vyskakující okna
Napsal: 12 led 2021 13:00
Dobrý den,
přítelkyně si stahovala nějakou hru z internetu a poté jsem zjistil, že po každém spuštění windows začnou vyskakovat nějaké cizí internetové stránky a mám dojem, že přestal fungovat i antivirus, prosím o případnou pomoc děkuji
Přikládám logy z FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-01-2021
Ran by Lenovo (administrator) on DESKTOP-CVQ9IOL (LENOVO 80G0) (12-01-2021 12:49:22)
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Platform: Windows 10 Home Version 2004 19041.685 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Conexant Systems, Inc.) [File not signed] C:\Windows\SysWOW64\UIUSrv.exe
(Fortemedia Inc -> ) C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <6>
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek semiconductor) C:\Windows\RTFTrack.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1831256 2016-01-08] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5062384 2015-08-30] (Realtek Semiconductor Corp -> Realtek semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2234086909-1374755945-2232299674-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32414392 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2234086909-1374755945-2232299674-1001\...\Run: [Windows Updates Service] => C:\Users\Lenovo\AppData\Roaming\Windows Updates Files\Windows Updates Service.vbe [1000 2021-01-05] () [File not signed] <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2019-12-24] () [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {30E0B40E-3902-4503-A344-72E1AE2AA4D7} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {490DE79A-8221-40C3-9F14-E47D2EEDE9D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {62E5F115-5503-477D-8AAE-04457E974F4F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7A5A1CC2-67FF-4006-8D97-51441F41A5AD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9C2057AD-78A1-4F13-8032-5B000C945300} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [26896568 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {BBC4C284-0130-4D12-9538-3A7929D45224} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D8227522-EE2C-41FA-88AC-AB925B5025AE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {DF0AB20B-22A6-4823-A3FA-19E2B8AF57E0} - System32\Tasks\LUKKOMP\Cisteni OS => C:\dusting.cmd 0
Task: {E548EFA9-10CF-42BF-B8F9-A5B50816ED7D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [693216 2021-01-11] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{d4243ff1-ca74-45d7-b3a5-c5ec021b344e}: [DhcpNameServer] 192.168.0.1
Edge:
======
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2021-01-12]
FireFox:
========
FF DefaultProfile: ccow8e9n.default
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\lrj1odvp.user [2021-01-12]
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\ccow8e9n.default [2020-10-09]
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\inag7a7p.default-release [2021-01-12]
FF Homepage: Mozilla\Firefox\Profiles\inag7a7p.default-release -> hxxps://www.seznam.cz/
FF Extension: (Αddοn) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\inag7a7p.default-release\Extensions\{b4012389-8047-46e4-b0a6-0aaff98822c2}.xpi [2020-12-20]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-12-07] (Adobe Inc. -> Adobe Systems Inc.)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
R2 UIUService; C:\Windows\SysWOW64\UIUSrv.exe [105984 2020-10-09] (Conexant Systems, Inc.) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2020-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [429296 2020-12-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-08] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-12 12:49 - 2021-01-12 12:50 - 000009223 _____ C:\Users\Lenovo\Desktop\FRST.txt
2021-01-12 12:49 - 2021-01-12 12:49 - 000000000 ____D C:\FRST
2021-01-12 12:48 - 2021-01-12 12:48 - 002281472 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2021-01-12 12:41 - 2021-01-12 12:41 - 000000000 ____D C:\rsit
2021-01-12 12:41 - 2021-01-12 12:41 - 000000000 ____D C:\Program Files\trend micro
2021-01-11 20:25 - 2021-01-11 20:25 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2021-01-06 15:22 - 2021-01-06 15:22 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Lord of the Rings - Conquest Čeština
2021-01-06 15:18 - 2021-01-06 15:18 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\BonusWeb
2021-01-06 15:18 - 2021-01-06 15:18 - 000000000 ____D C:\ProgramData\Caphyon
2021-01-06 15:17 - 2021-01-06 15:17 - 007886595 _____ C:\Users\Lenovo\Downloads\Lord of the Rings - Conquest Čeština.rar
2021-01-06 15:14 - 2021-01-06 20:07 - 2007596916 _____ C:\Users\Lenovo\Downloads\The.Lord.of.the.Rings.Conquest.zip
2021-01-06 12:17 - 2021-01-06 12:22 - 000000000 ____D C:\Users\Lenovo\Desktop\Životopisy (práce)
2021-01-06 12:13 - 2021-01-06 12:15 - 000000000 ___HD C:\Windows\msdownld.tmp
2021-01-06 12:13 - 2021-01-06 12:15 - 000000000 ____D C:\Windows\SysWOW64\directx
2021-01-06 12:06 - 2021-01-06 21:39 - 000000000 ____D C:\Users\Lenovo\Documents\The Lord of the Rings - Conquest
2021-01-05 20:23 - 2021-01-05 20:23 - 000001212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
2021-01-05 20:23 - 2021-01-05 20:23 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-01-05 20:23 - 2021-01-05 20:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-01-05 20:05 - 2021-01-05 21:00 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Windows Updates Files
2021-01-05 20:05 - 2021-01-05 20:53 - 000000270 __RSH C:\ProgramData\ntuser.pol
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files\Reference Assemblies
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files\MSBuild
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files (x86)\MSBuild
2021-01-05 20:01 - 2021-01-06 12:16 - 000000000 ____D C:\Users\Lenovo\Downloads\_Oceanofgames.com_Lord_of_the_Ring_Conquest
2021-01-05 19:49 - 2021-01-12 11:13 - 000000000 ____D C:\Program Files (x86)\WinRAR
2021-01-05 19:49 - 2021-01-05 19:49 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\WinRAR
2021-01-05 16:32 - 2021-01-05 16:33 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\My Battle for Middle-earth Files
2021-01-05 16:31 - 2021-01-05 16:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2021-01-05 16:15 - 2021-01-05 16:15 - 000000000 ____D C:\Program Files (x86)\EA GAMES
2021-01-05 16:04 - 2021-01-05 16:04 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Macromedia
2021-01-04 20:42 - 2021-01-12 11:13 - 000000000 ____D C:\Program Files\Mozilla Firefox
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-12 12:48 - 2020-10-09 10:28 - 000000000 ____D C:\Users\Lenovo\AppData\LocalLow\Mozilla
2021-01-12 12:47 - 2020-10-11 09:02 - 000000000 ____D C:\Program Files\CCleaner
2021-01-12 12:46 - 2020-10-09 10:17 - 000000000 ____D C:\ProgramData\Mozilla
2021-01-12 12:45 - 2020-10-09 10:43 - 000000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2021-01-12 12:45 - 2020-10-09 09:50 - 000008192 ___SH C:\DumpStack.log.tmp
2021-01-12 12:45 - 2020-10-09 09:50 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-01-12 12:45 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-12 12:44 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2021-01-12 12:38 - 2020-10-09 09:50 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-01-12 11:22 - 2020-10-09 09:59 - 001693136 _____ C:\Windows\system32\PerfStringBackup.INI
2021-01-12 11:22 - 2019-12-07 15:41 - 000718010 _____ C:\Windows\system32\perfh005.dat
2021-01-12 11:22 - 2019-12-07 15:41 - 000145152 _____ C:\Windows\system32\perfc005.dat
2021-01-12 11:22 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2021-01-12 11:13 - 2020-10-09 10:17 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-01-11 20:25 - 2020-10-09 10:17 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-01-11 20:19 - 2020-10-15 08:54 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-01-11 20:19 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-01-11 20:19 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2021-01-11 19:40 - 2020-10-11 09:02 - 000004210 _____ C:\Windows\system32\Tasks\CCleaner Update
2021-01-06 12:20 - 2020-10-11 10:38 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\MPC-HC
2021-01-06 12:18 - 2020-10-14 13:45 - 000000000 ____D C:\Users\Lenovo\Desktop\Filmy
2021-01-05 20:06 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2021-01-05 20:05 - 2019-12-07 10:14 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2021-01-05 20:05 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\MUI
2021-01-05 20:05 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\MUI
2021-01-05 16:10 - 2020-10-09 10:16 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\AIMP
2020-12-19 11:41 - 2020-10-11 10:09 - 000000000 ____D C:\Windows\Minidump
2020-12-19 11:40 - 2020-10-11 09:02 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
přítelkyně si stahovala nějakou hru z internetu a poté jsem zjistil, že po každém spuštění windows začnou vyskakovat nějaké cizí internetové stránky a mám dojem, že přestal fungovat i antivirus, prosím o případnou pomoc děkuji

Přikládám logy z FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-01-2021
Ran by Lenovo (administrator) on DESKTOP-CVQ9IOL (LENOVO 80G0) (12-01-2021 12:49:22)
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Platform: Windows 10 Home Version 2004 19041.685 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Conexant Systems, Inc.) [File not signed] C:\Windows\SysWOW64\UIUSrv.exe
(Fortemedia Inc -> ) C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <6>
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek semiconductor) C:\Windows\RTFTrack.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1831256 2016-01-08] (Conexant Systems, Inc. -> Conexant Systems, Inc.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5062384 2015-08-30] (Realtek Semiconductor Corp -> Realtek semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2234086909-1374755945-2232299674-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32414392 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2234086909-1374755945-2232299674-1001\...\Run: [Windows Updates Service] => C:\Users\Lenovo\AppData\Roaming\Windows Updates Files\Windows Updates Service.vbe [1000 2021-01-05] () [File not signed] <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2019-12-24] () [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {30E0B40E-3902-4503-A344-72E1AE2AA4D7} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {490DE79A-8221-40C3-9F14-E47D2EEDE9D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {62E5F115-5503-477D-8AAE-04457E974F4F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7A5A1CC2-67FF-4006-8D97-51441F41A5AD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9C2057AD-78A1-4F13-8032-5B000C945300} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [26896568 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {BBC4C284-0130-4D12-9538-3A7929D45224} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D8227522-EE2C-41FA-88AC-AB925B5025AE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {DF0AB20B-22A6-4823-A3FA-19E2B8AF57E0} - System32\Tasks\LUKKOMP\Cisteni OS => C:\dusting.cmd 0
Task: {E548EFA9-10CF-42BF-B8F9-A5B50816ED7D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [693216 2021-01-11] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{d4243ff1-ca74-45d7-b3a5-c5ec021b344e}: [DhcpNameServer] 192.168.0.1
Edge:
======
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2021-01-12]
FireFox:
========
FF DefaultProfile: ccow8e9n.default
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\lrj1odvp.user [2021-01-12]
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\ccow8e9n.default [2020-10-09]
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\inag7a7p.default-release [2021-01-12]
FF Homepage: Mozilla\Firefox\Profiles\inag7a7p.default-release -> hxxps://www.seznam.cz/
FF Extension: (Αddοn) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\inag7a7p.default-release\Extensions\{b4012389-8047-46e4-b0a6-0aaff98822c2}.xpi [2020-12-20]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-12-07] (Adobe Inc. -> Adobe Systems Inc.)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
R2 UIUService; C:\Windows\SysWOW64\UIUSrv.exe [105984 2020-10-09] (Conexant Systems, Inc.) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2020-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [429296 2020-12-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-08] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-12 12:49 - 2021-01-12 12:50 - 000009223 _____ C:\Users\Lenovo\Desktop\FRST.txt
2021-01-12 12:49 - 2021-01-12 12:49 - 000000000 ____D C:\FRST
2021-01-12 12:48 - 2021-01-12 12:48 - 002281472 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2021-01-12 12:41 - 2021-01-12 12:41 - 000000000 ____D C:\rsit
2021-01-12 12:41 - 2021-01-12 12:41 - 000000000 ____D C:\Program Files\trend micro
2021-01-11 20:25 - 2021-01-11 20:25 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2021-01-06 15:22 - 2021-01-06 15:22 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Lord of the Rings - Conquest Čeština
2021-01-06 15:18 - 2021-01-06 15:18 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\BonusWeb
2021-01-06 15:18 - 2021-01-06 15:18 - 000000000 ____D C:\ProgramData\Caphyon
2021-01-06 15:17 - 2021-01-06 15:17 - 007886595 _____ C:\Users\Lenovo\Downloads\Lord of the Rings - Conquest Čeština.rar
2021-01-06 15:14 - 2021-01-06 20:07 - 2007596916 _____ C:\Users\Lenovo\Downloads\The.Lord.of.the.Rings.Conquest.zip
2021-01-06 12:17 - 2021-01-06 12:22 - 000000000 ____D C:\Users\Lenovo\Desktop\Životopisy (práce)
2021-01-06 12:13 - 2021-01-06 12:15 - 000000000 ___HD C:\Windows\msdownld.tmp
2021-01-06 12:13 - 2021-01-06 12:15 - 000000000 ____D C:\Windows\SysWOW64\directx
2021-01-06 12:06 - 2021-01-06 21:39 - 000000000 ____D C:\Users\Lenovo\Documents\The Lord of the Rings - Conquest
2021-01-05 20:23 - 2021-01-05 20:23 - 000001212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
2021-01-05 20:23 - 2021-01-05 20:23 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-01-05 20:23 - 2021-01-05 20:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-01-05 20:05 - 2021-01-05 21:00 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Windows Updates Files
2021-01-05 20:05 - 2021-01-05 20:53 - 000000270 __RSH C:\ProgramData\ntuser.pol
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files\Reference Assemblies
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files\MSBuild
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2021-01-05 20:05 - 2021-01-05 20:05 - 000000000 ____D C:\Program Files (x86)\MSBuild
2021-01-05 20:01 - 2021-01-06 12:16 - 000000000 ____D C:\Users\Lenovo\Downloads\_Oceanofgames.com_Lord_of_the_Ring_Conquest
2021-01-05 19:49 - 2021-01-12 11:13 - 000000000 ____D C:\Program Files (x86)\WinRAR
2021-01-05 19:49 - 2021-01-05 19:49 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\WinRAR
2021-01-05 16:32 - 2021-01-05 16:33 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\My Battle for Middle-earth Files
2021-01-05 16:31 - 2021-01-05 16:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2021-01-05 16:15 - 2021-01-05 16:15 - 000000000 ____D C:\Program Files (x86)\EA GAMES
2021-01-05 16:04 - 2021-01-05 16:04 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Macromedia
2021-01-04 20:42 - 2021-01-12 11:13 - 000000000 ____D C:\Program Files\Mozilla Firefox
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-12 12:48 - 2020-10-09 10:28 - 000000000 ____D C:\Users\Lenovo\AppData\LocalLow\Mozilla
2021-01-12 12:47 - 2020-10-11 09:02 - 000000000 ____D C:\Program Files\CCleaner
2021-01-12 12:46 - 2020-10-09 10:17 - 000000000 ____D C:\ProgramData\Mozilla
2021-01-12 12:45 - 2020-10-09 10:43 - 000000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2021-01-12 12:45 - 2020-10-09 09:50 - 000008192 ___SH C:\DumpStack.log.tmp
2021-01-12 12:45 - 2020-10-09 09:50 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-01-12 12:45 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-12 12:44 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2021-01-12 12:38 - 2020-10-09 09:50 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-01-12 11:22 - 2020-10-09 09:59 - 001693136 _____ C:\Windows\system32\PerfStringBackup.INI
2021-01-12 11:22 - 2019-12-07 15:41 - 000718010 _____ C:\Windows\system32\perfh005.dat
2021-01-12 11:22 - 2019-12-07 15:41 - 000145152 _____ C:\Windows\system32\perfc005.dat
2021-01-12 11:22 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2021-01-12 11:13 - 2020-10-09 10:17 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-01-11 20:25 - 2020-10-09 10:17 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-01-11 20:19 - 2020-10-15 08:54 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-01-11 20:19 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-01-11 20:19 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2021-01-11 19:40 - 2020-10-11 09:02 - 000004210 _____ C:\Windows\system32\Tasks\CCleaner Update
2021-01-06 12:20 - 2020-10-11 10:38 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\MPC-HC
2021-01-06 12:18 - 2020-10-14 13:45 - 000000000 ____D C:\Users\Lenovo\Desktop\Filmy
2021-01-05 20:06 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2021-01-05 20:05 - 2019-12-07 10:14 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2021-01-05 20:05 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\MUI
2021-01-05 20:05 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\MUI
2021-01-05 16:10 - 2020-10-09 10:16 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\AIMP
2020-12-19 11:41 - 2020-10-11 10:09 - 000000000 ____D C:\Windows\Minidump
2020-12-19 11:40 - 2020-10-11 09:02 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================