Prosím o preventivní kontrolu logu
Napsal: 18 lis 2020 17:28
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-11-2020
Ran by RaJaMaJa (administrator) on RAJAMAJA-PC (Gigabyte Technology Co., Ltd. Z270P-D3) (18-11-2020 17:04:17)
Running from C:\Users\RaJaMaJa\Desktop
Loaded Profiles: RaJaMaJa & janac & marys & test & Classic .NET AppPool & .NET v4.5 & DefaultAppPool & .NET v2.0 & .NET v4.5 Classic & .NET v2.0 Classic
Platform: Windows 10 Pro Version 2004 19041.450 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\10.1.0.3194\AdskLicensingService\AdskLicensingService.exe
(Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2021\Moldflow\bin\mitsijm.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\afwServ.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\aswEngSrv.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\aswidsagent.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgToolsSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe <3>
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\wsc_proxy.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Secure VPN\Vpn.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Secure VPN\VpnSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\TuneUp\TuneupSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\TuneUp\TuneupUI.exe
(AVG Technologies USA, LLC -> AVG Technologies s.r.o) C:\Program Files (x86)\AVG\AntiTrack\NetFilter\AVGAntiTrackFilter.exe
(AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\AntiTrack\AVGAntiTrack.exe
(AVG Technologies USA, LLC -> Sciensoft Software Security) C:\Program Files (x86)\AVG\AntiTrack\Updshl10.exe
(AVG Technologies USA, LLC -> Software Security System) C:\Program Files (x86)\AVG\AntiTrack\Ekag20nt.exe
(AVG Technologies USA, LLC -> The CefSharp Authors) C:\Program Files (x86)\AVG\AntiTrack\CefSharp.BrowserSubprocess.exe <3>
(CANON INC. -> CANON INC.) C:\Windows\System32\CNAB4RPD.EXE
(Flexera Software LLC -> Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.) C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\AORUS.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft) C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe
(GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\Led\GvLedService.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <25>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\RaJaMaJa\AppData\Local\Microsoft\OneDrive\OneDrive.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [157320 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320584 2018-01-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [TuneupUI.exe] => C:\Program Files\AVG\TuneUp\TuneupUI.exe [2614832 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-05-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [VX3000] => C:\WINDOWS\vVX3000.exe [762736 2018-08-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 3.1 eXtensible Host Controller Driver\Application\iusb3mon.exe [299504 2016-08-18] (Intel(R) USB eXtensible Host Controller Drivers -> Intel Corporation)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [664872 2020-03-04] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50010064 2020-11-03] (Google LLC -> )
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Akamai NetSession Interface] => C:\Users\RaJaMaJa\AppData\Local\Akamai\netsession_win.exe [4490200 2017-09-08] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1208712 2014-05-14] (Autodesk, Inc -> Autodesk, Inc.)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [90952568 2020-09-29] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32281272 2020-11-10] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [com.squirrel.Teams.Teams] => C:\Users\RaJaMaJa\AppData\Local\Microsoft\Teams\Update.exe [2452664 2020-11-13] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --enable-audio-service-sandbox --restore-last-session -- hxxps://errorreport.autodesk.com/progres (the data entry has 126 more characters).
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Policies\Explorer: []
HKU\S-1-5-21-3853202556-3985030159-1422732261-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\janac\AppData\Local\Microsoft\Teams\Update.exe [2452664 2020-11-06] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1004\...\Run: [com.squirrel.Teams.Teams] => C:\Users\marys\AppData\Local\Microsoft\Teams\Update.exe [2452664 2020-11-15] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1004\...\Run: [Opera Browser Assistant] => C:\Users\marys\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3152920 2020-11-10] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1006\...\Run: [com.squirrel.Teams.Teams] => C:\Users\test\AppData\Local\Microsoft\Teams\Update.exe [2336912 2020-03-18] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1006\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-271721585-897601226-2024613209-625570482-296978595\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-3682073875-1643277370-2842298652-3532359455-2406259117\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-3876422241-1344743610-1729199087-774402673-2621913236\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-4068219030-1673637257-3279585211-533386110-4122969689\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [51032 2008-04-07] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\CNAB4 Monitor: C:\Windows\system32\CNAB4LMD.DLL [58880 2012-10-10] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{28B89EEF-4107-0000-7102-CF3F3A09B77D}] -> msiexec /fus {28B89EEF-4107-0000-7102-CF3F3A09B77D}
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-13] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVG Secure VPN.lnk [2019-07-22]
ShortcutTarget: AVG Secure VPN.lnk -> C:\Program Files (x86)\AVG\Secure VPN\Vpn.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP2900 Status Window.lnk [2018-01-02]
ShortcutTarget: Canon LBP2900 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE (CANON INC. -> CANON INC.)
Startup: C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE AORUS GRAPHICS ENGINE.lnk [2018-01-03]
ShortcutTarget: GIGABYTE AORUS GRAPHICS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\autorun.exe () [File not signed]
Startup: C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GRAPHICS ENGINE.lnk [2018-01-03]
ShortcutTarget: GRAPHICS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\autorun.exe () [File not signed]
BootExecute: autocheck autochk * icarus_rvrt.exe
GroupPolicy: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06FC4347-32AA-4FE9-9A99-F4B7BEC6EDE3} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
Task: {0EEB28AE-0425-477E-AA71-B38D15FADEB8} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {1CB48590-F7D1-4E8C-8A81-8C7439456262} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {1CBAB2C9-46DA-4179-A869-0897D4F0289D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [667856 2020-11-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {1ECEE4D5-E23D-4CB1-8B57-F6F46072DCA5} - System32\Tasks\AVG Secure VPN Update => C:\Program Files (x86)\AVG\Secure VPN\VpnUpdate.exe [1071512 2020-10-02] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {214F8791-DA6D-476E-A8FC-42E34A6E75D1} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {235A47BF-3B41-4BE1-BEA6-97BC966F1CA3} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {23658494-90A7-4CC7-9476-94B7507C34D2} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {23B47FF7-3CDA-46BD-8DBC-7D27CFF5F754} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {24152B22-DA5C-471A-B6EE-B35B3C6830F7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-12-14] (Google Inc -> Google Inc.)
Task: {2B1A6037-1E16-4911-9A79-374817AB921A} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2B2F43F6-3B9A-426A-A74C-2752491DC0A2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {33F8082D-EB01-415B-919C-FA75796947B8} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1526680 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {35326C6F-6729-47F5-A34C-20E5F68C6F1B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {41793E1A-7135-4660-BEA8-DF989FC096FC} - System32\Tasks\Opera scheduled assistant Autoupdate 1602747943 => C:\Users\marys\AppData\Local\Programs\Opera\launcher.exe [1721368 2020-11-10] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\marys\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {497F80FF-FC4A-4582-AD67-E3D585348C1D} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {4A3C0A62-ECA0-4F1C-89CA-EF9C2AC3D99C} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {4C9ADC9D-BA9D-4531-89FF-60DE71EE0B07} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {4F0D5228-BEAD-4C22-BB97-774E199A622E} - System32\Tasks\S-1-1-0\EnterpriseMgmt\{A518C617-15A7-40A5-AA40-A0E34C24E5D2}\Login Schedule created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [459776 2020-08-16] (Microsoft Windows -> Microsoft Corporation)
Task: {4F38667A-0C05-4683-A8C1-B2C2A419D629} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {51FA16A4-BA72-44B5-A92D-E550A688D2D5} - System32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE => C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\AORUS.exe [16930960 2017-12-08] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.)
Task: {52B499F5-358B-43F8-B84E-7C42C26A4074} - System32\Tasks\{63EF4212-718E-4D7E-A464-75EE5F0C768A} => C:\Windows\system32\pcalua.exe -a C:\Linux\unetbootin-windows-657.exe -d C:\Linux
Task: {59EEFB4D-5391-4611-B920-32F81F2A038C} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {61344086-CE4A-4877-8F18-2DB9D44466BB} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {62DB5042-2EDC-4A3F-B146-6DF7195266C9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [26781880 2020-11-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {6562D9BC-E363-41CB-88CB-8541CEBEC4D7} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {667252AC-F24C-47D0-928D-7859C44E83D7} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {70B86CEE-2946-4B6D-B339-8AF249354475} - System32\Tasks\Microsoft\Windows\AVGAntiTrack\AVGAntiTrackStart => C:\Program Files (x86)\AVG\AntiTrack\AVGAntiTrack.exe [14451336 2020-05-25] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {7B87736A-CAA2-4D17-85AB-BFD4211F7E24} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {7FAD7970-D713-4F7C-81FC-694B9767782D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {80853D09-9C47-4FFF-BF6A-9AA7E78E8BC5} - System32\Tasks\S-1-1-0\EnterpriseMgmt\{07743B27-31EF-46C2-83A4-F15855E7A86C}\Login Schedule created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [459776 2020-08-16] (Microsoft Windows -> Microsoft Corporation)
Task: {80D96BC6-219D-465B-9F52-BFBC6FC92D0D} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {84993D61-AD11-4CAB-904C-F7D87F53BB5D} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {852B0E6B-3F04-4878-B3EA-43860CA70D3A} - System32\Tasks\{D6239AB0-B778-428E-B9C8-8256CCBDE2A6} => C:\Windows\system32\pcalua.exe -a G:\Install\Win7\WindowsImageTool\WindowsImageTool.exe -d G:\Install\Win7\WindowsImageTool
Task: {8C4FFDE9-5813-46D1-8A30-560D11B73539} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8DADCDD1-37B5-43EB-A7F0-3F72316C044D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {8DF10DED-39A8-4ECE-9F4E-5567D77787C1} - System32\Tasks\{4CA0A453-8AD1-4F66-AA07-B7CD34FBDC60} => C:\Windows\system32\pcalua.exe -a G:\Install\IrfanView\irfanview_lang_czech.exe -d G:\Install\IrfanView
Task: {8FE31512-D3A9-4BB3-9BBF-78C2147C0FB3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [654456 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {930CE392-D2B5-446F-9B7C-995A92826D83} - System32\Tasks\Opera scheduled Autoupdate 1602747936 => C:\Users\marys\AppData\Local\Programs\Opera\launcher.exe [1721368 2020-11-10] (Opera Software AS -> Opera Software)
Task: {946F80FA-6B48-47AC-AD42-CEA0409ADDD7} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [543536 2016-10-13] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {96C3A2E8-671B-47BE-9FA5-5922D693C80B} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {996F2882-DFE1-406F-88BB-ED5335EC6C50} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {A1653A63-028B-49EC-95EC-AF7FF17642D1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {AAB2A24C-7E64-4411-AAC7-078489F2A9CC} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AAE82DAC-8D33-47B7-A084-FE3FE3045938} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {B1752A1A-5D53-45E0-BB3A-27D312A7EF63} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {B19731C0-075E-4C77-AAE0-55EDB0B4F624} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {B39D209B-1FD6-4491-861B-165D6004F870} - System32\Tasks\AVG\AVG TuneUp Update BugReport => C:\Program Files\AVG\TuneUp\AvBugReport.exe [2812664 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) -> --send "dumps|report" --silent --product 74 --programpath "C:\Program Files\AVG\TuneUp\Setup\.." --configpath "C:\Program Files\AVG\TuneUp\Setup" --path "C:\ProgramData\AVG\TuneUp\log" --path "C:\ProgramData\AVG\Icarus\Logs" --guid 4f44f860-b146-4448-a478-dd87377cf945
Task: {B65DC3F6-DD80-4D67-AA17-79C54A3485BC} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B76FCE28-16BC-4671-A220-ACBB979982E8} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {BE83E31D-E77C-4A2B-A85E-85ECB767E95F} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [4544136 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {C245BE18-AB48-4282-B398-2D80B49D2A29} - System32\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000 => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupdate.exe [31320 2020-10-21] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {C2897252-564C-444F-94CF-DC46029C4E2A} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C2973404-190C-4E1B-9FA1-C74684487AD4} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-11-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C7F6862E-91BA-4D35-BBF1-629594C72E19} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {C8DF63A8-9468-48E4-A601-93D04D1047BD} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [3047944 2020-08-31] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
Task: {CC0F49DB-56D1-4CD9-BD23-7CE6F9F871E2} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CEDB3414-D361-4EA0-BCAA-56F765D876C2} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {CF140738-696F-4858-BF88-202AF1FEBD54} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D1D200F0-83BF-4E3A-BE12-38D5656BA73E} - System32\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000 => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupload.exe [31320 2020-10-21] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D2656C81-76E4-4EDC-A7C3-CD377270756A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-12-14] (Google Inc -> Google Inc.)
Task: {D3541440-D01F-4759-BA9F-E055079921BF} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1773192 2020-09-20] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {D526C2DB-6E51-4EED-963F-36B63CC6032F} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301928 2019-10-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DDDA84F9-41D9-4980-B5D1-172EE95BF2F8} - System32\Tasks\AVG\AVG TuneUp Update => C:\Program Files\Common Files\AVG\Icarus\avg-tu\icarus.exe [5495432 2020-11-11] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {E0A6C0CE-B1D5-4942-ABE0-5F2C09C50368} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {E9AA5484-2BC5-4F8E-99DE-D19FEDD195E5} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [250056 2020-10-16] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {EA5D4FCB-C3C5-41EB-A7A3-0A7E08FAA1F3} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EAF40732-453A-4C0B-B8CA-DBA494AB59C8} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [752136 2020-10-16] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {EB61F8F8-015E-4605-9517-4B99F9EBC309} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {F9D8D419-D60C-4456-A503-BE625BB60583} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FC92DFC1-807D-44F0-86BB-16F2CBD34424} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupload.exe
Task: C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_vVX3000_exe.job => C:\WINDOWS\vVX3000.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 46.228.16.1
Tcpip\..\Interfaces\{0cbad714-b460-4ef6-8189-68d7661228b2}: [DhcpNameServer] 46.228.16.1
Tcpip\..\Interfaces\{5f4c62d5-a718-4df3-b346-c4fd7d609757}: [NameServer] 100.120.57.1
Edge:
======
DownloadDir:
FireFox:
========
FF DefaultProfile: mcmhlvuq.default
FF ProfilePath: C:\Users\RaJaMaJa\AppData\Roaming\Mozilla\Firefox\Profiles\mcmhlvuq.default [2020-11-18]
FF NewTab: Mozilla\Firefox\Profiles\mcmhlvuq.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10438__180802
FF Extension: (AVG AntiTrack) - C:\Users\RaJaMaJa\AppData\Roaming\Mozilla\Firefox\Profiles\mcmhlvuq.default\Extensions\antitrack@avg.com.xpi [2020-08-14]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll [2020-10-16] (Adobe Systems Incorporated -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll [2020-10-16] (Adobe Systems Incorporated -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-08-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-08-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin HKU\S-1-5-21-3853202556-3985030159-1422732261-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\RaJaMaJa\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-06] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-3853202556-3985030159-1422732261-1000: saba.com/SabaMeetingPlugin -> C:\Users\RaJaMaJa\AppData\Roaming\Centra\App\bin\npSabaMeetingPlugin3.dll [2018-02-05] (Saba Software, Inc. -> Saba)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default [2020-11-18]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://kytary.cz; hxxps://padlet.com; hxxps://teams.microsoft.com; hxxps://www.inventor3dblog.cz
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.cz/?gfe_rd=cr&ei=Eyv3U4jXOJH ... oogle.com/"
CHR Extension: (Prezentace) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-16]
CHR Extension: (eJOY English - Learn with Movies) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfojhdiedpdnlijjbhjnhokbnohfdfb [2020-11-11]
CHR Extension: (Dokumenty) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-16]
CHR Extension: (Disk Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-31]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2017-12-16]
CHR Extension: (YouTube) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-16]
CHR Extension: (Daum Equation Editor) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dinfmiceliiomokeofbocegmacmagjhe [2017-12-16]
CHR Extension: (Kalendář Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-12-16]
CHR Extension: (Tabulky) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-16]
CHR Extension: (GoToMeeting for Google Calendar) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaonpiemcjiihedemhopdoefaohcjoch [2020-07-09]
CHR Extension: (Vzdálená plocha Chrome) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-20]
CHR Extension: (QR Code Generator) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcmhlmapohffdglflokbgknlknnmogbb [2017-12-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-12]
CHR Extension: (Saba Meeting Chrome Connector) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjedkhmeelbomjafdlehdcomjhobcnbk [2019-10-20]
CHR Extension: (Kalendář Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjpceadhnpnpdelkidbjdmoodafopfkp [2017-12-16]
CHR Extension: (Google Keep – poznámky a seznamy) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2020-11-12]
CHR Extension: (Language Learning with Netflix) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoombieeljmmljlkjmnheibnpciblicm [2020-11-11]
CHR Extension: (Cisco Webex Extension) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2020-06-16]
CHR Extension: (Grammarly for Chrome) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2020-11-15]
CHR Extension: (EasyHome Homestyler) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2017-12-16]
CHR Extension: (Gmail) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmhopmchchfpfdcdjodmpfaaphdclmlj [2019-11-22]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2020-10-15]
CHR Extension: (Chomikuj.pl) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabmeicndgkgfompmmdkijoamfleoadk [2018-05-28]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2017-12-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-06]
CHR Extension: (Picasa) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2017-12-16]
CHR Extension: (20-20 3D Viewer for IKEA) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp [2018-02-12]
CHR Extension: (Gmail) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-15]
CHR HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1046904 2020-03-04] (Autodesk, Inc. -> Autodesk Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [250056 2020-10-16] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
R2 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [16930616 2019-12-18] (Autodesk, Inc. -> Autodesk)
R2 almservice; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [2209144 2018-01-17] (Siemens AG -> SIEMENS AG)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [360992 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVG Firewall; C:\Program Files (x86)\AVG\Antivirus\afwServ.exe [1187584 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVG Tools; C:\Program Files (x86)\AVG\Antivirus\avgToolsSvc.exe [2749064 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\aswidsagent.exe [8498112 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AvgWscReporter; C:\Program Files (x86)\AVG\Antivirus\wsc_proxy.exe [110608 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 CleanupPSvc; C:\Program Files\AVG\TuneUp\TuneupSvc.exe [12978896 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9057136 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
R2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [File not signed]
R2 Gservice; C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe [19888 2016-12-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 mitsijm2021; C:\Program Files\Autodesk\Inventor 2021\Moldflow\bin\mitsijm.exe [844088 2019-12-04] (Autodesk, Inc. -> Autodesk, Inc.)
R2 SecureVpn; C:\Program Files (x86)\AVG\Secure VPN\VpnSvc.exe [7025728 2020-10-02] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5097344 2020-08-16] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [206472 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [236176 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [195728 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [61072 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [16320 2020-07-21] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [42848 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [175784 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [518744 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 avgNetNd6; C:\WINDOWS\system32\DRIVERS\avgNetNd6.sys [29944 2017-12-19] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [109352 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [84928 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [851680 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [470984 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [217408 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 avgTap; C:\WINDOWS\System32\drivers\avgTap.sys [54888 2018-09-05] (AVG Technologies CZ, s.r.o. -> The OpenVPN Project)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [327000 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-10-04] (Bluestack Systems, Inc -> Bluestack System Inc.)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [18528 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R3 gdrv; C:\Windows\gdrv.sys [26280 2020-01-15] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 gdrv2; C:\WINDOWS\gdrv2.sys [32600 2020-01-15] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R1 netfilter2; C:\WINDOWS\System32\drivers\netfilter2.sys [86632 2020-05-25] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [25608 2020-05-12] (AVG Technologies CZ, s.r.o. -> SlimWare Utilities, Inc.)
R1 VD_FileDisk; C:\Windows\System32\Drivers\VD_FileDisk.sys [30312 2011-01-26] (Ghisler Software GmbH -> CaptainFlint Software)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-18 17:04 - 2020-11-18 17:04 - 000046408 _____ C:\Users\RaJaMaJa\Desktop\FRST.txt
2020-11-18 17:04 - 2020-11-18 17:04 - 000000000 ____D C:\FRST
2020-11-18 17:02 - 2020-11-18 17:02 - 002294784 _____ (Farbar) C:\Users\RaJaMaJa\Desktop\FRST64.exe
2020-11-17 15:06 - 2020-11-17 15:06 - 000202971 _____ C:\Users\marys\Downloads\ironchest-1.16.4-11.2.10.jar
2020-11-16 17:49 - 2020-11-16 17:49 - 001710412 _____ C:\Users\janac\Downloads\MAP_II_seminar_MSMT_pro_prijemce_komplet.pptx
2020-11-16 17:33 - 2020-11-16 17:33 - 000484846 _____ C:\Users\janac\Downloads\SKM_C224e20093013501 (1).pdf
2020-11-16 17:33 - 2020-11-16 17:33 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500 (3).pdf
2020-11-16 17:33 - 2020-11-16 17:33 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500 (2).pdf
2020-11-16 17:33 - 2020-11-16 17:33 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500 (1).pdf
2020-11-16 17:05 - 2020-11-16 17:05 - 000484846 _____ C:\Users\janac\Downloads\SKM_C224e20093013501.pdf
2020-11-16 17:05 - 2020-11-16 17:05 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500.pdf
2020-11-15 20:58 - 2020-11-15 20:58 - 000000000 ____D C:\Users\marys\AppData\Roaming\Teams
2020-11-15 14:36 - 2020-11-15 14:36 - 000000000 ____D C:\Users\marys\AppData\Roaming\java
2020-11-15 14:35 - 2020-11-17 15:35 - 000000000 ____D C:\Users\marys\AppData\Roaming\.tlauncher
2020-11-15 14:35 - 2020-11-17 15:35 - 000000000 ____D C:\Users\marys\AppData\Roaming\.minecraft
2020-11-15 14:35 - 2020-11-15 14:35 - 000001937 _____ C:\Users\marys\Desktop\TLauncher.lnk
2020-11-15 13:04 - 2020-11-17 16:17 - 000000000 ____D C:\Users\marys\Desktop\Blbosti od Kuby
2020-11-13 17:53 - 2020-11-13 17:53 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\java
2020-11-13 17:52 - 2020-11-13 17:56 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\.tlauncher
2020-11-13 17:52 - 2020-11-13 17:52 - 000001952 _____ C:\Users\RaJaMaJa\Desktop\TLauncher.lnk
2020-11-13 17:51 - 2020-11-13 18:07 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\.minecraft
2020-11-13 17:50 - 2020-11-13 17:50 - 017103496 _____ (TLauncher Inc.) C:\Users\marys\Downloads\TLauncher-2.72-Installer-0.6.8.exe
2020-11-13 13:15 - 2020-11-13 13:15 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\Teams
2020-11-12 12:41 - 2020-11-16 08:45 - 000000000 ____D C:\Users\marys\Desktop\SCANY
2020-11-11 21:53 - 2020-11-11 21:53 - 001617416 _____ C:\Users\janac\Downloads\IMG_0001.pdf
2020-11-11 21:46 - 2020-11-11 21:46 - 004301377 _____ C:\Users\janac\Downloads\OP.pdf
2020-11-11 11:38 - 2020-11-11 11:38 - 000000000 ____D C:\Users\marys\AppData\Local\stellarium
2020-11-11 11:37 - 2020-11-11 11:42 - 000000000 ____D C:\Users\marys\AppData\Roaming\Stellarium
2020-11-11 11:37 - 2020-11-11 11:37 - 000000000 ____D C:\Users\marys\Desktop\Gry
2020-11-07 18:58 - 2020-11-07 18:58 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\activplayer
2020-11-06 20:08 - 2020-11-06 20:08 - 000000000 ____D C:\Users\janac\AppData\Roaming\Teams
2020-11-04 23:35 - 2020-11-04 23:35 - 000000363 _____ C:\Users\RaJaMaJa\AppData\Roaming\Solve Elec 2.5 Prefs
2020-11-04 23:34 - 2020-11-04 23:34 - 000001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solve Elec.lnk
2020-11-04 23:34 - 2020-11-04 23:34 - 000001058 _____ C:\Users\RaJaMaJa\Desktop\Solve Elec.lnk
2020-11-04 23:34 - 2020-11-04 23:34 - 000000000 ____D C:\Program Files (x86)\Solve Elec 2.5
2020-11-04 12:06 - 2020-11-04 12:07 - 001362834 _____ C:\Users\marys\Downloads\document.pdf
2020-11-02 19:54 - 2020-11-02 19:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-11-02 11:32 - 2020-11-12 14:13 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-10-22 13:12 - 2020-11-12 14:07 - 000000000 ____D C:\Users\janac\AppData\Local\CrashDumps
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-18 17:00 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-18 16:56 - 2020-08-16 20:28 - 000000000 ____D C:\Users\marys
2020-11-18 16:47 - 2020-08-16 21:07 - 000813738 _____ C:\WINDOWS\system32\perfh015.dat
2020-11-18 16:47 - 2020-08-16 21:07 - 000165768 _____ C:\WINDOWS\system32\perfc015.dat
2020-11-18 16:47 - 2020-08-16 20:38 - 002872258 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-18 16:47 - 2019-12-07 15:43 - 000787616 _____ C:\WINDOWS\system32\perfh005.dat
2020-11-18 16:47 - 2019-12-07 15:43 - 000175498 _____ C:\WINDOWS\system32\perfc005.dat
2020-11-18 16:47 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2020-11-18 16:43 - 2017-12-28 18:00 - 000000000 ____D C:\Program Files\CCleaner
2020-11-18 16:42 - 2020-08-16 20:40 - 000004278 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2020-11-18 16:42 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-11-18 16:42 - 2017-12-14 23:43 - 000000000 ____D C:\ProgramData\NVIDIA
2020-11-18 16:41 - 2017-12-27 23:17 - 000000000 ___RD C:\Users\RaJaMaJa\OneDrive
2020-11-18 16:40 - 2020-10-16 21:40 - 000000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2020-11-18 16:40 - 2020-08-16 20:40 - 000003986 _____ C:\WINDOWS\system32\Tasks\AVG Secure VPN Update
2020-11-18 16:40 - 2020-08-16 20:40 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-18 16:40 - 2020-08-16 20:28 - 000000000 ____D C:\Users\RaJaMaJa
2020-11-18 16:40 - 2020-08-16 20:26 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-18 16:40 - 2018-11-06 16:53 - 000000676 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job
2020-11-18 16:40 - 2018-11-06 16:53 - 000000580 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job
2020-11-18 14:03 - 2017-12-16 14:31 - 000000000 ____D C:\ProgramData\Avg
2020-11-18 12:50 - 2020-10-16 21:40 - 000003128 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-11-18 12:50 - 2020-10-15 16:35 - 000002966 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper
2020-11-18 12:50 - 2020-10-15 08:45 - 000003752 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1602747943
2020-11-18 12:50 - 2020-10-15 08:45 - 000003498 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1602747936
2020-11-18 12:50 - 2020-08-16 20:40 - 000003400 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-11-18 12:50 - 2020-08-16 20:40 - 000003398 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000003274 _____ C:\WINDOWS\system32\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000
2020-11-18 12:50 - 2020-08-16 20:40 - 000003196 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000003178 _____ C:\WINDOWS\system32\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000
2020-11-18 12:50 - 2020-08-16 20:40 - 000003176 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-11-18 12:50 - 2020-08-16 20:40 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000003136 _____ C:\WINDOWS\system32\Tasks\Intel PTT EK Recertification
2020-11-18 12:50 - 2020-08-16 20:40 - 000003094 _____ C:\WINDOWS\system32\Tasks\Java Platform SE Auto Updater
2020-11-18 12:50 - 2020-08-16 20:40 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-11-18 12:50 - 2020-08-16 20:40 - 000002984 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002914 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3853202556-3985030159-1422732261-1004
2020-11-18 12:50 - 2020-08-16 20:40 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3853202556-3985030159-1422732261-1000
2020-11-18 12:50 - 2020-08-16 20:40 - 000002744 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002602 _____ C:\WINDOWS\system32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE
2020-11-18 12:50 - 2020-08-16 20:40 - 000002534 _____ C:\WINDOWS\system32\Tasks\SamsungMagician
2020-11-18 12:50 - 2020-08-16 20:40 - 000002322 _____ C:\WINDOWS\system32\Tasks\{D6239AB0-B778-428E-B9C8-8256CCBDE2A6}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002282 _____ C:\WINDOWS\system32\Tasks\{4CA0A453-8AD1-4F66-AA07-B7CD34FBDC60}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002238 _____ C:\WINDOWS\system32\Tasks\{63EF4212-718E-4D7E-A464-75EE5F0C768A}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002220 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-11-18 12:50 - 2020-08-16 20:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-11-18 07:51 - 2018-03-25 17:57 - 000000000 ____D C:\ProgramData\Autodesk
2020-11-18 07:41 - 2018-10-07 16:08 - 000000000 ___RD C:\Users\marys\OneDrive
2020-11-17 23:47 - 2019-12-07 10:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-11-16 18:01 - 2018-07-28 09:02 - 000000000 ____D C:\Users\janac\AppData\Local\Packages
2020-11-15 23:00 - 2018-02-17 16:17 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\vlc
2020-11-15 21:43 - 2017-12-27 23:15 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\Packages
2020-11-15 20:58 - 2020-03-24 07:58 - 000002368 _____ C:\Users\marys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-15 14:36 - 2019-01-13 10:05 - 000000000 ____D C:\Users\marys\AppData\Local\D3DSCache
2020-11-15 12:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-15 12:52 - 2020-06-13 19:10 - 000000000 ____D C:\Users\marys\Desktop\Kuba
2020-11-14 15:34 - 2018-10-07 16:07 - 000000000 ____D C:\Users\marys\AppData\Local\Packages
2020-11-14 10:10 - 2018-03-24 20:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2020-11-14 10:10 - 2016-03-06 23:37 - 000002071 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2020-11-14 10:10 - 2016-03-06 23:37 - 000002061 _____ C:\Users\Public\Desktop\Google Docs.lnk
2020-11-14 09:18 - 2017-12-16 18:44 - 000000000 ____D C:\Program Files\Microsoft Office
2020-11-13 13:15 - 2020-03-16 18:35 - 000002383 _____ C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-13 13:15 - 2020-03-16 18:35 - 000002375 _____ C:\Users\RaJaMaJa\Desktop\Microsoft Teams.lnk
2020-11-13 08:10 - 2017-12-14 23:12 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-13 08:10 - 2017-12-14 23:12 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-13 07:58 - 2020-10-15 08:45 - 000001409 _____ C:\Users\marys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2020-11-12 23:27 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-12 23:27 - 2017-12-27 23:32 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\PlaceholderTileLogoFolder
2020-11-12 22:31 - 2017-12-16 19:29 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\ElevatedDiagnostics
2020-11-12 18:55 - 2017-12-28 17:59 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\CrashDumps
2020-11-12 14:13 - 2018-07-28 09:04 - 000000000 ____D C:\Users\janac\AppData\LocalLow\Mozilla
2020-11-12 14:05 - 2020-06-13 17:01 - 000000000 ____D C:\Users\marys\AppData\LocalLow\Mozilla
2020-11-11 13:11 - 2020-06-14 10:00 - 000134792 _____ (AVG Technologies) C:\WINDOWS\system32\icarus_rvrt.exe
2020-11-11 12:32 - 2019-04-14 13:38 - 000000000 ____D C:\Users\marys\AppData\Roaming\vlc
2020-11-11 07:42 - 2018-10-31 16:04 - 000000000 ____D C:\Users\marys\AppData\Local\CrashDumps
2020-11-09 15:43 - 2020-10-16 21:44 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\activdashboard
2020-11-09 15:04 - 2020-10-16 21:40 - 000000000 ____D C:\ProgramData\Promethean
2020-11-07 19:23 - 2018-05-25 20:18 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\D3DSCache
2020-11-07 19:22 - 2019-04-23 21:23 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\Ubisoft Game Launcher
2020-11-07 19:03 - 2016-03-06 23:34 - 000000241 _____ C:\Users\RaJaMaJa\Desktop\Servis24.txt
2020-11-07 19:00 - 2019-04-23 21:23 - 000001310 _____ C:\Users\RaJaMaJa\Desktop\Ubisoft Connect.lnk
2020-11-07 19:00 - 2019-04-23 21:23 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2020-11-07 18:56 - 2018-12-10 23:22 - 000000000 ____D C:\Users\RaJaMaJa\Desktop\Autodesk
2020-11-06 20:08 - 2020-03-20 16:44 - 000002368 _____ C:\Users\janac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-06 20:08 - 2020-03-20 16:44 - 000002360 _____ C:\Users\janac\Desktop\Microsoft Teams.lnk
2020-11-04 07:41 - 2017-12-16 19:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-11-02 19:54 - 2017-12-16 19:12 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-02 07:59 - 2020-03-23 08:25 - 000921624 _____ C:\img2-001.raw
2020-10-27 08:30 - 2020-08-16 20:28 - 000002365 _____ C:\Users\marys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-10-27 08:09 - 2020-08-16 20:28 - 000002374 _____ C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-10-21 17:21 - 2018-11-06 16:53 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\GoToMeeting
2020-10-19 07:24 - 2020-09-08 15:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
==================== Files in the root of some directories ========
2020-11-04 23:35 - 2020-11-04 23:35 - 000000363 _____ () C:\Users\RaJaMaJa\AppData\Roaming\Solve Elec 2.5 Prefs
2019-10-07 19:20 - 2019-10-07 19:20 - 000007605 _____ () C:\Users\RaJaMaJa\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by RaJaMaJa (administrator) on RAJAMAJA-PC (Gigabyte Technology Co., Ltd. Z270P-D3) (18-11-2020 17:04:17)
Running from C:\Users\RaJaMaJa\Desktop
Loaded Profiles: RaJaMaJa & janac & marys & test & Classic .NET AppPool & .NET v4.5 & DefaultAppPool & .NET v2.0 & .NET v4.5 Classic & .NET v2.0 Classic
Platform: Windows 10 Pro Version 2004 19041.450 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\10.1.0.3194\AdskLicensingService\AdskLicensingService.exe
(Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2021\Moldflow\bin\mitsijm.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\afwServ.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\aswEngSrv.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\aswidsagent.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgToolsSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe <3>
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\wsc_proxy.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Secure VPN\Vpn.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Secure VPN\VpnSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\TuneUp\TuneupSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\TuneUp\TuneupUI.exe
(AVG Technologies USA, LLC -> AVG Technologies s.r.o) C:\Program Files (x86)\AVG\AntiTrack\NetFilter\AVGAntiTrackFilter.exe
(AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\AntiTrack\AVGAntiTrack.exe
(AVG Technologies USA, LLC -> Sciensoft Software Security) C:\Program Files (x86)\AVG\AntiTrack\Updshl10.exe
(AVG Technologies USA, LLC -> Software Security System) C:\Program Files (x86)\AVG\AntiTrack\Ekag20nt.exe
(AVG Technologies USA, LLC -> The CefSharp Authors) C:\Program Files (x86)\AVG\AntiTrack\CefSharp.BrowserSubprocess.exe <3>
(CANON INC. -> CANON INC.) C:\Windows\System32\CNAB4RPD.EXE
(Flexera Software LLC -> Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.) C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\AORUS.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft) C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe
(GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\Led\GvLedService.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <25>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\RaJaMaJa\AppData\Local\Microsoft\OneDrive\OneDrive.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [157320 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320584 2018-01-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [TuneupUI.exe] => C:\Program Files\AVG\TuneUp\TuneupUI.exe [2614832 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-05-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [VX3000] => C:\WINDOWS\vVX3000.exe [762736 2018-08-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 3.1 eXtensible Host Controller Driver\Application\iusb3mon.exe [299504 2016-08-18] (Intel(R) USB eXtensible Host Controller Drivers -> Intel Corporation)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [664872 2020-03-04] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50010064 2020-11-03] (Google LLC -> )
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Akamai NetSession Interface] => C:\Users\RaJaMaJa\AppData\Local\Akamai\netsession_win.exe [4490200 2017-09-08] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1208712 2014-05-14] (Autodesk, Inc -> Autodesk, Inc.)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [90952568 2020-09-29] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32281272 2020-11-10] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Run: [com.squirrel.Teams.Teams] => C:\Users\RaJaMaJa\AppData\Local\Microsoft\Teams\Update.exe [2452664 2020-11-13] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --enable-audio-service-sandbox --restore-last-session -- hxxps://errorreport.autodesk.com/progres (the data entry has 126 more characters).
HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\...\Policies\Explorer: []
HKU\S-1-5-21-3853202556-3985030159-1422732261-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\janac\AppData\Local\Microsoft\Teams\Update.exe [2452664 2020-11-06] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1004\...\Run: [com.squirrel.Teams.Teams] => C:\Users\marys\AppData\Local\Microsoft\Teams\Update.exe [2452664 2020-11-15] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1004\...\Run: [Opera Browser Assistant] => C:\Users\marys\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3152920 2020-11-10] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1006\...\Run: [com.squirrel.Teams.Teams] => C:\Users\test\AppData\Local\Microsoft\Teams\Update.exe [2336912 2020-03-18] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3853202556-3985030159-1422732261-1006\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-271721585-897601226-2024613209-625570482-296978595\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-3682073875-1643277370-2842298652-3532359455-2406259117\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-3876422241-1344743610-1729199087-774402673-2621913236\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-82-4068219030-1673637257-3279585211-533386110-4122969689\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [51032 2008-04-07] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\CNAB4 Monitor: C:\Windows\system32\CNAB4LMD.DLL [58880 2012-10-10] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{28B89EEF-4107-0000-7102-CF3F3A09B77D}] -> msiexec /fus {28B89EEF-4107-0000-7102-CF3F3A09B77D}
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-13] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVG Secure VPN.lnk [2019-07-22]
ShortcutTarget: AVG Secure VPN.lnk -> C:\Program Files (x86)\AVG\Secure VPN\Vpn.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP2900 Status Window.lnk [2018-01-02]
ShortcutTarget: Canon LBP2900 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE (CANON INC. -> CANON INC.)
Startup: C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE AORUS GRAPHICS ENGINE.lnk [2018-01-03]
ShortcutTarget: GIGABYTE AORUS GRAPHICS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\autorun.exe () [File not signed]
Startup: C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GRAPHICS ENGINE.lnk [2018-01-03]
ShortcutTarget: GRAPHICS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\autorun.exe () [File not signed]
BootExecute: autocheck autochk * icarus_rvrt.exe
GroupPolicy: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06FC4347-32AA-4FE9-9A99-F4B7BEC6EDE3} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
Task: {0EEB28AE-0425-477E-AA71-B38D15FADEB8} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {1CB48590-F7D1-4E8C-8A81-8C7439456262} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {1CBAB2C9-46DA-4179-A869-0897D4F0289D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [667856 2020-11-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {1ECEE4D5-E23D-4CB1-8B57-F6F46072DCA5} - System32\Tasks\AVG Secure VPN Update => C:\Program Files (x86)\AVG\Secure VPN\VpnUpdate.exe [1071512 2020-10-02] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {214F8791-DA6D-476E-A8FC-42E34A6E75D1} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {235A47BF-3B41-4BE1-BEA6-97BC966F1CA3} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {23658494-90A7-4CC7-9476-94B7507C34D2} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {23B47FF7-3CDA-46BD-8DBC-7D27CFF5F754} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {24152B22-DA5C-471A-B6EE-B35B3C6830F7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-12-14] (Google Inc -> Google Inc.)
Task: {2B1A6037-1E16-4911-9A79-374817AB921A} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2B2F43F6-3B9A-426A-A74C-2752491DC0A2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {33F8082D-EB01-415B-919C-FA75796947B8} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1526680 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {35326C6F-6729-47F5-A34C-20E5F68C6F1B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {41793E1A-7135-4660-BEA8-DF989FC096FC} - System32\Tasks\Opera scheduled assistant Autoupdate 1602747943 => C:\Users\marys\AppData\Local\Programs\Opera\launcher.exe [1721368 2020-11-10] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\marys\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {497F80FF-FC4A-4582-AD67-E3D585348C1D} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {4A3C0A62-ECA0-4F1C-89CA-EF9C2AC3D99C} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {4C9ADC9D-BA9D-4531-89FF-60DE71EE0B07} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {4F0D5228-BEAD-4C22-BB97-774E199A622E} - System32\Tasks\S-1-1-0\EnterpriseMgmt\{A518C617-15A7-40A5-AA40-A0E34C24E5D2}\Login Schedule created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [459776 2020-08-16] (Microsoft Windows -> Microsoft Corporation)
Task: {4F38667A-0C05-4683-A8C1-B2C2A419D629} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {51FA16A4-BA72-44B5-A92D-E550A688D2D5} - System32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE => C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\AORUS.exe [16930960 2017-12-08] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.)
Task: {52B499F5-358B-43F8-B84E-7C42C26A4074} - System32\Tasks\{63EF4212-718E-4D7E-A464-75EE5F0C768A} => C:\Windows\system32\pcalua.exe -a C:\Linux\unetbootin-windows-657.exe -d C:\Linux
Task: {59EEFB4D-5391-4611-B920-32F81F2A038C} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {61344086-CE4A-4877-8F18-2DB9D44466BB} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {62DB5042-2EDC-4A3F-B146-6DF7195266C9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [26781880 2020-11-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {6562D9BC-E363-41CB-88CB-8541CEBEC4D7} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {667252AC-F24C-47D0-928D-7859C44E83D7} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {70B86CEE-2946-4B6D-B339-8AF249354475} - System32\Tasks\Microsoft\Windows\AVGAntiTrack\AVGAntiTrackStart => C:\Program Files (x86)\AVG\AntiTrack\AVGAntiTrack.exe [14451336 2020-05-25] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {7B87736A-CAA2-4D17-85AB-BFD4211F7E24} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {7FAD7970-D713-4F7C-81FC-694B9767782D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {80853D09-9C47-4FFF-BF6A-9AA7E78E8BC5} - System32\Tasks\S-1-1-0\EnterpriseMgmt\{07743B27-31EF-46C2-83A4-F15855E7A86C}\Login Schedule created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [459776 2020-08-16] (Microsoft Windows -> Microsoft Corporation)
Task: {80D96BC6-219D-465B-9F52-BFBC6FC92D0D} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {84993D61-AD11-4CAB-904C-F7D87F53BB5D} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {852B0E6B-3F04-4878-B3EA-43860CA70D3A} - System32\Tasks\{D6239AB0-B778-428E-B9C8-8256CCBDE2A6} => C:\Windows\system32\pcalua.exe -a G:\Install\Win7\WindowsImageTool\WindowsImageTool.exe -d G:\Install\Win7\WindowsImageTool
Task: {8C4FFDE9-5813-46D1-8A30-560D11B73539} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8DADCDD1-37B5-43EB-A7F0-3F72316C044D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {8DF10DED-39A8-4ECE-9F4E-5567D77787C1} - System32\Tasks\{4CA0A453-8AD1-4F66-AA07-B7CD34FBDC60} => C:\Windows\system32\pcalua.exe -a G:\Install\IrfanView\irfanview_lang_czech.exe -d G:\Install\IrfanView
Task: {8FE31512-D3A9-4BB3-9BBF-78C2147C0FB3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [654456 2019-10-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {930CE392-D2B5-446F-9B7C-995A92826D83} - System32\Tasks\Opera scheduled Autoupdate 1602747936 => C:\Users\marys\AppData\Local\Programs\Opera\launcher.exe [1721368 2020-11-10] (Opera Software AS -> Opera Software)
Task: {946F80FA-6B48-47AC-AD42-CEA0409ADDD7} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [543536 2016-10-13] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {96C3A2E8-671B-47BE-9FA5-5922D693C80B} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {996F2882-DFE1-406F-88BB-ED5335EC6C50} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {A1653A63-028B-49EC-95EC-AF7FF17642D1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {AAB2A24C-7E64-4411-AAC7-078489F2A9CC} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AAE82DAC-8D33-47B7-A084-FE3FE3045938} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {B1752A1A-5D53-45E0-BB3A-27D312A7EF63} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {B19731C0-075E-4C77-AAE0-55EDB0B4F624} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {B39D209B-1FD6-4491-861B-165D6004F870} - System32\Tasks\AVG\AVG TuneUp Update BugReport => C:\Program Files\AVG\TuneUp\AvBugReport.exe [2812664 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) -> --send "dumps|report" --silent --product 74 --programpath "C:\Program Files\AVG\TuneUp\Setup\.." --configpath "C:\Program Files\AVG\TuneUp\Setup" --path "C:\ProgramData\AVG\TuneUp\log" --path "C:\ProgramData\AVG\Icarus\Logs" --guid 4f44f860-b146-4448-a478-dd87377cf945
Task: {B65DC3F6-DD80-4D67-AA17-79C54A3485BC} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B76FCE28-16BC-4671-A220-ACBB979982E8} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-09-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {BE83E31D-E77C-4A2B-A85E-85ECB767E95F} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [4544136 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {C245BE18-AB48-4282-B398-2D80B49D2A29} - System32\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000 => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupdate.exe [31320 2020-10-21] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {C2897252-564C-444F-94CF-DC46029C4E2A} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C2973404-190C-4E1B-9FA1-C74684487AD4} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-11-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C7F6862E-91BA-4D35-BBF1-629594C72E19} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {C8DF63A8-9468-48E4-A601-93D04D1047BD} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [3047944 2020-08-31] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
Task: {CC0F49DB-56D1-4CD9-BD23-7CE6F9F871E2} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CEDB3414-D361-4EA0-BCAA-56F765D876C2} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {CF140738-696F-4858-BF88-202AF1FEBD54} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D1D200F0-83BF-4E3A-BE12-38D5656BA73E} - System32\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000 => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupload.exe [31320 2020-10-21] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D2656C81-76E4-4EDC-A7C3-CD377270756A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-12-14] (Google Inc -> Google Inc.)
Task: {D3541440-D01F-4759-BA9F-E055079921BF} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1773192 2020-09-20] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {D526C2DB-6E51-4EED-963F-36B63CC6032F} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301928 2019-10-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DDDA84F9-41D9-4980-B5D1-172EE95BF2F8} - System32\Tasks\AVG\AVG TuneUp Update => C:\Program Files\Common Files\AVG\Icarus\avg-tu\icarus.exe [5495432 2020-11-11] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {E0A6C0CE-B1D5-4942-ABE0-5F2C09C50368} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {E9AA5484-2BC5-4F8E-99DE-D19FEDD195E5} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [250056 2020-10-16] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {EA5D4FCB-C3C5-41EB-A7A3-0A7E08FAA1F3} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EAF40732-453A-4C0B-B8CA-DBA494AB59C8} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [752136 2020-10-16] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {EB61F8F8-015E-4605-9517-4B99F9EBC309} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {F9D8D419-D60C-4456-A503-BE625BB60583} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FC92DFC1-807D-44F0-86BB-16F2CBD34424} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job => C:\Users\RaJaMaJa\AppData\Local\GoToMeeting\18962\g2mupload.exe
Task: C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_vVX3000_exe.job => C:\WINDOWS\vVX3000.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 46.228.16.1
Tcpip\..\Interfaces\{0cbad714-b460-4ef6-8189-68d7661228b2}: [DhcpNameServer] 46.228.16.1
Tcpip\..\Interfaces\{5f4c62d5-a718-4df3-b346-c4fd7d609757}: [NameServer] 100.120.57.1
Edge:
======
DownloadDir:
FireFox:
========
FF DefaultProfile: mcmhlvuq.default
FF ProfilePath: C:\Users\RaJaMaJa\AppData\Roaming\Mozilla\Firefox\Profiles\mcmhlvuq.default [2020-11-18]
FF NewTab: Mozilla\Firefox\Profiles\mcmhlvuq.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10438__180802
FF Extension: (AVG AntiTrack) - C:\Users\RaJaMaJa\AppData\Roaming\Mozilla\Firefox\Profiles\mcmhlvuq.default\Extensions\antitrack@avg.com.xpi [2020-08-14]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll [2020-10-16] (Adobe Systems Incorporated -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll [2020-10-16] (Adobe Systems Incorporated -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-08-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-08-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin HKU\S-1-5-21-3853202556-3985030159-1422732261-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\RaJaMaJa\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-06] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-3853202556-3985030159-1422732261-1000: saba.com/SabaMeetingPlugin -> C:\Users\RaJaMaJa\AppData\Roaming\Centra\App\bin\npSabaMeetingPlugin3.dll [2018-02-05] (Saba Software, Inc. -> Saba)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default [2020-11-18]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://kytary.cz; hxxps://padlet.com; hxxps://teams.microsoft.com; hxxps://www.inventor3dblog.cz
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.cz/?gfe_rd=cr&ei=Eyv3U4jXOJH ... oogle.com/"
CHR Extension: (Prezentace) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-16]
CHR Extension: (eJOY English - Learn with Movies) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfojhdiedpdnlijjbhjnhokbnohfdfb [2020-11-11]
CHR Extension: (Dokumenty) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-16]
CHR Extension: (Disk Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-31]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2017-12-16]
CHR Extension: (YouTube) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-16]
CHR Extension: (Daum Equation Editor) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dinfmiceliiomokeofbocegmacmagjhe [2017-12-16]
CHR Extension: (Kalendář Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-12-16]
CHR Extension: (Tabulky) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-16]
CHR Extension: (GoToMeeting for Google Calendar) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaonpiemcjiihedemhopdoefaohcjoch [2020-07-09]
CHR Extension: (Vzdálená plocha Chrome) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-20]
CHR Extension: (QR Code Generator) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcmhlmapohffdglflokbgknlknnmogbb [2017-12-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-12]
CHR Extension: (Saba Meeting Chrome Connector) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjedkhmeelbomjafdlehdcomjhobcnbk [2019-10-20]
CHR Extension: (Kalendář Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjpceadhnpnpdelkidbjdmoodafopfkp [2017-12-16]
CHR Extension: (Google Keep – poznámky a seznamy) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2020-11-12]
CHR Extension: (Language Learning with Netflix) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoombieeljmmljlkjmnheibnpciblicm [2020-11-11]
CHR Extension: (Cisco Webex Extension) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2020-06-16]
CHR Extension: (Grammarly for Chrome) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2020-11-15]
CHR Extension: (EasyHome Homestyler) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2017-12-16]
CHR Extension: (Gmail) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmhopmchchfpfdcdjodmpfaaphdclmlj [2019-11-22]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2020-10-15]
CHR Extension: (Chomikuj.pl) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabmeicndgkgfompmmdkijoamfleoadk [2018-05-28]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2017-12-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-06]
CHR Extension: (Picasa) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2017-12-16]
CHR Extension: (20-20 3D Viewer for IKEA) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp [2018-02-12]
CHR Extension: (Gmail) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\RaJaMaJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-15]
CHR HKU\S-1-5-21-3853202556-3985030159-1422732261-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1046904 2020-03-04] (Autodesk, Inc. -> Autodesk Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [250056 2020-10-16] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
R2 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [16930616 2019-12-18] (Autodesk, Inc. -> Autodesk)
R2 almservice; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [2209144 2018-01-17] (Siemens AG -> SIEMENS AG)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [360992 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVG Firewall; C:\Program Files (x86)\AVG\Antivirus\afwServ.exe [1187584 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVG Tools; C:\Program Files (x86)\AVG\Antivirus\avgToolsSvc.exe [2749064 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\aswidsagent.exe [8498112 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AvgWscReporter; C:\Program Files (x86)\AVG\Antivirus\wsc_proxy.exe [110608 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 CleanupPSvc; C:\Program Files\AVG\TuneUp\TuneupSvc.exe [12978896 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9057136 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
R2 gadjservice; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [17920 2015-06-25] () [File not signed]
R2 Gservice; C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe [19888 2016-12-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 mitsijm2021; C:\Program Files\Autodesk\Inventor 2021\Moldflow\bin\mitsijm.exe [844088 2019-12-04] (Autodesk, Inc. -> Autodesk, Inc.)
R2 SecureVpn; C:\Program Files (x86)\AVG\Secure VPN\VpnSvc.exe [7025728 2020-10-02] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5097344 2020-08-16] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [206472 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [236176 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [195728 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [61072 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [16320 2020-07-21] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [42848 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [175784 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [518744 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 avgNetNd6; C:\WINDOWS\system32\DRIVERS\avgNetNd6.sys [29944 2017-12-19] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [109352 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [84928 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [851680 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [470984 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [217408 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 avgTap; C:\WINDOWS\System32\drivers\avgTap.sys [54888 2018-09-05] (AVG Technologies CZ, s.r.o. -> The OpenVPN Project)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [327000 2020-10-16] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-10-04] (Bluestack Systems, Inc -> Bluestack System Inc.)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [18528 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R3 gdrv; C:\Windows\gdrv.sys [26280 2020-01-15] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 gdrv2; C:\WINDOWS\gdrv2.sys [32600 2020-01-15] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R1 netfilter2; C:\WINDOWS\System32\drivers\netfilter2.sys [86632 2020-05-25] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [25608 2020-05-12] (AVG Technologies CZ, s.r.o. -> SlimWare Utilities, Inc.)
R1 VD_FileDisk; C:\Windows\System32\Drivers\VD_FileDisk.sys [30312 2011-01-26] (Ghisler Software GmbH -> CaptainFlint Software)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-18 17:04 - 2020-11-18 17:04 - 000046408 _____ C:\Users\RaJaMaJa\Desktop\FRST.txt
2020-11-18 17:04 - 2020-11-18 17:04 - 000000000 ____D C:\FRST
2020-11-18 17:02 - 2020-11-18 17:02 - 002294784 _____ (Farbar) C:\Users\RaJaMaJa\Desktop\FRST64.exe
2020-11-17 15:06 - 2020-11-17 15:06 - 000202971 _____ C:\Users\marys\Downloads\ironchest-1.16.4-11.2.10.jar
2020-11-16 17:49 - 2020-11-16 17:49 - 001710412 _____ C:\Users\janac\Downloads\MAP_II_seminar_MSMT_pro_prijemce_komplet.pptx
2020-11-16 17:33 - 2020-11-16 17:33 - 000484846 _____ C:\Users\janac\Downloads\SKM_C224e20093013501 (1).pdf
2020-11-16 17:33 - 2020-11-16 17:33 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500 (3).pdf
2020-11-16 17:33 - 2020-11-16 17:33 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500 (2).pdf
2020-11-16 17:33 - 2020-11-16 17:33 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500 (1).pdf
2020-11-16 17:05 - 2020-11-16 17:05 - 000484846 _____ C:\Users\janac\Downloads\SKM_C224e20093013501.pdf
2020-11-16 17:05 - 2020-11-16 17:05 - 000483343 _____ C:\Users\janac\Downloads\SKM_C224e20093013500.pdf
2020-11-15 20:58 - 2020-11-15 20:58 - 000000000 ____D C:\Users\marys\AppData\Roaming\Teams
2020-11-15 14:36 - 2020-11-15 14:36 - 000000000 ____D C:\Users\marys\AppData\Roaming\java
2020-11-15 14:35 - 2020-11-17 15:35 - 000000000 ____D C:\Users\marys\AppData\Roaming\.tlauncher
2020-11-15 14:35 - 2020-11-17 15:35 - 000000000 ____D C:\Users\marys\AppData\Roaming\.minecraft
2020-11-15 14:35 - 2020-11-15 14:35 - 000001937 _____ C:\Users\marys\Desktop\TLauncher.lnk
2020-11-15 13:04 - 2020-11-17 16:17 - 000000000 ____D C:\Users\marys\Desktop\Blbosti od Kuby
2020-11-13 17:53 - 2020-11-13 17:53 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\java
2020-11-13 17:52 - 2020-11-13 17:56 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\.tlauncher
2020-11-13 17:52 - 2020-11-13 17:52 - 000001952 _____ C:\Users\RaJaMaJa\Desktop\TLauncher.lnk
2020-11-13 17:51 - 2020-11-13 18:07 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\.minecraft
2020-11-13 17:50 - 2020-11-13 17:50 - 017103496 _____ (TLauncher Inc.) C:\Users\marys\Downloads\TLauncher-2.72-Installer-0.6.8.exe
2020-11-13 13:15 - 2020-11-13 13:15 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\Teams
2020-11-12 12:41 - 2020-11-16 08:45 - 000000000 ____D C:\Users\marys\Desktop\SCANY
2020-11-11 21:53 - 2020-11-11 21:53 - 001617416 _____ C:\Users\janac\Downloads\IMG_0001.pdf
2020-11-11 21:46 - 2020-11-11 21:46 - 004301377 _____ C:\Users\janac\Downloads\OP.pdf
2020-11-11 11:38 - 2020-11-11 11:38 - 000000000 ____D C:\Users\marys\AppData\Local\stellarium
2020-11-11 11:37 - 2020-11-11 11:42 - 000000000 ____D C:\Users\marys\AppData\Roaming\Stellarium
2020-11-11 11:37 - 2020-11-11 11:37 - 000000000 ____D C:\Users\marys\Desktop\Gry
2020-11-07 18:58 - 2020-11-07 18:58 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\activplayer
2020-11-06 20:08 - 2020-11-06 20:08 - 000000000 ____D C:\Users\janac\AppData\Roaming\Teams
2020-11-04 23:35 - 2020-11-04 23:35 - 000000363 _____ C:\Users\RaJaMaJa\AppData\Roaming\Solve Elec 2.5 Prefs
2020-11-04 23:34 - 2020-11-04 23:34 - 000001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solve Elec.lnk
2020-11-04 23:34 - 2020-11-04 23:34 - 000001058 _____ C:\Users\RaJaMaJa\Desktop\Solve Elec.lnk
2020-11-04 23:34 - 2020-11-04 23:34 - 000000000 ____D C:\Program Files (x86)\Solve Elec 2.5
2020-11-04 12:06 - 2020-11-04 12:07 - 001362834 _____ C:\Users\marys\Downloads\document.pdf
2020-11-02 19:54 - 2020-11-02 19:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-11-02 11:32 - 2020-11-12 14:13 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-10-22 13:12 - 2020-11-12 14:07 - 000000000 ____D C:\Users\janac\AppData\Local\CrashDumps
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-18 17:00 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-18 16:56 - 2020-08-16 20:28 - 000000000 ____D C:\Users\marys
2020-11-18 16:47 - 2020-08-16 21:07 - 000813738 _____ C:\WINDOWS\system32\perfh015.dat
2020-11-18 16:47 - 2020-08-16 21:07 - 000165768 _____ C:\WINDOWS\system32\perfc015.dat
2020-11-18 16:47 - 2020-08-16 20:38 - 002872258 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-18 16:47 - 2019-12-07 15:43 - 000787616 _____ C:\WINDOWS\system32\perfh005.dat
2020-11-18 16:47 - 2019-12-07 15:43 - 000175498 _____ C:\WINDOWS\system32\perfc005.dat
2020-11-18 16:47 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2020-11-18 16:43 - 2017-12-28 18:00 - 000000000 ____D C:\Program Files\CCleaner
2020-11-18 16:42 - 2020-08-16 20:40 - 000004278 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2020-11-18 16:42 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-11-18 16:42 - 2017-12-14 23:43 - 000000000 ____D C:\ProgramData\NVIDIA
2020-11-18 16:41 - 2017-12-27 23:17 - 000000000 ___RD C:\Users\RaJaMaJa\OneDrive
2020-11-18 16:40 - 2020-10-16 21:40 - 000000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2020-11-18 16:40 - 2020-08-16 20:40 - 000003986 _____ C:\WINDOWS\system32\Tasks\AVG Secure VPN Update
2020-11-18 16:40 - 2020-08-16 20:40 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-18 16:40 - 2020-08-16 20:28 - 000000000 ____D C:\Users\RaJaMaJa
2020-11-18 16:40 - 2020-08-16 20:26 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-18 16:40 - 2018-11-06 16:53 - 000000676 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job
2020-11-18 16:40 - 2018-11-06 16:53 - 000000580 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000.job
2020-11-18 14:03 - 2017-12-16 14:31 - 000000000 ____D C:\ProgramData\Avg
2020-11-18 12:50 - 2020-10-16 21:40 - 000003128 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-11-18 12:50 - 2020-10-15 16:35 - 000002966 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper
2020-11-18 12:50 - 2020-10-15 08:45 - 000003752 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1602747943
2020-11-18 12:50 - 2020-10-15 08:45 - 000003498 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1602747936
2020-11-18 12:50 - 2020-08-16 20:40 - 000003400 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-11-18 12:50 - 2020-08-16 20:40 - 000003398 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000003274 _____ C:\WINDOWS\system32\Tasks\G2MUploadTask-S-1-5-21-3853202556-3985030159-1422732261-1000
2020-11-18 12:50 - 2020-08-16 20:40 - 000003196 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000003178 _____ C:\WINDOWS\system32\Tasks\G2MUpdateTask-S-1-5-21-3853202556-3985030159-1422732261-1000
2020-11-18 12:50 - 2020-08-16 20:40 - 000003176 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-11-18 12:50 - 2020-08-16 20:40 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000003136 _____ C:\WINDOWS\system32\Tasks\Intel PTT EK Recertification
2020-11-18 12:50 - 2020-08-16 20:40 - 000003094 _____ C:\WINDOWS\system32\Tasks\Java Platform SE Auto Updater
2020-11-18 12:50 - 2020-08-16 20:40 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-11-18 12:50 - 2020-08-16 20:40 - 000002984 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002914 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3853202556-3985030159-1422732261-1004
2020-11-18 12:50 - 2020-08-16 20:40 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3853202556-3985030159-1422732261-1000
2020-11-18 12:50 - 2020-08-16 20:40 - 000002744 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002602 _____ C:\WINDOWS\system32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE
2020-11-18 12:50 - 2020-08-16 20:40 - 000002534 _____ C:\WINDOWS\system32\Tasks\SamsungMagician
2020-11-18 12:50 - 2020-08-16 20:40 - 000002322 _____ C:\WINDOWS\system32\Tasks\{D6239AB0-B778-428E-B9C8-8256CCBDE2A6}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002282 _____ C:\WINDOWS\system32\Tasks\{4CA0A453-8AD1-4F66-AA07-B7CD34FBDC60}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002238 _____ C:\WINDOWS\system32\Tasks\{63EF4212-718E-4D7E-A464-75EE5F0C768A}
2020-11-18 12:50 - 2020-08-16 20:40 - 000002220 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-11-18 12:50 - 2020-08-16 20:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-11-18 07:51 - 2018-03-25 17:57 - 000000000 ____D C:\ProgramData\Autodesk
2020-11-18 07:41 - 2018-10-07 16:08 - 000000000 ___RD C:\Users\marys\OneDrive
2020-11-17 23:47 - 2019-12-07 10:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-11-16 18:01 - 2018-07-28 09:02 - 000000000 ____D C:\Users\janac\AppData\Local\Packages
2020-11-15 23:00 - 2018-02-17 16:17 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\vlc
2020-11-15 21:43 - 2017-12-27 23:15 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\Packages
2020-11-15 20:58 - 2020-03-24 07:58 - 000002368 _____ C:\Users\marys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-15 14:36 - 2019-01-13 10:05 - 000000000 ____D C:\Users\marys\AppData\Local\D3DSCache
2020-11-15 12:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-15 12:52 - 2020-06-13 19:10 - 000000000 ____D C:\Users\marys\Desktop\Kuba
2020-11-14 15:34 - 2018-10-07 16:07 - 000000000 ____D C:\Users\marys\AppData\Local\Packages
2020-11-14 10:10 - 2018-03-24 20:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2020-11-14 10:10 - 2016-03-06 23:37 - 000002071 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2020-11-14 10:10 - 2016-03-06 23:37 - 000002061 _____ C:\Users\Public\Desktop\Google Docs.lnk
2020-11-14 09:18 - 2017-12-16 18:44 - 000000000 ____D C:\Program Files\Microsoft Office
2020-11-13 13:15 - 2020-03-16 18:35 - 000002383 _____ C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-13 13:15 - 2020-03-16 18:35 - 000002375 _____ C:\Users\RaJaMaJa\Desktop\Microsoft Teams.lnk
2020-11-13 08:10 - 2017-12-14 23:12 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-13 08:10 - 2017-12-14 23:12 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-13 07:58 - 2020-10-15 08:45 - 000001409 _____ C:\Users\marys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2020-11-12 23:27 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-12 23:27 - 2017-12-27 23:32 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\PlaceholderTileLogoFolder
2020-11-12 22:31 - 2017-12-16 19:29 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\ElevatedDiagnostics
2020-11-12 18:55 - 2017-12-28 17:59 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\CrashDumps
2020-11-12 14:13 - 2018-07-28 09:04 - 000000000 ____D C:\Users\janac\AppData\LocalLow\Mozilla
2020-11-12 14:05 - 2020-06-13 17:01 - 000000000 ____D C:\Users\marys\AppData\LocalLow\Mozilla
2020-11-11 13:11 - 2020-06-14 10:00 - 000134792 _____ (AVG Technologies) C:\WINDOWS\system32\icarus_rvrt.exe
2020-11-11 12:32 - 2019-04-14 13:38 - 000000000 ____D C:\Users\marys\AppData\Roaming\vlc
2020-11-11 07:42 - 2018-10-31 16:04 - 000000000 ____D C:\Users\marys\AppData\Local\CrashDumps
2020-11-09 15:43 - 2020-10-16 21:44 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\activdashboard
2020-11-09 15:04 - 2020-10-16 21:40 - 000000000 ____D C:\ProgramData\Promethean
2020-11-07 19:23 - 2018-05-25 20:18 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\D3DSCache
2020-11-07 19:22 - 2019-04-23 21:23 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\Ubisoft Game Launcher
2020-11-07 19:03 - 2016-03-06 23:34 - 000000241 _____ C:\Users\RaJaMaJa\Desktop\Servis24.txt
2020-11-07 19:00 - 2019-04-23 21:23 - 000001310 _____ C:\Users\RaJaMaJa\Desktop\Ubisoft Connect.lnk
2020-11-07 19:00 - 2019-04-23 21:23 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2020-11-07 18:56 - 2018-12-10 23:22 - 000000000 ____D C:\Users\RaJaMaJa\Desktop\Autodesk
2020-11-06 20:08 - 2020-03-20 16:44 - 000002368 _____ C:\Users\janac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-06 20:08 - 2020-03-20 16:44 - 000002360 _____ C:\Users\janac\Desktop\Microsoft Teams.lnk
2020-11-04 07:41 - 2017-12-16 19:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-11-02 19:54 - 2017-12-16 19:12 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-02 07:59 - 2020-03-23 08:25 - 000921624 _____ C:\img2-001.raw
2020-10-27 08:30 - 2020-08-16 20:28 - 000002365 _____ C:\Users\marys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-10-27 08:09 - 2020-08-16 20:28 - 000002374 _____ C:\Users\RaJaMaJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-10-21 17:21 - 2018-11-06 16:53 - 000000000 ____D C:\Users\RaJaMaJa\AppData\Local\GoToMeeting
2020-10-19 07:24 - 2020-09-08 15:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
==================== Files in the root of some directories ========
2020-11-04 23:35 - 2020-11-04 23:35 - 000000363 _____ () C:\Users\RaJaMaJa\AppData\Roaming\Solve Elec 2.5 Prefs
2019-10-07 19:20 - 2019-10-07 19:20 - 000007605 _____ () C:\Users\RaJaMaJa\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================