Prosím o kontrolu logu. Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: memphisto, Mods_senior, Security team

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 28 bře 2018 19:24

RogueKiller V12.12.10.0 [Mar 26 2018] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Webová stránka : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.16299) 32 bits version
Spuštěno : Normální režim
Uživatel : Zden?k [Práva správce]
Started from : C:\Users\Zden?k\Desktop\Zdeny\?i?t?ní Pc\RogueKiller_portable32.exe
Mód : Smazat -- Datum : 03/28/2018 18:13:13 (Duration : 00:59:01)

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 1 ¤¤¤
[PUP.uTorrentAds][Soubor] C:\Users\Zden?k\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe -> Smazáno

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 3 ¤¤¤
[PUM.HomePage][Firefox:Config] bhbxyp6s.default : user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668"); -> Nahrazeno (about:home)
[PUM.SearchEngine][Firefox:Config] bhbxyp6s.default : user_pref("browser.search.selectedEngine", "Seznam"); -> Smazáno
[PUM.SearchEngine][Firefox:Config] bhbxyp6s.default : user_pref("browser.search.defaultenginename", "Seznam"); -> Smazáno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD5000LPVX-80V0TT0 +++++
--- User ---
[MBR] 432f84b043e7d24876de3e0b1557b86f
[BSP] ae40940dbb04473bd794b3f43a1f391e : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 476388 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 975849472 | Size: 450 MB
User = LL1 ... OK
User = LL2 ... OK



Reklama
Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 28 bře 2018 19:40

Zoek.exe v5.0.0.2 Updated 21-Februari-2018(online version)
Tool run by ZdenŘk on st 28.03.2018 at 19:27:46,97.
Microsoft Windows 10 Home 10.0.16299 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\ZDENK~1\AppData\Local\Temp\scoped_dir6800_28450\zoek (1).exe [Scan all users] [Script inserted]

==== System Restore Info ======================

28.3.2018 19:32:43 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== FireFox Fix ======================

Deleted from C:\Users\ZDENK~1\AppData\Roaming\Mozilla\Firefox\Profiles\bhbxyp6s.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"about:home);
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.order.1", "Seznam");

Added to C:\Users\ZDENK~1\AppData\Roaming\Mozilla\Firefox\Profiles\bhbxyp6s.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\ZDENK~1\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668");
user_pref("browser.search.defaulturl", "http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.defaultenginename", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
user_pref("keyword.URL", "http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");

Added to C:\Users\ZDENK~1\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\ZDENK~1\AppData\Roaming\Mozilla\Firefox\Profiles\bhbxyp6s.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\ZDENK~1\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\ZDENK~1\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default
- Lita Centrum.cz - %ProfilePath%\extensions\toolbar@centrumholdings.com
- Firefox Hotfix - %ProfilePath%\extensions\firefox-hotfix@mozilla.org.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

==== Reset Google Chrome ======================

C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF23f216.TMP will be reset at reboot
C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF989cb9.TMP was reset successfully
C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\Users\ZDENK~1\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\ZDENK~1\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\ZDENK~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\ZDENK~1\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF23f216.TMP" not found

==== EOF on st 28.03.2018 at 19:37:22,08 ======================

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 28 bře 2018 20:00

Zemana AntiMalware 2.74.2.150 (instalační verze)

-------------------------------------------------------
Scan Result : Dokončeno
Scan Date : 2018.3.28
Operating System : Windows 10 32-bit
Processor : 2X Celeron(R) Dual-Core CPU T3300 @ 2.00GHz
BIOS Mode : Legacy
CUID : 1210C3088869D06345D911
Scan Type : Skenování systému
Duration : 11m 4s
Scanned Objects : 56713
Detected Objects : 0
Excluded Objects : 0
Read Level : SCSI
Auto Upload : Zapnuto
Detect All Extensions : Vypnuto
Scan Documents : Vypnuto
Domain Info : WORKGROUP,0,2

Detected Objects
-------------------------------------------------------

Nebyly zjištěny žádné hrozby

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 28 bře 2018 20:02

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:01:44, on 28.3.2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.16299.0192)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Users\Zdeněk\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Windows\System32\smartscreen.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser_crashreporter.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\conhost.exe
C:\Program Files\AVAST Software\Avast\AvastNM.exe
C:\WINDOWS\system32\backgroundTaskHost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\conhost.exe
C:\Program Files\AVAST Software\Avast\AvastNM.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
C:\Users\Zdeněk\Desktop\Zdeny\čištění Pc\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [SecurityHealth] %ProgramFiles%\Windows Defender\MSASCuiL.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [ZAM] "C:\Program Files\Zemana AntiMalware\ZAM.exe" /minimized
O4 - HKLM\..\RunOnce: [SBrowserCheck] "%ALLUSERSPROFILE%\Avast Software\Avast\SecureBrowser\avast_browser_setup_checker.exe" /s /run_source=av_update /runonce /cgid 101
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Zdeněk\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{f95f0d4f-0ec4-4fc8-bde2-fafec358f3b2}: NameServer = 77.234.40.79
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: ZAM Controller Service (ZAMSvc) - Copyright 2017. - C:\Program Files\Zemana AntiMalware\ZAM.exe

--
End of file - 5868 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 38602
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: Prosím o kontrolu logu.

Příspěvekod jaro3 » 28 bře 2018 20:23

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 29 bře 2018 07:28

Dobrý den, počítač je o něco rychlejší, ale pořád to není ono.Mám ho už 7 roků, tak se možná není čemu divit .Moc vám všem děkuji za pomoc.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 38602
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: Prosím o kontrolu logu.

Příspěvekod jaro3 » 29 bře 2018 09:44

Stáhni si Memtest:

Políčko , ve kterém je napsáno:
All unused RAM , změň na 2048.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.
poklepej na Memtest , pak znovu a znovu , do políček všech Memtestů napiš 2048 , pak dej u všech Memtestů "Start".

Ještě zkontrolovat HDD na chyby ,popř. zkusit jeho defragmentaci ..

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 29 bře 2018 22:31

----------------------------------------------------------------------------
CrystalDiskInfo 7.6.0 (C) 2008-2018 hiyohiyo
Crystal Dew World : https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 [10.0 Build 16299] (x86)
Date : 2018/03/29 22:31:33

-- Controller Map ----------------------------------------------------------
+ Standardní řadič SATA AHCI [ATA]
- WDC WD5000LPVX-80V0TT0
- TSSTcorp CDDVDW TS-L633C
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) WDC WD5000LPVX-80V0TT0 : 500,1 GB [0/0/0, pd1] - wd

----------------------------------------------------------------------------
(1) WDC WD5000LPVX-80V0TT0
----------------------------------------------------------------------------
Model : WDC WD5000LPVX-80V0TT0
Firmware : 01.01A01
Serial Number : WD-WXL1E54NDWN9
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ACS-2
Minor Version : ----
Transfer Mode : SATA/300 | SATA/600
Power On Hours : 7530 hod.
Power On Count : 2030 krát
Temperature : 36 C (96 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----
Drive Letter : C:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 150 144 _21 0000000005D3 Čas na roztočení ploten
04 _98 _98 __0 0000000009C5 Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _90 _90 __0 000000001D6A Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _98 _98 __0 0000000007EE Počet cyklů zapnutí zařízení
BF __1 __1 __0 00000000008E Počet udalostí zaznamenaných otřesovým senzorem
C0 200 200 __0 000000000020 Počet vypnutí disku
C1 152 152 __0 0000000236A5 Počet cyklů načítání/vymazání
C2 107 _90 __0 000000000024 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 100 253 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 253 __0 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 4C31 4535 344E 4457 4E39
020: 0000 4000 0000 3031 2E30 3141 3031 5744 4320 5744
030: 3530 3030 4C50 5658 2D38 3056 3054 5430 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F FF0E 0004 004C 0040
080: 03FE 0000 746B 7D69 6123 7469 BC49 6123 407F 002F
090: 002F 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6030 3A38 0000 0000 0000 0000 6003 0000 5001 4EE6
110: 5A2D A9D1 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 A3A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 96 90 D3 05 00 00 00 00 00 04 32 00 62 62 C5
020: 09 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5A 5A 6A 1D 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 62 62 EE 07 00 00 00 00 00 BF 32
070: 00 01 01 8E 00 00 00 00 00 00 C0 32 00 C8 C8 20
080: 00 00 00 00 00 00 C1 32 00 98 98 A5 36 02 00 00
090: 00 00 C2 22 00 6B 5A 24 00 00 00 00 00 00 C4 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C5 32 00 C8 C8 00
0B0: 00 00 00 00 00 00 C6 30 00 64 FD 00 00 00 00 00
0C0: 00 00 C7 32 00 C8 C8 00 00 00 00 00 00 00 C8 08
0D0: 00 64 FD 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 B0 22 01 7B
170: 03 00 01 00 02 67 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 02 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6C

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 00 00 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 BF 00
070: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
080: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C4 00
0A0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00
0B0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00
0C0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 C8 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 DE

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 38602
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: Prosím o kontrolu logu.

Příspěvekod jaro3 » 29 bře 2018 22:41

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.

a ještě zítra udělej znovu crystaldiskinfo.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 30 bře 2018 09:04

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14.03.2018
Ran by Zdeněk (30-03-2018 07:43:52)
Running from C:\Users\Zdeněk\Desktop
Microsoft Windows 10 Home Version 1709 16299.309 (X86) (2017-12-21 12:45:57)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3053463390-3481767629-2475232128-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3053463390-3481767629-2475232128-503 - Limited - Disabled)
Guest (S-1-5-21-3053463390-3481767629-2475232128-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3053463390-3481767629-2475232128-1002 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-3053463390-3481767629-2475232128-504 - Limited - Disabled)
Zdeněk (S-1-5-21-3053463390-3481767629-2475232128-1000 - Administrator - Enabled) => C:\Users\Zdeněk

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe Flash Player 29 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 29.0.0.113 - Adobe Systems Incorporated)
Audacity 2.2.1 (HKLM\...\Audacity_is1) (Version: 2.2.1 - Audacity Team)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 18.2.2328 - AVAST Software)
GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team)
Google Chrome (HKLM\...\Google Chrome) (Version: 65.0.3325.181 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
K-Lite Codec Pack 12.1.0 Full (HKLM\...\KLiteCodecPack_is1) (Version: 12.1.0 - KLCP)
LibreOffice 5.1.3.2 (HKLM\...\{5F7475A1-6240-4753-BE3E-61499621EC42}) (Version: 5.1.3.2 - The Document Foundation)
Malwarebytes verze 3.4.4.2398 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.4.2398 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-3053463390-3481767629-2475232128-1000\...\OneDriveSetup.exe) (Version: 18.044.0301.0006 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3053463390-3481767629-2475232128-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03302018063527532\...\OneDriveSetup.exe) (Version: 18.044.0301.0006 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 cs) (HKLM\...\Mozilla Firefox 46.0.1 (x86 cs)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 46.0.1 - Mozilla)
SafeZone Stable 4.58.2552.909 (HKLM\...\SafeZone 4.58.2552.909) (Version: 4.58.2552.909 - Avast Software) Hidden
Skype™ 7.40 (HKLM\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.151 - Skype Technologies S.A.)
Sophos Virus Removal Tool (HKLM\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.6.1 - Sophos Limited)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.3 - VideoLAN)
Windows 10 Update and Privacy Settings (HKLM\...\{542CC2C2-ABAF-4604-8723-DA296AF74540}) (Version: 1.0.14.0 - Microsoft Corporation)
WinRAR 5.31 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
Zemana AntiMalware (HKLM\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_CZ_is1) (Version: 19.1610.2.7 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-03-14] (AVAST Software)
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files\Zemana AntiMalware\ZAMShellExt32.dll [2018-03-28] ()
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-03-14] (AVAST Software)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-04] (Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-03-14] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-03] (Malwarebytes)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files\Zemana AntiMalware\ZAMShellExt32.dll [2018-03-28] ()
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-03-14] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-03] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-04] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00EC629A-C486-4E90-A4B7-7C8CAC1C7482} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {0425A7E2-A11E-4D9B-99C7-979403CCE95E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {065F7C5E-5509-423A-9963-3D0D85068560} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {0FB0A42E-4F1C-4C38-ACC2-090CAD2C5F5A} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {151F12AD-D0DE-40BE-B169-AA4A0585554E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {18AC8CA5-9F91-4C94-83D8-855F0A34AB4F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-05-29] (Google Inc.)
Task: {1B14BAEA-3E8E-49E9-AD80-3B78F24543B4} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4217CC69-6B3B-4C79-8080-F54F799C0598} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {5170ECEE-9802-41BD-A4CE-393DDBBBC430} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {51973EF4-D14C-413C-BC42-D0B859FF3727} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {6276C8A8-281B-46DB-BF4C-9E95EEF5EF9D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {65952684-803B-47FD-8795-78971EC105BD} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {71309FBD-B720-4CBA-A139-7E930EE21F59} - System32\Tasks\SafeZone scheduled Autoupdate 1464513258 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-08-04] (Avast Software)
Task: {7D40E492-4644-461C-9AFD-22EFBBC96994} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {843745E2-E171-4E63-8F49-E5BF1E269770} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {875EA9A1-8EA6-4F04-8D13-E03AA4ECCF9F} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {8B27F024-6FAC-4B00-A58A-45311EC869E3} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {995AAE86-B337-46E7-85C4-A6C499A69DA4} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-03-14] (AVAST Software)
Task: {9E0CCFA5-1CF8-469A-A0CB-93FF9E1376F3} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {A1441673-8E1F-41E6-A2CA-72623BC9F395} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-05-29] (Google Inc.)
Task: {A3262FC0-D80B-48B9-8BC6-8B482223BC9C} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A434A133-A55C-4A5A-AE2C-B447EA9CBAB3} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A8564F6D-38FD-40FB-868A-7DFEC4363B07} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {AB25DDCA-18EF-4EEA-A12D-18C9172D2797} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {AF947C67-D2E4-4134-8B1B-F5A4BFA8571B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {BE1E87E7-30CB-4BB9-8489-BAB123C33C95} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BEEF8624-81BB-4C55-94CA-6A7C311E0B3E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D46C1F18-65E6-4B4E-9D63-98FD54ADB195} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E17E058E-DBF4-494F-828D-EAFA76975B14} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {EA979BA4-0A45-4669-8EB9-54585AB2FE8A} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-01-08] (AVAST Software)
Task: {F4B1E394-BFF6-4D2C-916C-33D87204FFA7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_29_0_0_113_pepper.exe [2018-03-14] (Adobe Systems Incorporated)
Task: {F7EBBA92-48AB-4604-9860-65F11A2CCAA2} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-14] (Adobe Systems Incorporated)
Task: {FC459509-C282-4ADE-A782-11D178FAA349} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-09-29 13:49 - 2017-09-29 13:49 - 000149840 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-03-27 20:23 - 2018-02-05 15:44 - 001935136 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-03-27 20:23 - 2018-03-01 11:31 - 001908512 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2018-03-28 19:45 - 2018-03-28 19:45 - 000131952 _____ () C:\Program Files\Zemana AntiMalware\ZAMShellExt32.dll
2018-03-14 08:30 - 2018-02-22 02:12 - 007817728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2018-03-14 08:30 - 2018-02-22 02:09 - 001518592 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-03-27 06:23 - 2018-03-27 06:23 - 000075264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x86__kzf8qxf38zg5c\SkypeHost.exe
2018-03-27 06:23 - 2018-03-27 06:23 - 000166400 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x86__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-03-27 06:23 - 2018-03-27 06:23 - 016042496 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x86__kzf8qxf38zg5c\SkyWrap.dll
2018-03-27 06:23 - 2018-03-27 06:23 - 001798144 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x86__kzf8qxf38zg5c\skypert.dll
2018-03-14 07:57 - 2018-03-14 07:57 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-03-14 07:57 - 2018-03-14 07:57 - 000287960 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-03-14 07:57 - 2018-03-14 07:57 - 000280280 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2018-03-14 07:56 - 2018-03-14 07:56 - 000275160 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-09-26 22:22 - 2017-09-26 22:22 - 001984000 ____R () C:\Program Files\Skype\Phone\skypert.dll
2017-02-08 15:18 - 2017-02-08 15:18 - 000105760 _____ () C:\Program Files\AVAST Software\Avast\OpenVpn\lzo2.dll
2017-02-08 15:18 - 2017-02-08 15:18 - 000091184 _____ () C:\Program Files\AVAST Software\Avast\OpenVpn\libpkcs11-helper-1.dll
2017-09-07 17:57 - 2017-08-04 11:38 - 071398944 _____ () C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser_browser.dll
2018-03-14 07:57 - 2018-03-14 07:57 - 000613440 _____ () C:\Program Files\AVAST Software\Avast\AvastNM.exe

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2018-03-28 19:33 - 000000753 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03302018063527157\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03302018063527376\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3053463390-3481767629-2475232128-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3053463390-3481767629-2475232128-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03302018063527532\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 77.234.40.79 - 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{1FC04ABE-F218-4D3E-BACD-9657FA8239CA}C:\program files\skype\phone\skype.exe] => (Allow) C:\program files\skype\phone\skype.exe
FirewallRules: [UDP Query User{7C4CC836-4308-4674-8A77-99B23D001D5C}C:\program files\skype\phone\skype.exe] => (Allow) C:\program files\skype\phone\skype.exe

==================== Restore Points =========================

05-03-2018 10:13:05 Naplánovaný kontrolní bod
14-03-2018 08:28:03 Windows Update
23-03-2018 20:18:07 Naplánovaný kontrolní bod
28-03-2018 06:55:20 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/28/2018 07:12:04 PM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (03/28/2018 07:12:04 PM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (03/28/2018 07:11:24 PM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (03/28/2018 07:11:24 PM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (03/28/2018 04:42:13 PM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (03/28/2018 04:42:13 PM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (03/28/2018 01:39:03 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Zdenek-PC)
Description: Balíček Microsoft.Windows.ShellExperienceHost_10.0.16299.15_neutral_neutral_cw5n1h2txyewy+App se ukončil, protože jeho pozastavování trvalo moc dlouho.

Error: (03/28/2018 06:55:29 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.


System errors:
=============
Error: (03/30/2018 06:36:28 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (03/30/2018 06:34:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (03/30/2018 06:34:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (03/30/2018 06:34:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (03/30/2018 06:34:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (03/30/2018 06:33:26 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (22:20:54, ‎29.‎03.‎2018) bylo neočekávané.

Error: (03/29/2018 10:22:41 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (03/29/2018 10:21:33 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


==================== Memory info ===========================

Processor: Celeron(R) Dual-Core CPU T3300 @ 2.00GHz
Percentage of memory in use: 90%
Total physical RAM: 2008.6 MB
Available physical RAM: 185.83 MB
Total Virtual: 4184.6 MB
Available Virtual: 1079.99 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.22 GB) (Free:386.87 GB) NTFS

\\?\Volume{3e39d36f-24e3-11e6-ad0b-806e6f6e6963}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{91e05e3b-0000-0000-0000-905474000000}\ () (Fixed) (Total:0.44 GB) (Free:0.14 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 91E05E3B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

==================== End of Addition.txt ============================

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 30 bře 2018 09:05

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14.03.2018
Ran by Zdeněk (administrator) on ZDENEK-PC (30-03-2018 07:36:06)
Running from C:\Users\Zdeněk\Desktop
Loaded Profiles: Zdeněk & (Available Profiles: Zdeněk)
Platform: Microsoft Windows 10 Home Version 1709 16299.309 (X86) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Copyright 2017.) C:\Program Files\Zemana AntiMalware\ZAM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x86__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Copyright 2017.) C:\Program Files\Zemana AntiMalware\ZAM.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(The OpenVPN Project) C:\Program Files\AVAST Software\Avast\OpenVPN\openvpn.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser_crashreporter.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
() C:\Program Files\AVAST Software\Avast\AvastNM.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
() C:\Program Files\AVAST Software\Avast\AvastNM.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [488344 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [245608 2018-03-14] (AVAST Software)
HKLM\...\Run: [ZAM] => C:\Program Files\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKLM\...\RunOnce: [SBrowserCheck] => C:\ProgramData\Avast Software\Avast\SecureBrowser\avast_browser_setup_checker.exe [2482128 2018-03-23] ()
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-3053463390-3481767629-2475232128-1000\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTRAY.EXE [568904 2016-10-27] (ZONER software)
HKU\S-1-5-21-3053463390-3481767629-2475232128-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [27832264 2017-10-06] (Skype Technologies S.A.)
HKU\S-1-5-21-3053463390-3481767629-2475232128-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03302018063527532\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTRAY.EXE [568904 2016-10-27] (ZONER software)
HKU\S-1-5-21-3053463390-3481767629-2475232128-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03302018063527532\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [27832264 2017-10-06] (Skype Technologies S.A.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{be165a30-b6a1-47d8-a31d-5754fa667316}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{d4d62b55-7334-419b-87d7-4e7858d19bcb}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{f95f0d4f-0ec4-4fc8-bde2-fafec358f3b2}: [NameServer] 77.234.40.79

Internet Explorer:
==================

Edge:
======
Edge Extension: (AutoFormFill) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [2017-09-29]
Edge Extension: (LearningTools) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [2018-03-14]

FireFox:
========
FF ProfilePath: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default [2018-03-28]
FF Homepage: Mozilla\Firefox\Profiles\jqvdt89e.default -> about:home
FF NewTab: Mozilla\Firefox\Profiles\jqvdt89e.default -> about:newtab
FF Extension: (Firefox Hotfix) - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-24] [Legacy]
FF Extension: (Lišta Centrum.cz) - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default\Extensions\toolbar@centrumholdings.com [2014-10-17] [Legacy] [not signed]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default\features\{925aec54-f00c-43c9-a253-6fd7df1e6fec}\malware-remediation@mozilla.org.xpi [2016-09-24] [Legacy]
FF SearchPlugin: C:\Users\Zdeněk\AppData\Roaming\Mozilla\Firefox\Profiles\jqvdt89e.default\searchplugins\seznam-avast.xml [2018-03-27]
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-04-26] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)

Chrome:
=======
CHR DefaultProfile: Default
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKU\S-1-5-21-3053463390-3481767629-2475232128-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3053463390-3481767629-2475232128-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03302018063527532\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5909888 2018-03-14] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [303728 2018-03-14] (AVAST Software)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4675872 2018-03-03] (Malwarebytes)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [279408 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [86696 2017-09-29] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [167040 2018-03-14] (AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriverx.sys [185432 2018-03-14] (AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidshx.sys [157368 2018-03-14] (AVAST Software)
R0 aswblog; C:\WINDOWS\System32\drivers\aswblogx.sys [276688 2018-03-14] (AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbunivx.sys [50336 2018-03-14] (AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [169536 2018-03-14] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [42808 2018-03-14] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [39784 2017-09-07] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [124392 2018-03-14] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [100032 2018-03-14] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [70816 2018-03-14] (AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [783608 2018-03-14] (AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [391856 2018-03-14] (AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [152344 2018-03-14] (AVAST Software)
R3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [48152 2017-02-08] (The OpenVPN Project)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [310784 2018-03-14] (AVAST Software)
R3 athr; C:\WINDOWS\System32\drivers\athwn.sys [3228672 2017-09-29] (Qualcomm Atheros Communications, Inc.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [58664 2018-01-18] ()
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [167648 2018-03-28] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [90856 2018-03-30] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [41352 2018-03-30] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [220896 2018-03-30] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [81632 2018-03-30] (Malwarebytes)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37440 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [253848 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [98200 2017-09-29] (Microsoft Corporation)
R3 yukonw8; C:\WINDOWS\System32\drivers\yk63x86.sys [242688 2017-09-29] (Marvell)
R1 ZAM; C:\WINDOWS\System32\drivers\zam32.sys [181496 2018-03-28] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard32.sys [181496 2018-03-28] (Zemana Ltd.)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-30 07:36 - 2018-03-30 07:38 - 000012337 _____ C:\Users\Zdeněk\Desktop\FRST.txt
2018-03-30 07:35 - 2018-03-30 07:36 - 000000000 ____D C:\FRST
2018-03-30 07:33 - 2018-03-30 07:34 - 001764352 _____ (Farbar) C:\Users\Zdeněk\Desktop\FRST.exe
2018-03-29 12:47 - 2018-03-30 06:35 - 000081632 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-03-29 12:47 - 2018-03-29 12:47 - 000000000 ____D C:\WINDOWS\Minidump
2018-03-29 12:47 - 2018-03-29 12:47 - 000000000 _____ C:\WINDOWS\Minidump\032918-25593-01.dmp
2018-03-28 19:45 - 2018-03-30 07:38 - 000066460 _____ C:\WINDOWS\ZAM.krnl.trace
2018-03-28 19:45 - 2018-03-30 07:38 - 000036611 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-03-28 19:45 - 2018-03-28 19:45 - 000181496 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard32.sys
2018-03-28 19:45 - 2018-03-28 19:45 - 000181496 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam32.sys
2018-03-28 19:45 - 2018-03-28 19:45 - 000001961 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2018-03-28 19:45 - 2018-03-28 19:45 - 000000000 ____D C:\Users\Zdeněk\AppData\Local\Zemana
2018-03-28 19:45 - 2018-03-28 19:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2018-03-28 19:45 - 2018-03-28 19:45 - 000000000 ____D C:\Program Files\Zemana AntiMalware
2018-03-28 19:42 - 2018-03-28 19:42 - 006625600 _____ (Zemana Ltd. ) C:\Users\Zdeněk\Desktop\Zemana.AntiMalware.Setup.exe
2018-03-28 19:36 - 2018-03-30 06:33 - 000041352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-03-28 19:34 - 2018-03-28 19:27 - 000024064 _____ C:\WINDOWS\zoek-delete.exe
2018-03-28 19:27 - 2018-03-28 19:27 - 000000000 ____D C:\zoek_backup
2018-03-28 13:26 - 2018-03-28 18:13 - 000024688 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2018-03-28 13:26 - 2018-03-28 17:51 - 000000000 ____D C:\ProgramData\RogueKiller
2018-03-28 10:41 - 2018-03-28 10:41 - 000000000 ____D C:\ProgramData\Sophos
2018-03-28 10:40 - 2018-03-28 10:40 - 000002763 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2018-03-28 10:40 - 2018-03-28 10:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2018-03-28 10:39 - 2018-03-28 10:39 - 000000000 ____D C:\Program Files\Sophos
2018-03-28 07:00 - 2018-03-28 07:00 - 000000896 _____ C:\Users\Zdeněk\Desktop\JRT.txt
2018-03-28 06:35 - 2018-03-28 18:04 - 000001701 _____ C:\Users\Zdeněk\Desktop\Malware.txt
2018-03-28 05:56 - 2018-03-28 05:56 - 000002097 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-03-28 05:56 - 2018-03-28 05:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-03-28 05:52 - 2018-03-28 05:53 - 050751144 _____ (Malwarebytes ) C:\Users\Zdeněk\Downloads\3043.tmp
2018-03-27 21:14 - 2018-03-30 06:33 - 000220896 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-03-27 21:14 - 2018-03-30 06:33 - 000090856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-03-27 21:14 - 2018-03-28 05:57 - 000167648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2018-03-27 21:13 - 2018-01-18 08:03 - 000058664 _____ C:\WINDOWS\system32\Drivers\mbae.sys
2018-03-27 21:12 - 2018-03-27 21:12 - 000110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\48230029.sys
2018-03-27 20:14 - 2018-03-28 05:56 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-03-27 20:14 - 2018-03-27 20:14 - 000000000 ____D C:\Program Files\Malwarebytes
2018-03-27 20:03 - 2018-03-28 06:41 - 000000000 ____D C:\AdwCleaner
2018-03-27 19:59 - 2018-03-27 19:59 - 000000000 ____D C:\Users\Zdeněk\AppData\Local\CEF
2018-03-27 19:41 - 2018-03-27 19:41 - 000000000 ____D C:\Users\Zdeněk\AppData\Local\ConnectedDevicesPlatform
2018-03-17 16:39 - 2018-03-17 16:39 - 000001869 _____ C:\Users\Zdeněk\Desktop\License.avastvpn
2018-03-14 08:30 - 2018-03-01 22:28 - 000661504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-03-14 08:30 - 2018-03-01 08:56 - 000603544 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-03-14 08:30 - 2018-03-01 08:52 - 001328024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-03-14 08:30 - 2018-03-01 08:52 - 000517024 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-03-14 08:30 - 2018-03-01 08:52 - 000221592 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-03-14 08:30 - 2018-03-01 08:52 - 000119192 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-03-14 08:30 - 2018-03-01 08:51 - 001902488 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-03-14 08:30 - 2018-03-01 08:51 - 000542624 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-03-14 08:30 - 2018-03-01 08:51 - 000322464 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-03-14 08:30 - 2018-03-01 08:51 - 000062360 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-03-14 08:30 - 2018-03-01 08:43 - 006412192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-03-14 08:30 - 2018-03-01 08:41 - 000816632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-03-14 08:30 - 2018-03-01 08:40 - 000030616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-03-14 08:30 - 2018-03-01 08:39 - 000350616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-03-14 08:30 - 2018-03-01 08:39 - 000213400 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-03-14 08:30 - 2018-03-01 08:37 - 000508312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-03-14 08:30 - 2018-03-01 08:35 - 000607640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-03-14 08:30 - 2018-03-01 08:35 - 000451480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-03-14 08:30 - 2018-03-01 08:35 - 000142744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-03-14 08:30 - 2018-03-01 08:32 - 000414824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-03-14 08:30 - 2018-03-01 08:30 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-03-14 08:30 - 2018-03-01 08:30 - 002117536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-03-14 08:30 - 2018-03-01 08:30 - 000339360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-03-14 08:30 - 2018-03-01 08:28 - 006480616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-03-14 08:30 - 2018-03-01 08:28 - 002193168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-03-14 08:30 - 2018-03-01 08:27 - 000538760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-03-14 08:30 - 2018-03-01 08:27 - 000284112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-03-14 08:30 - 2018-03-01 08:27 - 000170904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-03-14 08:30 - 2018-03-01 08:26 - 001524776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-03-14 08:30 - 2018-03-01 08:26 - 000040856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-03-14 08:30 - 2018-03-01 08:25 - 000116120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-03-14 08:30 - 2018-03-01 08:24 - 000078232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-03-14 08:30 - 2018-03-01 08:04 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-03-14 08:30 - 2018-03-01 08:03 - 002902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-03-14 08:30 - 2018-03-01 08:03 - 000666112 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-03-14 08:30 - 2018-03-01 08:03 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcSpecfc.dll
2018-03-14 08:30 - 2018-03-01 08:03 - 000412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-03-14 08:30 - 2018-03-01 08:03 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-03-14 08:30 - 2018-03-01 08:03 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-03-14 08:30 - 2018-03-01 08:03 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-03-14 08:30 - 2018-03-01 08:03 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2018-03-14 08:30 - 2018-03-01 08:03 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2018-03-14 08:30 - 2018-03-01 08:03 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2018-03-14 08:30 - 2018-03-01 08:02 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2018-03-14 08:30 - 2018-03-01 08:01 - 019354624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-03-14 08:30 - 2018-03-01 08:01 - 006575616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-03-14 08:30 - 2018-03-01 08:01 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-03-14 08:30 - 2018-03-01 08:01 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcnfs.sys
2018-03-14 08:30 - 2018-03-01 07:58 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-03-14 08:30 - 2018-03-01 07:58 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2018-03-14 08:30 - 2018-03-01 07:58 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-03-14 08:30 - 2018-03-01 07:58 - 000405504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2018-03-14 08:30 - 2018-03-01 07:58 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-03-14 08:30 - 2018-03-01 07:57 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2018-03-14 08:30 - 2018-03-01 07:57 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-03-14 08:30 - 2018-03-01 07:56 - 018922496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-03-14 08:30 - 2018-03-01 07:56 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-03-14 08:30 - 2018-03-01 07:55 - 000346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-03-14 08:30 - 2018-03-01 07:54 - 003181568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-03-14 08:30 - 2018-03-01 07:54 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-03-14 08:30 - 2018-03-01 07:54 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-03-14 08:30 - 2018-03-01 07:52 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-03-14 08:30 - 2018-03-01 07:52 - 006030336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-03-14 08:30 - 2018-03-01 07:52 - 001132544 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-03-14 08:30 - 2018-03-01 07:50 - 003677184 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-03-14 08:30 - 2018-03-01 07:50 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-03-14 08:30 - 2018-03-01 07:50 - 001622528 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-03-14 08:30 - 2018-03-01 07:49 - 001762304 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-03-14 08:30 - 2018-03-01 07:49 - 000748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2018-03-14 08:30 - 2018-03-01 07:48 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-03-14 08:30 - 2018-03-01 07:48 - 000650240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-03-14 08:30 - 2018-02-22 03:23 - 000239000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2018-03-14 08:30 - 2018-02-22 02:54 - 000233376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2018-03-14 08:30 - 2018-02-22 02:48 - 000081824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-03-14 08:30 - 2018-02-22 02:48 - 000065432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-03-14 08:30 - 2018-02-22 02:46 - 000155552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2018-03-14 08:30 - 2018-02-22 02:45 - 000454048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-03-14 08:30 - 2018-02-22 02:43 - 000534944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-03-14 08:30 - 2018-02-22 02:43 - 000336800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2018-03-14 08:30 - 2018-02-22 02:43 - 000128408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2018-03-14 08:30 - 2018-02-22 02:43 - 000080800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-03-14 08:30 - 2018-02-22 02:42 - 000433568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-03-14 08:30 - 2018-02-22 02:42 - 000279448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-03-14 08:30 - 2018-02-22 02:42 - 000076192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2018-03-14 08:30 - 2018-02-22 02:42 - 000038304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2018-03-14 08:30 - 2018-02-22 02:19 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2018-03-14 08:30 - 2018-02-22 02:18 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-03-14 08:30 - 2018-02-22 02:18 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2018-03-14 08:30 - 2018-02-22 02:17 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-03-14 08:30 - 2018-02-22 02:12 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-03-14 08:29 - 2018-03-01 08:45 - 001933840 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-03-14 08:29 - 2018-03-01 08:44 - 000253144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-03-14 08:29 - 2018-03-01 08:35 - 000195488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-03-14 08:29 - 2018-03-01 08:28 - 000115096 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2018-03-14 08:29 - 2018-03-01 08:27 - 000221592 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2018-03-14 08:29 - 2018-03-01 08:25 - 000048024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\isapnp.sys
2018-03-14 08:29 - 2018-03-01 08:23 - 005105664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWSnapin.dll
2018-03-14 08:29 - 2018-03-01 08:21 - 001558856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2018-03-14 08:29 - 2018-03-01 08:01 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-03-14 08:29 - 2018-03-01 08:00 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-03-14 08:29 - 2018-03-01 07:59 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2018-03-14 08:29 - 2018-03-01 07:58 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2018-03-14 08:29 - 2018-03-01 07:51 - 002329088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2018-03-14 08:29 - 2018-03-01 07:48 - 001652224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-03-14 08:29 - 2018-03-01 07:46 - 004051968 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-03-14 08:29 - 2018-03-01 07:46 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2018-03-14 08:29 - 2018-03-01 07:45 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2018-03-14 08:29 - 2018-02-22 02:50 - 000156056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ataport.sys
2018-03-14 08:29 - 2018-02-22 02:42 - 000186784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2018-03-14 08:29 - 2018-02-22 02:16 - 001286144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-03-14 08:29 - 2018-02-22 02:16 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys
2018-03-14 07:58 - 2018-03-14 07:57 - 000319392 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2018-03-13 15:43 - 2018-03-13 15:43 - 000000000 ___HD C:\Users\Zdeněk\MicrosoftEdgeBackups

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-30 06:58 - 2017-09-29 13:55 - 000000000 ___HD C:\Program Files\WindowsApps
2018-03-30 06:58 - 2017-09-29 13:55 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-03-30 06:57 - 2017-09-29 13:55 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-03-30 06:48 - 2016-05-29 16:40 - 000000000 ____D C:\Users\Zdeněk\AppData\Roaming\Skype
2018-03-30 06:40 - 2017-12-21 14:40 - 004353574 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-03-30 06:40 - 2017-09-30 14:07 - 002085652 _____ C:\WINDOWS\system32\perfh005.dat
2018-03-30 06:40 - 2017-09-30 14:07 - 000546072 _____ C:\WINDOWS\system32\perfc005.dat
2018-03-30 06:34 - 2017-12-21 14:23 - 000000000 ____D C:\Users\Zdeněk
2018-03-30 06:33 - 2017-12-21 14:44 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-03-30 06:33 - 2017-12-21 14:20 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-03-29 21:14 - 2017-09-29 07:31 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-03-29 18:54 - 2016-05-29 10:17 - 000002433 _____ C:\Users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-03-29 18:54 - 2016-05-29 10:17 - 000000000 ___RD C:\Users\Zdeněk\OneDrive
2018-03-27 13:43 - 2016-05-28 16:56 - 000000000 ____D C:\Users\Zdeněk\AppData\Local\VirtualStore
2018-03-23 02:51 - 2016-05-29 10:57 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-23 02:51 - 2016-05-29 10:57 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-03-17 22:24 - 2016-07-05 23:24 - 000000000 ____D C:\Users\Zdeněk\AppData\Roaming\vlc
2018-03-17 17:48 - 2017-09-29 13:55 - 000000000 ____D C:\WINDOWS\rescache
2018-03-17 16:44 - 2016-05-28 17:54 - 000000000 ___RD C:\Users\Zdeněk\Desktop\Zdeny
2018-03-14 19:23 - 2017-09-29 13:45 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-03-14 19:18 - 2017-09-29 13:52 - 000000000 ____D C:\WINDOWS\INF
2018-03-14 19:16 - 2017-12-21 14:20 - 000293024 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-03-14 19:14 - 2017-09-29 13:55 - 000000000 ____D C:\WINDOWS\TextInput
2018-03-14 19:14 - 2017-09-29 13:55 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-03-14 19:14 - 2017-09-29 13:55 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-03-14 10:57 - 2017-09-29 13:55 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-03-14 08:47 - 2016-05-29 10:37 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-03-14 08:42 - 2017-10-12 09:44 - 127391104 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-03-14 08:42 - 2016-05-29 10:37 - 127391104 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-03-14 08:33 - 2017-09-29 13:49 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-03-14 08:32 - 2017-09-29 13:49 - 000075296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\disk.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Synth3dVsc.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000048536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vdrvroot.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000038944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000028056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsc.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000022400 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2018-03-14 08:32 - 2017-09-29 13:49 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HyperVideo.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpbus.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\VMBusHID.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hyperkbd.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmgencounter.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmgid.sys
2018-03-14 08:32 - 2017-09-29 13:49 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vms3cap.sys
2018-03-14 08:31 - 2017-09-29 13:49 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dmvsc.sys
2018-03-14 08:00 - 2017-06-07 09:34 - 000055160 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000391856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000310784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000167040 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000152344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000124392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000100032 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000070816 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-03-14 07:57 - 2017-12-20 18:47 - 000042808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-03-14 07:56 - 2018-01-09 15:51 - 000169536 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2018-03-14 07:56 - 2017-12-20 18:47 - 000783608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-03-14 07:56 - 2017-12-20 18:47 - 000276688 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswblogx.sys
2018-03-14 07:56 - 2017-12-20 18:47 - 000185432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriverx.sys
2018-03-14 07:56 - 2017-12-20 18:47 - 000157368 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidshx.sys
2018-03-14 07:56 - 2017-12-20 18:47 - 000050336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbunivx.sys
2018-03-02 23:09 - 2018-01-11 14:30 - 000834552 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2018-03-02 23:09 - 2018-01-11 14:30 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2016-12-31 18:48 - 2016-12-31 18:48 - 000000841 _____ () C:\Users\Zdeněk\AppData\Local\recently-used.xbel
2017-10-01 19:32 - 2017-10-01 19:32 - 000000000 _____ () C:\Users\Zdeněk\AppData\Local\{120ECEA5-754B-4506-B675-AFF3662490A1}

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-03-22 15:29

==================== End of FRST.txt ============================

Zdeny18
nováček
Příspěvky: 22
Registrován: březen 18
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu logu.

Příspěvekod Zdeny18 » 30 bře 2018 09:14

----------------------------------------------------------------------------
CrystalDiskInfo 7.6.0 (C) 2008-2018 hiyohiyo
Crystal Dew World : https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 [10.0 Build 16299] (x86)
Date : 2018/03/30 9:07:05

-- Controller Map ----------------------------------------------------------
+ Standardní řadič SATA AHCI [ATA]
- WDC WD5000LPVX-80V0TT0
- TSSTcorp CDDVDW TS-L633C
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) WDC WD5000LPVX-80V0TT0 : 500,1 GB [0/0/0, pd1] - wd

----------------------------------------------------------------------------
(1) WDC WD5000LPVX-80V0TT0
----------------------------------------------------------------------------
Model : WDC WD5000LPVX-80V0TT0
Firmware : 01.01A01
Serial Number : WD-WXL1E54NDWN9
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ACS-2
Minor Version : ----
Transfer Mode : SATA/300 | SATA/600
Power On Hours : 7533 hod.
Power On Count : 2031 krát
Temperature : 39 C (102 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----
Drive Letter : C:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 149 144 _21 00000000060E Čas na roztočení ploten
04 _98 _98 __0 0000000009C6 Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _90 _90 __0 000000001D6D Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _98 _98 __0 0000000007EF Počet cyklů zapnutí zařízení
BF __1 __1 __0 00000000008E Počet udalostí zaznamenaných otřesovým senzorem
C0 200 200 __0 000000000020 Počet vypnutí disku
C1 152 152 __0 0000000236A6 Počet cyklů načítání/vymazání
C2 104 _90 __0 000000000027 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 100 253 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 253 __0 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 4C31 4535 344E 4457 4E39
020: 0000 4000 0000 3031 2E30 3141 3031 5744 4320 5744
030: 3530 3030 4C50 5658 2D38 3056 3054 5430 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F FF0E 0004 004C 0040
080: 03FE 0000 746B 7D69 6123 7469 BC49 6123 407F 002F
090: 002F 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6030 3A38 0000 0000 0000 0000 6003 0000 5001 4EE6
110: 5A2D A9D1 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 A3A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 95 90 0E 06 00 00 00 00 00 04 32 00 62 62 C6
020: 09 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5A 5A 6D 1D 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 62 62 EF 07 00 00 00 00 00 BF 32
070: 00 01 01 8E 00 00 00 00 00 00 C0 32 00 C8 C8 20
080: 00 00 00 00 00 00 C1 32 00 98 98 A6 36 02 00 00
090: 00 00 C2 22 00 68 5A 27 00 00 00 00 00 00 C4 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C5 32 00 C8 C8 00
0B0: 00 00 00 00 00 00 C6 30 00 64 FD 00 00 00 00 00
0C0: 00 00 C7 32 00 C8 C8 00 00 00 00 00 00 00 C8 08
0D0: 00 64 FD 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 B0 22 01 7B
170: 03 00 01 00 02 67 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 02 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2B

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 00 00 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 BF 00
070: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
080: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C4 00
0A0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00
0B0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00
0C0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 C8 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 DE


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: CommonCrawl [Bot] a 1 host