prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

DeNNI85
Level 4.5
Level 4.5
Příspěvky: 1603
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

prosím o kontrolu logu

Příspěvekod DeNNI85 » 27 čer 2025 16:13

Zdravím, prosím o kontrolu logu. V notebooku nefunguje windows defender, nelze nainstalovat ani Malwarebytes, crashne to v průběhu instalace, bud, že se odpojí wifi a když to dám na lanku, tak to stejně před koncem spadne, nejde spustit ani adw clenaer a to ani v režimu nouzovém. Povedlo se mi oba programy spustit, když jsem nastartoval na ssd disk připojený přes usb s vlastním windows, ale tam to nic nenašlo. Předtím byl defender úplně vypnutý, te´d se tváří, že jede, ale když na něj kliknu a otevřu ho, dám spustit kontrolu, tak se nic neděje, ať vyberu jakoukoliv volbu. Přikládám log hijackthis.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:06:48, on 27.06.2025
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.26100.1882)
Boot mode: Safe mode with network support

Running processes:
C:\Users\David Fišer\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\137.0.3296.93\BHO\ie_to_edge_bho.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [WebPluginService] C:\Program Files (x86)\Web Plugins\WebPluginService.exe
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\David Fišer\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [org.whispersystems.signal-desktop] C:\Users\David Fišer\AppData\Local\Programs\signal-desktop\Signal.exe --start-in-tray
O4 - HKCU\..\Run: [Lunar Client] "C:\Users\David Fišer\AppData\Local\Programs\launcher\Lunar Client.exe" --hidden
O4 - HKCU\..\Run: [LGHUB] "C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe" --minimized
O4 - HKCU\..\Run: [AvastBrowserAutoLaunch_56C04F5BFC81B3E7B3214E575E95B9E6] "C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --check-run=src=logon --auto-launch-at-startup --profile-directory="Default"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIZFE.EXE /EPT "EPLTarget\P0000000000000000" /M "L5310 Series"
O4 - HKCU\..\Run: [MicrosoftEdgeAutoLaunch_53C5182FE6D0D86F1F8FAF352988E06A] "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Poslat do aplikace OneNote.lnk = C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Global Startup: FxSound.lnk = C:\Program Files\FxSound LLC\FxSound\FxSound.exe
O4 - Global Startup: GalaxyBookMask.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll/105
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlansp_c.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted IP range: http://88.101.22.47
O17 - HKLM\System\CCS\Services\Tcpip\..\{d984b644-c05d-485b-adce-97e6272c519c}: NameServer = 1.1.1.1,1.0.0.1
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apache2.2 - Apache Software Foundation - C:\apache\apache\bin\httpd.exe
O23 - Service: Služba Avast Browser Update (avast) (avast) - Gen Digital Inc. - C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
O23 - Service: Služba Avast Browser Update (avastm) (avastm) - Gen Digital Inc. - C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
O23 - Service: Avast Secure Browser Elevation Service (AvastSecureBrowserElevationService) (AvastSecureBrowserElevationService) - Gen Digital Inc. - C:\Program Files\AVAST Software\Browser\Application\137.0.30674.104\elevation_service.exe
O23 - Service: Battle.net Update Helper Svc (battlenet_helpersvc) - Blizzard Entertainment - C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e6980897e3126266\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e6980897e3126266\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_319af - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @oem129.inf,%ServiceDisplayName%;Dolby DAX API Service (DolbyDAXAPI) - Dolby Laboratories - C:\WINDOWS\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_fe9531bca29258f3\DAX3API.exe
O23 - Service: EasyAntiCheat - Epic Games, Inc - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: Easy Anti-Cheat (Epic Online Services) (EasyAntiCheat_EOS) - Epic Games, Inc. - C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Epson Printer Driver Security Support Tool (EpSecuritySupport) - Seiko Epson Corporation - C:\Program Files (x86)\Epson\Epson Printer Driver Security Support Tool\EpSecuritySupport.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\WINDOWS\system32\EscSvc64.exe (file missing)
O23 - Service: @oem63.inf,%ServiceDisplayName%;Intel(R) Dynamic Tuning service (esifsvc) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_82b77f8c4618e2d0\esif_uf.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Fortemedia APO Control Service (FMAPOService) - Unknown owner - C:\WINDOWS\System32\FMService64.exe (file missing)
O23 - Service: NVIDIA FrameView SDK service (FvSvc) - NVIDIA - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
O23 - Service: @%systemroot%\system32\GameInputSvc.exe,-101 (GameInputSvc) - Unknown owner - C:\WINDOWS\System32\GameInputSvc.exe (file missing)
O23 - Service: Interní aktualizační služba Google (GoogleUpdaterInternalService138.0.7194.0) (GoogleUpdaterInternalService138.0.7194.0) - Google LLC - C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe
O23 - Service: Aktualizační služba Google (GoogleUpdaterService138.0.7194.0) (GoogleUpdaterService138.0.7194.0) - Google LLC - C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Print Scan Doctor Service (HPPrintScanDoctorService) - HP Inc. - C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
O23 - Service: Intel(R) Graphics Command Center Service (igccservice) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_9cf4db1a1fd1b22d\OneApp.IGCC.WinService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_7208949846a9b9dc\igfxCUIService.exe
O23 - Service: @oem4.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @oem28.inf,%SocketHECIServiceName%;Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) - Intel(R) Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe
O23 - Service: @oem28.inf,%TPMProvisioningServiceName%;Intel(R) TPM Provisioning Service (Intel(R) TPM Provisioning Service) - Intel(R) Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe
O23 - Service: Intel(R) Audio Service (IntelAudioService) - Unknown owner - C:\WINDOWS\system32\cAVS\IAS\IntelAudioService.exe (file missing)
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @oem69.inf,%ServiceName%;Lenovo Fn and function keys service (LenovoFnAndFunctionKeys) - Lenovo - C:\WINDOWS\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe
O23 - Service: LenovoVantageService - Lenovo Group Ltd. - C:\Program Files (x86)\Lenovo\VantageService\LenovoVantageService.exe
O23 - Service: LGHUB Updater Service (LGHUBUpdaterService) - Logitech, Inc. - C:\Program Files\LGHUB\lghub_updater.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
O23 - Service: @%SystemRoot%\System32\localkdcsvc.dll,-1 (LocalKdc) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: MBVpnTunnelService - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MySQL - Unknown owner - C:\apache\mysql\bin\mysqld.exe
O23 - Service: Wondershare Native Push Service (NativePushService) - Wondershare - C:\Users\David Fišer\AppData\Local\Wondershare\Wondershare NativePush\WsNativePushService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NordSec Update Service (NordUpdaterService) - nordvpn S.A. - C:\Program Files\NordUpdater\NordUpdateService.exe
O23 - Service: nordvpn-service - TEFINCOM S.A. - C:\Program Files\NordVPN\nordvpn-service.exe
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\nvltsi.inf_amd64_e5986ec7298387cf\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ReFsDedupSvc.exe,-100 (refsdedupsvc) - Unknown owner - C:\WINDOWS\System32\ReFsDedupSvc.exe (file missing)
O23 - Service: Rockstar Game Library Service (Rockstar Service) - Rockstar Games - C:\Program Files\Rockstar Games\Launcher\RockstarService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @oem71.inf,%RstMwService.ServiceName%;Intel(R) Storage Middleware Service (RstMwService) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\iaahcic.inf_amd64_c98d5e0dfc88ac2f\RstMwService.exe
O23 - Service: Realtek Audio Universal Service (RtkAudioUniversalService) - Unknown owner - C:\WINDOWS\System32\RtkAudUService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Samsung Printer Dianostics Service - Unknown owner - C:\WINDOWS\system32\\spdsvc.exe
O23 - Service: Samsung Account (SamsungAccountService) - Unknown owner - C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungAccount_1.25.5230.0_x64__3c1yjt4zspk6g\SAService\SAService.exe
O23 - Service: Second Screen (SecondScreenService) - Unknown owner - C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SecondScreen_1.12.3.0_x64__wyx1vj98g3asy\SecondScreenService\SecondScreenService.exe
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Service Client Helper (ServiceClientHelper) - Unknown owner - C:\Users\Public\ClientRuntime\ServiceClientHelper.exe
O23 - Service: Service Client Reporter (ServiceClientReporter) - Unknown owner - C:\Users\Public\ClientRuntime\ServiceReporter.exe
O23 - Service: @firewallapi.dll,-50323 (SNMPTrap) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\steamservice.exe
O23 - Service: System Update (SUService) - Lenovo - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer - TeamViewer Germany GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: UltiDev Web Server Pro - UltiDev LLC - C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe
O23 - Service: UWS HiPriv Services - UltiDev LLC - C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe
O23 - Service: UWS LoPriv Services - UltiDev LLC - C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Služba Správce událostí tiskových úloh Xerox (XeroxPrintJobEventManagerService) - Xerox Corporation - C:\Program Files\Xerox\XeroxPrintExperience\CommonFiles\XeroxPrintJobEventManagerService.exe
O23 - Service: Zakynthos Service (zksvc) - KRAFTON, Inc. - C:\Program Files\Common Files\PUBG\zksvc.exe

--
End of file - 18912 bytes
Intel i3 6320, Gigabyte GA-Z170 Gaming K3, NZXT Kraken X31, 8GB DDR4 Crucial 2666MHz, Eurocase ECO+90 700w, MSI GTX1060 6GB OCV1, 1TB WD raid edition, monitor BenQ 24" FullHD LED

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 27 čer 2025 19:03

http://88.101.22.47
Znáš tu adresu?


Stáhni si Security Check by screen317 z některého odkazu
http://www.bleepingcomputer.com/download/securitycheck/
https://www.bleepingcomputer.com/downlo ... ritycheck/

ulož si ho na plochu, poklepej na něj a postupuj podle instrukcí v černém okně. Potom se automaticky otevře pozn. Blok, bude mít název checkup.txt. Jeho obsah sem prosím zkopíruj.


Vypni antivir i firewall.
Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
další odkaz:
http://www.bleepingcomputer.com/downloa ... scan-tool/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

DeNNI85
Level 4.5
Level 4.5
Příspěvky: 1603
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod DeNNI85 » včera, 10:55

Zdravím, ten první program nejde otevřít po stasžení, píše, že ho nemůže najít, nebo že je špatná přípona a další nesmysly, nevím jestli to taky neblokuje. Log z frst zde:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-06-2025
Ran by David Fišer (30-06-2025 10:46:38)
Running from C:\Users\David Fišer\Desktop
Microsoft Windows 11 Home Version 24H2 26100.4351 (X64) (2025-03-14 02:41:35)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-1473384019-949151177-2148177368-500 - Administrator - Disabled)
David Fišer (S-1-5-21-1473384019-949151177-2148177368-1001 - Administrator - Enabled) => C:\Users\David Fišer
DefaultAccount (S-1-5-21-1473384019-949151177-2148177368-503 - Limited - Disabled)
Guest (S-1-5-21-1473384019-949151177-2148177368-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1473384019-949151177-2148177368-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\uTorrent) (Version: 3.6.0.46884 - BitTorrent Inc.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 25.001.20531 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601110}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Ajax PRO Desktop verze 3.15 (HKLM-x32\...\{A9A003BD-C89D-4C65-95F1-1E26C684ADB0}_is1) (Version: 3.15 - Ajax Systems Inc.)
ASIX UP v.3-51 (HKLM-x32\...\ASIX UP_is1) (Version: - ASIX s.r.o.)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 137.0.30674.104 - Autoři prohlížeče Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1697.6 - AVAST Software) Hidden
AVG Update Helper (HKLM-x32\...\{EDB7AEE7-E932-4836-AE50-D3B0B7766CB5}) (Version: 1.8.1634.4 - AVG Technologies) Hidden
BabyWare v5.4.26 (HKLM\...\BabyWare v5.4.26) (Version: 5.4.26 - Paradox Security Systems)
Balíček ovladače systému Windows - BJJCZ USBDevice (09/04/2012 13.54.20.543) (HKLM\...\FF74BA0BDF257C8984C39DF664ABC53F11782246) (Version: 09/04/2012 13.54.20.543 - BJJCZ)
Balíček ovladače systému Windows - Silicon Laboratories (silabenm) Ports (03/19/2014 6.7.0.0) (HKLM\...\B97004A400E30DCF940971EFA7A0C13C6B0A4B66) (Version: 03/19/2014 6.7.0.0 - Silicon Laboratories)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Brother Printer Setting Tool (HKLM-x32\...\{8DA2E2DC-C572-4F87-89FC-833DB588CC7B}) (Version: 1.6.0081 - Brother Industries, Ltd.)
Brother P-touch Editor 5.4 (HKLM-x32\...\{3D6B8787-51B7-45F3-B730-79875DA88764}) (Version: 5.4.0050 - Brother Industries, Ltd.)
Brother P-touch Update Software (HKLM-x32\...\{66280DDE-C9ED-429C-88BB-F1101546510D}) (Version: 1.0.0210 - Brother Industries, Ltd.)
Brother PT-P700 Series Utility (HKLM-x32\...\{8F7AD37E-A622-468A-9DC5-CDB5A4341535}) (Version: 1.00.7046 - Brother Industries, ltd.) Hidden
CodeBlocks (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\CodeBlocks) (Version: 20.03 - The Code::Blocks Team)
ComLink verze 65 (HKLM-x32\...\{370A6D1F-FAAE-4D8C-A46E-91D972A37F70}_is1) (Version: 65 - Jablotron s.r.o.)
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
CurseForge (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj) (Version: 1.267.3.1695 - Overwolf app)
Discord (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\Discord) (Version: 1.0.9007 - Discord Inc.)
DZSALauncher version 0.0.5.7 (HKLM-x32\...\DZSALauncher_is1) (Version: 0.0.5.7 - Maca134)
Eclipse Temurin JDK with Hotspot 17.0.11+9 (x64) (HKLM\...\{73EBB86B-2304-42E7-8018-2C473DB207B7}) (Version: 17.0.11.9 - Eclipse Adoptium)
EL-Revize - Demoverze 18.4.6 (x86-64bit) (HKLM\...\ELMER-REVIZE-DEMO) (Version: 18.4.6 - ELMER software s.r.o.)
Epic Games Launcher (HKLM-x32\...\{209F4B4B-3DF2-4825-9906-D4D6A80EC09E}) (Version: 1.3.0.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epson Event Manager (HKLM-x32\...\{A3BFF401-11D7-4EAF-805C-118B4170604F}) (Version: 3.11.82 - Seiko Epson Corporation)
Epson Printer Connection Checker (HKLM-x32\...\{3E43D194-E18D-4C8A-B36D-15F14395A0A6}) (Version: 3.4.1.0 - Seiko Epson Corporation)
Epson Printer Driver Security Support Tool (HKLM-x32\...\{8E84134D-140B-4979-8BC8-016A673EDB1A}) (Version: 1.0.0.0 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version: - Seiko Epson Corporation)
Epson ScanSmart (HKLM-x32\...\{8D3E35BD-10F6-42A9-8F4D-F9BE5F51D477}) (Version: 3.7.17 - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\...\{EEF0814F-F67C-49F6-A705-230209F14DF9}) (Version: 4.6.9 - Seiko Epson Corporation)
FileZilla 3.67.1 (HKLM-x32\...\FileZilla Client) (Version: 3.67.1 - Tim Kosse)
F-Link 2.9.5.1546 (HKLM-x32\...\F-Link 2.9.5.1546_is1) (Version: F-Link 2.9.5.1546 - Jablotron Alarms a.s.)
Free Cam 8 (HKLM-x32\...\{7B1D3F21-3095-4292-877E-69C085253F59}) (Version: 8.7.27159 - iSpring Solutions Inc.)
FxSound (HKLM\...\{686221C2-D1C8-4EED-A285-5006FEFCAFF4}) (Version: 1.1.31.0 - FxSound LLC)
GalaxyRS (HKLM-x32\...\{77CC863B-5E65-4FE6-BE1C-987217718CD3}) (Version: 3.54.01 - Honeywell)
Google Earth Pro (HKLM\...\{AE3261A9-F9D9-4410-BB38-7FA1D6B54BDE}) (Version: 7.3.6.10201 - Google)
Intel(R) Chipset Device Software (HKLM\...\{B4BF76D4-C8E0-4341-A8C5-A33D1C506DED}) (Version: 10.1.18263.8193 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{66879245-162d-47f5-bac4-840156a7c01e}) (Version: 10.1.18263.8193 - Intel(R) Corporation)
iVMS-4200 (HKLM-x32\...\{CE2F96D0-63D2-4B9C-A8D6-0D1A60840BD8}) (Version: 3.10.0.6 - Hangzhou Hikvision Digital Technology Co., Ltd.)
iVMS-4200 Lite(v1.0.0.4) (HKLM-x32\...\{DB03E757-F619-463F-9370-28D16DB168C2}) (Version: 1.0.0.4 - hikvision)
JA-100-Link 2.6.1.1300 (HKLM-x32\...\JA-100-Link 2.6.1.1300_is1) (Version: JA-100-Link 2.6.1.1300 - Jablotron Alarms a.s.)
Java 8 Update 291 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180291F0}) (Version: 8.0.2910.10 - Oracle Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{88EC8D4A-54AB-4A7F-BDE9-4AD906D9D11F}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Lenovo Now (HKLM-x32\...\{622FA116-13E7-4BB6-839C-A3E0E3ECDFE6}_is1) (Version: 4.2.2.25 - Lenovo)
Lenovo Storage USB Driver 1.0.5 (Build 14) (HKLM-x32\...\{EEA5AC31-A92A-4AB5-A4E0-6B788D90BB8A}) (Version: 1.0.5.14 - Lenovo)
Lenovo System Update (HKLM-x32\...\TVSU_is1) (Version: 5.08.03.59 - Lenovo)
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 3.1.82.0 - Lenovo Group Ltd.)
LightBurn version 1.7.08 (HKLM\...\LightBurn_is1) (Version: 1.7.08 - )
Logitech G HUB (HKLM\...\{521c89be-637f-4274-a840-baaf7460c2b2}) (Version: 2025.1.673329 - Logitech)
Logitech Options (HKLM\...\LogiOptions) (Version: 10.22.14 - Logitech)
Microsoft .NET Host - 8.0.8 (x64) (HKLM\...\{3BA242F8-BDB5-4096-9FBC-333CD663BBAD}) (Version: 64.32.18380 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.8 (x64) (HKLM\...\{7FE24458-0796-4428-99C2-9A0F8DAB93CC}) (Version: 64.32.18380 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.8 (x64) (HKLM\...\{9ACB23DB-4D32-49ED-A5E3-F4E2F8D9D2AA}) (Version: 64.32.18380 - Microsoft Corporation) Hidden
Microsoft 365 - cs-cz (HKLM\...\O365HomePremRetail - cs-cz) (Version: 16.0.18827.20164 - Microsoft Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.18827.20164 - Microsoft Corporation)
Microsoft Access database engine 2010 (English) (HKLM-x32\...\{90140000-00D1-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Access database engine 2016 (English) (HKLM-x32\...\{90160000-00D1-0409-0000-0000000FF1CE}) (Version: 16.0.5044.1000 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 138.0.3351.55 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 137.0.3296.93 - Microsoft Corporation) Hidden
Microsoft Office 2019 pro studenty a domácnosti - cs-cz (HKLM\...\HomeStudent2019Retail - cs-cz) (Version: 16.0.18827.20164 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\OneDriveSetup.exe) (Version: 25.095.0518.0002 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server 2012 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2012) (Version: - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 RsFx Driver (HKLM\...\{A0F05048-7653-4FCD-9F3A-C740E4052ACE}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
Microsoft SQL Server 2012 Setup (English) (HKLM\...\{8CB0713F-CFE0-445D-BCB2-538465860E1A}) (Version: 11.1.3128.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{56F27690-F6EA-3356-980A-02BA379506EE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{1b103cea-f037-4504-81de-956057b442c3}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34433 (HKLM-x32\...\{804e7d66-ccc2-4c12-84ba-476da31d103d}) (Version: 14.42.34433.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34433 (HKLM-x32\...\{e7802eac-3305-4da0-9378-e55d1ed05518}) (Version: 14.42.34433.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34433 (HKLM\...\{E1902FC6-C423-4719-AB8A-AC7B2694B367}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34433 (HKLM\...\{382F1166-A409-4C5B-9B1E-85ED538B8291}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34433 (HKLM-x32\...\{84E3E712-6343-484B-8B6C-9F145F019A70}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34433 (HKLM-x32\...\{C2BB95AA-90F3-4891-81C1-A7E565BB836C}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft VSS Writer for SQL Server 2012 (HKLM\...\{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.8 (x64) (HKLM\...\{663E7053-3B36-4AE5-8223-234867FAEAE6}) (Version: 64.32.18376 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.8 (x64) (HKLM-x32\...\{33832ff3-5583-4b81-b270-d9fd42760e1a}) (Version: 8.0.8.33916 - Microsoft Corporation)
Minecraft Launcher (HKLM-x32\...\{733C3ACB-432D-4880-B0E1-660000D7974D}) (Version: 1.0.0.0 - Mojang)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 139.0.4 (x64 cs)) (Version: 139.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 109.0 - Mozilla)
NordUpdater (HKLM\...\{6E35DB82-3D19-4DD6-B8CB-F082815FDE18}_is1) (Version: 1.4.6.950 - Nord Security)
NordVPN (HKLM\...\{19465C24-3D5D-4327-B99F-3CC0A1D38151}_is1) (Version: 7.3.8.0 - Nord Security)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.6.4 - Notepad++ Team)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.28.0.417 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.28.0.417 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.4.0.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.0.1 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 561.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 561.09 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
Odinstalace tiskárny EPSON L5310 Series (HKLM\...\EPSON L5310 Series) (Version: - Seiko Epson Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.18827.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.18827.20164 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0405-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
OLink 2.0.6.994 (HKLM-x32\...\OLink 2.0.6.994_is1) (Version: OLink 2.0.6 - Jablotron Alarms a.s.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.276.0.6 - Overwolf Ltd.)
Paradox Launcher v2 (HKLM\...\{8C5CF4CE-D589-40B4-A77F-01FD64602C50}) (Version: 2.4.0 - Paradox Interactive)
PDFCreator (HKLM\...\{4EDD2692-1836-4670-A332-C6B76627D5E5}) (Version: 4.3.0 - pdfforge GmbH)
Pomocník s instalací Windows 11 (HKLM-x32\...\{115DF11E-4B4C-4EA9-9A79-00DB0C7EF02D}) (Version: 1.4.19041.5003 - Microsoft Corporation)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.98.2208_S13_R3 - Rockstar Games)
Rockstar Games SDK (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.3.8.0 - Rockstar Games)
Room Arranger (32-bit) (HKLM-x32\...\Room Arranger) (Version: 9.6.0 - Jan Adamec)
Room Arranger (64-bit) (HKLM-x32\...\Room Arranger x64) (Version: 9.6.0 - Jan Adamec)
SADP (HKLM-x32\...\{7D9B79C2-B1B2-433B-844F-F4299B86F26E}) (Version: 3.0.4.5 - Hangzhou Hikvision Digital Technology Co., Ltd.)
Samsung Diagnostika tiskárny Samsung (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.29 - HP Printing Korea Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Samsung Scan Process Machine (HKLM-x32\...\Samsung Scan Process Machine) (Version: 1.03.05.28 - Samsung Electronics Co., Ltd.) Hidden
Samsung SCX-3400 Series (HKLM-x32\...\Samsung SCX-3400 Series) (Version: 1.30.01 (19.06.2019) - Samsung Electronics Co., Ltd.)
SAP Crystal Reports runtime engine for .NET Framework (32-bit) (HKLM-x32\...\{29B54489-4060-4ADC-BEA6-23C72D864628}) (Version: 13.0.29.3671 - SAP)
Signal 7.33.0 (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\7d96caee-06e6-597c-9f2f-c7bb2e0948b4) (Version: 7.33.0 - Signal Messenger, LLC)
SQL Server 2012 Common Files (HKLM\...\{1D411379-9CE0-4B13-A19B-72D3222DD620}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Common Files (HKLM\...\{202AAF1F-69AA-442A-B59F-6B54B1AD07C6}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (HKLM\...\{18B2A97C-92C3-4AC7-BE72-F823E0BC895B}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (HKLM\...\{84FBCA4A-D650-4B0D-8094-EC0671FA9B91}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (HKLM\...\{54FF8FAB-DE27-4187-82F1-EBAE6AEE869A}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (HKLM\...\{6603C2CE-3C54-4F1D-92F9-8390CD4CCCA8}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2012 (HKLM-x32\...\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}) (Version: 11.0.2100.60 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (HKLM\...\{BED1EA3D-592D-4305-9D1F-20F03726EFC1}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TAS (HKLM-x32\...\TAS) (Version: - )
TeamViewer (HKLM\...\TeamViewer) (Version: 15.57.3 - TeamViewer)
Thunderstore Mod Manager (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\Overwolf_ahpflogoookodlegojjphcjpjaejgghjnfcdjdmi) (Version: 1.69.0 - Overwolf app)
TLauncher (HKLM-x32\...\TLauncher) (Version: 2.885 - TLauncher Inc.)
UltiDev Web Server Pro (HKLM-x32\...\{7CEE3E87-E1E6-4D6F-9892-1ADD67E87D74}) (Version: 2.0.20 - UltiDev LLC) Hidden
Uninstall Lunar Client (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\1fcec38f-e773-5444-8669-32b8eb41524b) (Version: 3.2.17-ow - Moonsworth LLC)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN)
Web Components (HKLM-x32\...\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1) (Version: 3.0.7.51 - )
Web Plugins (HKLM-x32\...\{B5702B61-F1CB-4605-8BC2-979ACBD9FA43}_is1) (Version: 4.0.2403.7 - )
Windows Driver Package - ASIX s.r.o. ASIX Development Tools Driver Package (08/16/2017 2.12.28.1) (HKLM\...\29D0F01874B2462A07E8F95AC5AE9CFCCA76B11D) (Version: 08/16/2017 2.12.28.1 - ASIX s.r.o.)
Windows Driver Package - ASIX s.r.o. ASIX Development Tools Driver Package (08/16/2017 2.12.28.1) (HKLM\...\D9FA9C6FF8DCB877499DC8C34660BE7D38A3831A) (Version: 08/16/2017 2.12.28.1 - ASIX s.r.o.)
WinLoad 5.71 (HKLM-x32\...\WinLoad 5.71_is1) (Version: - Paradox Security Systems)
WinRAR 6.02 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.02.0 - win.rar GmbH)
Wondershare Filmora 13(Build 13.3.8.7085) (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\Wondershare Filmora 13_is1) (Version: - Wondershare Software)
Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare)
Wondershare NativePush(Build 1.0.1.1) (HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\Wondershare NativePush_is1) (Version: - Wondershare Software)
Xerox Desktop Print Experience 8.5 (HKLM\...\{16B4CC67-50F6-DD5B-CEF3-E2F2EF460494}) (Version: 8.158.0.0 - Xerox Corporation)
X-Rite Color Assistant 2.12.0.0 (HKLM-x32\...\{6DCFB107-4604-4AA8-BEA6-CC80BCF0B3E4}_is1) (Version: 2.12.0.0 - X-Rite, Inc)

Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-17] ()
@{MicrosoftWindows.Client.CoreAI_1000.26100.4061.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CoreAI/AIXHost/ClickToDo/AppDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-06-17] (Microsoft Windows)
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2025-06-12] ()
Akce kliknutím (náhled) -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-06-17] (Microsoft Windows)
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-01-11] (INTEL CORP) [Startup Task]
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.54792954.Filons_cw5n1h2txyewy [2025-06-17] (Microsoft Windows)
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.56978801.Voiess_cw5n1h2txyewy [2025-06-17] (Microsoft Windows)
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57058570.Speion_cw5n1h2txyewy [2025-06-17] (Microsoft Windows)
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57074914.Livtop_cw5n1h2txyewy [2025-06-17] (Microsoft Windows)
Dolby Audio -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAudio_3.20602.609.0_x64__rz1tebttyb220 [2020-08-28] (Dolby Laboratories)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-10-07] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_159.2.1145.0_x64__v10z8vjag6ke6 [2025-06-04] (HP Inc.)
Lenovo Companion -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2501.20.0_x64__k1h2ywk1493x8 [2025-01-25] (LENOVO INC.)
Lenovo Hotkeys -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_4.7.18.0_x64__5grkq8ppsgwt4 [2025-05-16] (LENOVO INC) [Startup Task]
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2505.23002.0_x64__8wekyb3d8bbwe [2025-06-10] (Microsoft Corporation) [Startup Task]
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2023-09-18] (Microsoft Corp.)
Microsoft.Edge.GameAssist -> C:\Program Files\WindowsApps\Microsoft.Edge.GameAssist_1.0.3336.0_x64__8wekyb3d8bbwe [2025-06-05] (Microsoft Corporation)
Microsoft.StartExperiencesApp -> C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.51.3.0_x64__8wekyb3d8bbwe [2025-06-27] (Microsoft Corporation)
Notepad++ -> C:\Program Files\Notepad++\contextMenu [2024-05-01] (Notepad++)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.968.0_x64__56jybvy8sckqj [2025-06-18] (NVIDIA Corp.)
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2025-06-25] ()
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.12.219.0_x64__dt26b99r8h8gj [2021-05-14] (Realtek Semiconductor Corp)
Samsung Account -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungAccount_1.25.5230.0_x64__3c1yjt4zspk6g [2025-06-04] (Samsung Electronics Co. Ltd.)
Samsung Notes -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungNotes_4.3.418.0_x64__wyx1vj98g3asy [2025-05-14] (Samsung Electronics Co, Ltd.) [Startup Task]
Samsung Printer Experience -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungPrinterExperience_1.3.15.0_x64__3c1yjt4zspk6g [2022-11-17] (Samsung Electronics Co. Ltd.)
Second Screen -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SecondScreen_1.12.3.0_x64__wyx1vj98g3asy [2025-05-24] (Samsung Electronics Co, Ltd.)
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.150.3125.0_x64__kzf8qxf38zg5c [2025-05-09] (Skype)
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0 [2025-06-27] (Spotify AB) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2524.4.0_x64__cv1g1gvanyjgm [2025-06-20] (WhatsApp Inc.) [Startup Task]
WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-20] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_7000.522.1444.0_x64__8wekyb3d8bbwe [2025-06-25] (Microsoft Corp.)
Xerox Print and Scan Experience -> C:\Program Files\WindowsApps\XeroxCorp.PrintExperience_9.70.10.0_x64__f7egpvdyrs2a8 [2025-06-06] (Xerox Corp)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1473384019-949151177-2148177368-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1473384019-949151177-2148177368-1001_Classes\CLSID\{14100442-9664-1407-2647-000000000000}\localserver32 -> C:\Users\David Fišer\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe (Wondershare Technology Group Co.,Ltd -> Wondershare)
CustomCLSID: HKU\S-1-5-21-1473384019-949151177-2148177368-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1473384019-949151177-2148177368-1001_Classes\CLSID\{4566AA0B-8606-467C-AE12-0C3B00F4B761} -> [Galaxy S24 Ultra] => C:\Users\David Fišer\CrossDevice\Galaxy S24 Ultra [2025-05-10 10:41]
CustomCLSID: HKU\S-1-5-21-1473384019-949151177-2148177368-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\David Fišer\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20031.2\x64\Microsoft.Teams.AddinLoader.dll => No File
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\Program Files\PDFCreator\PDFCreatorShell.DLL [2020-11-12] (pdfforge GmbH -> pdfforge GmbH)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvltsi.inf_amd64_e5986ec7298387cf\nvshext.dll [2024-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\David Fišer\Desktop\Dochazka3000.lnk -> hxxp://127.0.0.1/dochazka2001

==================== Loaded Modules (Whitelisted) =============

2025-03-14 04:38 - 2025-03-14 04:38 - 000010752 _____ () [File not signed] [File is in use] C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Temporary ASP.NET Files\root\07504d0b\fa6973ba\App_Web_5vqmtyfs.dll
2025-03-14 04:38 - 2025-03-14 04:38 - 000049152 _____ () [File not signed] [File is in use] C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Temporary ASP.NET Files\root\07504d0b\fa6973ba\App_Web_hasyflxy.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 002354688 _____ () [File not signed] C:\Program Files (x86)\Web Plugins\AudioIntercom.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 000666112 _____ () [File not signed] C:\Program Files (x86)\Web Plugins\AudioProcess.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 000151552 _____ () [File not signed] C:\Program Files (x86)\Web Plugins\AudioRender.dll
2025-01-28 17:23 - 2024-09-06 12:04 - 000610304 _____ () [File not signed] C:\Program Files (x86)\Web Plugins\NetStream.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 000375808 _____ () [File not signed] C:\Program Files (x86)\Web Plugins\OpenAL32.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 006939136 _____ () [File not signed] C:\Program Files (x86)\Web Plugins\PlayCtrl.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 000722432 _____ () [File not signed] C:\Program Files (x86)\Web Plugins\StreamTransClient.dll
2024-08-11 11:45 - 2009-08-06 00:00 - 000147534 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\bin\libapr-1.dll
2024-08-11 11:45 - 2009-08-06 00:00 - 000036953 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\bin\libapriconv-1.dll
2024-08-11 11:45 - 2009-08-06 00:00 - 000188503 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\bin\libaprutil-1.dll
2024-08-11 11:45 - 2009-08-06 00:00 - 000274499 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\bin\libhttpd.dll
2024-08-11 11:45 - 2009-08-06 00:00 - 000024662 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_actions.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000024660 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_alias.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000024662 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_asis.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000032859 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_autoindex.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000028757 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_cgi.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000024658 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_dir.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000024659 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_env.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000041046 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_include.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000032855 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_isapi.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000028761 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_log_config.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000028752 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_mime.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000036954 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_negotiation.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000024664 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_setenvif.so
2024-08-11 11:45 - 2009-08-06 00:00 - 000024662 _____ (Apache Software Foundation) [File not signed] C:\apache\apache\modules\mod_userdir.so
2025-01-28 17:23 - 2024-09-06 12:03 - 000182784 _____ (HIKVISION) [File not signed] C:\Program Files (x86)\Web Plugins\slf.dll
2020-08-28 20:07 - 2020-08-28 20:07 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll
2020-08-28 20:07 - 2020-08-28 20:07 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\root\Office16\c2r64.dll
2021-06-21 15:54 - 2021-06-21 15:54 - 000116736 _____ (pdfforge GmbH) [File not signed] C:\WINDOWS\System32\pdfcmon.dll
2023-03-29 15:47 - 2023-03-29 15:47 - 000123904 _____ (Samsung Electronics Co., Ltd.) [File not signed] C:\Program Files (x86)\Samsung\Easy Printer Manager\SmartScreenPrint\CDAKEYMonitor64.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 002425856 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\Web Plugins\libcrypto-1_1.dll
2025-01-28 17:23 - 2024-09-06 12:03 - 000507392 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\Web Plugins\libssl-1_1.dll
2014-01-11 20:16 - 2014-01-11 20:16 - 000019968 _____ (UltiDev LLC) [File not signed] [File is in use] C:\Program Files (x86)\UltiDev\Web Server\UWS.MonitoringCommons.dll
2014-01-11 20:16 - 2014-01-11 20:16 - 000019968 _____ (UltiDev LLC) [File not signed] [File is in use] C:\Program Files\UltiDev\Web Server\UWS.MonitoringCommons.dll
2025-03-14 04:36 - 2025-03-14 04:36 - 000028672 _____ (UltiDev LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\GAC_MSIL\UltiDevCassiniServerConfiguration\2.0.5.1__cc16caed94880aaa\UltiDevCassiniServerConfiguration.dll
2025-03-14 04:36 - 2025-03-14 04:36 - 000141824 _____ (UltiDev LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\GAC_MSIL\UWS.Configuration\1.0.0.20__cc16caed94880aaa\UWS.Configuration.dll
2025-03-14 04:36 - 2025-03-14 04:36 - 000087040 _____ (UltiDev LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\GAC_MSIL\UWS.RequestProcessor\3.0.0.20__cc16caed94880aaa\UWS.RequestProcessor.dll
2025-03-14 04:38 - 2025-03-14 04:38 - 000015360 _____ (UltiDev LLC) [File not signed] [File is in use] C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Temporary ASP.NET Files\root\07504d0b\fa6973ba\assembly\dl3\05886718\00ed5b42_f90ecf01\UWSAppLocator.DLL

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMInstallerService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMInstallerService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKU\S-1-5-21-1473384019-949151177-2148177368-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
SearchScopes: HKU\S-1-5-21-1473384019-949151177-2148177368-1001 -> DefaultScope {48D3FEDD-C52F-4A0F-8C98-593252D31150} URL =
SearchScopes: HKU\S-1-5-21-1473384019-949151177-2148177368-1001 -> {48D3FEDD-C52F-4A0F-8C98-593252D31150} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_291\bin\ssv.dll [2021-05-29] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_291\bin\jp2ssv.dll [2021-05-29] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2025-06-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2021-05-26 08:19 - 2021-12-28 16:45 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 1.1.1.1 - 1.0.0.1
Windows Firewall is disabled.

Network Binding:
=============
Wi-Fi: Intel(R) Wi-Fi 6 AX201 160MHz -> Netwtw10.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
Síťové připojení Bluetooth 2: Bluetooth Device (Personal Area Network) #2 -> bthpan.sys
Ethernet 2: TAP-NordVPN Windows Adapter V9 -> tapnordvpn.sys

NordLwf: NordVPN LightWeight Firewall

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Eclipse Adoptium\jdk-17.0.11.9-hotspot\bin;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files\dotnet\
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\David Fišer\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\galactic-night-sky-astronomy-science-combined-generative-ai.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|c:\program files\mcafee'c:\program files\common files\mcafee'c:\program files (x86)\mcafee'c:\program files (x86)\common files\mcafee


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "LogiOptions"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "SPUpDateServerrun"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_53C5182FE6D0D86F1F8FAF352988E06A"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "org.whispersystems.signal-desktop"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "Lunar Client"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "AvastBrowserAutoLaunch_56C04F5BFC81B3E7B3214E575E95B9E6"
HKU\S-1-5-21-1473384019-949151177-2148177368-1001\...\StartupApproved\Run: => "LGHUB"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [FPS-SpoolWorker-In-TCP-NoScope] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP-V2] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{9D9BA31C-C9B3-4ACC-AC60-C6A59DC23D5C}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => (Block) C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe (HP Development Company, L.P.) [File not signed]
FirewallRules: [UDP Query User{C04665A2-97A5-4F51-B9E7-8D458BB7CEAE}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => (Block) C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe (HP Development Company, L.P.) [File not signed]
FirewallRules: [TCP Query User{FEB95A5E-CE20-4E15-8433-C3E12E86348A}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [UDP Query User{C3B680D5-0866-4B68-8008-9D73304C59C2}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [TCP Query User{B7F5E01D-94BA-4ACA-84E2-EA9BC6F476DE}C:\users\david fišer\appdata\local\wondershare\wondershare nativepush\wstoastnotification.exe] => (Allow) C:\users\david fišer\appdata\local\wondershare\wondershare nativepush\wstoastnotification.exe (Wondershare Technology Group Co.,Ltd -> Wondershare)
FirewallRules: [UDP Query User{4D34B162-4D3C-4494-A5A6-E44EE67CD826}C:\users\david fišer\appdata\local\wondershare\wondershare nativepush\wstoastnotification.exe] => (Allow) C:\users\david fišer\appdata\local\wondershare\wondershare nativepush\wstoastnotification.exe (Wondershare Technology Group Co.,Ltd -> Wondershare)
FirewallRules: [{AF68AF3D-3C87-4C3A-B0B0-A9CA7756C236}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{1D48ECA7-4DE8-4706-B8F8-C239B3E6EEFA}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{174F8ACD-4DD2-408A-AA39-85C0877118EA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{234BDE37-BE1B-465E-AB0B-1E4FA9EF53EC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BB2D16B9-EB7F-49A1-A37E-815C263DC4CE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1AA47002-D5BF-4335-AA55-78EC77E986B3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{3E6AFE81-3183-4F45-86D5-3AC250245BFE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{311898F0-4520-489D-AD91-EE78E48660A3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A64C75B5-C9A3-4B34-99E9-ECBC8BF472AA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{39BDAB47-A613-4712-942B-09B544DFCC5D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1B66D68E-45F2-4F2D-B832-FBEC3B1E1B1D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2CDF3409-06AA-4E2A-A0F0-4E526931A6C1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

==================== Restore Points =========================

21-06-2025 15:00:55 Windows Update
24-06-2025 18:22:21 Windows Update
24-06-2025 18:22:22 Windows Update
24-06-2025 18:22:22 Windows Update

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (06/30/2025 10:29:20 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 1324, identifikátor PID ProfSvc: 2068.

Error: (06/30/2025 10:29:20 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 4964, identifikátor PID ProfSvc: 2068.

Error: (06/30/2025 10:29:20 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 4964, identifikátor PID ProfSvc: 2068.

Error: (06/30/2025 10:29:20 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 13916, identifikátor PID ProfSvc: 2068.

Error: (06/30/2025 10:29:20 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 4964, identifikátor PID ProfSvc: 2068.

Error: (06/30/2025 10:29:20 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 1324, identifikátor PID ProfSvc: 2068.

Error: (06/30/2025 10:29:20 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 1324, identifikátor PID ProfSvc: 2068.

Error: (06/27/2025 05:19:03 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1512) (User: NT AUTHORITY)
Description: Systém Windows nemůže uvolnit soubor registru. Nebyla uvolněna paměť používaná registrem. Tento problém je často způsoben tím, že jsou služby spuštěny pomocí uživatelského účtu. Zkuste služby konfigurovat pro spuštění pomocí účtu místní nebo síťové služby.

PODROBNOSTI – Přístup byl odepřen.


System errors:
=============
Error: (06/30/2025 10:42:45 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Služba DCOM zjistila chybu 1053 při pokusu o spuštění služby WinDefend s argumenty za účelem spuštění serveru:
{2781761E-28E2-4109-99FE-B9D127C57AFE}

Error: (06/30/2025 10:42:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Antivirová ochrana v programu Microsoft Defender neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (06/30/2025 10:42:45 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Antivirová ochrana v programu Microsoft Defender bylo dosaženo časového limitu (30000 ms).

Error: (06/30/2025 10:40:45 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Služba DCOM zjistila chybu 1053 při pokusu o spuštění služby WinDefend s argumenty za účelem spuštění serveru:
{2781761E-28E2-4109-99FE-B9D127C57AFE}

Error: (06/30/2025 10:40:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Antivirová ochrana v programu Microsoft Defender neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (06/30/2025 10:40:45 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Antivirová ochrana v programu Microsoft Defender bylo dosaženo časového limitu (30000 ms).

Error: (06/30/2025 10:38:58 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Služba DCOM zjistila chybu 1053 při pokusu o spuštění služby WinDefend s argumenty za účelem spuštění serveru:
{2781761E-28E2-4109-99FE-B9D127C57AFE}

Error: (06/30/2025 10:38:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Antivirová ochrana v programu Microsoft Defender neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.


CodeIntegrity:
===============
Date: 2025-06-15 11:57:50
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\David Fišer\AppData\Local\Discord\app-1.0.9195\Discord.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Overwolf\0.276.0.6\OWClient.dll that did not meet the Microsoft signing level requirements.

Date: 2025-06-15 11:57:50
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\David Fišer\AppData\Local\Discord\app-1.0.9195\Discord.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Overwolf\0.276.0.6\ow-graphics-vulkan.dll that did not meet the Microsoft signing level requirements.

Date: 2025-05-17 20:15:31
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\David Fišer\AppData\Local\Discord\app-1.0.9191\Discord.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Overwolf\0.275.0.13\OWClient.dll that did not meet the Microsoft signing level requirements.

Date: 2025-05-17 20:15:31
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\David Fišer\AppData\Local\Discord\app-1.0.9191\Discord.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Overwolf\0.275.0.13\ow-graphics-vulkan.dll that did not meet the Microsoft signing level requirements.

Date: 2025-05-08 19:57:53
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\David Fišer\AppData\Local\Discord\app-1.0.9191\Discord.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Overwolf\0.273.1.4\OWClient.dll that did not meet the Microsoft signing level requirements.

Date: 2025-05-08 19:57:53
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\David Fišer\AppData\Local\Discord\app-1.0.9191\Discord.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Overwolf\0.273.1.4\ow-graphics-vulkan.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: LENOVO EGCN34WW 05/18/2021
Motherboard: LENOVO LNVNB161216
Processor: Intel(R) Core(TM) i5-10300H CPU @ 2.50GHz
Percentage of memory in use: 49%
Total physical RAM: 16251.8 MB
Available physical RAM: 8176 MB
Total Virtual: 28027.8 MB
Available Virtual: 19509.57 MB

==================== Drives ================================

Drive c: (Windows-SSD) (Fixed) (Total:475.63 GB) (Free:40.32 GB) (Model: SKHynix_HFM512GDHTNI-87A0B) NTFS
Drive d: (Samsung) (Fixed) (Total:1863 GB) (Free:1348.37 GB) (Model: Samsung SSD 980 PRO 2TB) NTFS

\\?\Volume{c8020d6f-e247-4f31-869b-61494e804dc7}\ () (Fixed) (Total:1.04 GB) (Free:0.12 GB) NTFS
\\?\Volume{089c068c-527f-4c1b-b054-8f7c1b096a89}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.21 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 47809A7F)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
Intel i3 6320, Gigabyte GA-Z170 Gaming K3, NZXT Kraken X31, 8GB DDR4 Crucial 2666MHz, Eurocase ECO+90 700w, MSI GTX1060 6GB OCV1, 1TB WD raid edition, monitor BenQ 24" FullHD LED

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » včera, 14:06

AV: Windows Defender (Enabled - Up to date)
Psal jsem vypnout antivir..
==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Chybí ten Avast.

Ten Avast pokud nepoužíváš , tak ho odinstaluj. Pomocí Revouninstallu třeba.


Drive c: (Windows-SSD) (Fixed) (Total:475.63 GB) (Free:40.32 GB)
Totální nedostatek volného místa na disku!! Něco odinstaluj , smaž. Máš mít nejméně 15-20% volného místa na syst. disku , pro zajištění bezproblémového chodu windows!!

Pak nový FRST, a oba logy, ne jen jeden!
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

DeNNI85
Level 4.5
Level 4.5
Příspěvky: 1603
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod DeNNI85 » včera, 16:19

s defenderem nejde nic dělat, je prostě mimo provoz a hlásí chybu, reinstaloval jsem systém, ale má to dva disky, tak bych potřeboval prověřit, jestli je vše pryč, protožepo reinstalu to šlape, na druhé ´m disku zůstala spousta dat, o který nechci přijít.
Intel i3 6320, Gigabyte GA-Z170 Gaming K3, NZXT Kraken X31, 8GB DDR4 Crucial 2666MHz, Eurocase ECO+90 700w, MSI GTX1060 6GB OCV1, 1TB WD raid edition, monitor BenQ 24" FullHD LED

DeNNI85
Level 4.5
Level 4.5
Příspěvky: 1603
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod DeNNI85 » včera, 16:44

tady log po reinstalu:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-06-2025
Ran by LENOVO (30-06-2025 16:42:23)
Running from C:\Users\LENOVO\Desktop
Microsoft Windows 11 Home Version 24H2 26100.2033 (X64) (2025-06-30 12:13:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3124560093-767035102-2101230797-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3124560093-767035102-2101230797-503 - Limited - Disabled)
Guest (S-1-5-21-3124560093-767035102-2101230797-501 - Limited - Disabled)
LENOVO (S-1-5-21-3124560093-767035102-2101230797-1001 - Administrator - Enabled) => C:\Users\LENOVO
WDAGUtilityAccount (S-1-5-21-3124560093-767035102-2101230797-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Lenovo Service Bridge (HKU\S-1-5-21-3124560093-767035102-2101230797-1001\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 5.0.2.18 - Lenovo)
Lenovo System Update (HKLM-x32\...\TVSU_is1) (Version: 5.07.0139 - Lenovo)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 138.0.3351.55 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 137.0.3296.93 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3124560093-767035102-2101230797-1001\...\OneDriveSetup.exe) (Version: 25.105.0601.0002 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.22.27821 (HKLM\...\{6E2C7A8E-B17A-4637-9CE9-F0B1157CF378}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.22.27821 (HKLM\...\{0093C20C-273D-4397-B623-515CB8616CB9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.22.27821 (HKLM-x32\...\{3BDE80F7-7EC9-448E-8160-4ADA0CDA8879}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.22.27821 (HKLM-x32\...\{1E6FC929-567E-4D22-9206-C5B83F0A21B9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 140.0.2 (x64 cs)) (Version: 140.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 140.0.2 - Mozilla)
NVIDIA App 11.0.4.148 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.4.148 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.5.10920.35420203 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.5.10920.35420203 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.4.3.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.3.2 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 576.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 576.80 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)

Packages:
=========
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-06-30] (INTEL CORP) [Startup Task]
Dolby Audio -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAudio_3.20602.609.0_x64__rz1tebttyb220 [2025-06-30] (Dolby Laboratories)
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.1.28.0_x64__8wekyb3d8bbwe [2025-06-30] (Microsoft Corp.)
Microsoft.Edge.GameAssist -> C:\Program Files\WindowsApps\Microsoft.Edge.GameAssist_1.0.3336.0_x64__8wekyb3d8bbwe [2025-06-30] (Microsoft Corporation)
Microsoft.StartExperiencesApp -> C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.51.3.0_x64__8wekyb3d8bbwe [2025-06-30] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.968.0_x64__56jybvy8sckqj [2025-06-30] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2025-06-30] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.3190.0_x64__8wekyb3d8bbwe [2025-06-30] (Microsoft Studios) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_41244f6c3b1e083c\nvshext.dll [2025-06-13] (NVIDIA Corporation -> NVIDIA Corporation)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\LENOVO\Desktop\Dochazka3000.lnk -> hxxp://127.0.0.1/dochazka2001

==================== Loaded Modules (Whitelisted) =============


==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.10.1
Windows Firewall is enabled.

Network Binding:
=============
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
Wi-Fi: Intel(R) Wi-Fi 6 AX201 160MHz -> Netwtw10.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3124560093-767035102-2101230797-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_0.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 4) (TamperProtectionSource: 2)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{9B8236AF-3A8F-41D7-9480-AD9C15F9A4E2}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E1A57FAE-F0D7-4894-99DC-F4DDD64D22EA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{7E6350B5-F365-4FCD-805F-A57980412BB8}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> )
FirewallRules: [{8AA740C3-43F8-4F07-82B8-F913C753EAF1}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> )
FirewallRules: [{3B3C003D-8A47-45EB-8D04-979E0A9F1513}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25153.1010.3727.5483_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C0B19039-9E87-4D03-A50E-26D5EA6E084C}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25153.1010.3727.5483_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5C85F2EB-65C9-4B7C-A1F8-769D6504960A}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\137.0.3296.93\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

30-06-2025 14:18:45 Windows Update
30-06-2025 14:18:45 Windows Update
30-06-2025 14:18:46 Windows Update

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (06/30/2025 04:34:18 PM) (Source: Application Hang) (EventID: 1002) (User: NT AUTHORITY)
Description: Verze 0.0.0.0 programu ClockWidgets.exe ukončila interakci se systémem Windows a byla ukončena. Pokud chcete zjistit, zda jsou k dispozici další informace o problému, zkontrolujte historii problémů v ovládacím panelu Zabezpečení a údržba.

Error: (06/30/2025 02:17:33 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x80004005
Argument příkazového řádku:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0567073a-7d74-403b-b2d5-6b35da372d8d;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (06/30/2025 02:17:33 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0x80072EE7
ID SKU=0567073a-7d74-403b-b2d5-6b35da372d8d

Error: (06/30/2025 02:17:33 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0x80072EE7

Error: (06/30/2025 02:16:38 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x80004005
Argument příkazového řádku:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0567073a-7d74-403b-b2d5-6b35da372d8d;NotificationInterval=1440;Trigger=UserLogon;SessionId=2

Error: (06/30/2025 02:16:14 PM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Při aktualizaci stavu Windows Defender na SECURITY_PRODUCT_STATE_ON došlo k chybě.

Error: (06/30/2025 02:16:13 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x80004005
Argument příkazového řádku:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0567073a-7d74-403b-b2d5-6b35da372d8d;NotificationInterval=1440;Trigger=TimerEvent

Error: (06/30/2025 02:16:13 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0x80072EE7
ID SKU=0567073a-7d74-403b-b2d5-6b35da372d8d


System errors:
=============
Error: (06/30/2025 04:24:32 PM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3503) (User: NT AUTHORITY)
Description: Služba přidružení zařízení zjistila chybu zjišťování koncového bodu.

Error: (06/30/2025 04:22:59 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (06/30/2025 04:22:40 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-3BK7V5O)
Description: Server {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} se v daném časovém limitu neregistroval u služby DCOM.

Error: (06/30/2025 04:20:33 PM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3503) (User: NT AUTHORITY)
Description: Služba přidružení zařízení zjistila chybu zjišťování koncového bodu.

Error: (06/30/2025 04:20:32 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Služba Windows Update se po přijetí pokynu pro vypnutí neukončila správně.

Error: (06/30/2025 02:53:49 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80240016): Realtek - SoftwareComponent - 1.0.0.210.

Error: (06/30/2025 02:53:45 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80240016): Realtek - SoftwareComponent - 1.0.0.210.

Error: (06/30/2025 02:53:45 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80240016): Realtek - SoftwareComponent - 11.0.6000.199.


Windows Defender:
================
Date: 2025-06-30 14:48:53
Description:
Antivirová ochrana v programu Microsoft Defender śčãп ħăѕ ьèзʼn şтόрφεð ьєƒôřę сбмρľεťіσи.%п %ŧŠčáʼn ĪĐ:%ъ{70B05854-5BAD-4A6E-BA34-EF524843B2D2}%ⁿ %τŜċâй Ŧуφĕ:%вAntimalwarový program%π %тЅсāπ Рãгåmэтзяŝ:%вÚplné prohledávání%и %тŰşéѓ:%ъDESKTOP-3BK7V5O\LENOVO%ʼn %ŧŜτøр Ѓēāѕσή:%ъ%12

CodeIntegrity:
===============
Date: 2025-06-30 16:23:34
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e6980897e3126266\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: LENOVO EGCN41WW 06/09/2023
Motherboard: LENOVO LNVNB161216
Processor: Intel(R) Core(TM) i5-10300H CPU @ 2.50GHz
Percentage of memory in use: 38%
Total physical RAM: 16251.8 MB
Available physical RAM: 10058.69 MB
Total Virtual: 19195.8 MB
Available Virtual: 13660.32 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:476.19 GB) (Free:287.03 GB) (Model: SKHynix_HFM512GDHTNI-87A0B) NTFS
Drive d: (Samsung) (Fixed) (Total:1863 GB) (Free:1218.88 GB) (Model: Samsung SSD 980 PRO 2TB) NTFS

\\?\Volume{51089fd2-751f-4bc1-be02-a642115b26f3}\ () (Fixed) (Total:0.63 GB) (Free:0.11 GB) NTFS
\\?\Volume{95654d83-20af-4115-b78a-39e9c6407d2d}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 47809A7F)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
Intel i3 6320, Gigabyte GA-Z170 Gaming K3, NZXT Kraken X31, 8GB DDR4 Crucial 2666MHz, Eurocase ECO+90 700w, MSI GTX1060 6GB OCV1, 1TB WD raid edition, monitor BenQ 24" FullHD LED

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » včera, 23:51

dva logy = FRST.txt a Addition.txt

Problémy dle mě způsoboval nejspíše zaplněný disk C:. Windows totiž odmítá správně pracovat při menším volném místě.

Ten první log je bez problémů. Druhý si nedodal.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: DotNetDotCom.org [Bot] a 71 hostů