
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Nejde aktualizovat antivirus, občas na ntb nefungují klávesy
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Nejde aktualizovat antivirus, občas na ntb nefungují klávesy
Dobrý den,
nejde mi aktualizovat antivirus a poslední dny i občas vypadávají některé klávesy a nejsou použít (c, 1, + atd.). Externí klávesnice přes usb funguje bez problému. Níže posílám logy. Moc díky!
LOG FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-04-2020
Ran by ASUS (administrator) on LAPTOP-P7ISUMHN (ASUSTeK COMPUTER INC. X555UB) (16-04-2020 22:55:12)
Running from C:\Users\ASUS\Desktop
Loaded Profiles: ASUS (Available Profiles: ASUS)
Platform: Windows 10 Home Version 1903 18362.720 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ASUS) [File not signed] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\95.4.441\QtWebEngineProcess.exe <2>
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\IntelCpHeciSvc.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1910.0.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12004.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2654512 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1710568 2015-10-03] (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed]
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [185648 2020-04-16] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [6287872 2020-04-14] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (Canon Inc. -> CANON INC.)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\Run: [Spotify] => C:\Users\ASUS\AppData\Roaming\Spotify\Spotify.exe [25828256 2019-08-07] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\Run: [utweb] => "C:\Users\ASUS\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-07] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-07-16] () [File not signed]
Startup: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2019-01-02]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {016098B7-51BD-4F46-8442-93508020D024} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
Task: {1145D8EC-E022-45B0-8CA2-14CCE85B9A28} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [979024 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {1B73E7D3-C637-4C60-8413-F22E7A616AF6} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19786024 2016-08-24] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
Task: {2055FF96-5C04-4532-B5BB-0A81AF83BFAB} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-09-25] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {20581BC9-C280-411F-9428-8FDDA65D80DD} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18392 2016-09-02] (ASUSTeK Computer Inc. -> AsusTek)
Task: {23DE882E-5C0E-43DA-88CA-5237E49139C5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [381008 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {2A453FA6-E159-4366-B5F8-3584C0BAFF27} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [143160 2019-03-12] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
Task: {3050956C-B469-410F-AC64-A5E722F847F8} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [979024 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {587FAA25-E1BB-452C-A82B-7B6AE6408D2A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-04] (Google Inc -> Google LLC)
Task: {6AABB440-4C4A-4D97-B20D-52D2E1BD7A3B} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {7243A93E-CFB0-4E9B-B68A-7B2F635868A6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [381008 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {864F0ABE-DEAD-4AF2-91DD-B305A986896F} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {944B1A1D-DEEA-4C1D-8873-0FDA93A20875} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {9FCB19FD-E872-4C51-9487-1D67D669E241} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-04] (Google Inc -> Google LLC)
Task: {A0DADCFA-2CEF-461D-BA19-578E59E1731F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-04-14] (Adobe Inc. -> Adobe)
Task: {A9616661-15D3-4DF4-B698-6D0D87B732E9} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [55808 2016-10-13] (ASUS) [File not signed]
Task: {C50D6151-5360-4E0B-913A-A99949EE4F86} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
Task: {D6300E77-BAF1-4DB7-A29F-95A630F53802} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16404224 2015-09-25] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {FAA92723-E23B-4D95-B606-E093664D5440} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_363_Plugin.exe [1458232 2020-04-14] (Adobe Inc. -> Adobe)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-3592886365-2214475677-956089615-1001] => http=127.0.0.1:8888;
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{20173415-1306-4b9e-a498-ef6a7ed15ffd}: [NameServer] 104.197.28.121,104.155.237.225
Tcpip\..\Interfaces\{b1a144a7-b23f-4b94-8a56-af0fdd1d8652}: [NameServer] 104.197.28.121,104.155.237.225
Tcpip\..\Interfaces\{b1a144a7-b23f-4b94-8a56-af0fdd1d8652}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{fba65c9a-dd42-4d33-bc52-ccc094258f2d}: [NameServer] 104.197.28.121,104.155.237.225
Tcpip\..\Interfaces\{fba65c9a-dd42-4d33-bc52-ccc094258f2d}: [DhcpNameServer] 192.168.4.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2020-03-09] (Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: css304qo.default-1548098639133
FF ProfilePath: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133 [2020-04-16]
FF Extension: (Download Manager (S3)) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\s3download@statusbar.xpi [2019-12-11]
FF Extension: (Porn/Malware Blocker) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{3df17fe5-3cb9-4b09-a704-1140eca22dfd}.xpi [2019-07-02]
FF Extension: (Public Fox) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{9AA46F4F-4DC7-4c06-97AF-6665170634FE}.xpi [2019-07-02]
FF Extension: (Private Begone) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{9c0fdd1d-a568-4247-99df-efa3a3727008}.xpi [2019-07-02]
FF Extension: (Video DownloadHelper) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-03-31]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_363.dll [2020-04-14] (Adobe Inc. -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_363.dll [2020-04-14] (Adobe Inc. -> )
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3592886365-2214475677-956089615-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\ASUS\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-04-02] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-04-16]
Chrome:
=======
CHR Profile: C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default [2020-04-08]
CHR Extension: (Prezentace) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-07-04]
CHR Extension: (Dokumenty) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-07-04]
CHR Extension: (Disk Google) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-07-04]
CHR Extension: (YouTube) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-07-04]
CHR Extension: (Tabulky) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-07-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-23]
CHR Extension: (Profitario - AliExpress Invoices For Free) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gohemgflodfhnlmbimcgefjnnmjmgnka [2020-04-08]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-11-06]
CHR Extension: (Gmail) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-04]
CHR Extension: (Chrome Media Router) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-08]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058256 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44552 2020-04-14] (Dropbox, Inc -> Dropbox, Inc.)
S3 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [326032 2018-06-05] (ASUSTeK Computer Inc. -> )
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2358784 2020-04-16] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2358784 2020-04-16] (ESET, spol. s r.o. -> ESET)
R2 esifsvc; C:\WINDOWS\SysWOW64\esif_uf.exe [1385640 2015-08-17] (Intel(R) Software -> Intel Corporation)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1208392 2020-01-04] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6617160 2020-01-04] (GOG Sp. z o.o. -> GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155376 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel® Trusted Connect Service -> Intel(R) Corporation)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2015-08-07] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568816 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2495792 2020-04-08] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3447608 2020-04-08] (Electronic Arts, Inc. -> Electronic Arts)
R2 RtkBtManServ; C:\WINDOWS\RtkBtManServ.exe [713816 2018-09-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\NisSrv.exe [3630832 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MsMpEng.exe [103168 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AiCharger; C:\WINDOWS\System32\DRIVERS\AiCharger.sys [29312 2016-08-24] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R2 ASMMAP64; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [18048 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUS)
R3 AsusSGDrv; C:\WINDOWS\system32\DRIVERS\AsusSGDrv.sys [152064 2016-09-02] (ASUSTeK Computer Inc. -> ASUS Corporation)
R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
S3 bsitf; C:\WINDOWS\system32\DRIVERS\bsitf.sys [37208 2018-12-17] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 CH341SER_A64; C:\WINDOWS\System32\Drivers\CH341S64.SYS [59904 2015-01-26] (http://www.winchiphead.com) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [136040 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [55816 2015-08-17] (Intel(R) Software -> Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [53752 2015-08-17] (Intel(R) Software -> Intel Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [154336 2020-04-16] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15800 2019-05-31] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [188872 2020-04-16] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [115960 2020-04-16] (ESET, spol. s r.o. -> ESET)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [261624 2015-08-17] (Intel(R) Software -> Intel Corporation)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32680 2019-08-07] (ASUSTek Computer Inc. -> ASUS)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvam.inf_amd64_1aae4f19e68d0780\nvlddmkm.sys [17003280 2017-12-12] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50472 2015-08-10] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [898296 2016-01-13] (Realtek Semiconductor Corp -> Realtek )
R3 RtkBtFilter; C:\WINDOWS\System32\drivers\RtkBtfilter.sys [758312 2018-09-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [428032 2017-02-16] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S3 RTWlanE01; C:\WINDOWS\System32\drivers\rtwlane01.sys [8169472 2019-03-19] (Microsoft Windows -> Realtek Semiconductor Corporation )
R3 RTWlanE02; C:\WINDOWS\System32\drivers\rtwlane02.sys [9599440 2018-12-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )
S3 RvNetMP60; C:\WINDOWS\System32\drivers\RvNetMP60.sys [69048 2018-12-25] (Famatech Corp. -> Famatech Corp.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166760 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46472 2019-09-17] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [346336 2019-09-17] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-09-17] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-16 22:55 - 2020-04-16 22:57 - 000028564 _____ C:\Users\ASUS\Desktop\FRST.txt
2020-04-16 22:53 - 2020-04-16 22:56 - 000000000 ____D C:\FRST
2020-04-16 22:52 - 2020-04-16 22:52 - 002281472 _____ (Farbar) C:\Users\ASUS\Desktop\FRST64(1).exe
2020-04-16 22:51 - 2020-04-16 22:51 - 001222144 _____ C:\Users\ASUS\Desktop\RSITx64.exe
2020-04-16 22:48 - 2020-04-16 22:49 - 016842232 _____ (VS Revo Group ) C:\Users\ASUS\Downloads\RevoUninProSetup(1).exe
2020-04-16 22:47 - 2020-04-16 22:47 - 000000000 ____D C:\ProgramData\VS Revo Group
2020-04-16 22:46 - 2020-04-16 22:47 - 016842232 _____ (VS Revo Group ) C:\Users\ASUS\Downloads\RevoUninProSetup.exe
2020-04-16 22:15 - 2020-04-16 22:22 - 000376338 _____ C:\WINDOWS\ntbtlog.txt
2020-04-16 22:15 - 2020-04-16 22:15 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2020-04-16 17:58 - 2020-04-16 17:58 - 000001930 _____ C:\Users\ASUS\Desktop\Zoom.lnk
2020-04-16 17:32 - 2020-04-16 17:32 - 002281472 _____ (Farbar) C:\Users\ASUS\Downloads\FRST64.exe
2020-04-15 21:31 - 2020-04-15 21:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2020-04-15 16:10 - 2020-04-15 15:09 - 1015786561 _____ C:\Users\ASUS\Desktop\20200415_150144.mp4
2020-04-15 13:50 - 2020-04-15 13:50 - 000050695 _____ C:\Users\ASUS\Downloads\Online-bohoslužba_-Vyhrávat-boj-v-mysli(1).srt
2020-04-15 10:54 - 2020-04-15 10:54 - 000050695 _____ C:\Users\ASUS\Downloads\Online-bohoslužba_-Vyhrávat-boj-v-mysli.srt
2020-04-14 20:23 - 2020-04-14 20:23 - 000048474 _____ C:\Users\ASUS\Downloads\receipt_of_the_MSF_funds.pdf
2020-04-14 19:33 - 2020-04-14 19:34 - 001032443 _____ C:\Users\ASUS\Desktop\payment_confirmation.pdf
2020-04-14 19:33 - 2020-04-14 19:33 - 000258395 _____ C:\Users\ASUS\Desktop\stansted-express-tickets.pdf
2020-04-14 14:19 - 2020-04-14 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2020-04-14 14:19 - 2020-04-14 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2020-04-14 14:19 - 2020-04-14 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2020-04-14 14:19 - 2020-04-14 14:19 - 000044552 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2020-04-09 15:05 - 2020-04-09 15:14 - 705736289 _____ C:\Users\ASUS\Downloads\steve rec 2.mov
2020-04-09 15:05 - 2020-04-09 15:12 - 1169822987 _____ C:\Users\ASUS\Downloads\IMG_5021.mov
2020-04-08 18:47 - 2020-04-08 18:47 - 000885061 _____ C:\Users\ASUS\Downloads\Otcovská Inventura.pdf
2020-04-08 18:13 - 2020-04-08 18:13 - 005876422 _____ C:\Users\ASUS\Downloads\Brožura_2020_03.pdf
2020-04-08 14:34 - 2020-04-08 14:34 - 000000000 ____D C:\Users\ASUS\Desktop\Gaute
2020-04-08 14:29 - 2020-04-08 14:29 - 000010880 _____ C:\Users\ASUS\Desktop\FINANCE 2020.xlsx
2020-04-08 11:10 - 2020-04-08 12:31 - 000001288 _____ C:\Users\ASUS\Downloads\Vyhledane pohyby(1).csv
2020-04-07 12:13 - 2020-04-07 12:13 - 000013742 _____ C:\Users\ASUS\Downloads\CityHouse Brno rozpočet ústředí 2020.xlsx
2020-04-07 12:13 - 2020-04-07 12:13 - 000013741 _____ C:\Users\ASUS\Desktop\CityHouse Brno rozpočet ústředí 2020.xlsx
2020-04-07 12:01 - 2020-04-07 12:13 - 000013742 _____ C:\Users\ASUS\Downloads\vzor rozpočet ústředí.xlsx
2020-04-02 20:24 - 2020-04-02 20:24 - 000080021 _____ C:\Users\ASUS\Desktop\SÉRIE NA KVĚTEN 2020_OTEVŘENÁ CÍRKEV.pdf
2020-04-02 19:32 - 2020-04-02 19:32 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2020-04-01 19:01 - 2020-04-16 21:46 - 000063443 _____ C:\Users\ASUS\Desktop\Michal výkaz.xlsx
2020-04-01 16:48 - 2020-04-01 15:00 - 1443154931 _____ C:\Users\ASUS\Downloads\20200401_144927.mp4
2020-04-01 16:46 - 2020-04-01 16:46 - 000063358 _____ C:\Users\ASUS\Downloads\Od-pondělí-do-soboty.pdf
2020-04-01 10:03 - 2020-04-01 11:56 - 000000000 ____D C:\Users\ASUS\Desktop\Leaderscape
2020-03-31 23:27 - 2020-03-31 23:29 - 312692117 _____ C:\Users\ASUS\Downloads\MYSLENKA DNE_1.mov
2020-03-31 22:00 - 2020-03-31 22:00 - 000000000 ____D C:\Users\ASUS\Documents\Zoom
2020-03-31 10:19 - 2020-04-16 17:58 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Zoom
2020-03-30 18:59 - 2020-03-30 19:02 - 000010437 _____ C:\Users\ASUS\Desktop\DOVOLENÁ-DOCHÁZKA, AC CityHouse BRNO, BŘEZEN 2020.xlsx
2020-03-30 18:57 - 2020-03-30 18:57 - 000010450 _____ C:\Users\ASUS\Downloads\DOVOLENÁ-DOCHÁZKA, AC CityHouse BRNO, LISTOPAD 2019.xlsx
2020-03-30 17:57 - 2020-03-30 17:57 - 000002523 _____ C:\Users\Public\Desktop\Evernote.lnk
2020-03-30 17:57 - 2020-03-30 17:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2020-03-28 10:39 - 2020-03-28 10:39 - 000066478 _____ C:\Users\ASUS\Downloads\Philips mg5730_15 doklad.PDF
2020-03-27 15:31 - 2020-03-27 15:34 - 206885503 _____ C:\Users\ASUS\Downloads\Better.Call.Saul.S05E06.720p.WEB.x265-MiNX.mkv
2020-03-25 21:17 - 2020-03-25 21:20 - 768289102 _____ C:\Users\ASUS\Downloads\Bez vedomi 1.dil (2019) CZ dabing 720p.avi
2020-03-25 16:20 - 2020-03-25 16:20 - 000000231 _____ C:\Users\ASUS\Desktop\Assassin's Creed II.url
2020-03-25 16:17 - 2020-03-25 16:17 - 000000000 ____D C:\ProgramData\Ubisoft
2020-03-25 16:16 - 2020-03-31 12:13 - 000000000 ____D C:\Users\ASUS\AppData\Local\Ubisoft Game Launcher
2020-03-25 16:16 - 2020-03-25 16:16 - 000001276 _____ C:\Users\ASUS\Desktop\Uplay.lnk
2020-03-25 16:16 - 2020-03-25 16:16 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2020-03-25 16:16 - 2020-03-25 16:16 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2020-03-25 16:15 - 2020-03-25 16:16 - 130190792 _____ (Ubisoft) C:\Users\ASUS\Downloads\UplayInstaller.exe
2020-03-24 22:01 - 2020-03-24 22:05 - 885251494 _____ C:\Users\ASUS\Downloads\homeland.s08e01.720p.web.h264-xlf[eztv].mkv
2020-03-24 19:24 - 2020-03-24 19:24 - 1256973640 _____ C:\WINDOWS\MEMORY.DMP
2020-03-24 19:24 - 2020-03-24 19:24 - 000000000 ____D C:\WINDOWS\Minidump
2020-03-23 18:53 - 2020-03-23 18:53 - 000725905 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.10_podloženo(1).pdf
2020-03-23 18:53 - 2020-03-23 18:53 - 000102442 _____ C:\Users\ASUS\Downloads\GC_1PP_S_kuchyn_rozsireni2_V3_návrh.pdf
2020-03-23 18:42 - 2020-03-23 18:43 - 000725905 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.10_podloženo.pdf
2020-03-19 23:51 - 2020-03-19 23:51 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3592886365-2214475677-956089615-1001
2020-03-19 14:24 - 2020-03-19 14:36 - 1229959458 _____ C:\Users\ASUS\Downloads\1080p.mov
2020-03-18 19:52 - 2020-03-18 19:59 - 000000000 ____D C:\Users\ASUS\Documents\FIFA 18
2020-03-18 19:45 - 2020-03-18 19:46 - 000000000 ____D C:\Users\ASUS\AppData\Local\Intel
2020-03-18 16:27 - 2020-03-18 16:27 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2020-03-18 16:25 - 2019-10-30 08:16 - 001082472 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 001082472 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 000940136 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 000940136 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 000853352 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-03-18 16:25 - 2019-10-30 08:16 - 000853352 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-03-18 16:25 - 2019-10-30 08:16 - 000711016 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-03-18 16:25 - 2019-10-30 08:16 - 000711016 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-03-18 16:25 - 2019-10-30 08:15 - 000281616 _____ C:\WINDOWS\system32\igfxCPL.cpl
2020-03-18 16:25 - 2019-10-30 08:15 - 000168976 _____ C:\WINDOWS\SysWOW64\libGLESv2.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000141840 _____ C:\WINDOWS\SysWOW64\libGLESv1_CM.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000136720 _____ C:\WINDOWS\SysWOW64\libEGL.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000121360 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000108048 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-03-18 16:25 - 2019-10-30 05:16 - 000212464 _____ (Intel Corporation) C:\WINDOWS\system32\intel_gfx_api-x64.dll
2020-03-18 16:25 - 2019-10-30 05:16 - 000184144 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\intel_gfx_api-x86.dll
2020-03-17 19:15 - 2020-03-17 19:15 - 000000000 ____D C:\Users\ASUS\AppData\Local\Electronic Arts
2020-03-17 15:36 - 2020-03-17 15:36 - 000001222 _____ C:\Users\Public\Desktop\FIFA 18.lnk
2020-03-17 15:36 - 2020-03-17 15:36 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller
2020-03-17 15:36 - 2020-03-17 15:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 18
2020-03-17 13:44 - 2020-04-14 18:13 - 000000000 ____D C:\Program Files (x86)\Origin Games
2020-03-17 13:40 - 2020-03-17 19:15 - 000000000 ____D C:\ProgramData\Electronic Arts
2020-03-17 13:38 - 2020-03-17 13:38 - 000001064 _____ C:\Users\Public\Desktop\Origin.lnk
2020-03-17 13:38 - 2020-03-17 13:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2020-03-17 13:37 - 2020-04-10 10:46 - 000000000 ____D C:\Program Files (x86)\Origin
2020-03-17 13:24 - 2020-04-14 18:13 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Origin
2020-03-17 13:24 - 2020-04-14 18:13 - 000000000 ____D C:\ProgramData\Origin
2020-03-17 13:24 - 2020-03-17 13:24 - 000000000 ____D C:\Users\ASUS\.QtWebEngineProcess
2020-03-17 13:24 - 2020-03-17 13:24 - 000000000 ____D C:\Users\ASUS\.Origin
2020-03-17 13:23 - 2020-04-14 13:27 - 000000000 ____D C:\Users\ASUS\AppData\Local\Origin
2020-03-17 13:21 - 2020-03-17 13:21 - 000203318 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.12_2.NP_200316(1).pdf
2020-03-17 13:19 - 2020-03-17 13:23 - 063645768 _____ (Electronic Arts) C:\Users\ASUS\Downloads\OriginThinSetup.exe
2020-03-17 13:10 - 2020-03-17 13:10 - 000007260 _____ C:\Users\ASUS\Downloads\index2.jfif
2020-03-17 12:54 - 2020-03-17 12:54 - 000000222 _____ C:\Users\ASUS\Desktop\Risen 3 - Titan Lords.url
2020-03-17 12:48 - 2020-03-17 12:48 - 000007787 _____ C:\Users\ASUS\Downloads\index.jfif
2020-03-17 10:11 - 2020-03-17 10:11 - 000000000 ___RD C:\Users\ASUS\Downloads\Microsoft.SkypeApp_kzf8qxf38zg5c!App
2020-03-17 09:07 - 2020-03-17 09:07 - 000203318 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.12_2.NP_200316.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-16 22:30 - 2018-12-19 18:22 - 000000000 ____D C:\Users\ASUS\AppData\LocalLow\Mozilla
2020-04-16 22:27 - 2018-12-14 21:46 - 000000200 _____ C:\Users\ASUS\AppData\Roaming\sp_data.sys
2020-04-16 22:26 - 2018-12-14 21:45 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2020-04-16 22:25 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF
2020-04-16 22:23 - 2019-07-20 17:16 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-16 22:23 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-16 22:23 - 2018-12-14 21:43 - 000000000 __SHD C:\Users\ASUS\IntelGraphicsProfiles
2020-04-16 22:23 - 2018-12-14 20:46 - 000000000 ____D C:\ProgramData\NVIDIA
2020-04-16 22:22 - 2019-03-19 06:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2020-04-16 22:20 - 2019-04-21 14:11 - 000000000 ____D C:\Users\ASUS\AppData\Local\ElevatedDiagnostics
2020-04-16 21:17 - 2018-12-19 18:25 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-04-16 21:00 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-16 21:00 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-16 19:01 - 2019-09-09 15:18 - 000188872 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-04-16 19:01 - 2019-09-09 15:18 - 000154336 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-04-16 19:01 - 2019-09-09 15:18 - 000115960 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-04-16 18:38 - 2019-07-20 16:52 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-15 21:31 - 2018-12-28 18:23 - 000000000 ____D C:\Program Files (x86)\Dropbox
2020-04-15 18:06 - 2018-12-31 13:33 - 000000000 ___RD C:\Users\ASUS\Dropbox
2020-04-14 16:28 - 2019-07-20 17:16 - 000004652 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier
2020-04-14 16:28 - 2019-07-20 17:16 - 000004506 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-04-14 16:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-04-14 16:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-04-13 22:39 - 2018-12-14 21:43 - 000000000 ____D C:\Users\ASUS\AppData\Local\Packages
2020-04-13 10:11 - 2018-12-21 23:21 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\vlc
2020-04-10 16:35 - 2019-01-21 21:23 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-04-10 16:35 - 2019-01-21 21:23 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-04-10 10:49 - 2019-01-21 21:23 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-04-07 23:06 - 2019-07-04 11:06 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-07 08:05 - 2019-07-20 17:13 - 001693640 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-07 08:05 - 2019-03-19 13:55 - 000719670 _____ C:\WINDOWS\system32\perfh005.dat
2020-04-07 08:05 - 2019-03-19 13:55 - 000145698 _____ C:\WINDOWS\system32\perfc005.dat
2020-04-04 23:17 - 2019-07-19 21:31 - 000000000 ____D C:\Users\ASUS
2020-03-31 23:34 - 2019-03-27 11:35 - 000000000 ____D C:\Users\ASUS\Documents\FFOutput
2020-03-21 10:57 - 2019-07-20 17:16 - 000003474 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-21 10:57 - 2019-07-20 17:16 - 000003350 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-19 23:51 - 2019-07-19 21:31 - 000002360 _____ C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-19 23:51 - 2018-12-14 21:47 - 000000000 ___RD C:\Users\ASUS\OneDrive
2020-03-19 11:40 - 2018-12-19 18:16 - 000000000 ____D C:\Users\ASUS\AppData\Local\PlaceholderTileLogoFolder
2020-03-19 00:44 - 2018-12-19 18:18 - 000000000 ____D C:\Program Files (x86)\Steam
2020-03-18 19:49 - 2018-12-19 20:20 - 000000000 ____D C:\Users\ASUS\AppData\Local\D3DSCache
2020-03-18 19:48 - 2018-12-19 18:30 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2020-03-18 16:27 - 2018-12-14 20:41 - 000000000 ____D C:\ProgramData\Intel
2020-03-18 16:27 - 2018-12-14 20:40 - 000000000 ____D C:\Program Files\Intel
2020-03-17 16:34 - 2019-07-20 17:16 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-17 16:33 - 2018-12-19 18:22 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-17 15:34 - 2018-12-14 20:39 - 000000000 ____D C:\ProgramData\Package Cache
==================== Files in the root of some directories ========
2018-12-14 21:46 - 2020-04-16 22:27 - 000000200 _____ () C:\Users\ASUS\AppData\Roaming\sp_data.sys
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
ADDITION.TXT
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2020
Ran by ASUS (16-04-2020 22:59:01)
Running from C:\Users\ASUS\Desktop
Windows 10 Home Version 1903 18362.720 (X64) (2019-07-20 15:17:06)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3592886365-2214475677-956089615-500 - Administrator - Disabled)
ASUS (S-1-5-21-3592886365-2214475677-956089615-1001 - Administrator - Enabled) => C:\Users\ASUS
DefaultAccount (S-1-5-21-3592886365-2214475677-956089615-503 - Limited - Disabled)
Guest (S-1-5-21-3592886365-2214475677-956089615-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3592886365-2214475677-956089615-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 18.05 (x64) (HKLM\...\7-Zip) (Version: 18.05 - Igor Pavlov)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.363 - Adobe)
Assassin's Creed II (HKLM-x32\...\Uplay Install 4) (Version: - Ubisoft)
ASUS Device Activation (HKLM-x32\...\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}) (Version: 1.0.4.0 - ASUSTeK COMPUTER INC.)
ASUS HiPost (HKLM-x32\...\{04768366-F421-4BA5-8423-B84F644B5249}) (Version: 1.0.6 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.6.8 - ASUSTeK COMPUTER INC.)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.16 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.19.0004 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.1.8 - ASUS)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0040 - ASUS)
Audacity 2.3.2 (HKLM-x32\...\Audacity_is1) (Version: 2.3.2 - Audacity Team)
AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.0.93 - ICEpower a/s)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - Canon Inc.)
Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version: - )
Dropbox (HKLM-x32\...\Dropbox) (Version: 95.4.441 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.295.1 - Dropbox, Inc.) Hidden
EPUB File Reader (HKLM-x32\...\{818C5857-5C74-4CAC-9F43-E5597086852D}_is1) (Version: - epubfilereader.com)
ESET Security (HKLM\...\{1CE8E9F0-4D99-4C80-B3CB-4A19C083B2B5}) (Version: 13.1.21.0 - ESET, spol. s r.o.)
Evernote v. 6.24.2 (HKLM-x32\...\{A8B80634-6257-11EA-8C8E-005056951CAD}) (Version: 6.24.2.8919 - Evernote Corp.)
FIFA 18 (HKLM-x32\...\{213CC10A-B8CB-4EBA-B277-6B08B7C22A65}) (Version: 1.0.57.57320 - Electronic Arts)
FM Genie Scout 17g version 1.1 17.3.2 (HKLM-x32\...\FM Genie Scout 17g_is1) (Version: 1.1 17.3.2 - )
FMRTE 17.3.2.23 (HKLM\...\{72A84F14-6742-48AD-9B14-E9C1BE155F7A}_is1) (Version: 17.3.2.23 - FMRTE)
Football Manager 2017 (HKLM\...\Football Manager 2017_is1) (Version: 1.0 - )
Football Manager 2017 Editor (HKLM\...\Football Manager 2017 Editor_is1) (Version: 1.0 - )
FormatFactory 2.60 (HKLM-x32\...\FormatFactory) (Version: 2.60 - Free Time)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
GTA San Andreas CZ (HKLM-x32\...\GTA San Andreas CZ 1.3.0) (Version: 1.3.0 - Rockstar Games)
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10603.192 - Intel Corporation)
Intel(R) Chipset Device Software (HKLM-x32\...\{a2d9fda8-65eb-4c06-81ef-31e0a4daa335}) (Version: 10.1.1.11 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.7325 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Krtek a jeho veliké dobrodružství (HKLM-x32\...\{5DF18D93-076F-4E90-B6CF-3CF96110F1D4}_is1) (Version: - Play sp. z o. o.)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Office 2013 pro profesionály - cs-cz (HKLM\...\ProfessionalRetail - cs-cz) (Version: 15.0.5215.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 15.0.5215.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 75.0 (x64 cs) (HKLM\...\Mozilla Firefox 75.0 (x64 cs)) (Version: 75.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 64.0.2 - Mozilla)
NVIDIA GeForce Experience 2.5.15.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.46 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (HKLM\...\{90150000-008C-0000-1000-0000000FF1CE}) (Version: 15.0.5215.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-007E-0000-1000-0000000FF1CE}) (Version: 15.0.5215.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM\...\{90150000-008C-0405-1000-0000000FF1CE}) (Version: 15.0.5215.1000 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 10.5.67.39484 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 388.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.57 - NVIDIA Corporation) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31233 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.3.723.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7620 - Realtek Semiconductor Corp.)
SafeSurfer-Desktop 1.0.2 (HKLM\...\{50c8ce74-58ce-5a3c-a7b4-e66f974a2b23}) (Version: 1.0.2 - Safe Surfer)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 4.1.500 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 2.5.15.46 - NVIDIA Corporation) Hidden
Spotify (HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\Spotify) (Version: 1.1.12.449.g4109e645 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
The Witcher 2 - Assassins of Kings Enhanced Edition (HKLM-x32\...\1207658930_is1) (Version: 3.5.0.26 - GOG.com)
Theophilos 3 (HKLM-x32\...\Theophilos_is1) (Version: - )
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 104.0 - Ubisoft)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Windows Driver Package - ASUS (AsusSGDrv) Mouse (08/19/2016 8.0.0.26) (HKLM\...\912D9B7DE050AA48F945407778CC01897B5E23BB) (Version: 08/19/2016 8.0.0.26 - ASUS)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.2.2 - ASUSTeK COMPUTER INC.)
Zoom (HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\ZoomUMX) (Version: 4.6 - Zoom Video Communications, Inc.)
Packages:
=========
Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_2.9.0.1_neutral__6e5tt8cgb93ep [2020-03-11] (Canon Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-02] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-02] (Microsoft Corporation) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.96.725.0_x64__mcm4njqhnhss8 [2020-04-11] (Netflix, Inc.)
PowerPoint Mobile -> C:\Program Files\WindowsApps\Microsoft.Office.PowerPoint_16001.12730.20086.0_x64__8wekyb3d8bbwe [2020-04-16] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3592886365-2214475677-956089615-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\ASUS\Dropbox [2018-12-31 13:33]
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-04-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-04-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\igfxDTCM.dll [2019-10-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-04-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2016-10-13 08:17 - 2016-10-13 08:17 - 000125440 _____ () [File not signed] C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000033280 _____ () [File not signed] C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000029184 _____ () [File not signed] C:\Program Files (x86)\ASUS\Splendid\VideoEnhance.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 001676288 _____ (ASUS TeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\Splendid\ApplyLUT.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000178176 _____ (ASUS TeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\Splendid\GenLUT.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000165888 _____ (ASUSTeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\Splendid\ColorU.dll
2019-01-21 22:23 - 2011-01-15 17:45 - 000319488 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNSS_ENU.DLL
2019-01-21 22:22 - 2012-06-14 18:18 - 000359936 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMN6PPM.DLL
2018-12-25 19:39 - 2018-04-30 14:00 - 000075776 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2018-12-14 20:46 - 2015-10-03 04:23 - 001439184 _____ (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed] C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll
2020-03-17 13:37 - 2020-03-16 15:05 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2020-03-24 23:24 - 2020-03-16 15:06 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2020-03-24 23:24 - 2020-03-17 13:37 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-12 01:38 - 2018-04-12 01:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ASUS\Downloads\1464434a46adb17ab7ab8d3ad8eaaa0d.jpg
DNS Servers: 104.197.28.121 - 104.155.237.225
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\StartupApproved\Run: => "Spotify"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{96351871-B984-451A-94E5-5A1E6B162B41}C:\users\asus\desktop\fmrte 17.3.1\amped.exe] => (Allow) C:\users\asus\desktop\fmrte 17.3.1\amped.exe (AMPED) [File not signed]
FirewallRules: [UDP Query User{5A25C015-0035-49E1-9237-EEECBC4A3A74}C:\users\asus\desktop\fmrte 17.3.1\amped.exe] => (Allow) C:\users\asus\desktop\fmrte 17.3.1\amped.exe (AMPED) [File not signed]
FirewallRules: [{13A52804-00A2-4D2A-9B31-53DED8D173B3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{DF793086-1F0D-4DF9-8EA4-4A5483FE49D4}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{6CB9C1CA-3EE9-4540-B77C-403D94374F13}C:\program files\safesurfer-desktop\safesurfer-desktop.exe] => (Allow) C:\program files\safesurfer-desktop\safesurfer-desktop.exe (Safe Surfer) [File not signed]
FirewallRules: [UDP Query User{11C44091-A387-4E47-AB18-515693EB6051}C:\program files\safesurfer-desktop\safesurfer-desktop.exe] => (Allow) C:\program files\safesurfer-desktop\safesurfer-desktop.exe (Safe Surfer) [File not signed]
FirewallRules: [TCP Query User{D38FD24E-5F83-449D-84B3-A0FC926776CD}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{6DA0715D-76FE-4182-BF92-DF4853991FEC}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{43C84B4F-706B-499E-BD92-DA53AB2CBA80}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{97E7074F-80B9-4AF2-9BC0-EDB025B66FED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{E21EC250-27AC-4A03-83B7-18C0B8F68F5D}C:\users\asus\documents\far cry\far cry\bin32\farcry.exe] => (Allow) C:\users\asus\documents\far cry\far cry\bin32\farcry.exe (Crytek) [File not signed]
FirewallRules: [UDP Query User{49E835F6-EE56-4B4F-9106-3ED4726AE0CA}C:\users\asus\documents\far cry\far cry\bin32\farcry.exe] => (Allow) C:\users\asus\documents\far cry\far cry\bin32\farcry.exe (Crytek) [File not signed]
FirewallRules: [{8B3B9458-B20C-4604-A102-1FF9A7BA56E9}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CA36B338-3F3C-4CB0-8ADF-7E82E63F2702}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{719DACF0-884A-4A92-9A75-E87F6D8B47E1}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{85B0B12F-C5BB-4B4C-A0AF-01144B342A8B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{89BBE896-FF17-4642-91FB-9AB7135FCC9D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{14549188-C66A-4ADD-95ED-D3735E41CFCA}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{5C32ED7F-10D3-4D62-B7BF-9BD4E6D8A374}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{296F4AC3-3A69-45A3-8EBA-A7646A16EE5C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risen 3\system\Risen3.exe (Piranha Bytes) [File not signed]
FirewallRules: [{E4F37D87-3486-428C-8D1D-EF87B6249D60}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risen 3\system\Risen3.exe (Piranha Bytes) [File not signed]
FirewallRules: [{D8EBCECC-8FD1-4CF8-B997-9E5BBFA38806}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 18\FIFASetup\fifaconfig.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{6FD469D1-FC05-4ED8-BC76-2F34738483B2}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 18\FIFASetup\fifaconfig.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [TCP Query User{0774E8AC-4815-48C8-A612-A01CF91FAB76}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [UDP Query User{D08934A0-021F-4FAA-9486-A057FCB64D2E}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [TCP Query User{3E32E38A-8ECD-461E-8471-52C893025384}C:\program files (x86)\origin games\fifa 18\fifa18.exe] => (Allow) C:\program files (x86)\origin games\fifa 18\fifa18.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [UDP Query User{478EC4A8-8F11-402B-B977-583472A77786}C:\program files (x86)\origin games\fifa 18\fifa18.exe] => (Allow) C:\program files (x86)\origin games\fifa 18\fifa18.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{125B86DF-2E92-41CC-AE11-9393E504A9A3}] => (Allow) C:\Users\ASUS\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{D55484B8-61CC-4831-AA9F-BF1990AB48BC}] => (Allow) C:\Users\ASUS\AppData\Roaming\Zoom\bin\airhost.exe No File
FirewallRules: [{D19AB693-E02E-40DF-9E12-5A0DBD654738}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{BD75490D-8B11-4C80-9451-E0C9C074CA24}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
==================== Restore Points =========================
30-03-2020 17:55:23 Installed Evernote v. 6.24.2
08-04-2020 12:18:28 Naplánovaný kontrolní bod
==================== Faulty Device Manager Devices ============
Name: USB2.0 VGA UVC WebCam
Description: Zobrazovací zařízení USB
Class Guid: {ca3e7ab9-b4c3-4ae6-8251-579ef933890f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: ========================
Application errors:
==================
Error: (04/16/2020 10:58:53 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11088,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
Error: (04/16/2020 10:43:47 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (6340,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
Error: (04/16/2020 10:35:17 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5464,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]
Error: (04/16/2020 09:32:14 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10524,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
System errors:
=============
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:02 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:02 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Windows Defender:
===================================
Date: 2019-09-18 21:28:59.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {0AF6AB42-B01E-4BCD-AE0C-03917469B57D}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-09-07 22:54:52.872
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {C3462366-8CEC-423B-BAAC-CBF9E5BFC325}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-09-05 12:26:53.373
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {7C8EF927-5A96-4FE1-AC0D-3781FF752966}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-08-14 12:40:02.993
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {82A4F8E3-E390-46A1-95CB-DCB8D5394CFD}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-08-14 12:22:50.153
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {218EB0D5-19B8-4BA0-9DE3-159E796775B0}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2020-04-16 20:57:04.830
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.830
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.829
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.820
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.820
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
CodeIntegrity:
===================================
Date: 2020-04-16 22:27:13.247
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:27:11.790
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:27:11.753
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:26:49.545
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:26:49.540
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:26:49.528
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:11:14.515
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:11:12.008
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
BIOS: American Megatrends Inc. X555UB.304 04/24/2019
Motherboard: ASUSTeK COMPUTER INC. X555UB
Processor: Intel(R) Core(TM) i5-6200U CPU @ 2.30GHz
Percentage of memory in use: 65%
Total physical RAM: 8090.87 MB
Available physical RAM: 2799.03 MB
Total Virtual: 13722.87 MB
Available Virtual: 7739.75 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:930.46 GB) (Free:562.11 GB) NTFS
\\?\Volume{fb42643f-7b7a-45d6-86da-8866abe7eaff}\ (RECOVERY) (Fixed) (Total:0.78 GB) (Free:0.35 GB) NTFS
\\?\Volume{5a0158fd-3ac9-4f15-b446-c3a8722eaf72}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C61970B3)
Partition: GPT.
==================== End of Addition.txt =======================
RSIT log se sem nevešel, dávám do přílohy.
nejde mi aktualizovat antivirus a poslední dny i občas vypadávají některé klávesy a nejsou použít (c, 1, + atd.). Externí klávesnice přes usb funguje bez problému. Níže posílám logy. Moc díky!
LOG FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-04-2020
Ran by ASUS (administrator) on LAPTOP-P7ISUMHN (ASUSTeK COMPUTER INC. X555UB) (16-04-2020 22:55:12)
Running from C:\Users\ASUS\Desktop
Loaded Profiles: ASUS (Available Profiles: ASUS)
Platform: Windows 10 Home Version 1903 18362.720 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ASUS) [File not signed] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\95.4.441\QtWebEngineProcess.exe <2>
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\IntelCpHeciSvc.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1910.0.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12004.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2654512 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1710568 2015-10-03] (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed]
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [185648 2020-04-16] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [6287872 2020-04-14] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (Canon Inc. -> CANON INC.)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\Run: [Spotify] => C:\Users\ASUS\AppData\Roaming\Spotify\Spotify.exe [25828256 2019-08-07] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\Run: [utweb] => "C:\Users\ASUS\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-07] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-07-16] () [File not signed]
Startup: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2019-01-02]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {016098B7-51BD-4F46-8442-93508020D024} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
Task: {1145D8EC-E022-45B0-8CA2-14CCE85B9A28} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [979024 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {1B73E7D3-C637-4C60-8413-F22E7A616AF6} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19786024 2016-08-24] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
Task: {2055FF96-5C04-4532-B5BB-0A81AF83BFAB} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-09-25] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {20581BC9-C280-411F-9428-8FDDA65D80DD} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18392 2016-09-02] (ASUSTeK Computer Inc. -> AsusTek)
Task: {23DE882E-5C0E-43DA-88CA-5237E49139C5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [381008 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {2A453FA6-E159-4366-B5F8-3584C0BAFF27} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [143160 2019-03-12] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
Task: {3050956C-B469-410F-AC64-A5E722F847F8} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [979024 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {587FAA25-E1BB-452C-A82B-7B6AE6408D2A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-04] (Google Inc -> Google LLC)
Task: {6AABB440-4C4A-4D97-B20D-52D2E1BD7A3B} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {7243A93E-CFB0-4E9B-B68A-7B2F635868A6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [381008 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {864F0ABE-DEAD-4AF2-91DD-B305A986896F} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {944B1A1D-DEEA-4C1D-8873-0FDA93A20875} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {9FCB19FD-E872-4C51-9487-1D67D669E241} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-04] (Google Inc -> Google LLC)
Task: {A0DADCFA-2CEF-461D-BA19-578E59E1731F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-04-14] (Adobe Inc. -> Adobe)
Task: {A9616661-15D3-4DF4-B698-6D0D87B732E9} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [55808 2016-10-13] (ASUS) [File not signed]
Task: {C50D6151-5360-4E0B-913A-A99949EE4F86} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
Task: {D6300E77-BAF1-4DB7-A29F-95A630F53802} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16404224 2015-09-25] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {FAA92723-E23B-4D95-B606-E093664D5440} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_363_Plugin.exe [1458232 2020-04-14] (Adobe Inc. -> Adobe)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-3592886365-2214475677-956089615-1001] => http=127.0.0.1:8888;
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{20173415-1306-4b9e-a498-ef6a7ed15ffd}: [NameServer] 104.197.28.121,104.155.237.225
Tcpip\..\Interfaces\{b1a144a7-b23f-4b94-8a56-af0fdd1d8652}: [NameServer] 104.197.28.121,104.155.237.225
Tcpip\..\Interfaces\{b1a144a7-b23f-4b94-8a56-af0fdd1d8652}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{fba65c9a-dd42-4d33-bc52-ccc094258f2d}: [NameServer] 104.197.28.121,104.155.237.225
Tcpip\..\Interfaces\{fba65c9a-dd42-4d33-bc52-ccc094258f2d}: [DhcpNameServer] 192.168.4.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2020-03-09] (Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: css304qo.default-1548098639133
FF ProfilePath: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133 [2020-04-16]
FF Extension: (Download Manager (S3)) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\s3download@statusbar.xpi [2019-12-11]
FF Extension: (Porn/Malware Blocker) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{3df17fe5-3cb9-4b09-a704-1140eca22dfd}.xpi [2019-07-02]
FF Extension: (Public Fox) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{9AA46F4F-4DC7-4c06-97AF-6665170634FE}.xpi [2019-07-02]
FF Extension: (Private Begone) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{9c0fdd1d-a568-4247-99df-efa3a3727008}.xpi [2019-07-02]
FF Extension: (Video DownloadHelper) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Profiles\css304qo.default-1548098639133\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-03-31]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_363.dll [2020-04-14] (Adobe Inc. -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_363.dll [2020-04-14] (Adobe Inc. -> )
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL [2019-02-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3592886365-2214475677-956089615-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\ASUS\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-04-02] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-04-16]
Chrome:
=======
CHR Profile: C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default [2020-04-08]
CHR Extension: (Prezentace) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-07-04]
CHR Extension: (Dokumenty) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-07-04]
CHR Extension: (Disk Google) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-07-04]
CHR Extension: (YouTube) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-07-04]
CHR Extension: (Tabulky) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-07-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-23]
CHR Extension: (Profitario - AliExpress Invoices For Free) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gohemgflodfhnlmbimcgefjnnmjmgnka [2020-04-08]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-11-06]
CHR Extension: (Gmail) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-04]
CHR Extension: (Chrome Media Router) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-08]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058256 2019-02-13] (Microsoft Corporation -> Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-31] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44552 2020-04-14] (Dropbox, Inc -> Dropbox, Inc.)
S3 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [326032 2018-06-05] (ASUSTeK Computer Inc. -> )
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2358784 2020-04-16] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2358784 2020-04-16] (ESET, spol. s r.o. -> ESET)
R2 esifsvc; C:\WINDOWS\SysWOW64\esif_uf.exe [1385640 2015-08-17] (Intel(R) Software -> Intel Corporation)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1208392 2020-01-04] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6617160 2020-01-04] (GOG Sp. z o.o. -> GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155376 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel® Trusted Connect Service -> Intel(R) Corporation)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2015-08-07] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568816 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2495792 2020-04-08] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3447608 2020-04-08] (Electronic Arts, Inc. -> Electronic Arts)
R2 RtkBtManServ; C:\WINDOWS\RtkBtManServ.exe [713816 2018-09-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\NisSrv.exe [3630832 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MsMpEng.exe [103168 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AiCharger; C:\WINDOWS\System32\DRIVERS\AiCharger.sys [29312 2016-08-24] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R2 ASMMAP64; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [18048 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUS)
R3 AsusSGDrv; C:\WINDOWS\system32\DRIVERS\AsusSGDrv.sys [152064 2016-09-02] (ASUSTeK Computer Inc. -> ASUS Corporation)
R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
S3 bsitf; C:\WINDOWS\system32\DRIVERS\bsitf.sys [37208 2018-12-17] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 CH341SER_A64; C:\WINDOWS\System32\Drivers\CH341S64.SYS [59904 2015-01-26] (http://www.winchiphead.com) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [136040 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [55816 2015-08-17] (Intel(R) Software -> Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [53752 2015-08-17] (Intel(R) Software -> Intel Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [154336 2020-04-16] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15800 2019-05-31] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [188872 2020-04-16] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [115960 2020-04-16] (ESET, spol. s r.o. -> ESET)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [261624 2015-08-17] (Intel(R) Software -> Intel Corporation)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32680 2019-08-07] (ASUSTek Computer Inc. -> ASUS)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvam.inf_amd64_1aae4f19e68d0780\nvlddmkm.sys [17003280 2017-12-12] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50472 2015-08-10] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [898296 2016-01-13] (Realtek Semiconductor Corp -> Realtek )
R3 RtkBtFilter; C:\WINDOWS\System32\drivers\RtkBtfilter.sys [758312 2018-09-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [428032 2017-02-16] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S3 RTWlanE01; C:\WINDOWS\System32\drivers\rtwlane01.sys [8169472 2019-03-19] (Microsoft Windows -> Realtek Semiconductor Corporation )
R3 RTWlanE02; C:\WINDOWS\System32\drivers\rtwlane02.sys [9599440 2018-12-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )
S3 RvNetMP60; C:\WINDOWS\System32\drivers\RvNetMP60.sys [69048 2018-12-25] (Famatech Corp. -> Famatech Corp.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166760 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46472 2019-09-17] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [346336 2019-09-17] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-09-17] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-16 22:55 - 2020-04-16 22:57 - 000028564 _____ C:\Users\ASUS\Desktop\FRST.txt
2020-04-16 22:53 - 2020-04-16 22:56 - 000000000 ____D C:\FRST
2020-04-16 22:52 - 2020-04-16 22:52 - 002281472 _____ (Farbar) C:\Users\ASUS\Desktop\FRST64(1).exe
2020-04-16 22:51 - 2020-04-16 22:51 - 001222144 _____ C:\Users\ASUS\Desktop\RSITx64.exe
2020-04-16 22:48 - 2020-04-16 22:49 - 016842232 _____ (VS Revo Group ) C:\Users\ASUS\Downloads\RevoUninProSetup(1).exe
2020-04-16 22:47 - 2020-04-16 22:47 - 000000000 ____D C:\ProgramData\VS Revo Group
2020-04-16 22:46 - 2020-04-16 22:47 - 016842232 _____ (VS Revo Group ) C:\Users\ASUS\Downloads\RevoUninProSetup.exe
2020-04-16 22:15 - 2020-04-16 22:22 - 000376338 _____ C:\WINDOWS\ntbtlog.txt
2020-04-16 22:15 - 2020-04-16 22:15 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2020-04-16 17:58 - 2020-04-16 17:58 - 000001930 _____ C:\Users\ASUS\Desktop\Zoom.lnk
2020-04-16 17:32 - 2020-04-16 17:32 - 002281472 _____ (Farbar) C:\Users\ASUS\Downloads\FRST64.exe
2020-04-15 21:31 - 2020-04-15 21:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2020-04-15 16:10 - 2020-04-15 15:09 - 1015786561 _____ C:\Users\ASUS\Desktop\20200415_150144.mp4
2020-04-15 13:50 - 2020-04-15 13:50 - 000050695 _____ C:\Users\ASUS\Downloads\Online-bohoslužba_-Vyhrávat-boj-v-mysli(1).srt
2020-04-15 10:54 - 2020-04-15 10:54 - 000050695 _____ C:\Users\ASUS\Downloads\Online-bohoslužba_-Vyhrávat-boj-v-mysli.srt
2020-04-14 20:23 - 2020-04-14 20:23 - 000048474 _____ C:\Users\ASUS\Downloads\receipt_of_the_MSF_funds.pdf
2020-04-14 19:33 - 2020-04-14 19:34 - 001032443 _____ C:\Users\ASUS\Desktop\payment_confirmation.pdf
2020-04-14 19:33 - 2020-04-14 19:33 - 000258395 _____ C:\Users\ASUS\Desktop\stansted-express-tickets.pdf
2020-04-14 14:19 - 2020-04-14 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2020-04-14 14:19 - 2020-04-14 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2020-04-14 14:19 - 2020-04-14 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2020-04-14 14:19 - 2020-04-14 14:19 - 000044552 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2020-04-09 15:05 - 2020-04-09 15:14 - 705736289 _____ C:\Users\ASUS\Downloads\steve rec 2.mov
2020-04-09 15:05 - 2020-04-09 15:12 - 1169822987 _____ C:\Users\ASUS\Downloads\IMG_5021.mov
2020-04-08 18:47 - 2020-04-08 18:47 - 000885061 _____ C:\Users\ASUS\Downloads\Otcovská Inventura.pdf
2020-04-08 18:13 - 2020-04-08 18:13 - 005876422 _____ C:\Users\ASUS\Downloads\Brožura_2020_03.pdf
2020-04-08 14:34 - 2020-04-08 14:34 - 000000000 ____D C:\Users\ASUS\Desktop\Gaute
2020-04-08 14:29 - 2020-04-08 14:29 - 000010880 _____ C:\Users\ASUS\Desktop\FINANCE 2020.xlsx
2020-04-08 11:10 - 2020-04-08 12:31 - 000001288 _____ C:\Users\ASUS\Downloads\Vyhledane pohyby(1).csv
2020-04-07 12:13 - 2020-04-07 12:13 - 000013742 _____ C:\Users\ASUS\Downloads\CityHouse Brno rozpočet ústředí 2020.xlsx
2020-04-07 12:13 - 2020-04-07 12:13 - 000013741 _____ C:\Users\ASUS\Desktop\CityHouse Brno rozpočet ústředí 2020.xlsx
2020-04-07 12:01 - 2020-04-07 12:13 - 000013742 _____ C:\Users\ASUS\Downloads\vzor rozpočet ústředí.xlsx
2020-04-02 20:24 - 2020-04-02 20:24 - 000080021 _____ C:\Users\ASUS\Desktop\SÉRIE NA KVĚTEN 2020_OTEVŘENÁ CÍRKEV.pdf
2020-04-02 19:32 - 2020-04-02 19:32 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2020-04-01 19:01 - 2020-04-16 21:46 - 000063443 _____ C:\Users\ASUS\Desktop\Michal výkaz.xlsx
2020-04-01 16:48 - 2020-04-01 15:00 - 1443154931 _____ C:\Users\ASUS\Downloads\20200401_144927.mp4
2020-04-01 16:46 - 2020-04-01 16:46 - 000063358 _____ C:\Users\ASUS\Downloads\Od-pondělí-do-soboty.pdf
2020-04-01 10:03 - 2020-04-01 11:56 - 000000000 ____D C:\Users\ASUS\Desktop\Leaderscape
2020-03-31 23:27 - 2020-03-31 23:29 - 312692117 _____ C:\Users\ASUS\Downloads\MYSLENKA DNE_1.mov
2020-03-31 22:00 - 2020-03-31 22:00 - 000000000 ____D C:\Users\ASUS\Documents\Zoom
2020-03-31 10:19 - 2020-04-16 17:58 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Zoom
2020-03-30 18:59 - 2020-03-30 19:02 - 000010437 _____ C:\Users\ASUS\Desktop\DOVOLENÁ-DOCHÁZKA, AC CityHouse BRNO, BŘEZEN 2020.xlsx
2020-03-30 18:57 - 2020-03-30 18:57 - 000010450 _____ C:\Users\ASUS\Downloads\DOVOLENÁ-DOCHÁZKA, AC CityHouse BRNO, LISTOPAD 2019.xlsx
2020-03-30 17:57 - 2020-03-30 17:57 - 000002523 _____ C:\Users\Public\Desktop\Evernote.lnk
2020-03-30 17:57 - 2020-03-30 17:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2020-03-28 10:39 - 2020-03-28 10:39 - 000066478 _____ C:\Users\ASUS\Downloads\Philips mg5730_15 doklad.PDF
2020-03-27 15:31 - 2020-03-27 15:34 - 206885503 _____ C:\Users\ASUS\Downloads\Better.Call.Saul.S05E06.720p.WEB.x265-MiNX.mkv
2020-03-25 21:17 - 2020-03-25 21:20 - 768289102 _____ C:\Users\ASUS\Downloads\Bez vedomi 1.dil (2019) CZ dabing 720p.avi
2020-03-25 16:20 - 2020-03-25 16:20 - 000000231 _____ C:\Users\ASUS\Desktop\Assassin's Creed II.url
2020-03-25 16:17 - 2020-03-25 16:17 - 000000000 ____D C:\ProgramData\Ubisoft
2020-03-25 16:16 - 2020-03-31 12:13 - 000000000 ____D C:\Users\ASUS\AppData\Local\Ubisoft Game Launcher
2020-03-25 16:16 - 2020-03-25 16:16 - 000001276 _____ C:\Users\ASUS\Desktop\Uplay.lnk
2020-03-25 16:16 - 2020-03-25 16:16 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2020-03-25 16:16 - 2020-03-25 16:16 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2020-03-25 16:15 - 2020-03-25 16:16 - 130190792 _____ (Ubisoft) C:\Users\ASUS\Downloads\UplayInstaller.exe
2020-03-24 22:01 - 2020-03-24 22:05 - 885251494 _____ C:\Users\ASUS\Downloads\homeland.s08e01.720p.web.h264-xlf[eztv].mkv
2020-03-24 19:24 - 2020-03-24 19:24 - 1256973640 _____ C:\WINDOWS\MEMORY.DMP
2020-03-24 19:24 - 2020-03-24 19:24 - 000000000 ____D C:\WINDOWS\Minidump
2020-03-23 18:53 - 2020-03-23 18:53 - 000725905 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.10_podloženo(1).pdf
2020-03-23 18:53 - 2020-03-23 18:53 - 000102442 _____ C:\Users\ASUS\Downloads\GC_1PP_S_kuchyn_rozsireni2_V3_návrh.pdf
2020-03-23 18:42 - 2020-03-23 18:43 - 000725905 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.10_podloženo.pdf
2020-03-19 23:51 - 2020-03-19 23:51 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3592886365-2214475677-956089615-1001
2020-03-19 14:24 - 2020-03-19 14:36 - 1229959458 _____ C:\Users\ASUS\Downloads\1080p.mov
2020-03-18 19:52 - 2020-03-18 19:59 - 000000000 ____D C:\Users\ASUS\Documents\FIFA 18
2020-03-18 19:45 - 2020-03-18 19:46 - 000000000 ____D C:\Users\ASUS\AppData\Local\Intel
2020-03-18 16:27 - 2020-03-18 16:27 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2020-03-18 16:25 - 2019-10-30 08:16 - 001082472 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 001082472 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 000940136 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 000940136 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-03-18 16:25 - 2019-10-30 08:16 - 000853352 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-03-18 16:25 - 2019-10-30 08:16 - 000853352 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-03-18 16:25 - 2019-10-30 08:16 - 000711016 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-03-18 16:25 - 2019-10-30 08:16 - 000711016 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-03-18 16:25 - 2019-10-30 08:15 - 000281616 _____ C:\WINDOWS\system32\igfxCPL.cpl
2020-03-18 16:25 - 2019-10-30 08:15 - 000168976 _____ C:\WINDOWS\SysWOW64\libGLESv2.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000141840 _____ C:\WINDOWS\SysWOW64\libGLESv1_CM.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000136720 _____ C:\WINDOWS\SysWOW64\libEGL.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000121360 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-03-18 16:25 - 2019-10-30 08:15 - 000108048 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-03-18 16:25 - 2019-10-30 05:16 - 000212464 _____ (Intel Corporation) C:\WINDOWS\system32\intel_gfx_api-x64.dll
2020-03-18 16:25 - 2019-10-30 05:16 - 000184144 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\intel_gfx_api-x86.dll
2020-03-17 19:15 - 2020-03-17 19:15 - 000000000 ____D C:\Users\ASUS\AppData\Local\Electronic Arts
2020-03-17 15:36 - 2020-03-17 15:36 - 000001222 _____ C:\Users\Public\Desktop\FIFA 18.lnk
2020-03-17 15:36 - 2020-03-17 15:36 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller
2020-03-17 15:36 - 2020-03-17 15:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 18
2020-03-17 13:44 - 2020-04-14 18:13 - 000000000 ____D C:\Program Files (x86)\Origin Games
2020-03-17 13:40 - 2020-03-17 19:15 - 000000000 ____D C:\ProgramData\Electronic Arts
2020-03-17 13:38 - 2020-03-17 13:38 - 000001064 _____ C:\Users\Public\Desktop\Origin.lnk
2020-03-17 13:38 - 2020-03-17 13:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2020-03-17 13:37 - 2020-04-10 10:46 - 000000000 ____D C:\Program Files (x86)\Origin
2020-03-17 13:24 - 2020-04-14 18:13 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Origin
2020-03-17 13:24 - 2020-04-14 18:13 - 000000000 ____D C:\ProgramData\Origin
2020-03-17 13:24 - 2020-03-17 13:24 - 000000000 ____D C:\Users\ASUS\.QtWebEngineProcess
2020-03-17 13:24 - 2020-03-17 13:24 - 000000000 ____D C:\Users\ASUS\.Origin
2020-03-17 13:23 - 2020-04-14 13:27 - 000000000 ____D C:\Users\ASUS\AppData\Local\Origin
2020-03-17 13:21 - 2020-03-17 13:21 - 000203318 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.12_2.NP_200316(1).pdf
2020-03-17 13:19 - 2020-03-17 13:23 - 063645768 _____ (Electronic Arts) C:\Users\ASUS\Downloads\OriginThinSetup.exe
2020-03-17 13:10 - 2020-03-17 13:10 - 000007260 _____ C:\Users\ASUS\Downloads\index2.jfif
2020-03-17 12:54 - 2020-03-17 12:54 - 000000222 _____ C:\Users\ASUS\Desktop\Risen 3 - Titan Lords.url
2020-03-17 12:48 - 2020-03-17 12:48 - 000007787 _____ C:\Users\ASUS\Downloads\index.jfif
2020-03-17 10:11 - 2020-03-17 10:11 - 000000000 ___RD C:\Users\ASUS\Downloads\Microsoft.SkypeApp_kzf8qxf38zg5c!App
2020-03-17 09:07 - 2020-03-17 09:07 - 000203318 _____ C:\Users\ASUS\Downloads\cityhouse_gaute-var.12_2.NP_200316.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-16 22:30 - 2018-12-19 18:22 - 000000000 ____D C:\Users\ASUS\AppData\LocalLow\Mozilla
2020-04-16 22:27 - 2018-12-14 21:46 - 000000200 _____ C:\Users\ASUS\AppData\Roaming\sp_data.sys
2020-04-16 22:26 - 2018-12-14 21:45 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2020-04-16 22:25 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF
2020-04-16 22:23 - 2019-07-20 17:16 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-16 22:23 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-16 22:23 - 2018-12-14 21:43 - 000000000 __SHD C:\Users\ASUS\IntelGraphicsProfiles
2020-04-16 22:23 - 2018-12-14 20:46 - 000000000 ____D C:\ProgramData\NVIDIA
2020-04-16 22:22 - 2019-03-19 06:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2020-04-16 22:20 - 2019-04-21 14:11 - 000000000 ____D C:\Users\ASUS\AppData\Local\ElevatedDiagnostics
2020-04-16 21:17 - 2018-12-19 18:25 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-04-16 21:00 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-16 21:00 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-16 19:01 - 2019-09-09 15:18 - 000188872 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-04-16 19:01 - 2019-09-09 15:18 - 000154336 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-04-16 19:01 - 2019-09-09 15:18 - 000115960 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-04-16 18:38 - 2019-07-20 16:52 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-15 21:31 - 2018-12-28 18:23 - 000000000 ____D C:\Program Files (x86)\Dropbox
2020-04-15 18:06 - 2018-12-31 13:33 - 000000000 ___RD C:\Users\ASUS\Dropbox
2020-04-14 16:28 - 2019-07-20 17:16 - 000004652 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier
2020-04-14 16:28 - 2019-07-20 17:16 - 000004506 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-04-14 16:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-04-14 16:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-04-13 22:39 - 2018-12-14 21:43 - 000000000 ____D C:\Users\ASUS\AppData\Local\Packages
2020-04-13 10:11 - 2018-12-21 23:21 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\vlc
2020-04-10 16:35 - 2019-01-21 21:23 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-04-10 16:35 - 2019-01-21 21:23 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-04-10 10:49 - 2019-01-21 21:23 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-04-07 23:06 - 2019-07-04 11:06 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-07 08:05 - 2019-07-20 17:13 - 001693640 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-07 08:05 - 2019-03-19 13:55 - 000719670 _____ C:\WINDOWS\system32\perfh005.dat
2020-04-07 08:05 - 2019-03-19 13:55 - 000145698 _____ C:\WINDOWS\system32\perfc005.dat
2020-04-04 23:17 - 2019-07-19 21:31 - 000000000 ____D C:\Users\ASUS
2020-03-31 23:34 - 2019-03-27 11:35 - 000000000 ____D C:\Users\ASUS\Documents\FFOutput
2020-03-21 10:57 - 2019-07-20 17:16 - 000003474 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-21 10:57 - 2019-07-20 17:16 - 000003350 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-19 23:51 - 2019-07-19 21:31 - 000002360 _____ C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-19 23:51 - 2018-12-14 21:47 - 000000000 ___RD C:\Users\ASUS\OneDrive
2020-03-19 11:40 - 2018-12-19 18:16 - 000000000 ____D C:\Users\ASUS\AppData\Local\PlaceholderTileLogoFolder
2020-03-19 00:44 - 2018-12-19 18:18 - 000000000 ____D C:\Program Files (x86)\Steam
2020-03-18 19:49 - 2018-12-19 20:20 - 000000000 ____D C:\Users\ASUS\AppData\Local\D3DSCache
2020-03-18 19:48 - 2018-12-19 18:30 - 000000000 ____D C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2020-03-18 16:27 - 2018-12-14 20:41 - 000000000 ____D C:\ProgramData\Intel
2020-03-18 16:27 - 2018-12-14 20:40 - 000000000 ____D C:\Program Files\Intel
2020-03-17 16:34 - 2019-07-20 17:16 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-17 16:33 - 2018-12-19 18:22 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-17 15:34 - 2018-12-14 20:39 - 000000000 ____D C:\ProgramData\Package Cache
==================== Files in the root of some directories ========
2018-12-14 21:46 - 2020-04-16 22:27 - 000000200 _____ () C:\Users\ASUS\AppData\Roaming\sp_data.sys
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
ADDITION.TXT
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2020
Ran by ASUS (16-04-2020 22:59:01)
Running from C:\Users\ASUS\Desktop
Windows 10 Home Version 1903 18362.720 (X64) (2019-07-20 15:17:06)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3592886365-2214475677-956089615-500 - Administrator - Disabled)
ASUS (S-1-5-21-3592886365-2214475677-956089615-1001 - Administrator - Enabled) => C:\Users\ASUS
DefaultAccount (S-1-5-21-3592886365-2214475677-956089615-503 - Limited - Disabled)
Guest (S-1-5-21-3592886365-2214475677-956089615-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3592886365-2214475677-956089615-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 18.05 (x64) (HKLM\...\7-Zip) (Version: 18.05 - Igor Pavlov)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.363 - Adobe)
Assassin's Creed II (HKLM-x32\...\Uplay Install 4) (Version: - Ubisoft)
ASUS Device Activation (HKLM-x32\...\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}) (Version: 1.0.4.0 - ASUSTeK COMPUTER INC.)
ASUS HiPost (HKLM-x32\...\{04768366-F421-4BA5-8423-B84F644B5249}) (Version: 1.0.6 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.6.8 - ASUSTeK COMPUTER INC.)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.16 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.19.0004 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.1.8 - ASUS)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0040 - ASUS)
Audacity 2.3.2 (HKLM-x32\...\Audacity_is1) (Version: 2.3.2 - Audacity Team)
AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.0.93 - ICEpower a/s)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - Canon Inc.)
Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version: - )
Dropbox (HKLM-x32\...\Dropbox) (Version: 95.4.441 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.295.1 - Dropbox, Inc.) Hidden
EPUB File Reader (HKLM-x32\...\{818C5857-5C74-4CAC-9F43-E5597086852D}_is1) (Version: - epubfilereader.com)
ESET Security (HKLM\...\{1CE8E9F0-4D99-4C80-B3CB-4A19C083B2B5}) (Version: 13.1.21.0 - ESET, spol. s r.o.)
Evernote v. 6.24.2 (HKLM-x32\...\{A8B80634-6257-11EA-8C8E-005056951CAD}) (Version: 6.24.2.8919 - Evernote Corp.)
FIFA 18 (HKLM-x32\...\{213CC10A-B8CB-4EBA-B277-6B08B7C22A65}) (Version: 1.0.57.57320 - Electronic Arts)
FM Genie Scout 17g version 1.1 17.3.2 (HKLM-x32\...\FM Genie Scout 17g_is1) (Version: 1.1 17.3.2 - )
FMRTE 17.3.2.23 (HKLM\...\{72A84F14-6742-48AD-9B14-E9C1BE155F7A}_is1) (Version: 17.3.2.23 - FMRTE)
Football Manager 2017 (HKLM\...\Football Manager 2017_is1) (Version: 1.0 - )
Football Manager 2017 Editor (HKLM\...\Football Manager 2017 Editor_is1) (Version: 1.0 - )
FormatFactory 2.60 (HKLM-x32\...\FormatFactory) (Version: 2.60 - Free Time)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
GTA San Andreas CZ (HKLM-x32\...\GTA San Andreas CZ 1.3.0) (Version: 1.3.0 - Rockstar Games)
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10603.192 - Intel Corporation)
Intel(R) Chipset Device Software (HKLM-x32\...\{a2d9fda8-65eb-4c06-81ef-31e0a4daa335}) (Version: 10.1.1.11 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.7325 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Krtek a jeho veliké dobrodružství (HKLM-x32\...\{5DF18D93-076F-4E90-B6CF-3CF96110F1D4}_is1) (Version: - Play sp. z o. o.)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Office 2013 pro profesionály - cs-cz (HKLM\...\ProfessionalRetail - cs-cz) (Version: 15.0.5215.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 15.0.5215.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 75.0 (x64 cs) (HKLM\...\Mozilla Firefox 75.0 (x64 cs)) (Version: 75.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 64.0.2 - Mozilla)
NVIDIA GeForce Experience 2.5.15.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.46 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (HKLM\...\{90150000-008C-0000-1000-0000000FF1CE}) (Version: 15.0.5215.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-007E-0000-1000-0000000FF1CE}) (Version: 15.0.5215.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM\...\{90150000-008C-0405-1000-0000000FF1CE}) (Version: 15.0.5215.1000 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 10.5.67.39484 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 388.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.57 - NVIDIA Corporation) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31233 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.3.723.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7620 - Realtek Semiconductor Corp.)
SafeSurfer-Desktop 1.0.2 (HKLM\...\{50c8ce74-58ce-5a3c-a7b4-e66f974a2b23}) (Version: 1.0.2 - Safe Surfer)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 4.1.500 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 2.5.15.46 - NVIDIA Corporation) Hidden
Spotify (HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\Spotify) (Version: 1.1.12.449.g4109e645 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
The Witcher 2 - Assassins of Kings Enhanced Edition (HKLM-x32\...\1207658930_is1) (Version: 3.5.0.26 - GOG.com)
Theophilos 3 (HKLM-x32\...\Theophilos_is1) (Version: - )
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 104.0 - Ubisoft)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Windows Driver Package - ASUS (AsusSGDrv) Mouse (08/19/2016 8.0.0.26) (HKLM\...\912D9B7DE050AA48F945407778CC01897B5E23BB) (Version: 08/19/2016 8.0.0.26 - ASUS)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.2.2 - ASUSTeK COMPUTER INC.)
Zoom (HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\ZoomUMX) (Version: 4.6 - Zoom Video Communications, Inc.)
Packages:
=========
Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_2.9.0.1_neutral__6e5tt8cgb93ep [2020-03-11] (Canon Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-02] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-02] (Microsoft Corporation) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.96.725.0_x64__mcm4njqhnhss8 [2020-04-11] (Netflix, Inc.)
PowerPoint Mobile -> C:\Program Files\WindowsApps\Microsoft.Office.PowerPoint_16001.12730.20086.0_x64__8wekyb3d8bbwe [2020-04-16] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3592886365-2214475677-956089615-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\ASUS\Dropbox [2018-12-31 13:33]
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-08-18] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-04-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-04-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\igfxDTCM.dll [2019-10-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-04-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2016-10-13 08:17 - 2016-10-13 08:17 - 000125440 _____ () [File not signed] C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000033280 _____ () [File not signed] C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000029184 _____ () [File not signed] C:\Program Files (x86)\ASUS\Splendid\VideoEnhance.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 001676288 _____ (ASUS TeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\Splendid\ApplyLUT.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000178176 _____ (ASUS TeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\Splendid\GenLUT.dll
2016-10-13 08:17 - 2016-10-13 08:17 - 000165888 _____ (ASUSTeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\Splendid\ColorU.dll
2019-01-21 22:23 - 2011-01-15 17:45 - 000319488 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNSS_ENU.DLL
2019-01-21 22:22 - 2012-06-14 18:18 - 000359936 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMN6PPM.DLL
2018-12-25 19:39 - 2018-04-30 14:00 - 000075776 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2018-12-14 20:46 - 2015-10-03 04:23 - 001439184 _____ (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed] C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll
2020-03-17 13:37 - 2020-03-16 15:05 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2020-03-24 23:24 - 2020-03-16 15:06 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2020-03-24 23:24 - 2020-03-17 13:37 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2020-04-10 10:46 - 2020-03-17 13:37 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-12 01:38 - 2018-04-12 01:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ASUS\Downloads\1464434a46adb17ab7ab8d3ad8eaaa0d.jpg
DNS Servers: 104.197.28.121 - 104.155.237.225
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\...\StartupApproved\Run: => "Spotify"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{96351871-B984-451A-94E5-5A1E6B162B41}C:\users\asus\desktop\fmrte 17.3.1\amped.exe] => (Allow) C:\users\asus\desktop\fmrte 17.3.1\amped.exe (AMPED) [File not signed]
FirewallRules: [UDP Query User{5A25C015-0035-49E1-9237-EEECBC4A3A74}C:\users\asus\desktop\fmrte 17.3.1\amped.exe] => (Allow) C:\users\asus\desktop\fmrte 17.3.1\amped.exe (AMPED) [File not signed]
FirewallRules: [{13A52804-00A2-4D2A-9B31-53DED8D173B3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{DF793086-1F0D-4DF9-8EA4-4A5483FE49D4}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{6CB9C1CA-3EE9-4540-B77C-403D94374F13}C:\program files\safesurfer-desktop\safesurfer-desktop.exe] => (Allow) C:\program files\safesurfer-desktop\safesurfer-desktop.exe (Safe Surfer) [File not signed]
FirewallRules: [UDP Query User{11C44091-A387-4E47-AB18-515693EB6051}C:\program files\safesurfer-desktop\safesurfer-desktop.exe] => (Allow) C:\program files\safesurfer-desktop\safesurfer-desktop.exe (Safe Surfer) [File not signed]
FirewallRules: [TCP Query User{D38FD24E-5F83-449D-84B3-A0FC926776CD}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{6DA0715D-76FE-4182-BF92-DF4853991FEC}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{43C84B4F-706B-499E-BD92-DA53AB2CBA80}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{97E7074F-80B9-4AF2-9BC0-EDB025B66FED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{E21EC250-27AC-4A03-83B7-18C0B8F68F5D}C:\users\asus\documents\far cry\far cry\bin32\farcry.exe] => (Allow) C:\users\asus\documents\far cry\far cry\bin32\farcry.exe (Crytek) [File not signed]
FirewallRules: [UDP Query User{49E835F6-EE56-4B4F-9106-3ED4726AE0CA}C:\users\asus\documents\far cry\far cry\bin32\farcry.exe] => (Allow) C:\users\asus\documents\far cry\far cry\bin32\farcry.exe (Crytek) [File not signed]
FirewallRules: [{8B3B9458-B20C-4604-A102-1FF9A7BA56E9}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CA36B338-3F3C-4CB0-8ADF-7E82E63F2702}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{719DACF0-884A-4A92-9A75-E87F6D8B47E1}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{85B0B12F-C5BB-4B4C-A0AF-01144B342A8B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{89BBE896-FF17-4642-91FB-9AB7135FCC9D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{14549188-C66A-4ADD-95ED-D3735E41CFCA}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{5C32ED7F-10D3-4D62-B7BF-9BD4E6D8A374}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{296F4AC3-3A69-45A3-8EBA-A7646A16EE5C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risen 3\system\Risen3.exe (Piranha Bytes) [File not signed]
FirewallRules: [{E4F37D87-3486-428C-8D1D-EF87B6249D60}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risen 3\system\Risen3.exe (Piranha Bytes) [File not signed]
FirewallRules: [{D8EBCECC-8FD1-4CF8-B997-9E5BBFA38806}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 18\FIFASetup\fifaconfig.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{6FD469D1-FC05-4ED8-BC76-2F34738483B2}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 18\FIFASetup\fifaconfig.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [TCP Query User{0774E8AC-4815-48C8-A612-A01CF91FAB76}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [UDP Query User{D08934A0-021F-4FAA-9486-A057FCB64D2E}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [TCP Query User{3E32E38A-8ECD-461E-8471-52C893025384}C:\program files (x86)\origin games\fifa 18\fifa18.exe] => (Allow) C:\program files (x86)\origin games\fifa 18\fifa18.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [UDP Query User{478EC4A8-8F11-402B-B977-583472A77786}C:\program files (x86)\origin games\fifa 18\fifa18.exe] => (Allow) C:\program files (x86)\origin games\fifa 18\fifa18.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{125B86DF-2E92-41CC-AE11-9393E504A9A3}] => (Allow) C:\Users\ASUS\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{D55484B8-61CC-4831-AA9F-BF1990AB48BC}] => (Allow) C:\Users\ASUS\AppData\Roaming\Zoom\bin\airhost.exe No File
FirewallRules: [{D19AB693-E02E-40DF-9E12-5A0DBD654738}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{BD75490D-8B11-4C80-9451-E0C9C074CA24}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
==================== Restore Points =========================
30-03-2020 17:55:23 Installed Evernote v. 6.24.2
08-04-2020 12:18:28 Naplánovaný kontrolní bod
==================== Faulty Device Manager Devices ============
Name: USB2.0 VGA UVC WebCam
Description: Zobrazovací zařízení USB
Class Guid: {ca3e7ab9-b4c3-4ae6-8251-579ef933890f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: ========================
Application errors:
==================
Error: (04/16/2020 10:58:53 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11088,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
Error: (04/16/2020 10:43:47 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (6340,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
Error: (04/16/2020 10:35:17 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5464,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.
Error: (04/16/2020 09:59:44 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]
Error: (04/16/2020 09:32:14 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10524,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
System errors:
=============
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:03 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:02 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Error: (04/16/2020 11:04:02 PM) (Source: TPM) (EventID: 27) (User: NT AUTHORITY)
Description: Inicializace čipu TPM (Trusted Platform Module) se nezdařila. Čip může být v režimu selhání. Pokud chcete povolit diagnostiku, kontaktujte jeho výrobce a předejte mu připojené informace.
Windows Defender:
===================================
Date: 2019-09-18 21:28:59.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {0AF6AB42-B01E-4BCD-AE0C-03917469B57D}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-09-07 22:54:52.872
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {C3462366-8CEC-423B-BAAC-CBF9E5BFC325}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-09-05 12:26:53.373
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {7C8EF927-5A96-4FE1-AC0D-3781FF752966}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-08-14 12:40:02.993
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {82A4F8E3-E390-46A1-95CB-DCB8D5394CFD}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2019-08-14 12:22:50.153
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {218EB0D5-19B8-4BA0-9DE3-159E796775B0}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2020-04-16 20:57:04.830
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.830
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.829
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.820
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
Date: 2020-04-16 20:57:04.820
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.25.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.
CodeIntegrity:
===================================
Date: 2020-04-16 22:27:13.247
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:27:11.790
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:27:11.753
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:26:49.545
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:26:49.540
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:26:49.528
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:11:14.515
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-16 22:11:12.008
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
BIOS: American Megatrends Inc. X555UB.304 04/24/2019
Motherboard: ASUSTeK COMPUTER INC. X555UB
Processor: Intel(R) Core(TM) i5-6200U CPU @ 2.30GHz
Percentage of memory in use: 65%
Total physical RAM: 8090.87 MB
Available physical RAM: 2799.03 MB
Total Virtual: 13722.87 MB
Available Virtual: 7739.75 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:930.46 GB) (Free:562.11 GB) NTFS
\\?\Volume{fb42643f-7b7a-45d6-86da-8866abe7eaff}\ (RECOVERY) (Fixed) (Total:0.78 GB) (Free:0.35 GB) NTFS
\\?\Volume{5a0158fd-3ac9-4f15-b446-c3a8722eaf72}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C61970B3)
Partition: GPT.
==================== End of Addition.txt =======================
RSIT log se sem nevešel, dávám do přílohy.
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
Ahoj 
Problem s nemoznostou aktualizacie sa vyskytuje v antiviruse ESET? Aka chybova hlaska sa ukazuje?
Co sa tyka problemu s nefungujucimi klavesami, myslim, ze v tomto pripade sa jedna skor o HW chybu.
Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/




- Uloz na plochu a ukonci vsetky programy
- Spusti AdwCleaner ako spravca
- Odsuhlas licencne podmienky
- Klikni na Skenovat nyni (Scan now) a pockaj na dokoncenie
- V pripade nalezov nechaj vsetky nalezy oznacene a klikni na Karantena
- Ak nebudu ziadne nalezy, klikni na
- Pockaj na dokoncenie a potvrd restartovanie PC
- Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
- Otvori sa log, jeho obsah sem skopiruj
Absolvent skoly pre novacikov 
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!

E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
Ahoj 
Ano, nefungujíí klávesy můžou být HW původu, ntb už dosluhuje, ale občas fungují a občas ne, je to podezřelé...
Neaktualizující se antivir je eset, žádná chybová hláška ovšem nevyskakuje, prostě se jen atualizace "stahuje", ale nikdy se nestáhne...
Log z Adwcleaneru:
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 04-17-2020
# Duration: 00:00:08
# OS: Windows 10 Home
# Cleaned: 26
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{20173415-1306-4b9e-a498-ef6a7ed15ffd}|NameServer - "104.197.28.121,104.155.237.225"
Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{b1a144a7-b23f-4b94-8a56-af0fdd1d8652}|NameServer - "104.197.28.121,104.155.237.225"
Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{fba65c9a-dd42-4d33-bc52-ccc094258f2d}|NameServer - "104.197.28.121,104.155.237.225"
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.ASUSDeviceActivation Folder C:\Program Files (x86)\ASUS\ASUS DEVICE ACTIVATION
Deleted Preinstalled.ASUSDeviceActivation Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}
Deleted Preinstalled.ASUSLiveUpdate Folder C:\Program Files (x86)\ASUS\ASUS LIVE UPDATE
Deleted Preinstalled.ASUSLiveUpdate Folder C:\ProgramData\ASUS\ASUS LIVE UPDATE
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A453FA6-E159-4366-B5F8-3584C0BAFF27}
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Checker
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}
Deleted Preinstalled.ASUSLiveUpdate Task C:\Windows\System32\Tasks\UPDATE CHECKER
Deleted Preinstalled.ASUSSmartGesture Folder C:\Program Files (x86)\ASUS\ASUS SMART GESTURE
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20581BC9-C280-411F-9428-8FDDA65D80DD}
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Smart Gesture Launcher
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\Software\Classes\CLSID\{F31B5912-07D6-4895-B4BA-5486CF3B18B1}
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
Deleted Preinstalled.ASUSSmartGesture Task C:\Windows\System32\Tasks\ASUS SMART GESTURE LAUNCHER
Deleted Preinstalled.ASUSSplendid Folder C:\Program Files (x86)\ASUS\SPLENDID
Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9616661-15D3-4DF4-B698-6D0D87B732E9}
Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Splendid ACMON
Deleted Preinstalled.ASUSSplendid Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0969AF05-4FF6-4C00-9406-43599238DE0D}
Deleted Preinstalled.ASUSSplendid Task C:\Windows\System32\Tasks\ASUS SPLENDID ACMON
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [4533 octets] - [17/04/2020 11:22:52]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Ano, nefungujíí klávesy můžou být HW původu, ntb už dosluhuje, ale občas fungují a občas ne, je to podezřelé...
Neaktualizující se antivir je eset, žádná chybová hláška ovšem nevyskakuje, prostě se jen atualizace "stahuje", ale nikdy se nestáhne...
Log z Adwcleaneru:
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 04-17-2020
# Duration: 00:00:08
# OS: Windows 10 Home
# Cleaned: 26
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{20173415-1306-4b9e-a498-ef6a7ed15ffd}|NameServer - "104.197.28.121,104.155.237.225"
Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{b1a144a7-b23f-4b94-8a56-af0fdd1d8652}|NameServer - "104.197.28.121,104.155.237.225"
Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{fba65c9a-dd42-4d33-bc52-ccc094258f2d}|NameServer - "104.197.28.121,104.155.237.225"
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.ASUSDeviceActivation Folder C:\Program Files (x86)\ASUS\ASUS DEVICE ACTIVATION
Deleted Preinstalled.ASUSDeviceActivation Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}
Deleted Preinstalled.ASUSLiveUpdate Folder C:\Program Files (x86)\ASUS\ASUS LIVE UPDATE
Deleted Preinstalled.ASUSLiveUpdate Folder C:\ProgramData\ASUS\ASUS LIVE UPDATE
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A453FA6-E159-4366-B5F8-3584C0BAFF27}
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Checker
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}
Deleted Preinstalled.ASUSLiveUpdate Task C:\Windows\System32\Tasks\UPDATE CHECKER
Deleted Preinstalled.ASUSSmartGesture Folder C:\Program Files (x86)\ASUS\ASUS SMART GESTURE
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20581BC9-C280-411F-9428-8FDDA65D80DD}
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Smart Gesture Launcher
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\Software\Classes\CLSID\{F31B5912-07D6-4895-B4BA-5486CF3B18B1}
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
Deleted Preinstalled.ASUSSmartGesture Task C:\Windows\System32\Tasks\ASUS SMART GESTURE LAUNCHER
Deleted Preinstalled.ASUSSplendid Folder C:\Program Files (x86)\ASUS\SPLENDID
Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9616661-15D3-4DF4-B698-6D0D87B732E9}
Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Splendid ACMON
Deleted Preinstalled.ASUSSplendid Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0969AF05-4FF6-4C00-9406-43599238DE0D}
Deleted Preinstalled.ASUSSplendid Task C:\Windows\System32\Tasks\ASUS SPLENDID ACMON
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [4533 octets] - [17/04/2020 11:22:52]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
ESET cely cas zostava "zaseknuty" na stahovani aktualizacii? Aka je aktualna verzia virusovej databazy?
Poprosim o obidva nove logy z FRST.
Poprosim o obidva nove logy z FRST.
Absolvent skoly pre novacikov 
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!

E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
Á...tak právě se mi ESET aktualizoval po tom adwcleaneru a přidání souborů do karantény...
FRST logy v příloze. Díky!
FRST logy v příloze. Díky!
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
Můžu se zeptat, je tam ještě něco? Po zapnutí ntb se mi zapíná pochybná stránka v mozilla prohlížeči...
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
Pardon za zdrzanie. Ano, v logu vidim subor, ktory zrejme sposobuje otvaranie tejto stranky. Nasledujucim fixlistom by sa to malo vyriesit.
Otvor poznamkovy blok (Win+R -> notepad -> enter)

- Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:
Kód: Vybrat vše
Start CloseProcesses: CreateRestorePoint: PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum CMD: type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat" File: C:\Windows\system32\nvspcap64.dll File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe File: C:\WINDOWS\System32\drivers\BthA2dp.sys File: C:\WINDOWS\System32\Drivers\CH341S64.SYS Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-07-16] () [File not signed] SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = S3 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [X] 2020-04-16 23:07 - 2020-04-16 23:07 - 000000000 ____D C:\rsit 2020-04-16 23:07 - 2020-04-16 23:07 - 000000000 ____D C:\Program Files\trend micro 2020-04-16 22:51 - 2020-04-16 22:51 - 001222144 _____ C:\Users\ASUS\Desktop\RSITx64.exe ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File FirewallRules: [TCP Query User{0774E8AC-4815-48C8-A612-A01CF91FAB76}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File FirewallRules: [UDP Query User{D08934A0-021F-4FAA-9486-A057FCB64D2E}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File FirewallRules: [{D55484B8-61CC-4831-AA9F-BF1990AB48BC}] => (Allow) C:\Users\ASUS\AppData\Roaming\Zoom\bin\airhost.exe No File Hosts: EmptyTemp: End
- Uloz na plochu s nazvom fixlist.txt
- Spusti znovu FRST a klikni na Fix
- Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
- Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj
Absolvent skoly pre novacikov 
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!

E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
Obsah fixlogu:
Fix result of Farbar Recovery Scan Tool (x64) Version: 19-04-2020
Ran by ASUS (20-04-2020 09:50:02) Run:1
Running from C:\Users\ASUS\Desktop
Loaded Profiles: ASUS (Available Profiles: ASUS)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
CMD: type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat"
File: C:\Windows\system32\nvspcap64.dll
File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
File: C:\WINDOWS\System32\drivers\BthA2dp.sys
File: C:\WINDOWS\System32\Drivers\CH341S64.SYS
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-07-16] () [File not signed]
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S3 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [X]
2020-04-16 23:07 - 2020-04-16 23:07 - 000000000 ____D C:\rsit
2020-04-16 23:07 - 2020-04-16 23:07 - 000000000 ____D C:\Program Files\trend micro
2020-04-16 22:51 - 2020-04-16 22:51 - 001222144 _____ C:\Users\ASUS\Desktop\RSITx64.exe
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
FirewallRules: [TCP Query User{0774E8AC-4815-48C8-A612-A01CF91FAB76}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [UDP Query User{D08934A0-021F-4FAA-9486-A057FCB64D2E}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [{D55484B8-61CC-4831-AA9F-BF1990AB48BC}] => (Allow) C:\Users\ASUS\AppData\Roaming\Zoom\bin\airhost.exe No File
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========
Count : 38
Average :
Sum : 1036918801
Maximum :
Minimum :
Property : Length
========= End of Powershell: =========
========= type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat" =========
@echo off
TITLE Update check..
start "" http://zipansion.com/2HkmW
========= End of CMD: =========
========================= File: C:\Windows\system32\nvspcap64.dll ========================
C:\Windows\system32\nvspcap64.dll
File not signed
MD5: E4631786E983D745E6E598FD39C0E3D2
Creation and modification date: 2018-12-14 20:46 - 2015-10-03 04:22
Size: 001710568
Attributes: ----A
Company Name: NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation
Internal Name: nvspcap
Original Name: nvspcap.dll
Product: NVIDIA GeForce Experience
Description: NVIDIA Capture Server Proxy
File Version: 2.5.15.46
Product Version: 2.5.15.46
Copyright: (C) NVIDIA Corporation. All rights reserved.
VirusTotal: https://www.virustotal.com/file/d915e00 ... 576501276/
====== End of File: ======
========================= File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe ========================
C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
File not signed
MD5: 8213094EA736A9C575AB0E22AD09B0BA
Creation and modification date: 2015-05-19 19:11 - 2015-05-19 19:11
Size: 000335872
Attributes: ----A
Company Name: Intel Corporation
Internal Name: isa.exe
Original Name: isa.exe
Product: Intel(R) Security Assist
Description: Intel(R) Security Assist
File Version: 1.0.0.532
Product Version: 1.0.0.532
Copyright: Copyright © 2014
VirusTotal: https://www.virustotal.com/file/12670a4 ... 586335351/
====== End of File: ======
========================= File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe ========================
C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
File not signed
MD5: 1DFC3CCA51785254C5604238BB1A5467
Creation and modification date: 2015-05-19 19:11 - 2015-05-19 19:11
Size: 000007680
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: https://www.virustotal.com/file/31451a9 ... 586196234/
====== End of File: ======
========================= File: C:\WINDOWS\System32\drivers\BthA2dp.sys ========================
C:\WINDOWS\System32\drivers\BthA2dp.sys
File not signed
MD5: CCA2505C9EB10CDABDC9FEE10D812F02
Creation and modification date: 2019-09-14 09:18 - 2019-09-14 09:18
Size: 000231936
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: btha2dp.sys
Original Name: btha2dp.sys
Product: Microsoft® Windows® Operating System
Description: Bluetooth A2DP Driver
File Version: 10.0.18362.356 (WinBuild.160101.0800)
Product Version: 10.0.18362.356
Copyright: © Microsoft Corporation. All rights reserved.
VirusTotal: https://www.virustotal.com/file/8b0f65f ... 587366449/
====== End of File: ======
========================= File: C:\WINDOWS\System32\Drivers\CH341S64.SYS ========================
C:\WINDOWS\System32\Drivers\CH341S64.SYS
File not signed
MD5: 3C0A1B6F538E00F318C109F4A3F29515
Creation and modification date: 2019-05-29 04:18 - 2015-01-26 00:00
Size: 000059904
Attributes: ----A
Company Name: www.winchiphead.com
Internal Name: CH341SER
Original Name: CH341SER
Product: CH341SER.SYS
Description: WDM_64 for CH341 serial, by W.ch
File Version: 3.40 built by: WinDDK
Product Version: 3.40
Copyright: Copyright (C) W.ch 2001-2014
VirusTotal: 0
====== End of File: ======
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat => moved successfully
"HKU\S-1-5-21-3592886365-2214475677-956089615-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\System\CurrentControlSet\Services\DevActSvc => removed successfully
DevActSvc => service removed successfully
C:\rsit => moved successfully
C:\Program Files\trend micro => moved successfully
C:\Users\ASUS\Desktop\RSITx64.exe => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0774E8AC-4815-48C8-A612-A01CF91FAB76}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D08934A0-021F-4FAA-9486-A057FCB64D2E}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D55484B8-61CC-4831-AA9F-BF1990AB48BC}" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 10248192 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 43314551 B
Java, Flash, Steam htmlcache => 263981160 B
Windows/system/drivers => 2532582 B
Edge => 574219 B
Chrome => 126141107 B
Firefox => 891184441 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 125514 B
NetworkService => 276074 B
ASUS => 124419365 B
RecycleBin => 0 B
EmptyTemp: => 1.4 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 09:54:50 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 19-04-2020
Ran by ASUS (20-04-2020 09:50:02) Run:1
Running from C:\Users\ASUS\Desktop
Loaded Profiles: ASUS (Available Profiles: ASUS)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
CMD: type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat"
File: C:\Windows\system32\nvspcap64.dll
File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
File: C:\WINDOWS\System32\drivers\BthA2dp.sys
File: C:\WINDOWS\System32\Drivers\CH341S64.SYS
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-07-16] () [File not signed]
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3592886365-2214475677-956089615-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S3 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [X]
2020-04-16 23:07 - 2020-04-16 23:07 - 000000000 ____D C:\rsit
2020-04-16 23:07 - 2020-04-16 23:07 - 000000000 ____D C:\Program Files\trend micro
2020-04-16 22:51 - 2020-04-16 22:51 - 001222144 _____ C:\Users\ASUS\Desktop\RSITx64.exe
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
FirewallRules: [TCP Query User{0774E8AC-4815-48C8-A612-A01CF91FAB76}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [UDP Query User{D08934A0-021F-4FAA-9486-A057FCB64D2E}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe No File
FirewallRules: [{D55484B8-61CC-4831-AA9F-BF1990AB48BC}] => (Allow) C:\Users\ASUS\AppData\Roaming\Zoom\bin\airhost.exe No File
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========
Count : 38
Average :
Sum : 1036918801
Maximum :
Minimum :
Property : Length
========= End of Powershell: =========
========= type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat" =========
@echo off
TITLE Update check..
start "" http://zipansion.com/2HkmW
========= End of CMD: =========
========================= File: C:\Windows\system32\nvspcap64.dll ========================
C:\Windows\system32\nvspcap64.dll
File not signed
MD5: E4631786E983D745E6E598FD39C0E3D2
Creation and modification date: 2018-12-14 20:46 - 2015-10-03 04:22
Size: 001710568
Attributes: ----A
Company Name: NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation
Internal Name: nvspcap
Original Name: nvspcap.dll
Product: NVIDIA GeForce Experience
Description: NVIDIA Capture Server Proxy
File Version: 2.5.15.46
Product Version: 2.5.15.46
Copyright: (C) NVIDIA Corporation. All rights reserved.
VirusTotal: https://www.virustotal.com/file/d915e00 ... 576501276/
====== End of File: ======
========================= File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe ========================
C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
File not signed
MD5: 8213094EA736A9C575AB0E22AD09B0BA
Creation and modification date: 2015-05-19 19:11 - 2015-05-19 19:11
Size: 000335872
Attributes: ----A
Company Name: Intel Corporation
Internal Name: isa.exe
Original Name: isa.exe
Product: Intel(R) Security Assist
Description: Intel(R) Security Assist
File Version: 1.0.0.532
Product Version: 1.0.0.532
Copyright: Copyright © 2014
VirusTotal: https://www.virustotal.com/file/12670a4 ... 586335351/
====== End of File: ======
========================= File: C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe ========================
C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
File not signed
MD5: 1DFC3CCA51785254C5604238BB1A5467
Creation and modification date: 2015-05-19 19:11 - 2015-05-19 19:11
Size: 000007680
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: https://www.virustotal.com/file/31451a9 ... 586196234/
====== End of File: ======
========================= File: C:\WINDOWS\System32\drivers\BthA2dp.sys ========================
C:\WINDOWS\System32\drivers\BthA2dp.sys
File not signed
MD5: CCA2505C9EB10CDABDC9FEE10D812F02
Creation and modification date: 2019-09-14 09:18 - 2019-09-14 09:18
Size: 000231936
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: btha2dp.sys
Original Name: btha2dp.sys
Product: Microsoft® Windows® Operating System
Description: Bluetooth A2DP Driver
File Version: 10.0.18362.356 (WinBuild.160101.0800)
Product Version: 10.0.18362.356
Copyright: © Microsoft Corporation. All rights reserved.
VirusTotal: https://www.virustotal.com/file/8b0f65f ... 587366449/
====== End of File: ======
========================= File: C:\WINDOWS\System32\Drivers\CH341S64.SYS ========================
C:\WINDOWS\System32\Drivers\CH341S64.SYS
File not signed
MD5: 3C0A1B6F538E00F318C109F4A3F29515
Creation and modification date: 2019-05-29 04:18 - 2015-01-26 00:00
Size: 000059904
Attributes: ----A
Company Name: www.winchiphead.com
Internal Name: CH341SER
Original Name: CH341SER
Product: CH341SER.SYS
Description: WDM_64 for CH341 serial, by W.ch
File Version: 3.40 built by: WinDDK
Product Version: 3.40
Copyright: Copyright (C) W.ch 2001-2014
VirusTotal: 0
====== End of File: ======
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat => moved successfully
"HKU\S-1-5-21-3592886365-2214475677-956089615-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-3592886365-2214475677-956089615-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\System\CurrentControlSet\Services\DevActSvc => removed successfully
DevActSvc => service removed successfully
C:\rsit => moved successfully
C:\Program Files\trend micro => moved successfully
C:\Users\ASUS\Desktop\RSITx64.exe => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0774E8AC-4815-48C8-A612-A01CF91FAB76}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D08934A0-021F-4FAA-9486-A057FCB64D2E}C:\program files (x86)\steam\steamapps\common\thqbcnp1\gothicremake\binaries\win64\gothicremake.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D55484B8-61CC-4831-AA9F-BF1990AB48BC}" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 10248192 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 43314551 B
Java, Flash, Steam htmlcache => 263981160 B
Windows/system/drivers => 2532582 B
Edge => 574219 B
Chrome => 126141107 B
Firefox => 891184441 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 125514 B
NetworkService => 276074 B
ASUS => 124419365 B
RecycleBin => 0 B
EmptyTemp: => 1.4 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 09:54:50 ====
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
OK. Ako to vyzera s PC?
Absolvent skoly pre novacikov 
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!

E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá
Stránka už se po zapmnutí nenačítá, můžeme toto téma uzavřít.
Díky za pomoc!
Díky za pomoc!
Re: Nejde aktualizovat antivirus, občas na ntb nefungují klá

- Stiahni DelFix: https://toolslib.net/downloads/finish/2-delfix/
- Uloz na plochu a spusti
- Nechaj oznacenu moznost "Remove disinfection tools"
- Klikni na "Run"
Absolvent skoly pre novacikov 
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!

E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!