Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vyskakovací okna s reklamou (u hodin)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Sobi
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 13 lis 2009 13:54

Vyskakovací okna s reklamou (u hodin)

#1 Příspěvek od Sobi »

Ahoj,

prosím o pomoc s odstraněním vyskakovací reklamy (u hodin). Už se mi to jednou stalo a bylo to doplňkem v prohlížeči. Díval jsem se tam a žádné rozšíření tam nemám nainstalované. Ukazuje se u toho hlavička edge. Děkuji moc.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-02-2022
Ran by Jirka (administrator) on PV7 (07-02-2022 21:08:29)
Running from C:\Users\Martina\Downloads
Loaded Profiles: Jirka & Martina
Platform: Microsoft Windows 10 Pro Version 20H2 19042.1466 (X64) Language: Čeština (Česko) -> Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Brother\BrUtilities\BrLogRx.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Foxit Software Incorporated -> Foxit Corporation) C:\Users\Martina\AppData\Roaming\Foxit Software\Addon\Foxit Reader\FoxitReaderUpdater.exe
(Foxit Software Incorporated -> Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe
(Google LLC -> Google LLC) C:\Users\Martina\AppData\Local\Google\Update\1.3.36.122\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Users\Martina\AppData\Local\Google\Update\1.3.36.122\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\MartinaClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCopyAccelerator.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe <2>
(Seagull Scientific, Inc -> Seagull Scientific, Inc.) C:\Program Files\Seagull\BarTender Suite\BtSystem.Service.exe
(Seagull Scientific, Inc -> Seagull Scientific, Inc.) C:\Program Files\Seagull\BarTender Suite\Integration.Service.exe
(Seagull Scientific, Inc -> Seagull Scientific, Inc.) C:\Program Files\Seagull\BarTender Suite\Maestro.Service.exe
(Seagull Scientific, Inc -> Seagull Scientific, Inc.) C:\Program Files\Seagull\BarTender Suite\PrintScheduler.Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(VIA Technologies Inc. -> VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
0 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2111.12605.0_x64__8wekyb3d8bbwe\Cortana.exe
0 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2111.12605.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe
0 C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21090.10008.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
0 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21121.256.0_x64__8wekyb3d8bbwe\YourPhone.exe
0 C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.21102.11411.0_x64__8wekyb3d8bbwe\Music.UI.exe
0 C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.21111.10511.0_x64__8wekyb3d8bbwe\Video.UI.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] (Samsung Electronics CO., LTD. -> )
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5694640 2017-03-29] (VIA Technologies Inc. -> VIA)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2892800 2017-03-30] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2017-04-05] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [M17A] => C:\WINDOWS\twain_32\Brimm17a\Common\TwDsUiLaunch.exe [86128 2020-03-27] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM-x32\...\RunOnce: [ccleaner_update_helper] => C:\Program Files\CCleaner\ccleaner_update_helper.exe [674944 2021-12-06] (Piriform Software Ltd -> Piriform)
HKU\S-1-5-21-1002822495-3348159901-391683250-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [29072568 2020-05-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1002822495-3348159901-391683250-1002\...\Run: [Google Update] => C:\Users\Martina\AppData\Local\Google\Update\1.3.36.122\GoogleUpdateCore.exe [223816 2022-01-21] (Google LLC -> Google LLC)
HKU\S-1-5-21-1002822495-3348159901-391683250-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [29072568 2020-05-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1002822495-3348159901-391683250-1002\...\Run: [MicrosoftEdgeAutoLaunch_81CE46FB7677C90EE1BD2516428C28D7] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
HKLM\...\Windows x64\Print Processors\hpcpp101: C:\Windows\System32\spool\prtprocs\x64\hpcpp101.dll [323584 2010-09-23] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Windows x64\Print Processors\up003pp: C:\Windows\System32\spool\prtprocs\x64\up003pp.dll [119296 2015-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\HP Fax Port: C:\WINDOWS\system32\hppfaxprintermon5.dll [27704 2014-04-28] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\WINDOWS\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [File not signed]
HKLM\...\Print\Monitors\pdfcmon: C:\WINDOWS\system32\pdfcmon.dll [120072 2016-07-25] (pdfforge GmbH -> pdfforge GmbH)
HKLM\...\Print\Monitors\up003 Langmon: C:\WINDOWS\system32\up003lm.dll [22528 2014-08-08] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\us008 Langmon: C:\WINDOWS\system32\us008lm.dll [31256 2016-02-15] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\ux003 Langmon: C:\WINDOWS\system32\ux003lm.dll [22528 2015-03-12] (Microsoft Windows Hardware Compatibility Publisher -> )

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {21410683-7FCC-4F51-A332-EAC004C42D86} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2499DEE5-3AC7-47E0-97BC-32BDF54ED96C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {32C42439-E79C-4CB7-BC9A-CF74D9EF6085} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3548AD86-52C4-4A22-BAD1-D809FA2AEA0F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002UA => C:\Users\Martina\AppData\Local\Google\Update\GoogleUpdate.exe [156456 2019-04-04] (Google Inc -> Google LLC)
Task: {5625D46A-16EA-40AF-BC0E-6E9F47F498E4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {70CA50F5-7F8A-4965-96CA-B3EF0E87B0E0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-17] (Adobe Inc. -> Adobe Inc.)
Task: {7E896DDD-5E4A-4A13-A560-5D80ECB52D1A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002Core => C:\Users\Martina\AppData\Local\Google\Update\GoogleUpdate.exe [156456 2019-04-04] (Google Inc -> Google LLC)
Task: {7EDD8168-CA28-4DD8-81B1-9C91F3AD0EF8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24690360 2020-05-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {8AECEB1E-C008-4489-8BEF-C71E9E86767B} - System32\Tasks\Microsoft\Martina\Martina ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\MartinaC2RClient.exe [22880112 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {9BC2CC86-9DC3-4B80-817F-458483CF7862} - System32\Tasks\Microsoft\Martina\Martina Feature Updates Logon => C:\Program Files (x86)\Microsoft Martina\root\Martina16\sdxhelper.exe [108904 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {A639073E-0BF4-4E8A-A9E2-CD2A05479FCD} - System32\Tasks\AdwCleaner_onReboot => C:\Users\Martina\Downloads\adwcleaner_8.0.5.exe [8402608 2020-06-01] (Malwarebytes Inc -> Malwarebytes)
Task: {AC3D5055-E7D8-49FD-BEF5-93B94411ABBC} - System32\Tasks\Microsoft\Martina\Martina Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\MartinaC2RClient.exe [22880112 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {CEA409DE-8AD3-46A6-9D81-BBE033390E04} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-05-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E023AE7E-2733-498A-88BE-364538B76658} - System32\Tasks\Microsoft\Martina\Martina Feature Updates => C:\Program Files (x86)\Microsoft Martina\root\Martina16\sdxhelper.exe [108904 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{c4ba4df9-8063-4670-97e7-890e6129ae4f}: [NameServer] 8.8.8.8,10.0.0.1

Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]

FireFox:
========
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-29] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-29] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Martina\root\Martina16\NPSPWRAP.DLL [2021-11-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-12-24] (Adobe Inc. -> Adobe Systems Inc.)

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-17] (Adobe Inc. -> Adobe Inc.)
R2 BarTender Integration Service; C:\Program Files\Seagull\BarTender Suite\Integration.Service.exe [35088 2017-09-12] (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
R2 BarTender Print Scheduler; C:\Program Files\Seagull\BarTender Suite\PrintScheduler.Service.exe [32016 2017-09-12] (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
R2 BarTender System Service; C:\Program Files\Seagull\BarTender Suite\BtSystem.Service.exe [43280 2017-09-12] (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [298496 2017-03-22] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\MartinaClickToRun.exe [12124536 2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
R2 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659456 2018-04-17] (Foxit Software Incorporated -> Foxit Software Inc.)
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [File not signed]
R2 Maestro; C:\Program Files\Seagull\BarTender Suite\Maestro.Service.exe [239376 2017-09-12] (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6137040 2022-01-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13036464 2022-01-24] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies Inc. -> VIA Technologies, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe [2876152 2021-12-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe [128360 2021-12-16] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2021-12-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435432 2021-12-16] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86248 2021-12-16] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-02-07 21:08 - 2022-02-07 21:09 - 000018344 _____ C:\Users\Martina\Downloads\FRST.txt
2022-02-07 21:07 - 2022-02-07 21:07 - 002311680 _____ (Farbar) C:\Users\Martina\Downloads\FRST64.exe
2022-02-07 14:11 - 2022-02-07 14:20 - 000013283 ____C C:\Users\Martina\Desktop\Dodavatelský ceník NOVÁK.xlsx
2022-02-06 21:22 - 2022-02-06 21:22 - 008540344 _____ (Malwarebytes) C:\Users\Martina\Downloads\adwcleaner_8.3.1.exe
2022-02-01 15:05 - 2022-02-01 15:05 - 000053684 ____C C:\Users\Martina\Documents\PV OBV_21_2022_45.PDF
2022-02-01 15:03 - 2022-02-01 15:03 - 000053187 ____C C:\Users\Martina\Documents\PV OBV_21_2022_44.PDF
2022-02-01 14:59 - 2022-02-01 14:59 - 000052164 ____C C:\Users\Martina\Documents\PV OBV_11_2022_92.PDF
2022-02-01 12:26 - 2022-02-01 12:26 - 000059530 ____C C:\Users\Martina\Documents\PV OBV_11_2022_89.PDF
2022-01-31 09:49 - 2022-01-31 09:49 - 000061062 ____C C:\Users\Martina\Documents\PV OBV_11_2021_56.PDF
2022-01-31 07:58 - 2022-01-31 07:58 - 000053416 ____C C:\Users\Martina\Documents\PV OBV_11_2022_84.PDF
2022-01-28 15:08 - 2022-01-28 15:08 - 000052965 ____C C:\Users\Martina\Documents\PV OBV_21_2022_42.PDF
2022-01-28 13:03 - 2022-01-28 13:03 - 000054657 ____C C:\Users\Martina\Documents\PV OBV_21_2022_41.PDF
2022-01-28 08:05 - 2022-01-28 08:05 - 000060548 ____C C:\Users\Martina\Documents\PV OBV_11_2022_81.PDF
2022-01-27 12:51 - 2022-01-27 12:51 - 000054079 ____C C:\Users\Martina\Documents\PV OBV_21_2022_39.PDF
2022-01-27 10:46 - 2022-01-27 10:46 - 000060557 ____C C:\Users\Martina\Documents\PV OBV_11_2022_79.PDF
2022-01-27 10:20 - 2022-01-27 10:20 - 000053164 ____C C:\Users\Martina\Documents\PV OBV_21_2022_33.PDF
2022-01-26 11:51 - 2022-01-26 11:51 - 000061691 ____C C:\Users\Martina\Documents\PV OBV_11_2022_72.PDF
2022-01-26 11:25 - 2022-01-26 11:25 - 000067329 ____C C:\Users\Martina\Documents\PV OBV_21_2022_36.PDF
2022-01-26 11:20 - 2022-01-26 11:20 - 000053796 ____C C:\Users\Martina\Documents\PV OBV_11_2022_76.PDF
2022-01-26 11:05 - 2022-01-26 11:05 - 000049135 ____C C:\Users\Martina\Documents\PV OBV_11_2022_75.PDF
2022-01-26 11:03 - 2022-01-26 11:03 - 000058855 ____C C:\Users\Martina\Documents\PV OBV_11_2022_74.PDF
2022-01-26 10:57 - 2022-01-26 10:57 - 000052661 ____C C:\Users\Martina\Documents\PV OBV_11_2022_73.PDF
2022-01-26 10:36 - 2022-01-26 10:36 - 000054037 ____C C:\Users\Martina\Documents\PV OBV_11_2022_71.PDF
2022-01-26 10:32 - 2022-01-26 10:32 - 000054044 ____C C:\Users\Martina\Documents\PV OBV_11_2022_70.PDF
2022-01-26 10:08 - 2022-01-26 10:08 - 000053164 ____C C:\Users\Martina\Documents\PV OBV_11_2022_69.PDF
2022-01-25 15:12 - 2022-01-25 15:12 - 000054168 ____C C:\Users\Martina\Documents\PV OBV_21_2022_32.PDF
2022-01-25 14:12 - 2022-01-25 14:12 - 000070463 ____C C:\Users\Martina\Documents\PV OBV_21_2022_31.PDF
2022-01-25 14:05 - 2022-01-25 14:05 - 000060776 ____C C:\Users\Martina\Documents\PV OBV_11_2022_67.PDF
2022-01-25 12:48 - 2022-01-25 12:48 - 000069785 ____C C:\Users\Martina\Documents\PV OBV_21_2022_30.PDF
2022-01-25 07:26 - 2022-01-25 07:26 - 000059731 ____C C:\Users\Martina\Documents\PV OBV_21_2022_28.PDF
2022-01-20 15:02 - 2022-01-20 15:02 - 000052131 ____C C:\Users\Martina\Documents\PV OBV_11_2022_47.PDF
2022-01-20 14:58 - 2022-01-20 14:58 - 000073332 ____C C:\Users\Martina\Documents\PV OBV_21_2022_21.PDF
2022-01-14 07:37 - 2022-01-14 07:37 - 000523776 _____ (curl, hxxps://curl.se/) C:\WINDOWS\system32\curl.exe
2022-01-14 07:37 - 2022-01-14 07:37 - 000464384 _____ (curl, hxxps://curl.se/) C:\WINDOWS\SysWOW64\curl.exe
2022-01-14 07:37 - 2022-01-14 07:37 - 000011797 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-01-14 07:26 - 2022-01-14 07:26 - 000000000 ___HD C:\$WinREAgent
2022-01-11 11:11 - 2022-01-11 11:11 - 000014701 _____ C:\Users\Martina\Desktop\seznam zboží pro SK.xlsx

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-02-07 21:08 - 2020-06-01 09:52 - 000000000 ____D C:\FRST
2022-02-07 21:08 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2022-02-07 21:01 - 2021-03-22 16:16 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-02-07 21:01 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-02-07 15:34 - 2016-07-26 10:28 - 000000000 ___DC C:\Users\Martina\Documents\Soubory aplikace Outlook
2022-02-07 15:33 - 2017-12-20 07:05 - 000000000 ___DC C:\Users\Martina\AppData\Local\Packages
2022-02-07 02:25 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-02-06 00:59 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-02-05 13:51 - 2020-07-21 05:58 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-02-05 13:51 - 2020-07-21 05:58 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2022-02-04 09:25 - 2016-07-26 11:24 - 000000034 ____H C:\WINDOWS\sys6153
2022-02-04 09:25 - 2016-07-26 11:24 - 000000034 ____H C:\WINDOWS\stmp2025
2022-02-04 09:25 - 2016-07-26 11:24 - 000000034 ____H C:\WINDOWS\kds1005
2022-02-04 09:25 - 2016-07-26 11:24 - 000000034 ____H C:\WINDOWS\drvr491
2022-02-04 06:53 - 2016-07-25 22:59 - 000000000 ___RD C:\Users\Martina\OneDrive
2022-02-04 06:52 - 2017-06-21 15:57 - 000000000 ____D C:\Program Files (x86)\Microsoft Martina
2022-01-31 14:15 - 2021-07-01 10:46 - 000012677 _____ C:\Users\Martina\Desktop\sum.xlsx
2022-01-27 13:18 - 2021-12-22 12:30 - 000000000 ___DC C:\Users\Martina\Desktop\moje eitikety
2022-01-27 11:27 - 2016-07-25 22:48 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2022-01-26 06:44 - 2021-04-13 05:59 - 000003490 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d71f2f4a8c5790
2022-01-26 06:44 - 2021-03-22 16:29 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-01-24 06:57 - 2021-12-13 06:51 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1002822495-3348159901-391683250-1002
2022-01-24 06:57 - 2021-03-22 16:29 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1002822495-3348159901-391683250-1002
2022-01-24 06:57 - 2021-03-22 16:18 - 000002380 ____C C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-01-21 11:58 - 2021-03-22 16:29 - 000003736 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002UA
2022-01-21 11:58 - 2021-03-22 16:29 - 000003468 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002Core
2022-01-20 15:32 - 2021-03-22 16:18 - 000000000 ____D C:\Users\Martina
2022-01-20 12:26 - 2021-03-22 16:23 - 001606012 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-01-20 12:26 - 2019-12-07 15:43 - 000682184 _____ C:\WINDOWS\system32\perfh005.dat
2022-01-20 12:26 - 2019-12-07 15:43 - 000137000 _____ C:\WINDOWS\system32\perfc005.dat
2022-01-20 12:22 - 2021-03-22 16:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-01-20 12:22 - 2021-03-22 16:16 - 000008192 ___SH C:\DumpStack.log.tmp
2022-01-20 06:58 - 2019-04-04 08:31 - 000002503 ____C C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-01-20 06:58 - 2019-04-04 08:31 - 000002466 ____C C:\Users\Martina\Desktop\Google Chrome.lnk
2022-01-14 15:34 - 2019-12-07 10:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2022-01-14 15:33 - 2021-03-22 16:16 - 000326880 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-01-14 15:32 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-01-14 15:32 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2022-01-14 15:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-01-14 15:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-01-14 15:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2022-01-14 15:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-01-14 15:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-01-14 15:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-01-14 14:43 - 2021-12-07 14:59 - 000010454 _____ C:\Users\Martina\Desktop\Sum nová.xlsx
2022-01-14 07:40 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-01-14 07:26 - 2016-07-26 11:06 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-01-14 07:21 - 2016-07-26 11:06 - 145765912 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-01-13 07:03 - 2021-03-22 16:29 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-01-13 07:03 - 2016-10-18 14:54 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2022-01-11 14:39 - 2020-08-25 07:58 - 000014043 ____C C:\Users\Martina\Desktop\kontejner v USD.xlsx

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-02-2022
Ran by Jirka (07-02-2022 21:11:31)
Running from C:\Users\Martina\Downloads
Microsoft Windows 10 Pro Version 20H2 19042.1466 (X64) (2021-03-22 15:29:42)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

$BarTender_Security$ (S-1-5-21-1002822495-3348159901-391683250-1008 - Limited - Enabled)
$Printer_Maestro$ (S-1-5-21-1002822495-3348159901-391683250-1013 - Limited - Enabled)
Administrator (S-1-5-21-1002822495-3348159901-391683250-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1002822495-3348159901-391683250-503 - Limited - Disabled)
Guest (S-1-5-21-1002822495-3348159901-391683250-501 - Limited - Disabled)
Martina (S-1-5-21-1002822495-3348159901-391683250-1002 - Limited - Enabled) => C:\Users\Martina
Jirka (S-1-5-21-1002822495-3348159901-391683250-1001 - Administrator - Enabled) => C:\Users\Jirka
WDAGUtilityAccount (S-1-5-21-1002822495-3348159901-391683250-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (HKLM\...\{C788B026-20BD-4E96-B698-533F1D6C5013}) (Version: 7.2.4 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 21.011.20039 - Adobe Systems Incorporated)
AppLogLibSetup (HKLM-x32\...\{52FB0C8F-DF05-4C61-AEB6-18C55F8C385F}) (Version: 1.0.3.0 - Brother Industries Ltd.) Hidden
BarTender 2016 R5 (HKLM\...\{6D7A7476-9B22-4531-923C-A74AFCD8E7BF}) (Version: 11.0.3132 - Seagull Scientific) Hidden
BarTender 2016 R5 (HKLM\...\BarTender Suite) (Version: 11.0.3132 - Seagull Scientific)
BrLauncher (HKLM-x32\...\{42D26B47-887C-45FC-BCAE-0BE485C5C0BB}) (Version: 2.0.11.0 - Brother Industries Ltd.) Hidden
BrLogRx (HKLM-x32\...\{190861E7-09C5-42D8-BB4B-0AFB234BCFC1}) (Version: 1.0.3.1 - Brother Industries Ltd.) Hidden
Brother MFL-Pro Suite MFC-L2700DW series (HKLM-x32\...\{F8ECC2FD-CE2B-4ED4-BDCC-90D0D34206FD}) (Version: 1.0.3.0 - Brother Industries, Ltd.)
Brother Printer Driver (HKLM-x32\...\{EAD4E66C-102F-4ED0-85B5-A1C9037A6E8B}) (Version: 1.7.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (HKLM-x32\...\{CE1E9BB4-0414-4541-A4A9-1578D8E53F21}) (Version: 1.0.24.1 - Brother Industries Ltd.) Hidden
BrSupportTools (HKLM-x32\...\{32F47565-84B1-42CC-B09A-4CDDD9A32F94}) (Version: 1.0.20.0 - Brother Industries Ltd.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.67 - Piriform)
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
ControlCenter4 (HKLM-x32\...\{9091B952-8719-49C3-9CC7-6E20EC61081F}) (Version: 4.6.6.1 - Brother Industries, Ltd.) Hidden
ControlCenter4 CSDK (HKLM-x32\...\{FD8A9511-BFC9-43B5-BB75-9CEC0EA03CF0}) (Version: 4.6.1.1 - Brother Industries, Ltd.) Hidden
D-Link SmartConsole Utility (HKLM-x32\...\{B562C735-BAB2-473D-AF3C-80D1C8284020}) (Version: 2.10.02 - D-Link)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 9.1.0.5096 - Foxit Software Inc.)
Google Chrome (HKU\S-1-5-21-1002822495-3348159901-391683250-1002\...\Google Chrome) (Version: 97.0.4692.99 - Google LLC)
HowToGuide (HKLM-x32\...\{36580EEB-4EDF-4880-BBD4-097E2C645ECD}) (Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
HP LaserJet Professional M1530 MFP Series (HKLM-x32\...\{74280B5D-A0AF-46c5-9C85-D9EA078262F1}) (Version: 15.0.15188.928 - Hewlett-Packard)
HP LJ M1530 MFP Series HP Scan (HKLM-x32\...\{C05002F1-06F8-4A15-B6F8-E4DC655C28AA}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPLaserJetHelp_LearnCenter (HKLM-x32\...\{B2AA0F22-E167-4C4A-BAE2-E0025028E61B}) (Version: 1.02.0000 - Hewlett-Packard)
I.R.I.S. OCR (HKLM-x32\...\{F20A04CF-5BE6-404A-9295-D59046238245}) (Version: 12.3.6.6 - HP)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
IS K2 Local (HKLM-x32\...\{7EBF44D7-094B-4473-A55D-4DEF95E60524}) (Version: 5.22.1.109758 - K2 atmitec s.r.o.)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{88EC8D4A-54AB-4A7F-BDE9-4AD906D9D11F}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 98.0.1108.43 - Microsoft Corporation)
Microsoft Martina 2016 pro podnikatele - cs-cz (HKLM\...\HomeBusinessRetail - cs-cz) (Version: 16.0.14827.20158 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1002822495-3348159901-391683250-1001\...\OneDriveSetup.exe) (Version: 17.3.6998.0830 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1002822495-3348159901-391683250-1002\...\OneDriveSetup.exe) (Version: 22.002.0103.0004 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 x64 ENU (HKLM\...\{8424B163-D1E0-48B7-88A2-C7A61767B3D7}) (Version: 4.0.8482.1 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{29B15818-E79F-4AB0-8938-9410C807AD76}) (Version: 2.84.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.2.0 - Mozilla)
Mozilla Thunderbird 52.2.0 (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 52.2.0 (x86 cs)) (Version: 52.2.0 - Mozilla)
NetworkRepairTool (HKLM-x32\...\{86E68F57-FAFE-4052-BDD4-3B90C38236AE}) (Version: 1.2.16.0 - Brother Industries, Ltd.) Hidden
NirSoft NK2Edit (HKLM-x32\...\NirSoft NK2Edit) (Version: - )
Martina 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.14827.20088 - Microsoft Corporation) Hidden
Martina 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.14827.20088 - Microsoft Corporation) Hidden
Martina 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.14827.20158 - Microsoft Corporation) Hidden
Martina 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.3.2 - pdfforge GmbH)
Pervasive PSQL v11 Client (32-bit) SP3 (HKLM-x32\...\Pervasive PSQL v11 Client (32-bit)) (Version: 11.30.061 - Pervasive Software)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
RemoteSetup (HKLM-x32\...\{FAB8A30A-B074-48F9-9D73-5E9A757403F8}) (Version: 3.10.2.0 - Brother Industries Ltd.) Hidden
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.05.51.00(2014.06.19) - Samsung Electronics Co., Ltd.)
ScannerUtilityInstaller (HKLM-x32\...\{D65C0754-7790-427F-AD73-D7C644260F57}) (Version: 1.19.9.1 - Brother) Hidden
StatusMonitor (HKLM-x32\...\{40578A7A-6E36-457F-A4F0-45BC37EB61FD}) (Version: 1.20.1.0 - Brother Insutries Ltd.) Hidden
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.26.4 - TeamViewer)
Uninstall Samsung Printer Software (HKLM-x32\...\TotalUninstaller) (Version: 4.0.0.13 - Samsung Electronics CO., LTD.)
UsbRepairTool (HKLM-x32\...\{F8762A81-32B5-4144-9F3C-9274F515A651}) (Version: 1.4.0.0 - Brother Industries, Ltd.) Hidden

Packages:
=========
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{041F9391-C79D-44EE-AA4E-AF4E029C4B47}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.112\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{6D264B70-DA18-401D-910C-B202D89670C6}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.32\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{75399D28-E622-4973-8752-BC0F7DC47AF3}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.122\psuser_64.dll (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{85D8EE2F-794F-41F0-BB03-49D56A23BEF4}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.122\psuser_64.dll (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{8B480070-D37D-4090-A063-7A429F849652}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.93\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\localserver32 -> C:\Users\Martina\AppData\Local\Google\Chrome\Application\97.0.4692.99\notification_helper.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{BE5C2E39-090F-46A2-AFAA-47540743B4FE}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.102\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA8FA699-91CD-412F-9D13-9B1222F4370E}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.83\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA919489-0396-4164-A6E7-94CDED45A707}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.52\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{DEDF773D-E27B-485E-8E7D-85C5B0EB5A67}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.72\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.122\psuser_64.dll (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{E9E7529D-7F09-410B-AF2A-CC154473B19C}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.35.452\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2018-04-16] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\Program Files\PDFCreator\PDFCreatorShell.DLL [2016-02-19] (pdfforge GmbH -> pdfforge GmbH)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2018-04-16] (Foxit Software Incorporated -> Foxit Software Inc.)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2019-03-29 12:27 - 2009-02-27 16:38 - 000139264 ____R () [File not signed] C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2021-10-18 08:00 - 2021-10-18 08:00 - 000556544 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Interop.BarTender\3a9d75b0fcd4aff47a4eab00d1055040\Interop.BarTender.ni.dll
2021-10-18 08:00 - 2021-10-18 08:00 - 000310784 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Interop.Dri41e2da2e#\697af87b111803a6e9ba44529207725e\Interop.DriverAutomationLibrary.ni.dll
2021-10-18 08:02 - 2021-10-18 08:02 - 000294912 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Interop.MSClusterLib\06e0066d436f6a367beff54155566aa1\Interop.MSClusterLib.ni.dll
2017-03-29 08:03 - 2005-04-22 12:36 - 000143360 _____ () [File not signed] C:\WINDOWS\system32\BrSNMP64.dll
2016-04-12 09:07 - 2016-04-12 09:07 - 000067584 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Brother\AppLogLib\BrBFLogI.dll
2017-03-22 16:21 - 2017-03-22 16:21 - 000491008 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BrMonitor.dll
2017-03-29 08:04 - 2010-09-29 17:07 - 000180224 ____N (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BroSNMP.dll
2016-10-04 13:25 - 2016-10-04 13:25 - 001708032 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\Brother\BrStMonWRes.dll
2020-06-20 00:37 - 2014-06-16 14:45 - 000137728 ____N (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcAssoc.dll
2017-01-27 14:39 - 2017-01-27 14:39 - 000087552 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcDlgRc.dll
2017-04-05 08:53 - 2017-04-05 08:53 - 000124416 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcFcnv.dll
2017-01-27 14:39 - 2017-01-27 14:39 - 017974784 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcGrImg.dll
2017-01-27 14:33 - 2017-01-27 14:33 - 000090112 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcLCze.dll
2020-06-20 00:37 - 2014-06-16 14:46 - 000078848 ____N (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcSmon.dll
2017-04-05 08:53 - 2017-04-05 08:53 - 000955392 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrImgProc.dll
2017-04-05 08:53 - 2017-04-05 08:53 - 000440832 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\Track.dll
2017-03-29 08:03 - 2016-11-01 10:27 - 000090112 _____ (Brother Industries, Ltd.) [File not signed] C:\WINDOWS\system32\BrNetSti.dll
2017-01-05 17:45 - 2017-01-05 17:45 - 000279040 _____ (Brother Industries,LTD.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrImageConversion.dll
2017-01-05 17:45 - 2017-01-05 17:45 - 000082944 _____ (Brother Industries,LTD.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrImgPdf.dll
2017-01-05 17:44 - 2017-01-05 17:44 - 000109056 _____ (Brother Industries,LTD.) [File not signed] C:\Program Files (x86)\ControlCenter4\brTPGSplash.dll
2009-09-16 17:44 - 2009-09-16 17:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hptcpmib.dll
2009-09-16 17:45 - 2009-09-16 17:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\HpTcpMon.dll
2009-09-16 10:44 - 2009-09-16 10:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hpzjrd01.dll
2009-09-16 17:45 - 2009-09-16 17:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\System32\HPTcpMUI.dll
2022-01-17 07:40 - 2022-01-17 07:40 - 001556480 _____ (Microsoft® Corporation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\System.Data83d0a0fd#\88e4475f04d2e73be5e1cb712505e50c\System.Data.SqlServerCe.ni.dll
2022-01-17 07:31 - 2022-01-17 07:31 - 002274816 _____ (NLog) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\NLog\869f2971c5cb5889aadcee1b1516b243\NLog.ni.dll
2017-09-12 11:19 - 2017-09-12 11:19 - 000827392 _____ (Seagull Scientific, Inc.) [File not signed] [File is in use] C:\Program Files\Seagull\BarTender Suite\DriverInteropLibrary.dll
2022-01-17 07:35 - 2022-01-17 07:35 - 000210944 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.Client\e870832772bbb720348c898449c335ab\BtSystem.Client.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000503808 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.DataAccess\4bc70e35730f93975d75b7ee8da3f6bf\BtSystem.DataAccess.ni.dll
2022-01-17 07:35 - 2022-01-17 07:35 - 000295424 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.Interfaces\b7e4b0c48fc696bc092e1d7cce038387\BtSystem.Interfaces.ni.dll
2021-10-18 07:55 - 2021-10-18 07:55 - 000040960 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.Network\1794dc833e9282522c0433891ccf506d\BtSystem.Network.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 001105920 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.Server\1da94e85a8abeefdd6cd5d2458276c1c\BtSystem.Server.ni.dll
2021-10-18 07:55 - 2021-10-18 07:55 - 000392192 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.Strings\a3e71d7d1b64cbe5afaa2d57f3c8341c\BtSystem.Strings.ni.dll
2022-01-17 07:35 - 2022-01-17 07:35 - 000262656 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.Support\2f38979d17af4a6590f96e5c419f0a0b\BtSystem.Support.ni.dll
2021-10-18 07:55 - 2021-10-18 07:55 - 000623104 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\BtSystem.UI\15425ebf517fdd3445765a5cdfcf6c4b\BtSystem.UI.ni.dll
2021-10-18 08:02 - 2021-10-18 08:02 - 000384512 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DriverInteropLibrary\9287b1c4c49d9d6ae6f63069f2e92196\DriverInteropLibrary.ni.dll
2021-10-18 08:02 - 2021-10-18 08:02 - 000130560 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\EventSystem.Router\057ed32d84d691b6ae8ff47313faa665\EventSystem.Router.ni.dll
2021-10-18 08:02 - 2021-10-18 08:02 - 000126464 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Maestro.Clustering\7da872f816c7ab62270eea96a460b673\Maestro.Clustering.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000116736 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Maestro.Interface\744f857852486568669a135b1bdaa578\Maestro.Interface.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000824832 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Maestro.Library\f0a2026aed1acd4e856fa284ee6f394e\Maestro.Library.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 001742848 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Bar52f6c96c#\2b18f6afa1d4d4edfe401a9ad7261a67\Seagull.BarTender.Print.ni.dll
2022-01-17 07:28 - 2022-01-17 07:28 - 005080064 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Framework\9f845b759f0ca77bdaf53a4f9dedc741\Seagull.Framework.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 003716096 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Integrations\3f1b804d1063973af7f6ef934d783a71\Seagull.Integrations.ni.dll
2021-10-18 08:00 - 2021-10-18 08:00 - 000426496 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Interop\458e68a1b911cab6091cf2350e92bcdf\Seagull.Interop.ni.dll
2022-01-17 07:35 - 2022-01-17 07:35 - 001179136 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Libe73a82db#\46ba9f11b1ebb0e3397c6bac1ca4b3fa\Seagull.Librarian.Core.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000124928 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Performance\df9e672857e85ed16ef13544a69e58c0\Seagull.Performance.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000926208 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Repository\bff8cc93b03cd8d243ea981fdac9691a\Seagull.Repository.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000043008 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser0cdd02dd#\b8404ea012830d69792c64c662335e82\Seagull.Services.Performance.Server.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000074752 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser1943360d#\f63c80e8bd1f526435cafde859adeba0\Seagull.Services.Hosts.Integration.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000131072 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser25568677#\bcf06d45205cecc4aa8d1654c4471a4a\Seagull.Services.StorageSite.Server.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000029696 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser3c1f8901#\5dfa5c7ef71cb5ea4125ceb7841bf433\Seagull.Services.Hosts.StorageSite.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000256000 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser56c8031c#\f834077e0756ca7de7f24fcf7a6820c3\Seagull.Services.Deployment.Server.ni.dll
2022-01-17 07:37 - 2022-01-17 07:37 - 000123392 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser6016f0bf#\e8247afa26f8325f102263ebdba16190\Seagull.Services.Integration.Contracts.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000161792 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser67342d28#\03181485c38fc1815617843ee828efa5\Seagull.Services.PrintScheduler.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000382464 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser68508cfb#\63e0c32066422db908ae8de70d677129\Seagull.Services.Integration.Server.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000061952 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser7500b1f8#\671d6ea957988e799339a3977c7eb4d5\Seagull.Services.Deployment.Contracts.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000203776 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Ser99e01c43#\57dc2a402b2cd30917d0a223831d82d1\Seagull.Services.PrintScheduler.Server.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000090624 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Sera65c0687#\4f62f083f7564264c12dddd42ee53692\Seagull.Services.PrintScheduler.Contracts.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000030720 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Serccbfad00#\425a1ccc653e625d34e3a1e0818f888c\Seagull.Services.StorageSite.Accounts.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000046080 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Serd4a3fad5#\0098f3880b8af2e641711663102a47cf\Seagull.Services.Hosts.PrintScheduler.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000044032 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Seref26334d#\85eba0418dfd92df236b02779b0452da\Seagull.Services.Hosts.Integration.Messaging.ni.dll
2022-01-17 07:39 - 2022-01-17 07:39 - 000035840 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Serf42f3459#\c2668ed54c1498ae9b37c7faa05cac09\Seagull.Services.Performance.Contracts.ni.dll
2022-01-17 07:38 - 2022-01-17 07:38 - 000083456 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Serf533a9b3#\8c32775c2ef122b7123116a01866b9c9\Seagull.Services.StorageSite.Contracts.ni.dll
2022-01-17 07:37 - 2022-01-17 07:37 - 000207872 _____ (Seagull Scientific, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Seagull.Serfcd89b0d#\6ce9c2cd6970275528625f8d47e1565c\Seagull.Services.Integration.Management.ni.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKU\S-1-5-21-1002822495-3348159901-391683250-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Martina\root\VFS\ProgramFilesX64\Microsoft Martina\Martina16\OCHelper.dll [2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-29] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-29] (Oracle America, Inc. -> Oracle Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Martina\root\Martina16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Martina\root\Martina16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Martina\root\Martina16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Martina\root\Martina16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-30 08:24 - 2015-10-30 08:21 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Pervasive Software\PSQL\bin\;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1002822495-3348159901-391683250-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jirka\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-1002822495-3348159901-391683250-1002\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 8.8.8.8 - 10.0.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKU\S-1-5-21-1002822495-3348159901-391683250-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1002822495-3348159901-391683250-1001\...\StartupApproved\Run: => "CCleaner Monitoring"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{1A5325D4-A2C5-40C0-B010-7E3203DB6AFE}] => (Allow) LPort=54925
FirewallRules: [UDP Query User{5469A4B2-875D-41B2-BC9B-EAC82BE07ADD}\\server2012\magis\magic940\mgrntw.exe] => (Block) \\server2012\magis\magic940\mgrntw.exe => No File
FirewallRules: [TCP Query User{5AD272AE-0D9D-489B-BC58-6EDBED2AF571}\\server2012\magis\magic940\mgrntw.exe] => (Block) \\server2012\magis\magic940\mgrntw.exe => No File
FirewallRules: [{142B30A5-DB36-44FD-967F-1A628583AA90}] => (Allow) C:\Program Files\Seagull\BarTender Suite\Maestro.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{8F17B2EA-CC54-4D6A-A723-A4573AA54A34}] => (Allow) C:\Program Files\Seagull\BarTender Suite\Maestro.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{45E7250A-B6A1-48BC-9B93-FF98D744D900}] => (Allow) C:\Program Files\Seagull\BarTender Suite\Maestro.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{86D15ED9-E6DB-43FD-B032-BE67EC456267}] => (Allow) C:\Program Files\Seagull\BarTender Suite\Maestro.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{E3F0D7BA-FC1C-4E0E-9D73-AD321638B379}] => (Allow) C:\Program Files\Seagull\BarTender Suite\SystemDatabaseWizard.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{513D8CC6-69E2-4166-8798-ADC6419E23EE}] => (Allow) C:\Program Files\Seagull\BarTender Suite\SystemDatabaseWizard.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{443FB479-C599-4E52-A584-336840036DAA}] => (Allow) C:\Program Files\Seagull\BarTender Suite\AdminConsole.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{685C91E1-E877-4FE4-96A9-796D265B50B6}] => (Allow) C:\Program Files\Seagull\BarTender Suite\AdminConsole.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{79C01907-DA71-474D-9314-9E5049AF1318}] => (Allow) C:\Program Files\Seagull\BarTender Suite\ReprintConsole.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{831DBE99-60C9-455B-B784-AEE5CB636517}] => (Allow) C:\Program Files\Seagull\BarTender Suite\ReprintConsole.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{C4F76467-C4DA-4E97-A086-A8F5E539D80B}] => (Allow) C:\Program Files\Seagull\BarTender Suite\HistoryExplorer.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{76233B93-70CF-4B6D-B475-E316766835E1}] => (Allow) C:\Program Files\Seagull\BarTender Suite\HistoryExplorer.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{43306B38-6C03-42CF-87E3-5AA638AA792C}] => (Allow) C:\Program Files\Seagull\BarTender Suite\IntegrationBuilder.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{CED55C2F-51B2-48C9-86C4-6FD13AD3EAAE}] => (Allow) C:\Program Files\Seagull\BarTender Suite\IntegrationBuilder.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{CA267912-73EA-47FE-9D8D-3CC07F4CB1C7}] => (Allow) C:\Program Files\Seagull\BarTender Suite\Integration.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{E4AAEDF3-0A64-4FEB-97BC-9471C6A86200}] => (Allow) C:\Program Files\Seagull\BarTender Suite\Integration.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{E4687013-FE9D-4008-83C3-F78623FB7C97}] => (Allow) C:\Program Files\Seagull\BarTender Suite\PrintScheduler.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{D9BA6CCB-4757-4AC6-8907-F82DA5292396}] => (Allow) C:\Program Files\Seagull\BarTender Suite\PrintScheduler.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{79EA2581-0785-436C-B222-241C4366BCA2}] => (Allow) C:\Program Files\Seagull\BarTender Suite\BtSystem.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [{BEF77CD0-8BAB-45D3-8070-E76FD3991F70}] => (Allow) C:\Program Files\Seagull\BarTender Suite\BtSystem.Service.exe (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
FirewallRules: [UDP Query User{C2218C6A-EB3B-4906-AC6A-BD2071EB3AED}C:\program files (x86)\d-link smartconsole utility\d-link smartconsole utility.exe] => (Allow) C:\program files (x86)\d-link smartconsole utility\d-link smartconsole utility.exe (D-Link) [File not signed]
FirewallRules: [TCP Query User{C22FF0C6-10D7-462F-B83D-401A32F49EFF}C:\program files (x86)\d-link smartconsole utility\d-link smartconsole utility.exe] => (Allow) C:\program files (x86)\d-link smartconsole utility\d-link smartconsole utility.exe (D-Link) [File not signed]
FirewallRules: [{650378D2-8DE4-4AF5-9EA0-1D768BC16DF1}] => (Allow) C:\Program Files (x86)\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{0BF4691A-5D0E-4D89-809A-0F40F9AC5A40}] => (Allow) C:\Program Files (x86)\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{7F141C77-E261-4584-A1ED-7D83DF930FBC}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe (Samsung Electronics CO., LTD. -> Scan2PCNotify)
FirewallRules: [{6DA86DC0-53B2-4128-B7E2-2785440F54B8}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe (Samsung Electronics CO., LTD. -> Scan2PCNotify)
FirewallRules: [{5F70089A-FE9F-40E0-9EC6-67A66DD8020B}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe (Samsung Electronics CO., LTD. -> ScanProcess)
FirewallRules: [{84C2DF0D-762B-456C-86C7-444C7B54F175}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe (Samsung Electronics CO., LTD. -> ScanProcess)
FirewallRules: [{8DDC01DE-2200-4E57-819A-09B01EB279A5}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{5125E0E7-5CF9-4460-B471-064988BC5EBE}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{D83465BC-221E-4070-B991-256751F30777}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\uninstall.exe (Samsung Electronics Co., Ltd.) [File not signed]
FirewallRules: [{B1CF1D26-81FB-481F-8A87-4467C2FD0102}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\uninstall.exe (Samsung Electronics Co., Ltd.) [File not signed]
FirewallRules: [{40885082-403A-45F5-8C1E-66DFD508B280}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{45C4CF29-A90F-4392-9823-001A66840C50}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{4E1B79F9-CA1F-45EF-BE8D-062B5BFC36E1}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{B25A1D37-31B6-444C-8088-7011C05B2FB9}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{7F19BAA4-1878-4884-8342-9FF60588AD5A}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{47654B5C-E229-4C78-9EE6-9A27D30022F8}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{8291320A-3B0A-4B78-9543-95536B0ADA8E}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{5D293AFA-1841-445B-A10C-2F457C6BAA54}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{D3249BBD-3717-4917-958B-7B7D906726D7}] => (Allow) C:\Program Files (x86)\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Pervasive Software Inc. -> Pervasive Software Inc.)
FirewallRules: [{9F84196A-0DD4-4FFC-A12A-D5BE065563A3}] => (Allow) C:\Program Files (x86)\Brother\Brmfl14d\FAXRX.EXE (Brother Industries, Ltd.) [File not signed]
FirewallRules: [TCP Query User{BBF3CBC9-3147-4A5A-8E46-0D3B087BFE9F}C:\users\office\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\office\appdata\local\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{F80B6B1E-BEF3-4D51-8877-5BA1BD6C5A2D}C:\users\office\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\office\appdata\local\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{C1C16960-3761-4C73-8D10-AEFA3CB85E26}\\server2012\magis\unipaas19\unirte.exe] => (Block) \\server2012\magis\unipaas19\unirte.exe => No File
FirewallRules: [UDP Query User{A6525E86-7FD0-437A-8651-95A9470B021E}\\server2012\magis\unipaas19\unirte.exe] => (Block) \\server2012\magis\unipaas19\unirte.exe => No File
FirewallRules: [{C0F19DDC-FF1A-4A0F-B347-3346CD3D00E1}] => (Allow) LPort=54925
FirewallRules: [{2AE49BF8-D476-4313-B9DD-46F70FF399F6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A2E70382-8061-4B15-BC98-08B49DE52E36}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A2962E9F-40BB-41A6-B591-B04FA64A1219}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BFD24828-8298-4056-8F2A-799D10D626ED}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2DB43C5E-29C1-43F8-940E-12FC536CB225}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{52F28178-8E62-42A7-9899-024BA79C7E3E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{80AF83F0-60BB-4DFC-A4D2-6344E2B7C8F4}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A778F3FE-2756-4051-A7FE-BA88A354CEF6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7C22C8E0-668D-4F75-B76E-5FD3FEE878D4}] => (Allow) C:\Program Files (x86)\Microsoft Martina\root\Martina16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D1342BF5-4C81-4B4B-818B-5C94F2A82393}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0D2FBB2F-7F5F-4E08-93B7-028CD012D362}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{39CC6C34-51B8-4148-B539-790581750CF9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{AF13DB4D-F7C6-4441-A9E6-B86FA6343824}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{AB33A03F-A086-465A-A0A1-16BE7A086AFF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{37E384B4-AEFC-4916-B02E-2BE346B6AD28}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{6499A5D3-4273-4AED-BC11-3A61B68AECBB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{8EFD21DF-AD56-4DB1-BB01-709FD6C13C6A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{64BC51F7-9E92-43D2-9DF2-19E935AEEB5E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{519DE444-BC6F-4B02-BCDA-6A4457F19935}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B4822DB4-4454-4AE4-B50A-C9A55F2B6507}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{7F211E48-FAE7-4F56-81EC-6831CFD8BC08}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)

==================== Restore Points =========================

ATTENTION: System Restore is disabled (Total:110.72 GB) (Free:4.56 GB) (4%)

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (02/06/2022 09:23:56 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 2988, identifikátor PID ProfSvc: 1232.

Error: (02/06/2022 09:23:56 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 8516, identifikátor PID ProfSvc: 1232.

Error: (02/06/2022 06:27:51 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Data (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (02/05/2022 02:27:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program identity_helper.exe verze 98.0.1108.43 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 2a90

Čas spuštění: 01d81a940c29d695

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files (x86)\Microsoft\Edge\Application\98.0.1108.43\identity_helper.exe

ID hlášení: b973e310-2fa3-45fd-bbf1-bdaa3adc0e3c

Úplný název balíčku s chybou: Microsoft.MicrosoftEdge.Stable_97.0.1072.76_neutral__8wekyb3d8bbwe

ID aplikace relativní podle balíčku s chybou: App

Typ zablokování: Quiesce

Error: (02/01/2022 08:00:08 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Data (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (02/01/2022 07:49:13 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Data (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (02/01/2022 07:29:51 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Data (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (02/01/2022 06:55:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: MartinaC2RClient.exe, verze: 16.0.14729.20254, časové razítko: 0x61dc00d9
Název chybujícího modulu: MartinaC2RClient.exe, verze: 16.0.14729.20254, časové razítko: 0x61dc00d9
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000472073
ID chybujícího procesu: 0x2c84
Čas spuštění chybující aplikace: 0x01d8173038f462da
Cesta k chybující aplikaci: C:\Program Files\Common Files\Microsoft Shared\ClickToRun\MartinaC2RClient.exe
Cesta k chybujícímu modulu: C:\Program Files\Common Files\Microsoft Shared\ClickToRun\MartinaC2RClient.exe
ID zprávy: 5a385692-b1a4-43ac-97e5-f630a2ad52ae
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (02/05/2022 11:50:07 AM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: Při vytváření přihlašovacích údajů TLS Klient se stala závažná chyba. Stav interní chyby je 10013.

Error: (02/04/2022 06:26:02 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: Při vytváření přihlašovacích údajů TLS Klient se stala závažná chyba. Stav interní chyby je 10013.

Error: (02/04/2022 06:52:58 AM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: Při vytváření přihlašovacích údajů TLS Klient se stala závažná chyba. Stav interní chyby je 10013.

Error: (02/02/2022 07:27:42 AM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: Při vytváření přihlašovacích údajů TLS Klient se stala závažná chyba. Stav interní chyby je 10013.

Error: (02/01/2022 03:32:05 PM) (Source: DCOM) (EventID: 10010) (User: Jirka7)
Description: Server Microsoft.MicrosoftMartinaHub_18.2110.13110.0_x64__8wekyb3d8bbwe!Microsoft.MicrosoftMartinaHub.AppXt4mh7c9swwc5cmd5jgmtmwcfmvkddpn1.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (02/01/2022 03:32:05 PM) (Source: DCOM) (EventID: 10010) (User: Jirka7)
Description: Server Microsoft.Wallet_2.4.18324.0_x64__8wekyb3d8bbwe!App.AppXgvxkrr1tm1jwgecmqbxe81yfbwpjdn1h.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (02/01/2022 03:32:05 PM) (Source: DCOM) (EventID: 10010) (User: Jirka7)
Description: Server Microsoft.Windows.Search_1.14.2.19041_neutral_neutral_cw5n1h2txyewy!ShellFeedsUI.AppXfbff151h5bmghg166fvn34ccayg70vts.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/31/2022 03:36:50 PM) (Source: DCOM) (EventID: 10010) (User: Jirka7)
Description: Server microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca se v daném časovém limitu neregistroval u služby DCOM.


Windows Defender:
================
Date: 2022-02-07 08:06:01
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {C240ED32-0AC2-4F7A-9BDC-B099CE31F0BF}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2022-02-06 08:23:07
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {0A73B641-C92D-4903-9F70-C054B1B334A3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2022-02-05 08:23:07
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {E1FCBC3B-FB08-462B-9992-2EF2CC577149}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2022-02-04 08:27:12
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {9CD83367-5437-4F0B-8BD9-9FEB57EBDAD7}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2022-02-03 07:41:09
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {5DF11441-EA73-461F-91D4-8AADE84CA81E}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Event[0]:

Date: 2021-12-22 07:01:13
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.355.600.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.18800.4
Kód chyby: 0x80240009
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0606 08/08/2012
Motherboard: ASUSTeK COMPUTER INC. P8B75-M LX
Processor: Intel(R) Celeron(R) CPU G550 @ 2.60GHz
Percentage of memory in use: 52%
Total physical RAM: 7862.25 MB
Available physical RAM: 3757.68 MB
Total Virtual: 9078.25 MB
Available Virtual: 3887.4 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:110.72 GB) (Free:4.56 GB) NTFS
Drive d: (Data) (Fixed) (Total:232.88 GB) (Free:100.95 GB) NTFS

\\?\Volume{3a94d2cf-4b7a-454c-b68d-8ebd7cfe0571}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.43 GB) NTFS
\\?\Volume{af221d96-e03f-4d66-9a43-244ad03dfdae}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{3a34e5af-e98e-4a88-8135-c9dc2d6d956d}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: B8C2E6AE)

Partition: GPT.

==========================================================
Disk: 1 (Size: 111.8 GB) (Disk ID: 00005456)

Partition: GPT.

==================== End of Addition.txt =======================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119383
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyskakovací okna s reklamou (u hodin)

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sobi
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 13 lis 2009 13:54

Re: Vyskakovací okna s reklamou (u hodin)

#3 Příspěvek od Sobi »

Zdravím, tady je log.

# -------------------------------
# Malwarebytes AdwCleaner 8.3.1.0
# -------------------------------
# Build: 11-18-2021
# Database: 2022-02-03.4 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 02-07-2022
# Duration: 00:00:46
# OS: Windows 10 Pro
# Scanned: 32049
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.


AdwCleaner[S00].txt - [1405 octets] - [01/06/2020 13:28:43]
AdwCleaner[C00].txt - [1595 octets] - [01/06/2020 13:31:25]
AdwCleaner[S01].txt - [1527 octets] - [06/02/2022 21:24:54]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119383
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyskakovací okna s reklamou (u hodin)

#4 Příspěvek od Rudy »

OK. Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
Task: {3548AD86-52C4-4A22-BAD1-D809FA2AEA0F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002UA => C:\Users\Martina\AppData\Local\Google\Update\GoogleUpdate.exe [156456 2019-04-04] (Google Inc -> Google LLC)
Task: {7E896DDD-5E4A-4A13-A560-5D80ECB52D1A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002Core => C:\Users\Martina\AppData\Local\Google\Update\GoogleUpdate.exe [156456 2019-04-04] (Google Inc -> Google LLC)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{041F9391-C79D-44EE-AA4E-AF4E029C4B47}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.112\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{6D264B70-DA18-401D-910C-B202D89670C6}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.32\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{8B480070-D37D-4090-A063-7A429F849652}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.93\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{BE5C2E39-090F-46A2-AFAA-47540743B4FE}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.102\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA8FA699-91CD-412F-9D13-9B1222F4370E}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.83\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA919489-0396-4164-A6E7-94CDED45A707}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.52\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{DEDF773D-E27B-485E-8E7D-85C5B0EB5A67}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.72\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{E9E7529D-7F09-410B-AF2A-CC154473B19C}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.35.452\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
FirewallRules: [UDP Query User{5469A4B2-875D-41B2-BC9B-EAC82BE07ADD}\\server2012\magis\magic940\mgrntw.exe] => (Block) \\server2012\magis\magic940\mgrntw.exe => No File
FirewallRules: [TCP Query User{5AD272AE-0D9D-489B-BC58-6EDBED2AF571}\\server2012\magis\magic940\mgrntw.exe] => (Block) \\server2012\magis\magic940\mgrntw.exe => No File
FirewallRules: [TCP Query User{C1C16960-3761-4C73-8D10-AEFA3CB85E26}\\server2012\magis\unipaas19\unirte.exe] => (Block) \\server2012\magis\unipaas19\unirte.exe => No File
FirewallRules: [UDP Query User{A6525E86-7FD0-437A-8651-95A9470B021E}\\server2012\magis\unipaas19\unirte.exe] => (Block) \\server2012\magis\unipaas19\unirte.exe => No File

EmptyTemp:
End
Uložte do C:\Users\Martina\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sobi
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 13 lis 2009 13:54

Re: Vyskakovací okna s reklamou (u hodin)

#5 Příspěvek od Sobi »

Zdravím,

níže posílám log.

Fix result of Farbar Recovery Scan Tool (x64) Version: 05-02-2022
Ran by Jirka (10-02-2022 17:08:04) Run:3
Running from C:\Users\Martina\Downloads
Loaded Profiles: Jirka & Martina
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
Task: {3548AD86-52C4-4A22-BAD1-D809FA2AEA0F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002UA => C:\Users\Martina\AppData\Local\Google\Update\GoogleUpdate.exe [156456 2019-04-04] (Google Inc -> Google LLC)
Task: {7E896DDD-5E4A-4A13-A560-5D80ECB52D1A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002Core => C:\Users\Martina\AppData\Local\Google\Update\GoogleUpdate.exe [156456 2019-04-04] (Google Inc -> Google LLC)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{041F9391-C79D-44EE-AA4E-AF4E029C4B47}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.112\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{6D264B70-DA18-401D-910C-B202D89670C6}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.32\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{8B480070-D37D-4090-A063-7A429F849652}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.93\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{BE5C2E39-090F-46A2-AFAA-47540743B4FE}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.102\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA8FA699-91CD-412F-9D13-9B1222F4370E}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.83\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA919489-0396-4164-A6E7-94CDED45A707}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.52\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{DEDF773D-E27B-485E-8E7D-85C5B0EB5A67}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.36.72\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{E9E7529D-7F09-410B-AF2A-CC154473B19C}\InprocServer32 -> C:\Users\Martina\AppData\Local\Google\Update\1.3.35.452\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
FirewallRules: [UDP Query User{5469A4B2-875D-41B2-BC9B-EAC82BE07ADD}\\server2012\magis\magic940\mgrntw.exe] => (Block) \\server2012\magis\magic940\mgrntw.exe => No File
FirewallRules: [TCP Query User{5AD272AE-0D9D-489B-BC58-6EDBED2AF571}\\server2012\magis\magic940\mgrntw.exe] => (Block) \\server2012\magis\magic940\mgrntw.exe => No File
FirewallRules: [TCP Query User{C1C16960-3761-4C73-8D10-AEFA3CB85E26}\\server2012\magis\unipaas19\unirte.exe] => (Block) \\server2012\magis\unipaas19\unirte.exe => No File
FirewallRules: [UDP Query User{A6525E86-7FD0-437A-8651-95A9470B021E}\\server2012\magis\unipaas19\unirte.exe] => (Block) \\server2012\magis\unipaas19\unirte.exe => No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3548AD86-52C4-4A22-BAD1-D809FA2AEA0F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3548AD86-52C4-4A22-BAD1-D809FA2AEA0F}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002UA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002UA" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7E896DDD-5E4A-4A13-A560-5D80ECB52D1A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E896DDD-5E4A-4A13-A560-5D80ECB52D1A}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002Core => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-1002822495-3348159901-391683250-1002Core" => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{041F9391-C79D-44EE-AA4E-AF4E029C4B47} => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{6D264B70-DA18-401D-910C-B202D89670C6} => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{8B480070-D37D-4090-A063-7A429F849652} => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{BE5C2E39-090F-46A2-AFAA-47540743B4FE} => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA8FA699-91CD-412F-9D13-9B1222F4370E} => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{CA919489-0396-4164-A6E7-94CDED45A707} => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{DEDF773D-E27B-485E-8E7D-85C5B0EB5A67} => removed successfully
HKU\S-1-5-21-1002822495-3348159901-391683250-1002_Classes\CLSID\{E9E7529D-7F09-410B-AF2A-CC154473B19C} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5469A4B2-875D-41B2-BC9B-EAC82BE07ADD}\\server2012\magis\magic940\mgrntw.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5AD272AE-0D9D-489B-BC58-6EDBED2AF571}\\server2012\magis\magic940\mgrntw.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C1C16960-3761-4C73-8D10-AEFA3CB85E26}\\server2012\magis\unipaas19\unirte.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A6525E86-7FD0-437A-8651-95A9470B021E}\\server2012\magis\unipaas19\unirte.exe" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5270801 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 9069815 B
Edge => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 556626 B
Jirka => 30818589 B
Martina => 304018178 B

RecycleBin => 0 B
EmptyTemp: => 334.8 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:08:48 ====

Sobi
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 13 lis 2009 13:54

Re: Vyskakovací okna s reklamou (u hodin)

#6 Příspěvek od Sobi »

Zatím se to tam bohužel pořád zobrazuje. :(

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119383
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyskakovací okna s reklamou (u hodin)

#7 Příspěvek od Rudy »

Jaká je to reklama? Na co, nebo čeho se týká?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sobi
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 13 lis 2009 13:54

Re: Vyskakovací okna s reklamou (u hodin)

#8 Příspěvek od Sobi »

Vypadá to, že je to nějaké rozšíření pod Edgem, ale u edge jsem žádné rozšíření nenašel. Posílám fotku v příloze. Vyskakuje vpravo dole nad hodinami.
Přílohy
reklama.png
reklama.png (89.91 KiB) Zobrazeno 3650 x

Sobi
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 13 lis 2009 13:54

Re: Vyskakovací okna s reklamou (u hodin)

#9 Příspěvek od Sobi »

Už jsem si vzpomněl, jak jsme to vyřešili posledně. Bylo to povolené oznámení webu (ne rozšíření). Našel jsem to a zablokoval. Myslím, že teď už se to zobrazovat nebude. Každopádně děkuji moc za pomoc. :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119383
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyskakovací okna s reklamou (u hodin)

#10 Příspěvek od Rudy »

OK, nemáte zač: Edge žádné rozšíření nemá, jak je patrné z logu a Virus Defender je nějaká haluz, nebo sám vir. Protože něco takového neexistuje. Je je jen Windows Defender. :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno