

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-07-2020 01
Ran by udrzbaaqp (administrator) on DESKTOP-POLALO5 (Dell Inc. Latitude 5580) (07-07-2020 12:56:53)
Running from C:\Users\udrzbaaqp\Desktop
Loaded Profiles: udrzbaaqp
Platform: Windows 10 Pro Version 1703 15063.1418 (X64) Language: Slovenčina (Slovensko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidMonitorSvc.exe
(Andrey Gruber) [File not signed] C:\Ečko\Programy\PNotes_9_3_0\PNotes\PNotes.exe
(Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Endpoint Security\egui.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe
(Geek Software GmbH -> Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <17>
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Network Platform Group -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6742a32d2d482a17\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6742a32d2d482a17\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6742a32d2d482a17\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6742a32d2d482a17\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_eea3cf789013ad4f\RstMwService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CastSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2006.10-0\MsMpEng.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7106.1428\DSAPI.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIRFE.EXE <2>
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.1000_x64__kzf8qxf38zg5c\SkypeHost.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [779376 2019-01-07] (ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11235928 2020-02-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-02-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [318920 2019-05-30] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [WavesSvc] => c:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1235160 2019-09-26] (Waves Inc -> Waves Audio Ltd.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [82183912 2019-07-11] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [479368 2020-01-15] (Geek Software GmbH -> Geek Software GmbH)
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1591160 2020-06-28] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe [23844664 2020-06-22] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIRFE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIRFE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\...\Run: [com.squirrel.Teams.Teams] => C:\Users\udrzbaaqp\AppData\Local\Microsoft\Teams\Update.exe [1789768 2019-08-26] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\...\MountPoints2: {6dd2d4b8-6b64-11e9-9ce8-f85971a8590c} - "D:\Lenovo_Suite.exe"
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\...\MountPoints2: {d5717618-fc7b-11e8-9cdb-d481d7f7f5c5} - "D:\Lenovo_Suite.exe"
HKLM\...\Print\Monitors\C368SeriesPCL Language Monitor: C:\Windows\system32\KOAXWJ_L.DLL [25600 2017-08-28] (Microsoft Windows Hardware Compatibility Publisher -> KONICA MINOLTA, INC.)
HKLM\...\Print\Monitors\EPSON XP-243 245 247 Series 64MonitorBE: C:\Windows\system32\E_YLMBRFE.DLL [182784 2015-12-08] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\...\Print\Monitors\IppMon: C:\Windows\system32\IPPMon.dll [225792 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.116\Installer\chrmstp.exe [2020-06-25] (Google LLC -> Google LLC)
HKLM\Software\...\Winlogon\GPExtensions: [{6490DB9D-2802-4956-BCCB-EC84EA0887BB}] -> C:\Program Files\Windows Small Business Server\Bin\SBSCSE.dll [2010-11-08] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{9650FDBC-053A-4715-AD14-FC2DC65E8330}] -> C:\Windows\system32\hvsigpext.dll [2017-07-08] (Microsoft Windows -> )
HKLM\Software\...\Winlogon\GPExtensions: [{D7300225-081C-4CED-9FAD-BFCF9EC3D1D3}] -> C:\Program Files\Windows Small Business Server\Bin\SBSCSE.dll [2010-11-08] (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\udrzbaaqp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PNotes.lnk [2019-01-24]
ShortcutTarget: PNotes.lnk -> C:\Ečko\Programy\PNotes_9_3_0\PNotes\PNotes.exe (Andrey Gruber) [File not signed]
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {063C2EB0-C7C3-4967-A709-0B41EAFC2307} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124776 2020-06-22] (Microsoft Corporation -> Microsoft Corporation)
"C:\Windows\System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected" was unlocked. <==== ATTENTION
Task: {17682665-60E1-442B-BB3A-EA36D030D068} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {21CD68F9-E2F6-4983-AB2E-FF80256C782A} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {3579EDA6-2001-47A0-9ECC-8EFCD1B3F07F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2018-12-04] (Google Inc -> Google Inc.)
Task: {3EAB45F4-FAD5-450D-ABA4-B23CB03D3149} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2018-12-04] (Google Inc -> Google Inc.)
Task: {3EAB8EB2-3643-4622-A352-BBAE99DE029F} - System32\Tasks\SystemToolsDailyTest => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1154008 2017-04-18] (Dell Inc. -> PC-Doctor, Inc.)
Task: {4546D6DE-FE8B-4ECE-AC99-7806FED0BAE0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MpCmdRun.exe [512272 2020-07-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {46FF2EBB-749F-4308-8566-9B6D84F19CAC} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2742136 2020-06-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {4D36AC81-46A7-4865-BB1F-7A2C4B7CACD7} - System32\Tasks\EPSON XP-243 245 247 Series Update {E2A961FB-51F3-4705-9BA5-637791BA99F3} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSRFE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {5EFC4D4F-E8C1-4B0C-B039-0CAB4DFAC595} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MpCmdRun.exe [512272 2020-07-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {63C040FF-CF67-4B86-A477-E367A9BF3308} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Ečko\Zálohy\Chrome down\esetonlinescanner_csy.exe LOGON
Task: {76F98DD7-042D-446C-B98D-9618D88D70A2} - System32\Tasks\EOSv3 Scheduler onTime => C:\Ečko\Zálohy\Chrome down\esetonlinescanner_csy.exe SCHED
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202}" was unlocked. <==== ATTENTION
Task: {87CD0E90-C76C-4335-8E9F-53EC5C7955CC} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\Windows\system32\gpupdate.exe [29696 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
Task: {9FDD784C-1446-4E59-83FA-307791146B69} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1321368 2020-06-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {A87A9330-A53D-4B41-90A6-2A6CFC09D51E} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {AFED2D50-27A6-4BE3-A0ED-F6B3E3B1A793} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MpCmdRun.exe [512272 2020-07-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C10D8BCB-81BC-4894-9F3E-D138B6B8DECE} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {C7C3CF0B-0E44-4B7B-81B1-69F49239E66D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23756168 2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {CB9FE7FA-DC00-4A99-BB02-AEDD619ABC22} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23756168 2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {CBD7C947-26AB-47BA-BCEC-FDC0AE972336} - System32\Tasks\EPSON XP-243 245 247 Series Update {13ACEA1D-E802-48E9-BCE9-7C74B0CAF84C} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSRFE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {D03D7F87-E8CF-4A12-824D-DE473E4714FE} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1553880 2020-05-03] (Dell Inc. -> Dell Inc.)
Task: {DA418FF9-212E-434A-928B-58E24B37F6CE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MpCmdRun.exe [512272 2020-07-02] (Microsoft Windows Publisher -> Microsoft Corporation)
"C:\Windows\System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up" was unlocked. <==== ATTENTION
Task: {DF260172-B53C-4049-A24A-C22637E9A3AF} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2302168 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {F1387B19-AE8C-4F65-AAC9-46F3D7188521} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124776 2020-06-22] (Microsoft Corporation -> Microsoft Corporation)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA}" was unlocked. <==== ATTENTION
Task: {F2BD8E11-1CB9-4F07-9937-666038E0CA7C} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\Windows\system32\gpupdate.exe [29696 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
Task: {F687CD97-A0B7-4AE5-986E-2244B3A4B3DE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {FB80F54B-77F2-4BBD-822A-28B59B55CF50} - System32\Tasks\PCDDataUploadTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1154008 2017-04-18] (Dell Inc. -> PC-Doctor, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\EPSON XP-243 245 247 Series Update {13ACEA1D-E802-48E9-BCE9-7C74B0CAF84C}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSRFE.EXE:/EXE:{13ACEA1D-E802-48E9-BCE9-7C74B0CAF84C} /F:UpdateTHERME\DESKTOP-POLALO5$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-243 245 247 Series Update {E2A961FB-51F3-4705-9BA5-637791BA99F3}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSRFE.EXE:/EXE:{E2A961FB-51F3-4705-9BA5-637791BA99F3} /F:UpdateTHERME\DESKTOP-POLALO5$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{e2cb4e83-ff22-4e83-8d4a-7bd8a6a9a3bc}: [DhcpNameServer] 208.91.112.53 208.91.112.52
Tcpip\..\Interfaces\{f82cf98f-69c3-425b-ae5c-8530af3ed851}: [DhcpNameServer] 192.168.0.9
Internet Explorer:
==================
HKU\S-1-5-21-1142325245-130890802-2529674674-2207\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1142325245-130890802-2529674674-2207 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-13] (Microsoft Corporation -> Microsoft Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2020-01-13] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF Extension: (Adblocker na Youtube™) - C:\Program Files\Mozilla Firefox\browser\features\{733ED5DC-6D54-4A04-900B-CA85BF4B9A1B}.xpi [2018-12-02] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2019-10-16] [Legacy] [not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-05-04] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1142325245-130890802-2529674674-2207: @zoom.us/ZoomVideoPlugin -> C:\Users\udrzbaaqp\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-04-22] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default [2020-07-07]
CHR DownloadDir: C:\Ečko\Zálohy\Chrome down
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://vosveteit.sk; hxxps://www.autodoc.sk; hxxps://www.facebook.com; hxxps://www.tyzden.sk; hxxps://www.viry.cz
CHR Extension: (Prezentácie) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-04]
CHR Extension: (Dokumenty) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-04]
CHR Extension: (Disk Google) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-04]
CHR Extension: (YouTube) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-04]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-07-04]
CHR Extension: (Chrome Remote Desktop) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmjfjelnicpmdcmfikempdhlmainjcb [2020-04-23]
CHR Extension: (Tabuľky) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-04]
CHR Extension: (Vzdialená plocha Chrome) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-11-06]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-05-31]
CHR Extension: (Google Calendar) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2020-06-12]
CHR Extension: (Chrome Remote Desktop) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2019-11-06]
CHR Extension: (Mapy Google) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\jofhmakmcmhjkgbkaknehpglphepfmii [2020-04-27]
CHR Extension: (10 skrytých funkcií v prehliadači Google Chrome, ktoré Vám uľahčia život. Poznáte ich? | Vosveteit.sk) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nedagfinghcpjjpcopcghojnmolfeoil [2019-10-05]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-06]
CHR Extension: (TeamViewer) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\oooiobdokpcfdlahlmcddobejikcmkfo [2019-11-19]
CHR Extension: (Ocean) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgedigcdbemilinbicidhplhebjoafpl [2018-12-04]
CHR Extension: (Gmail) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-06-10]
CHR Extension: (Stopky / časovač / Budík) - C:\Users\udrzbaaqp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmbmdkichekkmkgbohcbpfehiekdjnpl [2018-12-04]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [118952 2019-01-07] (ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.)
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\84.0.4147.39\remoting_host.exe [73200 2020-06-08] (Google LLC -> Spoločnosť Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [10634632 2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
S3 dcpm-notify; C:\Program Files\Dell\CommandPowerManager\NotifyService.exe [86048 2017-08-16] (Dell Inc -> Dell Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [248376 2020-01-22] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3359288 2020-01-22] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [271416 2020-01-22] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7106.1428\DSAPI.exe [965104 2020-05-10] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
S3 Dell.CommandPowerManager.Service; C:\Windows\system32\dllhost.exe /Processid:{D0FBE4E3-CEB7-4D1E-9F87-E7AB8A3A1F01} [21408 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
S3 Dell.CommandPowerManager.Service; C:\Windows\system32\dllhost.exe /Processid:{D0FBE4E3-CEB7-4D1E-9F87-E7AB8A3A1F01} [21408 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [36544 2020-04-17] (Dell Inc -> )
S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany) [File not signed]
S2 EHttpSrv; C:\Program Files\ESET\ESET Endpoint Security\ehttpsrv.exe [43208 2015-11-27] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe [1612000 2015-11-27] (ESET, spol. s r.o. -> ESET)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [145224 2016-11-08] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S3 eshasrv; C:\Program Files\ESET\ESET Endpoint Security\eshasrv.exe [185032 2015-11-27] (ESET, spol. s r.o. -> ESET)
S3 FileSyncHelper; C:\Program Files (x86)\Microsoft OneDrive\FileSyncHelper.exe [2157944 2020-06-28] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6970968 2020-07-07] (Malwarebytes Inc -> Malwarebytes)
S3 OneDrive Updater Service; C:\Program Files (x86)\Microsoft OneDrive\OneDriveUpdaterService.exe [2511216 2020-06-28] (Microsoft Corporation -> Microsoft Corporation)
R2 PDF24; C:\Program Files (x86)\PDF24\pdf24.exe [479368 2020-01-15] (Geek Software GmbH -> Geek Software GmbH)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [269600 2020-02-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2018-06-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [38360 2020-05-03] (Dell Inc. -> Dell Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13109264 2020-06-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [2302168 2018-12-25] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\NisSrv.exe [2496144 2020-07-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MsMpEng.exe [104192 2020-07-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3753016 2019-08-19] (Intel Corporation -> Intel® Corporation)
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Wondershare MobileTrans\DriverInstall.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 522A849C; C:\Windows\System32\drivers\522A849C.sys [478392 2020-07-06] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 ApHidfiltrService; C:\Windows\System32\drivers\ApHidfiltr.sys [370344 2019-01-07] (ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.)
S3 BthMtpEnum; C:\Windows\system32\DRIVERS\BthMtpEnum.sys [68096 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [35704 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
S3 DellProf; C:\Windows\system32\drivers\DellProf.sys [41208 2018-05-08] (Techporch Incorporated -> Dell Computer Corporation)
S3 DroidCam; C:\Windows\system32\DRIVERS\droidcam.sys [32240 2020-04-10] (Microsoft Windows Hardware Compatibility Publisher -> Dev47Apps)
S3 DroidCamVideo; C:\Windows\system32\DRIVERS\droidcamvideo.sys [33768 2020-04-18] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 e1dexpress; C:\Windows\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_63a4db11c926c9ab\e1d68x64.sys [606672 2019-08-06] (Intel(R) INTELND1820 -> Intel Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [253752 2015-11-11] (ESET, spol. s r.o. -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [186272 2015-11-11] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [205288 2015-11-11] (ESET, spol. s r.o. -> ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [52872 2015-11-11] (ESET, spol. s r.o. -> ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [69328 2015-11-11] (ESET, spol. s r.o. -> ESET)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153312 2020-07-07] (Malwarebytes Corporation -> Malwarebytes)
S3 FTDIBUS; C:\Windows\system32\drivers\ftdibus.sys [68800 2008-03-13] (Future Technology Devices International Ltd -> FTDI Ltd.)
S3 FTSER2K; C:\Windows\system32\drivers\ftser2k.sys [86376 2013-07-12] (Future Technology Devices International Ltd -> FTDI Ltd.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [216056 2020-07-07] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2020-07-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [196752 2020-07-07] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73368 2020-07-07] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-07-07] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [131728 2020-07-07] (Malwarebytes Inc -> Malwarebytes)
S3 mosuport; C:\Windows\System32\drivers\mosuport.sys [367744 2016-12-23] (WDKTestCert Alex,130940336584439605 -> ASIX Electronics Corporation)
R1 MpKslDrv; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3059821F-412C-4E13-9032-16BE2E89618A}\MpKslDrv.sys [43232 2020-07-07] (Microsoft Windows -> Microsoft Corporation)
S3 nmwcd; C:\Windows\system32\drivers\ccdcmbx64.sys [19968 2013-01-23] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\Windows\system32\drivers\ccdcmbox64.sys [27136 2013-01-23] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 pccsmcfd; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [26112 2012-10-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] (Microsoft Windows -> )
R0 stdcfltn; C:\Windows\System32\DRIVERS\stdcfltn.sys [30352 2016-10-07] (STMICROELECTRONICS S.R.L. -> ST Microelectronics)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] (Empty Loop -> )
S3 upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [9216 2013-01-23] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [9216 2013-01-23] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [45976 2020-07-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [408816 2020-07-02] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [64224 2020-07-02] (Microsoft Windows -> Microsoft Corporation)
R3 WUDFWpdComp; C:\Windows\system32\DRIVERS\WUDFRd.sys [220672 2017-03-18] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-07-07 12:56 - 2020-07-07 12:58 - 000037590 _____ C:\Users\udrzbaaqp\Desktop\FRST.txt
2020-07-07 12:25 - 2020-07-07 12:25 - 002292224 _____ (Farbar) C:\Users\udrzbaaqp\Desktop\FRST64.exe
2020-07-07 12:06 - 2020-07-07 12:06 - 000196752 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2020-07-07 12:06 - 2020-07-07 12:06 - 000131728 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2020-07-07 12:06 - 2020-07-07 12:06 - 000073368 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2020-07-07 12:06 - 2020-07-07 12:06 - 000002043 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-07-07 12:05 - 2020-07-07 12:05 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-07-07 12:05 - 2020-07-07 12:05 - 000216056 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-07-07 12:05 - 2020-07-07 12:05 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2020-07-07 12:05 - 2020-07-07 12:05 - 000019912 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2020-07-07 12:05 - 2020-07-07 12:05 - 000000000 ____D C:\Program Files\Malwarebytes
2020-07-06 20:06 - 2020-07-07 08:00 - 000000000 ____D C:\KVRT_Data
2020-07-06 20:06 - 2020-07-06 20:06 - 000478392 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\522A849C.sys
2020-07-04 18:06 - 2020-07-04 18:06 - 000000000 ____D C:\Users\udrzbaaqp\AppData\LocalLow\Intel
2020-07-03 13:58 - 2020-07-07 06:44 - 000000000 ____D C:\Users\udrzbaaqp\Desktop\Anomálie
2020-06-30 16:33 - 2020-06-30 16:33 - 000000756 _____ C:\Users\udrzbaaqp\Desktop\bluetooth_content_share.html
2020-06-28 16:17 - 2020-06-28 16:17 - 000003206 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2020-06-28 16:16 - 2020-06-28 16:16 - 000002174 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-06-16 06:39 - 2020-06-16 06:42 - 000001948 _____ C:\Users\udrzbaaqp\Desktop\Potvrdenie o prevzatí zariadenia na opravu.docx – odkaz.lnk
2020-06-14 17:59 - 2020-07-04 18:04 - 000000000 ____D C:\Windows\LastGood
2020-06-14 17:58 - 2020-06-14 17:57 - 024063104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRender64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 024942088 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioCapture64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 024161688 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRenderAVX64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 007272536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2020-06-14 17:58 - 2020-02-17 22:55 - 003819720 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 003676960 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2020-06-14 17:58 - 2020-02-17 22:55 - 003340304 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 003159672 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 002930040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 001353216 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 000692056 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 000575080 _____ (Intel Corporation) C:\Windows\system32\tbb_waves.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 000343600 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 000240024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTHDASIO64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 000200600 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RTHDASIO.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 000192872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2020-06-14 17:58 - 2020-02-17 22:55 - 000023584 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2020-06-14 17:58 - 2019-12-19 14:07 - 002877104 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2020-06-10 16:58 - 2020-06-10 17:02 - 000000000 ____D C:\Users\udrzbaaqp\Desktop\ODKAZY privát
2020-06-10 16:39 - 2020-06-10 16:39 - 000000819 _____ C:\Users\udrzbaaqp\Desktop\HELP – odkaz.lnk
2020-06-10 15:33 - 2020-06-14 18:58 - 1103011603 _____ C:\Windows\MEMORY.DMP
2020-06-10 15:33 - 2020-06-10 15:35 - 001806836 _____ C:\Windows\Minidump\061020-35296-01.dmp
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-07-07 12:57 - 2018-12-03 08:35 - 000000000 ____D C:\FRST
2020-07-07 12:57 - 2016-09-06 07:07 - 000000000 ____D C:\Users\udrzbaaqp\Documents\Archiv pošta
2020-07-07 12:56 - 2017-07-07 17:26 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-07-07 12:36 - 2018-06-28 20:24 - 000000515 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2020-07-07 12:30 - 2020-04-10 10:10 - 000500394 _____ C:\Windows\system32\perfh01B.dat
2020-07-07 12:30 - 2020-04-10 10:10 - 000140078 _____ C:\Windows\system32\perfc01B.dat
2020-07-07 12:30 - 2017-07-07 17:42 - 003504988 _____ C:\Windows\system32\PerfStringBackup.INI
2020-07-07 12:25 - 2018-06-19 18:33 - 000000000 ____D C:\Ečko
2020-07-07 12:12 - 2018-07-01 20:03 - 000000000 ____D C:\Users\udrzbaaqp\Desktop\Udrzba NB
2020-07-07 12:05 - 2018-07-01 19:38 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-07-07 12:05 - 2017-03-18 23:03 - 000000000 ___HD C:\Windows\ELAMBKUP
2020-07-07 12:04 - 2020-02-25 07:48 - 000000000 ____D C:\Users\udrzbaaqp\AppData\Local\CrashDumps
2020-07-07 11:01 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\Registration
2020-07-07 11:01 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\AppReadiness
2020-07-07 10:58 - 2018-06-19 13:27 - 000000000 __SHD C:\Users\udrzbaaqp\IntelGraphicsProfiles
2020-07-07 10:57 - 2018-06-19 16:59 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-07-07 10:56 - 2018-06-19 13:27 - 000000000 ____D C:\Users\udrzbaaqp
2020-07-07 10:56 - 2017-07-07 17:42 - 000000000 ____D C:\Intel
2020-07-07 10:56 - 2017-07-07 17:26 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-07-07 10:56 - 2017-03-18 13:40 - 002359296 _____ C:\Windows\system32\config\BBI
2020-07-06 20:40 - 2019-09-13 08:13 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2020-07-06 20:40 - 2017-07-07 17:43 - 000000000 ____D C:\ProgramData\Intel
2020-07-06 20:38 - 2017-03-18 13:40 - 000032768 _____ C:\Windows\system32\config\ELAM
2020-07-06 13:12 - 2019-10-13 09:06 - 000000000 ____D C:\ProgramData\AMMYY
2020-07-06 12:14 - 2018-06-19 13:27 - 000000000 ____D C:\Users\udrzbaaqp\AppData\Local\Packages
2020-07-04 18:04 - 2017-03-18 23:01 - 000000000 ____D C:\Windows\INF
2020-07-04 18:01 - 2017-07-07 17:48 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2020-07-04 15:59 - 2018-10-14 08:30 - 000000000 ____D C:\Users\udrzbaaqp\AppData\Roaming\vlc
2020-07-04 15:53 - 2018-10-14 08:30 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-07-03 10:06 - 2019-06-11 07:01 - 000002782 _____ C:\Users\udrzbaaqp\Desktop\DOVOLENKY 2020 Server.lnk
2020-07-02 09:36 - 2018-06-19 12:11 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-06-28 16:17 - 2018-06-19 13:30 - 000000000 ___RD C:\Users\udrzbaaqp\OneDrive
2020-06-28 16:17 - 2017-09-06 12:33 - 000000000 ___RD C:\Users\mbajannekk\OneDrive
2020-06-28 16:17 - 2017-08-16 10:13 - 000000000 ___RD C:\Users\admin\OneDrive
2020-06-25 09:42 - 2018-12-04 12:51 - 000002317 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-06-25 09:42 - 2018-12-04 12:51 - 000002276 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-06-23 20:15 - 2017-03-18 23:03 - 000000000 ___HD C:\Program Files\WindowsApps
2020-06-22 06:42 - 2017-03-18 23:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-06-22 06:40 - 2017-09-22 14:15 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-06-18 17:35 - 2018-06-19 19:44 - 000000000 ____D C:\Users\udrzbaaqp\Desktop\Odkazy VNC intranet
2020-06-18 06:42 - 2018-10-21 18:07 - 000000000 ____D C:\Users\udrzbaaqp\Desktop\Temp Skeny
2020-06-14 18:58 - 2018-07-16 14:52 - 000000000 ____D C:\Windows\Minidump
2020-06-14 18:05 - 2017-07-07 17:45 - 000000000 ___HD C:\Program Files (x86)\Temp
2020-06-14 17:59 - 2017-07-07 17:45 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2020-06-14 17:58 - 2017-07-07 17:45 - 000019632 _____ C:\Windows\SysWOW64\RtkMsgs.dll
2020-06-14 17:56 - 2017-07-07 17:42 - 000000000 ____D C:\Program Files (x86)\Intel
2020-06-14 16:59 - 2018-08-05 17:20 - 000000000 ____D C:\Users\udrzbaaqp\AppData\Roaming\Audacity
2020-06-12 16:44 - 2020-05-07 15:47 - 000001483 _____ C:\Users\udrzbaaqp\Desktop\Saunový svet_PD – odkaz.lnk
2020-06-10 15:52 - 2018-06-19 17:00 - 000000000 ____D C:\Users\udrzbaaqp\AppData\Roaming\TeamViewer
2020-06-10 15:34 - 2017-07-31 10:19 - 000000000 ____D C:\Users\admin
==================== Files in the root of some directories ========
2019-10-29 11:04 - 2019-10-29 11:04 - 000024052 _____ () C:\Users\udrzbaaqp\AppData\Roaming\Hodnoty oddelené čiarkou.ADR
2018-07-02 13:49 - 2018-07-02 13:49 - 000008242 _____ () C:\Users\udrzbaaqp\AppData\Roaming\Hodnoty oddelené čiarkou.EML
2020-02-15 12:48 - 2020-05-31 19:47 - 000005120 _____ () C:\Users\udrzbaaqp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-12-02 22:26 - 2018-12-02 22:26 - 000140800 _____ () C:\Users\udrzbaaqp\AppData\Local\installer.dat
2018-11-06 22:54 - 2018-11-06 22:54 - 000000017 _____ () C:\Users\udrzbaaqp\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2020-07-07 12:32
==================== End of FRST.txt ========================