Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Martinus
Návštěvník
Návštěvník
Příspěvky: 91
Registrován: 28 bře 2006 15:59

Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#1 Příspěvek od Martinus »

Dobrý den,
prosím o kontrolu logu PC manželky, neustále jí tam vyskakují okna o zavirovaném PC, Avast občas zablokuje pokus o připojení se na phisingovou stránku.
Ty hlášení jsou jen namátkou:

Zeus.2022 trojan detected
Pc bude zablokován¨
Obnovte licenci CCleaner (ten tam snad ani vůbec není nainstalován)
Systém je infikován
Byl zjištěn virus trojský kůň
a pak ještě něco v polštině atd.

Děkuji :)

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-09-2024
Ran by zeidl (administrator) on DESKTOP-5GGIUHK (15-09-2024 10:34:55)
Running from C:\Users\zeidl\Desktop\FRST64.exe
Loaded Profiles: zeidl
Platform: Microsoft Windows 10 Home Version 22H2 19045.4894 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\AvastUI.exe <5>
(C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\AVAST Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(DriverStore\FileRepository\igdlh64.inf_amd64_e6797382daf01d86\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_e6797382daf01d86\igfxEM.exe
(explorer.exe ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\ImageTransferUtility\ImageTransferUtility.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe <3>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe <6>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <14>
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_e6797382daf01d86\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_e6797382daf01d86\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_e6797382daf01d86\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Network Platform Group -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2016-08-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [426904 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\Run: [MicrosoftEdgeAutoLaunch_219F34CB22E66253DABC19F0AF82B3AB] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3741224 2024-09-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\Run: [AvastBrowserAutoLaunch_E6C195B2FA4B19E7DB06FAE20BE7FF79] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2960216 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {18ab0d40-2c36-11ec-9043-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {6428fd9c-49f4-11ef-9084-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {a3d7dc00-3367-11ee-906b-2c4d54d3d035} - "K:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {d3d4048c-ca36-11ec-904f-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {ef298e42-572d-11ee-9070-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKLM\...\Windows x64\Print Processors\Canon TS6100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDP.DLL [482816 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\hpzppw71: C:\Windows\System32\spool\prtprocs\x64\hpzppw71.dll [230400 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS6100 series: C:\WINDOWS\system32\CNMLMDP.DLL [1302016 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\LIDIL hpzllw71: C:\WINDOWS\system32\hpzllw71.dll [53248 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\91.1.10672.124\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\128.0.6613.138\Installer\chrmstp.exe [2024-09-13] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\127.0.26097.121\Installer\chrmstp.exe [2024-08-26] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\87.0.7478.88\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Image Transfer Utility.lnk [2018-08-25]
ShortcutTarget: Image Transfer Utility.lnk -> C:\Program Files (x86)\Canon\ImageTransferUtility\ImageTransferUtility.exe (Canon Inc. -> CANON INC.)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {44C11CFF-FBC4-468D-B3F2-77B529975638} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {8E432B36-B875-439C-B2A9-106FD1062937} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {E532467A-3937-4447-B870-6C9C7DB35175} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2960216 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {6CAE5AD5-A941-415D-A194-A8E5F690E424} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2960216 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {7C982977-67CB-44F9-BD4D-3732B8A88B50} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [5157272 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {490447E0-921E-4B8C-B85B-0439E2CF0995} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe -> C:\Program Files\Common Files\AV\avast! Antivirus\/backup /iavs
Task: {354783C7-19CE-4F52-9224-6E02244F6E69} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-08-04] (Avast Software s.r.o. -> Avast Software)
Task: {946B7040-1F7C-4C38-8BA8-CDFC702624EF} - System32\Tasks\AvastBrowserProtectS-1-5-21-4203351134-588599791-1491844603-1001 => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1690008 2024-04-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {E709B522-8C2D-4C68-97A7-7E3084065A0F} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
Task: {D05D4322-F718-4089-A01A-55D245CA4D49} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
Task: {5B218054-AEB4-4F04-A76D-9C5EA28A4742} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{F35BDA4B-824B-4FDA-A85A-7D606D375789} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
Task: {02178C3F-94EA-4DDC-86FF-75DA6E560826} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\IntelPTTEKRecertification.exe [855664 2023-12-14] (Intel Corporation -> Intel(R) Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{16131cc2-8d96-4ae2-93bc-db546eb2a5de}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2d4ded94-335e-4f44-a0f3-67a2c7669f9d}: [DhcpNameServer] 192.168.80.2

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\zeidl\AppData\Local\Microsoft\Edge\User Data\Default [2024-09-15]
Edge DownloadDir: Default -> D:\Download
Edge Notifications: Default -> hxxps://cz.avon-brochure.com; hxxps://re-captcha-23.azurewebsites.net
Edge HomePage: Default -> hxxps://www.seznam.cz/
Edge Extension: (Dokumenty Google offline) - C:\Users\zeidl\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-09-12]
Edge Extension: (Edge relevant text changes) - C:\Users\zeidl\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-29]

FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-08-23] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2017-10-17] (CANON INC.) [File not signed]
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1579.3\npAvastBrowserUpdate3.dll [2022-12-13] (Avast Software s.r.o. -> AVAST Software)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1579.3\npAvastBrowserUpdate3.dll [2022-12-13] (Avast Software s.r.o. -> AVAST Software)

Chrome:
=======
CHR Profile: C:\Users\zeidl\AppData\Local\Google\Chrome\User Data\Default [2024-03-22]
CHR HomePage: Default -> hxxp://www.google.com
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\zeidl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-10]
CHR HKU\S-1-5-21-4203351134-588599791-1491844603-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [9015080 2024-08-20] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [771480 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [1208216 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\127.0.26097.121\elevation_service.exe [1651832 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R2 CIJSRegister; C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe [153736 2017-03-02] (Canon Inc. -> CANON INC.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [398792 2019-02-28] (Canon Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] (ASUSTeK Computer Inc. -> )
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [20536 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [229944 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [380984 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [293944 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [84536 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [27744 2024-08-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [28728 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [271928 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [549848 2024-08-08] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [97840 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [69176 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [948792 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1198648 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [203728 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [306648 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [280064 2022-10-12] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-09-15 10:34 - 2024-09-15 10:35 - 000019598 _____ C:\Users\zeidl\Desktop\FRST.txt
2024-09-15 10:34 - 2024-09-15 10:35 - 000000000 ____D C:\FRST
2024-09-15 10:34 - 2024-09-15 10:34 - 002397696 _____ (Farbar) C:\Users\zeidl\Desktop\FRST64.exe
2024-09-13 18:55 - 2024-09-13 18:55 - 000049409 _____ C:\Users\zeidl\Desktop\Aktuálně vyhlášená výběrová řízení _ Veřejné informace _ Finanční správa _ Finanční správa.html
2024-09-13 18:55 - 2024-09-13 18:55 - 000000000 ____D C:\Users\zeidl\Desktop\Aktuálně vyhlášená výběrová řízení _ Veřejné informace _ Finanční správa _ Finanční správa_files
2024-09-12 16:45 - 2024-09-12 16:46 - 000000000 ____D C:\Users\zeidl\Desktop\Banánové řezy z podmáslí - TopRecepty.cz_files
2024-09-12 16:45 - 2024-09-12 16:45 - 000403230 _____ C:\Users\zeidl\Desktop\Krtkův dort na plechu - TopRecepty.cz.html
2024-09-12 16:45 - 2024-09-12 16:45 - 000353649 _____ C:\Users\zeidl\Desktop\Banánové řezy z podmáslí - TopRecepty.cz.html
2024-09-12 16:45 - 2024-09-12 16:45 - 000000000 ____D C:\Users\zeidl\Desktop\Krtkův dort na plechu - TopRecepty.cz_files
2024-09-12 11:27 - 2024-09-12 11:27 - 000226023 _____ C:\Users\zeidl\Desktop\Iveta Zeidlerová.pdf
2024-09-11 19:07 - 2024-09-12 16:45 - 000000000 ____D C:\Users\zeidl\Desktop\Datová schránka
2024-09-11 18:40 - 2024-09-11 18:40 - 000130391 _____ C:\Users\zeidl\Documents\test1.pdf
2024-09-11 15:39 - 2024-09-11 15:39 - 000000000 ___HD C:\$WinREAgent
2024-09-10 12:55 - 2024-09-10 12:55 - 000041569 _____ C:\Users\zeidl\Desktop\Nabídka práce_ Specialista péče o zákazníky - Personálka.cz.html
2024-09-10 12:55 - 2024-09-10 12:55 - 000000000 ____D C:\Users\zeidl\Desktop\Nabídka práce_ Specialista péče o zákazníky - Personálka.cz_files
2024-09-10 11:49 - 2024-09-10 11:49 - 000191863 _____ C:\Users\zeidl\Desktop\Specialista klientské podpory, operátor_ka call centra _ Kolín – VEGA TOOLS s.r.o..html
2024-09-10 11:49 - 2024-09-10 11:49 - 000000000 ____D C:\Users\zeidl\Desktop\Specialista klientské podpory, operátor_ka call centra _ Kolín – VEGA TOOLS s.r.o._files
2024-09-09 22:10 - 2024-09-09 22:10 - 000022919 _____ C:\Users\zeidl\Desktop\Motivační dopis.pdf
2024-09-09 22:09 - 2024-09-09 22:09 - 000010697 _____ C:\Users\zeidl\Desktop\Motivační dopis.odt
2024-09-06 12:28 - 2024-09-11 19:21 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2024-09-05 10:46 - 2024-09-05 10:46 - 000131788 _____ C:\Users\zeidl\Desktop\Expedient_expedientka 1 - Kolín.html
2024-09-05 10:46 - 2024-09-05 10:46 - 000000000 ____D C:\Users\zeidl\Desktop\Expedient_expedientka 1 - Kolín_files
2024-09-03 16:03 - 2024-09-03 16:03 - 000200241 _____ C:\Users\zeidl\Desktop\Back Office_Project manager jn – CHOCOLAND a.s..html
2024-09-03 16:03 - 2024-09-03 16:03 - 000000000 ____D C:\Users\zeidl\Desktop\Back Office_Project manager jn – CHOCOLAND a.s._files
2024-08-26 20:48 - 2024-08-26 20:48 - 000414894 _____ C:\Users\zeidl\Desktop\vypisRT-20240826-204808-ISRT2127857-2024.pdf
2024-08-25 22:25 - 2024-08-25 22:25 - 000226028 _____ C:\Users\zeidl\Desktop\Iveta Zeidlerová 1.odt
2024-08-23 09:20 - 2024-08-23 09:20 - 000318534 _____ C:\Users\zeidl\Desktop\Piškotový korpus opravdu super – 2. strana _ Mimibazar.cz.html
2024-08-23 09:20 - 2024-08-23 09:20 - 000000000 ____D C:\Users\zeidl\Desktop\Piškotový korpus opravdu super – 2. strana _ Mimibazar.cz_files
2024-08-23 09:02 - 2024-08-23 09:02 - 000244306 _____ C:\Users\zeidl\Desktop\PIŠKOTOVÝ KORPUS _ Mimibazar.cz.html
2024-08-23 09:02 - 2024-08-23 09:02 - 000000000 ____D C:\Users\zeidl\Desktop\PIŠKOTOVÝ KORPUS _ Mimibazar.cz_files
2024-08-21 21:24 - 2024-08-21 21:24 - 000310676 _____ C:\Users\zeidl\Desktop\Rychlý salát z červené řepy - TopRecepty.cz.html
2024-08-21 21:24 - 2024-08-21 21:24 - 000000000 ____D C:\Users\zeidl\Desktop\Rychlý salát z červené řepy - TopRecepty.cz_files

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-09-15 10:31 - 2020-12-09 00:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-09-15 10:31 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-09-15 09:06 - 2022-09-15 22:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-09-15 09:05 - 2017-05-23 21:02 - 000000000 ___SD C:\Users\zeidl\AppData\Roaming\Microsoft\Credentials
2024-09-15 09:04 - 2017-05-23 21:03 - 000000000 __SHD C:\Users\zeidl\IntelGraphicsProfiles
2024-09-15 00:47 - 2021-12-19 19:03 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-09-15 00:15 - 2021-12-13 17:22 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4203351134-588599791-1491844603-1001
2024-09-15 00:15 - 2020-12-09 00:09 - 000003568 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-09-15 00:15 - 2020-12-09 00:09 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-09-15 00:15 - 2020-12-09 00:09 - 000003352 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{3A4A226E-6463-4043-BC65-313549CAB6DA}
2024-09-15 00:15 - 2020-12-09 00:09 - 000003344 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-09-15 00:15 - 2020-12-09 00:09 - 000003226 _____ C:\WINDOWS\system32\Tasks\Intel PTT EK Recertification
2024-09-15 00:15 - 2020-12-09 00:09 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4203351134-588599791-1491844603-1001
2024-09-15 00:15 - 2020-12-09 00:09 - 000002768 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2
2024-09-14 23:06 - 2020-12-09 00:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2024-09-14 22:56 - 2020-06-08 13:24 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-09-14 17:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-09-14 17:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-09-14 15:45 - 2024-08-06 22:05 - 000000000 ____D C:\Users\zeidl\AppData\Roaming\vlc
2024-09-13 10:14 - 2018-03-15 14:32 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-09-13 10:14 - 2018-03-15 14:32 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-09-11 19:29 - 2020-12-09 00:03 - 000002377 _____ C:\Users\zeidl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-09-11 19:25 - 2020-12-09 00:11 - 001605606 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-09-11 19:25 - 2019-12-07 16:41 - 000682352 _____ C:\WINDOWS\system32\perfh005.dat
2024-09-11 19:25 - 2019-12-07 16:41 - 000137168 _____ C:\WINDOWS\system32\perfc005.dat
2024-09-11 19:25 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-09-11 19:24 - 2018-05-09 09:36 - 000000000 ____D C:\Users\zeidl\AppData\Local\D3DSCache
2024-09-11 19:21 - 2020-12-09 00:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-09-11 19:21 - 2020-12-09 00:02 - 000351600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-09-11 19:21 - 2020-12-09 00:02 - 000008192 ___SH C:\DumpStack.log.tmp
2024-09-11 19:21 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-09-11 19:21 - 2017-05-24 17:26 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-09-11 19:21 - 2017-05-23 21:16 - 000000000 ____D C:\ProgramData\AVAST Software
2024-09-11 19:21 - 2017-05-06 18:15 - 000000000 ____D C:\Intel
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-09-11 15:49 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-09-11 15:46 - 2020-12-09 00:03 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-09-11 15:20 - 2017-05-24 14:20 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-09-11 15:18 - 2017-05-24 14:20 - 199688632 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-09-10 11:03 - 2024-01-18 12:43 - 000000000 ____D C:\Users\zeidl\Desktop\Zaslané životopisy 2024
2024-09-08 20:49 - 2017-05-24 17:26 - 000001278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-08-27 15:03 - 2023-08-05 16:09 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-08-26 19:41 - 2018-04-05 13:40 - 000002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2024-08-25 22:34 - 2024-08-06 18:19 - 000226025 _____ C:\Users\zeidl\Desktop\Iveta Zeidlerová .odt
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\schemas
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2024-08-20 21:19 - 2018-07-03 20:16 - 000000000 ____D C:\Users\zeidl\AppData\Local\CrashDumps

==================== Files in the root of some directories ========

2017-05-29 20:59 - 2018-06-27 18:27 - 000007168 _____ () C:\Users\zeidl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-09-2024
Ran by zeidl (15-09-2024 10:36:58)
Running from C:\Users\zeidl\Desktop
Microsoft Windows 10 Home Version 22H2 19045.4894 (X64) (2020-12-08 22:09:10)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-4203351134-588599791-1491844603-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4203351134-588599791-1491844603-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-4203351134-588599791-1491844603-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-4203351134-588599791-1491844603-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4203351134-588599791-1491844603-504 - Limited - Disabled)
zeidl (S-1-5-21-4203351134-588599791-1491844603-1001 - Administrator - Enabled) => C:\Users\zeidl

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 24.003.20054 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601078}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 24.7.6124 - Avast Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 127.0.26097.121 - Autoři prohlížeče Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1579.3 - AVAST Software) Hidden
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.00.1.51 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.4.0.16 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.0.2 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
Canon TS6100 series Elektronická příručka (HKLM-x32\...\Canon TS6100 series Elektronická příručka) (Version: 1.1.0 - Canon Inc.)
Canon TS6100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS6100_series) (Version: 1.01 - Canon Inc.)
Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC) (Version: 8.10.7.32 - Canon Inc.)
Canon Utilities Map Utility (HKLM-x32\...\Map Utility Parent) (Version: 1.8.2.3 - Canon Inc.)
FreeTemplateFinder Internet Explorer Homepage and New Tab (HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\FreeTemplateFinderTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 128.0.6613.138 - Google LLC)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
Intel(R) Chipset Device Software (HKLM\...\{81520FC5-3518-40E9-9803-70CE8A801D07}) (Version: 10.1.1.38 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{6574B7E5-BC77-4EE6-8319-C18FD8B0C960}) (Version: 11.6.0.1030 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{AC4709F9-831D-4EDD-B8E8-83AC7C563B66}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Network Connections 21.1.30.0 (HKLM\...\{1E5EDF73-13EC-4211-820D-1900B8BD7951}) (Version: 21.1.30.0 - Intel) Hidden
Intel(R) Network Connections 21.1.30.0 (HKLM\...\PROSetDX) (Version: 21.1.30.0 - Intel)
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{75FE588B-F158-4BB3-A283-A8D18E522A52}) (Version: 1.43.301.1 - Intel Corporation) Hidden
IrfanView 4.44 (64-bit) (HKLM\...\IrfanView64) (Version: 4.44 - Irfan Skiljan)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
LibreOffice 5.3 Help Pack (Czech) (HKLM-x32\...\{8D06916E-9C3B-40AD-9A20-BCA27CE2BD59}) (Version: 5.3.3.2 - The Document Foundation)
LibreOffice 5.4.1.2 (HKLM-x32\...\{8E811365-CBFB-49AC-AB25-9197549B309E}) (Version: 5.4.1.2 - The Document Foundation)
Media Creator Student (HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\Media Creator Student) (Version: - NOVÁ ŠKOLA, s.r.o.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 128.0.2739.79 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 128.0.2739.79 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850405-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\OneDriveSetup.exe) (Version: 24.166.0818.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{6CAEAB4F-2B43-485A-B7F9-AFC2D88BD7A3}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{1AB26641-D555-4648-B08B-676F707A0B1B}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23918 (HKLM\...\{DFFEB619-5455-3697-B145-243D936DB95B}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23918 (HKLM\...\{7B50D081-E670-3B43-A460-0E2CDB5CE984}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23918 (HKLM-x32\...\{BD9CFD69-EB91-354E-9C98-D439E6091932}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23918 (HKLM-x32\...\{B5FC62F5-A367-37A5-9FD2-A6E137C0096F}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 115.15.0.9012 - Mozilla)
Mozilla Thunderbird (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 115.15.0 (x86 cs)) (Version: 115.15.0 - Mozilla)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7910 - Realtek Semiconductor Corp.)
Registrace tiskárny (HKLM-x32\...\Canon EISRegistration) (Version: 1.4.0 - Canon Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0a - Ghisler Software GmbH)
Unigine Valley Benchmark version 1.0 (HKLM-x32\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{85C69797-7336-4E83-8D97-32A7C8465A3B}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)

Packages:
=========

Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2024-06-16] ()
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.276.100.0_x64__kgqvnymyfvs32 [2024-09-09] (king.com)
Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_3.1.0.0_neutral__6e5tt8cgb93ep [2024-07-25] (Canon Inc.)
Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_9.6.12.0_x86__h6adky7gbf63m [2024-09-11] (Gameloft SE)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-15] (Microsoft Corporation)
Facebook -> C:\Program Files\WindowsApps\www.facebook.com-1C2D851A_2023.531.1.1_neutral__n468xs7erp6tc [2023-10-15] (www.facebook.com)
March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_8.5.0.0_x86__h6adky7gbf63m [2024-09-03] (Gameloft SE)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-06] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-06] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_7.0.8.0_neutral__mcm4njqhnhss8 [2024-08-07] (Netflix, Inc.)
Royal Revolt 2 -> C:\Program Files\WindowsApps\flaregamesGmbH.RoyalRevolt2_10.4.0.0_x86__g0q0z3kw54rap [2024-08-05] (flaregames GmbH)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-10] (Twitter Inc.)
Vyhledávání na webu z Microsoft Bingu -> C:\Program Files\WindowsApps\Microsoft.BingSearch_1.0.95.0_x64__8wekyb3d8bbwe [2024-07-22] (Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4203351134-588599791-1491844603-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-4203351134-588599791-1491844603-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_e6797382daf01d86\igfxDTCM.dll [2022-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\zeidl\Desktop\Škola 1. třída učení z internetu\Media Creator Student.lnk -> D:\Plocha\mc.bat ()
Shortcut: C:\Users\zeidl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Media Creator Student\Media Creator Student.lnk -> D:\Plocha\mc.bat ()

==================== Loaded Modules (Whitelisted) =============

2019-05-20 17:35 - 2017-12-07 11:25 - 000123904 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJPLM\CNMPU.DLL
2019-05-20 17:43 - 2017-07-05 13:43 - 000561152 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CCL.dll
2019-05-20 17:43 - 2017-07-05 13:49 - 000593920 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CNQMMWRP.dll
2016-10-07 16:05 - 2016-10-07 16:05 - 000347648 _____ (Intel(R) Corporation) [File not signed] C:\Windows\system32\NCS2Setp.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKU\S-1-5-21-4203351134-588599791-1491844603-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
DownloadDir: D:\Download
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKU\S-1-5-21-4203351134-588599791-1491844603-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-4203351134-588599791-1491844603-1001 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 13:47 - 2019-01-04 20:38 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-4203351134-588599791-1491844603-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\zeidl\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\2550519188725940415\133708149315740407.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Intel(R) Ethernet Connection (2) I219-V -> e1i65x64.sys

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{B05FD680-4CAB-4980-A9A0-D31ACBE80BB3}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File
FirewallRules: [TCP Query User{C277B7F5-4A89-4A10-ACFA-5B48F8C1AA03}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File
FirewallRules: [{D016D1B4-ADDE-4A7C-B953-F2732D09F3C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{39EFF931-458F-4528-ABA8-8F5D1B8A282A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{DB240B4F-A893-443D-9D54-A7D9B0CF07D6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E7FC5B91-BF59-46F4-8C0D-569B889A2909}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{EE5951B8-A1B0-4969-A376-45CE6D3F227B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{35E12407-CF8E-48A0-9625-85A78A6426C8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{7EE8AD7C-4A7F-432E-97E0-9E15CEEAD7E3}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{FBEF0BA2-6CA6-4884-A184-3AC023681235}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{E0059C7A-6618-4720-85A8-18B1DE65D5AB}] => (Allow) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{8BA4034D-FDB5-4521-8AE4-25F083C69B65}] => (Allow) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{43A1EC32-9C15-49DB-A7B4-67491D70EF85}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{8C06814B-307B-4059-809B-DFF79B50634E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{B34507CA-B223-4BE9-B84D-D50AB0943BC1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9C00967A-308E-4E46-8F04-63677CF81C9A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5DFD2A5F-97CB-4F52-BA61-57E9C21EA0FF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9D2F6BA3-EDEC-408D-B912-2CAB5C6A9D22}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{E3EB1186-A0E6-486E-A126-3AEA111B2135}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\128.0.2739.79\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

09-09-2024 13:43:34 Naplánovaný kontrolní bod
11-09-2024 15:39:18 Instalační služba modulů systému Windows
11-09-2024 15:41:20 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (09/12/2024 10:22:45 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (09/05/2024 08:49:11 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (09/02/2024 11:17:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.4717 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: ebc

Čas spuštění: 01dafd1734863eb7

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe

ID hlášení: 875215dd-7f97-477e-ae8a-0780de7cf30e

Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.15.19041_neutral_neutral_cw5n1h2txyewy

ID aplikace relativní podle balíčku s chybou: ShellFeedsUI

Typ zablokování: Quiesce

Error: (09/01/2024 07:12:09 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (08/31/2024 09:44:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.4717 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 2f18

Čas spuštění: 01dafbde334ebe60

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe

ID hlášení: 5019a957-16b0-4fb8-8cca-265a5858d590

Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.15.19041_neutral_neutral_cw5n1h2txyewy

ID aplikace relativní podle balíčku s chybou: ShellFeedsUI

Typ zablokování: Quiesce

Error: (08/22/2024 11:45:46 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.4648 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 375c

Čas spuštění: 01daf4563c887c20

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe

ID hlášení: f149dddf-7202-4120-9774-81ad07dc89b7

Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.15.19041_neutral_neutral_cw5n1h2txyewy

ID aplikace relativní podle balíčku s chybou: ShellFeedsUI

Typ zablokování: Quiesce

Error: (08/22/2024 08:49:33 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (08/20/2024 10:39:32 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)


System errors:
=============
Error: (09/15/2024 09:07:11 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (09/14/2024 06:00:01 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (09/14/2024 08:50:27 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (09/13/2024 06:00:00 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (09/13/2024 10:16:30 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (09/12/2024 09:57:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Avast Antivirus byla nečekaně ukončena. Stalo se to 2 krát. Následující opravná akce bude spuštěna za 5000 milisekund: Restartovat službu.

Error: (09/12/2024 08:49:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Avast Antivirus byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 5000 milisekund: Restartovat službu.

Error: (09/12/2024 06:00:00 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931


CodeIntegrity:
===============
Date: 2024-09-15 09:04:44
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2024-09-14 21:18:22
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. 0303 11/08/2016
Motherboard: ASUSTeK COMPUTER INC. PRIME B250M-PLUS
Processor: Intel(R) Pentium(R) CPU G4560 @ 3.50GHz
Percentage of memory in use: 65%
Total physical RAM: 8061.63 MB
Available physical RAM: 2777.8 MB
Total Virtual: 12029.63 MB
Available Virtual: 5544.14 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.51 GB) (Free:99.54 GB) (Model: KINGSTON SUV400S37240G) NTFS
Drive d: (Nový svazek) (Fixed) (Total:931.39 GB) (Free:307.44 GB) (Model: ST1000DM010-2EP102) NTFS

\\?\Volume{96ce1382-2ba0-484d-b907-7af5fa2faea6}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{212d13f1-b38d-41c0-a2d4-7a162b7d94ba}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{56a01328-60dc-4d51-a149-c4eb4c85a887}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119314
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Martinus
Návštěvník
Návštěvník
Příspěvky: 91
Registrován: 28 bře 2006 15:59

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#3 Příspěvek od Martinus »

Provedeno :James008:
Po scanu jsem tam měl volbu dát soubory do karantény, tak jsem to zvolil. Dál tam bylo Základní oprava a Přeskočit základní opravu, dal jsem Přeskočit. Přesně to čištění a opravy tam nebylo...
Děkuji

# -------------------------------
# Malwarebytes AdwCleaner 8.4.2.0
# -------------------------------
# Build: 03-04-2024
# Database: 2024-03-04.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-15-2024
# Duration: 00:00:01
# OS: Windows 10 (Build 19045.4894)
# Cleaned: 6
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\FreeTemplateFinder
Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ak.staticimgfarm.com
Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hp.myway.com
Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\izito.cz
Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.izito.cz

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2012 octets] - [15/09/2024 13:40:31]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119314
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#4 Příspěvek od Rudy »

OK. Dejte nový log FRST+Addition.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Martinus
Návštěvník
Návštěvník
Příspěvky: 91
Registrován: 28 bře 2006 15:59

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#5 Příspěvek od Martinus »

Provedl jsem nový sken a přikládám. Ani po té karanténě se situace zatím nezlepšila, když jsem dělal ten sken, tak tam na mě zase něco vyskočilo a má to nahoře adresu re-captcha-23.azurewebsites.net A časově po té karanténě jsou tam myslím další oznámení, viz obrázek
https://drive.google.com/file/d/1M7OkN8 ... sp=sharing
EDIT: Ještě mě napadlo, že jsem měl PC možná po té karanténě restartovat, což jsem neudělal. Pokud je to jen vymazalo z registrů, aby se to nespouštělo po startu, tak ale můžou být stále aktivní v paměti...


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-09-2024
Ran by zeidl (administrator) on DESKTOP-5GGIUHK (15-09-2024 15:05:22)
Running from C:\Users\zeidl\Desktop\FRST64.exe
Loaded Profiles: zeidl
Platform: Microsoft Windows 10 Home Version 22H2 19045.4894 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\AVAST Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(dllhost.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\AvastUI.exe <5>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <36>
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe <3>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe <6>
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22053.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2016-08-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [426904 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\Run: [MicrosoftEdgeAutoLaunch_219F34CB22E66253DABC19F0AF82B3AB] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3741224 2024-09-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\Run: [AvastBrowserAutoLaunch_E6C195B2FA4B19E7DB06FAE20BE7FF79] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2960216 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {18ab0d40-2c36-11ec-9043-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {6428fd9c-49f4-11ef-9084-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {a3d7dc00-3367-11ee-906b-2c4d54d3d035} - "K:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {d3d4048c-ca36-11ec-904f-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {ef298e42-572d-11ee-9070-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKLM\...\Windows x64\Print Processors\Canon TS6100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDP.DLL [482816 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\hpzppw71: C:\Windows\System32\spool\prtprocs\x64\hpzppw71.dll [230400 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS6100 series: C:\WINDOWS\system32\CNMLMDP.DLL [1302016 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\LIDIL hpzllw71: C:\WINDOWS\system32\hpzllw71.dll [53248 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\91.1.10672.124\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\128.0.6613.138\Installer\chrmstp.exe [2024-09-13] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\127.0.26097.121\Installer\chrmstp.exe [2024-08-26] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\87.0.7478.88\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Image Transfer Utility.lnk [2018-08-25]
ShortcutTarget: Image Transfer Utility.lnk -> C:\Program Files (x86)\Canon\ImageTransferUtility\ImageTransferUtility.exe (Canon Inc. -> CANON INC.)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {44C11CFF-FBC4-468D-B3F2-77B529975638} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {8E432B36-B875-439C-B2A9-106FD1062937} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {E532467A-3937-4447-B870-6C9C7DB35175} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2960216 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {6CAE5AD5-A941-415D-A194-A8E5F690E424} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2960216 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {7C982977-67CB-44F9-BD4D-3732B8A88B50} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [5157272 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {490447E0-921E-4B8C-B85B-0439E2CF0995} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe -> C:\Program Files\Common Files\AV\avast! Antivirus\/backup /iavs
Task: {354783C7-19CE-4F52-9224-6E02244F6E69} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-08-04] (Avast Software s.r.o. -> Avast Software)
Task: {946B7040-1F7C-4C38-8BA8-CDFC702624EF} - System32\Tasks\AvastBrowserProtectS-1-5-21-4203351134-588599791-1491844603-1001 => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1690008 2024-04-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {E709B522-8C2D-4C68-97A7-7E3084065A0F} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
Task: {D05D4322-F718-4089-A01A-55D245CA4D49} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
Task: {5B218054-AEB4-4F04-A76D-9C5EA28A4742} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{F35BDA4B-824B-4FDA-A85A-7D606D375789} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
Task: {02178C3F-94EA-4DDC-86FF-75DA6E560826} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\IntelPTTEKRecertification.exe [855664 2023-12-14] (Intel Corporation -> Intel(R) Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{16131cc2-8d96-4ae2-93bc-db546eb2a5de}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2d4ded94-335e-4f44-a0f3-67a2c7669f9d}: [DhcpNameServer] 192.168.80.2

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\zeidl\AppData\Local\Microsoft\Edge\User Data\Default [2024-09-15]
Edge DownloadDir: Default -> D:\Download
Edge Notifications: Default -> hxxps://cz.avon-brochure.com; hxxps://re-captcha-23.azurewebsites.net
Edge HomePage: Default -> hxxps://www.seznam.cz/
Edge Extension: (Dokumenty Google offline) - C:\Users\zeidl\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-09-12]
Edge Extension: (Edge relevant text changes) - C:\Users\zeidl\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-29]

FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-09] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-08-23] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2017-10-17] (CANON INC.) [File not signed]
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1579.3\npAvastBrowserUpdate3.dll [2022-12-13] (Avast Software s.r.o. -> AVAST Software)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1579.3\npAvastBrowserUpdate3.dll [2022-12-13] (Avast Software s.r.o. -> AVAST Software)

Chrome:
=======
CHR Profile: C:\Users\zeidl\AppData\Local\Google\Chrome\User Data\Default [2024-03-22]
CHR HomePage: Default -> hxxp://www.google.com
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\zeidl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-10]
CHR HKU\S-1-5-21-4203351134-588599791-1491844603-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [9015080 2024-08-20] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [771480 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [1208216 2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\127.0.26097.121\elevation_service.exe [1651832 2024-08-19] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
S2 CIJSRegister; C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe [153736 2017-03-02] (Canon Inc. -> CANON INC.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [398792 2019-02-28] (Canon Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] (ASUSTeK Computer Inc. -> )
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [20536 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [229944 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [380984 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [293944 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [84536 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [27744 2024-08-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [28728 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [271928 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [549848 2024-08-08] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [97840 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [69176 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [948792 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1198648 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [203728 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [306648 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [280064 2022-10-12] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-09-15 13:41 - 2024-09-15 13:41 - 000002092 _____ C:\Users\zeidl\Desktop\AdwCleaner[C00].txt
2024-09-15 13:38 - 2024-09-15 13:41 - 000000000 ____D C:\AdwCleaner
2024-09-15 13:38 - 2024-09-15 13:38 - 008790880 _____ (Malwarebytes) C:\Users\zeidl\Desktop\adwcleaner.exe
2024-09-15 10:34 - 2024-09-15 15:05 - 000018107 _____ C:\Users\zeidl\Desktop\FRST.txt
2024-09-15 10:34 - 2024-09-15 15:05 - 000000000 ____D C:\FRST
2024-09-15 10:34 - 2024-09-15 10:34 - 002397696 _____ (Farbar) C:\Users\zeidl\Desktop\FRST64.exe
2024-09-13 18:55 - 2024-09-13 18:55 - 000049409 _____ C:\Users\zeidl\Desktop\Aktuálně vyhlášená výběrová řízení _ Veřejné informace _ Finanční správa _ Finanční správa.html
2024-09-13 18:55 - 2024-09-13 18:55 - 000000000 ____D C:\Users\zeidl\Desktop\Aktuálně vyhlášená výběrová řízení _ Veřejné informace _ Finanční správa _ Finanční správa_files
2024-09-12 16:45 - 2024-09-12 16:46 - 000000000 ____D C:\Users\zeidl\Desktop\Banánové řezy z podmáslí - TopRecepty.cz_files
2024-09-12 16:45 - 2024-09-12 16:45 - 000403230 _____ C:\Users\zeidl\Desktop\Krtkův dort na plechu - TopRecepty.cz.html
2024-09-12 16:45 - 2024-09-12 16:45 - 000353649 _____ C:\Users\zeidl\Desktop\Banánové řezy z podmáslí - TopRecepty.cz.html
2024-09-12 16:45 - 2024-09-12 16:45 - 000000000 ____D C:\Users\zeidl\Desktop\Krtkův dort na plechu - TopRecepty.cz_files
2024-09-12 11:27 - 2024-09-12 11:27 - 000226023 _____ C:\Users\zeidl\Desktop\Iveta Zeidlerová.pdf
2024-09-11 19:07 - 2024-09-12 16:45 - 000000000 ____D C:\Users\zeidl\Desktop\Datová schránka
2024-09-11 18:40 - 2024-09-11 18:40 - 000130391 _____ C:\Users\zeidl\Documents\test1.pdf
2024-09-11 15:39 - 2024-09-11 15:39 - 000000000 ___HD C:\$WinREAgent
2024-09-10 12:55 - 2024-09-10 12:55 - 000041569 _____ C:\Users\zeidl\Desktop\Nabídka práce_ Specialista péče o zákazníky - Personálka.cz.html
2024-09-10 12:55 - 2024-09-10 12:55 - 000000000 ____D C:\Users\zeidl\Desktop\Nabídka práce_ Specialista péče o zákazníky - Personálka.cz_files
2024-09-10 11:49 - 2024-09-10 11:49 - 000191863 _____ C:\Users\zeidl\Desktop\Specialista klientské podpory, operátor_ka call centra _ Kolín – VEGA TOOLS s.r.o..html
2024-09-10 11:49 - 2024-09-10 11:49 - 000000000 ____D C:\Users\zeidl\Desktop\Specialista klientské podpory, operátor_ka call centra _ Kolín – VEGA TOOLS s.r.o._files
2024-09-09 22:10 - 2024-09-09 22:10 - 000022919 _____ C:\Users\zeidl\Desktop\Motivační dopis.pdf
2024-09-09 22:09 - 2024-09-09 22:09 - 000010697 _____ C:\Users\zeidl\Desktop\Motivační dopis.odt
2024-09-06 12:28 - 2024-09-11 19:21 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2024-09-05 10:46 - 2024-09-05 10:46 - 000131788 _____ C:\Users\zeidl\Desktop\Expedient_expedientka 1 - Kolín.html
2024-09-05 10:46 - 2024-09-05 10:46 - 000000000 ____D C:\Users\zeidl\Desktop\Expedient_expedientka 1 - Kolín_files
2024-09-03 16:03 - 2024-09-03 16:03 - 000200241 _____ C:\Users\zeidl\Desktop\Back Office_Project manager jn – CHOCOLAND a.s..html
2024-09-03 16:03 - 2024-09-03 16:03 - 000000000 ____D C:\Users\zeidl\Desktop\Back Office_Project manager jn – CHOCOLAND a.s._files
2024-08-26 20:48 - 2024-08-26 20:48 - 000414894 _____ C:\Users\zeidl\Desktop\vypisRT-20240826-204808-ISRT2127857-2024.pdf
2024-08-25 22:25 - 2024-08-25 22:25 - 000226028 _____ C:\Users\zeidl\Desktop\Iveta Zeidlerová 1.odt
2024-08-23 09:20 - 2024-08-23 09:20 - 000318534 _____ C:\Users\zeidl\Desktop\Piškotový korpus opravdu super – 2. strana _ Mimibazar.cz.html
2024-08-23 09:20 - 2024-08-23 09:20 - 000000000 ____D C:\Users\zeidl\Desktop\Piškotový korpus opravdu super – 2. strana _ Mimibazar.cz_files
2024-08-23 09:02 - 2024-08-23 09:02 - 000244306 _____ C:\Users\zeidl\Desktop\PIŠKOTOVÝ KORPUS _ Mimibazar.cz.html
2024-08-23 09:02 - 2024-08-23 09:02 - 000000000 ____D C:\Users\zeidl\Desktop\PIŠKOTOVÝ KORPUS _ Mimibazar.cz_files
2024-08-21 21:24 - 2024-08-21 21:24 - 000310676 _____ C:\Users\zeidl\Desktop\Rychlý salát z červené řepy - TopRecepty.cz.html
2024-08-21 21:24 - 2024-08-21 21:24 - 000000000 ____D C:\Users\zeidl\Desktop\Rychlý salát z červené řepy - TopRecepty.cz_files

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-09-15 14:53 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-09-15 14:48 - 2022-09-15 22:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-09-15 14:46 - 2020-12-09 00:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-09-15 09:05 - 2017-05-23 21:02 - 000000000 ___SD C:\Users\zeidl\AppData\Roaming\Microsoft\Credentials
2024-09-15 09:04 - 2017-05-23 21:03 - 000000000 __SHD C:\Users\zeidl\IntelGraphicsProfiles
2024-09-15 00:47 - 2021-12-19 19:03 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-09-15 00:15 - 2021-12-13 17:22 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4203351134-588599791-1491844603-1001
2024-09-15 00:15 - 2020-12-09 00:09 - 000003568 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-09-15 00:15 - 2020-12-09 00:09 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-09-15 00:15 - 2020-12-09 00:09 - 000003352 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{3A4A226E-6463-4043-BC65-313549CAB6DA}
2024-09-15 00:15 - 2020-12-09 00:09 - 000003344 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-09-15 00:15 - 2020-12-09 00:09 - 000003226 _____ C:\WINDOWS\system32\Tasks\Intel PTT EK Recertification
2024-09-15 00:15 - 2020-12-09 00:09 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4203351134-588599791-1491844603-1001
2024-09-15 00:15 - 2020-12-09 00:09 - 000002768 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2
2024-09-14 23:06 - 2020-12-09 00:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2024-09-14 22:56 - 2020-06-08 13:24 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-09-14 17:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-09-14 17:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-09-14 15:45 - 2024-08-06 22:05 - 000000000 ____D C:\Users\zeidl\AppData\Roaming\vlc
2024-09-13 10:14 - 2018-03-15 14:32 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-09-13 10:14 - 2018-03-15 14:32 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-09-11 19:29 - 2020-12-09 00:03 - 000002377 _____ C:\Users\zeidl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-09-11 19:25 - 2020-12-09 00:11 - 001605606 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-09-11 19:25 - 2019-12-07 16:41 - 000682352 _____ C:\WINDOWS\system32\perfh005.dat
2024-09-11 19:25 - 2019-12-07 16:41 - 000137168 _____ C:\WINDOWS\system32\perfc005.dat
2024-09-11 19:25 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-09-11 19:24 - 2018-05-09 09:36 - 000000000 ____D C:\Users\zeidl\AppData\Local\D3DSCache
2024-09-11 19:21 - 2020-12-09 00:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-09-11 19:21 - 2020-12-09 00:02 - 000351600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-09-11 19:21 - 2020-12-09 00:02 - 000008192 ___SH C:\DumpStack.log.tmp
2024-09-11 19:21 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-09-11 19:21 - 2017-05-24 17:26 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-09-11 19:21 - 2017-05-23 21:16 - 000000000 ____D C:\ProgramData\AVAST Software
2024-09-11 19:21 - 2017-05-06 18:15 - 000000000 ____D C:\Intel
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-09-11 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-09-11 15:49 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-09-11 15:46 - 2020-12-09 00:03 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-09-11 15:20 - 2017-05-24 14:20 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-09-11 15:18 - 2017-05-24 14:20 - 199688632 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-09-10 11:03 - 2024-01-18 12:43 - 000000000 ____D C:\Users\zeidl\Desktop\Zaslané životopisy 2024
2024-09-08 20:49 - 2017-05-24 17:26 - 000001278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-08-27 15:03 - 2023-08-05 16:09 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-08-26 19:41 - 2018-04-05 13:40 - 000002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2024-08-25 22:34 - 2024-08-06 18:19 - 000226025 _____ C:\Users\zeidl\Desktop\Iveta Zeidlerová .odt
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\schemas
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-08-23 00:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2024-08-20 21:19 - 2018-07-03 20:16 - 000000000 ____D C:\Users\zeidl\AppData\Local\CrashDumps

==================== Files in the root of some directories ========

2017-05-29 20:59 - 2018-06-27 18:27 - 000007168 _____ () C:\Users\zeidl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================








Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-09-2024
Ran by zeidl (15-09-2024 15:07:20)
Running from C:\Users\zeidl\Desktop
Microsoft Windows 10 Home Version 22H2 19045.4894 (X64) (2020-12-08 22:09:10)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-4203351134-588599791-1491844603-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4203351134-588599791-1491844603-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-4203351134-588599791-1491844603-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-4203351134-588599791-1491844603-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4203351134-588599791-1491844603-504 - Limited - Disabled)
zeidl (S-1-5-21-4203351134-588599791-1491844603-1001 - Administrator - Enabled) => C:\Users\zeidl

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 24.003.20054 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601078}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 24.7.6124 - Avast Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 127.0.26097.121 - Autoři prohlížeče Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1579.3 - AVAST Software) Hidden
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.00.1.51 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.4.0.16 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.0.2 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
Canon TS6100 series Elektronická příručka (HKLM-x32\...\Canon TS6100 series Elektronická příručka) (Version: 1.1.0 - Canon Inc.)
Canon TS6100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS6100_series) (Version: 1.01 - Canon Inc.)
Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC) (Version: 8.10.7.32 - Canon Inc.)
Canon Utilities Map Utility (HKLM-x32\...\Map Utility Parent) (Version: 1.8.2.3 - Canon Inc.)
FreeTemplateFinder Internet Explorer Homepage and New Tab (HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\FreeTemplateFinderTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 128.0.6613.138 - Google LLC)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
Intel(R) Chipset Device Software (HKLM\...\{81520FC5-3518-40E9-9803-70CE8A801D07}) (Version: 10.1.1.38 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{6574B7E5-BC77-4EE6-8319-C18FD8B0C960}) (Version: 11.6.0.1030 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{AC4709F9-831D-4EDD-B8E8-83AC7C563B66}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Network Connections 21.1.30.0 (HKLM\...\{1E5EDF73-13EC-4211-820D-1900B8BD7951}) (Version: 21.1.30.0 - Intel) Hidden
Intel(R) Network Connections 21.1.30.0 (HKLM\...\PROSetDX) (Version: 21.1.30.0 - Intel)
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{75FE588B-F158-4BB3-A283-A8D18E522A52}) (Version: 1.43.301.1 - Intel Corporation) Hidden
IrfanView 4.44 (64-bit) (HKLM\...\IrfanView64) (Version: 4.44 - Irfan Skiljan)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
LibreOffice 5.3 Help Pack (Czech) (HKLM-x32\...\{8D06916E-9C3B-40AD-9A20-BCA27CE2BD59}) (Version: 5.3.3.2 - The Document Foundation)
LibreOffice 5.4.1.2 (HKLM-x32\...\{8E811365-CBFB-49AC-AB25-9197549B309E}) (Version: 5.4.1.2 - The Document Foundation)
Media Creator Student (HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\Media Creator Student) (Version: - NOVÁ ŠKOLA, s.r.o.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 128.0.2739.79 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 128.0.2739.79 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850405-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\OneDriveSetup.exe) (Version: 24.166.0818.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{6CAEAB4F-2B43-485A-B7F9-AFC2D88BD7A3}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{1AB26641-D555-4648-B08B-676F707A0B1B}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23918 (HKLM\...\{DFFEB619-5455-3697-B145-243D936DB95B}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23918 (HKLM\...\{7B50D081-E670-3B43-A460-0E2CDB5CE984}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23918 (HKLM-x32\...\{BD9CFD69-EB91-354E-9C98-D439E6091932}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23918 (HKLM-x32\...\{B5FC62F5-A367-37A5-9FD2-A6E137C0096F}) (Version: 14.0.23918 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 115.15.0.9012 - Mozilla)
Mozilla Thunderbird (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 115.15.0 (x86 cs)) (Version: 115.15.0 - Mozilla)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7910 - Realtek Semiconductor Corp.)
Registrace tiskárny (HKLM-x32\...\Canon EISRegistration) (Version: 1.4.0 - Canon Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0a - Ghisler Software GmbH)
Unigine Valley Benchmark version 1.0 (HKLM-x32\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{85C69797-7336-4E83-8D97-32A7C8465A3B}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)

Packages:
=========

Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2024-06-16] ()
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.276.100.0_x64__kgqvnymyfvs32 [2024-09-09] (king.com)
Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_3.1.0.0_neutral__6e5tt8cgb93ep [2024-07-25] (Canon Inc.)
Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_9.6.12.0_x86__h6adky7gbf63m [2024-09-11] (Gameloft SE)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-15] (Microsoft Corporation)
Facebook -> C:\Program Files\WindowsApps\www.facebook.com-1C2D851A_2023.531.1.1_neutral__n468xs7erp6tc [2023-10-15] (www.facebook.com)
March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_8.5.0.0_x86__h6adky7gbf63m [2024-09-03] (Gameloft SE)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-06] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-06] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_7.0.8.0_neutral__mcm4njqhnhss8 [2024-08-07] (Netflix, Inc.)
Royal Revolt 2 -> C:\Program Files\WindowsApps\flaregamesGmbH.RoyalRevolt2_10.4.0.0_x86__g0q0z3kw54rap [2024-08-05] (flaregames GmbH)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-10] (Twitter Inc.)
Vyhledávání na webu z Microsoft Bingu -> C:\Program Files\WindowsApps\Microsoft.BingSearch_1.0.95.0_x64__8wekyb3d8bbwe [2024-07-22] (Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4203351134-588599791-1491844603-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-4203351134-588599791-1491844603-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_e6797382daf01d86\igfxDTCM.dll [2022-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2024-08-02] (Avast Software s.r.o. -> Gen Digital Inc.)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\zeidl\Desktop\Škola 1. třída učení z internetu\Media Creator Student.lnk -> D:\Plocha\mc.bat ()
Shortcut: C:\Users\zeidl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Media Creator Student\Media Creator Student.lnk -> D:\Plocha\mc.bat ()

==================== Loaded Modules (Whitelisted) =============

2019-05-20 17:35 - 2017-12-07 11:25 - 000123904 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJPLM\CNMPU.DLL

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKU\S-1-5-21-4203351134-588599791-1491844603-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
DownloadDir: D:\Download
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKU\S-1-5-21-4203351134-588599791-1491844603-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-4203351134-588599791-1491844603-1001 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 13:47 - 2019-01-04 20:38 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-4203351134-588599791-1491844603-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Intel(R) Ethernet Connection (2) I219-V -> e1i65x64.sys

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{B05FD680-4CAB-4980-A9A0-D31ACBE80BB3}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File
FirewallRules: [TCP Query User{C277B7F5-4A89-4A10-ACFA-5B48F8C1AA03}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File
FirewallRules: [{D016D1B4-ADDE-4A7C-B953-F2732D09F3C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{39EFF931-458F-4528-ABA8-8F5D1B8A282A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{DB240B4F-A893-443D-9D54-A7D9B0CF07D6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E7FC5B91-BF59-46F4-8C0D-569B889A2909}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{EE5951B8-A1B0-4969-A376-45CE6D3F227B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{35E12407-CF8E-48A0-9625-85A78A6426C8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{7EE8AD7C-4A7F-432E-97E0-9E15CEEAD7E3}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{FBEF0BA2-6CA6-4884-A184-3AC023681235}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{E0059C7A-6618-4720-85A8-18B1DE65D5AB}] => (Allow) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{8BA4034D-FDB5-4521-8AE4-25F083C69B65}] => (Allow) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{43A1EC32-9C15-49DB-A7B4-67491D70EF85}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{8C06814B-307B-4059-809B-DFF79B50634E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{B34507CA-B223-4BE9-B84D-D50AB0943BC1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9C00967A-308E-4E46-8F04-63677CF81C9A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5DFD2A5F-97CB-4F52-BA61-57E9C21EA0FF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.127.3200.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9D2F6BA3-EDEC-408D-B912-2CAB5C6A9D22}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{E3EB1186-A0E6-486E-A126-3AEA111B2135}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\128.0.2739.79\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

09-09-2024 13:43:34 Naplánovaný kontrolní bod
11-09-2024 15:39:18 Instalační služba modulů systému Windows
11-09-2024 15:41:20 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (09/12/2024 10:22:45 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (09/05/2024 08:49:11 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (09/02/2024 11:17:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.4717 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: ebc

Čas spuštění: 01dafd1734863eb7

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe

ID hlášení: 875215dd-7f97-477e-ae8a-0780de7cf30e

Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.15.19041_neutral_neutral_cw5n1h2txyewy

ID aplikace relativní podle balíčku s chybou: ShellFeedsUI

Typ zablokování: Quiesce

Error: (09/01/2024 07:12:09 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (08/31/2024 09:44:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.4717 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 2f18

Čas spuštění: 01dafbde334ebe60

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe

ID hlášení: 5019a957-16b0-4fb8-8cca-265a5858d590

Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.15.19041_neutral_neutral_cw5n1h2txyewy

ID aplikace relativní podle balíčku s chybou: ShellFeedsUI

Typ zablokování: Quiesce

Error: (08/22/2024 11:45:46 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.4648 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 375c

Čas spuštění: 01daf4563c887c20

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe

ID hlášení: f149dddf-7202-4120-9774-81ad07dc89b7

Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.15.19041_neutral_neutral_cw5n1h2txyewy

ID aplikace relativní podle balíčku s chybou: ShellFeedsUI

Typ zablokování: Quiesce

Error: (08/22/2024 08:49:33 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (08/20/2024 10:39:32 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)


System errors:
=============
Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Management Engine WMI Provider Registration byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HECI Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HDCP Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) PROSet Monitoring Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) HD Graphics Control Panel Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Czech Canon IJ Scan Utility register event byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (09/15/2024 01:41:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service byla neočekávaně ukončena. Tento stav nastal již 1krát.


CodeIntegrity:
===============
Date: 2024-09-15 13:05:35
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2024-09-15 11:02:36
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. 0303 11/08/2016
Motherboard: ASUSTeK COMPUTER INC. PRIME B250M-PLUS
Processor: Intel(R) Pentium(R) CPU G4560 @ 3.50GHz
Percentage of memory in use: 65%
Total physical RAM: 8061.63 MB
Available physical RAM: 2805.05 MB
Total Virtual: 12029.63 MB
Available Virtual: 5168.03 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.51 GB) (Free:98.31 GB) (Model: KINGSTON SUV400S37240G) NTFS
Drive d: (Nový svazek) (Fixed) (Total:931.39 GB) (Free:307.44 GB) (Model: ST1000DM010-2EP102) NTFS

\\?\Volume{96ce1382-2ba0-484d-b907-7af5fa2faea6}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{212d13f1-b38d-41c0-a2d4-7a162b7d94ba}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{56a01328-60dc-4d51-a149-c4eb4c85a887}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119314
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#6 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start

Closeprocesses:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {18ab0d40-2c36-11ec-9043-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {6428fd9c-49f4-11ef-9084-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {a3d7dc00-3367-11ee-906b-2c4d54d3d035} - "K:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {d3d4048c-ca36-11ec-904f-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {ef298e42-572d-11ee-9070-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {44C11CFF-FBC4-468D-B3F2-77B529975638} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {5B218054-AEB4-4F04-A76D-9C5EA28A4742} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{F35BDA4B-824B-4FDA-A85A-7D606D375789} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
C:\Users\zeidl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Toolbar: HKU\S-1-5-21-4203351134-588599791-1491844603-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FirewallRules: [UDP Query User{B05FD680-4CAB-4980-A9A0-D31ACBE80BB3}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File
FirewallRules: [TCP Query User{C277B7F5-4A89-4A10-ACFA-5B48F8C1AA03}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Martinus
Návštěvník
Návštěvník
Příspěvky: 91
Registrován: 28 bře 2006 15:59

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#7 Příspěvek od Martinus »

Provedeno, nebylo to úplně bez problémů. Spustil jsem FRST.EXE, ten původní co jsem už měl na ploše. Ale zapomněl jsem ho pustit jako správce. FRST si stáhlo novou aktualizaci, ale pak ho Avast zablokoval, hlásilo to Zablokovali jsme FRST64.EXE, protože jsme v něm zjistili infekci IDP.ALEXA.54. Zvolil jsem teda přesunout do karantény a chtěl jsem ho stáhnout znovu. Ale už mi to nešlo uložit na plochu, že na to nemám práva. Tak jsem ho uložil do jiného adresáře i s tím souborem fixlist.txt. Ta oprava trvala i na SSD hodinu, dlouho to mazalo haldu souborů v Appdata/local/temp, to už vypadalo, že se to zaseklo a budu to muset přerušit. Ale nakonec to doběhlo a zde je výsledek. Díky za pomoc :)

EDIT: Bohužel manželka hlásí, že problém stále trvá, opět hlášení o zablokování PC z re-captcha-23.azurewebsites.net

Fix result of Farbar Recovery Scan Tool (x64) Version: 16-09-2024
Ran by zeidl (16-09-2024 17:18:09) Run:1
Running from C:\Test
Loaded Profiles: defaultuser0 & zeidl
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

Closeprocesses:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {18ab0d40-2c36-11ec-9043-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {6428fd9c-49f4-11ef-9084-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {a3d7dc00-3367-11ee-906b-2c4d54d3d035} - "K:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {d3d4048c-ca36-11ec-904f-001a7dda7111} - "K:\OnePlus_setup.exe" /s
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\...\MountPoints2: {ef298e42-572d-11ee-9070-2c4d54d3d035} - "K:\OnePlus_setup.exe" /s
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {44C11CFF-FBC4-468D-B3F2-77B529975638} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {5B218054-AEB4-4F04-A76D-9C5EA28A4742} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{F35BDA4B-824B-4FDA-A85A-7D606D375789} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC)
C:\Users\zeidl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Toolbar: HKU\S-1-5-21-4203351134-588599791-1491844603-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FirewallRules: [UDP Query User{B05FD680-4CAB-4980-A9A0-D31ACBE80BB3}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File
FirewallRules: [TCP Query User{C277B7F5-4A89-4A10-ACFA-5B48F8C1AA03}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe] => (Block) C:\users\zeidl\appdata\roaming\icq\bin\icq.exe => No File

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION => restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{18ab0d40-2c36-11ec-9043-001a7dda7111} => removed successfully
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6428fd9c-49f4-11ef-9084-2c4d54d3d035} => removed successfully
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3d7dc00-3367-11ee-906b-2c4d54d3d035} => removed successfully
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3d4048c-ca36-11ec-904f-001a7dda7111} => removed successfully
HKU\S-1-5-21-4203351134-588599791-1491844603-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ef298e42-572d-11ee-9070-2c4d54d3d035} => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{44C11CFF-FBC4-468D-B3F2-77B529975638}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44C11CFF-FBC4-468D-B3F2-77B529975638}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B218054-AEB4-4F04-A76D-9C5EA28A4742}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B218054-AEB4-4F04-A76D-9C5EA28A4742}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{F35BDA4B-824B-4FDA-A85A-7D606D375789} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{F35BDA4B-824B-4FDA-A85A-7D606D375789}" => removed successfully
C:\Users\zeidl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
"HKU\S-1-5-21-4203351134-588599791-1491844603-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B05FD680-4CAB-4980-A9A0-D31ACBE80BB3}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C277B7F5-4A89-4A10-ACFA-5B48F8C1AA03}C:\users\zeidl\appdata\roaming\icq\bin\icq.exe" => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 1289884845 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 88785604 B
Windows/system/drivers => 175085 B
Edge => 0 B
Chrome => 29050601 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 304318 B
NetworkService => 306396 B
defaultuser0 => 313564 B
zeidl => 243509866 B

RecycleBin => 13603388053 B
EmptyTemp: => 14.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:09:29 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119314
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#8 Příspěvek od Rudy »

Bodeť ne, když v tempech bylo více než 14GB dat (zbytečností). Dále některé antiviry nemají utility, které používáme k čištění rádi. Takže se stalo, to, co se stalo. Příště při práci FRST AV vypněte. Co se týká toho zablokování, nechápu. Spusťte ještě AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 . Stáhněte, uložte spusťte a po ukončení akce smažte vše, co najde.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15645
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#9 Příspěvek od JaRon »

len doplnim:
nastavit v Edge blokovanie reklam a hlaseni + zmazat cookies
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Martinus
Návštěvník
Návštěvník
Příspěvky: 91
Registrován: 28 bře 2006 15:59

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#10 Příspěvek od Martinus »

Nakonec se to podařilo vyřešit, oni totiž všechny ty oznámení zmizely kromě toho jednoho. Tak jsem po tom pátral a zjistil jsem, že v Edge někdo povolil pro ten web azurewebsites.net oznámení :?: Oni tam občas chodí i děti...
Takže problém vypadá vyřešen, teď už pár hodin nic. Děkuji oběma za rady a za vyčištění PC od balastu. :idea:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119314
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, neustálé hlášení o zavirovaném PC

#11 Příspěvek od Rudy »

I za kolegu: Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno