Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Viry v PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Viry v PC

#1 Příspěvek od Hanss1982 »

Zdravím prosím o kontrolu logu, Kašperský hlásí trojana (Globalroot) a možná i jiné havěti od syna. Penízky zase pošlu :-). Děkuji

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-10-2020
Ran by norst (administrator) on DESKTOP-EE21DUM (Micro-Star International Co., Ltd MS-7B86) (13-10-2020 19:59:34)
Running from C:\Users\norst\OneDrive\Plocha
Loaded Profiles: norst
Platform: Windows 10 Pro Version 2004 19041.508 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\Bloody ToneMaker1.exe
() [File not signed] C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\SDK\CM_LibraryIO.exe
(Advanced Micro Devices, Inc. -> ) C:\Program Files\AMD\Performance Profile Client\RyzenMaster\AUEPRyzenMasterAC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPUF.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0359518.inf_amd64_ddc5c961c2795261\B359297\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0359518.inf_amd64_ddc5c961c2795261\B359297\atiesrxx.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <10>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\avpui.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub.exe <3>
(Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_agent.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.45.11001.0_x64__8wekyb3d8bbwe\GamingServices.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.45.11001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12010.1001.2.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [710776 2020-06-18] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\Run: [BloodyToneMaker] => C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\Bloody ToneMaker1.exe [8555008 2017-10-16] () [File not signed]
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [104586376 2020-09-16] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [30870200 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG5600 series: CNMLMCA.DLL
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG5600 series XPS: C:\WINDOWS\system32\CNMXLMCA.DLL [408576 2014-03-18] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [375296 2014-03-17] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.75\Installer\chrmstp.exe [2020-10-08] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {1C6139F8-7E9B-406C-8548-1836B74C3A25} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {1F016E36-A542-478E-9A7A-89B5EBA9E906} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [25492152 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {225495CE-5C56-443E-A764-E6701E99F488} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {22644B36-DAD9-4986-AD92-65E09EA6CDFE} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe
Task: {28C03987-0F63-4970-A105-52DCC3323688} - System32\Tasks\Opera scheduled assistant Autoupdate 1578932433 => C:\Users\norst\AppData\Local\Programs\Opera\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\norst\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {2B39C103-4D08-40AA-892B-276F76CB0027} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {301C4F66-5C0A-464A-AFF6-EE40F6FC74ED} - System32\Tasks\Opera scheduled Autoupdate 1578932429 => C:\Users\norst\AppData\Local\Programs\Opera\launcher.exe
Task: {369DC468-1797-4EBA-9E8C-BCC404D7FDEF} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [752136 2020-10-08] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {3E5DD7C3-8654-4228-9104-3936EEA5F3AD} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {4B49EA0C-C5DB-4BC9-922F-78FEF842E710} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1645240 2020-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {6D446367-9A1A-4C0F-B7E2-EAF12C234087} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
Task: {776C11D6-A312-4C06-9AB5-14F3F059EDFD} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {96750DF5-A1CF-4AD6-8D31-E90BC8718C7A} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1642672 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {9C109C0D-CC2C-4044-8CCE-090542F1316C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Task: {B4C2ECE5-F208-4D3A-A00A-FF970FDC3883} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Task: {C21542E8-1144-4B38-AC80-DF97F716F95E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {C7759254-19C3-4043-B6F6-EAEC916449D2} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1645240 2020-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {CCABB30C-1C33-4567-BA8C-2DC18FA66905} - System32\Tasks\AdwCleaner_onReboot => C:\Users\norst\OneDrive\Plocha\adwcleaner_8.0.6.exe
Task: {D6E559AA-1845-48BE-AE71-86F4E0655564} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
Task: {E5244FD6-C3BE-400B-AF98-84FAE1A49ED1} - System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-EE21DUM-norst DESKTOP-EE21DUM => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [469640 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {EBC84B1A-BA74-4C62-906E-AF7C6AE97506} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1645240 2020-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {ECC0B3AA-00DC-47D7-ACA2-512C712073C8} - System32\Tasks\Agent Activation Runtime\S-1-5-21-1957376853-3360443333-2721091683-1006 => C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe [13312 2020-06-12] (Microsoft Windows -> )
Task: {FB768E82-D8C8-4358-972C-D0B2EFFEB1C6} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [69304 2020-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll => No File
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll => No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0633f68a-5932-46fa-b504-4ad5e168613f}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{07e268a3-dbf0-408d-9600-988267faa0c5}: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{7a985afa-9063-429c-a2a0-b31657f79488}: [DhcpNameServer] 192.168.0.1

Edge:
======
DownloadDir: C:\Users\norst\Downloads

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-08-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-08-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-04-23] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-04-23] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-09-11] (Adobe Inc. -> Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default [2020-10-13]
CHR DownloadDir: E:\Chrome
CHR Notifications: Default -> hxxps://aternos.org; hxxps://kfc.cz
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR NewTab: Default -> Not-active:"chrome-extension://cepmfckfppjpbkjgnpokojedlngflnca/newtab.html"
CHR Extension: (Prezentace) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-01-13]
CHR Extension: (Dokumenty) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-01-13]
CHR Extension: (Disk Google) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-01-13]
CHR Extension: (YouTube) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-01-13]
CHR Extension: (Les Háttérképek) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\cepmfckfppjpbkjgnpokojedlngflnca [2020-01-23]
CHR Extension: (Tabulky) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-01-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-09-12]
CHR Extension: (Mountain Lake) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\longgbnofmdadlfgpklfagfimlefidmo [2020-01-24]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-01-13]
CHR Extension: (Gmail) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-01-13]
CHR Extension: (Chrome Media Router) - C:\Users\norst\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-08]
CHR HKLM\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk
CHR HKLM-x32\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
R2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPLauncher.exe [61624 2020-09-23] (Advanced Micro Devices, Inc. -> AMD)
R2 AVP20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\avp.exe [357416 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8686928 2020-09-03] (BattlEye Innovations e.K. -> )
S4 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803952 2019-08-02] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S4 EQU8_13; C:\ProgramData\EQU8\Diabotical\bin\anticheat.x64.equ8.exe [5542592 2020-09-23] (Int3 Software AB -> Int3 Software AB)
S4 HnGEpicService; E:\Epic Games\HeroesGeneralsWWII\hngservice.exe [788776 2020-10-13] (Reto-Moto ApS -> Reto-Moto ApS)
S3 klvssbridge64_20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\vssbridge64.exe [438928 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab)
S4 KSDE4.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksde.exe [619752 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab)
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [11139720 2020-09-16] (Logitech Inc -> Logitech, Inc.)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7185288 2020-10-04] (Malwarebytes Inc -> Malwarebytes)
S3 mracsvc; C:\WINDOWS\System32\mracsvc.exe [20504728 2020-05-08] (Mail.Ru LLC -> LLC Mail.Ru)
S4 Rockstar Service; E:\RockStars Launcher\Launcher\RockstarService.exe [1629312 2020-09-30] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5097896 2020-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\NisSrv.exe [2496144 2020-07-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MsMpEng.exe [104192 2020-07-12] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [62056 2020-07-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 anvsnddrv; C:\WINDOWS\system32\drivers\anvsnddrv.sys [33872 2011-11-28] (AnvSoft Co., Ltd. -> AnvSoft Inc.)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-09-21] (Bluestack Systems, Inc -> Bluestack System Inc.)
R3 CMUAC; C:\WINDOWS\system32\DRIVERS\Headset6400x1.SYS [387072 2013-10-03] (C-MEDIA ELECTRONICS INC. -> A4Tech Inc.)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [246912 2019-02-16] (Kaspersky Lab -> AO Kaspersky Lab)
S3 EQU8_HELPER_13; C:\WINDOWS\system32\DRIVERS\EQU8_HELPER_13.sys [38032 2020-09-23] (Int3 Software AB -> )
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [79768 2020-05-20] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [145504 2020-05-20] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [93312 2019-03-12] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [37816 2020-05-20] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [251800 2020-08-15] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [643840 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [1277704 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP20.0\Bases\klids.sys [240728 2020-09-08] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [998808 2020-08-15] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [58192 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [79760 2020-05-20] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [59512 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [51328 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [45904 2019-03-10] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48592 2018-03-16] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [256760 2020-08-15] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [309768 2020-08-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [117512 2020-08-15] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [206888 2020-08-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [105600 2019-03-05] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [211048 2020-05-20] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [233368 2020-08-15] (Kaspersky Lab -> AO Kaspersky Lab)
R2 LGHUBTemperatureService; C:\ProgramData\LGHUB\depots\66043\driver_cpu_temperature\logi_core_temp.sys [25448 2020-09-16] (Logitech Inc. -> Logitech)
R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [38136 2020-03-25] (Logitech Inc -> Logitech)
R3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [26672 2020-05-21] (Logitech Inc -> Logitech)
R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [66808 2020-03-25] (Logitech Inc -> Logitech)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-10-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-10-04] (Malwarebytes Inc -> Malwarebytes)
S3 mracdrv; C:\WINDOWS\System32\drivers\mracdrv.sys [19736824 2020-05-08] (Mail.Ru LLC -> LLC Mail.Ru)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45976 2020-07-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [408816 2020-07-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64224 2020-07-12] (Microsoft Windows -> Microsoft Corporation)
U3 aswbdisk; no ImagePath
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-13 19:48 - 2020-10-13 19:48 - 000000000 ____D C:\WINDOWS\pss
2020-10-13 18:38 - 2020-10-13 18:38 - 000003946 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper
2020-10-13 18:34 - 2020-10-13 18:34 - 000002045 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk
2020-10-13 18:34 - 2020-10-13 18:34 - 000002033 _____ C:\ProgramData\Plocha\BlueStacks Multi-Instance Manager.lnk
2020-10-13 18:34 - 2020-10-13 18:34 - 000001884 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks.lnk
2020-10-13 18:34 - 2020-10-13 18:34 - 000001872 _____ C:\ProgramData\Plocha\BlueStacks.lnk
2020-10-13 18:33 - 2020-10-13 18:34 - 000000000 ____D C:\ProgramData\BlueStacks
2020-10-13 18:33 - 2020-10-13 18:33 - 000000000 ____D C:\Program Files\BlueStacks
2020-10-13 18:31 - 2020-10-13 18:32 - 000000000 ____D C:\Users\norst\AppData\Local\BlueStacksSetup
2020-10-13 18:31 - 2020-10-13 18:32 - 000000000 ____D C:\Users\norst\AppData\Local\Bluestacks
2020-10-13 15:25 - 2020-10-13 19:39 - 000000000 ____D C:\Users\norst\AppData\Local\Roblox
2020-10-13 15:25 - 2020-10-13 15:25 - 000000096 _____ C:\Users\norst\AppData\LocalLow\rbxcsettings.rbx
2020-10-13 14:08 - 2020-10-13 19:40 - 000000000 ____D C:\ProgramData\Gaijin
2020-10-13 14:08 - 2020-10-13 14:08 - 000000000 ____D C:\Users\norst\AppData\Local\Gaijin
2020-10-13 13:48 - 2020-10-13 13:48 - 000000000 ____D C:\Games
2020-10-12 13:24 - 2020-10-12 13:24 - 000000000 ____D C:\Users\norst\AppData\LocalLow\mestiez
2020-10-11 15:46 - 2020-10-11 15:46 - 000000000 __SHD C:\found.003
2020-10-11 15:25 - 2020-10-11 15:25 - 000000000 ____D C:\Users\norst\AppData\Local\AbzuGame
2020-10-04 15:24 - 2020-10-04 15:24 - 000003304 _____ C:\WINDOWS\system32\Tasks\StartCNBM
2020-10-04 15:23 - 2020-10-04 15:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Software
2020-10-04 15:22 - 2020-10-04 15:22 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2020-10-04 15:18 - 2020-09-29 15:12 - 001754336 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 001754336 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 001360096 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 001360096 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 001048416 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 001048416 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000910872 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000910872 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000762080 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 000737504 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000621792 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000497376 _____ C:\WINDOWS\system32\GameManager64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000493792 _____ C:\WINDOWS\system32\dgtrayicon.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 000469216 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000456928 _____ C:\WINDOWS\system32\atieah64.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 000433376 _____ C:\WINDOWS\system32\EEURestart.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 000380640 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000352480 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 000340192 _____ C:\WINDOWS\system32\clinfo.exe
2020-10-04 15:18 - 2020-09-29 15:12 - 000245984 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000213728 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000187616 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000183016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000167648 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000167136 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000157408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000143072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000141536 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000136416 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000126176 _____ C:\WINDOWS\system32\atidxx64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000108256 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000091360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mcl64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000076000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mcl32.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000047328 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000044256 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000020408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2020-10-04 15:18 - 2020-09-29 15:12 - 000020408 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 072724192 _____ C:\WINDOWS\system32\amd_comgr.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 071742176 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdhip64.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 060137696 _____ C:\WINDOWS\SysWOW64\amd_comgr32.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 004632288 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 004156640 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 001345248 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 001345248 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000941792 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000769248 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000554208 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000490208 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000467168 _____ C:\WINDOWS\system32\amdlogum.exe
2020-10-04 15:18 - 2020-09-29 15:11 - 000384224 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000380640 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000159280 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000135392 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000123104 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000121056 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000107744 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2020-10-04 15:18 - 2020-09-29 15:11 - 000070880 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 001686632 _____ (AMD) C:\WINDOWS\system32\amf-mft-mjpeg-decoder64.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 001365992 _____ (AMD) C:\WINDOWS\SysWOW64\amf-mft-mjpeg-decoder32.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 000547408 _____ C:\WINDOWS\system32\amdmiracast.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 000136536 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 000130856 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 000130856 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 000120880 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 000108872 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2020-10-04 15:18 - 2020-09-29 15:10 - 000108872 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2020-10-04 15:18 - 2020-09-23 09:16 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2020-10-04 15:18 - 2020-09-23 09:16 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2020-10-04 15:18 - 2020-09-23 04:57 - 000549352 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2020-10-04 15:18 - 2020-09-23 04:57 - 000549352 _____ C:\WINDOWS\system32\atiapfxx.blb
2020-10-04 15:14 - 2020-10-04 15:14 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-10-04 15:14 - 2020-10-04 15:13 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-09-29 17:28 - 2020-09-29 17:29 - 000000000 ____D C:\Users\norst\Downloads\menyooStuff
2020-09-29 13:22 - 2020-09-29 13:22 - 000000000 ____D C:\Users\norst\OneDrive\Dokumenty\My Cheat Tables
2020-09-25 17:13 - 2020-09-25 17:13 - 000000000 __SHD C:\found.002
2020-09-25 14:29 - 2020-09-25 14:30 - 000000000 ____D C:\Users\norst\OneDrive\Dokumenty\RCT3
2020-09-25 14:29 - 2020-09-25 14:29 - 000000000 ____D C:\Users\norst\AppData\Roaming\Frontier
2020-09-25 13:26 - 2020-10-13 13:51 - 000000000 ____D C:\Users\norst\AppData\LocalLow\Heroes and Generals
2020-09-25 13:26 - 2020-09-25 13:26 - 000000000 ____D C:\Users\norst\AppData\Roaming\HeroesAndGeneralsDesktop
2020-09-24 18:14 - 2020-09-24 18:14 - 000000000 ____D C:\Users\norst\OneDrive\Dokumenty\CPY_SAVES
2020-09-24 18:14 - 2020-09-24 18:14 - 000000000 ____D C:\Users\norst\OneDrive\Dokumenty\Assassin's Creed Odyssey
2020-09-23 20:34 - 2020-09-23 20:34 - 000038032 _____ C:\WINDOWS\system32\Drivers\EQU8_HELPER_13.sys
2020-09-23 20:34 - 2020-09-23 20:34 - 000000000 ____D C:\Users\norst\AppData\Roaming\Diabotical
2020-09-23 20:34 - 2020-09-23 20:34 - 000000000 ____D C:\ProgramData\EQU8
2020-09-22 19:34 - 2020-09-22 19:34 - 000000000 __SHD C:\found.001
2020-09-22 16:48 - 2020-10-10 15:56 - 000000000 ____D C:\Users\norst\AppData\LocalLow\KingArt
2020-09-21 13:07 - 2020-09-21 13:07 - 000000000 ____D C:\Users\norst\AppData\Roaming\KF2
2020-09-20 19:05 - 2020-09-20 19:05 - 000002249 _____ C:\ProgramData\Plocha\HP DeskJet 5000 series.lnk
2020-09-20 19:05 - 2020-09-20 19:05 - 000001273 _____ C:\ProgramData\Plocha\HP DeskJet 5000 series-HP Scan.lnk
2020-09-20 19:05 - 2020-09-20 19:05 - 000001196 _____ C:\ProgramData\Plocha\Objednání spotřebního materiálu - HP DeskJet 5000 series.lnk
2020-09-20 19:01 - 2020-09-20 19:01 - 000218783 _____ C:\Users\norst\OneDrive\Dokumenty\tt.pdf
2020-09-20 18:57 - 2020-09-20 18:57 - 000068053 _____ C:\Users\norst\OneDrive\Dokumenty\ttt.pdf
2020-09-20 18:46 - 2020-09-20 18:46 - 000000000 ____D C:\Users\norst\AppData\LocalLow\Temp
2020-09-19 13:04 - 2020-09-19 13:04 - 000000000 ____D C:\Users\norst\AppData\LocalLow\South East Games
2020-09-17 10:36 - 2020-09-17 10:36 - 000000000 ____D C:\Users\norst\AppData\Roaming\CreamAPI
2020-09-17 10:36 - 2020-09-17 10:36 - 000000000 ____D C:\Users\norst\AppData\LocalLow\Milkstone Studios
2020-09-16 11:45 - 2020-09-16 11:45 - 000000650 _____ C:\ProgramData\Plocha\Logitech G HUB.lnk
2020-09-16 11:45 - 2020-09-16 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi
2020-09-16 10:46 - 2020-01-23 09:06 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.check
2020-09-16 10:46 - 2020-01-23 09:06 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.backup
2020-09-15 11:29 - 2020-09-15 11:36 - 000000000 ____D C:\Users\norst\AppData\Roaming\MedievalEngineers
2020-09-15 10:11 - 2020-09-15 10:11 - 000000000 ____D C:\Users\norst\AppData\Roaming\HOODLUM
2020-09-15 10:11 - 2020-09-15 10:11 - 000000000 ____D C:\Users\norst\AppData\LocalLow\Cheesecake Dev
2020-09-15 10:10 - 2020-09-15 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Bug Report Tool
2020-09-13 09:34 - 2020-09-13 09:34 - 000000000 ____D C:\Users\norst\AppData\Roaming\Kalypso Media

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-13 19:59 - 2020-07-12 19:56 - 000000000 ____D C:\FRST
2020-10-13 19:58 - 2020-05-18 07:22 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2020-10-13 19:56 - 2020-07-06 17:58 - 000000000 ____D C:\Users\norst\AppData\Roaming\LGHUB
2020-10-13 19:56 - 2020-07-06 17:58 - 000000000 ____D C:\Users\norst\AppData\Local\LGHUB
2020-10-13 19:55 - 2020-02-05 09:53 - 000003126 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2020-10-13 19:55 - 2020-02-05 09:52 - 000003112 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2020-10-13 19:55 - 2020-01-13 13:41 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2020-10-13 19:55 - 2020-01-13 13:41 - 000008192 ___SH C:\DumpStack.log.tmp
2020-10-13 19:55 - 2020-01-13 13:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-10-13 19:55 - 2020-01-13 13:15 - 000000000 ____D C:\WINDOWS\ServiceState
2020-10-13 19:55 - 2020-01-13 13:15 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-10-13 19:55 - 2020-01-13 13:11 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-10-13 19:53 - 2020-01-13 13:58 - 001693136 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-10-13 19:53 - 2020-01-13 13:17 - 000716674 _____ C:\WINDOWS\system32\perfh005.dat
2020-10-13 19:53 - 2020-01-13 13:17 - 000144852 _____ C:\WINDOWS\system32\perfc005.dat
2020-10-13 19:53 - 2020-01-13 13:14 - 000000000 ____D C:\WINDOWS\INF
2020-10-13 19:52 - 2020-01-13 18:20 - 000000000 ____D C:\ProgramData\AVAST Software
2020-10-13 19:44 - 2020-05-18 07:08 - 000000000 ____D C:\Program Files (x86)\Steam
2020-10-13 19:43 - 2020-01-15 12:15 - 000000000 ____D C:\Users\norst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2020-10-13 18:33 - 2020-04-24 18:16 - 000000000 ____D C:\Users\Public\BlueStacks
2020-10-13 17:03 - 2020-08-04 18:13 - 000000000 ____D C:\Users\norst\AppData\Roaming\EasyAntiCheat
2020-10-13 17:03 - 2020-02-14 15:07 - 000000000 ____D C:\Users\norst\OneDrive\Dokumenty\My Games
2020-10-13 17:01 - 2020-01-13 18:22 - 000000000 ____D C:\Users\norst\AppData\Roaming\uTorrent
2020-10-13 17:01 - 2020-01-13 18:22 - 000000000 ____D C:\Users\norst\AppData\Local\CrashDumps
2020-10-13 15:17 - 2020-01-13 13:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-10-13 15:16 - 2020-01-13 13:15 - 000000000 ___HD C:\Program Files\WindowsApps
2020-10-13 15:16 - 2020-01-13 13:15 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-10-13 15:13 - 2020-02-09 21:20 - 000005266 _____ C:\WINDOWS\system32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-EE21DUM-norst DESKTOP-EE21DUM
2020-10-13 13:44 - 2020-09-02 10:22 - 000000000 ____D C:\Users\norst\AppData\Roaming\vlc
2020-10-11 16:42 - 2020-01-13 13:56 - 000000000 ____D C:\Users\norst
2020-10-11 16:40 - 2020-03-31 16:53 - 000000000 ____D C:\Program Files\CCleaner
2020-10-11 16:39 - 2020-08-04 17:05 - 000000823 _____ C:\ProgramData\Plocha\CCleaner.lnk
2020-10-11 16:39 - 2020-03-31 16:54 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-10-11 15:25 - 2020-01-13 14:31 - 000000000 ____D C:\Users\norst\AppData\Local\UnrealEngine
2020-10-10 15:57 - 2020-09-02 10:22 - 000000876 _____ C:\ProgramData\Plocha\VLC media player.lnk
2020-10-10 15:57 - 2020-09-02 10:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2020-10-10 15:57 - 2020-01-14 13:31 - 000000000 ____D C:\WINDOWS\Minidump
2020-10-10 15:54 - 2020-05-21 07:54 - 000000000 ____D C:\Riot Games
2020-10-10 15:54 - 2020-05-21 07:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2020-10-10 15:54 - 2020-05-21 07:53 - 000000000 ____D C:\Users\norst\AppData\Local\Riot Games
2020-10-10 15:49 - 2020-01-13 13:58 - 000000000 ____D C:\Users\norst\AppData\Local\Packages
2020-10-10 15:45 - 2020-01-13 14:00 - 000000000 ____D C:\Users\norst\AppData\Local\PlaceholderTileLogoFolder
2020-10-10 15:37 - 2020-01-13 13:11 - 000065536 _____ C:\WINDOWS\system32\config\ELAM
2020-10-09 20:32 - 2020-01-13 13:15 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-10-08 13:16 - 2020-01-13 20:16 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-10-04 15:24 - 2020-01-14 13:30 - 000000000 ____D C:\Program Files\AMD
2020-10-04 15:23 - 2020-02-05 09:52 - 000003194 _____ C:\WINDOWS\system32\Tasks\ModifyLinkUpdate
2020-10-04 15:23 - 2020-02-05 09:52 - 000003160 _____ C:\WINDOWS\system32\Tasks\StartCN
2020-10-04 15:23 - 2020-02-05 09:52 - 000003080 _____ C:\WINDOWS\system32\Tasks\StartDVR
2020-10-04 15:22 - 2020-01-13 13:41 - 000000000 ____D C:\WINDOWS\system32\AMD
2020-10-04 15:18 - 2020-01-13 14:15 - 000000000 ____D C:\AMD
2020-10-04 15:14 - 2020-08-05 19:12 - 000001993 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-10-04 15:14 - 2020-08-05 19:12 - 000001981 _____ C:\ProgramData\Plocha\Malwarebytes.lnk
2020-10-04 15:14 - 2020-01-13 13:15 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-10-04 15:13 - 2020-08-05 19:12 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-09-30 15:12 - 2020-01-14 12:50 - 000000000 ____D C:\Program Files\Rockstar Games
2020-09-30 15:12 - 2020-01-14 12:50 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2020-09-29 19:45 - 2020-08-05 18:11 - 000003402 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-09-29 19:45 - 2020-08-05 18:11 - 000003178 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-09-29 19:45 - 2020-05-18 07:23 - 000002486 _____ C:\WINDOWS\system32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2020-09-29 19:45 - 2020-03-31 16:54 - 000002238 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-09-29 19:45 - 2020-02-06 17:49 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-09-29 15:11 - 2020-07-13 11:42 - 000168536 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
2020-09-29 15:11 - 2020-02-05 09:51 - 001784032 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2020-09-29 15:11 - 2020-02-05 09:51 - 000199456 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
2020-09-27 16:19 - 2020-04-15 12:22 - 000000000 ____D C:\Users\norst\AppData\Roaming\.minecraft
2020-09-27 15:41 - 2020-02-06 17:49 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-09-24 18:14 - 2020-01-13 13:58 - 000000000 ____D C:\Users\norst\AppData\Local\D3DSCache
2020-09-23 16:43 - 2020-07-13 11:42 - 000510368 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdfendrsr.exe
2020-09-23 16:43 - 2020-07-13 11:42 - 000088992 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\amdfendr.sys
2020-09-22 16:50 - 2020-05-28 13:08 - 000000000 ____D C:\Users\norst\AppData\Roaming\Goldberg SteamEmu Saves
2020-09-22 16:48 - 2020-03-30 11:23 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2020-09-21 09:37 - 2020-01-13 13:15 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-09-21 09:35 - 2020-01-29 15:25 - 000000000 ____D C:\Users\norst\AppData\Local\ElevatedDiagnostics
2020-09-20 19:01 - 2020-03-02 17:04 - 000000000 ____D C:\ProgramData\HP
2020-09-18 13:04 - 2020-05-20 08:24 - 000166848 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2020-09-18 13:04 - 2020-04-15 12:37 - 001523640 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2020-09-18 13:04 - 2020-04-15 12:37 - 000204728 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInputRedist.dll
2020-09-18 13:04 - 2020-04-15 12:37 - 000165808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInputRedist.dll
2020-09-18 13:04 - 2020-04-15 12:37 - 000158640 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2020-09-18 13:04 - 2020-04-15 12:37 - 000150456 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2020-09-18 13:04 - 2020-04-15 12:37 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2020-09-18 13:04 - 2020-04-15 12:37 - 000033720 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe
2020-09-16 11:58 - 2020-01-13 13:58 - 000000000 ____D C:\ProgramData\Packages
2020-09-16 11:45 - 2020-08-01 14:45 - 000000000 ____D C:\Program Files\LGHUB
2020-09-15 10:10 - 2020-07-13 11:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMDBugReportTool

==================== Files in the root of some directories ========

2020-04-03 10:22 - 2020-09-10 13:22 - 000000097 _____ () C:\Users\norst\AppData\Roaming\LauncherSettings_live.cfg
2020-04-03 10:15 - 2020-04-03 10:15 - 000002513 _____ () C:\Users\norst\AppData\Roaming\TheHunterSettings_live.bin
2020-04-03 10:15 - 2020-09-10 13:09 - 000000050 _____ () C:\Users\norst\AppData\Roaming\TheHunterSettings_steam_live.cfg
2020-05-08 09:00 - 2020-05-21 19:56 - 000002448 _____ () C:\Users\norst\AppData\Local\krita-sysinfo.log
2020-05-08 09:00 - 2020-05-21 20:02 - 000001490 _____ () C:\Users\norst\AppData\Local\krita.log
2020-05-21 20:02 - 2020-05-21 20:02 - 000000039 _____ () C:\Users\norst\AppData\Local\kritadisplayrc
2020-05-08 09:00 - 2020-05-21 20:02 - 000016154 _____ () C:\Users\norst\AppData\Local\kritarc

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
Obrázek

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Viry v PC

#2 Příspěvek od Hanss1982 »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-10-2020
Ran by norst (13-10-2020 20:00:19)
Running from C:\Users\norst\OneDrive\Plocha
Windows 10 Pro Version 2004 19041.508 (X64) (2020-01-13 11:55:07)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1957376853-3360443333-2721091683-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1957376853-3360443333-2721091683-503 - Limited - Disabled)
Guest (S-1-5-21-1957376853-3360443333-2721091683-501 - Limited - Disabled)
norst (S-1-5-21-1957376853-3360443333-2721091683-1006 - Administrator - Enabled) => C:\Users\norst
WDAGUtilityAccount (S-1-5-21-1957376853-3360443333-2721091683-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Disabled - Out of date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM-x32\...\uTorrent) (Version: 3.1.3.26837 - emc, uTorrent.CZ)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 20.012.20048 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 20.9.2 - Advanced Micro Devices, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BlueStacks App Player (HKLM\...\BlueStacks) (Version: 4.240.0.1075 - BlueStack Systems, Inc.)
Branding64 (HKLM\...\{856DA29A-EA4A-468B-BBC2-B5F60DD75BFE}) (Version: 1.00.0002 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.72 - Piriform)
Epic Games Launcher (HKLM-x32\...\{1D4EB18B-0FEE-444E-B4D1-6F2CFBC363E6}) (Version: 1.1.267.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 86.0.4240.75 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.99.0 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\{5EFC6C07-6B87-43FC-9524-F9E967241741}) (Version: 1.0.2060.1 - Rockstar Games)
Java 8 Update 261 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180261F0}) (Version: 8.0.2610.12 - Oracle Corporation)
Kaspersky Secure Connection (HKLM-x32\...\{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky)
Kaspersky Total Security (HKLM-x32\...\{D891550B-ACFE-4797-B368-BCFC434BBEB1}) (Version: 20.0.14.1085 - Kaspersky) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{D891550B-ACFE-4797-B368-BCFC434BBEB1}) (Version: 20.0.14.1085 - Kaspersky)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Logitech G HUB (HKLM\...\{521c89be-637f-4274-a840-baaf7460c2b2}) (Version: - Logitech)
Malwarebytes version 4.2.1.89 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.1.89 - Malwarebytes)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508 (HKLM-x32\...\{6913e92a-b64e-41c9-a5e6-cef39207fe89}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation)
Microsoft Word 2013 (HKLM\...\Office15.WORD) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (HKLM\...\{90150000-001F-0405-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (HKLM\...\{90150000-001F-041B-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
PVZ Garden Warfare (HKLM-x32\...\{A5AC7D7B-C1D5-4AF9-8829-993DA335BE1B}) (Version: 1.0.3.0 - Electronic Arts)
Revo Uninstaller Pro 4.3.3 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 4.3.3 - VS Revo Group, Ltd.)
Revo Uninstaller Pro verze 4.3.1 (HKLM-x32\...\{A6939138-46FE-47E2-9043-4F20EAB62F92}_is1) (Version: 4.3.1 - VS Revo Group, Ltd.)
R-Link 2 Toolbox (HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\{R-Link 2 Toolbox}}_is1) (Version: 1.7.3 - Renault)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.29.283 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.7.0 - Rockstar Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
ToneMaker 1 (HKLM-x32\...\BloodyToneMaker) (Version: 17.10.0006 - Bloody)
UltraISO Premium V9.75 (HKLM-x32\...\UltraISO_is1) (Version: 9.75 - EZB Systems, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.10 - VideoLAN)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
Základní software zařízení HP DeskJet 5000 series (HKLM\...\{63C42C4B-CC13-4F09-A882-C4D4B17B7FE1}) (Version: 44.4.2678.1977 - HP Inc.)

Packages:
=========
8 Ball Pool -> C:\Program Files\WindowsApps\59794HighScoreHeroLtd.Two.8BallPool_10.5.0.0_x64__bkbk7x6g42dam [2020-10-10] (High Score Hero Ltd. Two Player Games) [MS Ad]
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-03-01] (Microsoft Corporation)
Granny Chapter Two -> C:\Program Files\WindowsApps\27084CasualAzurGamesPlayL.GrannyChapterTwo_22.1.3.0_x86__445vqteswpvvm [2020-07-24] (Casual Azur Games Play Ltd.) [MS Ad]
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_120.1.741.0_x64__v10z8vjag6ke6 [2020-10-10] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-01-13] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-01-13] (Microsoft Corporation) [MS Ad]
Microsoft Midi gm.dls -> C:\Program Files\WindowsApps\Microsoft.Midi.GmDls_1.0.1.0_neutral__8wekyb3d8bbwe [2020-07-09] (Microsoft Platform Extensions)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8101.0_x64__8wekyb3d8bbwe [2020-08-19] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.16.10059.0_x64__8wekyb3d8bbwe [2020-10-10] (Microsoft Studios)
Piano Music Tiles 2019 : Pop Songs -> C:\Program Files\WindowsApps\21108PianoMusicStudio.PianoTiles2018PopSongs_1.3.2.0_x64__m18892jqh4q9e [2020-07-09] (Piano Music Studio) [MS Ad]
Pool Billiard. -> C:\Program Files\WindowsApps\4422JiMing.58480ADCE3F99_1.0.0.0_neutral__qh321nt956kzw [2020-10-10] (JiMing) [MS Ad]
Real DJ -> C:\Program Files\WindowsApps\36059XiaoyaStudio.RealDJ_2.0.1.0_x86__ngh7ertwt50re [2020-09-16] (Xiaoya Lab)
ROBLOX -> C:\Program Files\WindowsApps\ROBLOXCORPORATION.ROBLOX_2.449.18515.0_x86__55nm5eh3cm0pr [2020-09-27] (ROBLOX Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\ShellEx.dll [2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers2: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\ShellEx.dll [2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers2: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\Program Files (x86)\UltraISO\isoshl64.dll [2009-10-22] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
ContextMenuHandlers4: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\ShellEx.dll [2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\Program Files (x86)\UltraISO\isoshl64.dll [2009-10-22] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2020-09-23] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\ShellEx.dll [2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2019-03-29] (VS Revo Group Ltd. -> VS Revo Group)
ContextMenuHandlers6: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\Program Files (x86)\UltraISO\isoshl64.dll [2009-10-22] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2020-02-26 17:35 - 2014-01-10 11:48 - 004260352 _____ () [File not signed] C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\Data\RES\Forms\Internet_Advertisement\Internet_Advertisement_DLL.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 000017920 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 003567616 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-03-13 04:47 - 2018-03-13 04:47 - 000912896 _____ () [File not signed] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-core.dll
2018-03-13 04:47 - 2018-03-13 04:47 - 003109888 _____ () [File not signed] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-s3.dll
2015-02-19 01:13 - 2015-02-19 01:13 - 000817152 _____ () [File not signed] C:\Program Files\AMD\Performance Profile Client\Device.dll
2015-02-19 01:13 - 2015-02-19 01:13 - 003650560 _____ () [File not signed] C:\Program Files\AMD\Performance Profile Client\Platform.dll
2020-09-23 04:00 - 2020-09-23 04:00 - 001583104 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\WVR\OpenVR\bin\win64\driver_amdwvr.dll
2020-02-04 17:00 - 2014-03-17 20:15 - 000375296 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMN6PPM.DLL
2020-02-06 17:51 - 2014-03-18 06:00 - 000408576 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMXLMCA.DLL
2020-02-26 17:35 - 2013-08-09 03:02 - 000243200 _____ (C-MEDIA Electronics INC.) [File not signed] C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\SDK\x64\Vista\osConfLib.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 001180672 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\qsqlite.dll
2020-09-23 04:09 - 2020-09-23 04:09 - 006010880 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 006345216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 001078272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 000313856 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 004000256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 003802624 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 000205312 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Sql.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 000376320 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 092323328 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 000113152 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 005560832 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 000463360 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 000188416 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2020-08-19 17:48 - 2020-08-19 17:48 - 002888704 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\norst:Heroes & Generals [38]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [492]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_261\bin\ssv.dll [2020-08-16] (Oracle America, Inc. -> Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_261\bin\jp2ssv.dll [2020-08-16] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2020-01-13 13:15 - 2020-01-23 09:06 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\Control Panel\Desktop\\Wallpaper -> C:\Users\norst\OneDrive\Plocha\Fotky\dovča Holešice2020\P8120118.JPG
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: EasyAntiCheat => 3
MSCONFIG\Services: EQU8_13 => 3
MSCONFIG\Services: HnGEpicService => 3
MSCONFIG\Services: Rockstar Service => 3
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "AvastUI.exe"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\StartupApproved\StartupFolder: => "Twitch.lnk"
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\StartupApproved\Run: => "R-Link 2 Toolbox"
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\StartupApproved\Run: => "Wargaming.net Game Center"
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1957376853-3360443333-2721091683-1006\...\StartupApproved\Run: => "CCXProcess"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{D7D7FD96-25A7-4CE9-88B8-9F3C5E54A4FA}C:\users\norst\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\norst\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [UDP Query User{A616FA5E-04E1-48BA-B926-424F171A9C34}C:\users\norst\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\norst\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [{99528E43-7B87-4AAF-B19E-4062EEF0AC04}] => (Allow) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
FirewallRules: [{86A38593-FDD0-4AF7-90C6-9067364066C0}] => (Allow) C:\Program Files\AMD\CNext\CNext\Radeonsoftware.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
FirewallRules: [{44A43A71-7C86-483D-A04A-D0E595E805DB}] => (Allow) LPort=5357
FirewallRules: [TCP Query User{FAFBC1A8-7E57-49ED-AEDB-5767BBA7D776}C:\users\norst\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\norst\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [UDP Query User{C46B7FA3-0966-4B17-BE32-706AE3EF41A6}C:\users\norst\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\norst\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [TCP Query User{FD6D803A-B3A5-4B18-82F8-A9A458176192}E:\rockstars launcher\grand theft auto v\gta5.exe] => (Allow) E:\rockstars launcher\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{3DDA8D7C-7C65-4EFD-AF0C-2B4CAA4D92C1}E:\rockstars launcher\grand theft auto v\gta5.exe] => (Allow) E:\rockstars launcher\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{1EDB077E-C2A0-41A4-950A-98C322A66E22}] => (Allow) E:\SteamLibrary\steamapps\common\Slime Rancher\SlimeRancher.exe () [File not signed]
FirewallRules: [{45B30991-0AD9-4C9B-8D93-F8033F5B615F}] => (Allow) E:\SteamLibrary\steamapps\common\Slime Rancher\SlimeRancher.exe () [File not signed]
FirewallRules: [{0E1D655D-FB46-4D25-AD51-A6A56E3AD376}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{8287132C-552B-41C6-AF61-F056044A0923}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{471ADF6B-E58F-4E33-BF94-1FA19825C4CC}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs Zombies Garden Warfare\PVZ.Main_Win64_Retail.exe (Electronic Arts -> EA PopCap)
FirewallRules: [{E201BB2D-C080-4186-ACC0-72A96D83E134}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs Zombies Garden Warfare\PVZ.Main_Win64_Retail.exe (Electronic Arts -> EA PopCap)
FirewallRules: [{AF876C88-34C3-4946-A35F-2155E3B05C65}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{3AD90F9A-6FBA-4C57-9447-C30B50B433A4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{21401989-5C79-4BC2-9B79-30A257F13CE5}] => (Allow) E:\Steam\steamapps\common\World of Tanks Blitz\wotblitz.exe (Wargaming.net) [File not signed]
FirewallRules: [{AB523793-D4DD-4850-8DE8-436484248868}] => (Allow) E:\Steam\steamapps\common\World of Tanks Blitz\wotblitz.exe (Wargaming.net) [File not signed]
FirewallRules: [{BF10A159-68A4-40D9-962C-5523023C887D}] => (Allow) E:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{22E28C4A-03C5-4ECA-A338-5B3CF7100500}] => (Allow) E:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [TCP Query User{3DBC7398-5367-4833-891C-03D4DF30EBB1}C:\program files\lghub\lghub_agent.exe] => (Block) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.)
FirewallRules: [UDP Query User{DCE4B44D-CC1D-4525-B381-36FC9995D1B6}C:\program files\lghub\lghub_agent.exe] => (Block) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.)
FirewallRules: [TCP Query User{988C1445-F33A-46F2-9CF7-DEC264A09061}C:\program files\lghub\lghub_agent.exe] => (Block) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.)
FirewallRules: [UDP Query User{AA43B0B6-F0F0-4BC8-A317-45C270891D52}C:\program files\lghub\lghub_agent.exe] => (Block) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.)
FirewallRules: [{1E1830AE-087E-4120-8783-6957FECB4F21}] => (Allow) C:\Program Files\HP\HP DeskJet 5000 series\Bin\DeviceSetup.exe (HP Inc -> HP Inc.)
FirewallRules: [{36438C86-C996-41BC-A429-4C33D5F6709F}] => (Allow) C:\Program Files\HP\HP DeskJet 5000 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc -> HP Inc.)
FirewallRules: [{96E778C3-83F3-466D-A8CA-629985D9FA47}] => (Allow) E:\Epic Games\Diabotical\diabotical.exe () [File not signed]
FirewallRules: [{0BDDA3E3-D81B-4478-970D-7FF522A7C184}] => (Allow) E:\Epic Games\Diabotical\diabotical.exe () [File not signed]
FirewallRules: [{F2A591C9-CC12-4EDA-B492-9C0BE4C1FC2F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5CB21486-599A-431C-9887-23164DD8C018}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)

==================== Restore Points =========================

13-10-2020 13:50:30 Revo Uninstaller Pro's restore point -
13-10-2020 19:40:58 Revo Uninstaller Pro's restore point - Assassin's Creed Odyssey
13-10-2020 19:50:12 Revo Uninstaller Pro's restore point - Avast Free Antivirus

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (10/13/2020 07:50:12 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {fedc985c-44c4-4e40-b510-db32336dcdec}

Error: (10/13/2020 07:40:57 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {8d96c75a-2fc0-4394-bbc2-88398f349eed}

Error: (10/13/2020 05:01:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 3.1.3.26837, časové razítko: 0x4f5934c0
Název chybujícího modulu: GDI32.dll, verze: 10.0.19041.1, časové razítko: 0xd4f1fbcd
Kód výjimky: 0xc000041d
Posun chyby: 0x00005d67
ID chybujícího procesu: 0x413c
Čas spuštění chybující aplikace: 0x01d6a171866ab90e
Cesta k chybující aplikaci: C:\Users\norst\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: af32ccd0-8e86-4c06-bb52-f2a4c66b8353
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (10/13/2020 02:06:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 3.1.3.26837, časové razítko: 0x4f5934c0
Název chybujícího modulu: GDI32.dll, verze: 10.0.19041.1, časové razítko: 0xd4f1fbcd
Kód výjimky: 0xc000041d
Posun chyby: 0x00005d67
ID chybujícího procesu: 0x3be8
Čas spuštění chybující aplikace: 0x01d6a157e1426049
Cesta k chybující aplikaci: C:\Users\norst\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: aff15b30-1e1b-493f-a00d-ae757f356d7f
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (10/13/2020 01:50:29 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {8d96c75a-2fc0-4394-bbc2-88398f349eed}

Error: (10/13/2020 01:18:48 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (10/12/2020 04:46:35 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program People Playground.exe verze 2019.2.0.49510 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 1248

Čas spuštění: 01d6a0a4aaefe29a

Čas ukončení: 7

Cesta k aplikaci: E:\Chrome\People.Playground.v1.2.3\People.Playground.v1.2.3\People Playground.exe

ID hlášení: 0976042a-1274-46f2-b26a-f4a3c58d09da

Úplný název balíčku s chybou:

ID aplikace relativní podle balíčku s chybou:

Typ zablokování: Unknown

Error: (10/12/2020 01:13:55 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0


System errors:
=============
Error: (10/13/2020 07:49:09 PM) (Source: volmgr) (EventID: 161) (User: )
Description: Soubor s výpisem paměti se nepodařilo vytvořit kvůli chybě při vytváření výpisu paměti.

Error: (10/13/2020 07:48:39 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Služba DCOM zjistila chybu 1115 při pokusu o spuštění služby wuauserv s argumenty Není k dispozici za účelem spuštění serveru:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error: (10/13/2020 07:48:39 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Služba DCOM zjistila chybu 1115 při pokusu o spuštění služby wuauserv s argumenty Není k dispozici za účelem spuštění serveru:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error: (10/13/2020 01:14:46 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (19:59:52, ‎12.‎10.‎2020) bylo neočekávané.

Error: (10/13/2020 01:14:35 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221225684Při zpracování obnovovacích dat došlo k závažné chybě.

Error: (10/12/2020 01:10:06 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Publikování prostředků rozpoznávání funkcí byla ukončena s následující chybou:
%%2147952449 = Požadovaná adresa není v tomto kontextu platná.

Error: (10/12/2020 01:10:00 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (19:10:55, ‎11.‎10.‎2020) bylo neočekávané.

Error: (10/12/2020 01:09:50 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221225684Při zpracování obnovovacích dat došlo k závažné chybě.


Windows Defender:
===================================
Date: 2020-06-25 19:54:33.2440000Z
Description:
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: PUA:Win32/uTorrent
ID: 236126
Závažnost: Nízké
Kategorie: Potenciálně nežádoucí software
Cesta: file:_C:\Users\norst\Downloads\uTorrent313.MPC-HC.exe
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-EE21DUM\norst
Název procesu: C:\Windows\explorer.exe
Verze bezpečnostních informací: AV: 1.319.142.0, AS: 1.319.142.0, NIS: 1.319.142.0
Verze modulu: AM: 1.1.17200.2, NIS: 1.1.17200.2

Date: 2020-05-18 07:05:00.9780000Z
Description:
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: PUA:Win32/Keygen
ID: 225063
Závažnost: Nízké
Kategorie: Potenciálně nežádoucí software
Cesta: file:_E:\Torrenty\RarLab.WinRAR.v5.11.Final.X86.X64.Incl.Keygen-FFF\KEYGEN-FFF.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-EE21DUM\norst
Název procesu: C:\Windows\explorer.exe
Verze bezpečnostních informací: AV: 1.315.890.0, AS: 1.315.890.0, NIS: 1.315.890.0
Verze modulu: AM: 1.1.17000.7, NIS: 1.1.17000.7

Date: 2020-05-18 07:00:20.6400000Z
Description:
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: App:Utorrent
ID: 268641
Závažnost: Nízké
Kategorie: Potenciálně nežádoucí software
Cesta: file:_C:\Users\norst\AppData\Roaming\uTorrent\utorrent.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-EE21DUM\norst
Název procesu: C:\Windows\explorer.exe
Verze bezpečnostních informací: AV: 1.315.890.0, AS: 1.315.890.0, NIS: 1.315.890.0
Verze modulu: AM: 1.1.17000.7, NIS: 1.1.17000.7

Date: 2020-05-17 09:53:58.9200000Z
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {2454E64C-3335-4146-8AFD-003493185D48}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2020-05-16 20:22:24.9490000Z
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {2503F8BE-059F-45DB-B5CC-B1BA158C41EB}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2020-06-24 18:44:55.6090000Z
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.317.617.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.17100.2
Kód chyby: 0x80240017
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

CodeIntegrity:
===================================

Date: 2020-10-13 19:58:00.5660000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-13 19:57:57.1030000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-13 19:57:56.0760000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-13 19:57:56.0630000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-13 19:57:55.6310000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-13 19:57:55.6260000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-13 19:57:55.5660000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-13 19:57:55.5590000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. A.C0 11/08/2019
Motherboard: Micro-Star International Co., Ltd B450-A PRO (MS-7B86)
Processor: AMD Ryzen 5 2600 Six-Core Processor
Percentage of memory in use: 43%
Total physical RAM: 8143.04 MB
Available physical RAM: 4587.77 MB
Total Virtual: 18383.04 MB
Available Virtual: 11922.61 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.47 GB) (Free:59.56 GB) NTFS
Drive d: () (Fixed) (Total:44.77 GB) (Free:1.25 GB) NTFS
Drive e: (Ostatní) (Fixed) (Total:931.5 GB) (Free:271.75 GB) NTFS
Drive g: (Mortal Kombat XL) (CDROM) (Total:38.82 GB) (Free:0 GB) UDF

\\?\Volume{3f56fba8-0156-4b64-b49c-cf546d53f9e0}\ (Obnovení) (Fixed) (Total:0.52 GB) (Free:0.09 GB) NTFS
\\?\Volume{ff876857-b282-44f1-bf7f-a7826ca06bb5}\ () (Fixed) (Total:0.47 GB) (Free:0.08 GB) NTFS
\\?\Volume{47112dd1-a372-427b-bf08-e369e67013c6}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 2 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Viry v PC

#3 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Viry v PC

#4 Příspěvek od Hanss1982 »

# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-09-29.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 10-13-2020
# Duration: 00:00:00
# OS: Windows 10 Pro
# Cleaned: 0
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1405 octets] - [13/10/2020 20:16:18]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
Obrázek

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Viry v PC

#5 Příspěvek od Hanss1982 »

Vypadá to dobře, i Kašperský se vzpamatoval, poslal jsem vám něco :-) moc děkuji
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Viry v PC

#6 Příspěvek od Rudy »

Za příspěvek děkujeme, ale je třeba ještě dočištění. Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
AlternateDataStreams: C:\Users\norst:Heroes & Generals [38]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [492]
C:\Users\norst\Downloads\uTorrent313.MPC-HC.exe
E:\Torrenty\RarLab.WinRAR.v5.11.Final.X86.X64.Incl.Keygen-FFF\KEYGEN-FFF.exe
C:\Users\norst\AppData\Roaming\uTorrent\utorrent.exe
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {9C109C0D-CC2C-4044-8CCE-090542F1316C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Task: {B4C2ECE5-F208-4D3A-A00A-FF970FDC3883} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll => No File
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll => No File
U3 aswbdisk; no ImagePath
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End
Uložte do C:\Users\norst\OneDrive\Plocha jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Viry v PC

#7 Příspěvek od Hanss1982 »

Fix result of Farbar Recovery Scan Tool (x64) Version: 11-10-2020
Ran by norst (13-10-2020 21:19:30) Run:2
Running from C:\Users\norst\OneDrive\Plocha
Loaded Profiles: norst
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
AlternateDataStreams: C:\Users\norst:Heroes & Generals [38]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [492]
C:\Users\norst\Downloads\uTorrent313.MPC-HC.exe
E:\Torrenty\RarLab.WinRAR.v5.11.Final.X86.X64.Incl.Keygen-FFF\KEYGEN-FFF.exe
C:\Users\norst\AppData\Roaming\uTorrent\utorrent.exe
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {9C109C0D-CC2C-4044-8CCE-090542F1316C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Task: {B4C2ECE5-F208-4D3A-A00A-FF970FDC3883} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll => No File
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll => No File
U3 aswbdisk; no ImagePath
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
C:\Users\norst => ":Heroes & Generals" ADS removed successfully
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully
"C:\Users\norst\Downloads\uTorrent313.MPC-HC.exe" => not found
"E:\Torrenty\RarLab.WinRAR.v5.11.Final.X86.X64.Incl.Keygen-FFF\KEYGEN-FFF.exe" => not found
C:\Users\norst\AppData\Roaming\uTorrent\utorrent.exe => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9C109C0D-CC2C-4044-8CCE-090542F1316C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C109C0D-CC2C-4044-8CCE-090542F1316C}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B4C2ECE5-F208-4D3A-A00A-FF970FDC3883}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4C2ECE5-F208-4D3A-A00A-FF970FDC3883}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008 => removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000008 => removed successfully
HKLM\System\CurrentControlSet\Services\aswbdisk => removed successfully
aswbdisk => service removed successfully
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 15441627 B
Java, Flash, Steam htmlcache => 389607174 B
Windows/system/drivers => 27939 B
Edge => 191488 B
Chrome => 371409333 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 56642 B
NetworkService => 59604 B
norst => 124527840 B

RecycleBin => 1487668457 B
EmptyTemp: => 2.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:19:42 ====
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Viry v PC

#8 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Viry v PC

#9 Příspěvek od Hanss1982 »

Kašperský už nehlásí nevyřešitelný problém, mockrát vám děkuji za obrovskou pomoc :-)
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Viry v PC

#10 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno