samovolné otevírání oken Chrom - prosím o kontrolu
Napsal: 02 zář 2022 07:59
Dobrý den,
stává se mi, že při kliknutí na odkaz (libovolné stránky) se mi otevře okno s erotickou nebo jinou tématikou. Smazal jsem obsah prohlížeče atd. Antivir nehlásí nic špatného.
prosím o kontrolu logů:
Děkuji.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
Ran by Prodejna (02-09-2022 08:41:31)
Running from C:\Users\Prodejna\Desktop
Microsoft Windows 10 Home Version 21H2 19044.1889 (X64) (2020-08-26 16:05:35)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-3885610105-3758572810-27774397-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3885610105-3758572810-27774397-503 - Limited - Disabled)
Guest (S-1-5-21-3885610105-3758572810-27774397-501 - Limited - Disabled)
Prodejna (S-1-5-21-3885610105-3758572810-27774397-1001 - Administrator - Enabled) => C:\Users\Prodejna
WDAGUtilityAccount (S-1-5-21-3885610105-3758572810-27774397-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Bitdefender Antivirus (Enabled - Up to date) {840E1EB8-082E-3D95-EAAA-FD11CF357A26}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {BC359F9D-4241-3CCD-C1F5-542431E63D5D}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (HKLM\...\{C788B026-20BD-4E96-B698-533F1D6C5013}) (Version: 7.2.4 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 22.002.20191 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-001824458876}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 6.0.7 - philandro Software GmbH)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 26.0.1.231 - Bitdefender)
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 23.0.16.72 - Bitdefender)
Canon LBP6310 (HKLM\...\Canon LBP6310) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 6.03 - Piriform)
eM Client (HKLM-x32\...\{DCA2551A-C6C8-413E-85B5-5FECAAE001AF}) (Version: 8.2.1659.0 - eM Client Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 105.0.5195.54 - Google LLC)
Honeywell HSM USB Serial Drv x64 ver 3.5.9 (HKLM\...\{1224D576-15FA-464A-B1E8-5CB53942847A}) (Version: 3.5.9 - Honeywell)
HP LaserJet Professional M1530 MFP Series (HKLM-x32\...\{74280B5D-A0AF-46c5-9C85-D9EA078262F1}) (Version: 15.0.15188.928 - Hewlett-Packard)
HP LJ M1530 MFP Series HP Scan (HKLM-x32\...\{C05002F1-06F8-4A15-B6F8-E4DC655C28AA}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP Unified IO (HKLM\...\{5C76ED0D-0F6F-4985-8B34-F9AE7834848F}) (Version: 2.0.0.434 - HP) Hidden
HP Unified IO (HKLM-x32\...\{F1390872-2500-4408-A46C-CD16C960C661}) (Version: 2.0.0.434 - HP) Hidden
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 104.0.1293.70 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 104.0.1293.70 - Microsoft Corporation)
Microsoft Office Access database engine 2007 (English) (HKLM-x32\...\{90120000-00D1-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\OneDriveSetup.exe) (Version: 22.166.0807.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27024 (HKLM-x32\...\{2ff11a2a-f7ac-4a6c-8cd4-c7bb974f3642}) (Version: 14.16.27024.1 - Microsoft Corporation)
Microsoft Visual C++ 2017 X86 Additional Runtime - 14.16.27024 (HKLM-x32\...\{7258184A-EC44-4B1A-A7D3-68D85A35BFD0}) (Version: 14.16.27024 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 X86 Minimum Runtime - 14.16.27024 (HKLM-x32\...\{5EEFCEFB-E5F7-4C82-99A5-813F04AA4FBD}) (Version: 14.16.27024 - Microsoft Corporation) Hidden
QNAP Qsync Client (HKLM-x32\...\Qsync) (Version: 5.0.5.0620 - QNAP Systems, Inc.)
Sticky Password 8.3.1.10 (HKLM-x32\...\Sticky Password_is1) (Version: 8.3 - Lamantine Software)
STORMWARE POHODA E1 Klient CZ Premium (HKLM-x32\...\{775B81F0-CD06-42D2-9BD1-1C27AA9355D0}) (Version: 12100.85 - STORMWARE)
STORMWARE POHODA Start CZ (HKLM-x32\...\{EE8FCA5D-FD65-4138-AF76-FD44473DD374}) (Version: 12204.28 - STORMWARE)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.2.36224 - TeamViewer)
TSP100 Setup Version 7.4.0 (HKLM\...\{F273C16D-1109-417F-84B3-5115A9F5B6D5}) (Version: 7.4.0 - Star Micronics)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{B2E25355-C24E-4E7D-8AD3-455D59810838}) (Version: 2.57.0.0 - Microsoft Corporation)
Viber (HKLM-x32\...\{4821E6B5-9C96-48E7-B0AC-AB3E8EEB6958}) (Version: 9.6.5.16 - Viber Media Inc.) Hidden
Viber (HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\{6af7d50d-3e8e-465c-8e56-bbe86869755b}) (Version: 9.6.5.16 - Viber Media Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN)
WPS Office (11.2.0.11254) (HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\Kingsoft Office) (Version: 11.2.0.11254 - Kingsoft Corp.)
Packages:
=========
Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.2340.1.0_x64__kgqvnymyfvs32 [2022-08-22] (king.com)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.225.300.0_x64__kgqvnymyfvs32 [2022-08-26] (king.com)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.14.67.0_x64__rz1tebttyb220 [2022-07-11] (Dolby Laboratories)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-01-15] (Microsoft Corporation)
Hidden City: Hidden Object Adventure -> C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.49.4904.0_x86__ytsefhwckbdv6 [2022-08-23] (G5 Entertainment AB)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_138.2.412.0_x64__v10z8vjag6ke6 [2022-08-25] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-23] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-23] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.13.7180.0_x64__8wekyb3d8bbwe [2022-07-29] (Microsoft Studios) [MS Ad]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{28A80003-18FD-411D-B0A3-3C81F618E22B}\InprocServer32 -> C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\11.2.0.11254\office6\kwpsmenushellext64.dll (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{57D0E8CF-2552-4B76-A5C4-B1E9D413FD14} -> [Qsync] => C:\Users\Prodejna\AppData\Local\QNAP\Qsync\Quick Access [2018-09-18 15:14]
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{6166E16F-FE11-4C78-94E3-DD042B15E50B} -> [QNAP Qsync Client: ALPNAS (Qsync)] => C:\Users\Prodejna\Qsync [2018-09-18 15:16]
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [ QsyncEx_Icon1] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [ QsyncEx_Icon2] -> {A31C3AF7-2870-4121-AF94-1BF770A2C95B} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [ QsyncEx_Icon3] -> {7937C765-6EFA-4184-A69C-1101127615E8} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [ QsyncEx_Icon4] -> {DDA7CE77-08EA-4047-A53E-C4FB10C307F2} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers1: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers4: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-04] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers6: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers1_S-1-5-21-3885610105-3758572810-27774397-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\11.2.0.11254\office6\kwpsmenushellext64.dll [2022-08-08] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
ContextMenuHandlers4_S-1-5-21-3885610105-3758572810-27774397-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\11.2.0.11254\office6\kwpsmenushellext64.dll [2022-08-08] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2021-09-09 13:24 - 2021-09-09 13:24 - 000011264 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Accounts.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000003584 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Commands.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000009216 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Common.UI.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000004608 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Protocols.Gdata.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000007680 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Protocols.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000006656 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Protocols.Smtp.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000821248 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.resources.dll
2021-06-24 11:56 - 2021-06-24 11:56 - 001206784 _____ () [File not signed] C:\Program Files (x86)\eM Client\e_sqlite3.DLL
2021-07-06 13:33 - 2021-07-06 13:33 - 093837824 _____ () [File not signed] C:\Program Files (x86)\eM Client\libcef\libcef.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000188928 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\IOTCAPIs.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000037376 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\json-c.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000039424 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\P2PTunnelAPIs.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 000166400 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\RdiffDll.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000031232 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\RDTAPIs.dll
2018-05-31 18:00 - 2018-05-31 18:00 - 000090112 _____ () [File not signed] C:\Program Files (x86)\StarMicronics\TSP100\Software\20171207\StarMicronicsCloudNativeLibrary_futurePRNT.dll
2021-05-14 07:10 - 2020-11-30 17:17 - 001101824 _____ () [File not signed] C:\Program Files (x86)\Sticky Password\DLLs\_hashlib.pyd
2018-05-31 18:01 - 2018-05-31 18:01 - 000111616 _____ () [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarMicronicsCloudNativeLibrary_futurePRNT.dll
2021-03-19 03:04 - 2021-03-19 03:04 - 000143872 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Auth.dll
2020-10-26 18:09 - 2020-10-26 18:09 - 000093696 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Calendar.v3.dll
2021-03-19 03:04 - 2021-03-19 03:04 - 000076800 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Core.dll
2021-03-19 03:04 - 2021-03-19 03:04 - 000080896 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.dll
2020-10-22 18:11 - 2020-10-22 18:11 - 000111616 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Gmail.v1.dll
2021-03-25 18:17 - 2021-03-25 18:17 - 000093184 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.PeopleService.v1.dll
2020-10-22 18:12 - 2020-10-22 18:12 - 000029696 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Tasks.v1.dll
2009-09-16 18:44 - 2009-09-16 18:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hptcpmib.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\HpTcpMon.dll
2009-09-16 11:44 - 2009-09-16 11:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hpzjrd01.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\System32\HPTcpMUI.dll
2021-06-24 18:34 - 2021-06-24 18:34 - 000006144 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.batteries_v2.dll
2021-06-24 18:33 - 2021-06-24 18:33 - 000050176 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.core.dll
2021-06-24 18:33 - 2021-06-24 18:33 - 000005632 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.nativelibrary.dll
2021-06-24 18:34 - 2021-06-24 18:34 - 000061440 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.provider.dynamic_cdecl.dll
2017-12-22 17:01 - 2017-12-22 17:01 - 000173056 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\CommandEmulator.dll
2017-12-22 17:03 - 2017-12-22 17:03 - 000157184 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\CompGAF.dll
2017-12-22 17:01 - 2017-12-22 17:01 - 000417280 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\Configuration.dll
2017-12-22 17:03 - 2017-12-22 17:03 - 003606016 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\ESCPOSSE.dll
2017-12-22 17:02 - 2017-12-22 17:02 - 000335360 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\GenericAction.dll
2015-10-27 10:28 - 2015-10-27 10:28 - 000486912 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarIOPort.dll
2017-12-22 17:03 - 2017-12-22 17:03 - 006893568 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarLineModeSE.dll
2017-12-22 17:02 - 2017-12-22 17:02 - 000144896 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarTSPTC.dll
2017-12-22 17:01 - 2017-12-22 17:01 - 000110592 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\TargetAction.dll
2018-05-28 20:33 - 2018-05-28 20:33 - 000595456 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\tsp100lm.dll
2018-05-28 20:36 - 2018-05-28 20:36 - 000360960 _____ (Star Micronics Co., Ltd.) [File not signed] C:\WINDOWS\System32\smjt100epm.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 000394752 _____ (The curl library, hxxps://curl.se/) [File not signed] C:\Program Files (x86)\QNAP\Qsync\libcurl.dll
2021-07-06 13:33 - 2021-07-06 13:33 - 000729600 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\eM Client\libcef\chrome_elf.dll
2021-07-15 17:23 - 2021-07-15 17:23 - 002953216 _____ (The Legion of the Bouncy Castle Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\BouncyCastle.Crypto.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 002052096 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\QNAP\Qsync\libcrypto-1_1.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 000497664 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\QNAP\Qsync\libssl-1_1.dll
2021-10-07 13:25 - 2021-10-07 13:25 - 000442368 _____ (Thomas Maierhofer) [File not signed] C:\Program Files (x86)\eM Client\Hunspellx86.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:40C12C39 [130]
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
BHO: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\bdtbie.dll [2022-08-09] (Bitdefender SRL -> Bitdefender)
BHO: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2022-07-15] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\antispam32\bdtbie.dll [2022-08-30] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2022-08-30] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2022-07-15] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM-x32 - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2022-08-30] (Bitdefender SRL -> Bitdefender)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-12 01:38 - 2022-07-14 16:41 - 000000000 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3885610105-3758572810-27774397-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img1.jpg
DNS Servers: 192.168.1.1 - 31.30.90.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{0F040FCB-3BAB-4F47-890C-7E788E016738}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{57E9CC07-3611-4913-89E7-DD4AF746EDF6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{876E1849-4C0B-4CFB-8778-DA5DE0A4472F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{17EFE983-6508-431F-BC39-45096CC63B0B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{56B500F7-262B-4569-AA76-EC6C903284C2}] => (Allow) C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\10.2.0.7646\office6\wpscloudsvr.exe => No File
FirewallRules: [{B4260383-F094-4A50-9494-5BE87E65887A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0AC2FDA9-78EA-476E-BEFD-B134BBD52068}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{C46806FD-F14C-4AD2-B53D-A6444BF5C762}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{50505813-1E26-42FD-8200-0FCA4368FEEA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{56F71A60-A7B9-48DF-B440-01BBD8237E4B}] => (Allow) C:\Program Files (x86)\Sticky Password\stpass.exe (Lamantine Software a.s. -> Lamantine Software a.s.)
FirewallRules: [{4E3AF8D8-B640-4723-A827-E844687A0063}] => (Allow) C:\Program Files (x86)\Sticky Password\stpass.exe (Lamantine Software a.s. -> Lamantine Software a.s.)
FirewallRules: [TCP Query User{2700165C-BE15-44D7-9B42-E12F60167710}C:\program files (x86)\qnap\qsync\qsync.exe] => (Block) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [UDP Query User{CB6AF4E3-CCCD-4969-BAEE-428DFEA61FA7}C:\program files (x86)\qnap\qsync\qsync.exe] => (Block) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [{01CD1BF3-3E2D-40AA-8791-A51547D139D8}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{BA5AD4E9-73DB-4B57-A94D-5B0CDA30712A}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{B4086070-3A9F-4328-A7FD-DFC9352CDE2C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{AC855F51-32C8-4F5B-9469-D5C93A6A400C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{0332DC71-9D4F-4084-8E81-A627599D77E7}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{F33EA30B-F6D5-485D-96B8-D0BEF940E200}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{E9F3E863-C3C0-4D93-96F5-91D5DA98C87F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{63CA8BED-5FE2-4ECC-9B93-70F3E8378084}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{58D9FC45-DB46-400D-BDC2-B75ACA201488}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F9637543-3A97-4CF4-AF55-08256C1CDE41}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AF5C8A01-2CB0-4994-8645-8AB9912ADBBF}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\104.0.1293.70\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B17B62CC-E0CD-4BD4-A879-4F560C013FBD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
17-08-2022 08:05:18 Naplánovaný kontrolní bod
25-08-2022 08:06:54 Naplánovaný kontrolní bod
==================== Faulty Device Manager Devices ============
Name: Intel(R) Trusted Execution Engine Interface
Description: Intel(R) Trusted Execution Engine Interface
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: TXEIx64
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: ========================
Application errors:
==================
Error: (07/15/2022 08:14:02 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_OFF došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 18) (User: )
Description: Službě Centrum zabezpečení Windows se nepodařilo načíst instance objektu FirewallProduct z úložiště dat.
Error: (07/14/2022 08:18:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.1741 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.
ID procesu: 247c
Čas spuštění: 01d89747317a48f9
Čas ukončení: 4294967295
Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
ID hlášení: 2e8ea768-813a-4b91-8793-cc9cd0fbc30a
Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.5.19041_neutral_neutral_cw5n1h2txyewy
ID aplikace relativní podle balíčku s chybou: ShellFeedsUI
Typ zablokování: Quiesce
Error: (07/04/2022 04:44:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.1741 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.
ID procesu: 15cc
Čas spuštění: 01d88f6a46ae440d
Čas ukončení: 4294967295
Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
ID hlášení: acdbf1f3-0cf8-4579-a358-4c1109759eb3
Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.5.19041_neutral_neutral_cw5n1h2txyewy
ID aplikace relativní podle balíčku s chybou: ShellFeedsUI
Typ zablokování: Quiesce
System errors:
=============
Error: (09/01/2022 05:01:31 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server Microsoft.MicrosoftOfficeHub_18.2205.1091.0_x64__8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub.AppXvhez9tbpytkh6zv5q0bx5fj12yay14wg.mca se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/29/2022 05:00:38 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/29/2022 05:00:38 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/26/2022 04:58:52 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/26/2022 04:58:52 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/26/2022 07:43:43 AM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/25/2022 05:00:34 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/25/2022 05:00:34 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
CodeIntegrity:
===============
Date: 2022-09-02 07:58:12
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdamsi\266126562904114456\antimalware_provider64.dll that did not meet the Windows signing level requirements.
Date: 2022-09-01 14:53:13
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdamsi\266126562904114456\antimalware_provider64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: Insyde P12-A1 01/12/2015
Motherboard: Acer UI2H
Processor: Intel(R) Pentium(R) CPU N3540 @ 2.16GHz
Percentage of memory in use: 89%
Total physical RAM: 3983.45 MB
Available physical RAM: 413.14 MB
Total Virtual: 7824.24 MB
Available Virtual: 1103.13 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.29 GB) (Free:150.07 GB) (Model: Samsung SSD 860 EVO 250GB) NTFS
\\?\Volume{78a31b23-032d-46a9-9151-c8d97db5dbab}\ (Obnovení) (Fixed) (Total:0.49 GB) (Free:0.05 GB) NTFS
\\?\Volume{451917f6-2d3b-4da2-a73d-920895cd7209}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
stává se mi, že při kliknutí na odkaz (libovolné stránky) se mi otevře okno s erotickou nebo jinou tématikou. Smazal jsem obsah prohlížeče atd. Antivir nehlásí nic špatného.
prosím o kontrolu logů:
Děkuji.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
Ran by Prodejna (02-09-2022 08:41:31)
Running from C:\Users\Prodejna\Desktop
Microsoft Windows 10 Home Version 21H2 19044.1889 (X64) (2020-08-26 16:05:35)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-3885610105-3758572810-27774397-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3885610105-3758572810-27774397-503 - Limited - Disabled)
Guest (S-1-5-21-3885610105-3758572810-27774397-501 - Limited - Disabled)
Prodejna (S-1-5-21-3885610105-3758572810-27774397-1001 - Administrator - Enabled) => C:\Users\Prodejna
WDAGUtilityAccount (S-1-5-21-3885610105-3758572810-27774397-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Bitdefender Antivirus (Enabled - Up to date) {840E1EB8-082E-3D95-EAAA-FD11CF357A26}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {BC359F9D-4241-3CCD-C1F5-542431E63D5D}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (HKLM\...\{C788B026-20BD-4E96-B698-533F1D6C5013}) (Version: 7.2.4 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 22.002.20191 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-001824458876}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 6.0.7 - philandro Software GmbH)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 26.0.1.231 - Bitdefender)
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 23.0.16.72 - Bitdefender)
Canon LBP6310 (HKLM\...\Canon LBP6310) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 6.03 - Piriform)
eM Client (HKLM-x32\...\{DCA2551A-C6C8-413E-85B5-5FECAAE001AF}) (Version: 8.2.1659.0 - eM Client Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 105.0.5195.54 - Google LLC)
Honeywell HSM USB Serial Drv x64 ver 3.5.9 (HKLM\...\{1224D576-15FA-464A-B1E8-5CB53942847A}) (Version: 3.5.9 - Honeywell)
HP LaserJet Professional M1530 MFP Series (HKLM-x32\...\{74280B5D-A0AF-46c5-9C85-D9EA078262F1}) (Version: 15.0.15188.928 - Hewlett-Packard)
HP LJ M1530 MFP Series HP Scan (HKLM-x32\...\{C05002F1-06F8-4A15-B6F8-E4DC655C28AA}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP Unified IO (HKLM\...\{5C76ED0D-0F6F-4985-8B34-F9AE7834848F}) (Version: 2.0.0.434 - HP) Hidden
HP Unified IO (HKLM-x32\...\{F1390872-2500-4408-A46C-CD16C960C661}) (Version: 2.0.0.434 - HP) Hidden
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 104.0.1293.70 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 104.0.1293.70 - Microsoft Corporation)
Microsoft Office Access database engine 2007 (English) (HKLM-x32\...\{90120000-00D1-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\OneDriveSetup.exe) (Version: 22.166.0807.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27024 (HKLM-x32\...\{2ff11a2a-f7ac-4a6c-8cd4-c7bb974f3642}) (Version: 14.16.27024.1 - Microsoft Corporation)
Microsoft Visual C++ 2017 X86 Additional Runtime - 14.16.27024 (HKLM-x32\...\{7258184A-EC44-4B1A-A7D3-68D85A35BFD0}) (Version: 14.16.27024 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 X86 Minimum Runtime - 14.16.27024 (HKLM-x32\...\{5EEFCEFB-E5F7-4C82-99A5-813F04AA4FBD}) (Version: 14.16.27024 - Microsoft Corporation) Hidden
QNAP Qsync Client (HKLM-x32\...\Qsync) (Version: 5.0.5.0620 - QNAP Systems, Inc.)
Sticky Password 8.3.1.10 (HKLM-x32\...\Sticky Password_is1) (Version: 8.3 - Lamantine Software)
STORMWARE POHODA E1 Klient CZ Premium (HKLM-x32\...\{775B81F0-CD06-42D2-9BD1-1C27AA9355D0}) (Version: 12100.85 - STORMWARE)
STORMWARE POHODA Start CZ (HKLM-x32\...\{EE8FCA5D-FD65-4138-AF76-FD44473DD374}) (Version: 12204.28 - STORMWARE)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.2.36224 - TeamViewer)
TSP100 Setup Version 7.4.0 (HKLM\...\{F273C16D-1109-417F-84B3-5115A9F5B6D5}) (Version: 7.4.0 - Star Micronics)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{B2E25355-C24E-4E7D-8AD3-455D59810838}) (Version: 2.57.0.0 - Microsoft Corporation)
Viber (HKLM-x32\...\{4821E6B5-9C96-48E7-B0AC-AB3E8EEB6958}) (Version: 9.6.5.16 - Viber Media Inc.) Hidden
Viber (HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\{6af7d50d-3e8e-465c-8e56-bbe86869755b}) (Version: 9.6.5.16 - Viber Media Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN)
WPS Office (11.2.0.11254) (HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\Kingsoft Office) (Version: 11.2.0.11254 - Kingsoft Corp.)
Packages:
=========
Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.2340.1.0_x64__kgqvnymyfvs32 [2022-08-22] (king.com)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.225.300.0_x64__kgqvnymyfvs32 [2022-08-26] (king.com)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.14.67.0_x64__rz1tebttyb220 [2022-07-11] (Dolby Laboratories)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-01-15] (Microsoft Corporation)
Hidden City: Hidden Object Adventure -> C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.49.4904.0_x86__ytsefhwckbdv6 [2022-08-23] (G5 Entertainment AB)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_138.2.412.0_x64__v10z8vjag6ke6 [2022-08-25] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-23] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-23] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.13.7180.0_x64__8wekyb3d8bbwe [2022-07-29] (Microsoft Studios) [MS Ad]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{28A80003-18FD-411D-B0A3-3C81F618E22B}\InprocServer32 -> C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\11.2.0.11254\office6\kwpsmenushellext64.dll (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{57D0E8CF-2552-4B76-A5C4-B1E9D413FD14} -> [Qsync] => C:\Users\Prodejna\AppData\Local\QNAP\Qsync\Quick Access [2018-09-18 15:14]
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{6166E16F-FE11-4C78-94E3-DD042B15E50B} -> [QNAP Qsync Client: ALPNAS (Qsync)] => C:\Users\Prodejna\Qsync [2018-09-18 15:16]
CustomCLSID: HKU\S-1-5-21-3885610105-3758572810-27774397-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [ QsyncEx_Icon1] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [ QsyncEx_Icon2] -> {A31C3AF7-2870-4121-AF94-1BF770A2C95B} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [ QsyncEx_Icon3] -> {7937C765-6EFA-4184-A69C-1101127615E8} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [ QsyncEx_Icon4] -> {DDA7CE77-08EA-4047-A53E-C4FB10C307F2} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers1: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers4: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-04] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers6: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2021-09-27] (QNAP Systems, Inc. -> )
ContextMenuHandlers1_S-1-5-21-3885610105-3758572810-27774397-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\11.2.0.11254\office6\kwpsmenushellext64.dll [2022-08-08] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
ContextMenuHandlers4_S-1-5-21-3885610105-3758572810-27774397-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\11.2.0.11254\office6\kwpsmenushellext64.dll [2022-08-08] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2021-09-09 13:24 - 2021-09-09 13:24 - 000011264 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Accounts.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000003584 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Commands.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000009216 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Common.UI.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000004608 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Protocols.Gdata.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000007680 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Protocols.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000006656 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.Protocols.Smtp.resources.dll
2021-09-09 13:24 - 2021-09-09 13:24 - 000821248 _____ () [File not signed] [File is in use] C:\Program Files (x86)\eM Client\cs\MailClient.resources.dll
2021-06-24 11:56 - 2021-06-24 11:56 - 001206784 _____ () [File not signed] C:\Program Files (x86)\eM Client\e_sqlite3.DLL
2021-07-06 13:33 - 2021-07-06 13:33 - 093837824 _____ () [File not signed] C:\Program Files (x86)\eM Client\libcef\libcef.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000188928 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\IOTCAPIs.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000037376 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\json-c.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000039424 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\P2PTunnelAPIs.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 000166400 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\RdiffDll.dll
2022-04-28 05:01 - 2022-04-28 05:01 - 000031232 _____ () [File not signed] C:\Program Files (x86)\QNAP\Qsync\RDTAPIs.dll
2018-05-31 18:00 - 2018-05-31 18:00 - 000090112 _____ () [File not signed] C:\Program Files (x86)\StarMicronics\TSP100\Software\20171207\StarMicronicsCloudNativeLibrary_futurePRNT.dll
2021-05-14 07:10 - 2020-11-30 17:17 - 001101824 _____ () [File not signed] C:\Program Files (x86)\Sticky Password\DLLs\_hashlib.pyd
2018-05-31 18:01 - 2018-05-31 18:01 - 000111616 _____ () [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarMicronicsCloudNativeLibrary_futurePRNT.dll
2021-03-19 03:04 - 2021-03-19 03:04 - 000143872 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Auth.dll
2020-10-26 18:09 - 2020-10-26 18:09 - 000093696 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Calendar.v3.dll
2021-03-19 03:04 - 2021-03-19 03:04 - 000076800 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Core.dll
2021-03-19 03:04 - 2021-03-19 03:04 - 000080896 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.dll
2020-10-22 18:11 - 2020-10-22 18:11 - 000111616 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Gmail.v1.dll
2021-03-25 18:17 - 2021-03-25 18:17 - 000093184 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.PeopleService.v1.dll
2020-10-22 18:12 - 2020-10-22 18:12 - 000029696 _____ (Google Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\Google.Apis.Tasks.v1.dll
2009-09-16 18:44 - 2009-09-16 18:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hptcpmib.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\HpTcpMon.dll
2009-09-16 11:44 - 2009-09-16 11:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hpzjrd01.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\System32\HPTcpMUI.dll
2021-06-24 18:34 - 2021-06-24 18:34 - 000006144 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.batteries_v2.dll
2021-06-24 18:33 - 2021-06-24 18:33 - 000050176 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.core.dll
2021-06-24 18:33 - 2021-06-24 18:33 - 000005632 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.nativelibrary.dll
2021-06-24 18:34 - 2021-06-24 18:34 - 000061440 _____ (SourceGear) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\SQLitePCLRaw.provider.dynamic_cdecl.dll
2017-12-22 17:01 - 2017-12-22 17:01 - 000173056 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\CommandEmulator.dll
2017-12-22 17:03 - 2017-12-22 17:03 - 000157184 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\CompGAF.dll
2017-12-22 17:01 - 2017-12-22 17:01 - 000417280 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\Configuration.dll
2017-12-22 17:03 - 2017-12-22 17:03 - 003606016 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\ESCPOSSE.dll
2017-12-22 17:02 - 2017-12-22 17:02 - 000335360 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\GenericAction.dll
2015-10-27 10:28 - 2015-10-27 10:28 - 000486912 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarIOPort.dll
2017-12-22 17:03 - 2017-12-22 17:03 - 006893568 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarLineModeSE.dll
2017-12-22 17:02 - 2017-12-22 17:02 - 000144896 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\StarTSPTC.dll
2017-12-22 17:01 - 2017-12-22 17:01 - 000110592 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\TargetAction.dll
2018-05-28 20:33 - 2018-05-28 20:33 - 000595456 _____ (Star Micronics Co., Ltd.) [File not signed] C:\Program Files\StarMicronics\TSP100\Software\20171207\tsp100lm.dll
2018-05-28 20:36 - 2018-05-28 20:36 - 000360960 _____ (Star Micronics Co., Ltd.) [File not signed] C:\WINDOWS\System32\smjt100epm.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 000394752 _____ (The curl library, hxxps://curl.se/) [File not signed] C:\Program Files (x86)\QNAP\Qsync\libcurl.dll
2021-07-06 13:33 - 2021-07-06 13:33 - 000729600 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\eM Client\libcef\chrome_elf.dll
2021-07-15 17:23 - 2021-07-15 17:23 - 002953216 _____ (The Legion of the Bouncy Castle Inc.) [File not signed] [File is in use] C:\Program Files (x86)\eM Client\BouncyCastle.Crypto.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 002052096 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\QNAP\Qsync\libcrypto-1_1.dll
2022-04-28 05:02 - 2022-04-28 05:02 - 000497664 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\QNAP\Qsync\libssl-1_1.dll
2021-10-07 13:25 - 2021-10-07 13:25 - 000442368 _____ (Thomas Maierhofer) [File not signed] C:\Program Files (x86)\eM Client\Hunspellx86.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:40C12C39 [130]
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
BHO: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\bdtbie.dll [2022-08-09] (Bitdefender SRL -> Bitdefender)
BHO: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2022-07-15] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender Trackers Blocking -> {159ff5d5-55f1-4d2f-b706-767a55f77abb} -> C:\Program Files\Bitdefender\Bitdefender Security\antispam32\bdtbie.dll [2022-08-30] (Bitdefender SRL -> Bitdefender)
BHO-x32: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2022-08-30] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2022-07-15] (Bitdefender SRL -> Bitdefender)
Toolbar: HKLM-x32 - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2022-08-30] (Bitdefender SRL -> Bitdefender)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2018-04-12 01:38 - 2022-07-14 16:41 - 000000000 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3885610105-3758572810-27774397-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img1.jpg
DNS Servers: 192.168.1.1 - 31.30.90.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-3885610105-3758572810-27774397-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{0F040FCB-3BAB-4F47-890C-7E788E016738}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{57E9CC07-3611-4913-89E7-DD4AF746EDF6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{876E1849-4C0B-4CFB-8778-DA5DE0A4472F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{17EFE983-6508-431F-BC39-45096CC63B0B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{56B500F7-262B-4569-AA76-EC6C903284C2}] => (Allow) C:\Users\Prodejna\AppData\Local\Kingsoft\WPS Office\10.2.0.7646\office6\wpscloudsvr.exe => No File
FirewallRules: [{B4260383-F094-4A50-9494-5BE87E65887A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0AC2FDA9-78EA-476E-BEFD-B134BBD52068}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{C46806FD-F14C-4AD2-B53D-A6444BF5C762}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{50505813-1E26-42FD-8200-0FCA4368FEEA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{56F71A60-A7B9-48DF-B440-01BBD8237E4B}] => (Allow) C:\Program Files (x86)\Sticky Password\stpass.exe (Lamantine Software a.s. -> Lamantine Software a.s.)
FirewallRules: [{4E3AF8D8-B640-4723-A827-E844687A0063}] => (Allow) C:\Program Files (x86)\Sticky Password\stpass.exe (Lamantine Software a.s. -> Lamantine Software a.s.)
FirewallRules: [TCP Query User{2700165C-BE15-44D7-9B42-E12F60167710}C:\program files (x86)\qnap\qsync\qsync.exe] => (Block) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [UDP Query User{CB6AF4E3-CCCD-4969-BAEE-428DFEA61FA7}C:\program files (x86)\qnap\qsync\qsync.exe] => (Block) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [{01CD1BF3-3E2D-40AA-8791-A51547D139D8}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{BA5AD4E9-73DB-4B57-A94D-5B0CDA30712A}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{B4086070-3A9F-4328-A7FD-DFC9352CDE2C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{AC855F51-32C8-4F5B-9469-D5C93A6A400C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{0332DC71-9D4F-4084-8E81-A627599D77E7}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{F33EA30B-F6D5-485D-96B8-D0BEF940E200}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH)
FirewallRules: [{E9F3E863-C3C0-4D93-96F5-91D5DA98C87F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{63CA8BED-5FE2-4ECC-9B93-70F3E8378084}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{58D9FC45-DB46-400D-BDC2-B75ACA201488}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F9637543-3A97-4CF4-AF55-08256C1CDE41}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.87.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AF5C8A01-2CB0-4994-8645-8AB9912ADBBF}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\104.0.1293.70\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B17B62CC-E0CD-4BD4-A879-4F560C013FBD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
17-08-2022 08:05:18 Naplánovaný kontrolní bod
25-08-2022 08:06:54 Naplánovaný kontrolní bod
==================== Faulty Device Manager Devices ============
Name: Intel(R) Trusted Execution Engine Interface
Description: Intel(R) Trusted Execution Engine Interface
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: TXEIx64
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: ========================
Application errors:
==================
Error: (07/15/2022 08:14:02 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_OFF došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_ON došlo k chybě.
Error: (07/15/2022 07:57:52 AM) (Source: SecurityCenter) (EventID: 18) (User: )
Description: Službě Centrum zabezpečení Windows se nepodařilo načíst instance objektu FirewallProduct z úložiště dat.
Error: (07/14/2022 08:18:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.1741 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.
ID procesu: 247c
Čas spuštění: 01d89747317a48f9
Čas ukončení: 4294967295
Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
ID hlášení: 2e8ea768-813a-4b91-8793-cc9cd0fbc30a
Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.5.19041_neutral_neutral_cw5n1h2txyewy
ID aplikace relativní podle balíčku s chybou: ShellFeedsUI
Typ zablokování: Quiesce
Error: (07/04/2022 04:44:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchApp.exe verze 10.0.19041.1741 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.
ID procesu: 15cc
Čas spuštění: 01d88f6a46ae440d
Čas ukončení: 4294967295
Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
ID hlášení: acdbf1f3-0cf8-4579-a358-4c1109759eb3
Úplný název balíčku s chybou: Microsoft.Windows.Search_1.14.5.19041_neutral_neutral_cw5n1h2txyewy
ID aplikace relativní podle balíčku s chybou: ShellFeedsUI
Typ zablokování: Quiesce
System errors:
=============
Error: (09/01/2022 05:01:31 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server Microsoft.MicrosoftOfficeHub_18.2205.1091.0_x64__8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub.AppXvhez9tbpytkh6zv5q0bx5fj12yay14wg.mca se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/29/2022 05:00:38 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/29/2022 05:00:38 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/26/2022 04:58:52 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/26/2022 04:58:52 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/26/2022 07:43:43 AM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/25/2022 05:00:34 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/25/2022 05:00:34 PM) (Source: DCOM) (EventID: 10010) (User: PRODEJNA-KASA)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
CodeIntegrity:
===============
Date: 2022-09-02 07:58:12
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdamsi\266126562904114456\antimalware_provider64.dll that did not meet the Windows signing level requirements.
Date: 2022-09-01 14:53:13
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdamsi\266126562904114456\antimalware_provider64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: Insyde P12-A1 01/12/2015
Motherboard: Acer UI2H
Processor: Intel(R) Pentium(R) CPU N3540 @ 2.16GHz
Percentage of memory in use: 89%
Total physical RAM: 3983.45 MB
Available physical RAM: 413.14 MB
Total Virtual: 7824.24 MB
Available Virtual: 1103.13 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.29 GB) (Free:150.07 GB) (Model: Samsung SSD 860 EVO 250GB) NTFS
\\?\Volume{78a31b23-032d-46a9-9151-c8d97db5dbab}\ (Obnovení) (Fixed) (Total:0.49 GB) (Free:0.05 GB) NTFS
\\?\Volume{451917f6-2d3b-4da2-a73d-920895cd7209}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================