Eset hlásí adware v Opeře - není schopen jej zlikvidovat
Napsal: 16 bře 2021 16:59
Hlášky Esetu:
Čas;Skener;Typ objektu;Objekt;Detekce;Akce;Uživatel;Informace;Hash;První výskyt
16.03.2021 12:37:07;HTTP filtr;soubor;https://lapypushistyye.com/?r=dir&zonei ... e.Agent.AA aplikace;přerušeno spojení;AH\j.gb;Tato událost nastala při pokusu o přístup na web aplikací: C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera.exe (1F03BA3ACC3BCD1209B8E3A662C43418DCE0C966).;46228597FDCFC5152DE2BDF64DD988637002C96A;
Čas;Skener;Typ objektu;Objekt;Detekce;Akce;Uživatel;Informace;Hash;První výskyt
16.03.2021 12:26:24;HTTP filtr;soubor;https://ribunews.com/d/2103160625030825 ... e.Agent.AA aplikace;přerušeno spojení;AH\j.gb;Tato událost nastala při pokusu o přístup na web aplikací: C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera.exe (1F03BA3ACC3BCD1209B8E3A662C43418DCE0C966).;7642C82A55CDC571E760ECA57FCCC55671436001;
Prosím o kontrolu:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-03-2021
Ran by j.gb (administrator) on 2B2MP73 (Dell Inc. Latitude 5410) (16-03-2021 16:06:18)
Running from C:\Users\j.gb\Desktop
Loaded Profiles: j.gb
Platform: Windows 10 Pro Version 20H2 19042.804 (X64) Language: Čeština (Česko)
Default browser: Opera
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
("STMicroelectronics Srl" -> ) C:\Windows\System32\drivers\DellFFDPWmiService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\anipart client\application.exe
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Windows\Temp\AdAppMgrUpdater.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe <3>
(Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(CANON INC. -> CANON INC.) C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE
(Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\egui.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_f75fa513cf0ccec1\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0b214be229a13e84\jhi_service.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_c0fd909ca6e7d672\LMS.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3f9eae06dd582000\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3f9eae06dd582000\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_42f9d9bfb72d84cf\RstMwService.exe
(Kvaser AB -> KVASER AB, Mölndal, SWEDEN) C:\Program Files\Kvaser\Drivers\32\KvEnumSrv.exe <2>
(Magic Control Technology Corp. -> ) C:\Windows\System32\mlpatch.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Users\j.gb\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\j.gb\AppData\Local\Microsoft\Teams\current\Teams.exe <9>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_3.8.8.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20688.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20688.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Opera Software AS -> Opera Software) C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera.exe <67>
(Opera Software AS -> Opera Software) C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera_crashreporter.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\DSAPI.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\SystemIdleCheck.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe <3>
(Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\IAS\IntelAudioService.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_177ab60f8bad72cc\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_177ab60f8bad72cc\WavesSysSvc64.exe
(WhatsApp, Inc -> WhatsApp) C:\Users\j.gb\AppData\Local\WhatsApp\app-2.2108.8\WhatsApp.exe <6>
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files\CodeMeter\Runtime\bin\CmWebAdmin.exe
(win.rar GmbH -> Alexander Roshal) C:\Program Files\WinRAR\WinRAR.exe
(Winamp SA -> Winamp SA) C:\Program Files (x86)\Winamp\winamp.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1223224 2021-01-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_177ab60f8bad72cc\WavesSvc64.exe [1776744 2020-12-24] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-11-11] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [508312 2009-12-15] (CANON INC. -> CANON INC.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [101284632 2020-09-16] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3499920 2014-09-12] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [664872 2020-03-04] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM\...\RunOnce: [msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}] => C:\Program Files (x86)\Microsoft\Edge\Application\89.0.774.54\Installer\setup.exe [3841424 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Run: [Opera Browser Assistant] => C:\Users\j.gb\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3366424 2020-12-16] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Run: [com.squirrel.Teams.Teams] => C:\Users\j.gb\AppData\Local\Microsoft\Teams\Update.exe [2453720 2021-02-26] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2007576 2017-02-03] (Autodesk, Inc -> Autodesk, Inc.)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Policies\Explorer: []
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\MountPoints2: {17a33837-4907-11eb-9545-dc41a949503d} - "D:\WHLoader.exe"
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2007576 2017-02-03] (Autodesk, Inc -> Autodesk, Inc.)
HKLM\...\Windows x64\Print Processors\Canon MG7100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBR.DLL [30208 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [55432 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG7100 series: C:\Windows\system32\CNMLMBR.DLL [391168 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\system32\CNMN6PPM.DLL [359936 2013-01-24] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon MFNP Port: C:\Windows\system32\CNCENPM6.dll [153088 2016-02-10] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\CPCA Language Monitor3b: C:\Windows\system32\CNAS0MOK.DLL [967168 2009-04-28] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2021-01-08]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk [2020-12-22]
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Network Server.lnk [2020-12-22]
ShortcutTarget: Network Server.lnk -> C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0945C09A-D144-4B8A-ABED-8C31F86CB13F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1511320 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {2BF0450A-4FF4-410C-A347-C952B1BBCAE8} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23079792 2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {2C9830F1-181C-40C6-980D-8920576FB3CB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {6309142C-DBAE-47D5-9BCF-6AB6F3B24D18} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23079792 2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202}" was unlocked. <==== ATTENTION
Task: {81474A3A-5E30-45A7-87FE-566AA8EE5360} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\Windows\system32\gpupdate.exe [30720 2020-11-19] (Microsoft Windows -> Microsoft Corporation)
Task: {A9A20BF5-C5CB-4E1E-B3DE-E122A38ACE13} - System32\Tasks\Opera scheduled assistant Autoupdate 1608627186 => C:\Users\j.gb\AppData\Local\Programs\Opera\launcher.exe [1793688 2021-03-11] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\j.gb\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {B1539CA3-A5EC-4DAC-A9F1-E5B1018A985E} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141136 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {BC5E9969-1F6A-47D6-8DAD-3CB3AFACCCF1} - System32\Tasks\Opera scheduled Autoupdate 1608627185 => C:\Users\j.gb\AppData\Local\Programs\Opera\launcher.exe [1793688 2021-03-11] (Opera Software AS -> Opera Software)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA}" was unlocked. <==== ATTENTION
Task: {CE9F5343-2192-46F9-B667-266D339EC1FF} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\Windows\system32\gpupdate.exe [30720 2020-11-19] (Microsoft Windows -> Microsoft Corporation)
Task: {D1F125C3-4FD4-4025-AD11-8714470B9A46} - System32\Tasks\GE_CloudProxySettings_1.1_V03 => C:\Windows\Options\Packages\GE_CloudProxySettings_1.1_V03\SchTasks.EXE [133195 2017-07-24] () [File not signed]
Task: {F4C778B2-134C-420D-85B7-7DE8D070B83E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141136 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {FCA4DB86-5AF9-4FE7-82B3-FC0F81A710F5} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1059336 2021-01-09] (Dell Inc -> Dell Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.20.11 8.8.8.8
Tcpip\..\Interfaces\{1bf34c8a-8607-42d7-b794-f40506edffaa}: [DhcpNameServer] 192.168.20.11 8.8.8.8
Tcpip\..\Interfaces\{79338ff9-755c-4fc2-897b-b0f4ecadaa5f}: [DhcpNameServer] 192.168.20.11 8.8.8.8
Tcpip\..\Interfaces\{ac8bc92f-de38-4010-b14d-caf54f08c7da}: [DhcpNameServer] 192.168.20.11 8.8.8.8
HKLM\System\...\Parameters\PersistentRoutes: [169.254.0.0,255.255.0.0,192.168.18.111,1]
HKLM\System\...\Parameters\PersistentRoutes: [169.254.0.0,255.255.0.0,192.168.20.114,1]
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\j.gb\AppData\Local\Microsoft\Edge\User Data\Default [2021-02-24]
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2021-01-08] [Legacy] [not signed]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-04-28] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-09-12] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems Incorporated -> Adobe Systems)
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-09-12]
Opera:
=======
OPR Profile: C:\Users\j.gb\AppData\Roaming\Opera Software\Opera Stable [2021-03-16]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=o ... utEncoding}
OPR Extension: (Translator) - C:\Users\j.gb\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnbpedcoekjafichoehopgaaldogogch [2021-01-11]
OPR Extension: (Rich Hints Agent) - C:\Users\j.gb\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-03-11]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1046904 2020-03-04] (Autodesk, Inc. -> Autodesk Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2021-01-08] () [File not signed]
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8988552 2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
R2 CmWebAdmin.exe; C:\Program Files\CodeMeter\Runtime\bin\CmWebAdmin.exe [12002208 2019-12-16] (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [287776 2020-10-25] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3750944 2020-10-25] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [507936 2020-10-25] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\DSAPI.exe [985584 2021-01-13] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [38592 2020-10-29] (Dell Inc -> )
R2 DellFFDPWmiService; C:\Windows\System32\drivers\DellFFDPWmiService.exe [32528 2020-02-17] ("STMicroelectronics Srl" -> )
S3 EHttpSrv; C:\Program Files\ESET\ESET Security\ehttpsrv.exe [49448 2020-11-11] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-11] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-11] (ESET, spol. s r.o. -> ESET)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] (Canon Inc. -> )
R2 KvEnumSrv; C:\Program Files\Kvaser\Drivers\32\kvenumsrv.exe [553640 2020-09-09] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R2 KvWiFiPairingSrv; C:\Program Files\Kvaser\Drivers\32\kvenumsrv.exe [553640 2020-09-09] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R2 MlPatch; C:\Windows\system32\MlPatch.exe [2244912 2014-08-22] (Magic Control Technology Corp. -> )
R2 RtkAudioUniversalService; C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1223224 2021-01-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5198064 2021-01-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39432 2021-01-09] (Dell Inc -> Dell Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12723480 2021-02-17] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R3 DDDriver; C:\Windows\System32\drivers\dddriver64Dcsa.sys [42376 2020-10-25] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [160992 2020-11-11] (ESET, spol. s r.o. -> ESET)
S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [109360 2020-11-11] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15824 2021-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [190464 2020-11-11] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [70560 2020-11-11] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [108808 2020-11-11] (ESET, spol. s r.o. -> ESET)
S3 f5ipfw; C:\Windows\system32\drivers\urfltv64.sys [44440 2020-09-10] (F5 Networks Inc -> F5 Networks, Inc.)
U3 Healcea; no ImagePath
S3 kcane; C:\Windows\system32\DRIVERS\kcane.sys [119352 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R3 kcanv; C:\Windows\system32\DRIVERS\kcanv.sys [98360 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R3 kvnetenum; C:\Windows\system32\DRIVERS\kvnetenum.sys [58424 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R2 kvsoftsync; C:\Windows\system32\Drivers\kvsoftsync.sys [32312 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R3 LAN9500; C:\Windows\System32\drivers\lan9500-x64-n650f.sys [109408 2017-04-27] (Microchip Technology Inc. -> Microchip Technology Inc.)
R3 MctUsbAudio; C:\Windows\System32\drivers\MctFlt.sys [38680 2017-11-09] (Magic Control Technology Corp. -> Windows (R) Win 7 DDK provider)
R3 urvpndrv; C:\Windows\System32\drivers\covpnv64.sys [57736 2020-09-10] (F5 Networks Inc -> F5 Networks, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48536 2020-12-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [429296 2020-12-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-18] (Microsoft Windows -> Microsoft Corporation)
R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [118200 2020-03-18] (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
R3 WiManH; C:\Windows\System32\DriverStore\FileRepository\wiman.inf_amd64_4b0336d95f188e47\WiManH\WiManH.sys [168792 2020-09-02] (Intel Wireless Driver -> )
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-16 16:06 - 2021-03-16 16:06 - 000026621 _____ C:\Users\j.gb\Desktop\FRST.txt
2021-03-16 16:06 - 2021-03-16 16:06 - 000000000 ____D C:\FRST
2021-03-16 16:04 - 2021-03-16 16:04 - 002300928 _____ (Farbar) C:\Users\j.gb\Desktop\FRST64.exe
2021-03-16 11:58 - 2021-03-16 11:58 - 000000000 ____D C:\Users\j.gb\AppData\Local\Brice_Lambson
2021-03-16 11:56 - 2021-03-16 11:56 - 001083664 _____ (Brice Lambson) C:\Users\j.gb\Downloads\ImageResizerSetup-3.1.1.exe
2021-03-16 11:56 - 2021-03-16 11:56 - 000000000 ____D C:\Program Files\Image Resizer for Windows
2021-03-16 11:56 - 2021-03-16 11:56 - 000000000 ____D C:\Program Files (x86)\Image Resizer for Windows
2021-03-16 11:50 - 2021-03-16 11:58 - 000000000 ____D C:\Users\j.gb\Downloads\drive-download-20210316T104853Z-001
2021-03-16 11:49 - 2021-03-16 11:49 - 028919689 _____ C:\Users\j.gb\Downloads\drive-download-20210316T104853Z-001.zip
2021-03-15 10:22 - 2021-03-15 10:22 - 000000004 ____H C:\ProgramData\cm-lock
2021-03-15 10:21 - 2021-03-15 11:20 - 000307116 _____ C:\Users\j.gb\Desktop\29145583_Installation Protocol BC T200.pdf
2021-03-12 22:08 - 2021-03-12 22:10 - 000000000 ____D C:\Users\j.gb\Desktop\Fighting With My Family (2019) [WEBRip] [1080p] [YTS.AM]
2021-03-03 16:50 - 2021-03-03 16:50 - 000241456 _____ C:\Users\j.gb\Downloads\Dap2020Jenda.XLSX
2021-03-03 11:39 - 2021-03-03 11:39 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\Media Player Classic
2021-03-03 11:38 - 2021-03-03 11:38 - 001969179 _____ C:\Users\j.gb\Downloads\mpc_6490+_2kXP_cze.zip
2021-02-24 15:57 - 2021-02-24 15:57 - 000000000 ____D C:\Users\j.gb\AppData\Local\GHISLER
2021-02-24 15:56 - 2021-02-24 15:57 - 000000000 ____D C:\totalcmd
2021-02-24 15:56 - 2021-02-24 15:56 - 008095960 _____ (Ghisler Software GmbH) C:\Users\j.gb\Downloads\tcmd951x32_64.exe
2021-02-24 15:56 - 2021-02-24 15:56 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2021-02-24 15:56 - 2021-02-24 15:56 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\GHISLER
2021-02-24 11:43 - 2021-02-24 11:44 - 000000000 ____D C:\SERVICEmgr32
2021-02-24 11:39 - 2021-03-15 10:23 - 000000000 ____D C:\ProgramData\boost_interprocess
2021-02-24 11:21 - 2021-02-24 11:21 - 013746920 _____ (Kvaser AB, Mölndal, Sweden) C:\Users\j.gb\Downloads\kvaser_drivers_setup.exe
2021-02-24 11:21 - 2021-02-24 11:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kvaser CAN Drivers
2021-02-24 11:21 - 2021-02-24 11:21 - 000000000 ____D C:\Program Files\Kvaser
2021-02-24 11:21 - 2020-09-17 08:28 - 000156216 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcany.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000145976 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanyr.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000133176 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanl.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000126008 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanlr.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000119352 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanx.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000117816 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanf.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000112696 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanh.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000111160 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcans.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000098360 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanv.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000058424 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kvnetenum.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000032312 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kvsoftsync.sys
2021-02-24 11:21 - 2020-09-09 23:09 - 000670888 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\kvalapw2.dll
2021-02-24 11:21 - 2020-09-09 23:09 - 000564904 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\kcanconf.exe
2021-02-24 11:21 - 2020-09-09 23:09 - 000538280 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\kvaser_vcndrvms.dll
2021-02-24 11:21 - 2020-09-09 23:09 - 000509608 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\canlib32.dll
2021-02-24 11:21 - 2020-09-09 23:09 - 000442024 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\kcanconf.exe
2021-02-24 11:18 - 2021-02-24 11:43 - 000262144 ____N (Microsoft Corporation) C:\Windows\Setup1.exe
2021-02-24 11:18 - 2021-02-24 11:43 - 000073216 _____ (Microsoft Corporation) C:\Windows\ST6UNST.EXE
2021-02-24 11:18 - 2021-02-24 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SERVICEmgr32
2021-02-24 11:18 - 2015-03-18 20:31 - 002896977 ____N C:\Windows\SERVIC~1.CAB
2021-02-23 12:48 - 2021-02-23 12:48 - 000665428 _____ C:\Users\j.gb\Downloads\potvrzeni (1).pdf
2021-02-23 11:51 - 2021-02-23 11:51 - 004526932 _____ C:\Users\j.gb\Downloads\SITUACE.pdf
2021-02-22 15:49 - 2021-02-22 15:49 - 000000000 ____D C:\Users\j.gb\Downloads\The-Prodigy---Diskografie-+Singly-(1991-2009)-(MP3-320kbps).Mp3_HQ-by-PiPeTamer
2021-02-22 11:14 - 2021-02-22 13:20 - 2277271356 _____ C:\Users\j.gb\Downloads\The-Prodigy---Diskografie-+Singly-(1991-2009)-(MP3-320kbps).Mp3_HQ-by-PiPeTamer.rar
2021-02-22 10:46 - 2021-02-22 10:46 - 001462176 _____ C:\Users\j.gb\Desktop\1_podlaží.psd
2021-02-22 10:45 - 2021-02-22 10:45 - 001695762 _____ C:\Users\j.gb\Desktop\1_podlaží.pdf
2021-02-16 12:09 - 2021-02-16 12:45 - 104941649 _____ C:\Users\j.gb\Downloads\PoR - PL.rar
2021-02-16 12:03 - 2021-02-16 12:23 - 354036255 _____ C:\Users\j.gb\Downloads\Mo-Do - Was Ist Das (1995)FLAC.rar
2021-02-16 12:00 - 2021-02-16 12:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoCAD 2018 – Čeština (Czech)
2021-02-16 11:59 - 2021-02-16 11:59 - 111747832 _____ (Autodesk, Inc.) C:\Users\j.gb\Downloads\AutoCAD_2018_Czech_LP_Win_64bit_dlm.sfx.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-16 16:04 - 2020-12-21 23:59 - 000000000 ____D C:\ProgramData\Adobe
2021-03-16 16:04 - 2020-12-21 23:26 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\Adobe
2021-03-16 16:02 - 2021-01-04 10:00 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\WhatsApp
2021-03-16 16:02 - 2020-12-21 23:17 - 000000136 _____ C:\Windows\system32\config\netlogon.ftl
2021-03-16 15:58 - 2020-11-18 23:46 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-03-16 15:58 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-03-16 11:56 - 2020-12-18 21:57 - 000000000 ____D C:\ProgramData\Package Cache
2021-03-16 11:50 - 2020-12-28 11:00 - 000000000 ____D C:\Program Files (x86)\anipart client
2021-03-16 11:50 - 2020-12-28 10:48 - 000000000 ____D C:\Users\j.gb\Documents\aniPart support
2021-03-16 08:58 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2021-03-16 08:50 - 2020-12-18 21:33 - 000000000 ____D C:\Windows\system32\MRT
2021-03-16 08:46 - 2020-12-18 21:33 - 131005360 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-03-15 20:40 - 2020-11-19 00:48 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-03-15 20:40 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-03-15 20:40 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2021-03-15 11:02 - 2021-01-04 10:00 - 000000000 ____D C:\Users\j.gb\AppData\Local\WhatsApp
2021-03-15 10:46 - 2020-11-08 12:08 - 000015824 _____ (ESET) C:\Windows\system32\Drivers\eelam.sys
2021-03-15 10:46 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2021-03-15 10:34 - 2021-02-12 13:27 - 000000000 ____D C:\ProgramData\Autodesk
2021-03-15 10:23 - 2020-12-21 23:30 - 000000000 ____D C:\Program Files\Microsoft Office
2021-03-15 10:23 - 2020-12-21 23:26 - 000000000 __SHD C:\Users\j.gb\IntelGraphicsProfiles
2021-03-15 10:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-03-15 10:22 - 2020-12-18 22:04 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-03-15 10:22 - 2020-12-18 21:39 - 000000000 ____D C:\Intel
2021-03-15 10:22 - 2020-12-18 21:26 - 000008192 ___SH C:\DumpStack.log.tmp
2021-03-15 10:22 - 2020-11-19 00:46 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-03-15 10:22 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ServiceState
2021-03-15 10:22 - 2019-12-07 10:03 - 000786432 _____ C:\Windows\system32\config\BBI
2021-03-15 10:06 - 2021-01-08 13:48 - 000000000 ____D C:\ProgramData\CanonIJPLM
2021-03-15 10:05 - 2020-12-22 00:00 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-03-15 10:04 - 2020-12-22 09:53 - 000004182 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1608627185
2021-03-15 10:04 - 2020-12-22 09:53 - 000001515 _____ C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2021-03-08 22:02 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\LiveKernelReports
2021-03-08 17:29 - 2020-12-28 10:34 - 000000000 ____D C:\Users\j.gb\Documents\Pharmatech
2021-03-04 12:35 - 2020-11-19 00:48 - 000003584 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-03-04 12:35 - 2020-11-19 00:48 - 000003460 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-03-04 10:00 - 2020-12-21 23:26 - 000003368 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-229502678-4061752961-2197657978-1117
2021-03-04 10:00 - 2020-12-21 23:26 - 000002407 _____ C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-03-04 10:00 - 2020-12-21 23:26 - 000000000 ___RD C:\Users\j.gb\OneDrive
2021-03-03 15:13 - 2020-12-28 10:32 - 000000000 ____D C:\Users\j.gb\Documents\Protokoly
2021-03-01 12:34 - 2020-12-21 23:26 - 000000000 ____D C:\Users\j.gb\AppData\Local\Packages
2021-03-01 11:51 - 2021-01-08 12:20 - 000000000 ____D C:\Users\j.gb\Desktop\Proformy
2021-02-26 03:29 - 2020-12-22 16:01 - 000002416 _____ C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-02-24 16:05 - 2020-12-28 10:33 - 000000000 ____D C:\Users\j.gb\Documents\Projít
2021-02-24 12:02 - 2021-02-02 18:31 - 000000000 ____D C:\Users\j.gb\AppData\Local\Google
2021-02-24 12:02 - 2021-02-02 18:31 - 000000000 ____D C:\Program Files (x86)\Google
2021-02-24 11:43 - 2014-10-30 21:03 - 000001291 _____ C:\Windows\SERVICEmgr32.ini
2021-02-24 11:43 - 2006-01-19 13:22 - 000000526 _____ C:\Windows\Eptcan32.ini
2021-02-24 11:43 - 2003-11-04 15:56 - 000000259 _____ C:\Windows\xptcan32.ini
2021-02-24 11:39 - 2021-02-12 13:30 - 000000000 ____D C:\Users\j.gb\AppData\Local\Autodesk
2021-02-24 11:39 - 2021-02-12 13:23 - 000536984 _____ C:\Windows\system32\FNTCACHE.DAT
2021-02-24 11:37 - 2020-12-22 16:06 - 000000000 ____D C:\Users\j.gb\GRAPHISOFT
2021-02-24 11:37 - 2020-12-22 16:06 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\GRAPHISOFT
2021-02-24 11:37 - 2020-12-22 16:06 - 000000000 ____D C:\Users\j.gb\AppData\Local\GRAPHISOFT
2021-02-24 11:18 - 2020-12-28 10:43 - 000000000 ____D C:\SERVICEmgr323
2021-02-23 13:34 - 2020-12-28 10:27 - 000000000 ____D C:\Users\j.gb\Documents\Dům
2021-02-22 11:33 - 2021-01-08 12:40 - 000000000 ____D C:\Users\j.gb\AppData\Local\CrashDumps
2021-02-17 14:29 - 2020-12-21 23:26 - 000000000 ____D C:\Users\j.gb
2021-02-16 12:00 - 2021-02-12 13:29 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared
2021-02-16 12:00 - 2021-02-12 13:29 - 000000000 ____D C:\Program Files\Autodesk
2021-02-16 12:00 - 2021-02-12 13:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2021-02-16 11:59 - 2021-02-12 12:37 - 000000000 ____D C:\Autodesk
2021-02-15 13:14 - 2020-12-28 10:32 - 000000000 ____D C:\Users\j.gb\Documents\Výkazy f
2021-02-15 13:14 - 2020-12-28 10:26 - 000000000 ____D C:\Users\j.gb\Documents\AutoDELFIA
==================== Files in the root of some directories ========
2021-01-08 10:08 - 2021-01-08 10:08 - 000003584 _____ () C:\Users\j.gb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2021-01-08 12:29 - 2021-01-08 12:29 - 000000017 _____ () C:\Users\j.gb\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Čas;Skener;Typ objektu;Objekt;Detekce;Akce;Uživatel;Informace;Hash;První výskyt
16.03.2021 12:37:07;HTTP filtr;soubor;https://lapypushistyye.com/?r=dir&zonei ... e.Agent.AA aplikace;přerušeno spojení;AH\j.gb;Tato událost nastala při pokusu o přístup na web aplikací: C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera.exe (1F03BA3ACC3BCD1209B8E3A662C43418DCE0C966).;46228597FDCFC5152DE2BDF64DD988637002C96A;
Čas;Skener;Typ objektu;Objekt;Detekce;Akce;Uživatel;Informace;Hash;První výskyt
16.03.2021 12:26:24;HTTP filtr;soubor;https://ribunews.com/d/2103160625030825 ... e.Agent.AA aplikace;přerušeno spojení;AH\j.gb;Tato událost nastala při pokusu o přístup na web aplikací: C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera.exe (1F03BA3ACC3BCD1209B8E3A662C43418DCE0C966).;7642C82A55CDC571E760ECA57FCCC55671436001;
Prosím o kontrolu:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-03-2021
Ran by j.gb (administrator) on 2B2MP73 (Dell Inc. Latitude 5410) (16-03-2021 16:06:18)
Running from C:\Users\j.gb\Desktop
Loaded Profiles: j.gb
Platform: Windows 10 Pro Version 20H2 19042.804 (X64) Language: Čeština (Česko)
Default browser: Opera
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
("STMicroelectronics Srl" -> ) C:\Windows\System32\drivers\DellFFDPWmiService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\anipart client\application.exe
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Windows\Temp\AdAppMgrUpdater.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe <3>
(Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(CANON INC. -> CANON INC.) C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE
(Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\egui.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_f75fa513cf0ccec1\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0b214be229a13e84\jhi_service.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_c0fd909ca6e7d672\LMS.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3f9eae06dd582000\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3f9eae06dd582000\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_42f9d9bfb72d84cf\RstMwService.exe
(Kvaser AB -> KVASER AB, Mölndal, SWEDEN) C:\Program Files\Kvaser\Drivers\32\KvEnumSrv.exe <2>
(Magic Control Technology Corp. -> ) C:\Windows\System32\mlpatch.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Users\j.gb\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\j.gb\AppData\Local\Microsoft\Teams\current\Teams.exe <9>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_3.8.8.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20688.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20688.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Opera Software AS -> Opera Software) C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera.exe <67>
(Opera Software AS -> Opera Software) C:\Users\j.gb\AppData\Local\Programs\Opera\74.0.3911.218\opera_crashreporter.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\DSAPI.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\SystemIdleCheck.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe <3>
(Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\IAS\IntelAudioService.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_177ab60f8bad72cc\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_177ab60f8bad72cc\WavesSysSvc64.exe
(WhatsApp, Inc -> WhatsApp) C:\Users\j.gb\AppData\Local\WhatsApp\app-2.2108.8\WhatsApp.exe <6>
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files\CodeMeter\Runtime\bin\CmWebAdmin.exe
(win.rar GmbH -> Alexander Roshal) C:\Program Files\WinRAR\WinRAR.exe
(Winamp SA -> Winamp SA) C:\Program Files (x86)\Winamp\winamp.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1223224 2021-01-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_177ab60f8bad72cc\WavesSvc64.exe [1776744 2020-12-24] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-11-11] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [508312 2009-12-15] (CANON INC. -> CANON INC.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [101284632 2020-09-16] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3499920 2014-09-12] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [664872 2020-03-04] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM\...\RunOnce: [msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}] => C:\Program Files (x86)\Microsoft\Edge\Application\89.0.774.54\Installer\setup.exe [3841424 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Run: [Opera Browser Assistant] => C:\Users\j.gb\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3366424 2020-12-16] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Run: [com.squirrel.Teams.Teams] => C:\Users\j.gb\AppData\Local\Microsoft\Teams\Update.exe [2453720 2021-02-26] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2007576 2017-02-03] (Autodesk, Inc -> Autodesk, Inc.)
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\Policies\Explorer: []
HKU\S-1-5-21-229502678-4061752961-2197657978-1117\...\MountPoints2: {17a33837-4907-11eb-9545-dc41a949503d} - "D:\WHLoader.exe"
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2007576 2017-02-03] (Autodesk, Inc -> Autodesk, Inc.)
HKLM\...\Windows x64\Print Processors\Canon MG7100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBR.DLL [30208 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [55432 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG7100 series: C:\Windows\system32\CNMLMBR.DLL [391168 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\system32\CNMN6PPM.DLL [359936 2013-01-24] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon MFNP Port: C:\Windows\system32\CNCENPM6.dll [153088 2016-02-10] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\CPCA Language Monitor3b: C:\Windows\system32\CNAS0MOK.DLL [967168 2009-04-28] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2021-01-08]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk [2020-12-22]
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Network Server.lnk [2020-12-22]
ShortcutTarget: Network Server.lnk -> C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0945C09A-D144-4B8A-ABED-8C31F86CB13F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1511320 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {2BF0450A-4FF4-410C-A347-C952B1BBCAE8} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23079792 2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {2C9830F1-181C-40C6-980D-8920576FB3CB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {6309142C-DBAE-47D5-9BCF-6AB6F3B24D18} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23079792 2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202}" was unlocked. <==== ATTENTION
Task: {81474A3A-5E30-45A7-87FE-566AA8EE5360} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\Windows\system32\gpupdate.exe [30720 2020-11-19] (Microsoft Windows -> Microsoft Corporation)
Task: {A9A20BF5-C5CB-4E1E-B3DE-E122A38ACE13} - System32\Tasks\Opera scheduled assistant Autoupdate 1608627186 => C:\Users\j.gb\AppData\Local\Programs\Opera\launcher.exe [1793688 2021-03-11] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\j.gb\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {B1539CA3-A5EC-4DAC-A9F1-E5B1018A985E} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141136 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {BC5E9969-1F6A-47D6-8DAD-3CB3AFACCCF1} - System32\Tasks\Opera scheduled Autoupdate 1608627185 => C:\Users\j.gb\AppData\Local\Programs\Opera\launcher.exe [1793688 2021-03-11] (Opera Software AS -> Opera Software)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA}" was unlocked. <==== ATTENTION
Task: {CE9F5343-2192-46F9-B667-266D339EC1FF} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\Windows\system32\gpupdate.exe [30720 2020-11-19] (Microsoft Windows -> Microsoft Corporation)
Task: {D1F125C3-4FD4-4025-AD11-8714470B9A46} - System32\Tasks\GE_CloudProxySettings_1.1_V03 => C:\Windows\Options\Packages\GE_CloudProxySettings_1.1_V03\SchTasks.EXE [133195 2017-07-24] () [File not signed]
Task: {F4C778B2-134C-420D-85B7-7DE8D070B83E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141136 2021-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {FCA4DB86-5AF9-4FE7-82B3-FC0F81A710F5} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1059336 2021-01-09] (Dell Inc -> Dell Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.20.11 8.8.8.8
Tcpip\..\Interfaces\{1bf34c8a-8607-42d7-b794-f40506edffaa}: [DhcpNameServer] 192.168.20.11 8.8.8.8
Tcpip\..\Interfaces\{79338ff9-755c-4fc2-897b-b0f4ecadaa5f}: [DhcpNameServer] 192.168.20.11 8.8.8.8
Tcpip\..\Interfaces\{ac8bc92f-de38-4010-b14d-caf54f08c7da}: [DhcpNameServer] 192.168.20.11 8.8.8.8
HKLM\System\...\Parameters\PersistentRoutes: [169.254.0.0,255.255.0.0,192.168.18.111,1]
HKLM\System\...\Parameters\PersistentRoutes: [169.254.0.0,255.255.0.0,192.168.20.114,1]
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\j.gb\AppData\Local\Microsoft\Edge\User Data\Default [2021-02-24]
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2021-01-08] [Legacy] [not signed]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-04-28] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-09-12] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems Incorporated -> Adobe Systems)
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-09-12]
Opera:
=======
OPR Profile: C:\Users\j.gb\AppData\Roaming\Opera Software\Opera Stable [2021-03-16]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=o ... utEncoding}
OPR Extension: (Translator) - C:\Users\j.gb\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnbpedcoekjafichoehopgaaldogogch [2021-01-11]
OPR Extension: (Rich Hints Agent) - C:\Users\j.gb\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-03-11]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1046904 2020-03-04] (Autodesk, Inc. -> Autodesk Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2021-01-08] () [File not signed]
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8988552 2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
R2 CmWebAdmin.exe; C:\Program Files\CodeMeter\Runtime\bin\CmWebAdmin.exe [12002208 2019-12-16] (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [287776 2020-10-25] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3750944 2020-10-25] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [507936 2020-10-25] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\DSAPI.exe [985584 2021-01-13] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [38592 2020-10-29] (Dell Inc -> )
R2 DellFFDPWmiService; C:\Windows\System32\drivers\DellFFDPWmiService.exe [32528 2020-02-17] ("STMicroelectronics Srl" -> )
S3 EHttpSrv; C:\Program Files\ESET\ESET Security\ehttpsrv.exe [49448 2020-11-11] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-11] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-11-11] (ESET, spol. s r.o. -> ESET)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] (Canon Inc. -> )
R2 KvEnumSrv; C:\Program Files\Kvaser\Drivers\32\kvenumsrv.exe [553640 2020-09-09] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R2 KvWiFiPairingSrv; C:\Program Files\Kvaser\Drivers\32\kvenumsrv.exe [553640 2020-09-09] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R2 MlPatch; C:\Windows\system32\MlPatch.exe [2244912 2014-08-22] (Magic Control Technology Corp. -> )
R2 RtkAudioUniversalService; C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1223224 2021-01-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5198064 2021-01-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39432 2021-01-09] (Dell Inc -> Dell Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12723480 2021-02-17] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R3 DDDriver; C:\Windows\System32\drivers\dddriver64Dcsa.sys [42376 2020-10-25] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [160992 2020-11-11] (ESET, spol. s r.o. -> ESET)
S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [109360 2020-11-11] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15824 2021-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [190464 2020-11-11] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [70560 2020-11-11] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [108808 2020-11-11] (ESET, spol. s r.o. -> ESET)
S3 f5ipfw; C:\Windows\system32\drivers\urfltv64.sys [44440 2020-09-10] (F5 Networks Inc -> F5 Networks, Inc.)
U3 Healcea; no ImagePath
S3 kcane; C:\Windows\system32\DRIVERS\kcane.sys [119352 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R3 kcanv; C:\Windows\system32\DRIVERS\kcanv.sys [98360 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R3 kvnetenum; C:\Windows\system32\DRIVERS\kvnetenum.sys [58424 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R2 kvsoftsync; C:\Windows\system32\Drivers\kvsoftsync.sys [32312 2020-09-17] (Kvaser AB -> KVASER AB, Mölndal, SWEDEN)
R3 LAN9500; C:\Windows\System32\drivers\lan9500-x64-n650f.sys [109408 2017-04-27] (Microchip Technology Inc. -> Microchip Technology Inc.)
R3 MctUsbAudio; C:\Windows\System32\drivers\MctFlt.sys [38680 2017-11-09] (Magic Control Technology Corp. -> Windows (R) Win 7 DDK provider)
R3 urvpndrv; C:\Windows\System32\drivers\covpnv64.sys [57736 2020-09-10] (F5 Networks Inc -> F5 Networks, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48536 2020-12-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [429296 2020-12-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-18] (Microsoft Windows -> Microsoft Corporation)
R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [118200 2020-03-18] (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
R3 WiManH; C:\Windows\System32\DriverStore\FileRepository\wiman.inf_amd64_4b0336d95f188e47\WiManH\WiManH.sys [168792 2020-09-02] (Intel Wireless Driver -> )
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-16 16:06 - 2021-03-16 16:06 - 000026621 _____ C:\Users\j.gb\Desktop\FRST.txt
2021-03-16 16:06 - 2021-03-16 16:06 - 000000000 ____D C:\FRST
2021-03-16 16:04 - 2021-03-16 16:04 - 002300928 _____ (Farbar) C:\Users\j.gb\Desktop\FRST64.exe
2021-03-16 11:58 - 2021-03-16 11:58 - 000000000 ____D C:\Users\j.gb\AppData\Local\Brice_Lambson
2021-03-16 11:56 - 2021-03-16 11:56 - 001083664 _____ (Brice Lambson) C:\Users\j.gb\Downloads\ImageResizerSetup-3.1.1.exe
2021-03-16 11:56 - 2021-03-16 11:56 - 000000000 ____D C:\Program Files\Image Resizer for Windows
2021-03-16 11:56 - 2021-03-16 11:56 - 000000000 ____D C:\Program Files (x86)\Image Resizer for Windows
2021-03-16 11:50 - 2021-03-16 11:58 - 000000000 ____D C:\Users\j.gb\Downloads\drive-download-20210316T104853Z-001
2021-03-16 11:49 - 2021-03-16 11:49 - 028919689 _____ C:\Users\j.gb\Downloads\drive-download-20210316T104853Z-001.zip
2021-03-15 10:22 - 2021-03-15 10:22 - 000000004 ____H C:\ProgramData\cm-lock
2021-03-15 10:21 - 2021-03-15 11:20 - 000307116 _____ C:\Users\j.gb\Desktop\29145583_Installation Protocol BC T200.pdf
2021-03-12 22:08 - 2021-03-12 22:10 - 000000000 ____D C:\Users\j.gb\Desktop\Fighting With My Family (2019) [WEBRip] [1080p] [YTS.AM]
2021-03-03 16:50 - 2021-03-03 16:50 - 000241456 _____ C:\Users\j.gb\Downloads\Dap2020Jenda.XLSX
2021-03-03 11:39 - 2021-03-03 11:39 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\Media Player Classic
2021-03-03 11:38 - 2021-03-03 11:38 - 001969179 _____ C:\Users\j.gb\Downloads\mpc_6490+_2kXP_cze.zip
2021-02-24 15:57 - 2021-02-24 15:57 - 000000000 ____D C:\Users\j.gb\AppData\Local\GHISLER
2021-02-24 15:56 - 2021-02-24 15:57 - 000000000 ____D C:\totalcmd
2021-02-24 15:56 - 2021-02-24 15:56 - 008095960 _____ (Ghisler Software GmbH) C:\Users\j.gb\Downloads\tcmd951x32_64.exe
2021-02-24 15:56 - 2021-02-24 15:56 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2021-02-24 15:56 - 2021-02-24 15:56 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\GHISLER
2021-02-24 11:43 - 2021-02-24 11:44 - 000000000 ____D C:\SERVICEmgr32
2021-02-24 11:39 - 2021-03-15 10:23 - 000000000 ____D C:\ProgramData\boost_interprocess
2021-02-24 11:21 - 2021-02-24 11:21 - 013746920 _____ (Kvaser AB, Mölndal, Sweden) C:\Users\j.gb\Downloads\kvaser_drivers_setup.exe
2021-02-24 11:21 - 2021-02-24 11:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kvaser CAN Drivers
2021-02-24 11:21 - 2021-02-24 11:21 - 000000000 ____D C:\Program Files\Kvaser
2021-02-24 11:21 - 2020-09-17 08:28 - 000156216 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcany.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000145976 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanyr.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000133176 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanl.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000126008 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanlr.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000119352 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanx.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000117816 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanf.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000112696 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanh.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000111160 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcans.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000098360 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kcanv.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000058424 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kvnetenum.sys
2021-02-24 11:21 - 2020-09-17 08:28 - 000032312 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\Drivers\kvsoftsync.sys
2021-02-24 11:21 - 2020-09-09 23:09 - 000670888 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\kvalapw2.dll
2021-02-24 11:21 - 2020-09-09 23:09 - 000564904 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\system32\kcanconf.exe
2021-02-24 11:21 - 2020-09-09 23:09 - 000538280 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\kvaser_vcndrvms.dll
2021-02-24 11:21 - 2020-09-09 23:09 - 000509608 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\canlib32.dll
2021-02-24 11:21 - 2020-09-09 23:09 - 000442024 _____ (KVASER AB, Mölndal, SWEDEN) C:\Windows\SysWOW64\kcanconf.exe
2021-02-24 11:18 - 2021-02-24 11:43 - 000262144 ____N (Microsoft Corporation) C:\Windows\Setup1.exe
2021-02-24 11:18 - 2021-02-24 11:43 - 000073216 _____ (Microsoft Corporation) C:\Windows\ST6UNST.EXE
2021-02-24 11:18 - 2021-02-24 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SERVICEmgr32
2021-02-24 11:18 - 2015-03-18 20:31 - 002896977 ____N C:\Windows\SERVIC~1.CAB
2021-02-23 12:48 - 2021-02-23 12:48 - 000665428 _____ C:\Users\j.gb\Downloads\potvrzeni (1).pdf
2021-02-23 11:51 - 2021-02-23 11:51 - 004526932 _____ C:\Users\j.gb\Downloads\SITUACE.pdf
2021-02-22 15:49 - 2021-02-22 15:49 - 000000000 ____D C:\Users\j.gb\Downloads\The-Prodigy---Diskografie-+Singly-(1991-2009)-(MP3-320kbps).Mp3_HQ-by-PiPeTamer
2021-02-22 11:14 - 2021-02-22 13:20 - 2277271356 _____ C:\Users\j.gb\Downloads\The-Prodigy---Diskografie-+Singly-(1991-2009)-(MP3-320kbps).Mp3_HQ-by-PiPeTamer.rar
2021-02-22 10:46 - 2021-02-22 10:46 - 001462176 _____ C:\Users\j.gb\Desktop\1_podlaží.psd
2021-02-22 10:45 - 2021-02-22 10:45 - 001695762 _____ C:\Users\j.gb\Desktop\1_podlaží.pdf
2021-02-16 12:09 - 2021-02-16 12:45 - 104941649 _____ C:\Users\j.gb\Downloads\PoR - PL.rar
2021-02-16 12:03 - 2021-02-16 12:23 - 354036255 _____ C:\Users\j.gb\Downloads\Mo-Do - Was Ist Das (1995)FLAC.rar
2021-02-16 12:00 - 2021-02-16 12:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoCAD 2018 – Čeština (Czech)
2021-02-16 11:59 - 2021-02-16 11:59 - 111747832 _____ (Autodesk, Inc.) C:\Users\j.gb\Downloads\AutoCAD_2018_Czech_LP_Win_64bit_dlm.sfx.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-16 16:04 - 2020-12-21 23:59 - 000000000 ____D C:\ProgramData\Adobe
2021-03-16 16:04 - 2020-12-21 23:26 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\Adobe
2021-03-16 16:02 - 2021-01-04 10:00 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\WhatsApp
2021-03-16 16:02 - 2020-12-21 23:17 - 000000136 _____ C:\Windows\system32\config\netlogon.ftl
2021-03-16 15:58 - 2020-11-18 23:46 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-03-16 15:58 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-03-16 11:56 - 2020-12-18 21:57 - 000000000 ____D C:\ProgramData\Package Cache
2021-03-16 11:50 - 2020-12-28 11:00 - 000000000 ____D C:\Program Files (x86)\anipart client
2021-03-16 11:50 - 2020-12-28 10:48 - 000000000 ____D C:\Users\j.gb\Documents\aniPart support
2021-03-16 08:58 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2021-03-16 08:50 - 2020-12-18 21:33 - 000000000 ____D C:\Windows\system32\MRT
2021-03-16 08:46 - 2020-12-18 21:33 - 131005360 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-03-15 20:40 - 2020-11-19 00:48 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-03-15 20:40 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-03-15 20:40 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2021-03-15 11:02 - 2021-01-04 10:00 - 000000000 ____D C:\Users\j.gb\AppData\Local\WhatsApp
2021-03-15 10:46 - 2020-11-08 12:08 - 000015824 _____ (ESET) C:\Windows\system32\Drivers\eelam.sys
2021-03-15 10:46 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2021-03-15 10:34 - 2021-02-12 13:27 - 000000000 ____D C:\ProgramData\Autodesk
2021-03-15 10:23 - 2020-12-21 23:30 - 000000000 ____D C:\Program Files\Microsoft Office
2021-03-15 10:23 - 2020-12-21 23:26 - 000000000 __SHD C:\Users\j.gb\IntelGraphicsProfiles
2021-03-15 10:23 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-03-15 10:22 - 2020-12-18 22:04 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-03-15 10:22 - 2020-12-18 21:39 - 000000000 ____D C:\Intel
2021-03-15 10:22 - 2020-12-18 21:26 - 000008192 ___SH C:\DumpStack.log.tmp
2021-03-15 10:22 - 2020-11-19 00:46 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-03-15 10:22 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ServiceState
2021-03-15 10:22 - 2019-12-07 10:03 - 000786432 _____ C:\Windows\system32\config\BBI
2021-03-15 10:06 - 2021-01-08 13:48 - 000000000 ____D C:\ProgramData\CanonIJPLM
2021-03-15 10:05 - 2020-12-22 00:00 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-03-15 10:04 - 2020-12-22 09:53 - 000004182 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1608627185
2021-03-15 10:04 - 2020-12-22 09:53 - 000001515 _____ C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2021-03-08 22:02 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\LiveKernelReports
2021-03-08 17:29 - 2020-12-28 10:34 - 000000000 ____D C:\Users\j.gb\Documents\Pharmatech
2021-03-04 12:35 - 2020-11-19 00:48 - 000003584 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-03-04 12:35 - 2020-11-19 00:48 - 000003460 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-03-04 10:00 - 2020-12-21 23:26 - 000003368 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-229502678-4061752961-2197657978-1117
2021-03-04 10:00 - 2020-12-21 23:26 - 000002407 _____ C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-03-04 10:00 - 2020-12-21 23:26 - 000000000 ___RD C:\Users\j.gb\OneDrive
2021-03-03 15:13 - 2020-12-28 10:32 - 000000000 ____D C:\Users\j.gb\Documents\Protokoly
2021-03-01 12:34 - 2020-12-21 23:26 - 000000000 ____D C:\Users\j.gb\AppData\Local\Packages
2021-03-01 11:51 - 2021-01-08 12:20 - 000000000 ____D C:\Users\j.gb\Desktop\Proformy
2021-02-26 03:29 - 2020-12-22 16:01 - 000002416 _____ C:\Users\j.gb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-02-24 16:05 - 2020-12-28 10:33 - 000000000 ____D C:\Users\j.gb\Documents\Projít
2021-02-24 12:02 - 2021-02-02 18:31 - 000000000 ____D C:\Users\j.gb\AppData\Local\Google
2021-02-24 12:02 - 2021-02-02 18:31 - 000000000 ____D C:\Program Files (x86)\Google
2021-02-24 11:43 - 2014-10-30 21:03 - 000001291 _____ C:\Windows\SERVICEmgr32.ini
2021-02-24 11:43 - 2006-01-19 13:22 - 000000526 _____ C:\Windows\Eptcan32.ini
2021-02-24 11:43 - 2003-11-04 15:56 - 000000259 _____ C:\Windows\xptcan32.ini
2021-02-24 11:39 - 2021-02-12 13:30 - 000000000 ____D C:\Users\j.gb\AppData\Local\Autodesk
2021-02-24 11:39 - 2021-02-12 13:23 - 000536984 _____ C:\Windows\system32\FNTCACHE.DAT
2021-02-24 11:37 - 2020-12-22 16:06 - 000000000 ____D C:\Users\j.gb\GRAPHISOFT
2021-02-24 11:37 - 2020-12-22 16:06 - 000000000 ____D C:\Users\j.gb\AppData\Roaming\GRAPHISOFT
2021-02-24 11:37 - 2020-12-22 16:06 - 000000000 ____D C:\Users\j.gb\AppData\Local\GRAPHISOFT
2021-02-24 11:18 - 2020-12-28 10:43 - 000000000 ____D C:\SERVICEmgr323
2021-02-23 13:34 - 2020-12-28 10:27 - 000000000 ____D C:\Users\j.gb\Documents\Dům
2021-02-22 11:33 - 2021-01-08 12:40 - 000000000 ____D C:\Users\j.gb\AppData\Local\CrashDumps
2021-02-17 14:29 - 2020-12-21 23:26 - 000000000 ____D C:\Users\j.gb
2021-02-16 12:00 - 2021-02-12 13:29 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared
2021-02-16 12:00 - 2021-02-12 13:29 - 000000000 ____D C:\Program Files\Autodesk
2021-02-16 12:00 - 2021-02-12 13:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2021-02-16 11:59 - 2021-02-12 12:37 - 000000000 ____D C:\Autodesk
2021-02-15 13:14 - 2020-12-28 10:32 - 000000000 ____D C:\Users\j.gb\Documents\Výkazy f
2021-02-15 13:14 - 2020-12-28 10:26 - 000000000 ____D C:\Users\j.gb\Documents\AutoDELFIA
==================== Files in the root of some directories ========
2021-01-08 10:08 - 2021-01-08 10:08 - 000003584 _____ () C:\Users\j.gb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2021-01-08 12:29 - 2021-01-08 12:29 - 000000017 _____ () C:\Users\j.gb\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================