Klávesnice místo písmene "t" napíše "t.n" atd.
Napsal: 22 bře 2021 19:59
Dobrý večer,
na PC mi klávesnice píše nesmysly. Můžete mi prosím poradit jak to odstranit. Zkoušel jsem i jinou klávesnici, ale píše to pořád to samé.
Přikládám logy
Děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-03-2021
Ran by Josef (administrator) on DESKTOP-LODLLRJ (Gigabyte Technology Co., Ltd. GA-880GM-UD2H) (22-03-2021 19:41:07)
Running from E:\
Loaded Profiles: Josef
Platform: Windows 10 Home Version 20H2 19042.870 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Josef\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2102.8653.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2005.5-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2005.5-0\NisSrv.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1717840255-3575298095-3356635107-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32726088 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\89.0.4389.90\Installer\chrmstp.exe [2021-03-17] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {25E93C60-DAA4-4EAA-A8F8-60FC0FA51044} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [694256 2021-03-16] (Mozilla Corporation -> Mozilla Foundation)
Task: {3754F6FD-8E90-4F45-8384-06F4FD585E7D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [27168840 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {4760D19D-3918-4D6E-ADC7-01C972C91A74} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-02-16] (Piriform Software Ltd -> Piriform)
Task: {6C14239D-0A78-409A-9BA3-FD1A4BC86ED2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {851478CE-E6EE-4FF4-875A-C4B617F26E81} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8CDE5792-D120-4B57-96BD-10385DA7D805} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-12-06] (Google Inc -> Google LLC)
Task: {8F7E5F7D-3BB7-4151-812C-956F1DF8ED31} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {AAF43864-DBA0-4ABB-8A74-88AAC52E02F0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B53EA97A-ED59-4030-85EC-FDD16BEB0724} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-12-06] (Google Inc -> Google LLC)
Task: {D324E5A9-1B20-4DC6-9608-5254D12F2C50} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{ca4ed10a-0de0-4def-be89-bfb3f6698db7}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Josef\AppData\Local\Microsoft\Edge\User Data\Default [2021-03-22]
FireFox:
========
FF DefaultProfile: 5cs2abu7.default
FF ProfilePath: C:\Users\Josef\AppData\Roaming\Mozilla\Firefox\Profiles\5cs2abu7.default [2020-02-25]
FF Extension: (Avast SafePrice | Srovnání, výhodné nabídky, kupóny) - C:\Users\Josef\AppData\Roaming\Mozilla\Firefox\Profiles\5cs2abu7.default\Extensions\sp@avast.com.xpi [2020-01-11]
FF ProfilePath: C:\Users\Josef\AppData\Roaming\Mozilla\Firefox\Profiles\fwp4ufek.default-release [2021-03-22]
FF Homepage: Mozilla\Firefox\Profiles\fwp4ufek.default-release -> www.seznam.cz
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default [2021-03-22]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Prezentace) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-01-02]
CHR Extension: (Dokumenty) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-01-02]
CHR Extension: (Disk Google) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-01-02]
CHR Extension: (YouTube) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-01-02]
CHR Extension: (Tabulky) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-01-02]
CHR Extension: (Dokumenty Google offline) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-03-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-27]
CHR Extension: (Gmail) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-01-02]
CHR Extension: (Chrome Media Router) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-16]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5352528 2021-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\NisSrv.exe [2484256 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MsMpEng.exe [103168 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-06-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [401120 2020-06-04] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64224 2020-06-04] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-22 19:34 - 2021-03-22 19:42 - 000000000 ____D C:\FRST
2021-03-22 16:15 - 2021-03-22 16:16 - 000000000 ____D C:\AdwCleaner
2021-03-22 11:52 - 2021-03-22 11:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2021-03-22 09:52 - 2021-03-22 09:52 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-03-16 14:58 - 2021-03-16 14:58 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-03-16 09:37 - 2021-03-16 14:58 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-03-14 10:39 - 2021-03-14 10:39 - 000220613 _____ C:\Users\Josef\Desktop\1 4pxTenmsOGqge3LWz8k2_A.jpeg
2021-03-12 15:32 - 2021-03-12 15:32 - 000480256 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2021-03-12 15:29 - 2021-03-12 15:29 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-03-12 15:27 - 2021-03-12 15:27 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-03-12 15:27 - 2021-03-12 15:27 - 001314128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-03-12 15:25 - 2021-03-12 15:25 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-03-12 15:25 - 2021-03-12 15:25 - 000611952 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2021-03-12 15:23 - 2021-03-12 15:23 - 001822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-03-12 15:23 - 2021-03-12 15:23 - 001394024 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-03-12 15:22 - 2021-03-12 15:22 - 000707016 _____ C:\WINDOWS\system32\TextShaping.dll
2021-03-12 15:22 - 2021-03-12 15:22 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-03-12 15:22 - 2021-03-12 15:22 - 000091136 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-22 19:41 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-03-22 19:40 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2021-03-22 19:33 - 2020-11-14 18:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-03-22 19:26 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-03-22 19:14 - 2020-11-14 19:05 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-03-22 19:12 - 2020-11-14 18:42 - 000008192 ___SH C:\DumpStack.log.tmp
2021-03-22 19:12 - 2020-01-11 17:41 - 000000000 ____D C:\Program Files\CCleaner
2021-03-22 19:10 - 2020-11-14 19:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-03-22 19:10 - 2020-01-11 17:44 - 000000000 ____D C:\ProgramData\AVAST Software
2021-03-22 19:10 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-03-22 19:02 - 2021-01-03 15:30 - 000000000 ____D C:\Users\Josef\AppData\Local\AVAST Software
2021-03-22 16:08 - 2020-01-11 16:02 - 000000000 ____D C:\Users\Josef\AppData\LocalLow\Mozilla
2021-03-22 16:08 - 2020-01-11 16:02 - 000000000 ____D C:\ProgramData\Mozilla
2021-03-22 10:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-03-22 10:36 - 2020-11-14 18:46 - 000000000 ____D C:\Users\Josef
2021-03-22 09:52 - 2015-07-10 14:20 - 000413706 __RSH C:\bootmgr
2021-03-22 09:34 - 2020-01-11 18:04 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-03-20 11:58 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-03-20 11:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-03-19 07:35 - 2020-11-15 00:38 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-03-18 15:57 - 2020-12-06 15:56 - 000003400 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-03-18 15:57 - 2020-12-06 15:56 - 000003176 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-03-18 15:57 - 2020-11-23 15:21 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-03-18 15:57 - 2020-11-15 00:37 - 000003512 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-03-18 15:57 - 2020-11-15 00:37 - 000003288 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-03-18 15:57 - 2020-11-14 19:05 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1717840255-3575298095-3356635107-1001
2021-03-18 15:57 - 2020-11-14 19:05 - 000002238 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2021-03-17 12:24 - 2020-12-06 15:57 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-03-16 14:58 - 2020-01-11 16:02 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-03-16 14:58 - 2020-01-11 16:02 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-03-13 10:01 - 2020-11-14 18:46 - 000002365 _____ C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-03-13 10:01 - 2020-01-11 15:49 - 000000000 ___RD C:\Users\Josef\OneDrive
2021-03-12 18:53 - 2020-11-14 18:42 - 000348248 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-03-12 18:51 - 2019-12-07 15:47 - 000000000 ___SD C:\WINDOWS\system32\AppV
2021-03-12 18:51 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-03-12 09:34 - 2020-01-11 18:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-03-12 09:28 - 2020-01-11 18:06 - 131005360 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-03-04 10:20 - 2020-01-12 00:12 - 000000000 ____D C:\Users\Josef\AppData\Local\PlaceholderTileLogoFolder
2021-02-26 14:50 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-02-26 08:22 - 2020-01-18 16:21 - 000000000 ____D C:\Users\Josef\AppData\Local\CrashDumps
2021-02-21 17:04 - 2020-08-15 09:36 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
# -------------------------------
# Malwarebytes AdwCleaner 8.1.0.0
# -------------------------------
# Build: 02-15-2021
# Database: 2021-03-22.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 03-22-2021
# Duration: 00:00:17
# OS: Windows 10 Home
# Scanned: 2005
# Detected: 0
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
No malicious registry entries found.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
No Preinstalled Software found.
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
na PC mi klávesnice píše nesmysly. Můžete mi prosím poradit jak to odstranit. Zkoušel jsem i jinou klávesnici, ale píše to pořád to samé.
Přikládám logy
Děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-03-2021
Ran by Josef (administrator) on DESKTOP-LODLLRJ (Gigabyte Technology Co., Ltd. GA-880GM-UD2H) (22-03-2021 19:41:07)
Running from E:\
Loaded Profiles: Josef
Platform: Windows 10 Home Version 20H2 19042.870 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Josef\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2102.8653.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2005.5-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2005.5-0\NisSrv.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1717840255-3575298095-3356635107-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32726088 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\89.0.4389.90\Installer\chrmstp.exe [2021-03-17] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {25E93C60-DAA4-4EAA-A8F8-60FC0FA51044} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [694256 2021-03-16] (Mozilla Corporation -> Mozilla Foundation)
Task: {3754F6FD-8E90-4F45-8384-06F4FD585E7D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [27168840 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {4760D19D-3918-4D6E-ADC7-01C972C91A74} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-02-16] (Piriform Software Ltd -> Piriform)
Task: {6C14239D-0A78-409A-9BA3-FD1A4BC86ED2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {851478CE-E6EE-4FF4-875A-C4B617F26E81} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8CDE5792-D120-4B57-96BD-10385DA7D805} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-12-06] (Google Inc -> Google LLC)
Task: {8F7E5F7D-3BB7-4151-812C-956F1DF8ED31} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {AAF43864-DBA0-4ABB-8A74-88AAC52E02F0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B53EA97A-ED59-4030-85EC-FDD16BEB0724} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-12-06] (Google Inc -> Google LLC)
Task: {D324E5A9-1B20-4DC6-9608-5254D12F2C50} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MpCmdRun.exe [491104 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{ca4ed10a-0de0-4def-be89-bfb3f6698db7}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Josef\AppData\Local\Microsoft\Edge\User Data\Default [2021-03-22]
FireFox:
========
FF DefaultProfile: 5cs2abu7.default
FF ProfilePath: C:\Users\Josef\AppData\Roaming\Mozilla\Firefox\Profiles\5cs2abu7.default [2020-02-25]
FF Extension: (Avast SafePrice | Srovnání, výhodné nabídky, kupóny) - C:\Users\Josef\AppData\Roaming\Mozilla\Firefox\Profiles\5cs2abu7.default\Extensions\sp@avast.com.xpi [2020-01-11]
FF ProfilePath: C:\Users\Josef\AppData\Roaming\Mozilla\Firefox\Profiles\fwp4ufek.default-release [2021-03-22]
FF Homepage: Mozilla\Firefox\Profiles\fwp4ufek.default-release -> www.seznam.cz
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default [2021-03-22]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Prezentace) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-01-02]
CHR Extension: (Dokumenty) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-01-02]
CHR Extension: (Disk Google) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-01-02]
CHR Extension: (YouTube) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-01-02]
CHR Extension: (Tabulky) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-01-02]
CHR Extension: (Dokumenty Google offline) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-03-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-27]
CHR Extension: (Gmail) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-01-02]
CHR Extension: (Chrome Media Router) - C:\Users\Josef\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-16]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5352528 2021-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\NisSrv.exe [2484256 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MsMpEng.exe [103168 2020-06-04] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-06-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [401120 2020-06-04] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64224 2020-06-04] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-22 19:34 - 2021-03-22 19:42 - 000000000 ____D C:\FRST
2021-03-22 16:15 - 2021-03-22 16:16 - 000000000 ____D C:\AdwCleaner
2021-03-22 11:52 - 2021-03-22 11:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2021-03-22 09:52 - 2021-03-22 09:52 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-03-16 14:58 - 2021-03-16 14:58 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-03-16 09:37 - 2021-03-16 14:58 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-03-14 10:39 - 2021-03-14 10:39 - 000220613 _____ C:\Users\Josef\Desktop\1 4pxTenmsOGqge3LWz8k2_A.jpeg
2021-03-12 15:32 - 2021-03-12 15:32 - 000480256 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2021-03-12 15:29 - 2021-03-12 15:29 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-03-12 15:27 - 2021-03-12 15:27 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-03-12 15:27 - 2021-03-12 15:27 - 001314128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-03-12 15:25 - 2021-03-12 15:25 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-03-12 15:25 - 2021-03-12 15:25 - 000611952 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2021-03-12 15:23 - 2021-03-12 15:23 - 001822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-03-12 15:23 - 2021-03-12 15:23 - 001394024 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-03-12 15:22 - 2021-03-12 15:22 - 000707016 _____ C:\WINDOWS\system32\TextShaping.dll
2021-03-12 15:22 - 2021-03-12 15:22 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-03-12 15:22 - 2021-03-12 15:22 - 000091136 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-03-22 19:41 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-03-22 19:40 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2021-03-22 19:33 - 2020-11-14 18:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-03-22 19:26 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-03-22 19:14 - 2020-11-14 19:05 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-03-22 19:12 - 2020-11-14 18:42 - 000008192 ___SH C:\DumpStack.log.tmp
2021-03-22 19:12 - 2020-01-11 17:41 - 000000000 ____D C:\Program Files\CCleaner
2021-03-22 19:10 - 2020-11-14 19:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-03-22 19:10 - 2020-01-11 17:44 - 000000000 ____D C:\ProgramData\AVAST Software
2021-03-22 19:10 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-03-22 19:02 - 2021-01-03 15:30 - 000000000 ____D C:\Users\Josef\AppData\Local\AVAST Software
2021-03-22 16:08 - 2020-01-11 16:02 - 000000000 ____D C:\Users\Josef\AppData\LocalLow\Mozilla
2021-03-22 16:08 - 2020-01-11 16:02 - 000000000 ____D C:\ProgramData\Mozilla
2021-03-22 10:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-03-22 10:36 - 2020-11-14 18:46 - 000000000 ____D C:\Users\Josef
2021-03-22 09:52 - 2015-07-10 14:20 - 000413706 __RSH C:\bootmgr
2021-03-22 09:34 - 2020-01-11 18:04 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-03-20 11:58 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-03-20 11:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-03-19 07:35 - 2020-11-15 00:38 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-03-18 15:57 - 2020-12-06 15:56 - 000003400 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-03-18 15:57 - 2020-12-06 15:56 - 000003176 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-03-18 15:57 - 2020-11-23 15:21 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-03-18 15:57 - 2020-11-15 00:37 - 000003512 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-03-18 15:57 - 2020-11-15 00:37 - 000003288 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-03-18 15:57 - 2020-11-14 19:05 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1717840255-3575298095-3356635107-1001
2021-03-18 15:57 - 2020-11-14 19:05 - 000002238 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2021-03-17 12:24 - 2020-12-06 15:57 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-03-16 14:58 - 2020-01-11 16:02 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-03-16 14:58 - 2020-01-11 16:02 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-03-13 10:01 - 2020-11-14 18:46 - 000002365 _____ C:\Users\Josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-03-13 10:01 - 2020-01-11 15:49 - 000000000 ___RD C:\Users\Josef\OneDrive
2021-03-12 18:53 - 2020-11-14 18:42 - 000348248 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-03-12 18:51 - 2019-12-07 15:47 - 000000000 ___SD C:\WINDOWS\system32\AppV
2021-03-12 18:51 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-03-12 18:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-03-12 09:34 - 2020-01-11 18:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-03-12 09:28 - 2020-01-11 18:06 - 131005360 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-03-04 10:20 - 2020-01-12 00:12 - 000000000 ____D C:\Users\Josef\AppData\Local\PlaceholderTileLogoFolder
2021-02-26 14:50 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-02-26 08:22 - 2020-01-18 16:21 - 000000000 ____D C:\Users\Josef\AppData\Local\CrashDumps
2021-02-21 17:04 - 2020-08-15 09:36 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
# -------------------------------
# Malwarebytes AdwCleaner 8.1.0.0
# -------------------------------
# Build: 02-15-2021
# Database: 2021-03-22.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 03-22-2021
# Duration: 00:00:17
# OS: Windows 10 Home
# Scanned: 2005
# Detected: 0
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
No malicious registry entries found.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
No Preinstalled Software found.
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########