Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

vyskakují okna s hrozbou

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

vyskakují okna s hrozbou

#1 Příspěvek od ouhara »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-05-2025
Ran by User (administrator) on DESKTOP-R93ONLB (Gigabyte Technology Co., Ltd. B650M D3HP) (05-05-2025 21:05:35)
Running from C:\Users\User\Downloads\FRST64.exe
Loaded Profiles: User
Platform: Microsoft Windows 11 Home Version 24H2 26100.3915 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(DriverStore\FileRepository\u0405277.inf_amd64_00f6bd87014da3b2\B404941\atiesrxx.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0405277.inf_amd64_00f6bd87014da3b2\B404941\atieclxx.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe <16>
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Download Navigator\EPSDNMON.EXE
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE
(explorer.exe ->) (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIR4E.EXE
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (ZONER software, a.s. -> ZONER software) C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
(RuntimeBroker.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <13>
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\System32\GigabyteUpdateService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_987f8cede005f427\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0405277.inf_amd64_00f6bd87014da3b2\B404941\atiesrxx.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25032.52.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2517.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\GCC.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.327.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\User\AppData\Local\Microsoft\OneDrive\25.065.0406.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.8401.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [KeePass 2 PreLoad] => C:\Program Files\KeePass Password Safe 2\KeePass.exe [3308928 2024-06-01] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [455968 2023-05-26] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1151872 2016-11-18] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4693600 2025-04-28] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Run: [EPSDNMON] => C:\Program Files (x86)\Epson Software\Download Navigator\EPSDNMON.EXE [350032 2022-07-21] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIR4E.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Run: [com.messenger] => "C:\Users\User\AppData\Local\Programs\Messenger\Messenger.exe" messenger://openAtLogin (No File)
HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Run: [MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4045880 2025-05-01] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [774168 2013-02-18] (ZONER software, a.s. -> ZONER software)
HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Run: [GoogleUpdaterTaskUser138.0.7156.0] => C:\Users\User\AppData\Local\Google\GoogleUpdater\138.0.7156.0\updater.exe [7096416 2025-05-02] (Google LLC -> Google LLC)
HKLM\...\Print\Monitors\EPSON L3050 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBR4E.DLL [187392 2018-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\FPR12:: C:\WINDOWS\system32\fpmon12-x64.dll [150264 2024-11-15] (FinePrint Software, LLC -> FinePrint Software)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Messenger.lnk [2025-01-07]
ShortcutTarget: Messenger.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {FD680773-3A0C-49FE-97C7-7C6BACBE41A0} - System32\Tasks\EPSON L3050 Series Update {CF9206B0-EE29-436E-B736-0580A3092F26} => C:\Windows\System32\spool\drivers\x64\3\E_YTSR4E.EXE [690536 2013-11-21] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {4743EA07-E84A-47A0-89EF-D6DA8D82F640} - System32\Tasks\GCC => C:\Program Files\GIGABYTE\Control Center\GCC.exe [35403888 2024-06-27] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) -> C:\Program Files\GIGABYTE\Control Center\\-b
Task: {76859AAF-737A-418C-9DF9-498DD7A4E7AA} - System32\Tasks\GoogleUser\GoogleUpdater\GoogleUpdaterTaskUser138.0.7156.0{EAD8B0DA-A8A5-4556-8061-59BAA7F494D3} => C:\Users\User\AppData\Local\Google\GoogleUpdater\138.0.7156.0\updater.exe [7096416 2025-05-02] (Google LLC -> Google LLC)
Task: {EE99632E-BB73-496E-8F9F-F15D912626E8} - System32\Tasks\Meta\Messenger-SL-Helper-S-1-5-21-3512291557-84185808-1624565692-1001 => C:\Users\User\AppData\Local\Programs\Messenger\MessengerHelper.exe [2192632 2024-09-17] (Facebook, Inc. -> Meta Platforms, Inc.)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {CC096A74-1346-4FAA-B065-5C416FC56318} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A77F8271-0973-4394-B92F-CE12F6448330} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D235690D-9C3F-4A2B-B798-B174FA8C6F98} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4554A018-172F-47CB-A4FF-244861845828} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C6E31EFE-02A8-4915-9CAB-E5BAEF1516A5} - System32\Tasks\Microsoft\Windows\WindowsAI\Recall\InitialConfiguration => {709FD5EF-7296-4154-BD3A-E9830FCFA60A} C:\WINDOWS\system32\ShellConfigTask.dll [274432 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
Task: {A170A618-C8B5-4900-9DF0-512A93BCA1C2} - System32\Tasks\Microsoft\Windows\WindowsAI\Recall\PolicyConfiguration => {0BE6820D-B667-4CB6-931B-C153A77DA895} C:\WINDOWS\system32\ShellConfigTask.dll [274432 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
Task: {1F484341-3697-4037-A77F-E7B55D2285B8} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3512291557-84185808-1624565692-1001 => C:\Users\User\AppData\Local\Microsoft\OneDrive\25.065.0406.0002\OneDriveLauncher.exe [679232 2025-05-05] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\EPSON L3050 Series Update {CF9206B0-EE29-436E-B736-0580A3092F26}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSR4E.EXE:/EXE:{CF9206B0-EE29-436E-B736-0580A3092F26} /F:UpdateWORKGROUP\DESKTOP-R93ONLB$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{af363fc7-7abe-4f97-9a34-30c45cd39377}: [DhcpNameServer] 192.168.0.1

Edge:
=======
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2025-05-05]
Edge Notifications: Default -> hxxps://www.messenger.com
Edge Extension: (Dokumenty Google offline) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-05-05]
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-06-21]

Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2025-02-17]
CHR HomePage: Default -> hxxps://www.google.cz/
CHR StartupUrls: Default -> "hxxps://www.google.cz/"
CHR Extension: (Překladač Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-09-09]
CHR Extension: (Tampermonkey) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2024-12-09]
CHR Extension: (Avast Passwords) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2024-06-26]
CHR Extension: (IITC Button) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\febaefghpimpenpigafpolgljcfkeakn [2024-10-09]
CHR Extension: (Full Screen Weather) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2024-06-26]
CHR Extension: (Chrome Capture - Screenshot & GIF) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggaabchcecdbomdcnbahdfddfikjmphe [2024-12-05]
CHR Extension: (Dokumenty Google offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-02-04]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2025-02-06]
CHR Extension: (Avast Online Security & Privacy) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2024-12-05]
CHR Extension: (FormApps Extension) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2024-06-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-06-26]
CHR Extension: (KeePassXC-Browser) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\oboonakemofpalcgghocfoadofidjkkk [2024-12-27]
CHR Extension: (Avast AntiTrack) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppdidpcihajhihmghhhkfnpklgdehold [2025-01-27]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1 [2025-05-05]
CHR Notifications: Profile 1 -> hxxps://calendar.google.com; hxxps://d00fi0m071bc73babu6g.steadychainconnection.co.in; hxxps://uaw3n32yrsycgi.steadychainconnection.co.in; hxxps://vtl11l9vzt1bnb.steadychainconnection.co.in; hxxps://www.facebook.com
CHR HomePage: Profile 1 -> hxxps://www.google.cz/
CHR StartupUrls: Profile 1 -> "hxxps://www.google.cz/"
CHR Extension: (Překladač Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2025-02-17]
CHR Extension: (Hallstatt Austria) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\alpplojofdhjhhbhbppkhlaeidahgopc [2025-02-17]
CHR Extension: (Tampermonkey) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2025-02-17]
CHR Extension: (Avast Passwords) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2025-04-21]
CHR Extension: (IITC Button) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\febaefghpimpenpigafpolgljcfkeakn [2025-02-17]
CHR Extension: (Full Screen Weather) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2025-02-17]
CHR Extension: (Chrome Capture - Screenshot & GIF) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ggaabchcecdbomdcnbahdfddfikjmphe [2025-04-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-23]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2025-05-04]
CHR Extension: (Avast Online Security & Privacy) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2025-03-29]
CHR Extension: (FormApps Extension) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2025-02-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-02-17]
CHR Extension: (KeePassXC-Browser) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oboonakemofpalcgghocfoadofidjkkk [2025-04-21]
CHR Extension: (Avast AntiTrack) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ppdidpcihajhihmghhhkfnpklgdehold [2025-02-24]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\System Profile [2025-02-17]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2024-07-08] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [150640 2023-11-06] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [206304 2020-10-02] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S3 LibreOfficeMaintenance; C:\Program Files\LibreOffice\program\update_service.exe [123304 2025-04-30] (The Document Foundation -> The Document Foundation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe [2009608 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\Display.NvContainer\NVDisplay.Container.exe [1275024 2024-11-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe [4538400 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe [278320 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ZTHELPER; C:\WINDOWS\System32\zthelper.dll [146096 2025-04-26] (Microsoft Windows -> Microsoft Corporation)
R2 GigabyteUpdateService; C:\WINDOWS\system32\GigabyteUpdateService.exe [898808 2025-05-05] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdfendrmgr; C:\WINDOWS\System32\DriverStore\FileRepository\amdfendr.inf_amd64_987f8cede005f427\amdfendrmgr.sys [55456 2024-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 amduw23g; C:\WINDOWS\System32\DriverStore\FileRepository\u0405277.inf_amd64_00f6bd87014da3b2\B404941\amdkmdag.sys [106144848 2024-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2024-12-29] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2024-12-29] (Microsoft Corporation) [File not signed]
R1 CTIIO; C:\Windows\system32\drivers\CtiIo64.sys [34920 2024-07-12] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
R3 gdrv3; C:\Windows\System32\drivers\gdrv3.sys [52432 2024-07-12] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-04-10] (Microsoft Windows -> Microsoft Corporation)
R3 rt25cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt25cx21x64.inf_amd64_5a99eeac5a197cd5\rt25cx21x64.sys [845272 2024-11-05] (Realtek Semiconductor Corp. -> Realtek)
R3 SteamStreamingMicrophone; C:\WINDOWS\system32\drivers\SteamStreamingMicrophone.sys [40736 2020-06-01] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\WINDOWS\system32\drivers\SteamStreamingSpeakers.sys [40736 2020-06-01] (Valve Corp. -> )
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-03-28] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
S3 usbscan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_971c769b103df369\usbscan.sys [90112 2024-12-29] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20016 2025-04-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [605576 2025-04-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-10] (Microsoft Windows -> Microsoft Corporation)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_8d863c975b4367df\wini3ctarget.sys [79288 2025-04-26] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-05-05 21:05 - 2025-05-05 21:05 - 000023234 _____ C:\Users\User\Downloads\FRST.txt
2025-05-05 21:03 - 2025-05-05 21:05 - 000000000 ____D C:\FRST
2025-05-05 20:34 - 2025-05-05 20:34 - 002405376 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2025-05-05 20:28 - 2025-05-05 20:28 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2025-05-05 19:39 - 2025-05-05 19:39 - 000677108 _____ C:\WINDOWS\system32\perfh005.dat
2025-05-05 19:39 - 2025-05-05 19:39 - 000144960 _____ C:\WINDOWS\system32\perfc005.dat
2025-04-30 14:40 - 2025-04-30 14:40 - 000000000 ____D C:\Program Files (x86)\LibreOffice Maintenance Service
2025-04-29 15:30 - 2025-04-29 15:42 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps
2025-04-26 13:08 - 2025-05-05 19:31 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-26 12:28 - 2025-04-26 12:28 - 000030998 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-26 12:28 - 2025-04-26 12:28 - 000030998 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-21 14:42 - 2025-04-21 14:42 - 000464134 _____ C:\Users\User\Downloads\predsmluvni_dokumentace-2025-04-20-jiri_kurka.pdf
2025-04-21 14:41 - 2025-04-21 14:41 - 000091000 _____ C:\Users\User\Downloads\smlouva-2025-04-20-.pdf
2025-04-14 20:32 - 2025-04-14 20:32 - 000482117 _____ C:\Users\User\Downloads\2955007850.pdf
2025-04-09 22:29 - 2025-04-09 22:29 - 000000000 ____D C:\inetpub

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-05-05 20:54 - 2024-06-26 15:37 - 000000000 ____D C:\Program Files (x86)\Steam
2025-05-05 20:09 - 2024-10-09 15:26 - 000000000 ____D C:\Users\User\AppData\Roaming\Messenger
2025-05-05 20:07 - 2024-12-29 23:43 - 000003446 _____ C:\WINDOWS\system32\Tasks\GCC
2025-05-05 20:06 - 2024-06-21 14:55 - 000000000 ____D C:\ProgramData\NVIDIA
2025-05-05 20:00 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-05-05 19:42 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-05-05 19:39 - 2024-12-29 23:48 - 001603798 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-05-05 19:39 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-05-05 19:37 - 2024-10-09 15:29 - 000000000 ____D C:\Users\User\AppData\Roaming\Telegram Desktop
2025-05-05 19:33 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-05-05 19:33 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-05-05 19:32 - 2024-12-29 23:43 - 000003212 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-05-05 19:31 - 2024-12-29 23:43 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-05-05 19:31 - 2024-06-21 20:15 - 000109304 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\system32\GigabyteDownloadAssistant.exe
2025-05-05 19:31 - 2024-06-21 19:59 - 000926544 _____ C:\WINDOWS\system32\wpbbin.exe
2025-05-05 19:31 - 2024-06-21 19:59 - 000898808 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\system32\GigabyteUpdateService.exe
2025-05-05 19:31 - 2024-06-21 19:59 - 000012288 ___SH C:\DumpStack.log.tmp
2025-05-05 19:27 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-05-05 19:23 - 2025-02-06 13:22 - 000003562 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3512291557-84185808-1624565692-1001
2025-05-05 19:23 - 2024-12-29 23:43 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3512291557-84185808-1624565692-1001
2025-05-05 19:23 - 2024-12-29 23:43 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3512291557-84185808-1624565692-1001
2025-05-05 19:23 - 2024-06-21 20:16 - 000002374 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-05-05 19:17 - 2024-12-29 23:43 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-05-05 19:17 - 2024-12-29 23:43 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-05-04 17:34 - 2024-12-29 23:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-05-02 12:33 - 2024-06-21 20:15 - 000000000 ____D C:\Users\User\AppData\Local\Packages
2025-05-02 11:31 - 2024-06-21 19:59 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-30 15:31 - 2024-06-21 15:56 - 000000000 ____D C:\Program Files\LibreOffice
2025-04-30 15:22 - 2024-06-21 20:19 - 000000000 ____D C:\Users\User\AppData\Local\PlaceholderTileLogoFolder
2025-04-29 17:39 - 2024-06-28 19:20 - 000000000 ____D C:\Users\Public\Documents\byt
2025-04-29 15:41 - 2024-07-02 18:01 - 000000000 ____D C:\Users\User\KMPlayer
2025-04-27 14:29 - 2024-06-21 20:18 - 000000000 ____D C:\Users\User\AppData\Local\D3DSCache
2025-04-26 22:31 - 2024-06-21 20:01 - 000000000 ____D C:\ProgramData\Packages
2025-04-26 22:30 - 2024-12-29 23:41 - 000445728 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-26 22:30 - 2024-12-29 23:38 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-04-26 22:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-26 12:28 - 2024-12-29 23:43 - 003369984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-04-24 22:26 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-24 21:57 - 2024-06-26 14:51 - 000002493 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-10 11:56 - 2024-06-21 19:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-04-09 22:29 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-09 22:29 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-07 19:35 - 2024-07-02 18:02 - 000000886 _____ C:\Users\User\Desktop\KMPlayer.lnk

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-05-2025
Ran by User (05-05-2025 21:06:25)
Running from C:\Users\User\Downloads
Microsoft Windows 11 Home Version 24H2 26100.3915 (X64) (2024-12-29 21:43:19)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3512291557-84185808-1624565692-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3512291557-84185808-1624565692-503 - Limited - Disabled)
Guest (S-1-5-21-3512291557-84185808-1624565692-501 - Limited - Disabled)
User (S-1-5-21-3512291557-84185808-1624565692-1001 - Administrator - Enabled) => C:\Users\User
WDAGUtilityAccount (S-1-5-21-3512291557-84185808-1624565692-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.133 - Advanced Micro Devices, Inc.) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 6.05.28.016 - Advanced Micro Devices, Inc.)
AMD I2C Driver (HKLM-x32\...\{B31D92D9-2914-46B0-9738-F668A563DE73}) (Version: 1.2.0.124 - Advanced Micro Devices, Inc.) Hidden
AMD PPM Provisioning File Driver (HKLM-x32\...\{3665A5DE-D07C-46D7-9207-713E8E9FEF32}) (Version: 8.0.0.32 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.27.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.44 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{f5a184ba-6bb9-4338-ab92-850cd47c99ab}) (Version: 6.05.28.016 - Advanced Micro Devices, Inc.) Hidden
ENE Video Capture Box HAL (HKLM\...\{A096611D-BA11-4A1A-8D09-0A0462D7C8F2}) (Version: 1.0.5.15 - Ene Tech.) Hidden
ENE Video Capture Box HAL (HKLM-x32\...\{974259bf-3ed1-4cd6-9ed1-40c7f601a786}) (Version: 1.0.5.15 - Ene Tech.) Hidden
ENE_AIC_Marvell_HAL (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden
ENE_AIC_Marvell_HAL (HKLM-x32\...\{887e18fb-6bc3-4cd4-b34e-32d9ff71bbae}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden
ENE_DRAM_RGB_AIO (HKLM\...\{B6309BF9-CFD5-4AA0-BE86-C58A6A917DA1}) (Version: 1.0.12.2 - Ene Tech.) Hidden
ENE_DRAM_RGB_AIO (HKLM-x32\...\{25ed5e8e-dbd3-4fa0-a28a-1b7de48b7bee}) (Version: 1.0.12.2 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.13.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{0d380ad9-daa5-4680-ada2-dc3ed9207e16}) (Version: 1.0.13.0 - ENE TECHNOLOGY INC.) Hidden
ENE_External_Device_HAL (HKLM\...\{2B8E611F-0B51-4FAC-87BB-AF50D82E7DDA}) (Version: 1.0.12.7 - ENE Tech) Hidden
ENE_External_Device_HAL (HKLM-x32\...\{a7b1cf47-d8f0-423d-9494-568195f1c864}) (Version: 1.0.12.7 - ENE Tech) Hidden
ENE_MousePad_HAL (HKLM\...\{9E97178A-ADB8-4778-BE60-7E28E2A72721}) (Version: 1.0.1.8 - ENE TECHNOLOGY INC.) Hidden
ENE_MousePad_HAL (HKLM-x32\...\{bf256b46-8ff7-48be-ab7f-5661e9a0651f}) (Version: 1.0.1.8 - ENE TECHNOLOGY INC.) Hidden
ENE_X_AIC_HAL (HKLM\...\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.6.3 - ENE TECHNOLOGY INC.) Hidden
ENE_X_AIC_HAL (HKLM-x32\...\{c662a481-d76a-4188-95d2-6eb4ffd55542}) (Version: 1.0.6.3 - ENE TECHNOLOGY INC.) Hidden
Epson Easy Photo Print 2 (HKLM-x32\...\{7E0261C4-8495-4365-BE48-647701D8B9BD}) (Version: 2.8.3.0 - Seiko Epson Corporation)
Epson Event Manager (HKLM-x32\...\{AB8BE3EA-01D3-44B7-8E77-A9601CBDEBDE}) (Version: 3.10.0085 - Seiko Epson Corporation)
EPSON L3050 Series Printer Uninstall (HKLM\...\EPSON L3050 Series) (Version: - Seiko Epson Corporation)
Epson Photo+ (HKLM-x32\...\{F712E00E-EC00-4A46-B756-9472C3994188}) (Version: 4.0.2.0 - Seiko Epson Corporation)
Epson Print Layout (HKLM\...\{DD6C4E88-D2A7-4B58-BF0A-B59D9C16AA0F}) (Version: 1.5.9 - Seiko Epson Corporation)
Epson Printer Connection Checker (HKLM-x32\...\{3E43D194-E18D-4C8A-B36D-15F14395A0A6}) (Version: 3.4.1.0 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version: - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{C37347BC-7549-47A6-8E7A-806A6751981E}) (Version: 3.00.06 - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\...\{711E8536-AB71-4455-A6C4-357FDBBEBF91}) (Version: 4.6.7 - Seiko Epson Corporation)
FastStone Image Viewer 7.8 (HKLM-x32\...\FastStone Image Viewer) (Version: 7.8 - FastStone Corporation)
FinePrint (HKLM\...\FinePrint) (Version: 12.10 - FinePrint Software)
GBT_MB_Update (HKLM\...\GBT_MB_Update) (Version: 24.06.25.01 - GIGABYTE)
GBT_RGB_Sync_Control 24.06.18.01 (HKLM\...\GBT_RGB_Sync_Control) (Version: 24.06.18.01 - GIGABYTE)
GBT_rgbMotherboard_UC 24.06.20.01 (HKLM\...\GBT_rgbMotherboard_UC) (Version: 24.06.20.01 - GIGABYTE)
GIGABYTE Control Center 24.06.27.01 (HKLM\...\GIGABYTE Control Center) (Version: 24.06.27.01 - GIGABYTE)
GIGABYTE Performance Library (HKLM\...\MBEasyTune) (Version: 24.06.21.01 - GIGABYTE)
GIGABYTE Storage Library (HKLM\...\MBStorage) (Version: 24.06.20.01 - GIGABYTE)
Google Chrome (HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\Google Chrome) (Version: 135.0.7049.115 - Google LLC)
KeePass Password Safe 2.57 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.57 - Dominik Reichl)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.2.3.21 - PandoraTV)
LibreOffice 24.8.4.2 (HKLM\...\{E3618E43-2988-4D1C-AA31-4473B6568DD8}) (Version: 24.8.4.2 - The Document Foundation)
Messenger (HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\0a93669aced325d6c1991ebd989628f4) (Version: 1.0 - Messenger)
Messenger (HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\c1b3adcf-2068-5e8d-b25d-30ce588e3a4c) (Version: 215.6.643112060 - Facebook, Inc.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 136.0.3240.50 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 135.0.3179.98 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\OneDriveSetup.exe) (Version: 25.065.0406.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33130 (HKLM-x32\...\{1de5e707-82da-4db6-b810-5d140cc4cbb3}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.38.33130 (HKLM-x32\...\{2cfeba4a-21f8-4ea7-9927-c5a5c6f13cc9}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33130 (HKLM\...\{C31777DB-51C1-4B19-9F80-38EF5C1D7C89}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33130 (HKLM\...\{1CA7421F-A225-4A9C-B320-A36981A2B789}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33130 (HKLM-x32\...\{5CA9AE7B-2EFC-4F02-81CD-32ABE173C755}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33130 (HKLM-x32\...\{DF1B52DF-C88E-4DDF-956B-6E7A03327F46}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
NVIDIA Ovladače grafiky 560.94 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 560.94 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.1 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM-x32\...\{07236f40-ec25-4646-8cb6-b6aaf1597324}) (Version: 1.1.0.1 - Patriot Memory) Hidden
Příručky společnosti EPSON (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.57.0.0 - Seiko Epson Corporation)
RGB Fusion (HKLM-x32\...\{FFA8F1FA-3C2C-4A94-AC0B-0DF47272C25F}) (Version: 3.24.0318.1 - Gigabyte)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Telegram Desktop (HKU\S-1-5-21-3512291557-84185808-1624565692-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 5.13.1 - Telegram FZ-LLC)
Total Commander 64+32-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 11.03 - Ghisler Software GmbH)
Verbatim_SureFireGaming_Product (HKLM\...\{35CB65C6-A7E3-4EE7-AD40-738D70A72164}) (Version: 1.0.3.11 - Verbatim) Hidden
Verbatim_SureFireGaming_Product (HKLM-x32\...\{d601832a-0d94-46ce-9b19-78e8a5887313}) (Version: 1.0.3.11 - Verbatim) Hidden
WD P40 Game Drive (HKLM\...\{EE55DBAE-ECDD-4ADD-AAB5-23DE848B0996}) (Version: 1.0.2.18 - Western Digital Corporation) Hidden
WD P40 Game Drive (HKLM-x32\...\{72b1a866-fc31-4381-bff3-fa6cd8823777}) (Version: 1.0.2.18 - Western Digital Corporation) Hidden
Zoner Photo Studio 15 (HKLM\...\ZonerPhotoStudio15_CZ_is1) (Version: 15.0.1.5 - ZONER software)

Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3624.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-04-26] (Microsoft Windows)
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-04-26] (Microsoft Windows)
Akce kliknutím (Preview) -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-04-26] (Microsoft Windows)
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-04-26] (Microsoft Windows)
GPX viewer and recorder -> C:\Program Files\WindowsApps\45442stefano64.GPXviewerandrecorder_2.0.0.0_x64__bszswgksnzmf2 [2024-12-28] (stefano64)
Messenger -> C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_2250.1.0.0_x64__8xx8rvfyw5nnt [2025-03-11] (Meta)
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2024-06-21] (Microsoft Corp.)
Microsoft.StartExperiencesApp -> C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.327.0_x64__8wekyb3d8bbwe [2025-05-02] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2024-12-29] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2024-12-11] (Realtek Semiconductor Corp)
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2517.4.0_x64__cv1g1gvanyjgm [2025-05-04] (WhatsApp Inc.) [Startup Task]
WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-29] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_7000.456.1632.0_x64__8wekyb3d8bbwe [2025-04-09] (Microsoft Corp.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3512291557-84185808-1624565692-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\User\AppData\Local\Google\GoogleUpdater\138.0.7156.0\updater.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-3512291557-84185808-1624565692-1001_Classes\CLSID\{547E9AEF-8043-5D26-879F-01E7664192DC}\localserver32 -> C:\Users\User\AppData\Local\Google\GoogleUpdater\138.0.7156.0\updater.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-3512291557-84185808-1624565692-1001_Classes\CLSID\{6DDCE70D-A4AE-4E97-908C-BE7B2DB750AD}\localserver32 -> C:\Users\User\AppData\Local\Google\GoogleUpdater\138.0.7156.0\updater.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-3512291557-84185808-1624565692-1001_Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\localserver32 -> C:\Users\User\AppData\Local\Google\Chrome\Application\135.0.7049.115\notification_helper.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-3512291557-84185808-1624565692-1001_Classes\CLSID\{BB3F5928-173B-5313-A933-4F29B6EA6E06}\localserver32 -> C:\Users\User\AppData\Local\Google\GoogleUpdater\138.0.7156.0\updater.exe (Google LLC -> Google LLC)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\nvshext.dll [2024-11-19] (NVIDIA Corporation -> NVIDIA Corporation)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32-x32: [vidc.XVID] => xvidvfw.dll
HKLM\...\Drivers32-x32: [VIDC.VP80] => vp8vfw.dll

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Messenger.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bbdeiblfgdokhlblpgeaokenkfknecgl --app-url=hxxps://www.messenger.com/?ref=homescreenpwa&__pwa=1 --app-run-on-os-login-mode=windowed --app-launch-source=19
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Messenger.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bbdeiblfgdokhlblpgeaokenkfknecgl --app-url=hxxps://www.messenger.com/?ref=homescreenpwa&__pwa=1 --app-run-on-os-login-mode=windowed --app-launch-source=19

==================== Loaded Modules (Whitelisted) =============

2024-11-13 12:04 - 2024-12-03 22:40 - 005378048 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavcodec-61.dll
2024-11-13 12:04 - 2024-12-03 22:40 - 000875008 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavfilter-10.dll
2024-11-13 12:04 - 2024-12-03 22:40 - 001674240 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavformat-61.dll
2024-11-13 12:04 - 2024-12-03 22:40 - 001640960 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavutil-59.dll
2024-11-13 12:04 - 2024-12-03 22:40 - 000630272 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libswresample-5.dll
2024-11-13 12:04 - 2024-12-03 22:40 - 001092608 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libswscale-8.dll
2017-02-13 14:54 - 2017-02-13 14:54 - 000132096 _____ (Seiko Epson Corporation) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\epnsm.dll
2009-10-21 17:39 - 2009-10-21 17:39 - 000291328 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\LcMgr.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2022-05-07 07:24 - 2022-05-07 07:22 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3512291557-84185808-1624565692-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\Downloads\1324829.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek Gaming 2.5GbE Family Controller -> rt25cx21x64.sys

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{C4A4AD8F-1C0D-4428-8FEA-1A79ADC35D6B}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{650F1AD5-EDBE-496E-83A8-CEFDB1B0A865}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{CCBAEDBC-26E7-4F8C-A609-933321AD8EA1}] => (Allow) C:\Program Files\GIGABYTE\Control Center\GCC.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [UDP Query User{9B330EB7-EDD7-43CB-805A-D8AF3D9420B7}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Block) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe (GAIJIN NETWORK LTD -> Gaijin Entertainment)
FirewallRules: [TCP Query User{8105692F-544B-44DA-85DB-F75077706880}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Block) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe (GAIJIN NETWORK LTD -> Gaijin Entertainment)
FirewallRules: [{B909A86E-85BF-46BE-A35B-35BF2837C031}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\War Thunder\launcher.exe (GAIJIN NETWORK LTD -> Gaijin)
FirewallRules: [{2DFAEB42-374F-4913-9905-AFBFE766DEEB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\War Thunder\launcher.exe (GAIJIN NETWORK LTD -> Gaijin)
FirewallRules: [{E409F83F-8559-421E-937E-7F3B13C6096C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\War Thunder\eac_wt_mlauncher.exe (Gaijin Entertainment) [File not signed]
FirewallRules: [{5CDE2A3F-1819-4155-97BB-B94D65D6F970}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\War Thunder\eac_wt_mlauncher.exe (Gaijin Entertainment) [File not signed]
FirewallRules: [{A0DD7323-44E6-45C7-8797-939BECDD4D1F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{9CC005C7-3E48-4B9F-B839-E7D5C6E47FED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{335402FA-6D27-4EC8-9CCB-39C83A3CFFC9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{07931F4F-07EB-4848-AB7E-FB94B380E182}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [UDP Query User{1B2A1788-71BD-48EE-897A-123430A96B4A}C:\users\user\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\user\appdata\local\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{A238CACB-1285-41FF-B81F-4ED6D01D68A2}C:\users\user\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\user\appdata\local\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{60DED7CB-C68C-45B5-9988-6CC70862D140}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24295.605.3225.8804_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7450C3C4-2676-44BF-8D8D-74E1E6D5119E}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24295.605.3225.8804_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP-V2] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP-NoScope] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{DF161784-F578-47CB-A1A9-87FDFC758F18}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\135.0.3179.98\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

30-04-2025 14:07:52 Windows Update
04-05-2025 13:04:02 Windows Update
04-05-2025 13:04:05 Windows Update
04-05-2025 13:04:07 Windows Update

==================== Faulty Device Manager Devices ============
Name: Skenovací zařízení USB
Description: Skenovací zařízení USB
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbscan
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (04/29/2025 03:42:03 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-R93ONLB)
Description: Název chybující aplikace: KMPlayer.exe, verze: 4.2.3.21, časové razítko: 0x67889952
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.26100.3912, časové razítko: 0xe47d5b78
Kód výjimky: 0xc0000005
Posun chyby: 0x000973be
ID chybujícího procesu: 0x4040
Čas spuštění chybující aplikace: 0x1dbb90c7a31c989
Cesta k chybující aplikaci: C:\Users\User\KMPlayer\KMPlayer.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID sestavy: bc6dec25-7f31-4dd9-ba20-b2cb346418e8
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (04/29/2025 03:30:45 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-R93ONLB)
Description: Název chybující aplikace: KMPlayer.exe, verze: 4.2.3.21, časové razítko: 0x67889952
Název chybujícího modulu: ntdll.dll, verze: 10.0.26100.3912, časové razítko: 0xb172bb62
Kód výjimky: 0xc0000005
Posun chyby: 0x000938df
ID chybujícího procesu: 0xd60
Čas spuštění chybující aplikace: 0x1dbb90ae6912a5b
Cesta k chybující aplikaci: C:\Users\User\KMPlayer\KMPlayer.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID sestavy: c9e1ff81-14d6-448f-9ab1-6b30b1be4512
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (04/29/2025 03:30:13 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-R93ONLB)
Description: Název chybující aplikace: KMPlayer.exe, verze: 4.2.3.21, časové razítko: 0x67889952
Název chybujícího modulu: ntdll.dll, verze: 10.0.26100.3912, časové razítko: 0xb172bb62
Kód výjimky: 0xc0000005
Posun chyby: 0x0004fd18
ID chybujícího procesu: 0x3994
Čas spuštění chybující aplikace: 0x1dbb90ad2fd1be8
Cesta k chybující aplikaci: C:\Users\User\KMPlayer\KMPlayer.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID sestavy: 1fd4ac28-1c22-49e7-a278-68e90a5a0276
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (04/26/2025 10:30:24 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..

Error: (04/26/2025 10:30:24 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]

Error: (04/26/2025 10:29:48 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: bad_module_info, verze: 0.0.0.0, časové razítko: 0x00000000
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0x00000000
Posun chyby: 0x0000000000000000
ID chybujícího procesu: 0xb4c
Čas spuštění chybující aplikace: 0x1dbb555b12725a9
Cesta k chybující aplikaci: bad_module_info
Cesta k chybujícímu modulu: unknown
ID sestavy: 36a62cb2-22bf-4496-b752-b216d2119039
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (04/24/2025 10:15:09 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..

Error: (04/24/2025 10:15:09 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]


System errors:
=============
Error: (05/05/2025 08:06:54 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-R93ONLB)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (05/05/2025 07:36:54 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (05/05/2025 07:27:31 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-R93ONLB)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (05/05/2025 07:17:28 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (05/04/2025 03:58:53 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (05/04/2025 01:43:59 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80073d02): 9PC1H9VN18CM-Microsoft.StartExperiencesApp.

Error: (05/04/2025 01:43:58 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80073d02): 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.

Error: (05/04/2025 01:04:25 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80073d02): 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.


Windows Defender:
================
Date: 2025-05-05 19:45:03
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Name: PUA:Win32/Linkury
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\$Recycle.Bin\S-1-5-21-3512291557-84185808-1624565692-1001\$RVXZVZF.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: User
Process Name: Unknown
Security intelligence Version: AV: 1.427.618.0, AS: 1.427.618.0, NIS: 1.427.618.0
Engine Version: AM: 1.1.25030.1, NIS: 1.1.25030.1

Date: 2025-05-04 13:43:40
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2025-05-02 12:45:09
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2025-04-30 14:19:31
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2025-04-29 15:09:07
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]

Date: 2025-05-05 19:27:33
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.427.618.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.25030.1
Error code: 0x8024001e
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

==================== Memory info ===========================

BIOS: American Megatrends International, LLC. F2 08/09/2023
Motherboard: Gigabyte Technology Co., Ltd. B650M D3HP
Processor: AMD Ryzen 5 7600 6-Core Processor
Percentage of memory in use: 43%
Total physical RAM: 15511.22 MB
Available physical RAM: 8779.68 MB
Total Virtual: 16535.22 MB
Available Virtual: 7719.67 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:953 GB) (Free:501.93 GB) (Model: Lexar SSD NM620 1TB) NTFS

\\?\Volume{ea2a5f14-edf7-490a-9c14-2473230caad8}\ () (Fixed) (Total:0.75 GB) (Free:0.18 GB) NTFS
\\?\Volume{85fbe190-6058-4e99-8e42-8192e5a8fd0e}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 953.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119316
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: vyskakují okna s hrozbou

#2 Příspěvek od Rudy »

Zdravím!
Hrozbu dává antivir, prohlížeč, nebo jiný program? Nadpis "Vyskakují okna s hrozbnou" bez dalšího komentáře je nicneříkající.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

Re: vyskakují okna s hrozbou

#3 Příspěvek od ouhara »

Dobrý den, omlouvám se za neúplnou informaci, okna vyskakují po otevření prohlížeče. Nejsou ale v prohlížeči, ale na něm. po zavření prohlížeče zůstanou na ploše.
Nejsem v počítačích úplně zdatný, tak se ještě jednou omlouvám. Děkuji, Kůrka

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119316
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: vyskakují okna s hrozbou

#4 Příspěvek od Rudy »

OK. Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
C:\$Recycle.Bin\S-1-5-21-3512291557-84185808-1624565692-1001\$RVXZVZF.exe

EmptyTemp:
End
Uložte do C:\Users\User\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Po ukončení čisticího procesu FRST spusťte ještě tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

Re: vyskakují okna s hrozbou

#5 Příspěvek od ouhara »

# -------------------------------
# Malwarebytes AdwCleaner 8.5.1.601
# -------------------------------
# Build: 03-26-2025
# Database: 2025-04-04.3 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 05-07-2025
# Duration: 00:00:01
# OS: Windows 11 (Build 26100.3915)
# Cleaned: 4
# Failed: 4


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

Not Deleted akaelkiagnbfcccfnmbimdbplecgbikh
Not Deleted akaelkiagnbfcccfnmbimdbplecgbikh

***** [ Chromium URLs ] *****

Deleted SweetIM Search
Deleted SweetIM Search
Deleted webssearches
Deleted webssearches
Not Deleted webssearches
Not Deleted webssearches

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2042 octets] - [06/05/2025 23:47:31]
AdwCleaner[C00].txt - [1976 octets] - [06/05/2025 23:47:59]
AdwCleaner[S01].txt - [1883 octets] - [07/05/2025 09:37:29]
AdwCleaner[C01].txt - [1925 octets] - [07/05/2025 09:37:48]
AdwCleaner[S02].txt - [2005 octets] - [07/05/2025 10:26:29]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119316
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: vyskakují okna s hrozbou

#6 Příspěvek od Rudy »

OK. Problém ustal?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

Re: vyskakují okna s hrozbou

#7 Příspěvek od ouhara »

Dobrý den, bohužel ne. Už jdou okna odstranit, ale po otevření prohlížeče tam vlezou. Kůrka

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119316
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: vyskakují okna s hrozbou

#8 Příspěvek od Rudy »

OK. Spusťte postupně tyto utility:

1. Stahnete Zoek.exe https://sdilej.cz/29519076/zoek.rar a ulozte jej na plochu

Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
Do okna vlozte skript nize




autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;





Nasledne kliknete na Run Script
PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem.

a

2. Junkware removal tool: https://www.stahuj.cz/utility_a_ostatni ... oval-tool/
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

Re: vyskakují okna s hrozbou

#9 Příspěvek od ouhara »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by User (Administrator) on 07.05.2025 at 20:50:39,14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 2

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.05.2025 at 20:51:38,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119316
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: vyskakují okna s hrozbou

#10 Příspěvek od Rudy »

A Zoek?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

Re: vyskakují okna s hrozbou

#11 Příspěvek od ouhara »

Opět má neznalost. Chtěl jsem poslat oboje zaráz a Zoe asi zmizel.
Mám ho udělat ještě jednou ?
Jen pro info okna vyskakují stále. Kůrka

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119316
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: vyskakují okna s hrozbou

#12 Příspěvek od Rudy »

Udělějte znovu a rád bych viděl to okno (alespoň jednno). Dejte sem screen.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

Re: vyskakují okna s hrozbou

#13 Příspěvek od ouhara »

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by User on 08.05.2025 at 15:18:06,78.
Microsoft Windows 11 Home 10.0.26100 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\User\AppData\Local\Temp\2cfd62b0-61fb-4b03-9911-faf6a39da6b9_zoek.rar.6b9\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2025-05-07-184522.log 260151 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\Program Files\ModifiableWindowsApps

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8b3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8b5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8c6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8c8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8ca.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8ce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8d2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8e4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8e6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8e8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8ec.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8ee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a8f0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a902.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a904.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a906.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a908.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a90a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a90c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a91d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b0c-334-28a91f.tmp deleted
"C:\DumpStack.log.tmp" not deleted

==== Chromium Look ======================


passwords - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik
IITC Button - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\febaefghpimpenpigafpolgljcfkeakn
Full Screen Weather - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg
Avast Online Security & Privacy - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
FormApps Extension - User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi
Wednesday Addams Browser Theme - User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lkplodmbckgmpcmiekhnfihkoaagioni
Edge relevant text changes - User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha

==== Chromium Startpages ======================

C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences
{"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"account_extension_type":0,"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13391117152830142","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117152830142","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Objevte skvělé aplikace, hry, rozšíření a motivy prohlížeče Google Chrome.","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Obchod Chrome","permissions":["webstorePrivate","management","system.cpu","system.display","system.memory","system.network","system.storage"],"version":"0.2"},"needs_sync":true,"page_ordinal":"n","path":"C:\\Users\\User\\AppData\\Local\\Google\\Chrome\\Application\\135.0.7049.117\\resources\\web_store","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"lkplodmbckgmpcmiekhnfihkoaagioni":{"account_extension_type":0,"active_bit":false,"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"allowlist":1,"commands":{},"content_settings":[],"creation_flags":9,"cws-info":{"is-live":true,"is-present":true,"last-updated-time-millis":"1671091200000","no-privacy-practice":false,"unpublished-long-ago":false,"violation-type":0},"events":[],"first_install_time":"13391119102583637","from_webstore":true,"granted_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391119102583637","location":1,"manifest":{"description":"","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhKZNQX/OU0/OAg0G6i82GvwEVb90ye/W3nnu+UyZ04MwccN5J53apZ1clmEOGolZprAkGzySFFGP69QLnsYtxL6mh7tt6nMp1sHUrdQ74UdwisEiN47KZZMsuYBPwwOGDNNwLCxFh6Gv5BVmzh4tYWYmwQnqZe49lxoCTgoYzSrL441jUXDlpfntd6a3bZstx6gsWrw0CS7ehMzUs3QKK7w32MAlEmTbKMXoVco6DuThGYx41DfpLHSsYHfY4up/AI8efC5pd6NeiLi35+WJTU7wsyLdtyVcDSn9EsOo1/SNxASleWTFHgFljL+1F1b1C513k2WqGoGXC0yi5IxQZwIDAQAB","manifest_version":3,"name":"Wednesday Addams Browser Theme","theme":{"colors":{"bookmark_text":[11,15,48],"button_background":[0,0,0,0],"frame":[11,15,48],"ntp_background":[11,15,48],"ntp_link":[255,255,255],"ntp_text":[255,255,255],"tab_background_text":[166,166,215],"tab_text":[11,15,48],"toolbar":[166,166,215]},"images":{"theme_frame":"images/theme_frame.png","theme_ntp_background":"images/theme_ntp_background.jpeg","theme_tab_background":"images/theme_tab_background.png","theme_toolbar":"images/theme_toolbar.png"},"properties":{"ntp_background_alignment":"top","ntp_background_repeat":"no-repeat"},"tints":{"buttons":[0.65,0.63,0.12]}},"update_url":"https://clients2.google.com/service/upd ... ons":{"api":["contentSettings","fileSystem","fileSystem.write","metricsPrivate","tabs","resourcesPrivate","pdfViewerPrivate"],"explicit_host":["chrome://resources/*","chrome://webui-test/*"],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13391117152830587","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117152830587","location":5,"manifest":{"content_security_policy":"script-src 'self' 'wasm-eval' blob: filesystem: chrome://resources chrome://webui-test; object-src * blob: externalfile: file: filesystem: data:","description":"","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDN6hM0rsDYGbzQPQfOygqlRtQgKUXMfnSjhIBL7LnReAVBEd7ZmKtyN2qmSasMl4HZpMhVe2rPWVVwBDl6iyNE/Kok6E6v6V3vCLGsOpQAuuNVye/3QxzIldzG/jQAdWZiyXReRVapOhZtLjGfywCvlWq7Sl/e3sbc0vWybSDI2QIDAQAB","manifest_version":2,"mime_types":["application/pdf"],"mime_types_handler":"index.html","name":"Chrome PDF Viewer","offline_enabled":true,"permissions":["chrome://resources/","chrome://webui-test/","contentSettings","metricsPrivate","pdfViewerPrivate","resourcesPrivate","tabs",{"fileSystem":["write"]}],"version":"1"},"path":"C:\\Users\\User\\AppData\\Local\\Google\\Chrome\\Application\\135.0.7049.117\\resources\\pdf","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"neajdppkdcdipfabeoofebfddakdcjhd":{"account_extension_type":0,"active_permissions":{"api":["metricsPrivate","systemPrivate","ttsEngine"],"explicit_host":["https://www.google.com/*"],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["ttsEngine.onPause","ttsEngine.onResume","ttsEngine.onSpeak","ttsEngine.onStop"],"first_install_time":"13391117152831178","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117152831178","location":5,"manifest":{"background":{"persistent":false,"scripts":["tts_extension.js"]},"description":"Component extension providing speech via the Google network text-to-speech service.","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8GSbNUMGygqQTNDMFGIjZNcwXsHLzkNkHjWbuY37PbNdSDZ4VqlVjzbWqODSe+MjELdv5Keb51IdytnoGYXBMyqKmWpUrg+RnKvQ5ibWr4MW9pyIceOIdp9GrzC1WZGgTmZismYR3AjaIpufZ7xDdQQv+XrghPWCkdVqLN+qZDA1HU+DURznkMICiDDSH2sU0egm9UbWfS218bZqzKeQDiC3OnTPlaxcbJtKUuupIm5knjze3Wo9Ae9poTDMzKgchg0VlFCv3uqox+wlD8sjXBoyBCCK9HpImdVAF1a7jpdgiUHpPeV/26oYzM9/grltwNR3bzECQgSpyXp0eyoegwIDAQAB","manifest_version":2,"name":"Google Network Speech","permissions":["metricsPrivate","systemPrivate","ttsEngine","https://www.google.com/"],"tts_engine":{"voices":[{"event_types":["start","end","error"],"gender":"female","lang":"de-DE","remote":true,"voice_name":"Google Deutsch"},{"event_types":["start","end","error"],"gender":"female","lang":"en-US","remote":true,"voice_name":"Google US English"},{"event_types":["start","end","error"],"gender":"female","lang":"en-GB","remote":true,"voice_name":"Google UK English Female"},{"event_types":["start","end","error"],"gender":"male","lang":"en-GB","remote":true,"voice_name":"Google UK English Male"},{"event_types":["start","end","error"],"gender":"female","lang":"es-ES","remote":true,"voice_name":"Google español"},{"event_types":["start","end","error"],"gender":"female","lang":"es-US","remote":true,"voice_name":"Google español de Estados Unidos"},{"event_types":["start","end","error"],"gender":"female","lang":"fr-FR","remote":true,"voice_name":"Google français"},{"event_types":["start","end","error"],"gender":"female","lang":"hi-IN","remote":true,"voice_name":"Google हिन्दी"},{"event_types":["start","end","error"],"gender":"female","lang":"id-ID","remote":true,"voice_name":"Google Bahasa Indonesia"},{"event_types":["start","end","error"],"gender":"female","lang":"it-IT","remote":true,"voice_name":"Google italiano"},{"event_types":["start","end","error"],"gender":"female","lang":"ja-JP","remote":true,"voice_name":"Google 日本語"},{"event_types":["start","end","error"],"gender":"female","lang":"ko-KR","remote":true,"voice_name":"Google 한국의"},{"event_types":["start","end","error"],"gender":"female","lang":"nl-NL","remote":true,"voice_name":"Google Nederlands"},{"event_types":["start","end","error"],"gender":"female","lang":"pl-PL","remote":true,"voice_name":"Google polski"},{"event_types":["start","end","error"],"gender":"female","lang":"pt-BR","remote":true,"voice_name":"Google português do Brasil"},{"event_types":["start","end","error"],"gender":"female","lang":"ru-RU","remote":true,"voice_name":"Google русский"},{"event_types":["start","end","error"],"gender":"female","lang":"zh-CN","remote":true,"voice_name":"Google 普通话(中国大陆)"},{"event_types":["start","end","error"],"gender":"female","lang":"zh-HK","remote":true,"voice_name":"Google 粤語(香港)"},{"event_types":["start","end","error"],"gender":"female","lang":"zh-TW","remote":true,"voice_name":"Google 國語(臺灣)"}]},"version":"1.0"},"path":"C:\\Users\\User\\AppData\\Local\\Google\\Chrome\\Application\\135.0.7049.117\\resources\\network_speech_synthesis","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"nkeimhogjdpnpccoofpliimaahmaaome":{"account_extension_type":0,"active_permissions":{"api":["processes","webrtcLoggingPrivate","system.cpu","enterprise.hardwarePlatform"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["runtime.onConnectExternal"],"first_install_time":"13391117152830902","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117152830902","location":5,"manifest":{"background":{"page":"background.html","persistent":false},"externally_connectable":{"matches":["https://*.meet.google.com/*"]},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB","manifest_version":2,"name":"Google Hangouts","permissions":["enterprise.hardwarePlatform","processes","system.cpu","webrtcLoggingPrivate"],"version":"1.3.23"},"path":"C:\\Users\\User\\AppData\\Local\\Google\\Chrome\\Application\\135.0.7049.117\\resources\\hangout_services","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"nmmhkkegccagdldgiimedpiccmgmieda":{"account_extension_type":0,"ack_external":true,"active_bit":false,"active_permissions":{"api":["identity","webview"],"explicit_host":["https://payments.google.com/*","https:/ ... eapis.com/*"],"manifest_permissions":[],"scriptable_host":[]},"allowlist":1,"commands":{},"content_settings":[],"creation_flags":137,"cws-info":{"is-live":true,"is-present":true,"last-updated-time-millis":"1611820800000","no-privacy-practice":false,"unpublished-long-ago":false,"violation-type":0},"events":["app.runtime.onLaunched","runtime.onConnectExternal"],"first_install_time":"13391117156123965","from_webstore":true,"granted_permissions":{"api":["identity","webview"],"explicit_host":["https://payments.google.com/*","https:/ ... eapis.com/*"],"manifest_permissions":[],"scriptable_host":[]},"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117156123965","lastpingday":"13391074800108340","location":10,"manifest":{"app":{"background":{"scripts":["craw_background.js"]}},"current_locale":"cs","default_locale":"en","description":"Platby Internetového obchodu Chrome","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"128":"images/icon_128.png","16":"images/icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrKfMnLqViEyokd1wk57FxJtW2XXpGXzIHBzv9vQI/01UsuP0IV5/lj0wx7zJ/xcibUgDeIxobvv9XD+zO1MdjMWuqJFcKuSS4Suqkje6u+pMrTSGOSHq1bmBVh0kpToN8YoJs/P/yrRd7FEtAXTaFTGxQL4C385MeXSjaQfiRiQIDAQAB","manifest_version":2,"minimum_chrome_version":"29","name":"Platby Internetového obchodu Chrome","oauth2":{"auto_approve":true,"client_id":"203784468217.apps.googleusercontent.com","scopes":["https://www.googleapis.com/auth/sierra" ... e.readonly"]},"permissions":["identity","webview","https://www.google.com/","https://www.g ... egrator.js"],"update_url":"https://clients2.google.com/service/upd ... 3394520726"}}}}

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Preferences
{"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"account_extension_type":0,"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":[],"first_install_time":"13391117140970617","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140970617","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Objevte rozšíření pro Microsoft Edge.","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Internetový obchod","permissions":["webstorePrivate","management","system.cpu","system.display","system.memory","system.network","system.storage"],"version":"0.2"},"needs_sync":true,"page_ordinal":"n","path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\web_store","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"ahokoikenoafgppiblgpenaaaolecifn":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"cjneempfhkonkkbcmnfdibgobmhbagaj":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"dcaajljecejllikfgbhjdgeognacjkkp":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"dgiklkfkllikcanfonkcabmbdfmgleag":{"account_extension_type":0,"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":[],"first_install_time":"13391117140971582","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140971582","location":5,"manifest":{"content_capabilities":{"include_globs":["https://*excel.officeapps.live.com/*","https://*onenote.officeapps.live.com/*","https://*powerpoint.officeapps.live.com/*","https://*word-edit.officeapps.live.com/*","https://*excel.officeapps.live.com.mcas.ms/*","https://*onenote.officeapps.live.com.mcas.ms/*","https://*word-edit.officeapps.live.com.mcas.ms/*","https://*excel.partner.officewebapps.cn/*","https://*onenote.partner.officewebapps.cn/*","https://*powerpoint.partner.officewebapps.cn/*","https://*word-edit.partner.officewebapps.cn/*","https://*excel.gov.online.office365.us/*","https://*onenote.gov.online.office365.us/*","https://*powerpoint.gov.online.office365.us/*","https://*word-edit.gov.online.office365.us/*","https://*excel.dod.online.office365.us/*","https://*onenote.dod.online.office365.us/*","https://*powerpoint.dod.online.office365.us/*","https://*word-edit.dod.online.office365.us/*","https://*visio.partner.officewebapps.cn/*","https://*visio.gov.online.office365.us/*","https://*visio.dod.online.office365.us/*"],"matches":["https://*.officeapps.live.com/*","https://*.officeapps.live.com.mcas.ms/*","https://*.partner.officewebapps.cn/*","https://*.gov.online.office365.us/*","https://*.dod.online.office365.us/*","https://*.app.whiteboard.microsoft.com/*","https://*.whiteboard.office.com/*","https://*.app.int.whiteboard.microsoft.com/*","https://*.whiteboard.office365.us/*","https://*.dev.whiteboard.microsoft.com/*"],"permissions":["clipboardRead","clipboardWrite"]},"default_locale":"en","description":"This extension grants Microsoft web sites permission to read and write from the clipboard.","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCz4t/X7GeuP6GBpjmxndrjtzF//4CWeHlC68rkoV7hP3h5Ka6eX7ZMNlYJkSjmB5iRmPHO5kR1y7rGY8JXnRPDQh/CQNLVA7OsKeV6w+UO+vx8KGI+TrTAhzH8YGcMIsxsUjxtC4cBmprja+xDr0zVp2EMgqHu+GBKgwSRHTkDuwIDAQAB","manifest_version":2,"minimum_chrome_version":"77","name":"Microsoft Clipboard Extension","version":"1.0"},"path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\edge_clipboard","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"ehlmnljdoejdahfjdfobmpfancoibmig":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"fikbjbembnmfhppjfnmfkahdhfohhjmg":{"account_extension_type":0,"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":[],"first_install_time":"13391117140972290","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140972290","location":5,"manifest":{"background":{"persistent":false,"scripts":["background.js"]},"externally_connectable":{"matches":["https://*.microsoftstream.com/*"]},"incognito":"split","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsAmDrYmQaYQlLxSAn/jTQTGNt1IffJGIJeKucE/B42d8QIyFD2RCarmHP1bmbY1YuTng2dL3J//qyvUNwXPt9cmxH9WKwi512tzOa5r2zYaCuOgP2vAIrah/bKnpO3XmUfFWj+LRcbZahOmMDMQxzPKxFKuIz2eOiakBXDE6Ok7azHJ13LLQTte1JgZIPmyFrAciPABLp/IKLfsfnebVW1YgaOyxBNyp/7bhSmoyZI3kBv8InKOpGE8pttrBg6l5zkvD67a7ViNAYkqZIpJJV5ZTQtVWCWSG0xU2y+3zXZtx8KbGbDiWUAcwNYDVPpsV+IQXVpgAplHvrZme+hAl6QIDAQAB","manifest_version":2,"name":"Media Internals Services Extension","permissions":["mediaInternalsPrivate"],"version":"2.0.0"},"path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\media_internals_services","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"fjngpfnaikknjdhkckmncgicobbkcnle":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"gbihlnbpmfkodghomcinpblknjhneknc":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"gbmoeijgfngecijpcnbooedokgafmmji":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"gcinnojdebelpnodghnoicmcdmamjoch":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"gecfnmoodchdkebjjffmdcmeghkflpib":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"ghbmnnjooekpmoecnnnilnnbdlolhkhi":{"account_extension_type":0,"ack_external":true,"active_permissions":{"api":["alarms","storage","unlimitedStorage","offscreen"],"explicit_host":["https://docs.google.com/*","https://drive.google.com/*"],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1048713,"disable_reasons":[134217728],"edge_last_update_check_time":"13391117142274052","first_install_time":"13391117142273644","from_webstore":true,"granted_permissions":{"api":["alarms","storage","unlimitedStorage","offscreen"],"explicit_host":["https://docs.google.com/*","https://drive.google.com/*"],"manifest_permissions":[],"scriptable_host":[]},"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117142273644","location":6,"manifest":{"author":{"email":"docs-hosted-app-own@google.com"},"background":{"service_worker":"service_worker_bin_prod.js"},"content_capabilities":{"matches":["https://docs.google.com/*","https://dri ... oogle.com/*"],"permissions":["clipboardRead","clipboardWrite","unlimitedStorage"]},"content_security_policy":{"extension_pages":"script-src 'self'; object-src 'self'"},"current_locale":"cs","default_locale":"en_US","description":"Upravujte, vytvářejte a zobrazujte své dokumenty, tabulky a prezentace – vše bez přístupu k internetu.","externally_connectable":{"matches":["https://docs.google.com/*","https://dri ... oogle.com/*"]},"host_permissions":["https://docs.google.com/*","https://drive.google.com/*"],"icons":{"128":"128.png"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnF7RGLAxIon0/XeNZ4MLdP3DMkoORzEAKVg0sb89JpA/W2osTHr91Wqwdc9lW0mFcSpCYS9Y3e7cUMFo/M2ETASIuZncMiUzX2/0rrWtGQ3UuEj3KSe5PdaVZfisyJw/FebvHwirEWrhqcgzVUj9fL9YjE0G45d1zMKcc1umKvLqPyTznNuKBZ9GJREdGLRJCBmUgCkI8iwtwC+QZTUppmaD50/ksnEUXv+QkgGN07/KoNA5oAgo49Jf1XBoMv4QXtVZQlBYZl84zAsI82hb63a6Gu29U/4qMWDdI7+3Ne5TRvo6Zi3EI4M2NQNplJhik105qrz+eTLJJxvf4slrWwIDAQAB","manifest_version":3,"minimum_chrome_version":"88","name":"Dokumenty Google offline","permissions":["alarms","storage","unlimitedStorage","offscreen"],"storage":{"managed_schema":"dasherSettingSchema.json"},"update_url":"https://clients2.google.com/service/upd ... _resources":[{"matches":["\u003Call_urls>"],"resources":["page_embed_script.js"]}]},"path":"ghbmnnjooekpmoecnnnilnnbdlolhkhi\\1.91.1_1","pending_on_installed_event_dispatch_info":{"previous_version":""},"preferences":{},"regular_only_preferences":{},"was_installed_by_default":true,"was_installed_by_oem":false,"withholding_permissions":false},"hfmgbegjielnmfghmoohgmplnpeehike":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"iglcjdemknebjbklcgkfaebgojjphkec":{"account_extension_type":0,"active_permissions":{"api":["identity","management","metricsPrivate","webstorePrivate","hubPrivate"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"w","commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":[],"first_install_time":"13391117140971343","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140971343","location":5,"manifest":{"app":{"launch":{"web_url":"https://microsoftedge.microsoft.com"},"urls":["https://microsoftedge.microsoft.com"]},"description":"Objevte rozšíření pro Microsoft Edge.","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtMvN4+y6cd3el/A/NT5eUnrz1WiD1WJRaJfMBvaMtJHIuFGEmYdYL/YuE74J19+pwhjOHeFZ3XUSMTdOa5moOaXXvdMr5wWaaN2frHewtAnNDO64NGbbZvdsfGm/kRkHKVGNV6dacZsAkylcz5CkwTmq97wOZ7ETaShHvhZEGwRQIt4K1poxurOkDYQw9ERZNf3fgYJ9ZTrLZMAFDLJY+uSF03pClWrr8VGc8LUQ4Naktb8QSgVUlrS14AdF/ESdbhnTvvdB0e7peNWRyoNtCqLJsbtTtBL6sOnqfusnwPowuueOFI+XskOT9TvLo6PcgxhLX5+d0mM+Jtn6PFTU8QIDAQAB","name":"Microsoft Store","permissions":["webstorePrivate","management","metricsPrivate","identity","hubPrivate"],"version":"0.2"},"needs_sync":true,"page_ordinal":"n","path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\microsoft_web_store","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"ihmafllikibpmigkcoadcmckbfhibefp":{"account_extension_type":0,"active_permissions":{"api":["debugger","feedbackPrivate","fileSystem","fileSystem.write","app.window.fullscreen","metricsPrivate","storage","tabs","fileSystem.readFullPath","edgeInternetConnectivityPrivate"],"explicit_host":["edge://resources/*"],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":["edgeFeedbackPrivate.onFeedbackRequested"],"first_install_time":"13391117140972025","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140972025","location":5,"manifest":{"app":{"background":{"scripts":["js/event_handler.js"]},"content_security_policy":"default-src 'none'; script-src 'self' blob: filesystem: chrome://resources; style-src 'unsafe-inline' blob: chrome: file: filesystem: data: *; img-src * blob: chrome: file: filesystem: data:; media-src 'self' blob: filesystem:; connect-src data:"},"description":"User feedback extension","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"128":"images/icon128.png","16":"images/icon16.png","192":"images/icon192.png","32":"images/icon32.png","48":"images/icon48.png"},"incognito":"split","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAl3vxWwvLjcMIFK4OfG6C8PmJkMhFYDKRnx+SqG23YlMG1A+bOkiNmAN1TWpFPPp1f2PpbiZGNq1y29u/QfkD+PC4bnO7GbNw/2X5tGoP0n2K+KGGAxhnr0ki/oyo2eiFGSTOXlQvTRo5q1vB+Lbg+9TbFsWKlHZyAkeZ/YGz/iijHTqw8Q4RWdl5Tp8SlUhS/92EsWhveNJLW22veaT/Up2iSeSSwfyoHVYy8LUPaD4fbyLvPQacVLJq1dac2bNDqjaNvSPgPWCnkZtDmawZrgxT53otLCES/e96xfAf8I24VHIc1pVP8LqdqKr1AV1Yxn93h3VJ2QejtEhIAWHU6QIDAQAB","manifest_version":2,"name":"Edge Feedback","permissions":["chrome://resources/","debugger","edgeInternetConnectivityPrivate","feedbackPrivate",{"fileSystem":["readFullPath","write"]},"fullscreen","metricsPrivate","storage","windows"],"version":"1.0.0.1"},"path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\edge_feedback","preferences":{},"regular_only_preferences":{},"running":false,"was_installed_by_default":false,"was_installed_by_oem":false},"jbleckejnaboogigodiafflhkajdmpcl":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"jdiccldimpdaibmpdkjnbmckianbfold":{"account_extension_type":0,"active_permissions":{"api":["activeTab","metricsPrivate","storage","systemPrivate","ttsEngine","errorReporting"],"explicit_host":["https://*.bing.com/*"],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":["ttsEngine.onPause","ttsEngine.onResume","ttsEngine.onSpeak","ttsEngine.onStop"],"first_install_time":"13391117140972783","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140972783","location":5,"manifest":{"background":{"persistent":false,"scripts":["lifetimeHelper.js","telemetryHelper.js","errorHelper.js","voiceList/voiceListRequester.js","voiceList/voiceListSingleton.js","voiceList/voiceModel.js","manifestHelper.js","config.js","ssml.js","uuid.js","wordBoundary.js","audioStreamer.js","wordBoundaryEventManager.js","audioViewModel.js","background.js"]},"description":"Provides access to Microsoft's online text-to-speech voices","key":"AAAAB3NzaC1yc2EAAAADAQABAAAAgQDjGOAV6/3fmEtQmFqlmqm5cZ+jlNhd6XikwMDp0I7BKh+AjG3aBIG/qqwlsF/7LAGatnSxBwUwZC0qMnGXtcOPVl26Q8OvMx0gt5Va5gxca+ae0Skluj9WN9TNxPFVhw21WbCt4D9q3kb+XXDlx/7v1ktYus4Fwr/skkjADG9cIQ==","manifest_version":2,"name":"Microsoft Voices","permissions":["activeTab","errorReporting","metricsPrivate","storage","systemPrivate","ttsEngine","https://*.bing.com/"],"tts_engine":{"voices":[{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"en-US","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (en-US, AriaNeural)","voice_name":"Microsoft Aria Online (Natural) - English (United States)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"en-US","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (en-US, GuyNeural)","voice_name":"Microsoft Guy Online (Natural) - English (United States)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"zh-CN","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (zh-CN, XiaoxiaoNeural)","voice_name":"Microsoft Xiaoxiao Online (Natural) - Chinese (Mainland)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"zh-CN","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (zh-CN, YunyangNeural)","voice_name":"Microsoft Yunyang Online (Natural) - Chinese (Mainland)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"zh-TW","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (zh-TW, HanHanRUS)","voice_name":"Microsoft HanHan Online - Chinese (Taiwan)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"zh-HK","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (zh-HK, TracyRUS)","voice_name":"Microsoft Tracy Online - Chinese (Hong Kong)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"ja-JP","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (ja-JP, NanamiNeural)","voice_name":"Microsoft Nanami Online (Natural) - Japanese (Japan)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"en-GB","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (en-GB, LibbyNeural)","voice_name":"Microsoft Libby Online (Natural) - English (United Kingdom)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"pt-BR","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (pt-BR, FranciscaNeural)","voice_name":"Microsoft Francisca Online (Natural) - Portuguese (Brazil)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"es-MX","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (es-MX, DaliaNeural)","voice_name":"Microsoft Dalia Online (Natural) - Spanish (Mexico)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"en-IN","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (en-IN, PriyaRUS)","voice_name":"Microsoft Priya Online - English (India)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"en-CA","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (en-CA, HeatherRUS)","voice_name":"Microsoft Heather Online - English (Canada)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"fr-CA","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (fr-CA, SylvieNeural)","voice_name":"Microsoft Sylvie Online (Natural) - French (Canada)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"fr-FR","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (fr-FR, DeniseNeural)","voice_name":"Microsoft Denise Online (Natural) - French (France)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"de-DE","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (de-DE, KatjaNeural)","voice_name":"Microsoft Katja Online (Natural) - German (Germany)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"ru-RU","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (ru-RU, EkaterinaRUS)","voice_name":"Microsoft Ekaterina Online - Russian (Russia)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"en-AU","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (en-AU, HayleyRUS)","voice_name":"Microsoft Hayley Online - English (Australia)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"it-IT","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (it-IT, ElsaNeural)","voice_name":"Microsoft Elsa Online (Natural) - Italian (Italy)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"ko-KR","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (ko-KR, SunHiNeural)","voice_name":"Microsoft SunHi Online (Natural) - Korean (Korea)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"nl-NL","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (nl-NL, HannaRUS)","voice_name":"Microsoft Hanna Online - Dutch (Netherlands)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"es-ES","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (es-ES, ElviraNeural)","voice_name":"Microsoft Elvira Online (Natural) - Spanish (Spain)"},{"codec":"audio-24khz-48kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"tr-TR","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (tr-TR, EmelNeural)","voice_name":"Microsoft Emel Online (Natural) - Turkish (Turkey)"},{"codec":"audio-16khz-32kbitrate-mono-mp3","event_types":["end","error","start","word"],"lang":"pl-PL","remote":true,"server_name":"Microsoft Server Speech Text to Speech Voice (pl-PL, PaulinaRUS)","voice_name":"Microsoft Paulina Online - Polish (Poland)"}]},"version":"1.0"},"path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\microsoft_voices","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"jmjflgjpcpepeafmmgdpfkogkghcpiha":{"account_extension_type":0,"ack_external":true,"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":["https://chrome.google.com/webstore/*"," ... oogle.com/*"]},"commands":{},"content_settings":[],"creation_flags":8321,"disable_reasons":[],"edge_last_update_check_time":"13391183651776421","events":[],"first_install_time":"13391117141656122","from_webstore":false,"granted_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":["https://chrome.google.com/webstore/*"," ... oogle.com/*"]},"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117141656122","lastpingday":"13391135999948975","location":10,"manifest":{"content_scripts":[{"js":["content.js"],"matches":["https://chrome.google.com/webstore/*"]},{"js":["content_new.js"],"matches":["https://chromewebstore.google.com/*"]}],"description":"Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu06p2Mjoy6yJDUUjCe8Hnqvtmjll73XqcbylxFZZWe+MCEAEK+1D0Nxrp0+IuWJL02CU3jbuR5KrJYoezA36M1oSGY5lIF/9NhXWEx5GrosxcBjxqEsdWv/eDoOOEbIvIO0ziMv7T1SUnmAA07wwq8DXWYuwlkZU/PA0Mxx0aNZ5+QyMfYqRmMpwxkwPG8gyU7kmacxgCY1v7PmmZo1vSIEOBYrxl064w5Q6s/dpalSJM9qeRnvRMLsszGY/J2bjQ1F0O2JfIlBjCOUg/89+U8ZJ1mObOFrKO4um8QnenXtH0WGmsvb5qBNrvbWNPuFgr2+w5JYlpSQ+O8zUCb8QZwIDAQAB","manifest_version":3,"name":"Edge relevant text changes","update_url":"https://edge.microsoft.com/extensionweb ... ons":{"api":["contentSettings","fileSystem","fileSystem.write","metricsPrivate","tabs","resourcesPrivate","pdfViewerPrivate","fileSystem.readFullPath","errorReporting","edgeLearningToolsPrivate","fileSystem.getCurrentEntry","edgePdfPrivate","edgeCertVerifierPrivate"],"explicit_host":["edge://resources/*","edge://webui-test/*"],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":[],"first_install_time":"13391117140971075","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140971075","location":5,"manifest":{"content_security_policy":"script-src 'self' 'wasm-eval' blob: filesystem: chrome://resources chrome://webui-test; object-src * blob: externalfile: file: filesystem: data:; trusted-types edge-internal fast-html pdf-url edge-pdf-static-policy;","description":"","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDN6hM0rsDYGbzQPQfOygqlRtQgKUXMfnSjhIBL7LnReAVBEd7ZmKtyN2qmSasMl4HZpMhVe2rPWVVwBDl6iyNE/Kok6E6v6V3vCLGsOpQAuuNVye/3QxzIldzG/jQAdWZiyXReRVapOhZtLjGfywCvlWq7Sl/e3sbc0vWybSDI2QIDAQAB","manifest_version":2,"mime_types":["application/pdf"],"mime_types_handler":"edge_pdf/index.html","name":"Microsoft Edge PDF Viewer","offline_enabled":true,"permissions":["errorReporting","chrome://resources/","chrome://webui-test/","contentSettings","metricsPrivate","edgeCertVerifierPrivate","edgeLearningToolsPrivate","edgePdfPrivate","pdfViewerPrivate","resourcesPrivate","tabs",{"fileSystem":["write","readFullPath","getCurrentEntry"]}],"version":"1"},"path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\edge_pdf","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"ncbjelpjchkpbikbpkcchkhkblodoama":{"account_extension_type":0,"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":[],"first_install_time":"13391117140972489","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140972489","location":5,"manifest":{"background":{"persistent":false,"scripts":["background.js"]},"externally_connectable":{"matches":["https://*.teams.microsoft.com/*","https://*.skype.com/*","https://*.teams.live.com/*"]},"incognito":"split","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtAdFAR3ckd5c7G8VSzUj4Ltt/QRInUOD00StG95LweksGcLBlFlYL46cHFVgHHj1gmzcpBtgsURdcrAC3V8yiE7GY4wtpOP+9l+adUGR+cyOG0mw9fLjyH+2Il0QqktsNXzkNiE1ogW4l0h4+PJc262j0vtm4hBzMvR0QScFWcAIcAErlUiWTt4jefXCAYqubV99ed5MvVMWBxe97wOa9hYwAhbCminOepA4RRTg9eyi0TiuHpq/bNI8C5qZgKIQNBAjgiFBaIx9hiMBFlK4NHUbFdgY6Qp/hSCMNurctwz1jpsXEnT4eHg1YWXfquoH8s4swIjkFCMBF6Ejc3cUkQIDAQAB","manifest_version":2,"name":"WebRTC Internals Extension","permissions":["webrtcInternalsPrivate"],"version":"2.0.2"},"path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\webrtc_internals","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"nkbndigcebkoaejohleckhekfmcecfja":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]},"nkeimhogjdpnpccoofpliimaahmaaome":{"account_extension_type":0,"active_permissions":{"api":["processes","webrtcLoggingPrivate","system.cpu","enterprise.hardwarePlatform"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"disable_reasons":[],"events":["runtime.onConnectExternal"],"first_install_time":"13391117140971794","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13391117140971794","location":5,"manifest":{"background":{"page":"background.html","persistent":false},"externally_connectable":{"ids":["moklfjoegmpoolceggbebbmgbddlhdgp","ldmpofkllgeicjiihkimgeccbhghhmfj","denipklgekfpcdmbahmbpnmokgajnhma","kjfhgcncjdebkoofmbjoiemiboifnpbo","ikfcpmgefdpheiiomgmhlmmkihchmdlj","jlgegmdnodfhciolbdjciihnlaljdbjo","lkbhffjfgpmpeppncnimiiikojibkhnm","acdafoiapclbpdkhnighhilgampkglpc","hkamnlhnogggfddmjomgbdokdkgfelgg"],"matches":["https://*.meet.teams.microsoft.com/*","https://*.meet.teams.live.com/*","https://*.meet.skype.com/*"]},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB","manifest_version":2,"name":"WebRTC Extension","permissions":["enterprise.hardwarePlatform","processes","system.cpu","webrtcLoggingPrivate"],"version":"1.3.24"},"path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\136.0.3240.50\\resources\\hangout_services","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"ofefcgjbeghpigppfmkologfjadafddi":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"disable_reasons":[8192]}}},"protection":{"macs":{"browser":{"show_home_button":"2E58B8CEB4F598A6C837E263D53E9E7236970F44D5B557CAD1EAEA142E134148"},"default_search_provider_data":{"template_url_data":"B601D2CB29D5017CACF8BCFA2473AC7019586EC41ED8F15802190DE386A32E30"},"edge":{"services":{"account_id":"06F7F4611C768324D61EDEAE342D643FC804690BF356C2DEC42960D3AB7DE13C","last_username":"980568BECD4ABDEEE5E6AD41BCC27C20C7673FD60C50DD01AAB5284355BF76A2"}},"enterprise_signin":{"policy_recovery_token":"423C9E03EFA65A8DDA9FAA5F60948A26646C5C305B308B77BD83668741DA7FA2"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"BAF1E4A9E1F66BBFA83FB05BB684462A7F8D5B6A1F53136DEFE5658CCFCBE835","ahokoikenoafgppiblgpenaaaolecifn":"3CAD1128532964FBE4E37F53345391EA920C300C6495542DD6CE4643404E1906","cjneempfhkonkkbcmnfdibgobmhbagaj":"B9374CD4C604B17DA4260BFE05DCE62A868EFEA71E2510A34941F6B79B6AC7DE","dcaajljecejllikfgbhjdgeognacjkkp":"16826A1949DACF0ADACF2E5F7E09DB8052F8A9025712EEB2EC84C13275BEAAA8","dgiklkfkllikcanfonkcabmbdfmgleag":"74DF828635BCEA5F9DFD18DD765ACC2B0576F6684793E6E4780E0AA0E0AF95DC","ehlmnljdoejdahfjdfobmpfancoibmig":"917713AD5F7162F5F4F8CEF97DA35ABDE877911ACEC00B445E02F6D354AE8520","fikbjbembnmfhppjfnmfkahdhfohhjmg":"B34E6734C293B54EFA7830CF718E6FBA2D5E716F292FC295A2D9C9384320E0F0","fjngpfnaikknjdhkckmncgicobbkcnle":"D6E21BE68755945FAFAF3FBB500D33648B5D49D199DF3D7448B2D5D40FA2492E","gbihlnbpmfkodghomcinpblknjhneknc":"27BF596DA9BB79D0A8FDC196D5CE036EE942AD824D3F93493368150550FE343F","gbmoeijgfngecijpcnbooedokgafmmji":"6B39E82E5C7FEF2262E5A81E784D3DE4F8B571E2D7AD2F46B377D80FB044766A","gcinnojdebelpnodghnoicmcdmamjoch":"D05C660831B5E8D226B212D92BD384D31901C84FFE88FD7FEE7DF425F9EE3AEC","gecfnmoodchdkebjjffmdcmeghkflpib":"9CA3878EC07B89276F12715E01F644F6596C14C507C4441B529D857D93973529","ghbmnnjooekpmoecnnnilnnbdlolhkhi":"79BDB0F471DB439B7574E4A04E31663100C9D677C1699803CC104AF88D40F869","hfmgbegjielnmfghmoohgmplnpeehike":"8FF5B419D0863B61BEEFA45F1828B19626EEEABC7CB2C359DCDF311101420364","iglcjdemknebjbklcgkfaebgojjphkec":"71F67A08B06EF2577947A87CDAFE89DE46328685918ACEE290F18B9B1DD648FE","ihmafllikibpmigkcoadcmckbfhibefp":"9E6AC604A026CD983560B4DE482F0DE9871A42E403DAC27A86B5E27FCC195D61","jbleckejnaboogigodiafflhkajdmpcl":"3A5162FB5F97EFFA4FAE7EA124EEF740F5D7357957F0F36C1E6EC782EA3E0349","jdiccldimpdaibmpdkjnbmckianbfold":"F76B5991BD02394B1A97E877FD66D8E77731B253D5FFC646E6EFEC552EF33370","jmjflgjpcpepeafmmgdpfkogkghcpiha":"A9A8751A5E3F77513D130772B8649F5B53D9738056E71E9BDA9CC9EBA9C86BF6","kfihiegbjaloebkmglnjnljoljgkkchm":"1EBD3745557FBE9184230B7C2947D23A08E11E29C84DF3E6BEF30805E12C1E20","mhjfbmdgcfjbbpaeojofohoefgiehjai":"15A8FFB7C497C458F5F4A5A8EC1DBA7995679C7CEF614E79F81820B8714633F7","ncbjelpjchkpbikbpkcchkhkblodoama":"DDF628270F68641AFE8EBF1965FBE1D15093191DD017191A238F723654A8AE4C","nkbndigcebkoaejohleckhekfmcecfja":"132568A14145E7236B2566CB0A6464540BE4C4E79F1D0A3E92E92D7C98A287FF","nkeimhogjdpnpccoofpliimaahmaaome":"466CC4AA5626CBB405ABD931819127BC5A9B1F152BE78FA52427CC35E4D21567","ofefcgjbeghpigppfmkologfjadafddi":"5998C9503DC0FEB3649C84ECA39C78BFC28DF86117B6B33F8A05D990DFE5CF68"},"ui":{"developer_mode":"FDC48D60E54C168430A4C999F41203609F596D7C2BAEC231A7386DE63FCEA063"}},"google":{"services":{"last_signed_in_username":"1005C5A70406263D50EDC8B91555A931B6F9B9DA0971E9ACC22F1368B5511B38"}},"homepage":"6B90D39EBD4139ECB1EBB5A1321931F73930C4C68BD41217A12114AFC4EBB98E","homepage_is_newtabpage":"867AF2568B64B28E32F9A7777C3FDED2E9B0FEFEB6D335FB2ECD4F060A5F48CF","media":{"cdm":{"origin_data":"636F071E6FFBC04F2D954737B20094174D189D6432E9684D4F816B4480DE27AE"},"storage_id_salt":"2E02B48D9915A91900288C174018EC01498A6FAA5AB0D6C21C8A968745318A71"},"pinned_tabs":"1BAC5790059E0AEE7392814B1F1876105EEE1BCFF00BB9F9EB6B92ADC9C2B894","prefs":{"preference_reset_time":"9B47D1E7DFB81E23959712BAFFADB8F8F2220F71D117A619D2F2057B1B5C7345"},"safebrowsing":{"incidents_sent":"D49503464D4B6454EDE5E28B4901611B11E724FC299E81AB5844D0094E3C6675"},"search_provider_overrides":"C8B562DE10B70D97C297B96BDF033A481D37591961C79EE14F58B8B3DAA32AD3","session":{"restore_on_startup":"D78CD1CD8B60252B9378E6DEEBA501E5E4AB58D88CBFE4D026C9A6DB65BEE358","startup_urls":"32C7BF8DD3896AB3C2181F28A6778B4702C393D47DD97B2027B1AA18E690C296"}},"super_mac":"5B59856E4A4174AC59C75AD91B57D536461E97F7A7ADA85D1497A2B6AD111390"}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IESR02"

==== Reset Google Chrome ======================

C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Preferences was reset successfully
C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Secure Preferences was reset successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data will be reset at reboot
C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data-journal will be reset at reboot
C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Web Data will be reset at reboot
C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Web Data-journal will be reset at reboot

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=63 folders=607 58705220 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\User\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\DumpStack.log.tmp" not deleted
"C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data" not found
"C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data-journal" not found
"C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Web Data" not found
"C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Web Data-journal" not found

==== EOF on 08.05.2025 at 15:25:41,64 ======================

ouhara
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 bře 2011 16:04

Re: vyskakují okna s hrozbou

#14 Příspěvek od ouhara »

A ještě doplním, dělá to jenom Google Chrome, Microsoft Edge to nedělá.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119316
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: vyskakují okna s hrozbou

#15 Příspěvek od Rudy »

OK. Sice stále nevím, jak ta okna z hláškami vypadají (nevím jaký program je dává). Spusťte tuto utilitu: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 . Stáhněte, spusťte, nechte pracovat a po skončení akce smažte vše, co najde. Pozor, popis v odkazu platí pro starší verzi utility.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět