Re: Naúspešné nainštalovanie Camtasia, CHyba: editorinterop.
Napsal: 12 dub 2020 10:47
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-04-2020
Ran by Doma (12-04-2020 11:47:06)
Running from C:\Users\Doma\Desktop
Windows 10 Home Single Language Version 1909 18363.752 (X64) (2020-01-29 19:16:24)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1459482069-237724922-515570800-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1459482069-237724922-515570800-503 - Limited - Disabled)
Doma (S-1-5-21-1459482069-237724922-515570800-1001 - Administrator - Enabled) => C:\Users\Doma
Guest (S-1-5-21-1459482069-237724922-515570800-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1459482069-237724922-515570800-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Antivirus (Enabled) {2092F4DC-EC63-3680-C854-E2DACF7E736A}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\uTorrent) (Version: 3.5.5.45628 - BitTorrent Inc.)
ABBYY FineReader 14 (HKLM\...\{F14000FE-0001-6400-0000-074957833700}) (Version: 14.7.210 - ABBYY Production LLC)
Adobe Acrobat Reader DC - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe Premiere Pro 2019 (HKLM-x32\...\PPRO_13_1_2) (Version: 13.1.2 - Adobe Systems Incorporated)
AVG Internet Security (HKLM-x32\...\AVG Antivirus) (Version: 20.2.3116 - AVG Technologies)
Bandicam (HKLM-x32\...\Bandicam) (Version: 4.5.7.1660 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
CanoScan LiDE 210 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4809) (Version: - Canon Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 10.1207.101.103 - ALPS ELECTRIC CO., LTD.)
DSD Transcoder ASIO Driver (HKLM-x32\...\DSDTranscoder) (Version: 1.0.10 - Maxim V.Anisiutkin)
EAGLE 9.5.2 (HKLM\...\{AUTODESK-EAGLE-9-5-2}_is1) (Version: 9.5.2 - Autodesk, Inc.)
ELDES Utility (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\{69b9dc42-8d9d-4858-ab80-b61a4ea1b695}) (Version: 1.0.0 - ELDES UAB)
Eraser 6.2.0.2982 (HKLM\...\{DFCF78CC-3DAD-4C1E-8BC6-94DC5B73461E}) (Version: 6.2.2982 - The Eraser Project)
FFmpeg (Windows) for Audacity verze 2.2.2 (HKLM-x32\...\{9C7E31E3-017F-434C-AC40-24431A354A1E}_is1) (Version: 2.2.2 - )
FFmpeg v0.6.2 for Audacity (HKLM-x32\...\FFmpeg for Audacity_is1) (Version: - )
foobar2000 v1.5.2 (HKLM-x32\...\foobar2000) (Version: 1.5.2 - Peter Pawlowski)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.92 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
GtPlayer (HKLM\...\GtPlayer) (Version: 1.0.34 - GtPlayer Team)
Java 8 Update 231 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180231F0}) (Version: 8.0.2310.11 - Oracle Corporation)
Java 8 Update 241 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
LibreOffice 6.2.0.3 (HKLM\...\{AD0844DC-C933-4D00-814A-3B7AAD254098}) (Version: 6.2.0.3 - The Document Foundation)
Microsoft OneDrive (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.3.1 - Mozilla)
Mozilla Thunderbird 68.6.0 (x86 sk) (HKLM-x32\...\Mozilla Thunderbird 68.6.0 (x86 sk)) (Version: 68.6.0 - Mozilla)
OBD2Spy V2.05 (HKLM-x32\...\ST6UNST #1) (Version: - )
OpenShot Video Editor verze 2.4.4 (HKLM\...\{4BB0DCDC-BC24-49EC-8937-72956C33A470}_is1) (Version: 2.4.4 - OpenShot Studios, LLC)
Opera Stable 67.0.3575.137 (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\Opera 67.0.3575.137) (Version: 67.0.3575.137 - Opera Software)
QuickPanel (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\QuickPanel) (Version: - )
ScanMaster-ELM 2.1.104.771 (HKLM\...\ScanMaster-ELM_is1) (Version: 2.1.104.771 - WGSoft.de)
ScanTool.net for Windows v1.13 (HKLM-x32\...\ScanTool.net for Windows) (Version: v1.13 - ScanTool.net, LLC)
Tunatic (HKLM-x32\...\Tunatic) (Version: - )
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{B2E25355-C24E-4E7D-8AD3-455D59810838}) (Version: 2.57.0.0 - Microsoft Corporation)
Videoder 1.0.9 (HKLM-x32\...\808fc302-3d01-59ce-8094-e0443a55877e) (Version: 1.0.9 - GlennioTech)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Web Companion (HKLM-x32\...\{de966205-5397-4871-8a7f-330ee6b54eba}) (Version: 4.10.2225.4082 - Lavasoft)
WinRAR 5.61 (64-bitová verzia) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH)
XRECODE 3 [64-bit] verze 1.101 (HKLM\...\{0870F25F-0A0A-4614-A1AD-7477C248502E}_is1) (Version: 1.101 - xrecode)
Packages:
=========
ACG Player -> C:\Program Files\WindowsApps\41038AXILESOFT.ACGMEDIAPLAYER_1.15.17502.0_x64__wxjjre7dryqb6 [2019-04-26] (Axilesoft) [MS Ad]
Adobe Reader Touch -> C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobeReader_3.1.8.7675_x86__ynb6jyjzte8ga [2019-03-20] (Adobe Systems Incorporated)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.4081.0_x64__rz1tebttyb220 [2020-01-29] (Dolby Laboratories)
Doplnok mediálneho nástroja pre Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-03] (Microsoft Corporation)
Doplnok pre Fotografie -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-12-03] (Microsoft Corporation)
Fitbit Coach -> C:\Program Files\WindowsApps\Fitbit.FitbitCoach_4.4.133.0_x64__6mqt6hf9g46tw [2018-10-29] (Fitbit)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_110.1.671.0_x64__v10z8vjag6ke6 [2020-02-13] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad]
Microsoft Midi gm.dls -> C:\Program Files\WindowsApps\Microsoft.Midi.GmDls_1.0.1.0_neutral__8wekyb3d8bbwe [2018-11-08] (Microsoft Platform Extensions)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-03-27] (Microsoft Studios) [MS Ad]
MSN Počasie -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-27] (Microsoft Corporation) [MS Ad]
Photo to Text OCR -> C:\Program Files\WindowsApps\19189MonsterAppFactory.PhototoTextOCR_1.1.29.0_x64__1254vmwvnx6wc [2019-06-12] (Monster App Factory) [MS Ad]
Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_3.7.1.0_x64__nfy108tqq3p12 [2020-04-06] (Thumbmunkeys Ltd) [MS Ad]
PicsArt - Photo Studio -> C:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_8.8.0.0_x86__crhqpqs3x1ygc [2019-10-16] (PicsArt Inc.) [MS Ad]
RAR Opener -> C:\Program Files\WindowsApps\DeviceDoctor.RAROpener_1.3.48.0_x64__mkdtfchztkfbm [2019-03-09] (Tiny Opener)
Raw Image Extension -> C:\Program Files\WindowsApps\Microsoft.RawImageExtension_1.0.21991.0_x64__8wekyb3d8bbwe [2020-04-11] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1459482069-237724922-515570800-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-04-05] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers1: [FineReader14ContextMenu] -> {FB074836-8286-4089-84DC-F504E9EF621C} => C:\Program Files (x86)\ABBYY FineReader 14\x64\FRIntegration.x64.dll [2018-10-07] (ABBYY Production LLC -> ABBYY Production LLC.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
ContextMenuHandlers2: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers2: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
ContextMenuHandlers4: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers4: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
ContextMenuHandlers5: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-04-05] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers6: [FineReader14ContextMenu] -> {FB074836-8286-4089-84DC-F504E9EF621C} => C:\Program Files (x86)\ABBYY FineReader 14\x64\FRIntegration.x64.dll [2018-10-07] (ABBYY Production LLC -> ABBYY Production LLC.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [vidc.mpeg] => C:\WINDOWS\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\WINDOWS\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2018-12-09 20:11 - 2013-04-22 18:03 - 022378434 _____ () [File not signed] C:\Program Files\Common Files\Eldes\icudt51.dll
2018-12-09 20:11 - 2013-04-22 18:03 - 003369922 _____ () [File not signed] C:\Program Files\Common Files\Eldes\icuin51.dll
2018-12-09 20:11 - 2013-04-22 18:03 - 001978690 _____ () [File not signed] C:\Program Files\Common Files\Eldes\icuuc51.dll
2018-12-09 20:11 - 2013-04-17 20:18 - 000544817 _____ () [File not signed] C:\Program Files\Common Files\Eldes\libgcc_s_dw2-1.dll
2018-12-09 20:11 - 2013-04-17 20:19 - 000989805 _____ () [File not signed] C:\Program Files\Common Files\Eldes\libstdc++-6.dll
2018-12-09 20:11 - 2018-02-18 23:26 - 000073216 _____ () [File not signed] C:\Program Files\Common Files\Eldes\QtSolutions_Service-head.dll
2018-12-09 20:11 - 2018-02-18 22:45 - 004604928 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Program Files\Common Files\Eldes\Qt5Core.dll
2018-12-09 20:11 - 2013-12-08 20:00 - 001392128 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Program Files\Common Files\Eldes\Qt5Network.dll
2018-12-09 20:11 - 2013-04-17 19:26 - 000073901 _____ (MingW-W64 Project. All rights reserved.) [File not signed] C:\Program Files\Common Files\Eldes\libwinpthread-1.dll
2019-01-19 00:16 - 2017-09-27 18:30 - 000489984 _____ (Newtonsoft) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\Newtonsoft.Json.dll
2019-01-19 00:16 - 2017-10-24 19:03 - 000088064 _____ (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppCollect.dll
2019-01-19 00:16 - 2017-10-24 19:03 - 000200192 _____ (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppCommon.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKLM\...\.scr: EAGLESCR => "c:\EAGLE 9.5.2\eagle.exe" -C "" "%1" <==== ATTENTION
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-12 01:38 - 2020-04-08 19:40 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1459482069-237724922-515570800-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.240.1 - 31.3.32.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [UDP Query User{3C0352AE-57C2-48B5-B1E4-43C463640619}C:\program files\openshot video editor\launch.exe] => (Block) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [TCP Query User{6F788ADD-8EB0-43A1-9FAF-39DA5D999750}C:\program files\openshot video editor\launch.exe] => (Block) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [TCP Query User{6657F6DE-8973-416C-B6C4-FC9ACC32CB3F}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{2DAC6679-64E7-41CC-9BF4-94E314D29CB7}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{9606909C-C929-412E-98E1-E088364297C7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{8E4E9370-8313-4A60-AEE5-77E86E26BB15}] => (Allow) C:\Users\Doma\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{A850F39A-B1DB-43DE-AE32-FF68E5EA4F99}] => (Allow) C:\Users\Doma\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{A63AE2ED-C6D7-4729-B290-DD3BE03D6E54}] => (Allow) C:\Users\Doma\AppData\Local\Programs\Opera\67.0.3575.137\opera.exe (Opera Software AS -> Opera Software)
==================== Restore Points =========================
ATTENTION: System Restore is disabled (Total:118.66 GB) (Free:20.71 GB) (17%)
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (04/12/2020 11:45:51 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9372,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 11:34:14 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (12876,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 11:12:31 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (6816,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 10:42:30 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (13376,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 10:12:31 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5884,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 09:42:30 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (616,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 09:12:28 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5304,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 08:42:27 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4568,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
System errors:
=============
Error: (04/11/2020 08:52:37 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Zlyhanie inštalácie: Systému Windows sa nepodarilo nainštalovať nasledujúcu aktualizáciu. Vyskytla sa chyba 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Error: (04/08/2020 07:40:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba WMI Performance Adapter sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 120000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 30000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Wondershare Application Framework Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba EldesService sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Bluetooth Driver Management Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Alps HID Monitor Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Windows Defender:
===================================
Date: 2020-04-05 21:31:16.398
Description:
Controlled Folder Access blocked C:\Program Files\AVG\Antivirus\AvBugReport.exe from making changes to memory.
Detection time: 2020-04-05T19:31:16.398Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Program Files\AVG\Antivirus\AvBugReport.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:31:16.396
Description:
Controlled Folder Access blocked C:\Program Files\AVG\Antivirus\AvEmUpdate.exe from making changes to memory.
Detection time: 2020-04-05T19:31:16.395Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:31:16.396
Description:
Controlled Folder Access blocked C:\Program Files\AVG\Antivirus\AvBugReport.exe from making changes to memory.
Detection time: 2020-04-05T19:31:16.395Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Program Files\AVG\Antivirus\AvBugReport.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:30:04.718
Description:
Controlled Folder Access blocked C:\Windows\Temp\asw.0cf3a329da27ad56\New_14020c2c\instup.exe from making changes to memory.
Detection time: 2020-04-05T19:30:04.717Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Windows\Temp\asw.0cf3a329da27ad56\New_14020c2c\instup.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:10:46.231
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Name: HackTool:BAT/AutoKMS
ID: 2147739951
Severity: Vysoká
Category: Nástroj
Path: file:_C:\Users\Doma\Downloads\Zálohy\windows10.cmd
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\cmd.exe
Security intelligence Version: AV: 1.313.839.0, AS: 1.313.839.0, NIS: 1.313.839.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
CodeIntegrity:
===================================
Date: 2020-04-12 11:47:58.359
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswhook.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:47:58.355
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\snxhk.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:42:00.898
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswhook.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:42:00.892
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\snxhk.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:57.328
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswhook.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:57.319
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\snxhk.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:53.844
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:53.794
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: Dell Inc. A18 01/18/2016
Motherboard: Dell Inc. 0DV71K
Processor: Intel(R) Core(TM) i5-3340M CPU @ 2.70GHz
Percentage of memory in use: 87%
Total physical RAM: 3998.92 MB
Available physical RAM: 515.23 MB
Total Virtual: 6302.92 MB
Available Virtual: 1250.17 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:118.66 GB) (Free:20.71 GB) NTFS
\\?\Volume{3f3a651c-0000-0000-0000-100000000000}\ () (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{3f3a651c-0000-0000-0000-80b01d000000}\ () (Fixed) (Total:0.48 GB) (Free:0.04 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 119.2 GB) (Disk ID: 3F3A651C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=118.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=494 MB) - (Type=27)
==================== End of Addition.txt =======================
Ran by Doma (12-04-2020 11:47:06)
Running from C:\Users\Doma\Desktop
Windows 10 Home Single Language Version 1909 18363.752 (X64) (2020-01-29 19:16:24)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1459482069-237724922-515570800-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1459482069-237724922-515570800-503 - Limited - Disabled)
Doma (S-1-5-21-1459482069-237724922-515570800-1001 - Administrator - Enabled) => C:\Users\Doma
Guest (S-1-5-21-1459482069-237724922-515570800-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1459482069-237724922-515570800-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Antivirus (Enabled) {2092F4DC-EC63-3680-C854-E2DACF7E736A}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\uTorrent) (Version: 3.5.5.45628 - BitTorrent Inc.)
ABBYY FineReader 14 (HKLM\...\{F14000FE-0001-6400-0000-074957833700}) (Version: 14.7.210 - ABBYY Production LLC)
Adobe Acrobat Reader DC - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe Premiere Pro 2019 (HKLM-x32\...\PPRO_13_1_2) (Version: 13.1.2 - Adobe Systems Incorporated)
AVG Internet Security (HKLM-x32\...\AVG Antivirus) (Version: 20.2.3116 - AVG Technologies)
Bandicam (HKLM-x32\...\Bandicam) (Version: 4.5.7.1660 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
CanoScan LiDE 210 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4809) (Version: - Canon Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 10.1207.101.103 - ALPS ELECTRIC CO., LTD.)
DSD Transcoder ASIO Driver (HKLM-x32\...\DSDTranscoder) (Version: 1.0.10 - Maxim V.Anisiutkin)
EAGLE 9.5.2 (HKLM\...\{AUTODESK-EAGLE-9-5-2}_is1) (Version: 9.5.2 - Autodesk, Inc.)
ELDES Utility (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\{69b9dc42-8d9d-4858-ab80-b61a4ea1b695}) (Version: 1.0.0 - ELDES UAB)
Eraser 6.2.0.2982 (HKLM\...\{DFCF78CC-3DAD-4C1E-8BC6-94DC5B73461E}) (Version: 6.2.2982 - The Eraser Project)
FFmpeg (Windows) for Audacity verze 2.2.2 (HKLM-x32\...\{9C7E31E3-017F-434C-AC40-24431A354A1E}_is1) (Version: 2.2.2 - )
FFmpeg v0.6.2 for Audacity (HKLM-x32\...\FFmpeg for Audacity_is1) (Version: - )
foobar2000 v1.5.2 (HKLM-x32\...\foobar2000) (Version: 1.5.2 - Peter Pawlowski)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.92 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
GtPlayer (HKLM\...\GtPlayer) (Version: 1.0.34 - GtPlayer Team)
Java 8 Update 231 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180231F0}) (Version: 8.0.2310.11 - Oracle Corporation)
Java 8 Update 241 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
LibreOffice 6.2.0.3 (HKLM\...\{AD0844DC-C933-4D00-814A-3B7AAD254098}) (Version: 6.2.0.3 - The Document Foundation)
Microsoft OneDrive (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.3.1 - Mozilla)
Mozilla Thunderbird 68.6.0 (x86 sk) (HKLM-x32\...\Mozilla Thunderbird 68.6.0 (x86 sk)) (Version: 68.6.0 - Mozilla)
OBD2Spy V2.05 (HKLM-x32\...\ST6UNST #1) (Version: - )
OpenShot Video Editor verze 2.4.4 (HKLM\...\{4BB0DCDC-BC24-49EC-8937-72956C33A470}_is1) (Version: 2.4.4 - OpenShot Studios, LLC)
Opera Stable 67.0.3575.137 (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\Opera 67.0.3575.137) (Version: 67.0.3575.137 - Opera Software)
QuickPanel (HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\QuickPanel) (Version: - )
ScanMaster-ELM 2.1.104.771 (HKLM\...\ScanMaster-ELM_is1) (Version: 2.1.104.771 - WGSoft.de)
ScanTool.net for Windows v1.13 (HKLM-x32\...\ScanTool.net for Windows) (Version: v1.13 - ScanTool.net, LLC)
Tunatic (HKLM-x32\...\Tunatic) (Version: - )
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{B2E25355-C24E-4E7D-8AD3-455D59810838}) (Version: 2.57.0.0 - Microsoft Corporation)
Videoder 1.0.9 (HKLM-x32\...\808fc302-3d01-59ce-8094-e0443a55877e) (Version: 1.0.9 - GlennioTech)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Web Companion (HKLM-x32\...\{de966205-5397-4871-8a7f-330ee6b54eba}) (Version: 4.10.2225.4082 - Lavasoft)
WinRAR 5.61 (64-bitová verzia) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH)
XRECODE 3 [64-bit] verze 1.101 (HKLM\...\{0870F25F-0A0A-4614-A1AD-7477C248502E}_is1) (Version: 1.101 - xrecode)
Packages:
=========
ACG Player -> C:\Program Files\WindowsApps\41038AXILESOFT.ACGMEDIAPLAYER_1.15.17502.0_x64__wxjjre7dryqb6 [2019-04-26] (Axilesoft) [MS Ad]
Adobe Reader Touch -> C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobeReader_3.1.8.7675_x86__ynb6jyjzte8ga [2019-03-20] (Adobe Systems Incorporated)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.4081.0_x64__rz1tebttyb220 [2020-01-29] (Dolby Laboratories)
Doplnok mediálneho nástroja pre Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-03] (Microsoft Corporation)
Doplnok pre Fotografie -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-12-03] (Microsoft Corporation)
Fitbit Coach -> C:\Program Files\WindowsApps\Fitbit.FitbitCoach_4.4.133.0_x64__6mqt6hf9g46tw [2018-10-29] (Fitbit)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_110.1.671.0_x64__v10z8vjag6ke6 [2020-02-13] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad]
Microsoft Midi gm.dls -> C:\Program Files\WindowsApps\Microsoft.Midi.GmDls_1.0.1.0_neutral__8wekyb3d8bbwe [2018-11-08] (Microsoft Platform Extensions)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-03-27] (Microsoft Studios) [MS Ad]
MSN Počasie -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-27] (Microsoft Corporation) [MS Ad]
Photo to Text OCR -> C:\Program Files\WindowsApps\19189MonsterAppFactory.PhototoTextOCR_1.1.29.0_x64__1254vmwvnx6wc [2019-06-12] (Monster App Factory) [MS Ad]
Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_3.7.1.0_x64__nfy108tqq3p12 [2020-04-06] (Thumbmunkeys Ltd) [MS Ad]
PicsArt - Photo Studio -> C:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_8.8.0.0_x86__crhqpqs3x1ygc [2019-10-16] (PicsArt Inc.) [MS Ad]
RAR Opener -> C:\Program Files\WindowsApps\DeviceDoctor.RAROpener_1.3.48.0_x64__mkdtfchztkfbm [2019-03-09] (Tiny Opener)
Raw Image Extension -> C:\Program Files\WindowsApps\Microsoft.RawImageExtension_1.0.21991.0_x64__8wekyb3d8bbwe [2020-04-11] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1459482069-237724922-515570800-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-04-05] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers1: [FineReader14ContextMenu] -> {FB074836-8286-4089-84DC-F504E9EF621C} => C:\Program Files (x86)\ABBYY FineReader 14\x64\FRIntegration.x64.dll [2018-10-07] (ABBYY Production LLC -> ABBYY Production LLC.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
ContextMenuHandlers2: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers2: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
ContextMenuHandlers4: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers4: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
ContextMenuHandlers5: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-04-05] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (Heidi Computers Ltd -> The Eraser Project)
ContextMenuHandlers6: [FineReader14ContextMenu] -> {FB074836-8286-4089-84DC-F504E9EF621C} => C:\Program Files (x86)\ABBYY FineReader 14\x64\FRIntegration.x64.dll [2018-10-07] (ABBYY Production LLC -> ABBYY Production LLC.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6: [Xr3shellContext] -> {8CFB8A37-C55C-438F-9C6F-E6CDDC610822} => C:\Program Files\xrecode3\bin\shell\xr3shellx64.dll [2019-09-14] (Eriks Aleksans -> )
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [vidc.mpeg] => C:\WINDOWS\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\WINDOWS\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2018-12-09 20:11 - 2013-04-22 18:03 - 022378434 _____ () [File not signed] C:\Program Files\Common Files\Eldes\icudt51.dll
2018-12-09 20:11 - 2013-04-22 18:03 - 003369922 _____ () [File not signed] C:\Program Files\Common Files\Eldes\icuin51.dll
2018-12-09 20:11 - 2013-04-22 18:03 - 001978690 _____ () [File not signed] C:\Program Files\Common Files\Eldes\icuuc51.dll
2018-12-09 20:11 - 2013-04-17 20:18 - 000544817 _____ () [File not signed] C:\Program Files\Common Files\Eldes\libgcc_s_dw2-1.dll
2018-12-09 20:11 - 2013-04-17 20:19 - 000989805 _____ () [File not signed] C:\Program Files\Common Files\Eldes\libstdc++-6.dll
2018-12-09 20:11 - 2018-02-18 23:26 - 000073216 _____ () [File not signed] C:\Program Files\Common Files\Eldes\QtSolutions_Service-head.dll
2018-12-09 20:11 - 2018-02-18 22:45 - 004604928 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Program Files\Common Files\Eldes\Qt5Core.dll
2018-12-09 20:11 - 2013-12-08 20:00 - 001392128 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Program Files\Common Files\Eldes\Qt5Network.dll
2018-12-09 20:11 - 2013-04-17 19:26 - 000073901 _____ (MingW-W64 Project. All rights reserved.) [File not signed] C:\Program Files\Common Files\Eldes\libwinpthread-1.dll
2019-01-19 00:16 - 2017-09-27 18:30 - 000489984 _____ (Newtonsoft) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\Newtonsoft.Json.dll
2019-01-19 00:16 - 2017-10-24 19:03 - 000088064 _____ (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppCollect.dll
2019-01-19 00:16 - 2017-10-24 19:03 - 000200192 _____ (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.231\WsAppCommon.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKLM\...\.scr: EAGLESCR => "c:\EAGLE 9.5.2\eagle.exe" -C "" "%1" <==== ATTENTION
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1459482069-237724922-515570800-1001\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-12 01:38 - 2020-04-08 19:40 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1459482069-237724922-515570800-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.240.1 - 31.3.32.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [UDP Query User{3C0352AE-57C2-48B5-B1E4-43C463640619}C:\program files\openshot video editor\launch.exe] => (Block) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [TCP Query User{6F788ADD-8EB0-43A1-9FAF-39DA5D999750}C:\program files\openshot video editor\launch.exe] => (Block) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [TCP Query User{6657F6DE-8973-416C-B6C4-FC9ACC32CB3F}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{2DAC6679-64E7-41CC-9BF4-94E314D29CB7}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{9606909C-C929-412E-98E1-E088364297C7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{8E4E9370-8313-4A60-AEE5-77E86E26BB15}] => (Allow) C:\Users\Doma\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{A850F39A-B1DB-43DE-AE32-FF68E5EA4F99}] => (Allow) C:\Users\Doma\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{A63AE2ED-C6D7-4729-B290-DD3BE03D6E54}] => (Allow) C:\Users\Doma\AppData\Local\Programs\Opera\67.0.3575.137\opera.exe (Opera Software AS -> Opera Software)
==================== Restore Points =========================
ATTENTION: System Restore is disabled (Total:118.66 GB) (Free:20.71 GB) (17%)
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (04/12/2020 11:45:51 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9372,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 11:34:14 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (12876,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 11:12:31 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (6816,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 10:42:30 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (13376,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 10:12:31 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5884,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 09:42:30 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (616,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 09:12:28 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5304,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/12/2020 08:42:27 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4568,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
System errors:
=============
Error: (04/11/2020 08:52:37 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Zlyhanie inštalácie: Systému Windows sa nepodarilo nainštalovať nasledujúcu aktualizáciu. Vyskytla sa chyba 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Error: (04/08/2020 07:40:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba WMI Performance Adapter sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 120000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 30000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Wondershare Application Framework Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba EldesService sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Bluetooth Driver Management Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Error: (04/08/2020 07:40:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Alps HID Monitor Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1-krát.
Windows Defender:
===================================
Date: 2020-04-05 21:31:16.398
Description:
Controlled Folder Access blocked C:\Program Files\AVG\Antivirus\AvBugReport.exe from making changes to memory.
Detection time: 2020-04-05T19:31:16.398Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Program Files\AVG\Antivirus\AvBugReport.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:31:16.396
Description:
Controlled Folder Access blocked C:\Program Files\AVG\Antivirus\AvEmUpdate.exe from making changes to memory.
Detection time: 2020-04-05T19:31:16.395Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:31:16.396
Description:
Controlled Folder Access blocked C:\Program Files\AVG\Antivirus\AvBugReport.exe from making changes to memory.
Detection time: 2020-04-05T19:31:16.395Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Program Files\AVG\Antivirus\AvBugReport.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:30:04.718
Description:
Controlled Folder Access blocked C:\Windows\Temp\asw.0cf3a329da27ad56\New_14020c2c\instup.exe from making changes to memory.
Detection time: 2020-04-05T19:30:04.717Z
Path: \Device\Harddisk0\DR0
Process Name: C:\Windows\Temp\asw.0cf3a329da27ad56\New_14020c2c\instup.exe
Security intelligence Version: 1.313.839.0
Engine Version: 1.1.16900.4
Product Version: 4.18.2003.8
Date: 2020-04-05 21:10:46.231
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Name: HackTool:BAT/AutoKMS
ID: 2147739951
Severity: Vysoká
Category: Nástroj
Path: file:_C:\Users\Doma\Downloads\Zálohy\windows10.cmd
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\cmd.exe
Security intelligence Version: AV: 1.313.839.0, AS: 1.313.839.0, NIS: 1.313.839.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
CodeIntegrity:
===================================
Date: 2020-04-12 11:47:58.359
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswhook.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:47:58.355
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\snxhk.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:42:00.898
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswhook.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:42:00.892
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\snxhk.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:57.328
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswhook.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:57.319
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\snxhk.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:53.844
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.
Date: 2020-04-12 11:41:53.794
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: Dell Inc. A18 01/18/2016
Motherboard: Dell Inc. 0DV71K
Processor: Intel(R) Core(TM) i5-3340M CPU @ 2.70GHz
Percentage of memory in use: 87%
Total physical RAM: 3998.92 MB
Available physical RAM: 515.23 MB
Total Virtual: 6302.92 MB
Available Virtual: 1250.17 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:118.66 GB) (Free:20.71 GB) NTFS
\\?\Volume{3f3a651c-0000-0000-0000-100000000000}\ () (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{3f3a651c-0000-0000-0000-80b01d000000}\ () (Fixed) (Total:0.48 GB) (Free:0.04 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 119.2 GB) (Disk ID: 3F3A651C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=118.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=494 MB) - (Type=27)
==================== End of Addition.txt =======================