Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-02-2022
Ran by Daniel (administrator) on DESKTOP-75DGSK6 (LENOVO 20EGS0QG1V) (28-02-2022 15:18:14)
Running from C:\Users\Daniel\Downloads
Loaded Profiles: Daniel
Platform: Microsoft Windows 10 Pro Version 21H2 19044.1526 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(DriverStore\FileRepository\fn.inf_amd64_700aca387f1cbd51\driver\tphkload.exe ->) (Lenovo -> Lenovo Group Limited) C:\Windows\System32\DriverStore\FileRepository\FN11CD~1.INF\driver\shtctky.exe
(DriverStore\FileRepository\fn.inf_amd64_700aca387f1cbd51\driver\tphkload.exe ->) (Lenovo -> Lenovo Group Limited) C:\Windows\System32\DriverStore\FileRepository\FN11CD~1.INF\driver\tpnumlkd.exe
(DriverStore\FileRepository\fn.inf_amd64_700aca387f1cbd51\driver\tphkload.exe ->) (Lenovo -> Lenovo Group Limited) C:\Windows\System32\DriverStore\FileRepository\FN11CD~1.INF\driver\tposd.exe
(explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\Daniel\AppData\Local\FluxSoftware\Flux\flux.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <13>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(services.exe ->) (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(services.exe ->) (Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\11.0.0.4854\AdskLicensingService\AdskLicensingService.exe
(services.exe ->) (Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Lenovo -> Lenovo Group Limited) C:\Windows\System32\DriverStore\FileRepository\fn.inf_amd64_700aca387f1cbd51\driver\tphkload.exe
(services.exe ->) (Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvwmi64.exe <2>
(services.exe ->) (O2Micro -> BayHubTech/O2Micro International) C:\Windows\System32\drivers\o2flash.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(svchost.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <2>
(svchost.exe ->) (Lenovo -> Lenovo) C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Y Soft Corporation, a.s. -> Y Soft Corporation) C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HotKeysCmds] => "C:\Windows\system32\hkcmd.exe" (No File)
HKLM\...\Run: [Persistence] => "C:\Windows\system32\igfxpers.exe" (No File)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe [1203488 2016-12-05] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
HKLM-x32\...\Run: [Autodesk Genuine Service ] => C:\ProgramData\Autodesk\Genuine Service\x64\GenuineService.exe [2483552 2021-01-07] (Autodesk, Inc. -> Autodesk)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [668376 2021-05-11] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1160408 2017-03-28] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [109324536 2021-03-12] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [SafeQ Client] => C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe [262328 2020-01-03] (Y Soft Corporation, a.s. -> Y Soft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2135673099-4067616780-898855417-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2618248 2022-02-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2135673099-4067616780-898855417-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35646080 2022-02-14] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2135673099-4067616780-898855417-1001\...\Run: [f.lux] => C:\Users\Daniel\AppData\Local\FluxSoftware\Flux\flux.exe [1515848 2021-06-18] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-2135673099-4067616780-898855417-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2135673099-4067616780-898855417-1001\...\MountPoints2: {7561fbb7-d8b3-11eb-9e01-5891cfe38360} - "F:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-2135673099-4067616780-898855417-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [39936 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\PDF-XChange Lite Port Monitor: C:\Windows\system32\pxcpmL.dll [2147072 2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
HKLM\...\Print\Monitors\RICOH Language Monitor2: C:\Windows\system32\rc4mon64.dll [28160 2013-12-26] (Microsoft Windows Hardware Compatibility Publisher -> RICOH CO.,Ltd.)
HKLM\...\Print\Monitors\SafeQ: C:\Windows\system32\SAFEQVS64.DLL [4889600 2019-12-23] () [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\98.0.4758.102\Installer\chrmstp.exe [2022-02-17] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2019-12-24] () [File not signed] <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {03AC9258-D514-491C-A608-CBBCB30B9929} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Schedule #1 created by enrollment client => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {04166A3E-75E2-4CAE-B535-C7B08CE19BE4} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2135673099-4067616780-898855417-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4158856 2022-02-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {04ECBAFC-7CCF-4B08-B687-547CFDB64E80} - System32\Tasks\CCleanerSkipUAC - Daniel => C:\Program Files\CCleaner\CCleaner.exe [29764224 2022-02-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {0FF693F4-9018-4267-B0F2-97DB991D1F7D} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Schedule #2 created by enrollment client => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {1B9C72DD-C50E-4604-BF5F-6C5920912056} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Schedule created by enrollment client for renewal of certificate warning => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {1CE51479-BBA5-4D2C-890B-DDB67B3CC60A} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\OS Edition Upgrade event listener created by enrollment client => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {2126C148-7F57-47C5-95ED-FE3D13969809} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Schedule to run OMADMClient by client => C:\Windows\system32\omadmclient.exe [438784 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {2FFA7A8E-E960-4690-8DB4-A5E3C75673CB} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [543536 2016-10-13] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {302FCD32-037C-4900-B266-84EA9F0E9F63} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\PushLaunch => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {4049FAB0-DD72-4DF5-B1E0-DDB4F3770BFF} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4158856 2022-02-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {50719F62-C23F-4191-9340-B7A57B463A6C} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4190296 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {5B04A768-95E6-45F1-B2A7-AA4390B782B1} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\PushRenewal => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {5CCC3B53-F7EC-4A4A-BC42-97D1B6BF97E5} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138600 2022-02-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D0116E0-A009-49DA-AC98-9676AECFE0C8} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Provisioning initiated session => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {638E129F-3949-4CB7-BAC2-40B9EEE44420} - System32\Tasks\GoogleUpdateTaskMachineUA{54EBC1CD-A99E-44A9-B657-5B5182C784ED} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-02-05] (Google LLC -> Google LLC)
Task: {7745ECB2-FCDF-47FB-8021-BFDD92106156} - System32\Tasks\Lenovo\Power Manager\Background monitor => C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe [114112 2021-12-02] (Lenovo -> Lenovo)
Task: {7CE12545-E3C8-4EC8-87E5-DF12D928260F} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-02-14] (Piriform Software Ltd -> Piriform)
Task: {8158EE08-3D17-4650-B5ED-C004306AD39B} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Passport for Work alert created by enrollment client => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {889FFCEF-926A-4435-A420-8317B0A2C206} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8573352 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {8F6519E7-EEC1-4F9E-A05C-9DB647364044} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {92959FBD-2EDD-4372-86AE-B7B28E5E8F0C} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Schedule to run OMADMClient by server => C:\Windows\system32\omadmclient.exe [438784 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {989C0325-7B1D-4965-BFE3-27CB5AC41728} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22880136 2022-02-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {98F07A6B-EBD2-4771-8CC0-8C312423FFF0} - System32\Tasks\Lenovo\Power Manager\Uninstall task => C:\Windows\SysWOW64\PowerMgrInst.exe [63936 2021-12-02] (Lenovo -> )
Task: {AA081E03-BBF1-4046-A922-CD9DC638ADC7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8573352 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B8EAEA85-0360-4964-9C0E-A375836E34A2} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe -autostart (No File)
Task: {BBA61178-AE3D-4F7C-9FAD-DD370D0FBA6E} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Schedule #3 created by enrollment client => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {CC3C36DB-8132-453E-9CD0-472C2F6A099D} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CDA68CE5-8B46-4273-BF16-C0492AD99284} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CE75983D-30C6-4C1D-B83E-43029C58D156} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D28577C0-49EA-4770-BA52-2ECE320B7F5B} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {E89A3BBE-4EEF-48BA-BAD6-4904790E80B5} - System32\Tasks\GoogleUpdateTaskMachineCore{199CC8E4-2AD3-4261-9FA3-70486FA682C5} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-02-05] (Google LLC -> Google LLC)
Task: {E9144194-81C9-4445-A480-6C74E773A113} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22880136 2022-02-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {F22A416A-641F-4ABB-9F30-A3680CFD48D3} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\E7E7C7CF-C745-4D89-BFF9-640969CBD123\Win10 S Mode event listener created by enrollment client => C:\Windows\system32\deviceenroller.exe [448512 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
Task: {FA43421C-B84A-41E5-AC1F-4D867C6F185D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138600 2022-02-20] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 158.196.0.53 158.196.99.166
Tcpip\..\Interfaces\{37b3fdfd-2fcd-4329-aad4-b63c2675a8ba}: [DhcpNameServer] 158.196.0.53 158.196.99.166
Tcpip\..\Interfaces\{e60e57c8-1405-4792-ae01-cbaef02d80ab}: [DhcpNameServer] 192.168.135.1 81.19.0.67 8.8.8.8
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Daniel\AppData\Local\Microsoft\Edge\User Data\Default [2022-02-28]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2019-07-01] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2019-07-01] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=3.0.15 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2135673099-4067616780-898855417-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2135673099-4067616780-898855417-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2135673099-4067616780-898855417-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2019-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
Chrome:
=======
CHR Profile: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default [2022-02-28]
CHR StartupUrls: Default -> "hxxp://
www.pulsetheworld.com/cz/jak-odstranit- ... ://newtab/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Prezentace) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-02-05]
CHR Extension: (Dokumenty) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2022-02-05]
CHR Extension: (Disk Google) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-02-05]
CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-02-05]
CHR Extension: (Tabulky) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-02-05]
CHR Extension: (Dokumenty Google offline) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-02-24]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-02-05]
CHR Extension: (Gmail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-02-05]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1050920 2021-05-11] (Autodesk, Inc. -> Autodesk Inc.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82640 2017-03-28] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [18673448 2020-11-17] (Autodesk, Inc. -> Autodesk)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12124536 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncHelper.exe [3380616 2022-02-26] (Microsoft Corporation -> Microsoft Corporation)
S2 LPlatSvc; C:\Windows\System32\LPlatSvc.exe [892288 2019-12-11] (Lenovo -> Lenovo.)
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [4738952 2019-08-15] (NVIDIA Corporation -> NVIDIA Corporation)
R2 O2FLASH; C:\Windows\SysWOW64\drivers\o2flash.exe [82096 2015-05-21] (O2Micro -> BayHubTech/O2Micro International)
S3 OfficeSvcManagerAddons; C:\Windows\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21312 2021-05-05] (Microsoft Windows -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.022.0130.0001\OneDriveUpdaterService.exe [3851128 2022-02-26] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6136536 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TPHKLOAD; C:\Windows\System32\DriverStore\FileRepository\fn.inf_amd64_700aca387f1cbd51\driver\TPHKLOAD.exe [465200 2020-12-28] (Lenovo -> Lenovo Group Limited)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe [2909208 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe [128376 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R3 O2FJ2RDR; C:\Windows\System32\drivers\O2FJ2x64.sys [201240 2015-05-21] (BayHub Technology Inc. -> BayHubTech/O2Micro)
R0 PMDRVS; C:\Windows\System32\drivers\pmdrvs.sys [38160 2019-12-11] (Lenovo -> Lenovo.)
S3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv64.sys [735744 2016-03-10] (Sunplus Innovation Technology Inc. -> Sunplus)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2022-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [438520 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [90360 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-02-28 15:18 - 2022-02-28 15:18 - 000028590 _____ C:\Users\Daniel\Downloads\FRST.txt
2022-02-28 14:18 - 2022-02-28 14:18 - 000000000 ____D C:\Users\Daniel\AppData\Roaming\Synaptics
2022-02-28 14:13 - 2022-02-28 14:13 - 000000000 ____D C:\Users\Daniel\AppData\Local\mbam
2022-02-28 14:10 - 2022-02-28 14:11 - 000000000 ____D C:\Program Files\Malwarebytes
2022-02-28 09:37 - 2022-02-28 09:37 - 000000158 _____ C:\Windows\system32\ricdb.ini
2022-02-28 09:37 - 2022-02-28 09:37 - 000000000 ____D C:\Users\Daniel\AppData\Local\TempSafeQ
2022-02-28 09:37 - 2022-02-28 09:37 - 000000000 ____D C:\Program Files (x86)\Y Soft
2022-02-28 09:37 - 2022-02-28 09:37 - 000000000 ____D C:\Program Files (x86)\SafeQ
2022-02-28 09:37 - 2019-12-23 10:46 - 004889600 _____ C:\Windows\system32\SAFEQVS64.DLL
2022-02-28 09:37 - 2019-12-23 10:46 - 000911360 _____ C:\Windows\system32\SafeQCairoLib64.DLL
2022-02-28 09:37 - 2019-12-23 10:46 - 000314368 _____ C:\Windows\system32\SAFEQ64UI.DLL
2022-02-28 09:37 - 2019-12-23 10:46 - 000001536 _____ C:\Windows\system32\SafeQEvent.dll
2022-02-10 01:58 - 2022-02-10 01:58 - 000288768 _____ C:\Windows\system32\Windows.Management.InprocObjects.dll
2022-02-10 01:58 - 2022-02-10 01:58 - 000272384 _____ C:\Windows\system32\TpmTool.exe
2022-02-10 01:58 - 2022-02-10 01:58 - 000223744 _____ C:\Windows\SysWOW64\TpmTool.exe
2022-02-10 01:58 - 2022-02-10 01:58 - 000162816 _____ C:\Windows\system32\DataStoreCacheDumpTool.exe
2022-02-10 01:58 - 2022-02-10 01:58 - 000011813 _____ C:\Windows\system32\DrtmAuthTxt.wim
2022-02-10 01:52 - 2022-02-10 01:52 - 000000000 ___HD C:\$WinREAgent
2022-02-08 22:40 - 2022-02-08 22:40 - 000000000 ____D C:\ProgramData\GOG.com
2022-02-08 22:37 - 2022-02-10 17:43 - 000000000 ____D C:\GOG Games
2022-02-05 16:46 - 2022-02-28 15:17 - 002312192 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe
2022-02-05 15:48 - 2022-02-28 15:18 - 000000000 ____D C:\FRST
2022-02-05 15:13 - 2022-02-17 01:19 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-02-05 15:13 - 2022-02-05 15:13 - 000000000 ____D C:\Program Files\Google
2022-02-05 15:12 - 2022-02-05 15:12 - 000003550 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA{54EBC1CD-A99E-44A9-B657-5B5182C784ED}
2022-02-05 15:12 - 2022-02-05 15:12 - 000003426 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore{199CC8E4-2AD3-4261-9FA3-70486FA682C5}
2022-02-05 13:07 - 2022-02-05 13:07 - 000000000 ____D C:\Windows\system32\appmgmt
2022-02-05 12:51 - 2022-02-05 16:16 - 000000140 _____ C:\Windows\Reimage.ini
2022-02-04 21:17 - 2022-02-04 21:17 - 000000000 ____D C:\ProgramData\Daniel
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-02-28 15:19 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-02-28 15:18 - 2021-06-04 11:06 - 000000000 ____D C:\Program Files (x86)\Google
2022-02-28 15:08 - 2019-12-07 10:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2022-02-28 14:53 - 2021-05-05 08:40 - 001694140 _____ C:\Windows\system32\PerfStringBackup.INI
2022-02-28 14:53 - 2019-12-07 15:43 - 000718262 _____ C:\Windows\system32\perfh005.dat
2022-02-28 14:53 - 2019-12-07 15:43 - 000145404 _____ C:\Windows\system32\perfc005.dat
2022-02-28 14:53 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2022-02-28 14:51 - 2021-06-21 20:28 - 000000000 ____D C:\Program Files\CCleaner
2022-02-28 14:49 - 2021-05-31 06:44 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2022-02-28 14:48 - 2021-05-05 09:14 - 000000000 ____D C:\ProgramData\NVIDIA
2022-02-28 14:48 - 2021-05-05 08:33 - 000008192 ___SH C:\DumpStack.log.tmp
2022-02-28 14:48 - 2021-05-05 08:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-02-28 14:48 - 2019-12-07 10:03 - 000786432 _____ C:\Windows\system32\config\BBI
2022-02-28 14:26 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\NDF
2022-02-28 14:24 - 2021-12-10 15:35 - 000000000 ____D C:\Program Files\Recuva
2022-02-28 14:24 - 2021-06-22 07:12 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-02-28 14:24 - 2021-06-21 20:55 - 000000000 ____D C:\Users\Daniel\AppData\Roaming\AIMP
2022-02-28 14:24 - 2021-06-04 10:49 - 000000000 __SHD C:\Users\Daniel\IntelGraphicsProfiles
2022-02-28 14:18 - 2021-06-04 10:50 - 000000000 ____D C:\Users\Daniel\AppData\Local\Packages
2022-02-28 14:18 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-02-28 14:18 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2022-02-28 12:36 - 2021-05-05 08:33 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-02-26 22:15 - 2021-06-22 07:03 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-02-26 22:15 - 2021-06-22 07:03 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-02-26 22:15 - 2021-05-05 09:29 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-02-26 22:01 - 2021-06-21 20:29 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-02-24 18:42 - 2021-06-04 10:47 - 000000000 ____D C:\Users\Daniel
2022-02-24 15:51 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\LiveKernelReports
2022-02-24 07:14 - 2021-06-21 20:53 - 000000000 ____D C:\Users\Daniel\AppData\Roaming\vlc
2022-02-20 21:59 - 2021-06-22 06:56 - 000000000 ____D C:\Program Files\Microsoft Office
2022-02-19 01:33 - 2021-05-05 09:15 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-02-16 20:41 - 2021-12-13 08:03 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2135673099-4067616780-898855417-1001
2022-02-10 02:17 - 2021-05-05 08:33 - 000000000 ____D C:\Windows\system32\Drivers\wd
2022-02-10 02:07 - 2021-05-05 08:33 - 000550200 _____ C:\Windows\system32\FNTCACHE.DAT
2022-02-10 02:06 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\et-EE
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\es-MX
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2022-02-10 02:06 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2022-02-10 02:06 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2022-02-10 02:01 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2022-02-10 01:58 - 2021-05-05 08:36 - 002877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2022-02-10 01:50 - 2021-05-05 09:12 - 000000000 ____D C:\Windows\system32\MRT
2022-02-10 01:38 - 2021-05-05 09:12 - 149611728 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-02-05 15:13 - 2021-06-04 11:05 - 000000000 ____D C:\Users\Daniel\AppData\Local\Google
2022-02-04 21:17 - 2021-06-22 07:27 - 000002369 _____ C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2022-02-04 21:17 - 2021-06-22 07:27 - 000000000 ____D C:\Users\Daniel\AppData\Local\SquirrelTemp
2022-01-29 12:30 - 2021-08-17 18:40 - 000000000 ____D C:\Windows\Minidump
==================== Files in the root of some directories ========
2021-12-10 16:00 - 2021-12-10 16:00 - 000000048 _____ () C:\Users\Daniel\AppData\Roaming\pfpath.ini
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================