Prosím o kontrolu, občas na mě něco vyskočí a nevím, zda je v pořádku.
Děkuji,
Lucie
PS: včera jsem zabrousila na kukaj.sk a tam spustila film a vyskočilo okno, ale počítač se tváří, že vše v pořádku a hrozby pořešeny.
log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-11-2024
Ran by abc (administrator) on DESKTOP-7B99GDP (Hewlett-Packard HP EliteBook 840 G2) (16-11-2024 19:18:02)
Running from C:\Users\abc\Desktop\FRST64.exe
Loaded Profiles: abc
Platform: Microsoft Windows 10 Pro Version 22H2 19045.5131 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\HotKeyServiceUWP.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\HPHotkeyNotification.exe
(explorer.exe ->) (EEDAA6AB-26BE-455F-9139-769243BEFDA8 -> ) C:\Program Files\WindowsApps\64343GTDocStudio.OfficeDocOpener_3.4.3.0_x64__3h5nez1g3qt2c\FileWatcher\FileWatcher.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Gen Digital Inc. -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(HP Inc. -> HP) C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation -> ) C:\Windows\System32\igfxTray.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\HotKeyServiceUWP.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\LanWlanWwanSwitchingServiceUWP.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2445.7.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\abc\AppData\Local\Microsoft\OneDrive\24.211.1020.0001\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2409.11.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8515832 2015-08-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [427304 2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM-x32\...\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [324488 2016-08-02] (HP Inc. -> HP)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe [1203488 2016-12-05] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4097707555-1598978024-893071888-1001\...\Run: [MicrosoftEdgeAutoLaunch_C43E0F6286A350B71A3F31AD450301E1] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3856464 2024-11-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4097707555-1598978024-893071888-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45359408 2024-11-06] (Gen Digital Inc. -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\131.0.6778.70\Installer\chrmstp.exe [2024-11-16] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {6943BB9F-EA51-4062-ACFC-69FAF9D07F18} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5205800 2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {41BE268A-60CB-464C-9585-9F3C68903197} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-08-02] (Avast Software s.r.o. -> Avast Software)
Task: {077F58BF-5FEB-42A3-BCD1-3C5B232A6A30} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [829408 2024-11-06] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {EEE4A257-716C-422F-A45D-5819DBD5A7B9} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5983536 2024-11-06] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "41b3270c-4ba6-4532-b9e6-65072ff30238" --version "6.30.11385" --silent
Task: {C9A88D07-0C27-4291-99A5-8067266550F2} - System32\Tasks\CCleanerSkipUAC - abc => C:\Program Files\CCleaner\CCleaner.exe [39135536 2024-11-06] (Gen Digital Inc. -> Piriform Software Ltd)
Task: {2E4253C1-A5D2-452A-BFDD-507525D13614} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6806.0{20B89C1A-EB93-42DA-AAAE-1F0CE1FA0B43} => C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe [5567072 2024-10-29] (Google LLC -> Google LLC)
Task: {A3138879-839A-4183-A595-16C1A70B69F8} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [543536 2016-10-13] (Intel(R) Trust Services -> Intel(R) Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{a5333e55-10f7-4f9b-9053-f3a6496d9ff1}: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{a5333e55-10f7-4f9b-9053-f3a6496d9ff1}: [DhcpDomain] home
Tcpip\..\Interfaces\{a5333e55-10f7-4f9b-9053-f3a6496d9ff1}\544656E6275646D2D4F62696C656: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{a5333e55-10f7-4f9b-9053-f3a6496d9ff1}\544656E6275646D2D4F62696C656: [DhcpDomain] mobile.wireless
Tcpip\..\Interfaces\{a5333e55-10f7-4f9b-9053-f3a6496d9ff1}\55053473035343039343: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{a5333e55-10f7-4f9b-9053-f3a6496d9ff1}\55053473035343039343: [DhcpDomain] home
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\abc\AppData\Local\Microsoft\Edge\User Data\Default [2024-11-16]
Edge Extension: (Dokumenty Google offline) - C:\Users\abc\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-16]
Edge Extension: (Edge relevant text changes) - C:\Users\abc\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default [2024-11-16]
CHR Notifications: Default -> hxxps://cs.mehvaccasestudies.com; hxxps://fastshare.cz; hxxps://meet.google.com; hxxps://teams.microsoft.com; hxxps://www.facebook.com; hxxps://www.lidl.cz; hxxps://www.ozp.cz; hxxps://www.yoursafetybulwark.com
CHR Extension: (Dokumenty Google offline) - C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7261480 2024-10-23] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [774952 2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1221416 2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2022-09-20] (Avast Software s.r.o. -> AVAST Software)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1087792 2024-11-06] (Gen Digital Inc. -> Piriform Software Ltd)
R2 HotKeyServiceUWP; C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\HotKeyServiceUWP.exe [819856 2019-05-14] (HP Inc. -> HP Inc.)
R2 LanWlanWwanSwitchingServiceUWP; C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\LanWlanWwanSwitchingServiceUWP.exe [731072 2019-05-14] (HP Inc. -> HP Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559368 2024-11-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe [3125112 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe [133560 2022-09-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [20536 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [233016 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [381496 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [294960 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [84536 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\Windows\System32\drivers\aswElam.sys [27744 2024-07-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [28752 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [273976 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [550456 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [97848 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [69176 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [951352 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [1202232 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [203832 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [307256 2024-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [49576 2022-09-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [453904 2022-09-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [94480 2022-09-07] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [32832 2016-07-31] (HP Inc. -> HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-11-16 19:18 - 2024-11-16 19:18 - 000016028 _____ C:\Users\abc\Desktop\FRST.txt
2024-11-16 19:17 - 2024-11-16 19:18 - 000000000 ____D C:\FRST
2024-11-16 19:12 - 2024-11-16 19:12 - 002402304 _____ (Farbar) C:\Users\abc\Desktop\FRST64.exe
2024-11-16 19:05 - 2024-11-16 19:06 - 000009468 _____ C:\cc_20241116_190553.reg
2024-11-16 19:04 - 2024-11-16 19:04 - 000329232 _____ C:\cc_20241116_190342.reg
2024-11-16 18:52 - 2024-11-16 18:52 - 000000000 ____D C:\ProgramData\Piriform
2024-11-16 18:50 - 2024-11-16 19:08 - 000000000 ____D C:\Program Files\CCleaner
2024-11-16 18:50 - 2024-11-16 19:07 - 000000666 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2024-11-16 18:50 - 2024-11-16 18:50 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2024-11-16 18:50 - 2024-11-16 18:50 - 000003380 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2024-11-16 18:50 - 2024-11-16 18:50 - 000002896 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC - abc
2024-11-16 18:50 - 2024-11-16 18:50 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2024-11-16 18:50 - 2024-11-16 18:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2024-11-16 18:49 - 2024-11-16 18:50 - 086350104 _____ (Piriform Software Ltd) C:\Users\abc\Downloads\ccsetup630.exe
2024-11-16 16:34 - 2024-11-16 18:35 - 2179661390 _____ C:\Users\abc\Downloads\V Hlavě 2 - 2024 CZ 1080p.mp4
2024-11-16 13:31 - 2024-11-16 13:36 - 1612209392 _____ C:\Users\abc\Downloads\V hlavě.avi
2024-11-15 16:32 - 2024-11-15 16:32 - 000000000 ___HD C:\$WinREAgent
2024-10-23 00:09 - 2024-10-23 00:08 - 000315688 _____ (Gen Digital Inc.) C:\Windows\system32\aswBoot.exe
2024-10-21 15:11 - 2024-10-21 15:11 - 000031364 _____ C:\Users\abc\Downloads\faktura Pletichová.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-11-16 19:13 - 2020-12-03 12:26 - 001605606 _____ C:\Windows\system32\PerfStringBackup.INI
2024-11-16 19:13 - 2019-12-07 15:43 - 000683606 _____ C:\Windows\system32\perfh005.dat
2024-11-16 19:13 - 2019-12-07 15:43 - 000137386 _____ C:\Windows\system32\perfc005.dat
2024-11-16 19:13 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2024-11-16 19:08 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-11-16 19:07 - 2022-09-20 09:18 - 000000000 ____D C:\ProgramData\Avast Software
2024-11-16 19:07 - 2020-12-03 13:14 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2024-11-16 19:07 - 2020-09-27 08:56 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-11-16 19:07 - 2020-09-27 06:55 - 000008192 ___SH C:\DumpStack.log.tmp
2024-11-16 19:07 - 2019-12-07 10:03 - 001048576 _____ C:\Windows\system32\config\BBI
2024-11-16 19:01 - 2023-01-20 23:30 - 000000000 ____D C:\Users\abc\AppData\Local\CrashDumps
2024-11-16 19:01 - 2020-12-03 13:18 - 000000000 ____D C:\Windows\Panther
2024-11-16 18:38 - 2020-12-25 19:24 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-11-16 18:38 - 2020-12-25 19:24 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-11-16 18:37 - 2021-12-15 00:15 - 000000000 ____D C:\Windows\SystemTemp
2024-11-16 18:36 - 2020-09-27 06:55 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-11-16 13:30 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-11-16 13:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2024-11-16 13:22 - 2020-12-03 13:14 - 000000000 __SHD C:\Users\abc\IntelGraphicsProfiles
2024-11-15 20:44 - 2020-09-27 06:55 - 000259768 _____ C:\Windows\system32\FNTCACHE.DAT
2024-11-15 20:43 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\setup
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\appraiser
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\DiagTrack
2024-11-15 20:43 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2024-11-15 16:53 - 2020-12-03 13:03 - 000000000 ____D C:\Users\abc\AppData\Local\D3DSCache
2024-11-15 16:44 - 2022-09-20 09:19 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2024-11-15 16:44 - 2021-12-11 12:32 - 000003062 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4097707555-1598978024-893071888-1001
2024-11-15 16:44 - 2020-12-03 15:04 - 000003118 _____ C:\Windows\system32\Tasks\Intel PTT EK Recertification
2024-11-15 16:44 - 2020-12-03 13:18 - 000002854 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4097707555-1598978024-893071888-500
2024-11-15 16:44 - 2020-12-03 12:25 - 000002858 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4097707555-1598978024-893071888-1001
2024-11-15 16:44 - 2020-09-27 08:58 - 000003568 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-11-15 16:44 - 2020-09-27 08:58 - 000003344 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-11-15 16:42 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2024-11-15 16:38 - 2020-09-27 08:58 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-11-15 16:31 - 2020-12-03 13:16 - 000000000 ____D C:\Windows\system32\MRT
2024-11-15 16:29 - 2020-12-03 13:16 - 202035632 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-11-15 16:27 - 2020-12-03 12:23 - 000002371 _____ C:\Users\abc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-11-09 15:47 - 2024-02-08 10:21 - 000000719 _____ C:\Users\abc\Desktop\Nadace SNF.txt
2024-11-09 09:49 - 2020-09-27 08:58 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-11-09 09:49 - 2020-09-27 08:58 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-11-05 16:21 - 2021-02-28 14:06 - 000000000 ____D C:\Users\abc\AppData\Roaming\vlc
2024-11-04 19:13 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\appcompat
2024-10-23 00:10 - 2020-12-03 12:24 - 000000000 ____D C:\Users\abc\AppData\Local\Packages
2024-10-23 00:09 - 2019-12-07 10:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2024-10-23 00:08 - 2022-09-20 09:19 - 001202232 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswSP.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000951352 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswSnx.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000550456 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswNetHub.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000381496 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswbidsdriver.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000307256 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswVmm.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000294960 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswbidsh.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000273976 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswMonFlt.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000233016 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswArPot.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000097848 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswRdr2.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000084536 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswbuniv.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000069176 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswRvrt.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000028752 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswKbd.sys
2024-10-23 00:08 - 2022-09-20 09:19 - 000020536 _____ (Gen Digital Inc.) C:\Windows\system32\Drivers\aswArDisk.sys
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
addition:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2024
Ran by abc (16-11-2024 19:20:42)
Running from C:\Users\abc\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.5131 (X64) (2020-12-03 12:20:39)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
abc (S-1-5-21-4097707555-1598978024-893071888-1001 - Administrator - Enabled) => C:\Users\abc
Administrator (S-1-5-21-4097707555-1598978024-893071888-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4097707555-1598978024-893071888-503 - Limited - Disabled)
Guest (S-1-5-21-4097707555-1598978024-893071888-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4097707555-1598978024-893071888-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 24.10.6133 - Avast Software)
CCleaner (HKLM\...\CCleaner) (Version: 6.30 - Piriform)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 131.0.6778.70 - Google LLC)
HP Wireless Button Driver (HKLM-x32\...\{099DAD2B-56C5-4919-9F82-418C2A018CAE}) (Version: 1.1.18.1 - HP)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1045 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{C0466C2A-C335-4936-BBF9-4BE174AB2A61}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{C63012D0-BAD2-48EF-BB78-2ED5FFA2B441}) (Version: 11.6.0.1045 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{F09842DB-C86A-4DCD-81DB-26CFBD506480}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{F255C3B6-F053-4592-9325-34898BF5EB46}) (Version: 1.44.398.0 - Intel Corporation) Hidden
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 130.0.2849.80 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 130.0.2849.80 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4097707555-1598978024-893071888-1001\...\OneDriveSetup.exe) (Version: 24.211.1020.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{08453CDC-B378-42D3-BAD9-CEA017301600}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{E0DE0BC0-9BF3-41C2-9A6D-AC252997690C}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7561 - Realtek Semiconductor Corp.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.19.63 - Synaptics Incorporated)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{DA80A019-4C3B-4DAA-ACA1-6937D7CAAF9E}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.12 - VideoLAN)
Zoom (HKU\S-1-5-21-4097707555-1598978024-893071888-1001\...\ZoomUMX) (Version: 5.17.11 (34827) - Zoom Video Communications, Inc.)
Packages:
=========
Angry Birds Friends -> C:\Program Files\WindowsApps\1ED5AEA5.AngryBirdsFriends_12.7.0.0_x64__p2gbknwb5d8r2 [2024-11-15] (Rovio Entertainment Oyj)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-12-02] (Microsoft Corporation)
HEVC Video Extensions -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_2.2.10.0_x64__8wekyb3d8bbwe [2024-10-23] (Microsoft Corporation)
HP System Information -> C:\Program Files\WindowsApps\AD2F1837.HPSystemInformation_8.10.39.0_x64__v10z8vjag6ke6 [2023-04-05] (HP Inc.)
Instagram -> C:\Program Files\WindowsApps\Facebook.InstagramBeta_42.0.23.0_neutral__8xx8rvfyw5nnt [2024-02-15] (Instagram)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa [2024-10-23] (Apple Inc.) [Startup Task]
Lazy Paint: No Talent, No Problem -> C:\Program Files\WindowsApps\Psykosoft.Psykopaint_1.0.0.77_x64__9ckx6dv3kqvng [2020-12-25] (Psykosoft)
Let’s IQ Campixu -> C:\Program Files\WindowsApps\49613LetsIQ.LetsIQCampixu_1.2.2.0_x86__5kzgjcztqed00 [2020-12-25] (PuzLogical)
Mahjong Solitair -> C:\Program Files\WindowsApps\31202Aliensbringchange.MahjongSolitair_4.1.6.0_x64__2kafcjnv9mrbg [2024-10-10] (Aliens bring change)
Messenger -> C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_2150.23.211.0_x64__8xx8rvfyw5nnt [2024-09-13] (Meta) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-12-25] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-12-25] (Microsoft Corporation) [MS Ad]
Microsoft Sudoku -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSudoku_2.11.8191.0_x64__8wekyb3d8bbwe [2024-09-13] (Microsoft Studios)
Piano Music Tiles : Free Piano Games -> C:\Program Files\WindowsApps\6091PianoMusicGames.PIANOMUSICGOFREEPIANOGAMES_1.5.12.0_x86__2emsn0jh1sz4a [2020-12-25] (Piano Music Games) [MS Ad]
Polarr Pro Photo Editor -> C:\Program Files\WindowsApps\613EBCEA.PolarrPhotoEditorAcademicEdition_5.11.9.0_x64__jb41c8remg0x2 [2024-09-27] (Polarr)
Relaxing Sounds -> C:\Program Files\WindowsApps\WizardsTimeLLC.RelaxingSounds_1.1.2.0_x86__k8n4acezppwj2 [2020-12-25] (Wizards Time) [MS Ad]
Spotify – hudba a podcasty -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0 [2024-11-15] (Spotify AB) [Startup Task]
Trio Office: DOCX & XLSX Editor -> C:\Program Files\WindowsApps\64343GTDocStudio.OfficeDocOpener_3.4.3.0_x64__3h5nez1g3qt2c [2024-10-06] (GT Office PDF Studio) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2445.7.0_x64__cv1g1gvanyjgm [2024-11-15] (WhatsApp Inc.) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2020-06-04] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2024-10-23] (Avast Software s.r.o. -> Gen Digital Inc.)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 10:14 - 2019-12-07 10:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT
HKU\S-1-5-21-4097707555-1598978024-893071888-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\abc\Downloads\4b31fb3950220b312475b97003d540e7.jpg
DNS Servers: 31.30.90.11 - 31.30.90.12
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi: Intel(R) Dual Band Wireless-N 7265 -> Netwtw02.sys
Ethernet: Intel(R) Ethernet Connection (3) I218-LM -> e1d65x64.sys
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{FC757319-8C07-4EB7-BE29-9E7AEC9D08C4}C:\users\abc\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\abc\appdata\roaming\zoom\bin\zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [UDP Query User{C087AC30-3996-4434-A164-FF5F7E1C4C9D}C:\users\abc\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\abc\appdata\roaming\zoom\bin\zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{AA10E3DD-AB13-433E-BCD4-094F51044290}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{3F25B5FA-3B1F-4C24-93B2-02558F9DD470}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{6C4FA503-FBF7-48DF-893E-32C413DEBD9C}] => (Allow) C:\Users\abc\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{999C3EC1-F356-4C52-AE4A-6574ED7A43BD}] => (Allow) C:\Users\abc\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{E5A0360E-4695-44B5-A3A9-93570505C850}] => (Allow) C:\Users\abc\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{FB394E11-1FA8-4073-9C94-4BD866047346}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{7E121EC3-EBE0-4AFF-A4F8-A214A431D37D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{C8CFB0CD-8BB9-4273-8B3D-5022071D7247}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{453D7157-E2EE-48E1-A156-D8437639716A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{247D5D0B-6419-47C5-B2C9-FF94F1DC60D4}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{0FC3EC2D-3EB6-4E9D-B33E-36261EA296EB}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{572929E9-4020-4A09-AF8D-CDC0DE31E5A0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{9C50EBC2-4997-4056-BA8B-49B07ABD722B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12134.4.3008.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{07EA9001-5AB8-4F24-AFB1-9E7603981664}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\130.0.2849.80\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3EB148A6-4521-480C-A089-09E62BB14478}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.132.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C4A2730F-B274-4062-9FE7-EEE98F96A437}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.132.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{975F50F3-394F-4E86-9E6E-7F0B5CC15969}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.132.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{79DE0A5D-23A1-48BC-AAB9-55A80F6B8FEE}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.132.3201.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2FE40A70-292A-4BF9-A42B-811A2BA27589}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1BE8269B-DC01-4B5D-91A2-49A0A8E9F218}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D3B23CDB-C615-409B-B27A-B7FCD6266F54}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BE9D5D6F-2980-471D-B5D1-E2309746ECF4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2E40830B-8FEF-4C96-9749-7613C202743D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{CF7EB016-0968-4665-89A0-38E927CB9143}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8AD04E54-532E-4B2D-BB24-1F194F3B892D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{169310EE-459F-4404-8606-67A45A149D03}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{5C9125B0-DB64-4FEC-AABA-F1A76D1BCC58}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{505841EF-7978-45ED-8B48-B54C32976572}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.250.335.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A23F6E3D-F8EB-4DCC-B75E-000B01FD1509}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/25/2024 09:41:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: mousocoreworker.exe, verze: 10.0.19041.4957, časové razítko: 0x1f215d2f
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.19041.3636, časové razítko: 0x81cf5d89
Kód výjimky: 0xc0000409
Posun chyby: 0x000000000007286e
ID chybujícího procesu: 0x1750
Čas spuštění chybující aplikace: 0x01db2712072ae0ce
Cesta k chybující aplikaci: C:\Windows\System32\mousocoreworker.exe
Cesta k chybujícímu modulu: C:\Windows\System32\ucrtbase.dll
ID zprávy: 051580ec-f296-4f54-af1e-28aa64f523ca
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (10/13/2024 01:34:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bad_module_info, verze: 0.0.0.0, časové razítko: 0x00000000
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00007ffbb848d940
ID chybujícího procesu: 0xbd0
Čas spuštění chybující aplikace: 0x01db1d6c38b2076f
Cesta k chybující aplikaci: bad_module_info
Cesta k chybujícímu modulu: unknown
ID zprávy: 61bbd65c-f843-4cfd-8c91-6d0a6da25d3d
Úplný název chybujícího balíčku: Microsoft.Windows.Search_1.14.17.19041_neutral_neutral_cw5n1h2txyewy
ID aplikace související s chybujícím balíčkem: ShellFeedsUI
Error: (08/05/2024 07:07:45 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: mousocoreworker.exe, verze: 10.0.19041.4355, časové razítko: 0x0115243d
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.19041.3636, časové razítko: 0x81cf5d89
Kód výjimky: 0xc0000409
Posun chyby: 0x000000000007286e
ID chybujícího procesu: 0xe54
Čas spuštění chybující aplikace: 0x01dae6f3fd796c00
Cesta k chybující aplikaci: C:\Windows\System32\mousocoreworker.exe
Cesta k chybujícímu modulu: C:\Windows\System32\ucrtbase.dll
ID zprávy: 6281c75c-918a-43d0-82fe-d9549ed2a935
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (07/21/2024 09:40:00 PM) (Source: System Restore) (EventID: 8211) (User: )
Description: Naplánovaný bod obnovení nebylo možné vytvořit. Další informace: (0x81000101).
Error: (07/21/2024 09:40:00 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení se nezdařilo (Proces = C:\Windows\system32\srtasks.exe ExecuteScheduledSPPCreation; Popis = Naplánovaný kontrolní bod; Chyba = 0x81000101).
Error: (07/18/2024 08:26:47 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..
Error: (07/18/2024 08:26:47 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..
Error: (07/18/2024 08:26:47 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]
System errors:
=============
Error: (11/16/2024 07:09:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Error: (11/16/2024 07:09:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).
Error: (11/16/2024 01:22:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Error: (11/16/2024 01:22:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).
Error: (11/15/2024 08:46:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Error: (11/15/2024 08:46:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).
Error: (11/15/2024 05:19:12 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.
Error: (11/15/2024 04:28:08 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7B99GDP)
Description: Server {94269C4E-071A-4116-90E6-52E557067E4E} se v daném časovém limitu neregistroval u služby DCOM.
Windows Defender:
================
Date: 2022-09-14 23:12:51
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {87D7C559-2917-4D4C-BFFC-C32376DAFF1C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2022-09-14 21:03:06
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {62F47565-F22D-4F25-B46F-C7BF77F0AC07}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2022-09-12 06:29:27
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {554B7AE8-0BFC-4833-8CD0-C89CAD7BA11B}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2022-09-11 09:48:53
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {ACD95177-90A3-4BDB-861E-09DB1493B0CE}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2022-09-07 06:30:05
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {A0C325D9-9CD1-4254-9F04-E2FD0309D75F}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Event[0]:
Date: 2022-04-18 00:24:48
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.363.537.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.19100.5
Kód chyby: 0x80245004
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.
CodeIntegrity:
===============
Date: 2024-10-23 01:08:07
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.
Date: 2024-10-23 01:07:22
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: Hewlett-Packard M71 Ver. 01.31 02/24/2020
Motherboard: Hewlett-Packard 2216
Processor: Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz
Percentage of memory in use: 43%
Total physical RAM: 8067.11 MB
Available physical RAM: 4570.99 MB
Total Virtual: 9347.11 MB
Available Virtual: 6050.51 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:237.87 GB) (Free:4.41 GB) (Model: KINGSTON SKC600256G) NTFS
\\?\Volume{b975e36b-f4cb-44b2-834f-84faedcc6054}\ () (Fixed) (Total:0.49 GB) (Free:0.08 GB) NTFS
\\?\Volume{7e310414-4464-4b2c-9cf7-6f14184e2607}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 238.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosba o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: prosba o kontrolu
Ahoj,
Drive c: () (Fixed) (Total:237.87 GB) (Free:4.41 GB) - daj pozor na zaplnanie disku
+
preventivne prescanuj s Adwcleanerom
Drive c: () (Fixed) (Total:237.87 GB) (Free:4.41 GB) - daj pozor na zaplnanie disku
+
preventivne prescanuj s Adwcleanerom
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: prosba o kontrolu
Dobrý den,
děkuji. Proskenovala jsem a 0 problémů. Nabídlo mi to základní opravy i přes tu nulu. Dala jsem nabízené přeskočit.
Místo na disku si udělám, děkuji.
JInak je tedy vše v pořádku?
Děkuji, Lucie
děkuji. Proskenovala jsem a 0 problémů. Nabídlo mi to základní opravy i přes tu nulu. Dala jsem nabízené přeskočit.
Místo na disku si udělám, děkuji.
JInak je tedy vše v pořádku?
Děkuji, Lucie
Re: prosba o kontrolu
Logy su OK
Mozes s prikazoveho riadku ako spravca spustit
sfc /scannow
Za malo
Mozes s prikazoveho riadku ako spravca spustit
sfc /scannow
Za malo

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: prosba o kontrolu
Dobrý den,
provedla jsem scan s tímto výsledkem -
Opravili se samy nějaké corrupted files a vytvořil se log.
Stačí to takto nebo budete chtít log zaslat.
Děkuji, Lucie
provedla jsem scan s tímto výsledkem -
Opravili se samy nějaké corrupted files a vytvořil se log.
Stačí to takto nebo budete chtít log zaslat.
Děkuji, Lucie
Re: prosba o kontrolu
Takto staci
Predpokladal som nejake poskodene subory, ak su opravene tak OK
Pekny vecer

Predpokladal som nejake poskodene subory, ak su opravene tak OK
Pekny vecer

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/