Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Podezření ze zavirovaného počítače

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
KlaraMertova
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 15 čer 2023 21:34

Podezření ze zavirovaného počítače

#1 Příspěvek od KlaraMertova »

Zdravím,

dnes mi byl před mýma očima dvakrát ukraden jak facebookový účet tak email (přes dvou fázové ověření). V prvním případě mi bylo změněno pouze heslo na FB a emailová adresa k facebookovému účtu. Změnila jsem komplet heslo k emailu a získala zpět svůj FB účet. Po pár hodinách se mi stalo to samé, nicméně byl mi odcizen i emailový účet. Účty jsem opět získala zpět (díky propojení s telefonem) a zase změnila hesla. Mám strach, že se mi to stane po třetí a nevím si rady. Můžete se prosím podívat na můj počítač?

Děkuji mnohokrát.

FRST zde:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-06-2023
Ran by Klárka (administrator) on DESKTOP-6GN5QHU (HP HP 250 G6 Notebook PC) (15-06-2023 21:51:12)
Running from C:\Users\Klárka\Desktop\FRST64.exe
Loaded Profiles: Klárka
Platform: Microsoft Windows 10 Pro Version 22H2 19045.3086 (X64) Language: Čeština (Česko)
Default browser: "C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" --single-argument %1
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\igfxCUIService.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\igfxEM.exe
(explorer.exe ->) () [File not signed] D:\Wallpaper.Engine.Build.1.0.746\wallpaper32.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (深圳市普联技术有限公司) [File not signed] C:\Program Files (x86)\TP-LINK\MFP and Storage Server\MFP and Storage Server.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Windows -> Microsoft Corporation) [File not signed] C:\Windows\System32\winlogon.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\igfxCUIService.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\IntelCpHDCPSvc.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\IntelCpHeciSvc.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11235928 2020-04-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [362056 2022-05-05] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [220056 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [WallpaperEngine] => D:\Wallpaper.Engine.Build.1.0.746\wallpaper32.exe [1245184 2017-05-26] () [File not signed]
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [MFP and Storage Server] => C:\Program Files (x86)\TP-LINK\MFP and Storage Server\MFP and Storage Server.exe [2076672 2013-07-12] (深圳市普联技术有限公司) [File not signed]
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Klárka\AppData\Local\Microsoft\Teams\Update.exe [2587368 2023-04-01] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [912480 2015-09-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [utweb] => "C:\Users\Klárka\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED (No File)
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [AvastBrowserAutoLaunch_D2A84004B69F243E1A55CDC435C0B3C8] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3362152 2023-06-06] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\114.0.5735.133\Installer\chrmstp.exe [2023-06-13] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\114.0.21412.110\Installer\chrmstp.exe [2023-06-15] (Avast Software s.r.o. -> AVAST Software)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {18837C35-982B-4C1B-8D02-B9B80728967A} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3362152 2023-06-06] (Avast Software s.r.o. -> AVAST Software)
Task: {69C16DBB-6CA8-48D5-AD36-010ECDF1AEA1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [7456984 2017-04-11] (Piriform Ltd -> Piriform Ltd)
Task: {A48F7E80-689D-4AC9-BD3C-379762D63E18} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_130_pepper.exe [1286656 2017-10-06] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {A64BD99C-F004-43FB-A6AF-289B076C5CDF} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2135448 2023-06-15] (Avast Software s.r.o. -> Avast Software)
Task: {B3A53801-8790-4754-BC8C-2F54E7FC9FB2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [617096 2022-02-25] (Apple Inc. -> Apple Inc.)
Task: {B5028E7A-F2C5-419C-AEE0-2C480FA32749} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-10-05] (Google Inc -> Google Inc.)
Task: {C11DFD96-065E-4D1A-ABC1-D855BED9A94B} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3362152 2023-06-06] (Avast Software s.r.o. -> AVAST Software)
Task: {CDE5C90C-48C2-4E04-BA56-958873F5AA2C} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
Task: {D18EDB4F-18EA-4909-A24D-6BCC4A4D53C2} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [754472 2021-04-05] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {D7F8724C-A66F-4BB3-A0A4-F6A399545927} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4885400 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
Task: {E28C5886-6E9F-4CAB-BFC3-520E31555F58} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
Task: {E3D0D033-12A8-448B-8548-0DCE4248527D} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel(R) Corporation)
Task: {EFE9399D-0C31-448A-9366-52D249FF57CD} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [696816 2021-03-18] (Mozilla Corporation -> Mozilla Foundation)
Task: {FDEE8CA3-CA1A-4F97-ACC5-ACD9D2ADE479} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-10-05] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{5ea9ca54-ce5d-41d2-b166-a660555e8082}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{705f9381-205a-4311-86d9-0c79181bd44a}: [DhcpNameServer] 10.0.0.138

Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\Klárka\AppData\Local\Microsoft\Edge\User Data\Default [2023-06-15]
Edge Extension: (Edge relevant text changes) - C:\Users\Klárka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-04-24]

FireFox:
========
FF DefaultProfile: 44ic3yxr.default
FF ProfilePath: C:\Users\Klárka\AppData\Roaming\Mozilla\Firefox\Profiles\44ic3yxr.default [2021-04-08]
FF ProfilePath: C:\Users\Klárka\AppData\Roaming\Mozilla\Firefox\Profiles\phjcdshk.default-release [2022-05-09]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-10-06] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-10-06] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1631.4\npAvastBrowserUpdate3.dll [2023-06-15] (Avast Software s.r.o. -> AVAST Software)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1631.4\npAvastBrowserUpdate3.dll [2023-06-15] (Avast Software s.r.o. -> AVAST Software)

Chrome:
=======
CHR Profile: C:\Users\Klárka\AppData\Local\Google\Chrome\User Data\Default [2023-06-15]
CHR Notifications: Default -> hxxps://outlook.office.com; hxxps://teams.microsoft.com; hxxps://www.freefilm.to
CHR Extension: (Dokumenty Google offline) - C:\Users\Klárka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Klárka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [100424 2022-05-02] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8826776 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [582552 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [583576 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\114.0.21412.110\elevation_service.exe [2035232 2023-06-06] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2023-06-15] (Avast Software s.r.o. -> AVAST Software)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9258016 2023-06-15] (Malwarebytes Inc. -> Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [336208 2023-06-14] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\NisSrv.exe [3232576 2023-06-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe [133592 2023-06-10] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [31376 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [236448 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [392320 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [297832 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [95912 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [25576 2023-06-15] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [39600 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [271504 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [556064 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [105248 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [80376 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [943456 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [703800 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [212680 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [319560 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-10-05] (Bluestack Systems, Inc -> Bluestack System Inc.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 EST_BusEnum; C:\WINDOWS\System32\drivers\GenBus.sys [29696 2009-10-06] (Microsoft Windows Hardware Compatibility Publisher -> )
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-06-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [199640 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77752 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [181984 2023-06-15] (Malwarebytes Inc. -> Malwarebytes)
S3 NUServer64; C:\WINDOWS\System32\drivers\NUServer64.sys [254464 2011-10-27] (Microsoft Windows Hardware Compatibility Publisher -> Elite Silicon Technology Inc.)
R3 NUS_Bus64; C:\WINDOWS\System32\drivers\NUS_Bus64.sys [34816 2011-10-14] (Microsoft Windows Hardware Compatibility Publisher -> Elite Silicon Technology Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49560 2023-06-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [498944 2023-06-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99568 2023-06-10] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [40104 2022-06-17] (HP Inc. -> HP)
U1 aswbdisk; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-06-15 21:51 - 2023-06-15 21:52 - 000022084 _____ C:\Users\Klárka\Desktop\FRST.txt
2023-06-15 21:50 - 2023-06-15 21:51 - 000000000 ____D C:\FRST
2023-06-15 21:48 - 2023-06-15 21:49 - 002383360 _____ (Farbar) C:\Users\Klárka\Desktop\FRST64.exe
2023-06-15 21:48 - 2023-06-15 21:48 - 002383360 _____ (Farbar) C:\Users\Klárka\Downloads\FRST64.exe
2023-06-15 20:32 - 2023-06-15 20:32 - 000181984 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2023-06-15 20:26 - 2023-06-15 20:27 - 000000000 ____D C:\AdwCleaner
2023-06-15 20:26 - 2023-06-15 20:26 - 008791352 _____ (Malwarebytes) C:\Users\Klárka\Downloads\adwcleaner.exe
2023-06-15 20:26 - 2023-06-15 20:26 - 000003856 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2023-06-15 20:26 - 2023-06-15 20:26 - 000003272 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2023-06-15 20:26 - 2023-06-15 20:26 - 000002583 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2023-06-15 20:25 - 2023-06-15 20:42 - 000000000 ____D C:\Users\Klárka\AppData\Local\Avast Software
2023-06-15 20:25 - 2023-06-15 20:25 - 000003510 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineUA
2023-06-15 20:25 - 2023-06-15 20:25 - 000003386 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineCore
2023-06-15 20:25 - 2023-06-15 20:25 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2023-06-15 20:24 - 2023-06-15 20:24 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2023-06-15 20:24 - 2023-06-15 20:24 - 000002161 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2023-06-15 20:24 - 2023-06-15 20:24 - 000000000 ____D C:\Users\Klárka\AppData\Roaming\Avast Software
2023-06-15 20:22 - 2023-06-15 20:35 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2023-06-15 20:22 - 2023-06-15 20:22 - 000313240 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2023-06-15 20:22 - 2023-06-15 20:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2023-06-15 20:22 - 2023-06-15 20:22 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2023-06-15 20:21 - 2023-06-15 20:32 - 000000000 ____D C:\ProgramData\Avast Software
2023-06-15 20:21 - 2023-06-15 20:21 - 000888600 _____ (Google LLC) C:\Users\Public\Documents\gcapi.dll
2023-06-15 20:21 - 2023-06-15 20:21 - 000000000 ____D C:\Program Files\Avast Software
2023-06-15 20:20 - 2023-06-15 20:21 - 000263576 _____ (AVAST Software) C:\Users\Klárka\Downloads\avast_free_antivirus_setup_online.exe
2023-06-15 20:13 - 2023-06-15 20:35 - 000000000 ____D C:\Users\Klárka\AppData\Local\Malwarebytes
2023-06-15 20:13 - 2023-06-15 20:13 - 000002046 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2023-06-15 20:13 - 2023-06-15 20:13 - 000002034 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2023-06-15 20:13 - 2023-06-15 20:13 - 000000000 ____D C:\Users\Klárka\AppData\Local\mbam
2023-06-15 20:12 - 2023-06-15 20:12 - 000000000 ____D C:\ProgramData\Malwarebytes
2023-06-15 20:12 - 2023-06-15 20:12 - 000000000 ____D C:\Program Files\Malwarebytes
2023-06-15 20:11 - 2023-06-15 20:12 - 002645944 _____ (Malwarebytes) C:\Users\Klárka\Downloads\MBSetup.exe
2023-06-15 18:07 - 2023-06-15 18:07 - 000000049 _____ C:\Users\Klárka\Downloads\Facebook-2FA-RecoveryCodes.txt
2023-06-14 21:37 - 2023-06-14 21:37 - 000000000 ___HD C:\$WinREAgent
2023-06-10 19:58 - 2023-06-10 19:58 - 000008192 _____ C:\Users\Klárka\Downloads\VIDEO_TS.IFO
2023-06-08 19:51 - 2023-06-08 19:51 - 000080555 _____ C:\Users\Klárka\Downloads\Monsters-Inc-(0000133518).srt
2023-06-08 19:49 - 2023-06-08 19:56 - 000000000 ____D C:\Users\Klárka\Downloads\Monsters Inc (2001) [1080p]
2023-06-08 19:49 - 2023-06-08 19:49 - 000015650 _____ C:\Users\Klárka\Downloads\Monsters, Inc. (2001) [1080p] [BluRay] [YTS.MX].torrent
2023-06-02 21:56 - 2023-06-02 21:59 - 108442923 _____ C:\Users\Klárka\Downloads\Podklady.rar
2023-05-30 10:53 - 2023-05-30 10:53 - 000709436 _____ C:\Users\Klárka\Downloads\20201130_STIP_RAD-UZ_po_2Z.pdf
2023-05-30 10:50 - 2023-05-30 10:50 - 000273685 _____ C:\Users\Klárka\Downloads\20230524_III_UZ_Stipendijni_rad-k_publikaci.pdf
2023-05-30 10:49 - 2023-05-30 10:49 - 000041520 _____ C:\Users\Klárka\Downloads\dokument_218438 (1).pdf
2023-05-22 21:00 - 2023-05-22 21:00 - 030862329 _____ C:\Users\Klárka\Downloads\DP_CAPM_v_hodnoceni_vykonnosti_podniku_SEBO_Igor_Archive.pdf
2023-05-22 11:31 - 2023-05-22 11:31 - 000097469 _____ C:\Users\Klárka\Downloads\zappul2_demo (1).pdf
2023-05-21 10:27 - 2023-05-21 10:27 - 000124833 _____ C:\Users\Klárka\Downloads\C2.pdf
2023-05-20 23:50 - 2023-05-20 23:50 - 000095928 _____ C:\Users\Klárka\Downloads\Zkouska_PNF_2.6.2021(mendelu.matros.cz-jXaR6).pdf
2023-05-20 23:20 - 2023-05-20 23:20 - 002002871 _____ C:\Users\Klárka\Downloads\3_planovani.pdf
2023-05-20 22:42 - 2023-05-20 22:42 - 000093432 _____ C:\Users\Klárka\Downloads\EBC_PF_slides_05_investment.pdf
2023-05-20 22:42 - 2023-05-20 22:42 - 000087987 _____ C:\Users\Klárka\Downloads\EBC_PF_sem_09_student_23.pdf
2023-05-20 21:41 - 2023-05-20 21:41 - 000206576 _____ C:\Users\Klárka\Downloads\10 Kapitálové plánování a investiční rozhodování..pdf
2023-05-20 09:32 - 2023-05-20 09:32 - 000066618 _____ C:\Users\Klárka\Downloads\C9.pdf
2023-05-20 09:31 - 2023-05-20 09:31 - 000167146 _____ C:\Users\Klárka\Downloads\C8 (1).pdf
2023-05-20 09:31 - 2023-05-20 09:31 - 000114278 _____ C:\Users\Klárka\Downloads\C6 (1).pdf
2023-05-20 09:31 - 2023-05-20 09:31 - 000107134 _____ C:\Users\Klárka\Downloads\C5 (1).pdf
2023-05-20 09:31 - 2023-05-20 09:31 - 000085265 _____ C:\Users\Klárka\Downloads\C7 (1).pdf
2023-05-19 19:58 - 2023-05-19 19:58 - 000114773 _____ C:\Users\Klárka\Downloads\C4.pdf
2023-05-19 19:55 - 2023-05-19 19:55 - 000110991 _____ C:\Users\Klárka\Downloads\EBC_PF_slides_03_money.pdf
2023-05-19 19:01 - 2023-05-19 19:01 - 000163982 _____ C:\Users\Klárka\Downloads\C3.pdf
2023-05-19 18:58 - 2023-05-19 18:58 - 000783331 _____ C:\Users\Klárka\Downloads\zappul_demo (1).pdf
2023-05-17 10:04 - 2023-05-17 10:04 - 000490632 _____ C:\Users\Klárka\Downloads\27._5(mendelu.matros.cz-brS31) (1).rar

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-06-15 21:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-06-15 21:30 - 2017-10-05 10:27 - 000000000 ____D C:\Program Files (x86)\Google
2023-06-15 20:40 - 2020-10-04 10:05 - 001693140 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-06-15 20:40 - 2019-12-07 16:43 - 000719496 _____ C:\WINDOWS\system32\perfh005.dat
2023-06-15 20:40 - 2019-12-07 16:43 - 000145622 _____ C:\WINDOWS\system32\perfc005.dat
2023-06-15 20:40 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2023-06-15 20:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-06-15 20:35 - 2017-10-05 09:54 - 000000000 __SHD C:\Users\Klárka\IntelGraphicsProfiles
2023-06-15 20:32 - 2020-10-04 10:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-06-15 20:32 - 2020-10-04 09:57 - 000444720 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-06-15 20:32 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2023-06-15 20:32 - 2019-12-07 11:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2023-06-15 20:31 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-06-15 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-06-15 20:22 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-06-15 19:37 - 2020-10-04 09:57 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-06-15 13:25 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-06-14 21:51 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-06-14 21:46 - 2020-10-04 10:00 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-06-14 21:12 - 2017-10-05 10:04 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-06-14 21:09 - 2020-10-04 10:06 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-06-14 21:09 - 2020-10-04 10:06 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-06-14 21:07 - 2017-10-05 10:04 - 170078616 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-06-14 07:29 - 2017-10-05 10:27 - 000002314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-06-14 07:29 - 2017-10-05 10:27 - 000002273 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-06-10 20:06 - 2017-12-06 19:33 - 000000000 ____D C:\Users\Klárka\AppData\Local\Packages
2023-06-10 19:51 - 2020-06-06 09:38 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-06-10 19:51 - 2020-06-06 09:38 - 000002287 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-06-10 09:42 - 2018-02-17 10:32 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2023-06-09 22:11 - 2021-12-13 16:38 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2224448597-100382662-3852032163-1001
2023-06-09 22:11 - 2020-10-04 10:06 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2224448597-100382662-3852032163-1001
2023-06-09 22:11 - 2020-10-04 09:59 - 000002393 _____ C:\Users\Klárka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-06-06 08:53 - 2021-12-19 00:46 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-06-04 10:58 - 2017-10-05 10:49 - 000000000 ____D C:\Users\Klárka\AppData\Roaming\Microsoft\Excel
2023-06-04 10:56 - 2017-10-05 10:47 - 000000000 ____D C:\Users\Klárka\AppData\Roaming\Microsoft\Word
2023-05-28 11:10 - 2017-12-06 19:43 - 000000000 ____D C:\Users\Klárka\AppData\Local\PlaceholderTileLogoFolder
2023-05-18 20:25 - 2020-10-04 10:06 - 000003768 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-05-18 20:25 - 2020-10-04 10:06 - 000003644 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories ========

2022-12-06 23:53 - 2022-12-06 23:53 - 000000218 _____ () C:\Users\Klárka\AppData\Local\recently-used.xbel

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
Přílohy
Addition.rar
(10.1 KiB) Staženo 24 x

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Podezření ze zavirovaného počítače

#2 Příspěvek od JaRon »

ahoj,
citat:
Tvorba fixlistu pro FRST
•Spustte poznamkovy blok (Start-spustit-notepad)
•Zkopirujte skript >>

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [utweb] => "C:\Users\Klárka\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED (No File)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {FDEE8CA3-CA1A-4F97-ACC5-ACD9D2ADE479} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-10-05] (Google Inc -> Google Inc.)



EmptyTemp:
Reboot:
End
•Ulozte vytvoreny TXT jako fixlist.txt
•Presunte vytvoreny fixlist vedle FRST

:arrow: Spustte znovu FRST.exe
•Kliknete na Fix
•Probehne oprava a vytvori log Fixlog.txt

:arrow: Restart PC a dejte mi sem fixlog.txt
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

KlaraMertova
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 15 čer 2023 21:34

Re: Podezření ze zavirovaného počítače

#3 Příspěvek od KlaraMertova »

Zdravím,

děkuji moc za rychlou reakci, posílám obsah fixlogu:

Fix result of Farbar Recovery Scan Tool (x64) Version: 15-06-2023
Ran by Klárka (16-06-2023 15:29:15) Run:1
Running from C:\Users\Klárka\Desktop
Loaded Profiles: Klárka
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2224448597-100382662-3852032163-1001\...\Run: [utweb] => "C:\Users\Klárka\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED (No File)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {FDEE8CA3-CA1A-4F97-ACC5-ACD9D2ADE479} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-10-05] (Google Inc -> Google Inc.)



EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
"HKU\S-1-5-21-2224448597-100382662-3852032163-1001\Software\Microsoft\Windows\CurrentVersion\Run\\utweb" => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FDEE8CA3-CA1A-4F97-ACC5-ACD9D2ADE479}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FDEE8CA3-CA1A-4F97-ACC5-ACD9D2ADE479}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 270107781 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 4085782 B
Edge => 4495654 B
Chrome => 924437431 B
Firefox => 100452657 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 9134 B
NetworkService => 1779626 B
Klárka => 276365431 B

RecycleBin => 2548 B
EmptyTemp: => 1.5 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 15:35:18 ====

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Podezření ze zavirovaného počítače

#4 Příspěvek od JaRon »

Je to OK
Treba to sledovat, skus nestahovat torrenty
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

KlaraMertova
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 15 čer 2023 21:34

Re: Podezření ze zavirovaného počítače

#5 Příspěvek od KlaraMertova »

Děkuji moc! Takže už PC mohu normálně používat. Nemusím se bát? Torrentům se už nadobro vyhnu.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Podezření ze zavirovaného počítače

#6 Příspěvek od JaRon »

PC pouzivaj, obcasne zmen hesla bud ostrazita v klikani na rozne odkazy
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět