
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-12-2019
Ran by Admin (administrator) on DESKTOP-FESK4CA (ASUSTeK Computer Inc. K52F) (07-12-2019 09:44:54)
Running from C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\3HRQQEHY
Loaded Profiles: Admin (Available Profiles: Admin)
Platform: Windows 10 Home Version 1809 17763.195 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Malwarebytes Inc -> Malwarebytes) C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\3HRQQEHY\adwcleaner_8.0.0[1].exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MsMpEng.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKU\S-1-5-21-695600495-1735540645-183756443-1001\...\MountPoints2: {074c70ef-0112-11e9-bfff-806e6f6e6963} - "D:\setup.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-18] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.119\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1A1E2C68-BFDE-44EF-89DF-E90669C6A4FC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\MpCmdRun.exe [470176 2019-07-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1AEDAE2C-0B3F-459C-8410-6A3D5F4AD000} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-12-16] (Google Inc -> Google Inc.)
Task: {2CFC9E66-5C01-43B9-BFCA-42A24A707BC0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\MpCmdRun.exe [470176 2019-07-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {46714C5E-A984-4F54-AC8C-EE6ACE3C5A6A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-17] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {8BA0459C-8BAA-4F34-8660-CF250762B48A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\MpCmdRun.exe [470176 2019-07-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D6C7B5F8-3033-45F4-A9AF-EBC18CB19D60} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-12-16] (Google Inc -> Google Inc.)
Task: {D6FCE291-5482-42EB-88A7-A1A6516833B8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\MpCmdRun.exe [470176 2019-07-11] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{28a160c6-c54f-4318-b989-b1384e957ab1}: [NameServer] 217.77.165.81,217.77.165.211
Internet Explorer:
==================
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-16] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-16] (Google Inc -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-03] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Guest Profile
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default [2019-07-13]
CHR Extension: (Prezentace) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-16]
CHR Extension: (Dokumenty) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-16]
CHR Extension: (Disk Google) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-16]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-16]
CHR Extension: (Tabulky) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-23]
CHR Extension: (WebmailWorld) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\knoiojiiponkbflbljpefepdjlnifhdn [2019-06-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-16]
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-16]
CHR Extension: (Chrome Media Router) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-15]
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-12-05]
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\System Profile [2019-12-05]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\NisSrv.exe [2455544 2019-07-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\MsMpEng.exe [110104 2019-07-11] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 cxwmbclass; C:\Windows\System32\drivers\cxwmbclass.sys [123392 2018-12-16] (Microsoft Windows -> Microsoft Corporation)
S3 NETJME; C:\Windows\System32\drivers\NETJME.sys [137728 2018-09-15] (Microsoft Windows -> JMicron Technology Corp.)
S3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [8206848 2018-09-15] (Microsoft Windows -> Realtek Semiconductor Corporation )
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [47704 2019-07-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [367032 2019-07-11] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [54200 2019-07-11] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-07 09:44 - 2019-12-07 09:45 - 000000000 ____D C:\FRST
2019-12-05 12:31 - 2019-12-05 12:31 - 000000000 ____D C:\Users\Admin\AppData\Roaming\LibreOffice
2019-12-05 12:26 - 2019-12-05 12:29 - 000000000 ____D C:\AdwCleaner
2019-12-05 12:25 - 2019-12-05 12:25 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2019-12-05 10:40 - 2019-12-05 10:40 - 000000000 ___HD C:\$WINDOWS.~BT
2019-12-05 10:35 - 2019-12-05 11:59 - 000001908 _____ C:\Windows\diagwrn.xml
2019-12-05 10:35 - 2019-12-05 11:59 - 000001908 _____ C:\Windows\diagerr.xml
2019-12-05 00:03 - 2019-12-05 00:03 - 000000000 ____D C:\Windows\pss
2019-12-04 23:14 - 2019-12-04 23:47 - 000000000 ___HD C:\$SysReset
2019-12-02 00:05 - 2019-12-02 00:05 - 000000000 ____D C:\Windows\system32\Tasks\S-1-5-21-695600495-1735540645-183756443-1001
2019-12-01 23:14 - 2019-12-01 23:14 - 000008192 _____ C:\Windows\system32\config\userdiff
2019-12-01 22:50 - 2019-12-04 23:53 - 000000000 _____ C:\Recovery.txt
2019-12-01 21:44 - 2019-12-01 21:48 - 000000000 _____ C:\Users\Admin\AppData\Local\{CB4757B9-795D-4C4F-A6FA-5D71CB51EA08}
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-07 09:41 - 2018-12-16 10:07 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-12-07 04:22 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-12-05 12:34 - 2018-12-16 10:21 - 001606102 _____ C:\Windows\system32\PerfStringBackup.INI
2019-12-05 12:34 - 2018-09-15 18:32 - 000683600 _____ C:\Windows\system32\perfh005.dat
2019-12-05 12:34 - 2018-09-15 18:32 - 000137282 _____ C:\Windows\system32\perfc005.dat
2019-12-05 12:34 - 2018-09-15 08:31 - 000000000 ____D C:\Windows\INF
2019-12-05 12:30 - 2018-12-16 10:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-12-05 12:29 - 2018-09-15 07:09 - 000524288 _____ C:\Windows\system32\config\BBI
2019-12-04 23:47 - 2018-12-27 12:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty 4 - Modern Warfare
2019-12-04 23:47 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2019-12-04 23:46 - 2018-09-15 08:31 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2019-12-04 21:39 - 2019-07-12 18:17 - 000000000 ____D C:\Users\Admin\AppData\Local\ElevatedDiagnostics
2019-12-02 00:11 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\LiveKernelReports
2019-12-01 23:15 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\system32\oobe
2019-12-01 21:49 - 2018-12-16 10:21 - 000000000 ____D C:\Users\Admin
==================== Files in the root of some directories ========
2019-12-01 21:44 - 2019-12-01 21:48 - 000000000 _____ () C:\Users\Admin\AppData\Local\{CB4757B9-795D-4C4F-A6FA-5D71CB51EA08}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================