____ C:\Users\croft\Downloads\Earth - Den na zázračné planetě (2017) CZ dabing 4K HD(MOJEFILMY.XYZ).mkv
2020-10-25 17:54 - 2020-10-25 17:54 - 000310002 _____ C:\Users\croft\Downloads\201025_Shrnutí-voleb-pro-krajskou-schůzi.pdf
2020-10-24 14:49 - 2020-10-24 14:50 - 000000000 ____D C:\Users\croft\Downloads\z flešky
2020-10-24 14:40 - 2020-10-24 14:40 - 000042541 _____ C:\Users\croft\Downloads\proformaInvoice_2020011130.pdf
2020-10-22 23:42 - 2020-10-22 23:42 - 000065496 _____ (Adobe Systems Inc) C:\WINDOWS\system32\AdobePDF.dll
2020-10-22 23:42 - 2020-10-22 23:42 - 000036312 _____ (Adobe Systems Inc.) C:\WINDOWS\system32\AdobePDFUI.dll
2020-10-20 10:24 - 2020-10-20 10:24 - 002474437 _____ C:\Users\croft\Downloads\návod.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:03 - 2019-05-21 07:35 - 000000000 ____D C:\FRST
2020-11-17 18:02 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-17 17:07 - 2020-03-31 18:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-11-17 10:10 - 2020-03-31 18:22 - 001606106 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-17 10:10 - 2019-03-19 12:55 - 000685252 _____ C:\WINDOWS\system32\perfh005.dat
2020-11-17 10:10 - 2019-03-19 12:55 - 000137918 _____ C:\WINDOWS\system32\perfc005.dat
2020-11-17 10:10 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-11-17 09:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-16 15:43 - 2019-04-10 16:58 - 000000000 ____D C:\Users\Líba záloha
2020-11-16 15:07 - 2019-04-11 09:02 - 000000000 ____D C:\Users\Pracovní\Piráti
2020-11-16 15:02 - 2020-10-09 13:36 - 000000000 ____D C:\Users\croft\Downloads\inspirace
2020-11-16 15:01 - 2019-04-09 12:42 - 000000000 ____D C:\Users\croft\AppData\Local\Packages
2020-11-16 14:45 - 2019-10-13 08:29 - 000000000 ____D C:\Users\croft\AppData\Roaming\vlc
2020-11-15 14:12 - 2020-06-02 23:28 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-14 19:03 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-13 20:33 - 2019-10-29 11:16 - 000000000 ____D C:\Users\croft\AppData\LocalLow\Mozilla
2020-11-12 10:00 - 2019-04-09 12:45 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-11 12:19 - 2020-08-06 15:34 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-11-11 11:08 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-11 11:06 - 2019-03-08 15:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-11 11:03 - 2019-03-08 15:39 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-11-06 20:11 - 2019-04-09 21:08 - 000000000 ____D C:\Users\croft\AppData\Local\gtk-2.0
2020-11-06 20:11 - 2019-04-09 18:48 - 000000000 ____D C:\Users\croft\AppData\Local\babl-0.1
2020-11-06 18:33 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-11-06 17:51 - 2019-05-05 07:39 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2020-11-06 17:51 - 2019-05-05 07:39 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2020-11-05 16:57 - 2020-03-31 18:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-05 16:57 - 2019-11-05 14:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-11-05 16:55 - 2020-03-31 18:11 - 000000000 ____D C:\Users\croft
2020-11-05 16:55 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-11-05 16:35 - 2020-08-06 15:34 - 000000000 ____D C:\Program Files\CCleaner
2020-11-03 14:33 - 2020-07-15 15:36 - 000000000 ___HD C:\Users\croft\Downloads\[Originals]
2020-11-02 12:55 - 2019-10-30 18:20 - 000001273 _____ C:\Users\croft\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-02 12:55 - 2019-10-29 11:16 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-01 09:18 - 2020-06-02 23:28 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-01 09:18 - 2020-06-02 23:28 - 000003460 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-29 11:55 - 2019-04-09 12:44 - 000000000 ____D C:\Users\croft\AppData\Local\PlaceholderTileLogoFolder
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\ProgramData\Desktop\VLC media player.lnk
2020-10-27 17:34 - 2020-02-01 13:24 - 000000000 ____D C:\Users\croft\AppData\Roaming\uTorrent
2020-10-27 16:04 - 2020-04-02 12:43 - 000190464 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000160992 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000109360 _____ (ESET) C:\WINDOWS\system32\Drivers\edevmon.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000107784 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000070048 _____ (ESET) C:\WINDOWS\system32\Drivers\epfw.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000043720 _____ (ESET) C:\WINDOWS\system32\Drivers\ekbdflt.sys
2020-10-19 14:27 - 2019-11-21 15:21 - 000000000 ____D C:\Users\croft\Downloads\šití
2020-10-19 13:24 - 2020-03-30 15:58 - 000000000 ____D C:\Users\Pracovní\spolek
2020-10-19 13:23 - 2020-05-05 09:30 - 000000000 ____D C:\Users\Pracovní\Sika
==================== Files in the root of some directories ========
2019-04-10 21:09 - 2019-04-10 21:09 - 000000000 _____ () C:\Users\croft\AppData\Local\oobelibMkey.log
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ () C:\Users\croft\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
ráda bych poprosila o pomoc. V poslední době se mi při sledování filmů ( ale i při jiných činnostech, např. při práci s gimpem) začne přehřívat notebook a chlazení jede nepřetržitě a velmi hlasitě, jako když startuje dron.
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-11-2020
Ran by Líba (administrator) on LÍBA (HP HP Laptop 14-bp1xx) (17-11-2020 18:02:06)
Running from C:\Users\croft\Downloads
Loaded Profiles: Líba
Platform: Windows 10 Home Version 1909 18363.1139 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <58>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\hpservice.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHeciSvc.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [ACUW10EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\acdIDInTouch2.exe [2157000 2017-04-21] (ACD Systems International -> ACD Systems)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3674720 2018-05-11] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-10-29] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5866032 2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [ACDSeeCommanderUltimate10] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\ACDSeeCommanderUltimate10.exe [3427272 2017-04-25] (ACD Systems International -> )
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5491248 2020-10-22] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [29271224 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\...\Windows x64\Print Processors\hpcpp101: C:\Windows\System32\spool\prtprocs\x64\hpcpp101.dll [323584 2010-09-23] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\HP C411 Status Monitor: C:\WINDOWS\system32\hpinkstsC411LM.dll [333496 2013-02-04] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-12] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08393777-2384-440D-91E4-AEBC7CB6ED0A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24770744 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3321AC99-6979-4ADA-B63C-90A8469281F4} - System32\Tasks\GoogleUpdateTaskMachineCore1d5ff7dc8e0a443 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {4DC24594-1BA1-45EC-9939-FFEBCD1CAD3B} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3723532541-349634963-3060968088-500 => C:\Users\croft\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {6821FE11-081E-4D55-8806-9D4B3DEC6A8C} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {892F5E2F-A0EC-4EBB-AFC1-CE247EE87C0E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
Task: {989B7C29-748C-483A-898E-12FDE1FE5C06} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {B4EF7188-3BC3-47C3-A0CF-8312A44C8780} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C23CA36A-F7C9-4E42-9761-4A7AE2A2EAC4} - System32\Tasks\GoogleUpdateTaskMachineUA1d57dbef5a66ad0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {C71BBFD2-11D4-4C98-BE85-499A63738AE6} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269296 2018-10-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {C791C6D2-BA93-4234-AF14-816A47B4DE09} - System32\Tasks\GoogleUpdateTaskMachineCore1d57dbef58d7204 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {CA125255-6F8A-48EF-BD5B-4A8AF0C5121B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {D07DA521-5711-4294-B45F-9112A1BABCDD} - System32\Tasks\GoogleUpdateTaskMachineUA1d5ff7dc90708cf => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {DCA8ABD7-A530-428C-B2BA-DE5250B23511} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [660688 2020-11-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {DDB512BA-0014-491C-A822-3E5B7C2B1542} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61112 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {DEBB26FF-7B21-4D1E-9658-B4A2F3DFE592} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {FACE49CD-51CC-4B22-860A-013ED31E0D0B} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [68280 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.38 213.46.172.39
Tcpip\..\Interfaces\{01d9789d-5705-45b7-962a-a2adffa4a1ce}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{0cee5351-1667-498a-8c34-0a45e0c35c49}: [DhcpNameServer] 213.46.172.38 213.46.172.39
Edge:
======
DownloadDir: C:\Users\croft\Downloads
Edge DefaultProfile: Default
Edge Profile: C:\Users\croft\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-05]
FireFox:
========
FF DefaultProfile: 8yk82u7g.default
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\0blfb8qd.default-release-1 [2020-11-05]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\8yk82u7g.default [2020-01-22]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release [2020-11-17]
FF Extension: (Video DownloadHelper) - C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-08-04]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-11-15]
Chrome:
=======
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default [2020-11-17]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://cs.nex-software.com; hxxps://dev1security.blogspot.com; hxxps://dp32.ru; hxxps://drive.google.com; hxxps://et.piratihk.cz; hxxps://m.facebook.com; hxxps://mrak.pirati.cz; hxxps://trycracksoftware.com; hxxps://upload.facebook.com; hxxps://vk.com; hxxps://www.dreamstime.com; hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.reddit.com; hxxps://www.viry.cz; hxxps://www.vitalia.cz; hxxps://www.wondershare.com; hxxps://zulip.pirati.cz
CHR NewTab: Default -> Active:"chrome-extension://llaficoajjainaijghjlofdfmbjpebpa/newtab.html"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Prezentace) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-09]
CHR Extension: (Dokumenty) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-09]
CHR Extension: (Disk Google) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-22]
CHR Extension: (YouTube) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-09]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-09-11]
CHR Extension: (Tabulky) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-16]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2020-09-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Switch to Classic design on Facebook™) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\oancckmjgaoejmbedngcoiakblhacbog [2020-11-15]
CHR Extension: (Video & Audio Downloader) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchlfebelfohhojoomlngjbkcjponfha [2020-03-19]
CHR Extension: (Gmail) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-15]
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\System Profile [2020-11-05]
CHR HKU\S-1-5-21-3723532541-349634963-3060968088-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1369432 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-19] (Malwarebytes Inc -> Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\NisSrv.exe [2372048 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe [128376 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [493792 2017-10-24] (Wondershare Technology Co.,Ltd -> Wondershare)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R0 C981D415; C:\WINDOWS\System32\drivers\C981D415.sys [478392 2020-08-06] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47160 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-27] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-27] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-27] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-27] (ESET, spol. s r.o. -> ESET)
S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-10-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [428264 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [69864 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35392 2020-06-08] (HP Inc. -> HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:02 - 2020-11-17 18:04 - 000021958 _____ C:\Users\croft\Downloads\FRST.txt
2020-11-17 17:59 - 2020-11-17 17:59 - 002294784 _____ (Farbar) C:\Users\croft\Downloads\FRST64.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-11-09 09:12 - 2020-11-09 09:12 - 003648128 _____ C:\Users\croft\Downloads\ratzfatz-muetze-in-vielen-varianten-gr-39-bis-60.zip
2020-11-09 09:12 - 2019-10-28 15:23 - 004286813 _____ C:\Users\croft\Downloads\Anleitung_RatzFatz_Textilsucht.pdf
2020-11-09 09:12 - 2019-10-28 15:23 - 000152420 _____ C:\Users\croft\Downloads\Schnittmuster RatzFatz Muetze.pdf
2020-11-06 20:12 - 2020-11-06 20:12 - 000012756 _____ C:\Users\croft\Documents\adresy.xlsx
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ C:\Users\croft\AppData\Local\recently-used.xbel
2020-11-06 12:26 - 2020-11-06 12:26 - 000099723 _____ C:\Users\croft\Downloads\stanovy MS.pdf
2020-11-06 07:22 - 2020-11-06 07:22 - 000458853 ____H C:\Users\croft\Downloads\~WRL0004.tmp
2020-11-05 18:14 - 2020-11-05 18:14 - 000020282 _____ C:\Users\croft\Documents\cc_20201105_181449.reg
2020-11-03 13:08 - 2020-11-03 13:08 - 000579771 _____ C:\Users\croft\Downloads\Vítej_u_pirátů_královehradecky.pdf
2020-11-03 09:56 - 2020-11-03 09:56 - 000000000 ____D C:\Users\croft\AppData\Roaming\DataRecommendations
2020-11-03 09:55 - 2020-11-03 09:55 - 000000000 ____D C:\Users\croft\AppData\Local\Microsoft_Corporation
2020-11-02 17:53 - 2020-11-02 17:53 - 000408944 _____ C:\Users\croft\Downloads\damska-kapsa-do-svu.pdf
2020-11-02 12:55 - 2020-11-02 12:55 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-10-30 08:10 - 2017-12-29 14:52 - 208430445 _____ C:\Users\croft\Downloads\Earth - Den na zázračné planetě (2017) CZ dabing 4K HD(MOJEFILMY.XYZ).mkv
2020-10-25 17:54 - 2020-10-25 17:54 - 000310002 _____ C:\Users\croft\Downloads\201025_Shrnutí-voleb-pro-krajskou-schůzi.pdf
2020-10-24 14:49 - 2020-10-24 14:50 - 000000000 ____D C:\Users\croft\Downloads\z flešky
2020-10-24 14:40 - 2020-10-24 14:40 - 000042541 _____ C:\Users\croft\Downloads\proformaInvoice_2020011130.pdf
2020-10-22 23:42 - 2020-10-22 23:42 - 000065496 _____ (Adobe Systems Inc) C:\WINDOWS\system32\AdobePDF.dll
2020-10-22 23:42 - 2020-10-22 23:42 - 000036312 _____ (Adobe Systems Inc.) C:\WINDOWS\system32\AdobePDFUI.dll
2020-10-20 10:24 - 2020-10-20 10:24 - 002474437 _____ C:\Users\croft\Downloads\návod.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:03 - 2019-05-21 07:35 - 000000000 ____D C:\FRST
2020-11-17 18:02 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-17 17:07 - 2020-03-31 18:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-11-17 10:10 - 2020-03-31 18:22 - 001606106 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-17 10:10 - 2019-03-19 12:55 - 000685252 _____ C:\WINDOWS\system32\perfh005.dat
2020-11-17 10:10 - 2019-03-19 12:55 - 000137918 _____ C:\WINDOWS\system32\perfc005.dat
2020-11-17 10:10 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-11-17 09:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-16 15:43 - 2019-04-10 16:58 - 000000000 ____D C:\Users\Líba záloha
2020-11-16 15:07 - 2019-04-11 09:02 - 000000000 ____D C:\Users\Pracovní\Piráti
2020-11-16 15:02 - 2020-10-09 13:36 - 000000000 ____D C:\Users\croft\Downloads\inspirace
2020-11-16 15:01 - 2019-04-09 12:42 - 000000000 ____D C:\Users\croft\AppData\Local\Packages
2020-11-16 14:45 - 2019-10-13 08:29 - 000000000 ____D C:\Users\croft\AppData\Roaming\vlc
2020-11-15 14:12 - 2020-06-02 23:28 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-14 19:03 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-13 20:33 - 2019-10-29 11:16 - 000000000 ____D C:\Users\croft\AppData\LocalLow\Mozilla
2020-11-12 10:00 - 2019-04-09 12:45 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-11 12:19 - 2020-08-06 15:34 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-11-11 11:08 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-11 11:06 - 2019-03-08 15:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-11 11:03 - 2019-03-08 15:39 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-11-06 20:11 - 2019-04-09 21:08 - 000000000 ____D C:\Users\croft\AppData\Local\gtk-2.0
2020-11-06 20:11 - 2019-04-09 18:48 - 000000000 ____D C:\Users\croft\AppData\Local\babl-0.1
2020-11-06 18:33 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-11-06 17:51 - 2019-05-05 07:39 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2020-11-06 17:51 - 2019-05-05 07:39 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2020-11-05 16:57 - 2020-03-31 18:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-05 16:57 - 2019-11-05 14:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-11-05 16:55 - 2020-03-31 18:11 - 000000000 ____D C:\Users\croft
2020-11-05 16:55 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-11-05 16:35 - 2020-08-06 15:34 - 000000000 ____D C:\Program Files\CCleaner
2020-11-03 14:33 - 2020-07-15 15:36 - 000000000 ___HD C:\Users\croft\Downloads\[Originals]
2020-11-02 12:55 - 2019-10-30 18:20 - 000001273 _____ C:\Users\croft\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-02 12:55 - 2019-10-29 11:16 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-01 09:18 - 2020-06-02 23:28 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-01 09:18 - 2020-06-02 23:28 - 000003460 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-29 11:55 - 2019-04-09 12:44 - 000000000 ____D C:\Users\croft\AppData\Local\PlaceholderTileLogoFolder
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\ProgramData\Desktop\VLC media player.lnk
2020-10-27 17:34 - 2020-02-01 13:24 - 000000000 ____D C:\Users\croft\AppData\Roaming\uTorrent
2020-10-27 16:04 - 2020-04-02 12:43 - 000190464 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000160992 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000109360 _____ (ESET) C:\WINDOWS\system32\Drivers\edevmon.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000107784 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000070048 _____ (ESET) C:\WINDOWS\system32\Drivers\epfw.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000043720 _____ (ESET) C:\WINDOWS\system32\Drivers\ekbdflt.sys
2020-10-19 14:27 - 2019-11-21 15:21 - 000000000 ____D C:\Users\croft\Downloads\šití
2020-10-19 13:24 - 2020-03-30 15:58 - 000000000 ____D C:\Users\Pracovní\spolek
2020-10-19 13:23 - 2020-05-05 09:30 - 000000000 ____D C:\Users\Pracovní\Sika
==================== Files in the root of some directories ========
2019-04-10 21:09 - 2019-04-10 21:09 - 000000000 _____ () C:\Users\croft\AppData\Local\oobelibMkey.log
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ () C:\Users\croft\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Addition:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-11-2020
Ran by Líba (administrator) on LÍBA (HP HP Laptop 14-bp1xx) (17-11-2020 18:02:06)
Running from C:\Users\croft\Downloads
Loaded Profiles: Líba
Platform: Windows 10 Home Version 1909 18363.1139 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <58>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\hpservice.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHeciSvc.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [ACUW10EN] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\acdIDInTouch2.exe [2157000 2017-04-21] (ACD Systems International -> ACD Systems)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3674720 2018-05-11] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-10-29] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5866032 2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [ACDSeeCommanderUltimate10] => C:\Program Files\ACD Systems\ACDSee Ultimate\10.0\ACDSeeCommanderUltimate10.exe [3427272 2017-04-25] (ACD Systems International -> )
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5491248 2020-10-22] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3723532541-349634963-3060968088-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [29271224 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\...\Windows x64\Print Processors\hpcpp101: C:\Windows\System32\spool\prtprocs\x64\hpcpp101.dll [323584 2010-09-23] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\HP C411 Status Monitor: C:\WINDOWS\system32\hpinkstsC411LM.dll [333496 2013-02-04] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-12] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08393777-2384-440D-91E4-AEBC7CB6ED0A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24770744 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3321AC99-6979-4ADA-B63C-90A8469281F4} - System32\Tasks\GoogleUpdateTaskMachineCore1d5ff7dc8e0a443 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {4DC24594-1BA1-45EC-9939-FFEBCD1CAD3B} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3723532541-349634963-3060968088-500 => C:\Users\croft\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {6821FE11-081E-4D55-8806-9D4B3DEC6A8C} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {892F5E2F-A0EC-4EBB-AFC1-CE247EE87C0E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
Task: {989B7C29-748C-483A-898E-12FDE1FE5C06} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\croft\Downloads\esetonlinescanner_csy.exe
Task: {B4EF7188-3BC3-47C3-A0CF-8312A44C8780} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C23CA36A-F7C9-4E42-9761-4A7AE2A2EAC4} - System32\Tasks\GoogleUpdateTaskMachineUA1d57dbef5a66ad0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {C71BBFD2-11D4-4C98-BE85-499A63738AE6} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269296 2018-10-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {C791C6D2-BA93-4234-AF14-816A47B4DE09} - System32\Tasks\GoogleUpdateTaskMachineCore1d57dbef58d7204 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {CA125255-6F8A-48EF-BD5B-4A8AF0C5121B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {D07DA521-5711-4294-B45F-9112A1BABCDD} - System32\Tasks\GoogleUpdateTaskMachineUA1d5ff7dc90708cf => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-09] (Google Inc -> Google LLC)
Task: {DCA8ABD7-A530-428C-B2BA-DE5250B23511} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [660688 2020-11-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {DDB512BA-0014-491C-A822-3E5B7C2B1542} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61112 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {DEBB26FF-7B21-4D1E-9658-B4A2F3DFE592} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {FACE49CD-51CC-4B22-860A-013ED31E0D0B} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [68280 2019-08-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.38 213.46.172.39
Tcpip\..\Interfaces\{01d9789d-5705-45b7-962a-a2adffa4a1ce}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{0cee5351-1667-498a-8c34-0a45e0c35c49}: [DhcpNameServer] 213.46.172.38 213.46.172.39
Edge:
======
DownloadDir: C:\Users\croft\Downloads
Edge DefaultProfile: Default
Edge Profile: C:\Users\croft\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-05]
FireFox:
========
FF DefaultProfile: 8yk82u7g.default
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\0blfb8qd.default-release-1 [2020-11-05]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\8yk82u7g.default [2020-01-22]
FF ProfilePath: C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release [2020-11-17]
FF Extension: (Video DownloadHelper) - C:\Users\croft\AppData\Roaming\Mozilla\Firefox\Profiles\dm8nxv80.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-08-04]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems Incorporated -> Adobe Systems)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-11-15]
Chrome:
=======
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default [2020-11-17]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://cs.nex-software.com; hxxps://dev1security.blogspot.com; hxxps://dp32.ru; hxxps://drive.google.com; hxxps://et.piratihk.cz; hxxps://m.facebook.com; hxxps://mrak.pirati.cz; hxxps://trycracksoftware.com; hxxps://upload.facebook.com; hxxps://vk.com; hxxps://www.dreamstime.com; hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.reddit.com; hxxps://www.viry.cz; hxxps://www.vitalia.cz; hxxps://www.wondershare.com; hxxps://zulip.pirati.cz
CHR NewTab: Default -> Active:"chrome-extension://llaficoajjainaijghjlofdfmbjpebpa/newtab.html"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Prezentace) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-09]
CHR Extension: (Dokumenty) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-09]
CHR Extension: (Disk Google) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-22]
CHR Extension: (YouTube) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-09]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-09-11]
CHR Extension: (Tabulky) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-16]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2020-09-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Switch to Classic design on Facebook™) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\oancckmjgaoejmbedngcoiakblhacbog [2020-11-15]
CHR Extension: (Video & Audio Downloader) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchlfebelfohhojoomlngjbkcjponfha [2020-03-19]
CHR Extension: (Gmail) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\croft\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-15]
CHR Profile: C:\Users\croft\AppData\Local\Google\Chrome\User Data\System Profile [2020-11-05]
CHR HKU\S-1-5-21-3723532541-349634963-3060968088-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1369432 2015-11-18] (Disc Soft Ltd -> Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-29] (ESET, spol. s r.o. -> ESET)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-19] (Malwarebytes Inc -> Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\NisSrv.exe [2372048 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe [128376 2020-10-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppService.exe [493792 2017-10-24] (Wondershare Technology Co.,Ltd -> Wondershare)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R0 C981D415; C:\WINDOWS\System32\drivers\C981D415.sys [478392 2020-08-06] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47160 2019-04-14] (Disc Soft Ltd -> Disc Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-27] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-27] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-27] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-27] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-27] (ESET, spol. s r.o. -> ESET)
S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-10-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [428264 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [69864 2020-10-08] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35392 2020-06-08] (HP Inc. -> HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:02 - 2020-11-17 18:04 - 000021958 _____ C:\Users\croft\Downloads\FRST.txt
2020-11-17 17:59 - 2020-11-17 17:59 - 002294784 _____ (Farbar) C:\Users\croft\Downloads\FRST64.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-11-11 10:26 - 2020-11-11 10:27 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-11-09 09:12 - 2020-11-09 09:12 - 003648128 _____ C:\Users\croft\Downloads\ratzfatz-muetze-in-vielen-varianten-gr-39-bis-60.zip
2020-11-09 09:12 - 2019-10-28 15:23 - 004286813 _____ C:\Users\croft\Downloads\Anleitung_RatzFatz_Textilsucht.pdf
2020-11-09 09:12 - 2019-10-28 15:23 - 000152420 _____ C:\Users\croft\Downloads\Schnittmuster RatzFatz Muetze.pdf
2020-11-06 20:12 - 2020-11-06 20:12 - 000012756 _____ C:\Users\croft\Documents\adresy.xlsx
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ C:\Users\croft\AppData\Local\recently-used.xbel
2020-11-06 12:26 - 2020-11-06 12:26 - 000099723 _____ C:\Users\croft\Downloads\stanovy MS.pdf
2020-11-06 07:22 - 2020-11-06 07:22 - 000458853 ____H C:\Users\croft\Downloads\~WRL0004.tmp
2020-11-05 18:14 - 2020-11-05 18:14 - 000020282 _____ C:\Users\croft\Documents\cc_20201105_181449.reg
2020-11-03 13:08 - 2020-11-03 13:08 - 000579771 _____ C:\Users\croft\Downloads\Vítej_u_pirátů_královehradecky.pdf
2020-11-03 09:56 - 2020-11-03 09:56 - 000000000 ____D C:\Users\croft\AppData\Roaming\DataRecommendations
2020-11-03 09:55 - 2020-11-03 09:55 - 000000000 ____D C:\Users\croft\AppData\Local\Microsoft_Corporation
2020-11-02 17:53 - 2020-11-02 17:53 - 000408944 _____ C:\Users\croft\Downloads\damska-kapsa-do-svu.pdf
2020-11-02 12:55 - 2020-11-02 12:55 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-10-30 08:10 - 2017-12-29 14:52 - 208430445 _____ C:\Users\croft\Downloads\Earth - Den na zázračné planetě (2017) CZ dabing 4K HD(MOJEFILMY.XYZ).mkv
2020-10-25 17:54 - 2020-10-25 17:54 - 000310002 _____ C:\Users\croft\Downloads\201025_Shrnutí-voleb-pro-krajskou-schůzi.pdf
2020-10-24 14:49 - 2020-10-24 14:50 - 000000000 ____D C:\Users\croft\Downloads\z flešky
2020-10-24 14:40 - 2020-10-24 14:40 - 000042541 _____ C:\Users\croft\Downloads\proformaInvoice_2020011130.pdf
2020-10-22 23:42 - 2020-10-22 23:42 - 000065496 _____ (Adobe Systems Inc) C:\WINDOWS\system32\AdobePDF.dll
2020-10-22 23:42 - 2020-10-22 23:42 - 000036312 _____ (Adobe Systems Inc.) C:\WINDOWS\system32\AdobePDFUI.dll
2020-10-20 10:24 - 2020-10-20 10:24 - 002474437 _____ C:\Users\croft\Downloads\návod.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-17 18:03 - 2019-05-21 07:35 - 000000000 ____D C:\FRST
2020-11-17 18:02 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-17 17:07 - 2020-03-31 18:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-11-17 12:08 - 2019-10-05 09:46 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-11-17 10:10 - 2020-03-31 18:22 - 001606106 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-17 10:10 - 2019-03-19 12:55 - 000685252 _____ C:\WINDOWS\system32\perfh005.dat
2020-11-17 10:10 - 2019-03-19 12:55 - 000137918 _____ C:\WINDOWS\system32\perfc005.dat
2020-11-17 10:10 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-11-17 09:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-16 15:43 - 2019-04-10 16:58 - 000000000 ____D C:\Users\Líba záloha
2020-11-16 15:07 - 2019-04-11 09:02 - 000000000 ____D C:\Users\Pracovní\Piráti
2020-11-16 15:02 - 2020-10-09 13:36 - 000000000 ____D C:\Users\croft\Downloads\inspirace
2020-11-16 15:01 - 2019-04-09 12:42 - 000000000 ____D C:\Users\croft\AppData\Local\Packages
2020-11-16 14:45 - 2019-10-13 08:29 - 000000000 ____D C:\Users\croft\AppData\Roaming\vlc
2020-11-15 14:12 - 2020-06-02 23:28 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-14 19:03 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-13 20:33 - 2019-10-29 11:16 - 000000000 ____D C:\Users\croft\AppData\LocalLow\Mozilla
2020-11-12 10:00 - 2019-04-09 12:45 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-11 12:19 - 2020-08-06 15:34 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-11-11 11:08 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-11 11:06 - 2019-03-08 15:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-11 11:03 - 2019-03-08 15:39 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-11-06 20:11 - 2019-04-09 21:08 - 000000000 ____D C:\Users\croft\AppData\Local\gtk-2.0
2020-11-06 20:11 - 2019-04-09 18:48 - 000000000 ____D C:\Users\croft\AppData\Local\babl-0.1
2020-11-06 18:33 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-11-06 17:51 - 2019-05-05 07:39 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2020-11-06 17:51 - 2019-05-05 07:39 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2020-11-05 16:57 - 2020-03-31 18:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-05 16:57 - 2019-11-05 14:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-11-05 16:55 - 2020-03-31 18:11 - 000000000 ____D C:\Users\croft
2020-11-05 16:55 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-11-05 16:35 - 2020-08-06 15:34 - 000000000 ____D C:\Program Files\CCleaner
2020-11-03 14:33 - 2020-07-15 15:36 - 000000000 ___HD C:\Users\croft\Downloads\[Originals]
2020-11-02 12:55 - 2019-10-30 18:20 - 000001273 _____ C:\Users\croft\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-02 12:55 - 2019-10-29 11:16 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-01 09:18 - 2020-06-02 23:28 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-01 09:18 - 2020-06-02 23:28 - 000003460 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-29 11:55 - 2019-04-09 12:44 - 000000000 ____D C:\Users\croft\AppData\Local\PlaceholderTileLogoFolder
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-10-28 19:51 - 2019-10-13 08:29 - 000000916 _____ C:\ProgramData\Desktop\VLC media player.lnk
2020-10-27 17:34 - 2020-02-01 13:24 - 000000000 ____D C:\Users\croft\AppData\Roaming\uTorrent
2020-10-27 16:04 - 2020-04-02 12:43 - 000190464 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000160992 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000109360 _____ (ESET) C:\WINDOWS\system32\Drivers\edevmon.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000107784 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000070048 _____ (ESET) C:\WINDOWS\system32\Drivers\epfw.sys
2020-10-27 16:04 - 2020-04-02 12:43 - 000043720 _____ (ESET) C:\WINDOWS\system32\Drivers\ekbdflt.sys
2020-10-19 14:27 - 2019-11-21 15:21 - 000000000 ____D C:\Users\croft\Downloads\šití
2020-10-19 13:24 - 2020-03-30 15:58 - 000000000 ____D C:\Users\Pracovní\spolek
2020-10-19 13:23 - 2020-05-05 09:30 - 000000000 ____D C:\Users\Pracovní\Sika
==================== Files in the root of some directories ========
2019-04-10 21:09 - 2019-04-10 21:09 - 000000000 _____ () C:\Users\croft\AppData\Local\oobelibMkey.log
2020-11-06 20:11 - 2020-11-06 20:11 - 000048238 _____ () C:\Users\croft\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================