Stránka 1 z 1

Kontrola logu

Napsal: 17 kvě 2023 05:54
od dandar
Dobrý den, prosím o kontrolu logu. Děkuji DR

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-05-2023 01
Ran by Admin (administrator) on LAPTOP-BHS3FTNJ (Acer Extensa 2540) (17-05-2023 06:46:15)
Running from C:\Users\Admin\Desktop\FRST64.exe
Loaded Profiles: Admin
Platform: Microsoft Windows 10 Pro Version 22H2 19045.2965 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Windows\Xerox\PanelMgr\SSMMgr.exe
(C:\Windows\Xerox\PanelMgr\SSMMgr.exe ->) () [File not signed] C:\Windows\Xerox\PanelMgr\caller64.exe
(DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\igfxCUIService.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\igfxEM.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.212\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.212\GoogleCrashHandler64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <12>
(services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\igfxCUIService.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\IntelCpHDCPSvc.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\IntelCpHeciSvc.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (KYOCERA Document Solutions Inc.) [File not signed] C:\Program Files\KDService\bin\KDService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (NortonLifeLock Inc. -> NortonLifelock Inc.) C:\Program Files\Norton Security\Engine\22.23.4.6\NortonSecurity.exe <2>
(services.exe ->) (NortonLifeLock Inc. -> NortonLifeLock Inc.) C:\Program Files\Norton Security\Engine\22.23.4.6\nsWscSvc.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696840 2016-09-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [Xerox PanelMgr] => C:\WINDOWS\Xerox\PanelMgr\SSMMgr.exe [557056 2009-06-22] () [File not signed]
HKLM-x32\...\Run: [LocalServiceControl] => C:\Program Files (x86)\LocalServiceComponents\LocalServiceControl.exe [473600 2023-02-13] () [File not signed]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\74.0.3.0\GoogleDriveFS.exe [53339416 2023-05-03] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\74.0.3.0\GoogleDriveFS.exe [53339416 2023-05-03] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\74.0.3.0\GoogleDriveFS.exe [53339416 2023-05-03] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\...\Run: [MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4152256 2023-05-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\74.0.3.0\GoogleDriveFS.exe [53339416 2023-05-03] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp140: C:\Windows\System32\spool\prtprocs\x64\hpcpp140.DLL [559616 2012-09-28] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Windows x64\Print Processors\hpcpp190: C:\Windows\System32\spool\prtprocs\x64\hpcpp190.dll [651176 2016-08-26] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\sht13cPC: C:\Windows\System32\spool\prtprocs\x64\sht13cpc.dll [101080 2022-01-24] (联想图像(天津)科技有限公司 -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Windows x64\Print Processors\SXC2MPC: C:\Windows\System32\spool\prtprocs\x64\sxc2mpc.dll [33792 2008-01-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\uh004PC: C:\Windows\System32\spool\prtprocs\x64\uh004pc.dll [74048 2019-04-01] (联想图像(天津)科技有限公司 -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\Windows\system32\HPMPW081.DLL [127912 2016-08-26] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HPMLM190: C:\Windows\system32\hpmlm190.dll [310512 2016-08-26] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\KX Language Monitor: C:\Windows\system32\KXPLM64.DLL [117312 2018-09-21] (Microsoft Windows Hardware Compatibility Publisher -> KYOCERA Document Solutions Inc.)
HKLM\...\Print\Monitors\sht13c Langmon: C:\Windows\system32\sht13clm.dll [61840 2019-07-21] (联想图像(天津)科技有限公司 -> )
HKLM\...\Print\Monitors\SXC2M Langmon: C:\Windows\system32\sxc2ml6.dll [22016 2008-01-17] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\uh004 Langmon: uh004lm.dll (No File)
HKLM\...\Print\Monitors\us008 Langmon: C:\Windows\system32\us008lm.dll [31256 2016-02-15] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\113.0.5672.93\Installer\chrmstp.exe [2023-05-12] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0378CFC6-1AC8-4F46-A117-F763D942B4AD} - System32\Tasks\Acer Collection Application => C:\Program Files (x86)\Acer\Acer Collection\ACEStd.exe [479024 2017-12-14] (Acer Incorporated -> )
Task: {09DA8BB5-E64E-4CE7-B13C-7489487DA383} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-06-14] (Piriform Software Ltd -> Piriform)
Task: {0CB91BAE-B1D4-4CC7-9CB9-EEDEE02606F8} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [5967976 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {0E28F1EB-4755-4366-9793-A6E45DDD69BD} - System32\Tasks\AmazonAssistantHelper => C:\ProgramData\OEM\Transactional\amazonx@hermes\AmazonX.exe [28464 2018-08-23] (Acer Incorporated -> )
Task: {14FD949E-5F64-4AAC-9539-01D4F43662B8} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [41264 2017-02-22] (Acer Incorporated -> )
Task: {1D20CD6B-FC32-4BD5-8019-13102B1DF256} - System32\Tasks\Norton Security\Norton Security Error Analyzer => C:\Program Files\Norton Security\Engine\22.15.1.8\SymErr.exe/analyze
Task: {1E8C1558-F0BA-4079-A52E-B58FFB62878F} - System32\Tasks\Power Button => C:\Program Files\Acer\Acer Quick Access\ePowerButton_NB.exe [2767664 2017-02-15] (Acer Incorporated -> Acer Incorporated)
Task: {20BD5264-2667-43D5-93A9-886E725FE461} - System32\Tasks\Mozilla\Firefox Background Update E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\firefox.exe [676768 2023-05-12] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\E7CF176E110C211B\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {20E70B51-8812-4B91-A9F0-7C77331F4465} - System32\Tasks\{382206AF-3B40-4179-A5AB-6282A401826A} => C:\Users\Admin\AppData\Local\Temp\B48B80E2-A0E4-41F0-932C-865F8131BF7D\ga_service.exe/uninstall <==== ATTENTION
Task: {2316C0EA-DAA6-4992-8440-CB770BB9ED12} - System32\Tasks\Norton 360\Norton 360 Autofix => C:\Program Files\Norton Security\Engine\22.23.4.6\SymErr.exe [379024 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Task: {27B35985-BA30-45C7-8509-0CDCA81D85EC} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [445744 2017-02-15] (Acer Incorporated -> Acer Incorporated)
Task: {2EFB0596-5DF8-4C00-A6DE-E36BCB7A79E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-18] (Google Inc -> Google Inc.)
Task: {3144FFFB-1C23-4A2E-B08A-F9139297BC38} - System32\Tasks\Acer Collection Monitor Application => C:\Program Files (x86)\Acer\Acer Collection\ACEMon.exe [417072 2017-12-13] (Acer Incorporated -> Acer Incorporated)
Task: {33BA9B87-8E52-47F3-AB66-41FCE63096F2} - System32\Tasks\AcerCMUpdateTask2.1.16258 => C:\Program Files (x86)\Acer\Amundsen\2.1.16258\AWC.exe [152880 2016-09-20] (Acer Incorporated -> )
Task: {353355E8-4195-4CE4-956E-3656AF00ACA5} - System32\Tasks\Norton Security\Norton Security Error Processor => C:\Program Files\Norton Security\Engine\22.15.1.8\SymErr.exe/submit
Task: {376A4DA5-FFEC-4449-A88D-182DD726BB78} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [473904 2017-02-15] (Acer Incorporated -> Acer Incorporated)
Task: {3B8F794F-5F1C-4D98-BC6A-FAF80ACEA611} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [732064 2023-05-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {4427A36F-DE51-410B-A9D0-C7A51F64DC00} - System32\Tasks\Norton Security with Backup\Norton Security Error Processor => C:\Program Files\Norton Security\Engine\22.20.5.39\SymErr.exe/submit
Task: {4EF2CE71-34BD-4EC2-BF82-1F35DE54FA89} - System32\Tasks\Norton 360\Norton 360 Error Analyzer => C:\Program Files\Norton Security\Engine\22.23.4.6\SymErr.exe [379024 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Task: {5D55002A-314D-44A2-B6E9-2A10532AFB92} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [4645168 2017-02-22] (Acer Incorporated -> )
Task: {61427EEA-9E20-498F-A2A8-D37489DB022F} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security\Engine\22.23.4.6\WSCStub.exe [646520 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Task: {66CC0284-8F3E-4199-967B-6D876A7F42FB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [315056 2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {83AADD0C-76E7-4807-942A-32C31C77F57E} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2920752 2017-02-22] (Acer Incorporated -> )
Task: {9255825F-5742-4F46-B75B-9CB92F7D9989} - System32\Tasks\MonitorAcerPortal => C:\ProgramData\acer\Acer Portal\monitorPortal.exe [32472 2017-06-07] (Acer Incorporated -> )
Task: {9B69251A-9EF4-4682-A256-45347D0BA4F4} - System32\Tasks\Norton Security with Backup\Norton Security Error Analyzer => C:\Program Files\Norton Security\Engine\22.20.5.39\SymErr.exe/analyze
Task: {9E63A61A-3FF1-40F7-A2D4-4647B82F2362} - System32\Tasks\PicstreamAgent => C:\Program [Argument = Files (x86)\Acer\AOP Framework\uwplauncher.exe AcerIncorporated.6245439DEEE9E_48frkmn4z8aw4!abPhoto]Files (x86)\Acer\AOP Framework\uwplauncher.exe AcerIncorporated.6245439DEEE9E_48frkmn4z8aw4!abPhoto
Task: {A6FEB6C4-5C3F-40A1-84C4-E5697F39BB32} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.)
Task: {AE6D5F35-F095-4D3B-A08C-086359A5E902} - System32\Tasks\Norton Security\Norton Security Autofix => C:\Program Files\Norton Security\Engine\22.15.1.8\SymErr.exe/ui
Task: {B7C844C9-EA52-4FB4-A06E-FA6689A428DB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [5967976 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {C03D88F2-78E2-4AB7-B3C4-F4A4C0CDD3DA} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton 360\Upgrade.exe [2353000 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Task: {C2466FC8-AD00-4055-913F-D3728ACAEAFA} - System32\Tasks\AcerCloud => C:\ProgramData\acer\Acer Portal\launchPortal.exe [25816 2017-06-07] (Acer Incorporated -> )
Task: {CA53A48A-D8CD-4EE1-8AD3-CE47363DA880} - System32\Tasks\CCleanerSkipUAC - Admin => C:\Program Files\CCleaner\CCleaner.exe [31027800 2022-06-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {D34973D5-F00F-4EE0-9C2F-48C84BE1451F} - System32\Tasks\DashlaneUpgradeCheck => C:\Windows\system32\net.exe [59904 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {D5F3BF66-06D3-4396-AFA8-B4BFE78D92AC} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [909112 2016-07-27] (Intel(R) Trusted Connect Service -> Intel(R) Corporation)
Task: {DB287409-6E73-4D4F-8FF5-B8B47C14A4BD} - System32\Tasks\Norton 360\Norton 360 Error Processor => C:\Program Files\Norton Security\Engine\22.23.4.6\SymErr.exe [379024 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Task: {E1BE0946-37B1-49FE-AFC1-8EED7CD91195} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [215856 2017-02-18] (Acer Incorporated -> TODO: <Company name>)
Task: {E7F6CBB5-DF87-4C23-A65A-29FCE4DE3254} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [315056 2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {EB9BD520-0C1D-4D90-9665-976E1787C407} - System32\Tasks\Norton Security with Backup\Norton Security Autofix => C:\Program Files\Norton Security\Engine\22.20.5.39\SymErr.exe/ui
Task: {F50F14CE-02BF-4ECC-9842-D840AC68957A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-18] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{405655b1-a030-4f2e-a54c-ffd285d7acb4}: [NameServer] 192.168.1.1,8.8.8.8
Tcpip\..\Interfaces\{f3c2666c-e65f-407b-80e5-a367f81d9452}: [DhcpNameServer] 8.8.8.8

Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default [2023-05-17]
Edge StartupUrls: Default -> "hxxp://www.google.com/"
Edge Extension: (Edge relevant text changes) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-04-29]

FireFox:
========
FF DefaultProfile: 9d1qsgiw.New-1631164675338
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\9d1qsgiw.New-1631164675338 [2023-05-17]
FF Extension: (AdBlocker Ultimate) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\9d1qsgiw.New-1631164675338\Extensions\adblockultimate@adblockultimate.net.xpi [2023-05-16]
FF Extension: (Český slovník pro kontrolu pravopisu) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\9d1qsgiw.New-1631164675338\Extensions\cs@dictionaries.addons.mozilla.org.xpi [2021-09-10]
FF Extension: (TWP - Translate Web Pages) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\9d1qsgiw.New-1631164675338\Extensions\{036a55b4-5e72-4d05-a06c-cba2dfcc134a}.xpi [2023-05-05]
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nw3llktd.default [2022-06-28]
FF Homepage: Mozilla\Firefox\Profiles\nw3llktd.default -> www.seznam.cz
FF Extension: (Czech (CZ) Language Pack) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nw3llktd.default\Extensions\langpack-cs@firefox.mozilla.org.xpi [2018-08-30]
FF Extension: (Mozilla Partner Defaults) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nw3llktd.default\Extensions\partnerdefaults@mozilla.com [2018-08-30] [Legacy]
FF Extension: (User search study) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nw3llktd.default\Extensions\search-nudges@shield.mozilla.org.xpi [2018-08-30] [Legacy]
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-05-04] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @DVR/npplugin,version=3.1.0.4 -> C:\Program Files (x86)\webrec\WEB30\WebPlugin_V2\npPlugin.dll [2016-03-16] () [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Web Components -> C:\Program Files (x86)\Web Components\npWebVideoPlugin.dll [2019-11-27] () [File not signed]

Chrome:
=======
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default [2022-12-13]
CHR DownloadDir: C:\Users\Admin\Desktop
CHR Extension: (Lighthouse) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blipmdconlkpinefehnmjammfjpmpbjk [2022-04-20]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-09-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-06]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-01-23]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif]
CHR HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2272472 2017-06-07] (Acer Incorporated -> Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2776664 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
S2 Dashlane Upgrade Service; C:\Program Files (x86)\Dashlane\Upgrade\DashlaneUpgradeService.exe [83992 2017-08-23] (Dashlane -> Dashlane, Inc.)
R2 KDService; C:\Program Files\KDService\bin\KDService.exe [514560 2018-09-21] (KYOCERA Document Solutions Inc.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2019-02-01] (HP Inc.) [File not signed]
R2 NortonSecurity; C:\Program Files\Norton Security\Engine\22.23.4.6\NortonSecurity.exe [344888 2023-05-10] (NortonLifeLock Inc. -> NortonLifelock Inc.)
R2 nsWscSvc; C:\Program Files\Norton Security\Engine\22.23.4.6\nsWscSvc.exe [1059176 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2019-02-01] (HP Inc.) [File not signed]
S3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [461616 2017-02-15] (Acer Incorporated -> Acer Incorporated)
S3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [506672 2017-02-15] (Acer Incorporated -> Acer Incorporated)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [336256 2023-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [296752 2017-02-21] (Acer Incorporated -> acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndnetBus; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [38832 2021-01-21] (Microsoft Windows Hardware Compatibility Publisher -> LG Electronics Inc.)
S3 AndNetDiag; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [39312 2021-01-21] (Microsoft Windows Hardware Compatibility Publisher -> LG Electronics Inc.)
S3 ANDNetModem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [45976 2021-01-21] (Microsoft Windows Hardware Compatibility Publisher -> LG Electronics Inc.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 BHDrvx64; C:\Program Files\Norton Security\NortonData\22.9.2.3\Definitions\BASHDefs\20230516.001\BHDrvx64.sys [1696736 2023-03-07] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R1 ccSet_NGC; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\ccSetx64.sys [198280 2023-05-10] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [527864 2022-09-19] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [159720 2022-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R1 googledrivefs31092; C:\WINDOWS\System32\DRIVERS\googledrivefs31092.sys [384600 2023-02-08] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R1 IDSVia64; C:\Program Files\Norton Security\NortonData\22.9.2.3\Definitions\IPSDefs\20230516.061\IDSvia64.sys [1527816 2023-02-21] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [31000 2018-05-15] (Acer Incorporated -> Acer Incorporated)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [32352 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
S3 nsvst_NGC; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\nsvst.sys [57120 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [25368 2018-05-15] (Acer Incorporated -> Acer Incorporated)
R3 SRTSP; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\SRTSP64.SYS [956048 2023-05-10] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R1 SRTSPX; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\SRTSPX64.SYS [52872 2023-05-10] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R2 SSPORT; C:\WINDOWS\system32\Drivers\SSPORT.sys [14224 2021-04-01] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 SymEFASI; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\SYMEFASI64.SYS [2180248 2023-05-10] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
S0 SymELAM; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\SymELAM.sys [36016 2023-05-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Broadcom)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [100320 2022-05-12] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R3 SymEvnt; C:\Program Files\Norton Security\NortonData\22.9.2.3\SymPlatform\SymEvnt.sys [722400 2022-07-11] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R1 SymIRON; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\Ironx64.SYS [306824 2023-05-10] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R1 SymNetS; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\symnets.sys [492728 2023-05-10] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R1 wpCtrlDrv_NGC; C:\WINDOWS\System32\drivers\NGCx64\1617040.006\wpCtrlDrv.sys [1016792 2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
U4 npcap_wifi; no ImagePath
S2 npf; \??\C:\WINDOWS\system32\drivers\npf.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-05-17 06:46 - 2023-05-17 06:47 - 000029452 _____ C:\Users\Admin\Desktop\FRST.txt
2023-05-17 06:44 - 2023-05-17 06:44 - 002382848 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2023-05-17 06:39 - 2023-05-17 06:40 - 000010094 _____ C:\ProgramData\SMRResults540.dat
2023-05-17 06:32 - 2023-05-17 06:39 - 000000000 ____D C:\Users\Admin\AppData\Local\NPE
2023-05-17 06:32 - 2023-05-17 06:32 - 000119048 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SMR540.SYS.bak
2023-05-16 14:41 - 2023-05-16 14:41 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2023-05-16 14:38 - 2023-05-16 14:38 - 000210708 _____ C:\Users\Admin\Downloads\Faktura 91230057-1.pdf
2023-05-16 14:37 - 2023-05-16 14:37 - 000210708 _____ C:\Users\Admin\Downloads\Faktura 91230057.pdf
2023-05-16 14:31 - 2023-05-16 14:31 - 000242859 _____ C:\Users\Admin\Downloads\VFA_91230057.pdf
2023-05-16 10:36 - 2023-05-16 10:36 - 000449353 _____ C:\Users\Admin\Downloads\Bezpohybové zásoby_sklad_2-1.pdf
2023-05-16 10:17 - 2023-05-16 10:17 - 000274056 _____ C:\Users\Admin\Downloads\FRM-ZŠ_Trmice.pdf
2023-05-16 10:13 - 2023-05-16 10:13 - 000275273 _____ C:\Users\Admin\Downloads\FRM-VOGELNET.pdf
2023-05-16 09:54 - 2023-05-16 09:54 - 000274687 _____ C:\Users\Admin\Downloads\FRM-SITEL.pdf
2023-05-16 09:49 - 2023-05-16 09:49 - 000276019 _____ C:\Users\Admin\Downloads\FRM-S21_2.pdf
2023-05-16 09:47 - 2023-05-16 09:47 - 000276025 _____ C:\Users\Admin\Downloads\FRM-RK INGFIN_2.pdf
2023-05-16 09:29 - 2023-05-16 09:29 - 000275188 _____ C:\Users\Admin\Downloads\FRM-Bigsam.pdf
2023-05-16 09:27 - 2023-05-16 09:27 - 000275208 _____ C:\Users\Admin\Downloads\FRM-Bajger s.r.o_2.pdf
2023-05-16 09:07 - 2023-05-16 09:07 - 000276461 _____ C:\Users\Admin\Downloads\FRM-Grimax_3.pdf
2023-05-16 09:04 - 2023-05-16 09:04 - 000267071 _____ C:\Users\Admin\Downloads\FRM-CAFÉ POINT.pdf
2023-05-16 07:52 - 2023-05-17 06:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\Norton 360
2023-05-16 07:52 - 2023-05-16 08:10 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security
2023-05-16 07:52 - 2023-05-16 07:52 - 000003374 _____ C:\WINDOWS\system32\Tasks\Norton WSC Integration
2023-05-16 07:09 - 2023-05-16 07:09 - 000212298 _____ C:\Users\Admin\Downloads\Doklad SIPO_202305_4010981162.pdf
2023-05-16 06:25 - 2023-05-16 06:25 - 000195314 _____ C:\Users\Admin\Downloads\TL 07_38 rev5 Qualy Fill.pdf
2023-05-16 06:22 - 2023-05-16 06:22 - 000379809 _____ C:\Users\Admin\Downloads\TL 03_12 rev6 Silikon akrylový tmel.pdf
2023-05-16 06:19 - 2023-05-16 06:19 - 000325898 _____ C:\Users\Admin\Downloads\TL 03_06 rev6 Akryl Exterier.pdf
2023-05-15 15:04 - 2023-05-15 15:04 - 000336962 _____ C:\Users\Admin\Downloads\Šroubek_CZ_Dohoda o slevě_2023.pdf
2023-05-15 14:19 - 2023-05-15 14:19 - 000416293 _____ C:\Users\Admin\Downloads\mutace_63_SROUBEK-1.pdf
2023-05-15 11:55 - 2023-05-15 11:55 - 000384160 _____ C:\Users\Admin\Downloads\Bezpohybové zásoby_sklad_0.pdf
2023-05-15 11:43 - 2023-05-15 11:43 - 000449353 _____ C:\Users\Admin\Downloads\Bezpohybové zásoby_sklad_2.pdf
2023-05-15 11:34 - 2023-05-15 11:34 - 000424111 _____ C:\Users\Admin\Downloads\Bezpohybové zásoby_sklad_6.pdf
2023-05-15 10:59 - 2023-05-15 10:59 - 000506592 _____ C:\Users\Admin\Downloads\Analýza prodeje (detail).xlsx
2023-05-15 10:09 - 2023-05-15 10:09 - 002741160 _____ C:\Users\Admin\Downloads\BL SILDEKOR Silikonová fasádní barva 03 22.pdf
2023-05-15 10:09 - 2023-05-15 10:09 - 000312851 _____ C:\Users\Admin\Downloads\TL 10_27 rev1 Silikonová fasádní barva-3.pdf
2023-05-15 10:08 - 2023-05-15 10:08 - 001613507 _____ C:\Users\Admin\Downloads\BL SILDEKOR Fasádní penetrace pod silikonové nátěry 06 22-1.pdf
2023-05-15 10:06 - 2023-05-15 10:06 - 000191463 _____ C:\Users\Admin\Downloads\TL 07_81 rev1 Interiérová barva EXCLUSIVE-1.pdf
2023-05-15 10:02 - 2023-05-15 10:02 - 000312851 _____ C:\Users\Admin\Downloads\TL 10_27 rev1 Silikonová fasádní barva-2.pdf
2023-05-15 09:53 - 2023-05-15 09:53 - 000416240 _____ C:\Users\Admin\Downloads\mutace_63_SROUBEK.pdf
2023-05-15 08:04 - 2023-05-15 08:04 - 000001799 _____ C:\Users\Admin\Downloads\Sešit2-2.csv
2023-05-15 08:04 - 2023-05-15 08:04 - 000001799 _____ C:\Users\Admin\Downloads\Sešit2-1.csv
2023-05-15 08:03 - 2023-05-15 08:03 - 000011772 _____ C:\Users\Admin\Downloads\Sešit2-1-1.xlsx
2023-05-15 07:33 - 2023-05-15 07:33 - 001613507 _____ C:\Users\Admin\Downloads\BL SILDEKOR Fasádní penetrace pod silikonové nátěry 06 22.pdf
2023-05-15 07:25 - 2023-05-15 07:25 - 000312851 _____ C:\Users\Admin\Downloads\TL 10_27 rev1 Silikonová fasádní barva-1.pdf
2023-05-15 07:02 - 2023-05-15 07:02 - 000858580 _____ C:\Users\Admin\Downloads\12525DC07106_5_All_Data sheet.pdf
2023-05-15 06:57 - 2023-05-15 06:57 - 000195363 _____ C:\Users\Admin\Downloads\TL 07_76 rev6 Malířská akrylátová penetrace.pdf
2023-05-15 06:56 - 2023-05-15 06:56 - 000197462 _____ C:\Users\Admin\Downloads\TL 09_10 rev2 Primer Alfa.pdf
2023-05-15 06:55 - 2023-05-15 06:55 - 000204862 _____ C:\Users\Admin\Downloads\TL 06_97 rev3 Hloubkový penetrační nátěr _S.pdf
2023-05-15 06:55 - 2023-05-15 06:55 - 000186998 _____ C:\Users\Admin\Downloads\TL_06_91_rev7_Penetračn í_a_spojovací_nátěr.pdf
2023-05-15 06:54 - 2023-05-15 06:54 - 000236350 _____ C:\Users\Admin\Downloads\TL_06_96_rev2_Hloubková_penetrace_P.pdf
2023-05-15 06:52 - 2023-05-15 06:52 - 000328672 _____ C:\Users\Admin\Downloads\TL_06_96_rev8_Hloubkova_penetrace_NANO--1015657707119380317.pdf
2023-05-15 06:47 - 2023-05-15 06:47 - 000192394 _____ C:\Users\Admin\Downloads\TL 09_S-T70_10 rev4 Penetrace S2802A.pdf
2023-05-12 17:34 - 2023-05-17 06:40 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2023-05-12 14:41 - 2023-05-12 14:41 - 000103965 _____ C:\Users\Admin\Downloads\co je na skladě.xlsx
2023-05-11 15:05 - 2023-05-11 15:05 - 000011772 _____ C:\Users\Admin\Downloads\Sešit2-1.xlsx
2023-05-11 14:20 - 2023-05-11 14:20 - 000011848 _____ C:\Users\Admin\Downloads\XTline bez vazby_2.xlsx
2023-05-11 14:11 - 2023-05-11 14:11 - 000008673 _____ C:\Users\Admin\Downloads\XTline bez vazby_1.xlsx
2023-05-11 13:39 - 2023-05-11 13:40 - 001666956 _____ C:\Users\Admin\Downloads\VO-ceník_XTline_s MO_ceny_splatností_od_3.4.2023_ŠROUBEK.xlsx
2023-05-11 09:18 - 2023-05-11 09:18 - 000312851 _____ C:\Users\Admin\Downloads\TL 10_27 rev1 Silikonová fasádní barva.pdf
2023-05-11 07:27 - 2023-05-11 07:27 - 000012372 _____ C:\Users\Admin\Downloads\HPM_hmotnost.xlsx
2023-05-11 07:08 - 2023-05-11 07:08 - 000196056 _____ C:\Users\Admin\Downloads\TL 07_77 rev6 Interiérová barva AMBIENT.pdf
2023-05-11 07:06 - 2023-05-11 07:06 - 000191463 _____ C:\Users\Admin\Downloads\TL 07_81 rev1 Interiérová barva EXCLUSIVE.pdf
2023-05-10 13:25 - 2023-05-10 13:25 - 000089855 _____ C:\Users\Admin\Downloads\30-15 Katalogový list-1.pdf
2023-05-10 13:21 - 2023-05-10 13:21 - 000089855 _____ C:\Users\Admin\Downloads\30-15 Katalogový list.pdf
2023-05-10 12:00 - 2023-05-10 12:26 - 000000375 _____ C:\Users\Admin\Downloads\XTLine.csv
2023-05-10 11:11 - 2023-05-10 11:11 - 000001799 _____ C:\Users\Admin\Downloads\Sešit2.csv
2023-05-10 11:10 - 2023-05-10 11:10 - 000010429 _____ C:\Users\Admin\Downloads\Sešit2.xlsx
2023-05-10 11:06 - 2023-05-10 11:06 - 000018273 _____ C:\Users\Admin\Downloads\HPM pro preceneni.xlsx
2023-05-10 11:01 - 2023-05-10 11:01 - 000040450 _____ C:\Users\Admin\Downloads\ŠROUBEK Ústí nad Labem, s.r.o. - 1m, 1m, 0,5m regál-5.xlsx
2023-05-10 10:56 - 2023-05-10 10:56 - 000013608 _____ C:\Users\Admin\Downloads\sroubek_logo_redesing.pdf
2023-05-10 10:34 - 2023-05-10 10:34 - 001666956 _____ C:\Users\Admin\Downloads\VO-ceník_XTline_s MO_ceny_splatností_od_3.4.2023_ŠROUBEK-2.xlsx
2023-05-10 09:19 - 2023-05-10 09:19 - 000001082 _____ C:\Users\Admin\Downloads\HPM.csv
2023-05-10 08:41 - 2023-05-10 08:41 - 000043642 _____ C:\Users\Admin\Downloads\HPM_pavel_ALL_proDAN-1.xlsx
2023-05-10 07:46 - 2023-05-11 07:37 - 000041515 _____ C:\Users\Admin\Downloads\HPM_pavel_ALL_proDAN.xlsx
2023-05-10 07:38 - 2023-05-10 07:38 - 000008898 _____ C:\Users\Admin\Downloads\HPM duplicita.xlsx
2023-05-10 07:16 - 2023-05-10 07:16 - 000046378 _____ C:\Users\Admin\Downloads\Formulář pro vrácení zboží.pdf
2023-05-10 07:15 - 2023-05-10 07:15 - 000049341 _____ C:\Users\Admin\Downloads\CarrierLabel.pdf
2023-05-10 06:53 - 2023-05-10 06:53 - 000000000 ___HD C:\$WinREAgent
2023-05-06 19:27 - 2023-05-06 19:27 - 000449091 _____ C:\Users\Admin\Downloads\manual_Azur_Kit_2017_CZ.pdf
2023-05-05 15:17 - 2023-05-05 15:17 - 000000043 _____ C:\Users\Admin\Downloads\pokus_1.csv
2023-05-05 14:24 - 2023-05-05 14:24 - 000040450 _____ C:\Users\Admin\Downloads\ŠROUBEK Ústí nad Labem, s.r.o. - 1m, 1m, 0,5m regál-4.xlsx
2023-05-05 13:28 - 2023-05-05 13:28 - 000040450 _____ C:\Users\Admin\Downloads\ŠROUBEK Ústí nad Labem, s.r.o. - 1m, 1m, 0,5m regál-3.xlsx
2023-05-04 13:17 - 2023-05-04 13:17 - 000008817 _____ C:\Users\Admin\Downloads\obědy duben 23.xlsx
2023-05-04 09:43 - 2023-05-04 09:43 - 000074069 _____ C:\Users\Admin\Downloads\Drogerie.xlsx
2023-05-04 09:21 - 2023-05-04 09:21 - 004745909 _____ C:\Users\Admin\Downloads\XT line - obj_formular_katalog_Sroubek_2023-1.pdf
2023-05-04 08:59 - 2023-05-04 08:59 - 000150482 _____ C:\Users\Admin\Downloads\Kopie - XTline mj vs mj-1.xlsx
2023-05-04 08:38 - 2023-05-04 08:38 - 000008880 _____ C:\Users\Admin\Downloads\Kopie - XT.xlsx
2023-05-04 08:37 - 2023-05-04 08:37 - 000149745 _____ C:\Users\Admin\Downloads\XTline mj vs mj-1.xlsx
2023-05-04 08:26 - 2023-05-04 08:26 - 000150482 _____ C:\Users\Admin\Downloads\Kopie - XTline mj vs mj.xlsx
2023-05-04 08:04 - 2023-05-04 08:04 - 000265382 _____ C:\Users\Admin\Downloads\FRM-CAFE-POINT-1.pdf
2023-05-04 08:02 - 2023-05-04 08:03 - 000265382 _____ C:\Users\Admin\Downloads\FRM-CAFE-POINT.pdf
2023-05-03 15:18 - 2023-05-03 15:18 - 005498885 _____ C:\Users\Admin\Downloads\202302_un.pdf
2023-05-03 12:11 - 2023-05-03 12:11 - 000186810 _____ C:\Users\Admin\Downloads\Podaci_listek_avizovani_vpis.pdf
2023-05-03 11:27 - 2023-05-03 11:27 - 000106607 _____ C:\Users\Admin\Downloads\XTline obj kody z jejich ceniku.xlsx
2023-05-03 11:20 - 2023-05-04 14:16 - 000016599 _____ C:\Users\Admin\Downloads\XTline bez vazby_smazat obj kod.xlsx
2023-05-03 11:04 - 2023-05-03 11:04 - 000026373 _____ C:\Users\Admin\Downloads\XTline posl. dod. mimo primární dodav..xlsx
2023-05-03 10:28 - 2023-05-03 10:28 - 000008712 _____ C:\Users\Admin\Downloads\XT.xlsx
2023-05-03 10:14 - 2023-05-03 10:14 - 001666956 _____ C:\Users\Admin\Downloads\VO-ceník_XTline_s MO_ceny_splatností_od_3.4.2023_ŠROUBEK-1.xlsx
2023-05-03 07:56 - 2023-05-03 07:56 - 004745909 _____ C:\Users\Admin\Downloads\XT line - obj_formular_katalog_Sroubek_2023.pdf
2023-05-03 07:49 - 2023-05-03 07:49 - 004808148 _____ C:\Users\Admin\Downloads\XT line - obj_formular_katalog_Svoboda Horka_2023.pdf
2023-05-03 06:46 - 2023-05-03 06:46 - 000180839 _____ C:\Users\Admin\Downloads\poklop-ppr-650-1.pdf
2023-05-03 06:36 - 2023-05-03 06:36 - 000180839 _____ C:\Users\Admin\Downloads\poklop-ppr-650.pdf
2023-05-02 15:31 - 2023-05-03 07:43 - 000149745 _____ C:\Users\Admin\Downloads\XTline mj vs mj.xlsx
2023-05-02 14:21 - 2023-05-02 14:21 - 000009676 _____ C:\Users\Admin\Downloads\XTLine bez vazby.xlsx
2023-05-02 08:03 - 2023-05-02 08:03 - 000022066 _____ C:\Users\Admin\Downloads\09_Plastove_poklopy_cenik.pdf
2023-05-02 07:56 - 2023-05-02 07:56 - 000226634 _____ C:\Users\Admin\Downloads\ULP-tisk Akcí ( vazba na štítky DGU).pdf
2023-05-02 06:24 - 2023-05-02 06:24 - 000014518 _____ C:\Users\Admin\Downloads\sestavaZL-Celejewská T-1.pdf
2023-05-02 06:18 - 2023-05-02 06:18 - 000014518 _____ C:\Users\Admin\Downloads\sestavaZL-Celejewská T.pdf
2023-04-30 07:48 - 2023-04-30 07:48 - 000151549 _____ C:\Users\Admin\Downloads\cenik_domacnosti_cez_2023-1_svezi24.pdf
2023-04-30 07:41 - 2023-04-30 07:41 - 000137614 _____ C:\Users\Admin\Downloads\Cenik-Variant-PRO-24-Duben-2023-distribucni-uzemi-CEZ-1.pdf
2023-04-30 07:36 - 2023-04-30 07:36 - 000137614 _____ C:\Users\Admin\Downloads\Cenik-Variant-PRO-24-Duben-2023-distribucni-uzemi-CEZ.pdf
2023-04-30 07:35 - 2023-04-30 07:35 - 000137631 _____ C:\Users\Admin\Downloads\Cenik-Variant-PRO-12-Duben-2023-distribucni-uzemi-CEZ.pdf
2023-04-30 07:34 - 2023-04-30 07:35 - 000137186 _____ C:\Users\Admin\Downloads\Cenik-Elektrina-online-PRO-na-1-rok-3_23-distribucni-uzemi-CEZ.pdf
2023-04-30 07:28 - 2023-04-30 07:28 - 000192766 _____ C:\Users\Admin\Downloads\Podmínky jarní nabídky_ukončení akce.pdf
2023-04-29 19:28 - 2023-04-29 19:28 - 000152801 _____ C:\Users\Admin\Downloads\Tobiasova_KNZ_1BT__modelace_230428_130048.pdf
2023-04-29 19:27 - 2023-04-29 19:27 - 000076441 _____ C:\Users\Admin\Downloads\Majetek_Kalkulace-1.pdf
2023-04-29 19:26 - 2023-04-29 19:26 - 000076441 _____ C:\Users\Admin\Downloads\Majetek_Kalkulace.pdf
2023-04-28 08:02 - 2023-04-28 08:02 - 000009196 _____ C:\Users\Admin\Downloads\Min.xlsx
2023-04-27 12:06 - 2023-04-27 12:06 - 001468347 _____ C:\Users\Admin\Downloads\_nezpracovane_polozky.xlsx
2023-04-27 11:02 - 2023-04-27 11:02 - 000242867 _____ C:\Users\Admin\Downloads\Halasz-POZP 2022.pdf
2023-04-27 09:47 - 2023-04-27 09:47 - 000176429 _____ C:\Users\Admin\Downloads\prijemky.jpeg
2023-04-26 13:57 - 2023-04-26 13:57 - 002648396 _____ C:\Users\Admin\Downloads\513_ppp_kap-04.pdf
2023-04-26 13:27 - 2023-04-26 13:27 - 000017558 _____ C:\Users\Admin\Downloads\Radka životopis.pdf
2023-04-26 12:12 - 2023-04-26 12:12 - 000050552 _____ C:\Users\Admin\Downloads\Kopie - HPM-2.xlsx
2023-04-26 08:32 - 2023-04-26 08:32 - 000049748 _____ C:\Users\Admin\Downloads\HPM-2.xlsx
2023-04-26 07:43 - 2023-04-26 07:43 - 000042308 _____ C:\Users\Admin\Downloads\HPM-1.xlsx
2023-04-25 14:27 - 2023-04-25 14:27 - 000042308 _____ C:\Users\Admin\Downloads\HPM.xlsx
2023-04-25 10:24 - 2023-04-25 10:24 - 000167534 _____ C:\Users\Admin\Downloads\Pokles MO 2023.xlsx
2023-04-25 10:09 - 2023-04-25 10:09 - 000623450 _____ C:\Users\Admin\Downloads\Kalendar_svozu_odpadu_1_pololeti_2023_5698242c60.pdf
2023-04-25 07:12 - 2023-04-25 07:12 - 000040450 _____ C:\Users\Admin\Downloads\ŠROUBEK Ústí nad Labem, s.r.o. - 1m, 1m, 0,5m regál-2.xlsx
2023-04-25 06:23 - 2023-04-25 06:23 - 000242377 _____ C:\Users\Admin\Downloads\doc01164820180619064339.pdf
2023-04-24 15:14 - 2023-04-24 15:14 - 000022673 _____ C:\Users\Admin\Downloads\2_omater_HPMTEC-1.xlsx
2023-04-24 15:13 - 2023-04-24 15:13 - 000022673 _____ C:\Users\Admin\Downloads\2_omater_HPMTEC.xlsx
2023-04-24 12:32 - 2023-04-24 12:32 - 000020517 _____ C:\Users\Admin\Downloads\existující kódy s HM.xlsx
2023-04-24 12:32 - 2023-04-24 12:32 - 000010860 _____ C:\Users\Admin\Downloads\existující kód bez HM.xlsx
2023-04-24 12:31 - 2023-04-24 12:31 - 000016376 _____ C:\Users\Admin\Downloads\neexistující kód.xlsx
2023-04-24 10:50 - 2023-04-24 10:50 - 000385527 _____ C:\Users\Admin\Downloads\Primalex-1.xlsx
2023-04-24 10:50 - 2023-04-24 10:50 - 000385527 _____ C:\Users\Admin\Downloads\Primalex.xlsx
2023-04-21 15:09 - 2023-04-21 15:09 - 000040450 _____ C:\Users\Admin\Downloads\ŠROUBEK Ústí nad Labem, s.r.o. - 1m, 1m, 0,5m regál-1.xlsx
2023-04-21 13:51 - 2023-04-21 13:51 - 000040450 _____ C:\Users\Admin\Downloads\ŠROUBEK Ústí nad Labem, s.r.o. - 1m, 1m, 0,5m regál.xlsx
2023-04-20 06:39 - 2023-04-20 06:39 - 000246046 _____ C:\Users\Admin\Downloads\VFA_6230927-1.pdf
2023-04-20 06:25 - 2023-04-20 06:25 - 000246046 _____ C:\Users\Admin\Downloads\VFA_6230927.pdf
2023-04-19 08:41 - 2023-04-19 08:41 - 000176842 _____ C:\Users\Admin\Downloads\doc04145820230419083930.pdf
2023-04-19 08:38 - 2023-04-19 08:38 - 000008605 _____ C:\Users\Admin\Downloads\ULP_18.4..xlsx
2023-04-18 14:56 - 2023-04-18 14:56 - 000000557 _____ C:\Users\Admin\Downloads\Skladové položky - Maloobchod.csv
2023-04-18 10:04 - 2023-04-18 10:04 - 000297013 _____ C:\Users\Admin\Downloads\Faktura_deckart_2321.126_DECKART reklama s.r.o..pdf
2023-04-17 14:12 - 2023-04-17 14:12 - 000022069 _____ C:\Users\Admin\Downloads\20230414141434.pdf
2023-04-17 10:52 - 2023-04-17 10:52 - 000231891 _____ C:\Users\Admin\Downloads\Vodafone Vyúčtování číslo 893539683.pdf
2023-04-17 10:03 - 2023-04-17 10:03 - 000561907 _____ C:\Users\Admin\Downloads\doc04112920230417091736.pdf

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-05-17 06:47 - 2021-05-07 07:07 - 000000000 ____D C:\FRST
2023-05-17 06:47 - 2020-11-02 09:20 - 001693140 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-05-17 06:47 - 2019-12-07 16:43 - 000718024 _____ C:\WINDOWS\system32\perfh005.dat
2023-05-17 06:47 - 2019-12-07 16:43 - 000145166 _____ C:\WINDOWS\system32\perfc005.dat
2023-05-17 06:47 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2023-05-17 06:42 - 2022-02-09 13:49 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-05-17 06:42 - 2020-11-02 09:22 - 000003510 _____ C:\WINDOWS\system32\Tasks\DashlaneUpgradeCheck
2023-05-17 06:42 - 2018-09-18 06:44 - 000000000 ____D C:\Program Files (x86)\Google
2023-05-17 06:42 - 2018-08-30 20:31 - 000000000 ____D C:\Program Files\CCleaner
2023-05-17 06:40 - 2020-11-02 09:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-05-17 06:40 - 2020-11-02 09:09 - 000008192 ___SH C:\DumpStack.log.tmp
2023-05-17 06:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-05-17 06:40 - 2017-11-22 01:20 - 000000000 __SHD C:\Users\Admin\IntelGraphicsProfiles
2023-05-17 06:40 - 2017-11-21 23:52 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-05-17 06:39 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2023-05-17 06:39 - 2018-09-11 11:18 - 000000000 ____D C:\Program Files (x86)\Web Components
2023-05-17 06:32 - 2017-11-22 00:03 - 000000000 ____D C:\ProgramData\Norton
2023-05-17 06:31 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-05-17 06:31 - 2017-11-22 01:20 - 000000000 ____D C:\Users\Admin\AppData\Local\Packages
2023-05-17 06:30 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-05-17 06:12 - 2020-11-02 09:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-05-16 15:40 - 2018-08-30 19:37 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Excel
2023-05-16 14:16 - 2018-08-31 14:11 - 000000000 ____D C:\Tim
2023-05-16 09:03 - 2018-08-30 14:08 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Word
2023-05-16 08:36 - 2018-08-31 07:56 - 000000000 ____D C:\Program Files\Common Files\AV
2023-05-16 08:10 - 2023-02-14 16:31 - 000002401 _____ C:\Users\Public\Desktop\Norton Security.lnk
2023-05-16 07:52 - 2018-09-04 05:58 - 000000000 ____D C:\WINDOWS\system32\Drivers\NGCx64
2023-05-15 11:42 - 2019-06-05 15:27 - 000000000 ____D C:\Users\Admin\Documents\Soubory aplikace Outlook
2023-05-15 09:40 - 2020-11-23 14:06 - 000000000 ____D C:\Users\Admin\Desktop\Bordel
2023-05-13 15:52 - 2023-01-21 19:40 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-05-13 15:52 - 2020-06-03 09:49 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-05-13 05:39 - 2020-11-02 09:22 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-05-13 05:39 - 2020-11-02 09:22 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-05-13 05:38 - 2017-11-21 23:52 - 000001236 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-05-12 17:09 - 2022-12-08 18:54 - 000015194 _____ C:\Users\Admin\Desktop\Elektroměr.xlsx
2023-05-12 06:45 - 2021-09-03 15:28 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2023-05-12 06:16 - 2023-01-11 12:04 - 000002065 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2023-05-12 06:16 - 2022-10-13 07:01 - 000002077 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2023-05-12 06:16 - 2021-12-13 10:18 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2023-05-12 05:30 - 2018-09-18 06:45 - 000002305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-05-11 14:29 - 2018-08-30 13:47 - 000002382 ____H C:\Users\Admin\Documents\Default.rdp
2023-05-11 14:28 - 2019-12-07 16:45 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2023-05-10 12:39 - 2018-08-31 14:08 - 000000000 ____D C:\Scan
2023-05-10 09:31 - 2020-11-02 09:09 - 000582440 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-05-10 09:31 - 2019-12-07 11:03 - 000016384 _____ C:\WINDOWS\system32\config\ELAM
2023-05-10 09:30 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-05-10 09:30 - 2019-12-07 16:43 - 000000000 ____D C:\WINDOWS\SysWOW64\cs
2023-05-10 09:30 - 2019-12-07 16:43 - 000000000 ____D C:\WINDOWS\system32\cs
2023-05-10 09:30 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-05-10 09:30 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2023-05-10 09:30 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2023-05-10 09:30 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-05-10 09:30 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-05-10 09:30 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-05-10 07:13 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-05-10 07:08 - 2020-11-02 09:10 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-05-10 06:52 - 2018-08-30 14:33 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-05-10 06:44 - 2018-08-30 14:33 - 159583304 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-05-03 15:35 - 2023-01-16 15:49 - 000058174 _____ C:\Users\Admin\Desktop\Porovnání prodejů.xlsx
2023-05-03 06:23 - 2020-09-30 08:12 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-05-03 05:28 - 2021-09-21 18:22 - 000002061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-05-03 05:28 - 2021-09-21 18:22 - 000001903 _____ C:\Users\Default\Desktop\Google Slides.lnk
2023-05-03 05:28 - 2021-09-21 18:22 - 000001903 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2023-05-03 05:28 - 2021-09-21 18:22 - 000001891 _____ C:\Users\Default\Desktop\Google Docs.lnk
2023-04-27 08:44 - 2018-08-30 19:29 - 000000000 ____D C:\Users\Admin\Documents\Práce
2023-04-26 06:54 - 2020-09-22 17:56 - 000000000 ____D C:\Users\Admin\Documents\Doma
2023-04-25 15:51 - 2018-08-30 14:08 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Office
2023-04-21 18:59 - 2020-11-02 09:22 - 000003768 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-04-21 18:59 - 2020-11-02 09:22 - 000003644 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories ========

2023-05-17 06:39 - 2023-05-17 06:40 - 000010094 _____ () C:\ProgramData\SMRResults540.dat
2020-10-27 07:54 - 2020-10-27 07:54 - 000003584 _____ () C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2022-04-22 12:03 - 2022-04-22 12:03 - 000000000 _____ () C:\Users\Admin\AppData\Local\zenmap.exe.log

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-05-2023 01
Ran by Admin (17-05-2023 06:48:33)
Running from C:\Users\Admin\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.2965 (X64) (2020-11-02 07:23:01)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Admin (S-1-5-21-1522470202-1352138926-4199276785-1001 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-1522470202-1352138926-4199276785-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1522470202-1352138926-4199276785-503 - Limited - Disabled)
Guest (S-1-5-21-1522470202-1352138926-4199276785-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1522470202-1352138926-4199276785-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Security (Enabled - Up to date) {1122B19A-E671-38EC-8EAC-87048FD4528D}
AV: Norton Security (Enabled - Up to date) {A2708B76-6835-6565-CB96-694212954A75}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton 360 (Enabled - Up to date) {AECE2126-F4E7-6909-11F2-1B69D1FBCBD0}
AV: Norton 360 (Enabled - Up to date) {9E3FD331-C4C2-7AC4-0537-131EEF1B1F8A}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton Security (Disabled) {9A4B0A53-225A-643D-E0C9-C077EC460D0E}
FW: Norton 360 (Disabled) {A6045214-8EAD-7B9C-2E68-BA2B11C858F1}
FW: Norton 360 (Disabled) {96F5A003-BE88-6851-3AAD-B25C2F288CAB}
FW: Norton Security (Disabled) {291930BF-AC1E-39B4-A5F3-2E31710715F6}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (HKLM\...\{50229C72-539F-4E65-BEB5-F0491C5074B7}) (Version: 22.2.1 - HP Inc.) Hidden
Acer Care Center (HKLM\...\{1AF41E84-3408-499A-8C93-8891F0612719}) (Version: 2.00.3027 - Acer Incorporated)
Acer Collection (HKLM-x32\...\{8CD449EA-BBA0-477F-AFF9-9AF6E8C50EF2}) (Version: 1.01.3011 - Acer Incorporated)
Acer Configuration Manager (HKLM-x32\...\{414D554E-4453-454E-0201-000000016258}) (Version: 2.1.16258 - Acer)
Acer Quick Access (HKLM\...\{8BBF04F1-C68A-441C-B5EF-446EE9960EAF}) (Version: 2.01.3012 - Acer Incorporated)
Acer UEIP Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 3.03.3000 - Acer Incorporated)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 23.001.20174 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Aplikace Intel® PROSet/Wireless (HKLM-x32\...\{ed5cef80-a339-45bd-8c06-514eaf785ca8}) (Version: 19.71.0 - Intel Corporation)
Backup and Sync from Google (HKLM\...\{696895F7-52C7-4C9E-998B-C7E0CC907092}) (Version: 3.57.4256.0809 - Google, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 6.01 - Piriform)
Dashlane Upgrade Service (HKLM-x32\...\Dashlane Upgrade Service) (Version: 2.1.17.0 - Dashlane, Inc.)
Documentation Manager (HKLM\...\{FDDF7EA4-D624-4418-B3C5-1CF6247F844D}) (Version: 21.60.2.1 - Intel Corporation) Hidden
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 74.0.3.0 - Google LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 113.0.5672.93 - Google LLC)
HP Color Laser MFP 178 179 (HKLM-x32\...\HP Color Laser MFP 178 179) (Version: V1.15 (05.05.2021) - HP Inc.)
HP MFP Scan (HKLM-x32\...\HP MFP Scan) (Version: 1.06.67 (07.04.2021) - HP Inc.)
HP Scan Process Machine (HKLM-x32\...\HP Scan Process Machine) (Version: 1.03.05.30 - HP Development Company, L.P.) Hidden
Intel(R) Chipset Device Software (HKLM\...\{3AAD3A73-0D6A-4EFE-93FC-7719DC6C89E4}) (Version: 10.1.1.37 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{226be6c3-8e08-4d52-bd3a-d361008448c5}) (Version: 10.1.1.37 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1025 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{4EB05024-F740-48CF-B9B0-62A041E22D5C}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{DD04783C-E206-46DB-97A7-1155B1C76038}) (Version: 11.6.0.1025 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6446 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1633.3 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{EC883E72-01ED-4DED-AA46-9162C34A7D4F}) (Version: 30.100.1633.03 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000060-0210-1029-84C8-B8D95FA3C8C3}) (Version: 21.60.0.4 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{5E952F21-EFE4-47D8-9C8E-29AE9A2D75B7}) (Version: 19.71.0.1071 - Intel Corporation) Hidden
Intel® Software Installer (HKLM-x32\...\{91984066-e894-49de-ac7d-b2ef4fe7b446}) (Version: 21.60.2.1 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{75FE588B-F158-4BB3-A283-A8D18E522A52}) (Version: 1.43.301.1 - Intel Corporation) Hidden
IrfanView 4.53 (64-bit) (HKLM\...\IrfanView64) (Version: 4.53 - Irfan Skiljan)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Kyocera Product Library (HKLM\...\Kyocera Product Library) (Version: 5.0.3128 - KYOCERA Document Solutions Inc.)
KYOCERA Status Monitor 5 (HKLM\...\{24EE7F6D-C648-463f-9E71-DC5FD2258D17}) (Version: 5.0.62.13 - KYOCERA Document Solutions Inc.)
LG Mobile Driver (HKLM-x32\...\{3F490D0E-3131-438C-BCF9-7549CB88DF41}) (Version: 4.8.0 - LG Electronics)
LocalServiceComponents (HKLM-x32\...\{80DDB8B4-9C6F-44A2-81AD-155EE6917A9A}_is1) (Version: 1.0.0.48 - )
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 113.0.1774.42 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 113.0.1774.42 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 16.0.4266.1003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{BB052C53-34CB-42DE-AF41-66FDFCEEC868}) (Version: 3.72.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{B409944C-1493-4B0D-A92C-2CE3C5F5F289}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{0E8D087B-5654-4010-AF4D-DE1250B8C1EB}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30037 (HKLM-x32\...\{4b2f3795-f407-415e-88d5-8c8ab322909d}) (Version: 14.29.30037.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30040 (HKLM-x32\...\{a8968509-65be-4c09-a460-fd1584b1cdbf}) (Version: 14.29.30040.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.29.30037 (HKLM\...\{529D20E8-132A-4F1A-A25F-9211B8C943AC}) (Version: 14.29.30037 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.29.30037 (HKLM\...\{C874FB5A-1C85-460A-A4A9-CBCC3FAE7880}) (Version: 14.29.30037 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.29.30040 (HKLM-x32\...\{EFC21A37-5640-4BE1-981A-2FD3EDA1D893}) (Version: 14.29.30040 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.29.30040 (HKLM-x32\...\{3093CC12-EF27-4036-AD72-A759500271E9}) (Version: 14.29.30040 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 113.0.1 (x64 cs)) (Version: 113.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 92.0 - Mozilla)
Norton 360 (HKLM-x32\...\NGC) (Version: 22.23.4.6 - Symantec Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
PSPad editor (HKLM\...\PSPad editor 64bit_is1) (Version: 5.0.6.589 - Jan Fiala)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31228 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.10.714.2016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7936 - Realtek Semiconductor Corp.)
Tim 9.31.31 (HKLM-x32\...\{44B8FFD5-5D77-44F6-9B19-D459078ABDC5}) (Version: 9.31.31 - Ing. Martin Lenz - HippoSoft)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.22 - Ghisler Software GmbH)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden
Vision ERP (HKLM\...\Vision ERP_is1) (Version: - Vision Praha s.r.o.)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Web Components (HKLM-x32\...\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1) (Version: 3.0.7.21 - )
WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - )
Xerox Phaser 3435 (HKLM-x32\...\Xerox Phaser 3435) (Version: - )

Packages:
=========
abFiles -> C:\Program Files\WindowsApps\AcerIncorporated.abFiles_1.0.7.0_x86__48frkmn4z8aw4 [2018-08-31] (Acer Incorporated)
abPhoto -> C:\Program Files\WindowsApps\AcerIncorporated.6245439DEEE9E_1.0.10.0_x86__48frkmn4z8aw4 [2018-08-31] (Acer Incorporated)
Acer Collection -> C:\Program Files\WindowsApps\AcerIncorporated.AcerCollection_1.1.3013.0_x64__48frkmn4z8aw4 [2018-10-20] (Acer Incorporated)
Acer Portal -> C:\Program Files\WindowsApps\AcerIncorporated.AcerPortal_1.1.9.0_x86__48frkmn4z8aw4 [2018-09-01] (Acer Incorporated)
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-09] (Autodesk Inc.)
Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_7.33.22.0_x64__kgqvnymyfvs32 [2023-05-04] (king.com)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.242.800.0_x64__kgqvnymyfvs32 [2023-05-08] (king.com)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2023-03-30] (Microsoft Corporation)
eBay -> C:\Program Files\WindowsApps\eBay_1.0.1606.2210_x64__96rgg7pjt343r [2017-11-22] (CN=Acer Incorporated)
Evernote -> C:\Program Files\WindowsApps\Evernote.Evernote_10.56.9.0_x64__q4d96b2w5wcc2 [2023-05-10] (Evernote) [Startup Task]
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_145.2.1084.0_x64__v10z8vjag6ke6 [2023-05-10] (HP Inc.)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa [2023-04-03] (Apple Inc.) [Startup Task]
KYOCERA Print Center -> C:\Program Files\WindowsApps\A97ECD55.KYOCERAPrintCenter_4.1.11108.0_x64__kqmhh0ktdt7dg [2022-12-10] (KYOCERA Document Solutions Inc)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-13] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-13] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-17] (Netflix, Inc.)
Samsung Printer Experience -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungPrinterExperience_1.3.15.0_x64__3c1yjt4zspk6g [2018-08-31] (Samsung Electronics Co. Ltd.)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.16.3140.0_x64__8wekyb3d8bbwe [2023-03-22] (Microsoft Studios) [MS Ad]
WinZip Universal -> C:\Program Files\WindowsApps\WinZipComputing.WinZipUniversal_1.5.13516.0_x64__3ykzqggjzj4z0 [2019-06-01] (WinZip Computing)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1522470202-1352138926-4199276785-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\74.0.3.0\drivefsext.dll [2023-05-03] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\74.0.3.0\drivefsext.dll [2023-05-03] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\74.0.3.0\drivefsext.dll [2023-05-03] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\74.0.3.0\drivefsext.dll [2023-05-03] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2017-06-07] (Acer Incorporated -> Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2017-06-07] (Acer Incorporated -> Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2017-06-07] (Acer Incorporated -> Acer Incorporated)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\74.0.3.0\drivefsext.dll [2023-05-03] (Google LLC -> Google, Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2022-02-01] (Google LLC -> Google)
ContextMenuHandlers1: [NortonLifeLock.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security\Engine\22.23.4.6\NavShExt.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers2: [NortonLifeLock.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security\Engine\22.23.4.6\NavShExt.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\74.0.3.0\drivefsext.dll [2023-05-03] (Google LLC -> Google, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2022-02-01] (Google LLC -> Google)
ContextMenuHandlers4: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers4: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\74.0.3.0\drivefsext.dll [2023-05-03] (Google LLC -> Google, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\igfxDTCM.dll [2018-11-27] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Security\Engine\22.23.4.6\buShell.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
ContextMenuHandlers6: [NortonLifeLock.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security\Engine\22.23.4.6\NavShExt.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2018-08-30 13:51 - 2009-06-02 01:15 - 000051200 _____ () [File not signed] C:\Program Files (x86)\WinRAR\rarext64.dll
2019-02-01 23:42 - 2019-02-01 23:42 - 000050688 _____ (HP Inc.) [File not signed] c:\windows\system32\hpzinw12.dll
2019-02-01 23:42 - 2019-02-01 23:42 - 000066048 _____ (HP Inc.) [File not signed] c:\windows\system32\hpzipm12.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer17win10.msn.com/?pc=ACTE
SearchScopes: HKU\S-1-5-21-1522470202-1352138926-4199276785-1001 -> DefaultScope {BEFE635F-0D39-4DB6-989D-26AD27FA9366} URL =
SearchScopes: HKU\S-1-5-21-1522470202-1352138926-4199276785-1001 -> {BEFE635F-0D39-4DB6-989D-26AD27FA9366} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
BHO: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security\Engine\22.23.4.6\coIEPlg.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security\Engine32\22.23.4.6\coIEPlg.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security\Engine\22.23.4.6\coIEPlg.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security\Engine32\22.23.4.6\coIEPlg.dll [2023-05-10] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-03] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2017-03-18 23:01 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Vision32\asa\bin64;C:\Program Files\Vision32\asa\bin32;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKCU\Environment\\Path -> %USERPROFILE%\AppData\Local\Microsoft\WindowsApps
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.1.1 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "LocalServiceControl"
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\...\StartupApproved\Run: => "OneDriveSetup"
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B"
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\...\StartupApproved\Run: => "GoogleDriveFS"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{79F86C99-416F-46E8-959D-C06B2CBC6384}] => (Allow) C:\Users\Admin\AppData\Local\Apowersoft\Online Video Converter\Online Video Converter.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [{1360EDD5-E28A-4F7D-B7E0-747E93B8A02E}] => (Allow) C:\Users\Admin\AppData\Local\Apowersoft\Online Video Converter\Online Video Converter.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [{328D9B29-AEC4-4957-8778-62DD44BC9105}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E21D1282-EB22-4FBB-9E82-14527A3B0CC6}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5BD586B2-E5EF-40F3-A053-3C7D41E6C0A5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3C0A8C3D-B2CD-42D7-B366-05BFEE7B69C0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{89C6C083-B3EE-4CA3-9F05-98FBB9418108}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform)
FirewallRules: [{2E95C356-F3C2-498B-9FCA-83F37A018BD9}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform)
FirewallRules: [{8BD38E8A-C9F5-4E43-954F-CA5ECEBFAD50}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel(R) Wireless Connectivity Solutions -> )
FirewallRules: [{5A79AADA-2057-4FE3-A2C5-BFC0D9957844}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6F0120E6-28B7-439A-B83D-60199844B77F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{59A8F503-6459-45DF-8CE8-C1BD6154C93C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8B0EEA78-70D1-4B64-9948-4007F8BCEC4D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{19A4242E-8463-4A5E-BDF7-1508C7F3C54D}] => (Allow) LPort=9422
FirewallRules: [{E00877D0-3872-4E9D-A876-315FB2384D79}] => (Allow) LPort=9245
FirewallRules: [{92A2F723-9523-49BE-AB66-60DABD2C19D0}] => (Allow) LPort=9246
FirewallRules: [{CD05FB5C-7DD7-45E9-B24F-B5B1B5B11129}] => (Allow) LPort=9247
FirewallRules: [{A2BCE7B3-9FA8-4C07-A1DB-DCC9D751BB6C}] => (Allow) LPort=3702
FirewallRules: [{E476C6E2-6268-4FBB-82C1-F00C785A0EFB}] => (Allow) LPort=9244
FirewallRules: [{7871AF74-4C74-4289-B3C1-CE9C2ABD38DF}] => (Allow) LPort=9444
FirewallRules: [{CB6975C3-02F1-4CB4-92B3-B8CCF1C7D471}] => (Allow) C:\Windows\twain_32\HP\HPCLM17X\ScanCDLM\ScanCDLM.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{D22BBAFC-39F1-4301-AAA1-CBA9CE9177A1}] => (Allow) C:\Windows\twain_32\HP\HPCLM17X\ScanCDLM\ScanCDLM.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{CD6830CE-BBBC-484C-B151-2D485FA3C4F3}] => (Allow) C:\Program Files (x86)\HP\MFP Scan\EDC.exe () [File not signed]
FirewallRules: [{A5F8DB04-BB22-43C6-AF1D-15D057BA3A83}] => (Allow) C:\Program Files (x86)\HP\MFP Scan\EDC.exe () [File not signed]
FirewallRules: [{D825C2E8-BBE2-4DC3-8025-7BF3B8DF8497}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{96493252-D5C8-4D87-B170-2294F0897BD5}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FF845C7C-7622-4D36-BA42-C891C40AC343}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CA57B706-6EE1-4EF2-8EE7-96E0D3AA4065}] => (Allow) C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E7412666-7683-4FED-854C-395A70D8DDED}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{658F0E65-131C-4ED9-97C7-857FCA3B256C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{317E9918-6FDB-4487-85C1-ECA9CEDD73A8}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{A7A422E9-C99D-4FAE-8023-5FA0D7D09D52}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{757BF4A5-8CE6-4B65-A5AC-4323064FE872}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{2757609E-9095-49E9-84F2-CB882104D3DA}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{CC8D3778-0060-454B-B19C-7319089043C5}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{5C9C40B0-29D9-481E-81D7-93E626983089}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12128.2.57059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{98E8B86E-7494-4AB0-9E9F-B854C15F9CF6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{9AF9C101-EA7E-4B17-B466-F21823866AC9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.97.3404.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{20788D31-6B14-4426-80F1-59D9A98A0392}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.97.3404.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8217217D-E290-4569-9FA5-FC4BC4CB3F9A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.97.3404.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5EE853BC-2383-419B-B358-7D4D2A6994E6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.97.3404.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{700958F5-52DF-444A-AFB9-5E4BD4E24E6F}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\113.0.1774.42\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

27-04-2023 07:01:38 Instalační služba modulů systému Windows
05-05-2023 09:45:57 Naplánovaný kontrolní bod
10-05-2023 06:52:37 Instalační služba modulů systému Windows
10-05-2023 06:56:07 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (05/17/2023 06:42:26 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu na SECURITY_PRODUCT_STATE_SNOOZED došlo k chybě.

Error: (05/17/2023 06:39:39 AM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]

Error: (05/17/2023 06:38:44 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
Spouštění asynchronní operace

Kontext:
Aktuální stav: DoSnapshotSet

Error: (05/17/2023 06:38:11 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {afb6c037-b359-4286-9e50-4dfc8406806d}

Error: (05/16/2023 07:54:03 PM) (Source: Firefox Default Browser Agent) (EventID: 2) (User: )
Description: Event-ID 2

Error: (05/16/2023 02:14:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NortonSecurity.exe, verze: 17.2.3.65, časové razítko: 0x61f2cd8e
Název chybujícího modulu: ntdll.dll, verze: 10.0.19041.2788, časové razítko: 0x2f715b17
Kód výjimky: 0xc0000374
Posun chyby: 0x00000000000ff449
ID chybujícího procesu: 0x21b8
Čas spuštění chybující aplikace: 0x01d987bd2a215df9
Cesta k chybující aplikaci: C:\Program Files\Norton Security\Engine\22.23.4.6\NortonSecurity.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: 2d9ddd71-ff08-414b-98e3-ed04989a96db
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (05/16/2023 05:27:05 AM) (Source: Firefox Default Browser Agent) (EventID: 2) (User: )
Description: Event-ID 2

Error: (05/15/2023 05:29:28 AM) (Source: Firefox Default Browser Agent) (EventID: 2) (User: )
Description: Event-ID 2


System errors:
=============
Error: (05/17/2023 06:40:11 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba npf neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (05/16/2023 02:14:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Norton Security byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (05/10/2023 09:31:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba npf neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (05/09/2023 01:02:16 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-BHS3FTNJ)
Description: Server microsoft.windowscommunicationsapps_16005.14326.21422.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (05/08/2023 07:04:46 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-BHS3FTNJ)
Description: Server microsoft.windowscommunicationsapps_16005.14326.21422.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (05/02/2023 06:16:31 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-BHS3FTNJ)
Description: Server microsoft.windowscommunicationsapps_16005.14326.21422.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (04/29/2023 06:08:31 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-BHS3FTNJ)
Description: Server microsoft.windowscommunicationsapps_16005.14326.21422.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (04/22/2023 08:28:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba npf neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.


CodeIntegrity:
===============
Date: 2023-05-17 06:43:25
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume3\Program Files\Norton Security\Engine\22.23.4.6\symamsi.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: Insyde Corp. V1.11 08/11/2017
Motherboard: Acer BA40_SL
Processor: Intel(R) Core(TM) i3-6006U CPU @ 2.00GHz
Percentage of memory in use: 83%
Total physical RAM: 3976.91 MB
Available physical RAM: 645.39 MB
Total Virtual: 8584.91 MB
Available Virtual: 4587.41 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:445.9 GB) (Free:313.84 GB) (Model: KINGSTON SA400S37480G) NTFS
Drive s: () (Network) (Total:233.67 GB) (Free:103.54 GB) (Model: KINGSTON SA400S37480G)

\\?\Volume{a0722515-51e8-453d-98ee-d61caa603de3}\ (Recovery) (Fixed) (Total:1 GB) (Free:0.49 GB) NTFS
\\?\Volume{b1ffb85a-8c2f-4b6e-bd08-c51f5832fc5c}\ (ESP) (Fixed) (Total:0.1 GB) (Free:0.04 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 447.1 GB) (Disk ID: BDDFCC1E)

Partition: GPT.

==================== End of Addition.txt =======================

Re: Kontrola logu

Napsal: 17 kvě 2023 08:27
od Rudy
Zdravím!
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\...\Print\Monitors\uh004 Langmon: uh004lm.dll (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Task: {20E70B51-8812-4B91-A9F0-7C77331F4465} - System32\Tasks\{382206AF-3B40-4179-A5AB-6282A401826A} => C:\Users\Admin\AppData\Local\Temp\B48B80E2-A0E4-41F0-932C-865F8131BF7D\ga_service.exe/uninstall <==== ATTENTION
Task: {2EFB0596-5DF8-4C00-A6DE-E36BCB7A79E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-18] (Google Inc -> Google Inc.)
Task: {F50F14CE-02BF-4ECC-9842-D840AC68957A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-18] (Google Inc -> Google Inc.)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
U4 npcap_wifi; no ImagePath
C:\DumpStack.log.tmp
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers4: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers4: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
SearchScopes: HKU\S-1-5-21-1522470202-1352138926-4199276785-1001 -> DefaultScope {BEFE635F-0D39-4DB6-989D-26AD27FA9366} URL =
SearchScopes: HKU\S-1-5-21-1522470202-1352138926-4199276785-1001 -> {BEFE635F-0D39-4DB6-989D-26AD27FA9366} URL =

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Kontrola logu

Napsal: 17 kvě 2023 09:14
od dandar
Fix result of Farbar Recovery Scan Tool (x64) Version: 12-05-2023 01
Ran by Admin (17-05-2023 09:53:42) Run:1
Running from C:\Users\Admin\Desktop
Loaded Profiles: Admin
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\...\Print\Monitors\uh004 Langmon: uh004lm.dll (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Task: {20E70B51-8812-4B91-A9F0-7C77331F4465} - System32\Tasks\{382206AF-3B40-4179-A5AB-6282A401826A} => C:\Users\Admin\AppData\Local\Temp\B48B80E2-A0E4-41F0-932C-865F8131BF7D\ga_service.exe/uninstall <==== ATTENTION
Task: {2EFB0596-5DF8-4C00-A6DE-E36BCB7A79E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-18] (Google Inc -> Google Inc.)
Task: {F50F14CE-02BF-4ECC-9842-D840AC68957A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-18] (Google Inc -> Google Inc.)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
U4 npcap_wifi; no ImagePath
C:\DumpStack.log.tmp
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers4: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers4: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
SearchScopes: HKU\S-1-5-21-1522470202-1352138926-4199276785-1001 -> DefaultScope {BEFE635F-0D39-4DB6-989D-26AD27FA9366} URL =
SearchScopes: HKU\S-1-5-21-1522470202-1352138926-4199276785-1001 -> {BEFE635F-0D39-4DB6-989D-26AD27FA9366} URL =

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully
HKLM\System\CurrentControlSet\Control\Print\Monitors\uh004 Langmon => removed successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{20E70B51-8812-4B91-A9F0-7C77331F4465}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20E70B51-8812-4B91-A9F0-7C77331F4465}" => removed successfully
C:\WINDOWS\System32\Tasks\{382206AF-3B40-4179-A5AB-6282A401826A} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{382206AF-3B40-4179-A5AB-6282A401826A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2EFB0596-5DF8-4C00-A6DE-E36BCB7A79E2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2EFB0596-5DF8-4C00-A6DE-E36BCB7A79E2}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F50F14CE-02BF-4ECC-9842-D840AC68957A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F50F14CE-02BF-4ECC-9842-D840AC68957A}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
HKLM\System\CurrentControlSet\Services\npcap_wifi => removed successfully
npcap_wifi => service removed successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found
C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\WinRAR => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\WinRAR32 => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
"HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-1522470202-1352138926-4199276785-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BEFE635F-0D39-4DB6-989D-26AD27FA9366} => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 105429026 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 6395092 B
Edge => 29184 B
Chrome => 23313357 B
Firefox => 1638981965 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6656 B
ProgramData => 6656 B
Public => 6656 B
systemprofile => 6656 B
systemprofile32 => 6656 B
LocalService => 175286 B
NetworkService => 175286 B
Admin => 19577764 B

RecycleBin => 17235207278 B
EmptyTemp: => 17.7 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 17-05-2023 10:12:03)

C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 10:12:03 ====

Re: Kontrola logu

Napsal: 17 kvě 2023 12:27
od Rudy
Smazáno, log by již měl být OK.

Re: Kontrola logu

Napsal: 17 kvě 2023 12:34
od dandar
OK, děkuji

Re: Kontrola logu

Napsal: 17 kvě 2023 12:50
od Rudy
Rádo se stalo! :)