Preventivní kontrola logu
Napsal: 17 zář 2021 09:55
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-09-2021
Ran by Marcelka a Pavlíček (administrator) on DESKTOP-79A5PSH (LENOVO 20089) (17-09-2021 10:45:33)
Running from C:\Users\Marcelka a Pavlíček\Downloads
Loaded Profiles: Marcelka a Pavlíček
Platform: Windows 10 Home Version 21H1 19043.1237 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\NisSrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Xiaomi Technology Inc -> ) C:\Users\Marcelka a Pavlíček\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3951280 2016-01-07] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706344 2021-06-09] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3884071663-162100166-419435186-1001\...\Run: [MiPhoneManager] => C:\Users\Marcelka a Pavlíček\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-03-11] (Xiaomi Technology Inc -> )
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0044AF1F-F4CE-4DCB-B545-FD897F0105F2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {317C1B9C-D764-46D6-A369-FDF50F955F64} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7E8F6813-90DF-47D2-9BAA-E55865327CF9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.)
Task: {D9CA9A21-78FB-42F4-BA8B-E260ADA0C99B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E1E15941-1A3D-4F18-BAEB-2C0F75237C1A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [680888 2021-09-07] (Mozilla Corporation -> Mozilla Foundation)
Task: {E66088B2-0522-4584-B812-AE8D6CB45B41} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{6c242e33-4261-4d0b-a821-86a78574e0a0}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9ea2f77b-4681-4f2a-a8b5-723fe2cfe311}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{a4d78430-550a-4fd0-b1c6-9da366229c8b}: [DhcpNameServer] 192.168.0.1
Edge:
=======
DownloadDir: C:\Users\Marcelka a Pavlíček\Downloads
Edge HomeButtonPage: HKU\S-1-5-21-3884071663-162100166-419435186-1001 -> hxxp://www.seznam.cz/
Edge Notifications: HKU\S-1-5-21-3884071663-162100166-419435186-1001 -> hxxps://www.tipsport.cz
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (uBlock Origin) -> EdgeExtension_37833NikRollsuBlockOrigin_f8jsg5mm64m62 => C:\Program Files\WindowsApps\37833NikRolls.uBlockOrigin_1.15.24.0_neutral__f8jsg5mm64m62 [2020-04-11]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (Translator pro Microsoft Edge) -> MicrosoftTranslate_MicrosoftTranslatorforMicrosoftEdge_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.TranslatorforMicrosoftEdge_0.91.51.0_neutral__8wekyb3d8bbwe [2020-04-11]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Profile 1
Edge Profile: C:\Users\Marcelka a Pavlíček\AppData\Local\Microsoft\Edge\User Data\Guest Profile [2020-09-07]
Edge Profile: C:\Users\Marcelka a Pavlíček\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2021-09-17]
Edge StartupUrls: Profile 1 -> "hxxp://www.seznam.cz/"
FireFox:
========
FF DefaultProfile: 75qnsple.default
FF ProfilePath: C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\75qnsple.default [2019-08-28]
FF ProfilePath: C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release [2021-09-17]
FF Homepage: Mozilla\Firefox\Profiles\l82wqagt.default-release -> www.seznam.cz
FF Session Restore: Mozilla\Firefox\Profiles\l82wqagt.default-release -> is enabled.
FF Notifications: Mozilla\Firefox\Profiles\l82wqagt.default-release -> hxxps://www.aliexpress.com
FF Extension: (Copy PlainText) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\copyplaintext@eros.man.xpi [2021-03-05]
FF Extension: (LeechBlock NG) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\leechblockng@proginosko.com.xpi [2021-07-05]
FF Extension: (uBlock Origin) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\uBlock0@raymondhill.net.xpi [2021-07-31]
FF Extension: (ImTranslator: Překladač, Slovník, Hlas) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2021-08-13]
FF Plugin-x32: @java.com/DTPlugin,version=11.301.2 -> C:\Program Files (x86)\Java\jre1.8.0_301\bin\dtplugin\npDeployJava1.dll [2021-08-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.301.2 -> C:\Program Files (x86)\Java\jre1.8.0_301\bin\plugin2\npjp2.dll [2021-08-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.14 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-09-09] (Adobe Inc. -> Adobe Systems Inc.)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7785656 2021-09-14] (Malwarebytes Inc -> Malwarebytes)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13271336 2021-09-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\NisSrv.exe [2772856 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe [136640 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [210344 2021-09-14] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-09-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-09-14] (Malwarebytes Inc -> Malwarebytes)
S3 nmwcd; C:\WINDOWS\system32\drivers\ccdcmbx64.sys [19968 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\WINDOWS\system32\drivers\ccdcmbox64.sys [27136 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltx64.sys [9216 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltjx64.sys [9216 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2021-09-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [433384 2021-09-09] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86264 2021-09-09] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-17 10:45 - 2021-09-17 10:46 - 000013413 _____ C:\Users\Marcelka a Pavlíček\Downloads\FRST.txt
2021-09-17 10:45 - 2021-09-17 10:46 - 000000000 ____D C:\FRST
2021-09-17 10:44 - 2021-09-17 10:44 - 002304000 _____ (Farbar) C:\Users\Marcelka a Pavlíček\Downloads\FRST64.exe
2021-09-15 14:23 - 2021-09-15 14:23 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-09-15 14:23 - 2021-09-15 14:23 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-09-15 14:23 - 2021-09-15 14:23 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-09-15 14:23 - 2021-09-15 14:23 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2021-09-15 14:23 - 2021-09-15 14:23 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2021-09-15 14:23 - 2021-09-15 14:23 - 000011355 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-09-15 14:11 - 2021-09-15 14:11 - 000000000 ___HD C:\$WinREAgent
2021-09-14 19:02 - 2021-09-14 19:02 - 000210344 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-09-14 18:48 - 2021-09-14 18:48 - 002101944 _____ (Malwarebytes) C:\Users\Marcelka a Pavlíček\Downloads\MBSetup-119967.119967-consumer.exe
2021-09-08 14:22 - 2021-09-08 14:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-09-07 18:24 - 2021-09-16 17:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-09-04 10:41 - 2021-09-04 10:41 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-09-04 10:40 - 2021-09-04 10:40 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
2021-09-04 10:40 - 2021-09-04 10:40 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-09-04 10:40 - 2021-09-04 10:40 - 001393480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-09-04 10:40 - 2021-09-04 10:40 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-09-04 10:40 - 2021-09-04 10:40 - 001313608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-09-04 10:40 - 2021-09-04 10:40 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-09-04 10:40 - 2021-09-04 10:40 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-09-04 10:40 - 2021-09-04 10:40 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-09-04 10:39 - 2021-09-04 10:39 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
2021-09-04 10:39 - 2021-09-04 10:39 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-09-04 10:39 - 2021-09-04 10:39 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-09-04 10:39 - 2021-09-04 10:39 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-09-04 10:39 - 2021-09-04 10:39 - 000098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-08-27 20:44 - 2021-08-27 20:44 - 000000017 _____ C:\Users\Marcelka a Pavlíček\AppData\Local\resmon.resmoncfg
2021-08-22 19:44 - 2021-08-22 19:45 - 000013750 _____ C:\Users\Marcelka a Pavlíček\Documents\Motivační dopis Pavel Kulhavý.odt
2021-08-18 21:29 - 2021-08-22 19:34 - 000020159 _____ C:\Users\Marcelka a Pavlíček\Desktop\Pavel Kulhavý.odt
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-17 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-09-17 10:45 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-09-17 10:39 - 2019-08-28 22:45 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\LocalLow\Mozilla
2021-09-16 19:05 - 2020-06-08 22:53 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-09-16 17:37 - 2020-06-08 23:00 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-09-16 17:37 - 2019-08-30 20:34 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-09-16 17:29 - 2020-06-08 23:01 - 001696380 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-09-16 17:29 - 2019-12-07 16:41 - 000719042 _____ C:\WINDOWS\system32\perfh005.dat
2021-09-16 17:29 - 2019-12-07 16:41 - 000145638 _____ C:\WINDOWS\system32\perfc005.dat
2021-09-16 17:25 - 2020-11-03 22:33 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-09-16 17:21 - 2020-06-08 23:00 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-09-16 17:20 - 2020-06-08 22:53 - 000457256 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-09-16 17:20 - 2020-06-08 22:53 - 000008192 ___SH C:\DumpStack.log.tmp
2021-09-16 17:20 - 2019-08-28 22:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-09-16 17:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-09-16 17:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-09-16 17:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-09-16 17:19 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-09-16 17:17 - 2020-11-17 00:29 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Roaming\vlc
2021-09-16 14:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-09-15 14:25 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-09-15 14:10 - 2019-08-28 23:03 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-09-15 14:03 - 2019-08-28 23:03 - 135637312 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-09-14 18:55 - 2020-09-12 10:29 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Local\CrashDumps
2021-09-14 18:51 - 2020-11-14 12:13 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-09-14 18:51 - 2020-09-08 22:13 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-09-14 18:50 - 2020-02-11 20:53 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-09-14 18:22 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-09-13 16:16 - 2020-06-08 08:29 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-12 10:05 - 2020-06-08 23:00 - 000003404 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3884071663-162100166-419435186-1001
2021-09-12 10:05 - 2020-06-08 22:33 - 000002419 _____ C:\Users\Marcelka a Pavlíček\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-09-09 18:02 - 2019-08-28 22:28 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-09-08 19:52 - 2020-02-21 11:46 - 000000000 ____D C:\Users\Marcelka a Pavlíček\Documents\Inkaso a další platby
2021-09-08 14:22 - 2019-08-28 22:45 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-09-05 20:40 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2021-09-03 20:43 - 2021-02-21 15:44 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-09-01 09:13 - 2019-08-28 22:38 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Local\Packages
2021-08-31 14:23 - 2019-08-28 22:47 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-08-27 20:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Registration
2021-08-21 13:00 - 2019-09-13 15:51 - 000001435 _____ C:\Users\Marcelka a Pavlíček\Desktop\Roblox Player.lnk
2021-08-21 13:00 - 2019-09-13 15:45 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
==================== Files in the root of some directories ========
2021-02-02 20:55 - 2021-02-02 21:00 - 000000128 _____ () C:\Users\Marcelka a Pavlíček\AppData\Roaming\winscp.rnd
2019-10-01 21:04 - 2021-08-10 20:43 - 000025311 _____ () C:\Users\Marcelka a Pavlíček\AppData\Local\FSDownloader.err
2019-09-22 15:24 - 2021-08-10 20:43 - 000001128 _____ () C:\Users\Marcelka a Pavlíček\AppData\Local\FSDownloader.nast
2021-08-27 20:44 - 2021-08-27 20:44 - 000000017 _____ () C:\Users\Marcelka a Pavlíček\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by Marcelka a Pavlíček (administrator) on DESKTOP-79A5PSH (LENOVO 20089) (17-09-2021 10:45:33)
Running from C:\Users\Marcelka a Pavlíček\Downloads
Loaded Profiles: Marcelka a Pavlíček
Platform: Windows 10 Home Version 21H1 19043.1237 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\NisSrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Xiaomi Technology Inc -> ) C:\Users\Marcelka a Pavlíček\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3951280 2016-01-07] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706344 2021-06-09] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3884071663-162100166-419435186-1001\...\Run: [MiPhoneManager] => C:\Users\Marcelka a Pavlíček\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-03-11] (Xiaomi Technology Inc -> )
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0044AF1F-F4CE-4DCB-B545-FD897F0105F2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {317C1B9C-D764-46D6-A369-FDF50F955F64} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7E8F6813-90DF-47D2-9BAA-E55865327CF9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.)
Task: {D9CA9A21-78FB-42F4-BA8B-E260ADA0C99B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E1E15941-1A3D-4F18-BAEB-2C0F75237C1A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [680888 2021-09-07] (Mozilla Corporation -> Mozilla Foundation)
Task: {E66088B2-0522-4584-B812-AE8D6CB45B41} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe [851472 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{6c242e33-4261-4d0b-a821-86a78574e0a0}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9ea2f77b-4681-4f2a-a8b5-723fe2cfe311}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{a4d78430-550a-4fd0-b1c6-9da366229c8b}: [DhcpNameServer] 192.168.0.1
Edge:
=======
DownloadDir: C:\Users\Marcelka a Pavlíček\Downloads
Edge HomeButtonPage: HKU\S-1-5-21-3884071663-162100166-419435186-1001 -> hxxp://www.seznam.cz/
Edge Notifications: HKU\S-1-5-21-3884071663-162100166-419435186-1001 -> hxxps://www.tipsport.cz
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (uBlock Origin) -> EdgeExtension_37833NikRollsuBlockOrigin_f8jsg5mm64m62 => C:\Program Files\WindowsApps\37833NikRolls.uBlockOrigin_1.15.24.0_neutral__f8jsg5mm64m62 [2020-04-11]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (Translator pro Microsoft Edge) -> MicrosoftTranslate_MicrosoftTranslatorforMicrosoftEdge_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.TranslatorforMicrosoftEdge_0.91.51.0_neutral__8wekyb3d8bbwe [2020-04-11]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Profile 1
Edge Profile: C:\Users\Marcelka a Pavlíček\AppData\Local\Microsoft\Edge\User Data\Guest Profile [2020-09-07]
Edge Profile: C:\Users\Marcelka a Pavlíček\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2021-09-17]
Edge StartupUrls: Profile 1 -> "hxxp://www.seznam.cz/"
FireFox:
========
FF DefaultProfile: 75qnsple.default
FF ProfilePath: C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\75qnsple.default [2019-08-28]
FF ProfilePath: C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release [2021-09-17]
FF Homepage: Mozilla\Firefox\Profiles\l82wqagt.default-release -> www.seznam.cz
FF Session Restore: Mozilla\Firefox\Profiles\l82wqagt.default-release -> is enabled.
FF Notifications: Mozilla\Firefox\Profiles\l82wqagt.default-release -> hxxps://www.aliexpress.com
FF Extension: (Copy PlainText) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\copyplaintext@eros.man.xpi [2021-03-05]
FF Extension: (LeechBlock NG) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\leechblockng@proginosko.com.xpi [2021-07-05]
FF Extension: (uBlock Origin) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\uBlock0@raymondhill.net.xpi [2021-07-31]
FF Extension: (ImTranslator: Překladač, Slovník, Hlas) - C:\Users\Marcelka a Pavlíček\AppData\Roaming\Mozilla\Firefox\Profiles\l82wqagt.default-release\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2021-08-13]
FF Plugin-x32: @java.com/DTPlugin,version=11.301.2 -> C:\Program Files (x86)\Java\jre1.8.0_301\bin\dtplugin\npDeployJava1.dll [2021-08-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.301.2 -> C:\Program Files (x86)\Java\jre1.8.0_301\bin\plugin2\npjp2.dll [2021-08-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.14 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-09-09] (Adobe Inc. -> Adobe Systems Inc.)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7785656 2021-09-14] (Malwarebytes Inc -> Malwarebytes)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13271336 2021-09-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\NisSrv.exe [2772856 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpEng.exe [136640 2021-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [210344 2021-09-14] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-09-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-09-14] (Malwarebytes Inc -> Malwarebytes)
S3 nmwcd; C:\WINDOWS\system32\drivers\ccdcmbx64.sys [19968 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\WINDOWS\system32\drivers\ccdcmbox64.sys [27136 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltx64.sys [9216 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltjx64.sys [9216 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2021-09-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [433384 2021-09-09] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86264 2021-09-09] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-17 10:45 - 2021-09-17 10:46 - 000013413 _____ C:\Users\Marcelka a Pavlíček\Downloads\FRST.txt
2021-09-17 10:45 - 2021-09-17 10:46 - 000000000 ____D C:\FRST
2021-09-17 10:44 - 2021-09-17 10:44 - 002304000 _____ (Farbar) C:\Users\Marcelka a Pavlíček\Downloads\FRST64.exe
2021-09-15 14:23 - 2021-09-15 14:23 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-09-15 14:23 - 2021-09-15 14:23 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-09-15 14:23 - 2021-09-15 14:23 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-09-15 14:23 - 2021-09-15 14:23 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2021-09-15 14:23 - 2021-09-15 14:23 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2021-09-15 14:23 - 2021-09-15 14:23 - 000011355 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-09-15 14:11 - 2021-09-15 14:11 - 000000000 ___HD C:\$WinREAgent
2021-09-14 19:02 - 2021-09-14 19:02 - 000210344 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-09-14 18:48 - 2021-09-14 18:48 - 002101944 _____ (Malwarebytes) C:\Users\Marcelka a Pavlíček\Downloads\MBSetup-119967.119967-consumer.exe
2021-09-08 14:22 - 2021-09-08 14:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-09-07 18:24 - 2021-09-16 17:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-09-04 10:41 - 2021-09-04 10:41 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-09-04 10:40 - 2021-09-04 10:40 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
2021-09-04 10:40 - 2021-09-04 10:40 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-09-04 10:40 - 2021-09-04 10:40 - 001393480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-09-04 10:40 - 2021-09-04 10:40 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-09-04 10:40 - 2021-09-04 10:40 - 001313608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-09-04 10:40 - 2021-09-04 10:40 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-09-04 10:40 - 2021-09-04 10:40 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-09-04 10:40 - 2021-09-04 10:40 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-09-04 10:39 - 2021-09-04 10:39 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
2021-09-04 10:39 - 2021-09-04 10:39 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-09-04 10:39 - 2021-09-04 10:39 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-09-04 10:39 - 2021-09-04 10:39 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-09-04 10:39 - 2021-09-04 10:39 - 000098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-08-27 20:44 - 2021-08-27 20:44 - 000000017 _____ C:\Users\Marcelka a Pavlíček\AppData\Local\resmon.resmoncfg
2021-08-22 19:44 - 2021-08-22 19:45 - 000013750 _____ C:\Users\Marcelka a Pavlíček\Documents\Motivační dopis Pavel Kulhavý.odt
2021-08-18 21:29 - 2021-08-22 19:34 - 000020159 _____ C:\Users\Marcelka a Pavlíček\Desktop\Pavel Kulhavý.odt
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-17 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-09-17 10:45 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-09-17 10:39 - 2019-08-28 22:45 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\LocalLow\Mozilla
2021-09-16 19:05 - 2020-06-08 22:53 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-09-16 17:37 - 2020-06-08 23:00 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-09-16 17:37 - 2019-08-30 20:34 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-09-16 17:29 - 2020-06-08 23:01 - 001696380 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-09-16 17:29 - 2019-12-07 16:41 - 000719042 _____ C:\WINDOWS\system32\perfh005.dat
2021-09-16 17:29 - 2019-12-07 16:41 - 000145638 _____ C:\WINDOWS\system32\perfc005.dat
2021-09-16 17:25 - 2020-11-03 22:33 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-09-16 17:21 - 2020-06-08 23:00 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-09-16 17:20 - 2020-06-08 22:53 - 000457256 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-09-16 17:20 - 2020-06-08 22:53 - 000008192 ___SH C:\DumpStack.log.tmp
2021-09-16 17:20 - 2019-08-28 22:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-09-16 17:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-09-16 17:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-09-16 17:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-09-16 17:19 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-09-16 17:17 - 2020-11-17 00:29 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Roaming\vlc
2021-09-16 14:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-09-15 14:25 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-09-15 14:10 - 2019-08-28 23:03 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-09-15 14:03 - 2019-08-28 23:03 - 135637312 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-09-14 18:55 - 2020-09-12 10:29 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Local\CrashDumps
2021-09-14 18:51 - 2020-11-14 12:13 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-09-14 18:51 - 2020-09-08 22:13 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-09-14 18:50 - 2020-02-11 20:53 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-09-14 18:22 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-09-13 16:16 - 2020-06-08 08:29 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-12 10:05 - 2020-06-08 23:00 - 000003404 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3884071663-162100166-419435186-1001
2021-09-12 10:05 - 2020-06-08 22:33 - 000002419 _____ C:\Users\Marcelka a Pavlíček\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-09-09 18:02 - 2019-08-28 22:28 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-09-08 19:52 - 2020-02-21 11:46 - 000000000 ____D C:\Users\Marcelka a Pavlíček\Documents\Inkaso a další platby
2021-09-08 14:22 - 2019-08-28 22:45 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-09-05 20:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-09-05 20:40 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2021-09-03 20:43 - 2021-02-21 15:44 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-09-01 09:13 - 2019-08-28 22:38 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Local\Packages
2021-08-31 14:23 - 2019-08-28 22:47 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-08-27 20:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Registration
2021-08-21 13:00 - 2019-09-13 15:51 - 000001435 _____ C:\Users\Marcelka a Pavlíček\Desktop\Roblox Player.lnk
2021-08-21 13:00 - 2019-09-13 15:45 - 000000000 ____D C:\Users\Marcelka a Pavlíček\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
==================== Files in the root of some directories ========
2021-02-02 20:55 - 2021-02-02 21:00 - 000000128 _____ () C:\Users\Marcelka a Pavlíček\AppData\Roaming\winscp.rnd
2019-10-01 21:04 - 2021-08-10 20:43 - 000025311 _____ () C:\Users\Marcelka a Pavlíček\AppData\Local\FSDownloader.err
2019-09-22 15:24 - 2021-08-10 20:43 - 000001128 _____ () C:\Users\Marcelka a Pavlíček\AppData\Local\FSDownloader.nast
2021-08-27 20:44 - 2021-08-27 20:44 - 000000017 _____ () C:\Users\Marcelka a Pavlíček\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================