Stránka 1 z 1

Preventivka

Napsal: 13 pro 2023 12:44
od Dabol
Dobry den, poprosil by som o preventivnu kontrolu.

prikladam subor s logmi

Re: Preventivka

Napsal: 14 pro 2023 14:48
od Rudy
Zdravím!
ADWC je OK. Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {3ad3a40d-d2b9-11ed-80f2-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {3c93d59e-c79c-11ec-808e-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {4f93794f-3ca9-11ec-804e-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {be2b5f39-58f3-11ec-8059-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {cbc68fd4-f04c-11eb-802f-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
Task: {48CF8BD1-C0C4-43F7-B7B7-19CCA93F932F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-12-05] (Google Inc -> Google Inc.)
Task: {1A7473FC-BF27-4F3D-816F-49D043FD3F5B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-12-05] (Google Inc -> Google Inc.)
Task: {FF34FA94-FB60-4E10-A1D4-D6D0B6702DBA} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {1EF7CD48-64EC-4696-BEE2-DC874B8F12DF} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File)
Task: {4BC45D22-3476-4070-96C3-E53B070191E6} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File)
Task: {691E63EE-513C-4708-8F27-E8CDC2B92A28} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File)
Task: {D05AFD76-62EB-4680-9937-6E134C8D7CB2} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe /DRMInit (No File)
Task: {1413F395-76E8-4374-B44A-2C12DFAF324C} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File)
Task: {9470BEB8-EA09-4DAB-89D3-27E75EF349A2} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate $(Arg0) (No File)
Task: {3C692DCA-F9A7-4941-BF8A-9CBEDEDF67AE} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15 (No File)
Task: {EA98B11F-B665-46AD-A9D0-B0D309433D0C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask (No File)
Task: {71EF1EDB-FC21-4C88-BCA1-A467FAFDCBC7} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File)
Task: {29295ECC-D7E0-49C0-AE42-03D8CE573C2F} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate (No File)
Task: {D35F57F8-A671-4876-9CA5-81E16A9D7374} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File)
Task: {1F5A24E2-AEBB-4704-8390-A1DACDAEE1F7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery (No File)
Task: {8C3DE8AC-16F6-4C58-AF2F-721D04A08F83} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File)
Task: {057AA37C-1E7B-482E-AE5E-5D6494D61CC7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File)
Task: {7ABCAAE9-63A6-41C3-9255-3E0B9107708F} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe -pscn 0 (No File)
Task: {47E2B4C5-F0F3-44D1-A0B5-3F463EB56D14} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask (No File)
Task: {89A56F95-8F0F-4612-999C-9763FD8ADD5E} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe -PvrSchedule (No File)
Task: {ABE22294-5FD8-4B38-A82D-87554E005D90} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec /RestartRecording (No File)
Task: {53DA0B0D-B1F8-4834-ACBD-BBA34B940588} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File)
Task: {C2C77206-9EBE-4A13-AFE4-BC867EA12F31} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File)
Task: {1E71098D-F292-4CBC-9667-4B79B0C961F2} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File)
Task: {1D791CC3-17E4-4999-BF00-A4C3A000212E} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec /StartRecording (No File)
Task: {75EBF16C-4D2D-4B0F-84C4-ABC56EFDFF51} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File)
Task: {088E470C-3016-4CC7-BA6A-1F4E57BADF32} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4022844962-3646224466-4261461506-1003 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {D3AEE096-79FB-445A-A5E5-2C6B8C2DD711} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4022844962-3646224466-4261461506-1003 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
CustomCLSID: HKU\S-1-5-21-4022844962-3646224466-4261461506-1000_Classes\CLSID\{74D0CE91-F931-4FAC-BEA9-EE32E43EAD37}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2020 - English\dwgviewr.exe => No File
CustomCLSID: HKU\S-1-5-21-4022844962-3646224466-4261461506-1000_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> C:\Users\Marcel\AppData\Local\Microsoft\OneDrive\19.232.1124.0010\FileCoAuth.exe => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
BHO: No Name -> {FDF253AC-1724-4853-BE34-C2DBC18FB5CA} -> No File
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
FirewallRules: [TCP Query User{7F35E15D-D2B2-4B00-8A11-548224676FE1}C:\users\marcel\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\marcel\appdata\local\akamai\netsession_win.exe => No File
FirewallRules: [UDP Query User{5001F90A-FBF3-46EF-ABA7-42F5635157B0}C:\users\marcel\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\marcel\appdata\local\akamai\netsession_win.exe => No File
FirewallRules: [TCP Query User{1C42FDDF-DB7D-40E5-8A7A-5BA67CF9B772}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [TCP Query User{2DA6CA79-949D-47C9-8F4D-658C9CFD4123}C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe] => (Allow) C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe => No File
FirewallRules: [UDP Query User{ADF9E8B2-D4DD-4362-806B-853C665702FD}C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe] => (Allow) C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe => No File
FirewallRules: [TCP Query User{AC478712-04C4-47A1-BB10-3ABCC1CFF8DD}C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe] => (Allow) C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe => No File
FirewallRules: [UDP Query User{BA552399-773A-4856-87DB-839CCA54B264}C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe] => (Allow) C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe => No File
FirewallRules: [TCP Query User{B00142C6-BA19-4727-98CE-A57049D22CB1}C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe] => (Allow) C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe => No File
FirewallRules: [UDP Query User{28BF4B17-DE0D-4567-98C7-F104C95E8402}C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe] => (Allow) C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe => No File
FirewallRules: [{5DEB3814-0658-4C84-9289-A6B84B411451}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [{26D754B7-6AC5-42BF-93FB-823CB43B4264}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [{A1C76090-DFEF-4D80-BCFE-2F077D1E82CE}] => (Allow) C:\Program Files\LogiOptionsPlus\logivoice\logioptionsplus_logivoice => No File

EmoptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Preventivka

Napsal: 15 pro 2023 07:06
od Dabol
Fix result of Farbar Recovery Scan Tool (x64) Version: 13-12-2023
Ran by Marcel (15-12-2023 07:02:57) Run:2
Running from C:\Users\Marcel\Desktop
Loaded Profiles: Marcel
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {3ad3a40d-d2b9-11ed-80f2-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {3c93d59e-c79c-11ec-808e-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {4f93794f-3ca9-11ec-804e-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {be2b5f39-58f3-11ec-8059-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\...\MountPoints2: {cbc68fd4-f04c-11eb-802f-705a0fe9b902} - "F:\HiSuiteDownLoader.exe"
Task: {48CF8BD1-C0C4-43F7-B7B7-19CCA93F932F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-12-05] (Google Inc -> Google Inc.)
Task: {1A7473FC-BF27-4F3D-816F-49D043FD3F5B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-12-05] (Google Inc -> Google Inc.)
Task: {FF34FA94-FB60-4E10-A1D4-D6D0B6702DBA} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {1EF7CD48-64EC-4696-BEE2-DC874B8F12DF} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File)
Task: {4BC45D22-3476-4070-96C3-E53B070191E6} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File)
Task: {691E63EE-513C-4708-8F27-E8CDC2B92A28} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File)
Task: {D05AFD76-62EB-4680-9937-6E134C8D7CB2} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe /DRMInit (No File)
Task: {1413F395-76E8-4374-B44A-2C12DFAF324C} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File)
Task: {9470BEB8-EA09-4DAB-89D3-27E75EF349A2} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate $(Arg0) (No File)
Task: {3C692DCA-F9A7-4941-BF8A-9CBEDEDF67AE} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15 (No File)
Task: {EA98B11F-B665-46AD-A9D0-B0D309433D0C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask (No File)
Task: {71EF1EDB-FC21-4C88-BCA1-A467FAFDCBC7} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File)
Task: {29295ECC-D7E0-49C0-AE42-03D8CE573C2F} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate (No File)
Task: {D35F57F8-A671-4876-9CA5-81E16A9D7374} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File)
Task: {1F5A24E2-AEBB-4704-8390-A1DACDAEE1F7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery (No File)
Task: {8C3DE8AC-16F6-4C58-AF2F-721D04A08F83} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File)
Task: {057AA37C-1E7B-482E-AE5E-5D6494D61CC7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File)
Task: {7ABCAAE9-63A6-41C3-9255-3E0B9107708F} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe -pscn 0 (No File)
Task: {47E2B4C5-F0F3-44D1-A0B5-3F463EB56D14} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask (No File)
Task: {89A56F95-8F0F-4612-999C-9763FD8ADD5E} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe -PvrSchedule (No File)
Task: {ABE22294-5FD8-4B38-A82D-87554E005D90} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec /RestartRecording (No File)
Task: {53DA0B0D-B1F8-4834-ACBD-BBA34B940588} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File)
Task: {C2C77206-9EBE-4A13-AFE4-BC867EA12F31} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File)
Task: {1E71098D-F292-4CBC-9667-4B79B0C961F2} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File)
Task: {1D791CC3-17E4-4999-BF00-A4C3A000212E} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec /StartRecording (No File)
Task: {75EBF16C-4D2D-4B0F-84C4-ABC56EFDFF51} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File)
Task: {088E470C-3016-4CC7-BA6A-1F4E57BADF32} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4022844962-3646224466-4261461506-1003 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {D3AEE096-79FB-445A-A5E5-2C6B8C2DD711} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4022844962-3646224466-4261461506-1003 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
CustomCLSID: HKU\S-1-5-21-4022844962-3646224466-4261461506-1000_Classes\CLSID\{74D0CE91-F931-4FAC-BEA9-EE32E43EAD37}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2020 - English\dwgviewr.exe => No File
CustomCLSID: HKU\S-1-5-21-4022844962-3646224466-4261461506-1000_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> C:\Users\Marcel\AppData\Local\Microsoft\OneDrive\19.232.1124.0010\FileCoAuth.exe => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
BHO: No Name -> {FDF253AC-1724-4853-BE34-C2DBC18FB5CA} -> No File
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
FirewallRules: [TCP Query User{7F35E15D-D2B2-4B00-8A11-548224676FE1}C:\users\marcel\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\marcel\appdata\local\akamai\netsession_win.exe => No File
FirewallRules: [UDP Query User{5001F90A-FBF3-46EF-ABA7-42F5635157B0}C:\users\marcel\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\marcel\appdata\local\akamai\netsession_win.exe => No File
FirewallRules: [TCP Query User{1C42FDDF-DB7D-40E5-8A7A-5BA67CF9B772}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [TCP Query User{2DA6CA79-949D-47C9-8F4D-658C9CFD4123}C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe] => (Allow) C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe => No File
FirewallRules: [UDP Query User{ADF9E8B2-D4DD-4362-806B-853C665702FD}C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe] => (Allow) C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe => No File
FirewallRules: [TCP Query User{AC478712-04C4-47A1-BB10-3ABCC1CFF8DD}C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe] => (Allow) C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe => No File
FirewallRules: [UDP Query User{BA552399-773A-4856-87DB-839CCA54B264}C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe] => (Allow) C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe => No File
FirewallRules: [TCP Query User{B00142C6-BA19-4727-98CE-A57049D22CB1}C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe] => (Allow) C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe => No File
FirewallRules: [UDP Query User{28BF4B17-DE0D-4567-98C7-F104C95E8402}C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe] => (Allow) C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe => No File
FirewallRules: [{5DEB3814-0658-4C84-9289-A6B84B411451}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [{26D754B7-6AC5-42BF-93FB-823CB43B4264}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [{A1C76090-DFEF-4D80-BCFE-2F077D1E82CE}] => (Allow) C:\Program Files\LogiOptionsPlus\logivoice\logioptionsplus_logivoice => No File

EmoptyTemp:
End
*****************

Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ad3a40d-d2b9-11ed-80f2-705a0fe9b902} => removed successfully
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3c93d59e-c79c-11ec-808e-705a0fe9b902} => removed successfully
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4f93794f-3ca9-11ec-804e-705a0fe9b902} => removed successfully
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{be2b5f39-58f3-11ec-8059-705a0fe9b902} => removed successfully
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbc68fd4-f04c-11eb-802f-705a0fe9b902} => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{48CF8BD1-C0C4-43F7-B7B7-19CCA93F932F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{48CF8BD1-C0C4-43F7-B7B7-19CCA93F932F}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1A7473FC-BF27-4F3D-816F-49D043FD3F5B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A7473FC-BF27-4F3D-816F-49D043FD3F5B}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FF34FA94-FB60-4E10-A1D4-D6D0B6702DBA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF34FA94-FB60-4E10-A1D4-D6D0B6702DBA}" => removed successfully
C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1EF7CD48-64EC-4696-BEE2-DC874B8F12DF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EF7CD48-64EC-4696-BEE2-DC874B8F12DF}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4BC45D22-3476-4070-96C3-E53B070191E6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BC45D22-3476-4070-96C3-E53B070191E6}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{691E63EE-513C-4708-8F27-E8CDC2B92A28}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{691E63EE-513C-4708-8F27-E8CDC2B92A28}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D05AFD76-62EB-4680-9937-6E134C8D7CB2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D05AFD76-62EB-4680-9937-6E134C8D7CB2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ehDRMInit" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1413F395-76E8-4374-B44A-2C12DFAF324C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1413F395-76E8-4374-B44A-2C12DFAF324C}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\InstallPlayReady" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9470BEB8-EA09-4DAB-89D3-27E75EF349A2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9470BEB8-EA09-4DAB-89D3-27E75EF349A2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C692DCA-F9A7-4941-BF8A-9CBEDEDF67AE}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C692DCA-F9A7-4941-BF8A-9CBEDEDF67AE}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA98B11F-B665-46AD-A9D0-B0D309433D0C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA98B11F-B665-46AD-A9D0-B0D309433D0C}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71EF1EDB-FC21-4C88-BCA1-A467FAFDCBC7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71EF1EDB-FC21-4C88-BCA1-A467FAFDCBC7}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{29295ECC-D7E0-49C0-AE42-03D8CE573C2F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29295ECC-D7E0-49C0-AE42-03D8CE573C2F}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURActivate" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D35F57F8-A671-4876-9CA5-81E16A9D7374}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D35F57F8-A671-4876-9CA5-81E16A9D7374}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURDiscovery" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1F5A24E2-AEBB-4704-8390-A1DACDAEE1F7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F5A24E2-AEBB-4704-8390-A1DACDAEE1F7}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscovery" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8C3DE8AC-16F6-4C58-AF2F-721D04A08F83}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C3DE8AC-16F6-4C58-AF2F-721D04A08F83}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{057AA37C-1E7B-482E-AE5E-5D6494D61CC7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{057AA37C-1E7B-482E-AE5E-5D6494D61CC7}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7ABCAAE9-63A6-41C3-9255-3E0B9107708F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7ABCAAE9-63A6-41C3-9255-3E0B9107708F}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47E2B4C5-F0F3-44D1-A0B5-3F463EB56D14}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47E2B4C5-F0F3-44D1-A0B5-3F463EB56D14}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89A56F95-8F0F-4612-999C-9763FD8ADD5E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89A56F95-8F0F-4612-999C-9763FD8ADD5E}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{ABE22294-5FD8-4B38-A82D-87554E005D90}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ABE22294-5FD8-4B38-A82D-87554E005D90}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RecordingRestart" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{53DA0B0D-B1F8-4834-ACBD-BBA34B940588}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53DA0B0D-B1F8-4834-ACBD-BBA34B940588}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RegisterSearch" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C2C77206-9EBE-4A13-AFE4-BC867EA12F31}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2C77206-9EBE-4A13-AFE4-BC867EA12F31}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1E71098D-F292-4CBC-9667-4B79B0C961F2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E71098D-F292-4CBC-9667-4B79B0C961F2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D791CC3-17E4-4999-BF00-A4C3A000212E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D791CC3-17E4-4999-BF00-A4C3A000212E}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{75EBF16C-4D2D-4B0F-84C4-ABC56EFDFF51}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75EBF16C-4D2D-4B0F-84C4-ABC56EFDFF51}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{088E470C-3016-4CC7-BA6A-1F4E57BADF32}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{088E470C-3016-4CC7-BA6A-1F4E57BADF32}" => removed successfully
C:\WINDOWS\System32\Tasks\OneDrive Reporting Task-S-1-5-21-4022844962-3646224466-4261461506-1003 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Reporting Task-S-1-5-21-4022844962-3646224466-4261461506-1003" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D3AEE096-79FB-445A-A5E5-2C6B8C2DD711}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3AEE096-79FB-445A-A5E5-2C6B8C2DD711}" => removed successfully
C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4022844962-3646224466-4261461506-1003 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Standalone Update Task-S-1-5-21-4022844962-3646224466-4261461506-1003" => removed successfully
"HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08" => not found
"HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8" => not found
"HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824" => not found
"HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000_Classes\CLSID\{74D0CE91-F931-4FAC-BEA9-EE32E43EAD37} => removed successfully
HKU\S-1-5-21-4022844962-3646224466-4261461506-1000_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDF253AC-1724-4853-BE34-C2DBC18FB5CA} => removed successfully
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) => Error: No automatic fix found for this entry.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{7F35E15D-D2B2-4B00-8A11-548224676FE1}C:\users\marcel\appdata\local\akamai\netsession_win.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5001F90A-FBF3-46EF-ABA7-42F5635157B0}C:\users\marcel\appdata\local\akamai\netsession_win.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1C42FDDF-DB7D-40E5-8A7A-5BA67CF9B772}C:\program files (x86)\skype\phone\skype.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{2DA6CA79-949D-47C9-8F4D-658C9CFD4123}C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{ADF9E8B2-D4DD-4362-806B-853C665702FD}C:\users\marcel\desktop\phoenixminer_5.5c_windows_amd_nvidia (password-phoenix)\phoenixminer.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AC478712-04C4-47A1-BB10-3ABCC1CFF8DD}C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BA552399-773A-4856-87DB-839CCA54B264}C:\users\marcel\downloads\unmineable.miner.1.1.0-beta-mfi\phoenixminer_5.6d_windows\phoenixminer.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{B00142C6-BA19-4727-98CE-A57049D22CB1}C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{28BF4B17-DE0D-4567-98C7-F104C95E8402}C:\users\marcel\appdata\local\temp\7zs4bba\enterprisedu.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5DEB3814-0658-4C84-9289-A6B84B411451}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{26D754B7-6AC5-42BF-93FB-823CB43B4264}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A1C76090-DFEF-4D80-BCFE-2F077D1E82CE}" => removed successfully
EmoptyTemp: => Error: No automatic fix found for this entry.


The system needed a reboot.

==== End of Fixlog 07:03:00 ====

Re: Preventivka

Napsal: 15 pro 2023 09:24
od Rudy
Smazáno, log již vypadá OK.

Re: Preventivka

Napsal: 15 pro 2023 09:26
od Dabol
pozeram ze prikaz na zmazanie Temp bol zle zadany mozem ho zmazat rucne?

Re: Preventivka

Napsal: 15 pro 2023 09:58
od JaRon
vludil sa tam preklep - zopakuj fixlist:

Start

CloseProcesses:
EmptyTemp:

End

Re: Preventivka

Napsal: 15 pro 2023 10:15
od Dabol
Fix result of Farbar Recovery Scan Tool (x64) Version: 13-12-2023
Ran by Marcel (15-12-2023 10:03:59) Run:3
Running from C:\Users\Marcel\Desktop
Loaded Profiles: Marcel
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
EmptyTemp:

End
*****************

Processes closed successfully.

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 2011061427 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 123534237 B
Edge => 0 B
Chrome => 338827532 B
Firefox => 87327045 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 1002838 B
NetworkService => 1004268 B
Marcel => 286883784 B
DefaultAppPool => 286883784 B

RecycleBin => 0 B
EmptyTemp: => 2.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 10:10:00 ====

Re: Preventivka

Napsal: 15 pro 2023 13:46
od Rudy
Pardon, omlouvám se. Vše bylo smazáno. :-)

Re: Preventivka

Napsal: 15 pro 2023 14:48
od Dabol
nevadi, kazdopadne dakujem opat za pomoc.

(prikladam logy ak bude vsetko v poriadku tak mozte zamknut)

Re: Preventivka

Napsal: 15 pro 2023 16:43
od Rudy
Vše v pořádku. :closed: :)