Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosím o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
hakub
Návštěvník
Návštěvník
Příspěvky: 204
Registrován: 05 úno 2008 05:27

prosím o kontrolu

#1 Příspěvek od hakub »

Logfile of random's system information tool 1.10 (written by random/random)
Run by v at 2020-12-19 09:03:33
Microsoft Windows 7 Ultimate
System drive D: has 4 GB (24%) free of 18 GB
Total RAM: 3519 MB (60% free)

HijackThis download failed

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG_CC"=D:\PROGRA~1\Grisoft\AVG6\avgcc32.exe [2000-01-10 126976]
"AvastUI.exe"=D:\Program Files\Avast Software\Avast\AvLaunch.exe [2020-12-19 104552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Smart Cleaning"=D:\Program Files\CCleaner\CCleaner.exe [2020-12-08 26896568]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=D:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - D:\Windows\System32\Notepad.exe %1
.js - open - D:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2020-12-19 09:03:33 ----D---- D:\rsit
2020-12-19 09:03:33 ----D---- D:\Program Files\trend micro
2020-12-19 08:37:16 ----A---- D:\Windows\system32\drivers\mbam.sys
2020-12-19 08:37:07 ----A---- D:\Windows\system32\drivers\farflt.sys
2020-12-19 08:37:03 ----A---- D:\Windows\system32\drivers\mwac.sys
2020-12-19 07:59:32 ----A---- D:\Windows\system32\drivers\MbamChameleon.sys
2020-12-19 07:59:30 ----A---- D:\Windows\system32\drivers\mbamswissarmy.sys
2020-12-19 07:59:23 ----A---- D:\Windows\system32\drivers\mbae.sys
2020-12-19 07:59:15 ----D---- D:\ProgramData\Malwarebytes
2020-12-19 07:58:32 ----D---- D:\Program Files\Malwarebytes
2020-12-19 07:28:29 ----D---- D:\Program Files\CCleaner
2020-12-19 06:57:04 ----D---- D:\ProgramData\BSD
2020-12-19 06:42:55 ----D---- D:\Users\v\AppData\Roaming\Avast Software
2020-12-19 06:39:33 ----A---- D:\Windows\system32\aswBoot.exe
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswVmm.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswStm.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswSP.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswSnx.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswRvrt.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswRdr2.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswNetNd6.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswNetHub.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswMonFlt.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswKbd.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswbuniv.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswbidsh.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswbidsdriver.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswArPot.sys
2020-12-19 06:25:33 ----A---- D:\Windows\system32\drivers\aswArDisk.sys
2020-12-19 06:25:29 ----D---- D:\Program Files\Common Files\Avast Software
2020-12-19 06:24:39 ----D---- D:\Program Files\Avast Software
2020-12-19 06:24:18 ----D---- D:\ProgramData\Avast Software
2020-12-19 06:21:02 ----SHD---- D:\Windows\Installer
2020-12-19 06:16:00 ----D---- D:\Program Files\Google
2020-12-19 06:14:33 ----A---- D:\Windows\system32\wups2.dll
2020-12-19 06:14:33 ----A---- D:\Windows\system32\wucltux.dll
2020-12-19 06:14:33 ----A---- D:\Windows\system32\wuaueng.dll
2020-12-19 06:14:33 ----A---- D:\Windows\system32\wuauclt.exe
2020-12-19 06:14:28 ----A---- D:\Windows\system32\wups.dll
2020-12-19 06:14:28 ----A---- D:\Windows\system32\wudriver.dll
2020-12-19 06:14:28 ----A---- D:\Windows\system32\wuapi.dll
2020-12-19 06:14:23 ----A---- D:\Windows\system32\wuwebv.dll
2020-12-19 06:14:23 ----A---- D:\Windows\system32\wuapp.exe
2020-12-18 09:48:14 ----D---- D:\Windows\Minidump
2020-12-18 09:44:22 ----A---- D:\Windows\system32\avgxch32.dll
2020-12-18 09:44:19 ----D---- D:\Program Files\Grisoft
2020-12-18 09:43:19 ----A---- D:\Windows\system32\PerfStringBackup.INI
2020-12-18 09:39:35 ----D---- D:\Users\v\AppData\Roaming\Identities
2020-12-18 09:39:22 ----SD---- D:\Users\v\AppData\Roaming\Microsoft
2020-12-18 09:39:22 ----D---- D:\Users\v\AppData\Roaming\Media Center Programs
2020-12-18 09:39:13 ----SHD---- D:\Recovery
2020-12-18 09:39:13 ----SHD---- D:\ProgramData\Šablony
2020-12-18 09:39:13 ----SHD---- D:\ProgramData\Plocha
2020-12-18 09:39:13 ----SHD---- D:\ProgramData\Oblíbené položky
2020-12-18 09:39:13 ----SHD---- D:\ProgramData\Nabídka Start
2020-12-18 09:39:13 ----SHD---- D:\ProgramData\Dokumenty
2020-12-18 09:39:13 ----SHD---- D:\ProgramData\Data aplikací
2020-12-18 09:28:38 ----D---- D:\Windows\SoftwareDistribution
2020-12-18 09:26:14 ----D---- D:\Windows\Prefetch
2020-12-18 09:25:57 ----ASH---- D:\pagefile.sys
2020-12-18 09:25:55 ----ASH---- D:\hiberfil.sys
2020-12-18 09:09:39 ----SHD---- D:\System Volume Information
2020-12-18 09:01:39 ----D---- D:\Windows\Panther

======List of files/folders modified in the last 1 month======

2020-12-19 09:03:33 ----RD---- D:\Program Files
2020-12-19 08:57:29 ----D---- D:\Windows\Temp
2020-12-19 08:42:07 ----D---- D:\Windows\system32\NDF
2020-12-19 08:41:04 ----D---- D:\Windows\System32
2020-12-19 08:41:04 ----D---- D:\Windows\inf
2020-12-19 08:37:17 ----D---- D:\Windows\system32\catroot
2020-12-19 08:37:16 ----D---- D:\Windows\system32\drivers
2020-12-19 08:36:34 ----D---- D:\Windows
2020-12-19 08:06:20 ----D---- D:\Windows\system32\config
2020-12-19 08:03:01 ----D---- D:\Windows\Tasks
2020-12-19 08:03:00 ----D---- D:\Windows\system32\Tasks
2020-12-19 07:59:15 ----HD---- D:\ProgramData
2020-12-19 07:30:04 ----D---- D:\Windows\debug
2020-12-19 07:23:19 ----A---- D:\Windows\win.ini
2020-12-19 06:41:41 ----D---- D:\Windows\winsxs
2020-12-19 06:41:21 ----D---- D:\Windows\system32\cs-CZ
2020-12-19 06:33:47 ----RSD---- D:\Windows\assembly
2020-12-19 06:33:47 ----D---- D:\Windows\Microsoft.NET
2020-12-19 06:25:51 ----D---- D:\Windows\system32\DriverStore
2020-12-19 06:25:29 ----D---- D:\Program Files\Common Files
2020-12-19 06:14:38 ----D---- D:\Windows\system32\catroot2
2020-12-19 06:14:14 ----D---- D:\Windows\system32\restore
2020-12-18 21:56:02 ----D---- D:\Windows\Logs
2020-12-18 10:13:45 ----SHD---- D:\$Recycle.Bin
2020-12-18 09:59:04 ----SD---- D:\ProgramData\Microsoft
2020-12-18 09:58:51 ----D---- D:\Windows\system32\drivers\UMDF
2020-12-18 09:58:04 ----D---- D:\Windows\system32\wdi
2020-12-18 09:43:08 ----D---- D:\Windows\system32\wbem
2020-12-18 09:41:06 ----D---- D:\Windows\system32\CodeIntegrity
2020-12-18 09:39:22 ----RD---- D:\Users
2020-12-18 09:39:13 ----D---- D:\Program Files\Windows NT
2020-12-18 09:39:03 ----D---- D:\Windows\rescache
2020-12-18 09:29:01 ----D---- D:\Windows\system32\sysprep
2020-12-18 09:26:31 ----D---- D:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswArDisk;aswArDisk; D:\Windows\system32\drivers\aswArDisk.sys [2020-12-19 34680]
R0 aswbidsh;aswbidsh; D:\Windows\system32\drivers\aswbidsh.sys [2020-12-19 204880]
R0 aswbuniv;aswbuniv; D:\Windows\system32\drivers\aswbuniv.sys [2020-12-19 90192]
R0 aswRvrt;aswRvrt; D:\Windows\system32\drivers\aswRvrt.sys [2020-12-19 72488]
R0 aswVmm;aswVmm; D:\Windows\system32\drivers\aswVmm.sys [2020-12-19 277096]
R0 pciide;pciide; D:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; D:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswArPot;aswArPot; D:\Windows\system32\drivers\aswArPot.sys [2020-12-19 176504]
R1 aswbidsdriver;aswbidsdriver; D:\Windows\system32\drivers\aswbidsdriver.sys [2020-12-19 284240]
R1 aswKbd;aswKbd; D:\Windows\system32\drivers\aswKbd.sys [2020-12-19 40376]
R1 aswMonFlt;aswMonFlt; D:\Windows\system32\drivers\aswMonFlt.sys [2020-12-19 148888]
R1 aswNetHub;aswNetHub; D:\Windows\system32\drivers\aswNetHub.sys [2020-12-19 377984]
R1 aswRdr;aswRdr; D:\Windows\system32\drivers\aswRdr2.sys [2020-12-19 93840]
R1 aswSnx;aswSnx; D:\Windows\system32\drivers\aswSnx.sys [2020-12-19 691280]
R1 aswSP;aswSP; D:\Windows\system32\drivers\aswSP.sys [2020-12-19 395176]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; D:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\D:\Windows\system32\drivers\mbae.sys [2020-12-19 129056]
R2 aswStm;aswStm; D:\Windows\system32\drivers\aswStm.sys [2020-12-19 162440]
R2 MBAMChameleon;MBAMChameleon; D:\Windows\System32\Drivers\MbamChameleon.sys [2020-12-19 183592]
R3 aswNetNd6;Avast Firewall NDIS6 Helper; D:\Windows\system32\DRIVERS\aswNetNd6.sys [2020-12-19 36104]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; D:\Windows\system32\DRIVERS\e1k6032.sys [2009-07-13 164864]
R3 igfx;igfx; D:\Windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
R3 MBAMFarflt;MBAMFarflt; D:\Windows\system32\DRIVERS\farflt.sys [2020-12-19 161440]
R3 MBAMProtection;MBAMProtection; \??\D:\Windows\system32\DRIVERS\mbam.sys [2020-12-19 66648]
R3 MBAMSwissArmy;MBAMSwissArmy; D:\Windows\System32\Drivers\mbamswissarmy.sys [2020-12-19 213912]
R3 MBAMWebProtection;MBAMWebProtection; D:\Windows\system32\DRIVERS\mwac.sys [2020-12-19 107632]
R3 TPM;Čip TPM; D:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
S2 Parvdm;Parvdm; D:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; D:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; D:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; D:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; D:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RTL8167;Ovladač Realtek 8167 NT; D:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 s3cap;s3cap; D:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; D:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; D:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; D:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; D:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; D:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; D:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\D:\Users\v\AppData\Local\Temp\tmp73CA.tmp []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; D:\Program Files\Avast Software\Avast\AvastSvc.exe [2020-12-19 563544]
R2 avast! Tools;Avast Tools; D:\Program Files\Avast Software\Avast\aswToolsSvc.exe [2020-12-19 330848]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; D:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MBAMService;Malwarebytes Service; D:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2020-12-19 5959136]
R3 aswbIDSAgent;aswbIDSAgent; D:\Program Files\Avast Software\Avast\aswidsagent.exe [2020-12-19 7569312]
S2 gupdate;Služba Aktualizace Google (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2020-12-19 155592]
S3 AppMgmt;@appmgmts.dll,-3250; D:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 GoogleChromeElevationService;Google Chrome Elevation Service (GoogleChromeElevationService); D:\Program Files\Google\Chrome\Application\87.0.4280.88\elevation_service.exe [2020-12-02 1140720]
S3 gupdatem;Služba Aktualizace Google (gupdatem); D:\Program Files\Google\Update\GoogleUpdate.exe [2020-12-19 155592]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; D:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; D:\Windows\System32\svchost.exe [2009-07-14 20992]

-----------------EOF-----------------

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: prosím o kontrolu

#2 Příspěvek od Diallix »

Dobry den.

:arrow: Stiahnite si na plochu nastroj AdwCleaner, link. na stiahnutie tu: https://toolslib.net/downloads/finish/1/
Pred spustenim nastroja povypinajte vsetke beziace okna programov, to su vsetke beziace programy pod desktopom.
Kliknite pravym tlacidlom mysi na program -> spustit ako Administrator.
Pokracujte kliknutim na tlacidlo Prehladaj teraz (Scan now) a pockajte, kym sa system doskenuje.
Po skene nechajte oznacene vsetky chlieviky, pripadne najdene hrozieby a pokracujte v dolnom pravom rohu tlacidlom Vycistit Teraz (Clean and Repair).
Po restartovani PC sa spusti nastroj AdwCleaner, kliknite na Zobrazit soubor protokolu.
Spusti sa log, jeho obsah skopirujte sem.
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

hakub
Návštěvník
Návštěvník
Příspěvky: 204
Registrován: 05 úno 2008 05:27

Re: prosím o kontrolu

#3 Příspěvek od hakub »

# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-11-23.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 12-19-2020
# Duration: 00:00:18
# OS: Windows 7 Ultimate
# Scanned: 31920
# Detected: 4


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Legacy D:\ProgramData\BSD\DriverHiveEngine
PUP.Optional.Legacy D:\Users\v\AppData\Local\DriverToolkit
PUP.Optional.TweakBit D:\ProgramData\BSD\DriverHive

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.DriverUpdatePlus HKLM\Software\BSD

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.



########## EOF - D:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: prosím o kontrolu

#4 Příspěvek od Diallix »

Preskenujte pocitac s FRST - navod tu: https://forum.viry.cz/viewtopic.php?f=24&t=132509, skopirujte FRST.log + Addition log sem.
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

hakub
Návštěvník
Návštěvník
Příspěvky: 204
Registrován: 05 úno 2008 05:27

Re: prosím o kontrolu

#5 Příspěvek od hakub »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-12-2020
Ran by v (administrator) on V-PC (Hewlett-Packard HP Compaq 8000 Elite SFF PC) (19-12-2020 19:04:05)
Running from D:\Users\v\Desktop
Loaded Profiles: v
Platform: Microsoft Windows 7 Ultimate (X86) Language: Čeština (Česká republika)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avast Software s.r.o. -> AVAST Software) D:\Program Files\Avast Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) D:\Program Files\Avast Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) D:\Program Files\Avast Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) D:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(AVG Technologies USA, LLC -> AVG Technologies) D:\Program Files\AVG\Browser\Application\AVGBrowser.exe <3>
(AVG Technologies USA, LLC -> AVG Technologies) D:\Program Files\AVG\Browser\Update\1.8.1066.0\AVGBrowserCrashHandler.exe
(Google LLC -> Google LLC) D:\Program Files\Google\Chrome\Application\chrome.exe <28>
(Google LLC -> Google LLC) D:\Program Files\Google\Update\1.3.36.52\GoogleCrashHandler.exe
(Microsoft Windows -> Microsoft Corporation) D:\Windows\System32\dllhost.exe <2>
(Piriform Software Ltd -> Piriform Software Ltd) D:\Program Files\CCleaner\CCleaner.exe <2>

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AVG_CC] => D:\Program Files\Grisoft\AVG6\avgcc32.exe [126976 2000-01-10] (Grisoft(c) Software) [File not signed]
HKLM\...\Run: [AvastUI.exe] => D:\Program Files\Avast Software\Avast\AvLaunch.exe [104552 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-1919702734-300340787-790247573-1000\...\Run: [CCleaner Smart Cleaning] => D:\Program Files\CCleaner\CCleaner.exe [26896568 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1919702734-300340787-790247573-1000\...\MountPoints2: {16552121-410a-11eb-924f-806e6f6e6963} - E:\autorun.exe
HKLM\Software\Microsoft\Active Setup\Installed Components: [{48F69C39-1356-4A7B-A899-70E3539D4982}] -> D:\Program Files\AVG\Browser\Application\86.1.6937.200\Installer\chrmstp.exe [2020-12-19] (AVG Technologies USA, LLC -> AVG Technologies)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> D:\Program Files\Google\Chrome\Application\87.0.4280.88\Installer\chrmstp.exe [2020-12-19] (Google LLC -> Google LLC)
SubSystems: [Windows] => "%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16" <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {09E66FDF-106F-406C-8881-CA1250534674} - System32\Tasks\Avast Emergency Update => D:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4052072 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
Task: {1C9E989C-D08D-45F5-8A61-60D50824E3C5} - System32\Tasks\{8BB5761E-1E37-45CB-B9F9-ECB52429EDF5} => D:\Windows\system32\pcalua.exe -a D:\PROGRA~1\Grisoft\AVG6\setup.exe -c /UNINSTALL
Task: {285D5337-AE3E-428B-941A-C49038364917} - System32\Tasks\GoogleUpdateTaskMachineUA => D:\Program Files\Google\Update\GoogleUpdate.exe [155592 2020-12-19] (Google LLC -> Google LLC)
Task: {3366AC3D-146C-4784-B13F-2966B1FBEE6A} - System32\Tasks\AVGUpdateTaskMachineCore => D:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-12-19] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {544E2946-BAE8-449F-B51A-C7A3DBECC7F5} - System32\Tasks\CCleanerSkipUAC => D:\Program Files\CCleaner\CCleaner.exe [26896568 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {87149195-F1FA-489B-9373-7FEA94EE2A5D} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => D:\Program Files\AVG\Browser\Application\AVGBrowser.exe [1929816 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {9031AE57-1C09-4F7B-A15B-C1719A997D8D} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => D:\Program Files\AVG\Browser\Application\AVGBrowser.exe [1929816 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {92C4B4DF-DBD4-42A7-A054-07D0472C1F71} - System32\Tasks\GoogleUpdateTaskMachineCore => D:\Program Files\Google\Update\GoogleUpdate.exe [155592 2020-12-19] (Google LLC -> Google LLC)
Task: {B279881F-33B5-4AC0-8ED6-C7AF878214E3} - System32\Tasks\CCleaner Update => D:\Program Files\CCleaner\CCUpdate.exe [686384 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {BBB3E72E-2D91-4018-8774-5CB74B942F0A} - System32\Tasks\Avast Software\Overseer => D:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1499240 2020-12-19] (Avast Software s.r.o. -> Avast Software)
Task: {E4431DE1-8EE2-414E-84C0-42FCFB476EDB} - System32\Tasks\AVGUpdateTaskMachineUA => D:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-12-19] (AVG Technologies USA, LLC -> AVG Technologies)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{4F1085B5-6FAF-44CE-902E-15D831E398F8}: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF Plugin: @update.avgbrowser.com/AVG Browser;version=3 -> D:\Program Files\AVG\Browser\Update\1.8.1066.0\npAvgBrowserUpdate3.dll [2020-12-19] (AVG Technologies USA, LLC -> AVG Technologies)
FF Plugin: @update.avgbrowser.com/AVG Browser;version=9 -> D:\Program Files\AVG\Browser\Update\1.8.1066.0\npAvgBrowserUpdate3.dll [2020-12-19] (AVG Technologies USA, LLC -> AVG Technologies)

Chrome:
=======
CHR Profile: D:\Users\v\AppData\Local\Google\Chrome\User Data\Default [2020-12-19]
CHR Notifications: Default -> hxxps://cs.soringpcrepair.com
CHR HomePage: Default -> hxxps://seznam.cz/
CHR StartupUrls: Default -> "chrome://newtab/"
CHR Extension: (Překladač Google) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2020-12-19]
CHR Extension: (Prezentace) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-12-19]
CHR Extension: (Dokumenty) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-12-19]
CHR Extension: (Disk Google) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-12-19]
CHR Extension: (YouTube) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-12-19]
CHR Extension: (Avast Passwords) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2020-12-19]
CHR Extension: (Tabulky) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-12-19]
CHR Extension: (Word Online) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2020-12-19]
CHR Extension: (Full Screen Weather) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2020-12-19]
CHR Extension: (YouTube Flash Video Player) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\fldkdmkgnlbehfgeifjpjabmandnchpe [2020-12-19]
CHR Extension: (Pass Strength Meter) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\gahnebecgllcaakcojhgndipnamdlghe [2020-12-19]
CHR Extension: (Dokumenty Google offline) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-12-19]
CHR Extension: (Uložit na Disk Google) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2020-12-19]
CHR Extension: (LastPass: Free Password Manager) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2020-12-19]
CHR Extension: (Malwarebytes Browser Guard) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2020-12-19]
CHR Extension: (Speed Dial 2 New tab) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik [2020-12-19]
CHR Extension: (Netpanel) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbidbgoheiddfilfipcobicemncfogno [2020-12-19]
CHR Extension: (Webcam Toy) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2020-12-19]
CHR Extension: (Lightshot (Nástroje snímků)) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbniclmhobmnbdlbpiphghaielnnpgdp [2020-12-19]
CHR Extension: (Platby Internetového obchodu Chrome) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-12-19]
CHR Extension: (Gmail) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-12-19]
CHR Extension: (Chrome Media Router) - D:\Users\v\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-19]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; D:\Program Files\Avast Software\Avast\aswidsagent.exe [7569312 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; D:\Program Files\Avast Software\Avast\AvastSvc.exe [563544 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
S4 avast! Tools; D:\Program Files\Avast Software\Avast\aswToolsSvc.exe [330848 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
S2 avg; D:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-12-19] (AVG Technologies USA, LLC -> AVG Technologies)
S3 avgm; D:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-12-19] (AVG Technologies USA, LLC -> AVG Technologies)
S3 AVGSecureBrowserElevationService; D:\Program Files\AVG\Browser\Application\86.1.6937.200\elevation_service.exe [1136952 2020-11-12] (AVG Technologies USA, LLC -> AVG Technologies)
R2 WinDefend; D:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Windows -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 aswArDisk; D:\Windows\System32\drivers\aswArDisk.sys [34680 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; D:\Windows\System32\drivers\aswArPot.sys [176504 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; D:\Windows\System32\drivers\aswbidsdriver.sys [284240 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; D:\Windows\System32\drivers\aswbidsh.sys [204880 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; D:\Windows\System32\drivers\aswbuniv.sys [90192 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R1 aswKbd; D:\Windows\System32\drivers\aswKbd.sys [40376 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R1 aswMonFlt; D:\Windows\System32\drivers\aswMonFlt.sys [148888 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; D:\Windows\System32\drivers\aswNetHub.sys [377984 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R3 aswNetNd6; D:\Windows\System32\DRIVERS\aswNetNd6.sys [36104 2020-12-19] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; D:\Windows\System32\drivers\aswRdr2.sys [93840 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; D:\Windows\System32\drivers\aswRvrt.sys [72488 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; D:\Windows\System32\drivers\aswSnx.sys [691280 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; D:\Windows\System32\drivers\aswSP.sys [395176 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
S2 aswStm; D:\Windows\System32\drivers\aswStm.sys [162440 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; D:\Windows\System32\drivers\aswVmm.sys [277096 2020-12-19] (Avast Software s.r.o. -> AVAST Software)
R3 e1kexpress; D:\Windows\System32\DRIVERS\e1k6032.sys [164864 2009-07-13] (Microsoft Windows -> Intel Corporation)
S3 RTL8167; D:\Windows\System32\DRIVERS\Rt86win7.sys [139776 2009-07-13] (Microsoft Windows -> Realtek Corporation)
U1 avgbdisk; no ImagePath
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
S3 WinRing0_1_2_0; \??\D:\Users\v\AppData\Local\Temp\tmp73CA.tmp [X] <==== ATTENTION

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-12-19 19:04 - 2020-12-19 19:04 - 000013931 _____ D:\Users\v\Desktop\FRST.txt
2020-12-19 19:03 - 2020-12-19 19:03 - 002000384 _____ (Farbar) D:\Users\v\Desktop\FRST.exe
2020-12-19 18:57 - 2020-12-19 18:57 - 000000000 ___HD D:\$AV_ASW
2020-12-19 18:54 - 2020-12-19 19:04 - 000000000 ____D D:\FRST
2020-12-19 18:49 - 2020-12-19 18:49 - 001971865 _____ (Farbar) D:\Users\v\Nepotvrzeno 342037.crdownload
2020-12-19 18:46 - 2020-12-19 18:46 - 002000384 _____ D:\Users\v\FRST (1).exe
2020-12-19 18:39 - 2020-12-19 18:39 - 002000384 _____ (Farbar) D:\Users\v\FRST.exe
2020-12-19 18:30 - 2020-12-19 18:30 - 000000000 ___HD D:\$AV_AVG
2020-12-19 17:09 - 2020-12-19 17:10 - 000000000 ____D D:\AdwCleaner
2020-12-19 17:08 - 2020-12-19 17:08 - 008447152 _____ (Malwarebytes) D:\Users\v\Desktop\adwcleaner_8.0.8.exe
2020-12-19 15:53 - 2020-12-19 17:03 - 000000000 ____D D:\Users\v\AppData\Local\FSDART
2020-12-19 15:53 - 2020-12-19 15:55 - 000000000 ____D D:\ProgramData\F-Secure
2020-12-19 15:53 - 2020-12-19 15:53 - 000000000 ____D D:\Users\v\AppData\Local\F-Secure
2020-12-19 15:23 - 2020-12-19 15:23 - 000000000 __SHD D:\found.000
2020-12-19 15:13 - 2020-12-19 15:13 - 000003694 _____ D:\Windows\system32\Tasks\AVG Secure Browser Heartbeat Task (Hourly)
2020-12-19 15:13 - 2020-12-19 15:13 - 000003112 _____ D:\Windows\system32\Tasks\AVG Secure Browser Heartbeat Task (Logon)
2020-12-19 15:13 - 2020-12-19 15:13 - 000002324 _____ D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Secure Browser.lnk
2020-12-19 15:13 - 2020-12-19 15:13 - 000002281 _____ D:\Users\Public\Desktop\AVG Secure Browser.lnk
2020-12-19 15:13 - 2020-12-19 15:13 - 000002281 _____ D:\ProgramData\Desktop\AVG Secure Browser.lnk
2020-12-19 15:13 - 2020-12-19 15:13 - 000000000 ____D D:\Users\v\AppData\Local\AVG
2020-12-19 15:10 - 2020-12-19 15:10 - 000003376 _____ D:\Windows\system32\Tasks\AVGUpdateTaskMachineUA
2020-12-19 15:10 - 2020-12-19 15:10 - 000003248 _____ D:\Windows\system32\Tasks\AVGUpdateTaskMachineCore
2020-12-19 15:04 - 2020-12-19 15:04 - 000000000 ____D D:\Users\v\AppData\Roaming\AVG
2020-12-19 14:56 - 2020-12-19 14:56 - 000000000 ____D D:\Program Files\Common Files\AVG
2020-12-19 14:56 - 2020-12-19 14:55 - 000395312 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw869088bd17381e5f.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000378120 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\aswcdf3b3d93d217980.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000287368 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\avgBoot.exe
2020-12-19 14:56 - 2020-12-19 14:55 - 000277232 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\aswc1e26540f0879ac3.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000204944 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw2b80343a23826855.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000176648 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\aswa11c18b7df865cae.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000162576 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw9655f0153fcf1ab4.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000149032 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw35890c2055ccb89b.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000093976 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw3a3b2f5a87eee7b1.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000090256 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\aswc429fb4d3f5656e7.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000072624 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw0c90833d623840d8.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000040520 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\aswe3dde058ef929c07.tmp
2020-12-19 14:56 - 2020-12-19 14:55 - 000034824 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw4078405d580a9d90.tmp
2020-12-19 14:56 - 2020-12-19 14:54 - 000691416 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\aswd68e977e1cc74ac0.tmp
2020-12-19 14:56 - 2020-12-19 14:54 - 000284304 _____ (AVG Technologies CZ, s.r.o.) D:\Windows\system32\Drivers\asw2b54a2ef8fc457a1.tmp
2020-12-19 14:53 - 2020-12-19 15:09 - 000000000 ____D D:\Program Files\AVG
2020-12-19 14:52 - 2020-12-19 19:00 - 000000000 ____D D:\ProgramData\AVG
2020-12-19 14:51 - 2020-12-19 14:51 - 000259728 _____ (AVG Technologies CZ, s.r.o.) D:\Users\v\Downloads\avg_antivirus_free_setup.exe
2020-12-19 14:15 - 2020-12-19 14:23 - 000000000 ___HD D:\kleaner.tmp
2020-12-19 14:10 - 2020-12-19 14:11 - 000000000 ____D D:\ProgramData\Kaspersky Lab Setup Files
2020-12-19 14:10 - 2020-12-19 14:10 - 002550496 _____ (Kaspersky Lab) D:\Users\v\Downloads\kfa19.0.0.1088abcs_15064.exe
2020-12-19 13:51 - 2020-12-19 17:31 - 000000000 ____D D:\Users\v\AppData\Local\CrashDumps
2020-12-19 13:48 - 2020-12-19 13:48 - 000158608 _____ D:\Users\v\Desktop\setup.exe
2020-12-19 13:36 - 2020-12-19 13:37 - 000000000 ____D D:\Windows\pss
2020-12-19 09:43 - 2020-12-19 09:43 - 000007120 ____N D:\bootsqm.dat
2020-12-19 09:16 - 2020-12-19 09:16 - 000000000 ___SD D:\Users\v\AppData\LocalLow\Temp
2020-12-19 09:11 - 2020-12-19 09:14 - 000000000 ____D D:\Windows\SoftwareDistribution.old
2020-12-19 09:10 - 2020-12-19 09:10 - 001337944 _____ (NoVirusThanks Company Srl ) D:\Users\v\Desktop\win_update_fixer_setup.exe
2020-12-19 09:03 - 2020-12-19 09:03 - 001107968 _____ D:\Users\v\Downloads\RSIT.exe
2020-12-19 09:03 - 2020-12-19 09:03 - 000000000 ____D D:\rsit
2020-12-19 09:03 - 2020-12-19 09:03 - 000000000 ____D D:\Program Files\trend micro
2020-12-19 08:15 - 2020-12-19 08:15 - 004839424 _____ D:\Users\v\Downloads\avg6116cz.exe
2020-12-19 08:13 - 2020-12-19 08:13 - 000158608 _____ D:\Users\v\Downloads\setup.exe
2020-12-19 07:59 - 2020-12-19 07:59 - 000000000 ____D D:\Users\v\AppData\Local\mbam
2020-12-19 07:59 - 2020-12-19 07:59 - 000000000 ____D D:\ProgramData\Malwarebytes
2020-12-19 07:28 - 2020-12-19 18:59 - 000000000 ____D D:\Program Files\CCleaner
2020-12-19 07:28 - 2020-12-19 13:44 - 000004128 _____ D:\Windows\system32\Tasks\CCleaner Update
2020-12-19 07:28 - 2020-12-19 07:28 - 030312056 _____ (Piriform Software Ltd) D:\Users\v\Downloads\cctrialsetup.exe
2020-12-19 07:28 - 2020-12-19 07:28 - 000002792 _____ D:\Windows\system32\Tasks\CCleanerSkipUAC
2020-12-19 07:28 - 2020-12-19 07:28 - 000000965 _____ D:\Users\Public\Desktop\CCleaner.lnk
2020-12-19 07:28 - 2020-12-19 07:28 - 000000965 _____ D:\ProgramData\Desktop\CCleaner.lnk
2020-12-19 07:28 - 2020-12-19 07:28 - 000000000 ____D D:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2020-12-19 07:25 - 2020-12-19 07:25 - 000003074 _____ D:\Windows\system32\Tasks\{8BB5761E-1E37-45CB-B9F9-ECB52429EDF5}
2020-12-19 06:57 - 2020-12-19 17:10 - 000000000 ____D D:\ProgramData\BSD
2020-12-19 06:55 - 2020-12-19 06:55 - 014668368 _____ (Outbyte) D:\Users\v\Downloads\driver-updater-setup.exe
2020-12-19 06:42 - 2020-12-19 06:42 - 000002075 _____ D:\Users\Public\Desktop\Avast Free Antivirus.lnk
2020-12-19 06:42 - 2020-12-19 06:42 - 000002075 _____ D:\ProgramData\Desktop\Avast Free Antivirus.lnk
2020-12-19 06:42 - 2020-12-19 06:42 - 000000000 ____D D:\Users\v\AppData\Roaming\Avast Software
2020-12-19 06:42 - 2020-12-19 06:42 - 000000000 ____D D:\Users\v\AppData\Local\CEF
2020-12-19 06:42 - 2020-12-19 06:42 - 000000000 ____D D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2020-12-19 06:39 - 2020-12-19 06:25 - 000286816 _____ (AVAST Software) D:\Windows\system32\aswBoot.exe
2020-12-19 06:25 - 2020-12-19 14:36 - 000004168 _____ D:\Windows\system32\Tasks\Avast Emergency Update
2020-12-19 06:25 - 2020-12-19 06:25 - 000691280 _____ (AVAST Software) D:\Windows\system32\Drivers\aswSnx.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000395176 _____ (AVAST Software) D:\Windows\system32\Drivers\aswSP.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000377984 _____ (AVAST Software) D:\Windows\system32\Drivers\aswNetHub.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000284240 _____ (AVAST Software) D:\Windows\system32\Drivers\aswbidsdriver.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000277096 _____ (AVAST Software) D:\Windows\system32\Drivers\aswVmm.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000204880 _____ (AVAST Software) D:\Windows\system32\Drivers\aswbidsh.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000176504 _____ (AVAST Software) D:\Windows\system32\Drivers\aswArPot.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000162440 _____ (AVAST Software) D:\Windows\system32\Drivers\aswStm.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000148888 _____ (AVAST Software) D:\Windows\system32\Drivers\aswMonFlt.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000093840 _____ (AVAST Software) D:\Windows\system32\Drivers\aswRdr2.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000090192 _____ (AVAST Software) D:\Windows\system32\Drivers\aswbuniv.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000072488 _____ (AVAST Software) D:\Windows\system32\Drivers\aswRvrt.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000040376 _____ (AVAST Software) D:\Windows\system32\Drivers\aswKbd.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000036104 _____ (AVAST Software) D:\Windows\system32\Drivers\aswNetNd6.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000034680 _____ (AVAST Software) D:\Windows\system32\Drivers\aswArDisk.sys
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____D D:\Windows\system32\Tasks\Avast Software
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____D D:\Program Files\Common Files\Avast Software
2020-12-19 06:24 - 2020-12-19 18:13 - 000000000 ____D D:\ProgramData\Avast Software
2020-12-19 06:24 - 2020-12-19 06:24 - 000000000 ____D D:\Program Files\Avast Software
2020-12-19 06:23 - 2020-12-19 06:23 - 000220784 _____ (AVAST Software) D:\Users\v\Downloads\avast_free_antivirus_setup_online.exe
2020-12-19 06:17 - 2020-12-19 06:17 - 000002242 _____ D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-12-19 06:17 - 2020-12-19 06:17 - 000002201 _____ D:\Users\Public\Desktop\Google Chrome.lnk
2020-12-19 06:17 - 2020-12-19 06:17 - 000002201 _____ D:\ProgramData\Desktop\Google Chrome.lnk
2020-12-19 06:16 - 2020-12-19 06:17 - 000000000 ____D D:\Program Files\Google
2020-12-19 06:16 - 2020-12-19 06:16 - 000003374 _____ D:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-12-19 06:16 - 2020-12-19 06:16 - 000003246 _____ D:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-12-19 06:15 - 2020-12-19 06:19 - 000000000 ____D D:\Users\v\AppData\Local\Google
2020-12-18 10:05 - 2020-12-18 10:05 - 000000987 _____ D:\Users\v\Desktop\AVG 6.0.lnk
2020-12-18 10:05 - 2020-12-18 10:05 - 000000000 ____D D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirový systém AVG 6.0
2020-12-18 09:59 - 2020-12-18 09:59 - 000000000 ____H D:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2020-12-18 09:48 - 2020-12-19 07:30 - 000000000 ____D D:\Windows\Minidump
2020-12-18 09:44 - 2020-12-18 09:44 - 000000000 ____D D:\Program Files\Grisoft
2020-12-18 09:44 - 2000-01-10 06:00 - 000077824 _____ (GRISOFT(c) SOFTWARE) D:\Windows\system32\avgxch32.dll
2020-12-18 09:43 - 2020-12-19 17:20 - 001582262 _____ D:\Windows\system32\PerfStringBackup.INI
2020-12-18 09:43 - 2020-12-18 09:43 - 000057560 _____ D:\Users\v\AppData\Local\GDIPFONTCACHEV1.DAT
2020-12-18 09:39 - 2020-12-19 18:49 - 000000000 ____D D:\Users\v
2020-12-18 09:39 - 2020-12-18 09:39 - 000000020 ___SH D:\Users\v\ntuser.ini
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Šablony
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Soubory cookie
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Poslední
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Okolní tiskárny
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Okolní síť
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Nabídka Start
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Dokumenty
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Documents\Obrázky
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Documents\Hudba
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Documents\Filmy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\Data aplikací
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\v\AppData\Local\Data aplikací
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Public\Documents\Obrázky
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Public\Documents\Hudba
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Public\Documents\Filmy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Šablony
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Soubory cookie
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Poslední
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Okolní tiskárny
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Okolní síť
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Nabídka Start
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Dokumenty
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Documents\Obrázky
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Documents\Hudba
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Documents\Filmy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\Data aplikací
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default\AppData\Local\Data aplikací
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Šablony
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Soubory cookie
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Poslední
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Okolní tiskárny
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Okolní síť
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Nabídka Start
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Dokumenty
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Documents\Obrázky
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Documents\Hudba
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Documents\Filmy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\Data aplikací
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\Users\Default User\AppData\Local\Data aplikací
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Šablony
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Plocha
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Oblíbené položky
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Nabídka Start
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Microsoft\Windows\Start Menu\Programy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Dokumenty
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Documents\Obrázky
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Documents\Hudba
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Documents\Filmy
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 _SHDL D:\ProgramData\Data aplikací
2020-12-18 09:39 - 2020-12-18 09:39 - 000000000 ____D D:\Users\v\AppData\Local\VirtualStore
2020-12-18 09:39 - 2009-07-14 10:20 - 000000000 ____D D:\Users\v\AppData\Roaming\Media Center Programs
2020-12-18 09:29 - 2020-12-18 09:29 - 000001345 _____ D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2020-12-18 09:29 - 2020-12-18 09:29 - 000001326 _____ D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2020-12-18 09:01 - 2020-12-19 17:03 - 000000000 ____D D:\Windows\Panther

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-12-19 17:51 - 2009-07-14 03:37 - 000000000 ____D D:\Windows\system32\NDF
2020-12-19 17:48 - 2009-07-14 05:53 - 000000006 ____H D:\Windows\Tasks\SA.DAT
2020-12-19 17:48 - 2009-07-14 05:34 - 000009584 ____H D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-12-19 17:48 - 2009-07-14 05:34 - 000009584 ____H D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-12-19 17:29 - 2009-07-14 03:37 - 000000000 ____D D:\Windows\inf
2020-12-19 17:20 - 2009-07-14 09:44 - 000668138 _____ D:\Windows\system32\perfh005.dat
2020-12-19 17:20 - 2009-07-14 09:44 - 000140798 _____ D:\Windows\system32\perfc005.dat
2020-12-19 07:23 - 2009-07-14 03:04 - 000000466 _____ D:\Windows\win.ini
2020-12-18 20:11 - 2009-07-14 05:34 - 000012288 _____ D:\Windows\system32\umstartup.etl
2020-12-18 09:39 - 2009-07-14 03:37 - 000000000 ____D D:\Windows\rescache
2020-12-18 09:39 - 2009-07-14 03:37 - 000000000 ____D D:\Program Files\Windows NT
2020-12-18 09:29 - 2009-07-14 05:52 - 000000000 ___RD D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2020-12-18 09:29 - 2009-07-14 03:37 - 000000000 ____D D:\Windows\system32\sysprep
2020-12-18 09:26 - 2009-07-14 10:20 - 000000000 ____D D:\Windows\CSC
2020-12-18 09:26 - 2009-07-14 05:33 - 000265880 _____ D:\Windows\system32\FNTCACHE.DAT
2020-12-18 09:01 - 2009-07-14 05:52 - 000028672 _____ D:\Windows\system32\config\BCD-Template

==================== Files in the root of some directories ========

2020-12-19 18:46 - 2020-12-19 18:46 - 002000384 _____ () D:\Users\v\FRST (1).exe
2020-12-19 18:39 - 2020-12-19 18:39 - 002000384 _____ (Farbar) D:\Users\v\FRST.exe

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2020-12-19 11:16
==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-12-2020
Ran by v (19-12-2020 19:04:57)
Running from D:\Users\v\Desktop
Microsoft Windows 7 Ultimate (X86) (2020-12-18 08:39:17)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1919702734-300340787-790247573-500 - Administrator - Disabled)
Guest (S-1-5-21-1919702734-300340787-790247573-501 - Limited - Disabled)
v (S-1-5-21-1919702734-300340787-790247573-1000 - Administrator - Enabled) => D:\Users\v

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 20.10.2442 - Avast Software)
AVG Secure Browser (HKLM\...\AVG Secure Browser) (Version: 86.1.6937.200 - AVG Technologies)
AVG Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1066.0 - AVG Technologies) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.75 - Piriform)
Google Chrome (HKLM\...\Google Chrome) (Version: 87.0.4280.88 - Google LLC)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.51 - Google LLC) Hidden
Microsoft .NET Framework 4.5.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\Program Files\Avast Software\Avast\ashShell.dll [2020-12-19] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\Program Files\Avast Software\Avast\ashShell.dll [2020-12-19] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [AVG Shell Extension] -> {1E2CDF40-419B-11D2-A5A1-002018648BA7} => D:\Program Files\Grisoft\AVG6\avgse.dll [2000-01-10] (GRISOFT(c)SOFTWARE s.r.o.) [File not signed]
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\Program Files\Avast Software\Avast\ashShell.dll [2020-12-19] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\Program Files\Avast Software\Avast\ashShell.dll [2020-12-19] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [AVG Shell Extension] -> {1E2CDF40-419B-11D2-A5A1-002018648BA7} => D:\Program Files\Grisoft\AVG6\avgse.dll [2000-01-10] (GRISOFT(c)SOFTWARE s.r.o.) [File not signed]

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2020-12-18 09:44 - 2000-01-10 06:00 - 000045056 _____ (GRISOFT(c)SOFTWARE s.r.o.) [File not signed] D:\Program Files\Grisoft\AVG6\avgse.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011208 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-core-file-l1-2-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011208 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-core-file-l2-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000013768 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-core-localization-l1-2-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011720 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-core-processthreads-l1-1-1.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011920 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-core-synch-l1-2-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011712 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-core-timezone-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000015304 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-convert-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011720 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-environment-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000013248 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-filesystem-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000012232 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-heap-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011712 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-locale-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000021960 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-math-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000019400 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-multibyte-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000015816 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-runtime-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000017352 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-stdio-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000018072 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-string-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000013768 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-time-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000011712 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\api-ms-win-crt-utility-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000454128 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\MSVCP140.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 001170880 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\ucrtbase.DLL
2020-12-19 06:25 - 2020-12-19 06:25 - 000083952 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\avast.local_vc142.crt\VCRUNTIME140.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 005081072 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\Avast Software\Avast\mfc140u.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011208 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-core-file-l1-2-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011208 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-core-file-l2-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000013768 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-core-localization-l1-2-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011720 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-core-processthreads-l1-1-1.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011920 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-core-synch-l1-2-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011712 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-core-timezone-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000015304 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-convert-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011720 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-environment-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000013248 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-filesystem-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000012232 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-heap-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011712 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-locale-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000021960 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-math-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000015816 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-runtime-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000017352 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-stdio-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000018072 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-string-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000013768 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-time-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000011712 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\api-ms-win-crt-utility-l1-1-0.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000454128 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\msvcp140.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 001170880 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\ucrtbase.dll
2020-12-19 14:54 - 2020-12-19 14:54 - 000083952 _____ (Microsoft Corporation -> Microsoft Corporation) [File not signed] D:\Program Files\AVG\Antivirus\avg.local_vc142.crt\VCRUNTIME140.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-core-file-l1-2-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-core-file-l2-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-core-localization-l1-2-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-core-processthreads-l1-1-1.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-core-synch-l1-2-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-core-timezone-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-crt-convert-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-crt-heap-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-crt-runtime-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-crt-stdio-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\api-ms-win-crt-string-l1-1-0.dll
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\ucrtbase.DLL
2020-12-19 06:25 - 2020-12-19 06:25 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\1029\avast.local_vc142.crt\VCRUNTIME140.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-core-file-l1-2-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-core-file-l2-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-core-localization-l1-2-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-core-processthreads-l1-1-1.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-core-synch-l1-2-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-core-timezone-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-convert-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-environment-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-filesystem-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-heap-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-locale-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-math-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-multibyte-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-runtime-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-stdio-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-string-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-time-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\api-ms-win-crt-utility-l1-1-0.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\MSVCP140.dll
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\ucrtbase.DLL
2020-12-19 17:39 - 2020-12-19 17:39 - 000000000 ____L (Microsoft Corporation) D:\Program Files\Avast Software\Avast\defs\20121906\avast.local_vc142.crt\VCRUNTIME140.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Version 8) (Whitelisted) ==========

HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-1919702734-300340787-790247573-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxps://www.msn.com/cs-cz/?ocid=iehp

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2009-06-10 22:39 - 000000824 _____ D:\Windows\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1919702734-300340787-790247573-1000\Control Panel\Desktop\\Wallpaper -> D:\Users\v\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: avast! Tools => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: MBAMService => 2
MSCONFIG\startupreg: CCleaner Smart Cleaning => "D:\Program Files\CCleaner\CCleaner.exe" /MONITOR

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{7B38B11C-8331-455B-A5EE-51B1A4FB6750}] => (Allow) D:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{748DA55C-73D0-4AB5-B2EF-45B027D69D44}] => (Allow) D:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D2BB8BDA-68E9-4830-B8B8-EEBA2C29FC96}] => (Allow) D:\Program Files\AVG\Browser\Application\AVGBrowser.exe (AVG Technologies USA, LLC -> AVG Technologies)

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============

Name: Standardní klávesnice PS/2
Description: Standardní klávesnice PS/2
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardní klávesnice)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Řadič jednoduché komunikace pro sběrnici PCI
Description: Řadič jednoduché komunikace pro sběrnici PCI
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Sériový port sběrnice PCI
Description: Sériový port sběrnice PCI
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (12/19/2020 06:30:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.

Error: (12/19/2020 06:30:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.

Error: (12/19/2020 06:26:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.

Error: (12/19/2020 06:26:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.

Error: (12/19/2020 06:26:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.

Error: (12/19/2020 06:26:06 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.

Error: (12/19/2020 06:25:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.

Error: (12/19/2020 06:25:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Certifikační řetěz byl zpracován, ale byl ukončen v kořenovém certifikátu, který nemá důvěru zprostředkovatele důvěryhodnosti.
.


System errors:
=============
Error: (12/19/2020 06:43:31 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (12/19/2020 06:43:31 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (12/19/2020 06:43:30 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (12/19/2020 06:43:30 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (12/19/2020 05:49:02 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
avgNetHub

Error: (12/19/2020 05:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba MBAMChameleon neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (12/19/2020 05:48:05 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku D: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (12/19/2020 05:42:14 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba avgbIDSAgent byla nečekaně ukončena. Stalo se to 3 krát. Následující opravná akce bude spuštěna za 5000 milisekund: Restartovat službu.


CodeIntegrity:
===================================

Date: 2020-12-19 07:22:58.315
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-12-19 07:22:58.315
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-12-19 06:46:53.033
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-12-19 06:46:53.030
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-12-19 06:43:34.601
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because the set of per-page image hashes could not be found on the system.

Date: 2020-12-19 06:43:34.582
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because the set of per-page image hashes could not be found on the system.

Date: 2020-12-19 06:08:03.365
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-12-19 06:08:03.365
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Outbyte\PC Repair\DrvMonX86.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

BIOS: Hewlett-Packard 786G7 v01.02 10/22/2009
Motherboard: Hewlett-Packard 3646h
Processor: Intel(R) Core(TM)2 Quad CPU Q8300 @ 2.50GHz
Percentage of memory in use: 85%
Total physical RAM: 3519.25 MB
Available physical RAM: 501.41 MB
Total Virtual: 7036.77 MB
Available Virtual: 3081.38 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:446.99 GB) (Free:426.39 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:17.68 GB) (Free:1.83 GB) NTFS
Drive f: (USB VIN7) (Removable) (Total:7.46 GB) (Free:0.4 GB) FAT32


==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 6083130B)
Partition 1: (Not Active) - (Size=17.7 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=447 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (Protective MBR) (Size: 7.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: prosím o kontrolu

#6 Příspěvek od Diallix »

Do poznamkoveho bloku skopirujte obsah dole:

Kód: Vybrat vše

CloseProcesses:
CreateRestorePoint:

HKU\S-1-5-21-1919702734-300340787-790247573-1000\...\MountPoints2: {16552121-410a-11eb-924f-806e6f6e6963} - E:\autorun.exe
ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16" <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {1C9E989C-D08D-45F5-8A61-60D50824E3C5} - System32\Tasks\{8BB5761E-1E37-45CB-B9F9-ECB52429EDF5} => D:\Windows\system32\pcalua.exe -a D:\PROGRA~1\Grisoft\AVG6\setup.exe -c /UNINSTALL
Task: {285D5337-AE3E-428B-941A-C49038364917} - System32\Tasks\GoogleUpdateTaskMachineUA => D:\Program Files\Google\Update\GoogleUpdate.exe [155592 2020-12-19] (Google LLC -> Google LLC)
Task: {92C4B4DF-DBD4-42A7-A054-07D0472C1F71} - System32\Tasks\GoogleUpdateTaskMachineCore => D:\Program Files\Google\Update\GoogleUpdate.exe [155592 2020-12-19] (Google LLC -> Google LLC)
U1 avgbdisk; no ImagePath
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
S3 WinRing0_1_2_0; \??\D:\Users\v\AppData\Local\Temp\tmp73CA.tmp [X] <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-1919702734-300340787-790247573-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxps://www.msn.com/cs-cz/?ocid=iehp

EmptyTemp:
Poznamkovy blok ulozte pod nazvom fixlist.txt do umiestnenia kde je FRST.
Spustite FRST a odkliknite tlacidlo: Fix
Vykona sa funkcionalita po ktorej sa pocitac rebootuje. Po reboote sem vlozte obsah logu: fixlog.txt ulozeneho v umiestneni FRST.
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

hakub
Návštěvník
Návštěvník
Příspěvky: 204
Registrován: 05 úno 2008 05:27

Re: prosím o kontrolu

#7 Příspěvek od hakub »

Fix result of Farbar Recovery Scan Tool (x86) Version: 14-12-2020
Ran by v (20-12-2020 16:45:03) Run:1
Running from D:\Users\v\Desktop
Loaded Profiles: v
Boot Mode: Normal

==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:

HKU\S-1-5-21-1919702734-300340787-790247573-1000\...\MountPoints2: {16552121-410a-11eb-924f-806e6f6e6963} - E:\autorun.exe
ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16" <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {1C9E989C-D08D-45F5-8A61-60D50824E3C5} - System32\Tasks\{8BB5761E-1E37-45CB-B9F9-ECB52429EDF5} => D:\Windows\system32\pcalua.exe -a D:\PROGRA~1\Grisoft\AVG6\setup.exe -c /UNINSTALL
Task: {285D5337-AE3E-428B-941A-C49038364917} - System32\Tasks\GoogleUpdateTaskMachineUA => D:\Program Files\Google\Update\GoogleUpdate.exe [155592 2020-12-19] (Google LLC -> Google LLC)
Task: {92C4B4DF-DBD4-42A7-A054-07D0472C1F71} - System32\Tasks\GoogleUpdateTaskMachineCore => D:\Program Files\Google\Update\GoogleUpdate.exe [155592 2020-12-19] (Google LLC -> Google LLC)
U1 avgbdisk; no ImagePath
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
S3 WinRing0_1_2_0; \??\D:\Users\v\AppData\Local\Temp\tmp73CA.tmp [X] <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-1919702734-300340787-790247573-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxps://www.msn.com/cs-cz/?ocid=iehp

EmptyTemp:
*****************

Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-1919702734-300340787-790247573-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{16552121-410a-11eb-924f-806e6f6e6963} => removed successfully.
ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16" <==== ATTENTION => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Policies\Mozilla => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1C9E989C-D08D-45F5-8A61-60D50824E3C5}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1C9E989C-D08D-45F5-8A61-60D50824E3C5}" => removed successfully.
D:\Windows\System32\Tasks\{8BB5761E-1E37-45CB-B9F9-ECB52429EDF5} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8BB5761E-1E37-45CB-B9F9-ECB52429EDF5}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{285D5337-AE3E-428B-941A-C49038364917}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{285D5337-AE3E-428B-941A-C49038364917}" => removed successfully.
D:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{92C4B4DF-DBD4-42A7-A054-07D0472C1F71}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92C4B4DF-DBD4-42A7-A054-07D0472C1F71}" => removed successfully.
D:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully.
HKLM\System\CurrentControlSet\Services\avgbdisk => removed successfully.
avgbdisk => service removed successfully.
HKLM\System\CurrentControlSet\Services\MBAMChameleon => removed successfully.
MBAMChameleon => service removed successfully.
HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0 => removed successfully.
WinRing0_1_2_0 => service removed successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Local Page"="D:\Windows\System32\blank.htm" => value restored successfully
"HKU\S-1-5-21-1919702734-300340787-790247573-1000\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache" => removed successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 2456850 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 2452917 B
Edge => 0 B
Chrome => 75546151 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 149793 B
LocalService => 216021 B
NetworkService => 216021 B
v => 613801234 B

RecycleBin => 0 B
EmptyTemp: => 670.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 16:45:25 ====

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: prosím o kontrolu

#8 Příspěvek od Diallix »

Ok, ako je na to pocitac.

Pozn. vidim ze mate Avast, zatial vypnuty a Windows Defender zapnuty. V pc ma bezat len jeden rezidentny stit.
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

hakub
Návštěvník
Návštěvník
Příspěvky: 204
Registrován: 05 úno 2008 05:27

Re: prosím o kontrolu

#9 Příspěvek od hakub »

avast jsem musel dočasně vypnout,protože mi hlásil FRST jako vir a PC vyzkouším čistou instaalaci vin 7 protože před tím mi instalace nešla nešly nainstaalovat některé ovladače

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: prosím o kontrolu

#10 Příspěvek od Diallix »

A ako je na tom pocitac?
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

hakub
Návštěvník
Návštěvník
Příspěvky: 204
Registrován: 05 úno 2008 05:27

Re: prosím o kontrolu

#11 Příspěvek od hakub »

nejdou mi nainstalovat některé ovladače a nejde aktualizovAt win

hakub
Návštěvník
Návštěvník
Příspěvky: 204
Registrován: 05 úno 2008 05:27

Re: prosím o kontrolu

#12 Příspěvek od hakub »

jo PC v pořádku
děkuji

Uživatelský avatar
Diallix
Rádce
Rádce
Příspěvky: 2760
Registrován: 27 dub 2008 10:34
Kontaktovat uživatele:

Re: prosím o kontrolu

#13 Příspěvek od Diallix »

Mozete podrobnejsie popisat problemy? Ako vam nejdu nainstalovat aktualizacie, co vam hlasi, nejde sa pripojit alebo nereaguje rozhranie na aktualizacie? To iste s ovladacmi.
Vyšla moja nová kniha BOTNETY! :173: Informácie o nej nájdete tu: >> BOTNETY <<

¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­¯­­­
---
Obrázek Hľadáme nové posily do nášej CyberSecurity UNIT jednotky. Viac informácií o tom, čo to obnáša a ako sa pripojiť nájdete tu: >> CyberSecurity UNIT << Obrázek
----
Nízkoúrovňový, Vysokoúrovňový programátor - profilová karta tu: card <<
----
Háveťárna - UPLOAD Malwaru: >> upload <<
---
Ak sa Vám ľúbi moja práca a ste sňou spokojný, môžete ma kontaktovať na: diallix@centrum.sk, info@diallix.net alebo diallix@forum.viry.cz .
---
Momentálne aktívny ako:
- konzultant, vývojár a tutor výskumu inteligentného malwaru.
- tutor v oblasti dotazovacích jazykoch SQL (TSQL, PLSQL), objektového programovania (c++,c#,php) pre študentov.

Na fóre pôsobím ako:
- Bezpečnostná autorita viry.cz
- Zástupca tutora pre vzdelávanie nováčikov
- Zakladateľ Cyber Security jednotky

Odpovědět