Prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 04 pro 2022 14:11

Příčinou bude asi nejnovější Chrome a jeho nekompabilita s windows7.

Soumrak nad Windows 7 a 8.1. Chrome 111 je už nebude podporovat
https://www.zive.cz/clanky/soumrak-nad- ... fault.aspx

Vypni antivir i firewall.
Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
další odkaz:
http://www.bleepingcomputer.com/downloa ... scan-tool/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
OTAS
Level 3
Level 3
Příspěvky: 484
Registrován: červenec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod OTAS » 04 pro 2022 20:23

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-12-2022
Ran by Otto (04-12-2022 20:18:33)
Running from C:\Users\Otto\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X64) (2017-03-24 17:03:07)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-2781758306-2679381193-3636559717-500 - Administrator - Disabled)
Guest (S-1-5-21-2781758306-2679381193-3636559717-501 - Limited - Disabled)
Otto (S-1-5-21-2781758306-2679381193-3636559717-1000 - Administrator - Enabled) => C:\Users\Otto
UpdatusUser (S-1-5-21-2781758306-2679381193-3636559717-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Disabled - Up to date) {4F76F112-43EB-40E8-11D8-F7BD1853EA23}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Disabled - Up to date) {F41710F6-65D1-4F66-2B68-CCCF63D4A09E}
FW: Kaspersky Internet Security (Disabled) {774D7037-0984-41B0-3A87-5E88E680AD58}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3DYD Youtube Source (HKLM-x32\...\3DYD Youtube Source) (Version: 2.3.1 - 3DYD Soft)
AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky)
Adobe Acrobat Reader - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 22.003.20258 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-001824458876}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Aktualizace NVIDIA 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
ANT Drivers Installer x64 (HKLM\...\{0919C970-C55E-4322-AD6E-D561EC8C01EC}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ANT Drivers Installer x64 (HKLM\...\{7664AF65-7B0D-4171-9F0F-50455278B428}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ANT Drivers Installer x64 (HKLM\...\{99B72734-4395-42D0-ADFD-A9722A7AD7B0}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ANT Drivers Installer x64 (HKLM\...\{AE17953F-B52A-4D8E-8A6A-8409F127E0B4}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ANT Drivers Installer x64 (HKLM\...\{EE89194D-B4FC-4C28-B76E-A646216D689F}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apowersoft Video Konvertor V4.7.2 (HKLM-x32\...\{195E8D7F-292B-4B04-A6E7-E96CAF04C767}_is1) (Version: 4.7.2 - APOWERSOFT LIMITED)
Ashampoo Burning Studio 22 (HKLM-x32\...\Ashampoo Burning Studio 22_is1) (Version: 22.0.8.34 - Ashampoo GmbH & Co. KG)
Audials 2021 (HKLM-x32\...\{58111CE2-683D-4202-985C-27B5992016DA}) (Version: 21.0.94.0 - Audials AG)
Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Balíček ovladače systému Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Bass Audio Decoder (remove only) (HKLM-x32\...\Bass Audio Decoder) (Version: - )
Brother MFL-Pro Suite DCP-J105 (HKLM-x32\...\{B742757A-7658-4E09-A51A-085CF0F7F4D3}) (Version: 1.0.0.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 6.06 - Piriform)
DCoder Image Source (remove only) (HKLM-x32\...\DCoder Image Source) (Version: - )
Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
DirectVobSub (remove only) (HKLM-x32\...\DirectVobSub) (Version: - )
Doplněk Microsoft Save as PDF or XPS pro aplikace sady Microsoft Office 2007 (HKLM-x32\...\{90120000-00B2-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation)
Elevated Installer (HKLM-x32\...\{0794CCAE-DAB3-4FAC-85C2-4B9F5DCCF614}) (Version: 7.15.2.0 - Garmin Ltd or its subsidiaries) Hidden
EZ CD Audio Converter (HKLM-x32\...\EZ CD Audio Converter) (Version: 9.5 - Poikosoft)
FFMPEG Core Files (remove only) (HKLM-x32\...\FFMPEG Core Files) (Version: - )
Garmin BaseCamp (HKLM-x32\...\{a7339a73-aef7-4ce1-963f-e7396ba18511}) (Version: 4.7.4.0 - Garmin Ltd or its subsidiaries)
Garmin BaseCamp (HKLM-x32\...\{B48BC415-D96D-4676-BAB5-66EFDA0D8D7B}) (Version: 4.7.4.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{799EBEC4-CDFD-41D8-904A-4B968C64DF51}) (Version: 7.15.2.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{bde189fe-7f26-4da7-9c02-f68549544aff}) (Version: 7.15.2.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\...\{A336EAA0-135A-4338-B628-BA8DBB3BCA60}) (Version: 6.4.0.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin MapSource (HKLM-x32\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin POI Loader (HKLM-x32\...\{68ca17aa-815c-4a71-8894-39e537ecb526}) (Version: 2.7.3 - Garmin Ltd or its subsidiaries)
Garmin POILoader (HKLM-x32\...\{9EC5D99E-F5E5-4B88-AAAC-EA810E52CD4A}) (Version: 2.7.3 - Garmin Ltd or its subsidiaries) Hidden
Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 51.0.14.0 - Google LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 108.0.5359.95 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - )
HiSuite (HKLM-x32\...\Hi Suite) (Version: 10.0.0.510 - Huawei Technologies Co., Ltd.)
Inpaint 9.1 (HKLM\...\{5808866F-D115-46B2-8123-BB6801968101}_is1) (Version: - Teorex)
iTubeGo version 6.1.0 (HKLM\...\{0C37FCDD-DADB-4D5D-BA87-46EE769D1607}_is1) (Version: 6.1.0 - LuckyDog Software, Inc.)
Java 8 Update 351 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180351F0}) (Version: 8.0.3510.10 - Oracle Corporation)
Kaspersky Internet Security (HKLM-x32\...\{4FC79BE9-AD63-46C0-9626-E4F6BCE6A976}) (Version: 21.3.10.391 - Kaspersky) Hidden
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{4FC79BE9-AD63-46C0-9626-E4F6BCE6A976}) (Version: 21.3.10.391 - Kaspersky)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky VPN (HKLM-x32\...\{FEA95EF1-A4FE-3E02-B1C8-B79136C3A44A}) (Version: 21.8.5.452 - Kaspersky) Hidden
Kaspersky VPN (HKLM-x32\...\InstallWIX_{FEA95EF1-A4FE-3E02-B1C8-B79136C3A44A}) (Version: 21.8.5.452 - Kaspersky)
LAV Filters 0.76.1 (HKLM-x32\...\lavfilters_is1) (Version: 0.76.1 - Hendrik Leppkes)
MadVR (remove only) (HKLM-x32\...\MadVR) (Version: - )
Malwarebytes version 4.5.18.226 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.18.226 - Malwarebytes)
Microsoft .NET Framework 4.7.2 (CSY) (HKLM\...\{F4C44834-E4FA-3DA9-B999-A30EC54E95B0}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{09CCBE8E-B964-30EF-AE84-6537AB4197F9}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508 (HKLM-x32\...\{6913e92a-b64e-41c9-a5e6-cef39207fe89}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.25.28508 (HKLM-x32\...\{65e650ff-30be-469d-b63a-418d71ea1765}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.25.28508 (HKLM\...\{7D0B74C2-C3F8-4AF1-940F-CD79AB4B2DCE}) (Version: 14.25.28508 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.25.28508 (HKLM\...\{EEA66967-97E2-4561-A999-5C22E3CDE428}) (Version: 14.25.28508 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.25.28508 (HKLM-x32\...\{0FA68574-690B-4B00-89AA-B28946231449}) (Version: 14.25.28508 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.25.28508 (HKLM-x32\...\{2BC3BD4D-FABA-4394-93C7-9AC82A263FE2}) (Version: 14.25.28508 - Microsoft Corporation) Hidden
Microsoft Windows Debugging Symbols (HKLM-x32\...\{46EA439E-2D16-49B6-AA80-00DE992FE7CE}) (Version: 7601 - Microsoft)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 107.0.1 (x64 cs)) (Version: 107.0.1 - Mozilla)
MPC Audio Filters (remove only) (HKLM-x32\...\MPC Audio Filters) (Version: - )
NVIDIA Ovladače grafiky 309.08 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 309.08 - NVIDIA Corporation)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek)
Revo Uninstaller Pro 5.0.7 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.0.7 - VS Revo Group, Ltd.)
RogueKiller version 15.6.3.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 15.6.3.0 - Adlice Software)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.9.0 - Sophos Limited)
VSO ConvertXtoVideo Ultimate 2 (HKLM-x32\...\{{3852A371-F5ED-491A-86C3-998CD0688D4A}_is1) (Version: 2.0.0.92 - VSO Software)
VSO ConvertXtoVideo Ultimate 2.0.0.100 (HKLM-x32\...\VSO ConvertXtoVideo Ultimate_is1) (Version: 2.0.0.100 - lrepacks.ru)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
Zemana AntiMalware verze 3.2.28 (HKLM-x32\...\{4E1F3677-C72E-4F7D-B66E-85467B1A289E}_is1) (Version: 3.2.28 - Zemana)
Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: 17.1 - Inmatrix LTD)
Zoom Player Czech language (remove only) (HKLM-x32\...\ZoomPlayer_Czech) (Version: - )
ZPS 19 CZ (HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\...\{E83AA227-7862-F115-2E87-46DCA9E3D879}) (Version: v.19.2009.2.286 - 02.12.2020 - libbi)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\51.0.14.0\drivefsext.dll [2021-09-08] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\51.0.14.0\drivefsext.dll [2021-09-08] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\51.0.14.0\drivefsext.dll [2021-09-08] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\51.0.14.0\drivefsext.dll [2021-09-08] (Google LLC -> Google, Inc.)
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2021-03-30] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers1: [DriveFS 28 or later] -> [CC]{EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers1: [EzCd] -> [CC]{E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => -> No File
ContextMenuHandlers1: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\x64\shellex.dll [2022-02-16] (AO Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers2: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\x64\shellex.dll [2022-02-16] (AO Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-11-30] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [DriveFS 28 or later] -> [CC]{EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers4: [EzCd] -> [CC]{E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => -> No File
ContextMenuHandlers4: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\x64\shellex.dll [2022-02-16] (AO Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [ZPShellExt] -> [CC]{ABE00001-0123-ABED-1248-0248ADFA1909} => -> No File
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\51.0.14.0\drivefsext.dll [2021-09-08] (Google LLC -> Google, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2015-01-31] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2021-03-30] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers6: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\x64\shellex.dll [2022-02-16] (AO Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-11-30] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [RUShellExt] -> [CC]{2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => -> No File
ContextMenuHandlers6: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2017-03-26 01:12 - 2005-04-22 05:36 - 000143360 ____R () [File not signed] C:\Windows\system32\BrSNMP64.dll
2017-12-17 19:16 - 2012-10-19 13:02 - 000087040 ____R (Brother Industries, Ltd.) [File not signed] C:\Windows\system32\BrNetSti.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:D735933A [128]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Version 11) (Whitelisted) ==========

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_351\bin\ssv.dll [2022-12-04] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_351\bin\jp2ssv.dll [2022-12-04] (Oracle America, Inc. -> Oracle Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2020-01-28 21:24 - 2022-12-03 21:33 - 000000925 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 license.piriform.com
127.0.0.1 www.license.piriform.com

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\ProgramData\Oracle\Java\javapath;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Acronis\VirtualFile;C:\Program Files (x86)\Common Files\Acronis\VirtualFile64;C:\Program Files (x86)\Common Files\Acronis\SnapAPI;C:\Program Files\RogueKiller;
HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Otto\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 31.30.90.11 - 31.30.90.12
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\startupreg: Adobe Reader Synchronizer => "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe"
MSCONFIG\startupreg: AudialsNotifier => C:\Program Files (x86)\Audials\Audials 2021\AudialsNotifier.exe
MSCONFIG\startupreg: BrHelp => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe /AUTORUN
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: CCleaner Smart Cleaning => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: GarminExpress => "C:\Program Files (x86)\Garmin\Express\express.exe" /minimized
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: GoogleDriveFS => C:\Program Files\Google\Drive File Stream\51.0.14.0\GoogleDriveFS.exe --startup_mode
MSCONFIG\startupreg: SunJavaUpdateSched => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{AEB25413-11C6-47F7-9D58-838C5731CDC5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{6B366BD7-1EDC-4330-9B79-59545B3E4F15}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{4CEF0E7E-6D09-440C-BF97-702649B8BFAC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F5D17C64-42FC-4842-86EF-758295DD3CBB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{940B0368-E343-417D-90A9-66F16E3669A0}] => (Allow) LPort=54925
FirewallRules: [TCP Query User{13D2238A-F40C-412E-BBBD-74859E2D8017}C:\users\otto\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\otto\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [UDP Query User{72F976B0-20B4-40C2-8748-73129E25C2F7}C:\users\otto\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\otto\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [{34632808-E6E9-4539-A56A-34BA37EFE731}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Converter Studio\Video Converter Studio.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [{150E5750-8091-4099-90CF-B81B6B684F5D}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Converter Studio\Video Converter Studio.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [TCP Query User{EF5C1776-B958-4424-B8D8-16855E36E570}C:\users\otto\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\otto\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [UDP Query User{331EA9A8-7C1B-448C-AA3C-BF082C9330C1}C:\users\otto\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\otto\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [{DB2C4F1F-13F0-4123-9B63-091240DC6520}] => (Allow) C:\Users\Otto\AppData\Roaming\uTorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [{EAD0E95B-0EBA-4956-B4A9-33F1331740D1}] => (Allow) C:\Users\Otto\AppData\Roaming\uTorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [{EF643B85-0B1F-490C-A6A4-05A2C0EDB894}] => (Allow) LPort=12972
FirewallRules: [{E9BD3630-96B8-4C8A-A11D-B247E25C1E96}] => (Allow) LPort=14714
FirewallRules: [{42BE3305-AC62-44E2-B581-07343ED28DA2}] => (Allow) LPort=31931
FirewallRules: [{4DF07354-D9E8-4D89-87D8-9A37221A1CE4}] => (Allow) C:\Program Files (x86)\Audials\Audials 2021\Audials.exe (Audials AG -> Audials AG)
FirewallRules: [{AC9119C0-4A3A-48E6-BEBF-3E3983C19825}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{74DA3BCB-FA80-4A6D-9C46-6610AE093268}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8E6FBCAA-D053-4954-80F2-B3D74F2D6E63}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A61C6B84-EFE6-4128-B5F1-9A9E29F113BC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{82C2064D-BD20-4AF0-B28D-E2C6D98775DE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

27-11-2022 21:26:39 Installed 4K Video Downloader
29-11-2022 17:26:11 Operace obnovení
03-12-2022 01:13:16 JRT Pre-Junkware Removal
03-12-2022 01:23:13 Installed Sophos Virus Removal Tool.
03-12-2022 16:05:07 Garmin Express
03-12-2022 17:42:06 zoek.exe restore point
03-12-2022 19:59:27 Removed 4K Video Downloader

==================== Faulty Device Manager Devices ============

Name: ZAM Helper Driver
Description: ZAM Helper Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: ZAM
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: ZAM Guard Driver
Description: ZAM Guard Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: ZAM_Guard
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: ========================

Application errors:
==================
Error: (12/03/2022 09:02:23 PM) (Source: AntiMalware) (EventID: 0) (User: )
Description: Application has encountered a problem and needs to be closed. Please contact the adminstrator with the following information:

System.NullReferenceException: Odkaz na objekt není nastaven na instanci objektu.
v Zemana.AntiMalware.UI.Dialogs.dlgList.btnSend_Click(Object sender, EventArgs e) v Z:\Projects\Zemana AntiMalware Staging\Zemana.AntiMalware.UI\Dialogs\dlgList.cs:řádek 72
v System.Windows.Forms.Control.OnClick(EventArgs e)
v System.Windows.Forms.Button.OnClick(EventArgs e)
v System.Windows.Forms.Button.OnMouseUp(MouseEventArgs mevent)
v System.Windows.Forms.Control.WmMouseUp(Message& m, MouseButtons button, Int32 clicks)
v System.Windows.Forms.Control.WndProc(Message& m)
v System.Windows.Forms.ButtonBase.WndProc(Message& m)
v System.Windows.Forms.Button.WndProc(Message& m)
v System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
v System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
v System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)Odkaz na objekt není nastaven na instanci objektu.

Stack Trace:
v Zemana.AntiMalware.UI.Dialogs.dlgList.btnSend_Click(Object sender, EventArgs e) v Z:\Projects\Zemana AntiMalware Staging\Zemana.AntiMalware.UI\Dialogs\dlgList.cs:řádek 72
v System.Windows.Forms.Control.OnClick(EventArgs e)
v System.Windows.Forms.Button.OnClick(EventArgs e)
v System.Windows.Forms.Button.OnMouseUp(MouseEventArgs mevent)
v System.Windows.Forms.Control.WmMouseUp(Message& m, MouseButtons button, Int32 clicks)
v System.Windows.Forms.Control.WndProc(Message& m)
v System.Windows.Forms.ButtonBase.WndProc(Message& m)
v System.Windows.Forms.Button.WndProc(Message& m)
v System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
v System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
v System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)

Error: (11/29/2022 09:07:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program utorrent.exe verze 2.2.1.25534 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 1078

Čas spuštění: 01d9042e07926309

Čas ukončení: 3

Cesta k aplikaci: C:\Users\Otto\AppData\Roaming\uTorrent\utorrent.exe

ID hlášení: 7d970886-7021-11ed-b32d-50465d8f71a5

Error: (11/29/2022 05:34:57 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Během obnovení systému došlo k nespecifikované chybě: (Naplánovaný kontrolní bod). Další informace: 0x80070005.

Error: (11/27/2022 08:46:52 PM) (Source: MsiInstaller) (EventID: 10005) (User: Otto-PC)
Description: Product: 4K Video Downloader -- Another version of this product is already installed. Installation of this version cannot continue. To remove the existing version of this product, use Add/Remove Programs on the Control Panel.

Error: (11/27/2022 08:43:27 PM) (Source: MsiInstaller) (EventID: 10005) (User: Otto-PC)
Description: Product: 4K Video Downloader -- Another version of this product is already installed. Installation of this version cannot continue. To remove the existing version of this product, use Add/Remove Programs on the Control Panel.

Error: (11/17/2022 07:56:30 PM) (Source: ESENT) (EventID: 454) (User: )
Description: taskhost (2396) WebCacheLocal: Při zotavení či obnovení databáze došlo k neočekávané chybě -551.

Error: (11/17/2022 07:56:30 PM) (Source: ESENT) (EventID: 517) (User: )
Description: taskhost (2396) WebCacheLocal: Obnovení databáze se nezdařilo a došlo k chybě -551, protože byly zjištěny odkazy na databázi C:\Users\Otto\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat, která se neshoduje s aktuální sadou protokolů. Databázový stroj nepovolí dokončení obnovení pro tuto instanci, dokud nebude znovu vytvořena instance neshodné databáze. Pokud databáze již skutečně není k dispozici nebo není již nadále požadována, získáte pokyny týkající se odstranění této chyby ve znalostní bázi Microsoft Knowledge Base nebo po klepnutí na odkaz Další informace na konci této zprávy.

Error: (11/17/2022 07:56:29 PM) (Source: ESENT) (EventID: 465) (User: )
Description: taskhost (2396) WebCacheLocal: Při částečném obnovení byl zjištěn poškozený soubor protokolu C:\Users\Otto\AppData\Local\Microsoft\Windows\WebCache\V01.log. Záznam s chybou kontrolního součtu je umístěn na pozici END. Data neodpovídající záznamům protokolu se poprvé vyskytla v sektoru 690 (0x000002B2). Soubor je poškozený a nelze jej použít.


System errors:
=============
Error: (12/04/2022 08:22:36 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {BB6DF56B-CACE-11DC-9992-0019B93A3A84} se v daném časovém limitu neregistroval u služby DCOM.

Error: (12/04/2022 07:48:10 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.

Error: (12/04/2022 12:30:27 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.

Error: (12/03/2022 09:37:39 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby rkrtservice bylo dosaženo časového limitu (30000 ms).

Error: (12/03/2022 08:28:56 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby ShellHWDetection bylo dosaženo časového limitu (30000 ms).

Error: (12/03/2022 07:48:43 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Windows Update přestala během spouštění reagovat.

Error: (12/03/2022 07:48:37 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.

Error: (12/03/2022 06:07:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.


Windows Defender:
================
Date: 2021-04-25 12:49:26.119
Description:
Prohledávání Windows Defender bylo zastaveno před dokončením.
ID prohledávání:{B7EB0232-E5B9-4BF1-978C-48FA9D47921D}
Typ prohledávání:Antispywarový program
Parametry prohledávání:Rychlé prohledávání
Uživatel:Otto-PC\Otto

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0702 08/15/2012
Motherboard: ASUSTeK COMPUTER INC. P8H61-MX R2.0
Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 81%
Total physical RAM: 4047.84 MB
Available physical RAM: 756.07 MB
Total Virtual: 8093.83 MB
Available Virtual: 3111.16 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:133.63 GB) (Model: WDC WD5000AAKX-00ERMA0 ATA Device) NTFS

\\?\Volume{180fac7c-10b3-11e7-a0d5-806e6f6e6963}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 4965A0C3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================

OTAS
Level 3
Level 3
Příspěvky: 484
Registrován: červenec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod OTAS » 04 pro 2022 20:25

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-12-2022
Ran by Otto (administrator) on OTTO-PC (04-12-2022 20:17:03)
Running from C:\Users\Otto\Desktop
Loaded Profiles: Otto
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avp.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avpui.exe
(C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.8\ksde.exe ->) (AO Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.8\ksdeui.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\51.0.14.0\crashpad_handler.exe <2>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <15>
(nvvsvc.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avp.exe
(services.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.8\ksde.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
(services.exe ->) (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(taskeng.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe
(Zemana D.O.O. Sarajevo -> Zemana Ltd.) C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [711288 2022-09-15] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\51.0.14.0\GoogleDriveFS.exe [54124376 2021-09-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\51.0.14.0\GoogleDriveFS.exe [54124376 2021-09-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [38650192 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\Software\Policies\...\system: [disablecmd] 0
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\51.0.14.0\GoogleDriveFS.exe [54124376 2021-09-08] (Google LLC -> Google, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.95\Installer\chrmstp.exe [2022-12-03] (Google LLC -> Google LLC)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {03724753-82E9-45E1-B529-FAAF2ED458DC} - System32\Tasks\{12C882F2-52B0-4A7B-B896-9684C619C21F} => C:\Windows\system32\pcalua.exe -a "C:\Users\Otto\Desktop\CCleaner v.5.86.9258.exe" -d C:\Users\Otto\Desktop
Task: {0B761F03-206B-4693-82D2-243E3A8FBE43} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [29464 2022-11-03] (Garmin International, Inc. -> )
Task: {0C6FB184-16B6-4016-B929-E5D17924CF26} - System32\Tasks\{B3C392F5-C8C3-4C3C-8804-C840AFCE3810} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Task: {21389857-41C3-4C93-A1A1-F0F91A8B93A1} - \Microsoft\Windows\Management\Provisioning\8X9JmlVg\A22FA271-2F0F-4E4C-BB5D-EA0D8B08EEEB -> No File <==== ATTENTION
Task: {22F242C7-D481-4B6B-A139-13A698054B56} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe do-task "E7CF176E110C211B"
Task: {284D8FF2-F281-4A92-970F-87BA553794A0} - System32\Tasks\{F17D40F3-F484-4A50-8394-0EF545CAF746} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Task: {31B09697-86A1-4C6B-81E8-1C1C75245794} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe (No File)
Task: {3505291A-3A3F-4BE9-A45C-85B01C9DBE97} - System32\Tasks\AMHelper => C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe [682008 2021-03-30] (Zemana D.O.O. Sarajevo -> Zemana Ltd.)
Task: {4694D277-A408-412E-9796-6FCA837CFAD9} - System32\Tasks\CCleanerClean => C:\Program Files\CCleaner\CCleaner.exe [32325456 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {68F9F56F-F408-40E1-ACFF-925C8DFBCCB7} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-11-09] (Piriform Software Ltd -> Piriform)
Task: {8084A906-269D-4BCB-97B5-DCE48E862A79} - System32\Tasks\{BF90ADD3-4D64-4738-AA62-2C958541C62B} => C:\Windows\system32\pcalua.exe -a "C:\Users\Otto\Downloads\ZPS 19 CZ_SK\ZPS 19 CZ v.19.2004.2.262.exe" -d "C:\Users\Otto\Downloads\ZPS 19 CZ_SK"
Task: {81170E89-96F9-468D-92A0-34F1DFE51EA9} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "e6a1ecc5-04f9-4dae-a99e-c6955e4f6baa" --version "6.06.10144" --silent
Task: {85A680D3-B2AD-4CDE-943C-1D83D4BFBF43} - System32\Tasks\kpm_tray.exe => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe [622168 2021-03-20] (Kaspersky Lab JSC -> AO Kaspersky Lab)
Task: {9C1BC15C-96E6-4F3E-AB3E-1777C257F488} - System32\Tasks\{D43AA914-4C04-4A51-BCEB-9D2B1A3A847D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\DVDFab\uninstall.exe" -d "C:\Program Files (x86)\DVDFab"
Task: {A383FBAE-81E0-4970-92B3-0C089EBEBF42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
Task: {A4F5FB34-082F-4C90-8ACE-8FC79E9BC358} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
Task: {A8DAEB0D-77C0-49AE-8679-0B0C48A1D5AF} - System32\Tasks\{15EA5419-0BAF-4C27-943A-3645E7C9AFE4} => C:\Program Files (x86)\Microsoft Office\Office12\excelcnv.exe [14674216 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {BBE02732-D4C7-47C3-B654-4948B7850C8E} - System32\Tasks\{D9380227-5EEA-44A8-8744-4ABA6333C488} => C:\Windows\system32\pcalua.exe -a "C:\Users\Otto\Desktop\CCleaner v.5.86.9258.exe" -d C:\Users\Otto\Desktop
Task: {BF5A7B5B-19AD-4948-ABD8-48DA07F5852A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {C928B3DC-CEC5-464B-94F5-63AB7DD5009E} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [743488 2021-04-24] (Kaspersky Lab JSC -> AO Kaspersky Lab)
Task: {D52220CF-7FB8-46BB-A6DF-D9F866FFCE33} - System32\Tasks\CCleanerSkipUAC - Otto => C:\Program Files\CCleaner\CCleaner.exe [32325456 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {D877DBCC-96FD-4517-BC3D-C000C6D4557B} - System32\Tasks\AMSkipUAC => C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe [682008 2021-03-30] (Zemana D.O.O. Sarajevo -> Zemana Ltd.)
Task: {E0118AE4-E7C2-402D-8E1C-43F23669650A} - System32\Tasks\{8A4276CB-6FDF-4C33-BE3A-ED4F008DFEA5} => C:\Program Files (x86)\Microsoft Office\Office12\excelcnv.exe [14674216 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {E775CC9C-0E57-4CD1-B042-6202513E7026} - System32\Tasks\Mozilla\Firefox Background Update E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\E7CF176E110C211B\backgroundupdate.moz_log --backgroundtask backgroundupdate

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CCleanerClean.job => C:\Program Files\CCleaner\CCleaner.exe
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{01C3FF8A-351D-4688-A431-728EF9387B19}: [DhcpNameServer] 31.30.90.11 31.30.90.12
Tcpip\..\Interfaces\{0D0B23C0-6C35-474E-8175-7C25C02CFEA3}: [NameServer] 198.51.100.1,198.51.100.2

FireFox:
========
FF DefaultProfile: henbtv06.default-1537355602383
FF ProfilePath: C:\Users\Otto\AppData\Roaming\Mozilla\Firefox\Profiles\henbtv06.default-1537355602383 [2022-12-04]
FF Homepage: Mozilla\Firefox\Profiles\henbtv06.default-1537355602383 -> about:home|hxxps://www.seznam.cz/
FF NewTab: Mozilla\Firefox\Profiles\henbtv06.default-1537355602383 -> about:newtab
FF Notifications: Mozilla\Firefox\Profiles\henbtv06.default-1537355602383 -> hxxps://www.tipsport.cz
FF Extension: (Google Translator for Firefox) - C:\Users\Otto\AppData\Roaming\Mozilla\Firefox\Profiles\henbtv06.default-1537355602383\Extensions\translator@zoli.bod.xpi [2018-12-08]
FF Extension: (Private Video Downloader) - C:\Users\Otto\AppData\Roaming\Mozilla\Firefox\Profiles\henbtv06.default-1537355602383\Extensions\{b9a672d6-0a2c-470e-9bed-1ca2e2a900c5}.xpi [2022-11-07]
FF Extension: (Video DownloadHelper) - C:\Users\Otto\AppData\Roaming\Mozilla\Firefox\Profiles\henbtv06.default-1537355602383\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-11-15]
FF Plugin: @java.com/DTPlugin,version=11.351.2 -> C:\Program Files\Java\jre1.8.0_351\bin\dtplugin\npDeployJava1.dll [2022-12-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.351.2 -> C:\Program Files\Java\jre1.8.0_351\bin\plugin2\npjp2.dll [2022-12-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-09-28] (Adobe Inc. -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2021-04-13] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2021-04-13] <==== ATTENTION

Chrome:
=======
CHR Profile: C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default [2022-12-04]
CHR Notifications: Default -> hxxps://www.plnapenezenka.cz; hxxps://www.youtube.com
CHR HomePage: Default -> hxxps://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Extension: (Překladač Google) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2022-12-03]
CHR Extension: (Ochrana Kaspersky) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2022-12-03]
CHR Extension: (Tipli do prohlížeče) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfnbehhjknomdbfhcobpgpphnlnikp [2022-12-03]
CHR Extension: (Plná Peněženka Lištička) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecmgkhgjmodembdmiimbacpjgcdimiek [2022-12-03]
CHR Extension: (Adobe Acrobat: nástroje pro úpravu, převod a podpis souborů PDF) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-12-03]
CHR Extension: (Hamty.cz doplněk) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\gccfnphpieojibjmnodiiobdapckkkfb [2022-12-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-12-03]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2022-12-03]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Otto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-12-03]
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/deta ... fdlnjdpcdm
CHR HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/deta ... fdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
S3 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [4463960 2017-12-05] (Acronis International GmbH -> Acronis)
R2 AVP21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avp.exe [184768 2021-06-17] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [321536 2021-08-20] (Brother Industries, Ltd.) [File not signed]
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1003344 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2019-10-31] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S3 klvssbridge64_21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\x64\vssbridge64.exe [479280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [357272 2021-03-20] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 KSDE5.8; C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.8\ksde.exe [32008 2022-10-13] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8872736 2022-11-30] (Malwarebytes Inc. -> Malwarebytes)
S4 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [14715824 2022-11-15] (ADLICE -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aftap0901; C:\Windows\System32\DRIVERS\aftap0901.sys [48624 2018-06-15] (AnchorFree Inc -> The OpenVPN Project)
R1 amsdk; C:\Windows\system32\drivers\amsdk.sys [232792 2022-12-03] (Zemana D.O.O. Sarajevo -> Copyright 2018.)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 file_tracker; C:\Windows\System32\DRIVERS\file_tracker.sys [339808 2017-12-05] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R0 fltsrv; C:\Windows\System32\DRIVERS\fltsrv.sys [160600 2017-12-05] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R1 googledrivefs3525; C:\Windows\System32\DRIVERS\googledrivefs3525.sys [382944 2021-08-09] (Google LLC -> Google, Inc.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 int0800; C:\Windows\System32\DRIVERS\flashud.sys [51712 2009-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [644320 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klflt; C:\Windows\System32\DRIVERS\klflt.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klgse; C:\Windows\System32\DRIVERS\klgse.sys [657696 2021-03-15] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [1400600 2021-03-15] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [176864 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klim6; C:\Windows\System32\DRIVERS\klim6.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kltap; C:\Windows\System32\DRIVERS\kltap.sys [55592 2022-10-13] (AnchorFree Inc -> The OpenVPN Project)
R1 klwfp; C:\Windows\System32\DRIVERS\klwfp.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [78560 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [223176 2022-11-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2022-11-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 npf; C:\Windows\system32\drivers\npf.sys [36600 2017-01-02] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1049432 2017-12-05] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R2 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [202592 2017-12-05] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
S3 tnd; C:\Windows\System32\DRIVERS\tnd.sys [581464 2017-12-05] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R2 virtual_file; C:\Windows\System32\DRIVERS\virtual_file.sys [301408 2017-12-05] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64_prewin8.sys [31920 2018-02-26] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [159936 2016-08-16] (NGO -> MBB)
R3 kldlfmgr; C:\Windows\System32\Drivers\kldlfmgr.sys [24800 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kldlfwpk; C:\Windows\System32\Drivers\kldlfwpk.sys [24800 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 Kldlimpc; C:\Windows\System32\Drivers\Kldlimpc.sys [2524896 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kldlksec; C:\Windows\System32\Drivers\kldlksec.sys [24800 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kldlksl; C:\Windows\System32\Drivers\kldlksl.sys [24800 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kldlndis; C:\Windows\System32\Drivers\kldlndis.sys [24800 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kldlnio; C:\Windows\System32\Drivers\kldlnio.sys [24800 2022-02-16] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-12-04 20:17 - 2022-12-04 20:18 - 000022360 _____ C:\Users\Otto\Desktop\FRST.txt
2022-12-04 20:15 - 2022-12-04 20:17 - 000000000 ____D C:\FRST
2022-12-04 20:12 - 2022-12-04 20:13 - 002375680 _____ (Farbar) C:\Users\Otto\Desktop\FRST64.exe
2022-12-04 13:06 - 2022-12-04 13:06 - 000000000 ____D C:\Users\Otto\AppData\Roaming\Sun
2022-12-04 13:05 - 2022-12-04 13:05 - 000195232 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2022-12-04 13:05 - 2022-12-04 13:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2022-12-03 21:45 - 2022-12-03 21:45 - 000003032 _____ C:\Users\Otto\Documents\cc_20221203_214530.reg
2022-12-03 21:25 - 2022-12-03 21:25 - 000009839 _____ C:\Users\Otto\Downloads\[SkT]CCleaner_Professional_Edition_6.06.10144_(x64) (1).torrent
2022-12-03 20:58 - 2022-12-04 19:58 - 000002500 _____ C:\Windows\system32\Tasks\AMSkipUAC
2022-12-03 20:58 - 2022-12-04 19:58 - 000000000 ____D C:\Users\Otto\AppData\Local\AMSDK
2022-12-03 20:58 - 2022-12-03 20:58 - 000232792 _____ (Copyright 2018.) C:\Windows\system32\Drivers\amsdk.sys
2022-12-03 20:58 - 2022-12-03 20:58 - 000003472 _____ C:\Windows\system32\Tasks\AMHelper
2022-12-03 20:58 - 2022-12-03 20:58 - 000001260 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2022-12-03 20:58 - 2022-12-03 20:58 - 000000000 ____D C:\Users\Otto\AppData\Local\Zemana
2022-12-03 20:58 - 2022-12-03 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2022-12-03 20:58 - 2022-12-03 20:58 - 000000000 ____D C:\Program Files (x86)\Zemana
2022-12-03 20:57 - 2022-12-03 20:58 - 013922376 _____ (Zemana Ltd. ) C:\Users\Otto\Downloads\Zemana.AntiMalware.Setup.exe
2022-12-03 20:41 - 2022-12-03 20:53 - 000000000 ____D C:\Users\Otto\AppData\Local\iTubeGo
2022-12-03 20:38 - 2022-12-03 20:49 - 000000000 ____D C:\Program Files\iTubeGo
2022-12-03 20:38 - 2022-12-03 20:38 - 000000768 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTubeGo.lnk
2022-12-03 20:38 - 2022-12-03 20:38 - 000000756 _____ C:\Users\Public\Desktop\iTubeGo.lnk
2022-12-03 19:38 - 2022-12-03 21:26 - 000000000 ____D C:\Users\Otto\Downloads\Traktor - Discography
2022-12-03 18:44 - 2022-12-03 18:44 - 003875028 _____ C:\Users\Otto\Documents\záložky_03.12.22.html
2022-12-03 18:01 - 2014-02-13 23:59 - 000024064 _____ C:\Windows\zoek-delete.exe
2022-12-03 17:36 - 2022-12-03 17:56 - 000000000 ____D C:\zoek_backup
2022-12-03 16:09 - 2022-12-03 16:09 - 000001890 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2022-12-03 16:03 - 2022-12-03 16:03 - 000000000 ____D C:\Users\Otto\AppData\Local\CEF
2022-12-03 11:06 - 2022-12-03 13:03 - 000000000 ____D C:\ProgramData\RogueKiller
2022-12-03 11:05 - 2022-12-03 11:05 - 000000818 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2022-12-03 11:05 - 2022-12-03 11:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2022-12-03 11:05 - 2022-12-03 11:05 - 000000000 ____D C:\Program Files\RogueKiller
2022-12-03 11:03 - 2022-12-03 11:04 - 044673144 _____ (Adlice Software ) C:\Users\Otto\Desktop\RogueKiller_setup.exe
2022-12-03 10:42 - 2022-12-03 10:42 - 343262493 _____ C:\Users\Otto\Downloads\freevideo.cz-pane-doktore-ja-mam-ukrutne-malou-vaginu-720p.mp4
2022-12-03 01:24 - 2022-12-03 01:24 - 000002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2022-12-03 01:24 - 2022-12-03 01:24 - 000000000 ____D C:\ProgramData\Sophos
2022-12-03 01:24 - 2022-12-03 01:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2022-12-03 01:24 - 2022-12-03 01:24 - 000000000 ____D C:\Program Files (x86)\Sophos
2022-12-03 01:19 - 2022-12-03 01:21 - 185115928 _____ (Sophos Limited) C:\Users\Otto\Desktop\Sophos Virus Removal Tool.exe
2022-12-03 01:12 - 2022-12-03 01:12 - 001790024 _____ (Malwarebytes) C:\Users\Otto\Downloads\JRT.exe
2022-12-03 00:58 - 2022-12-03 00:58 - 000448512 _____ (OldTimer Tools) C:\Users\Otto\Desktop\TFC.exe
2022-12-03 00:49 - 2022-12-03 00:49 - 008791352 _____ (Malwarebytes) C:\Users\Otto\Desktop\adwcleaner(1).exe
2022-12-02 22:40 - 2022-12-02 22:41 - 000046763 _____ C:\Users\Otto\Downloads\Traktor - Discography 2004 2021 - Metal-Tracker.com.torrent
2022-11-30 14:45 - 2022-11-30 14:45 - 000000000 ____D C:\Users\Otto\AppData\Local\mbam
2022-11-30 14:44 - 2022-11-30 14:44 - 000239544 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2022-11-30 14:44 - 2022-11-30 14:44 - 000223176 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2022-11-30 14:44 - 2022-11-30 14:44 - 000001920 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2022-11-30 14:44 - 2022-11-30 14:44 - 000001908 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2022-11-30 14:43 - 2022-11-30 14:42 - 000158640 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2022-11-30 14:42 - 2022-11-30 14:42 - 000000000 ____D C:\ProgramData\Malwarebytes
2022-11-30 14:42 - 2022-11-30 14:42 - 000000000 ____D C:\Program Files\Malwarebytes
2022-11-30 14:41 - 2022-11-30 14:42 - 002632256 _____ (Malwarebytes) C:\Users\Otto\Downloads\MBSetup-6CB140DD.exe
2022-11-30 14:37 - 2022-12-03 00:51 - 000000000 ____D C:\AdwCleaner
2022-11-30 14:36 - 2022-11-30 14:36 - 008551608 _____ (Malwarebytes) C:\Users\Otto\Desktop\AdwCleaner.exe
2022-11-30 13:47 - 2022-11-30 13:48 - 000050688 _____ (Atribune.org) C:\Users\Otto\Downloads\ATF-Cleaner.exe
2022-11-29 21:07 - 2022-12-02 22:57 - 000000000 ____D C:\Users\Otto\Downloads\Microsoft Office 2007 CZ full
2022-11-29 21:06 - 2022-11-29 21:06 - 000011540 _____ C:\Users\Otto\Downloads\[SkT]Microsoft_Office_2007_CZ_full.torrent
2022-11-29 21:01 - 2022-11-29 21:01 - 000021582 _____ C:\Users\Otto\Downloads\[SkT]Microsoft_Office_2007_Portable_(Word_ _Excel)(Win7_fix).torrent
2022-11-29 20:51 - 2022-11-29 20:51 - 000027202 _____ C:\Users\Otto\Downloads\[SkT]Microsoft_Office_2016_Profesional_Plus_Final_16.0.4266.1001_VL_(x86_x64)(CZ)(2015).torrent
2022-11-29 20:22 - 2022-11-29 20:22 - 000388608 _____ (Trend Micro Inc.) C:\Users\Otto\Desktop\HijackThis.exe
2022-11-29 19:41 - 2022-12-03 16:13 - 000002986 _____ C:\Windows\system32\Tasks\{8A4276CB-6FDF-4C33-BE3A-ED4F008DFEA5}
2022-11-29 19:41 - 2022-12-03 16:13 - 000002986 _____ C:\Windows\system32\Tasks\{15EA5419-0BAF-4C27-943A-3645E7C9AFE4}
2022-11-29 18:09 - 2022-11-29 18:09 - 000116224 _____ C:\Users\Otto\Downloads\Cestovní náhrady Řijen .2022.xls
2022-11-27 21:25 - 2022-11-27 21:25 - 000001708 _____ C:\Users\Otto\Documents\cc_20221127_212542.reg
2022-11-27 20:40 - 2022-11-27 20:40 - 000015523 _____ C:\Users\Otto\Downloads\[SkT]4K_Video_Downloader_4.22.1.5160_(x64).torrent
2022-11-23 20:54 - 2022-11-23 20:54 - 000000908 _____ C:\Users\Otto\Documents\cc_20221123_205414.reg
2022-11-23 20:44 - 2022-11-23 20:44 - 000000000 ____D C:\Users\Otto\Downloads\CCleaner Professional Edition
2022-11-23 20:43 - 2022-11-23 20:43 - 000009839 _____ C:\Users\Otto\Downloads\[SkT]CCleaner_Professional_Edition_6.06.10144_(x64).torrent
2022-11-20 21:40 - 2022-11-04 11:08 - 000000000 ____D C:\Users\Otto\Downloads\Firewind - Between Heaven And Hell Remastered (2022)
2022-11-20 21:13 - 2022-11-20 21:14 - 000000000 ____D C:\Users\Otto\Downloads\Iron Savior 2022 - Reforged - Ironbound (2CD)
2022-11-20 21:12 - 2022-11-20 21:12 - 000059944 _____ C:\Users\Otto\Downloads\Iron Savior - Discography 1997 2022 - Metal-Tracker.com.torrent
2022-11-17 19:43 - 2022-11-27 13:34 - 000000280 _____ C:\Windows\Tasks\CCleanerClean.job
2022-11-17 19:43 - 2022-11-23 20:54 - 000003016 _____ C:\Windows\system32\Tasks\CCleanerClean
2022-11-11 19:04 - 2022-11-23 20:54 - 000003350 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2022-11-11 19:03 - 2022-11-27 13:34 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2022-11-10 21:03 - 2022-11-10 21:03 - 000002209 _____ C:\Users\Otto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk
2022-11-04 17:46 - 2022-11-04 17:46 - 000019921 _____ C:\Users\Otto\Downloads\Grave Digger - Symbol of Eternity - Metal-Tracker.com.torrent
2022-11-04 17:46 - 2022-11-04 17:46 - 000000000 ____D C:\Users\Otto\Downloads\Grave Digger - Symbol Of Eternity (2022)

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-12-04 20:18 - 2018-02-28 19:27 - 000297999 _____ C:\Windows\ZAM.krnl.trace
2022-12-04 20:00 - 2009-07-14 05:45 - 000020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-12-04 20:00 - 2009-07-14 05:45 - 000020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-12-04 19:49 - 2022-05-14 07:09 - 000000000 ____D C:\Program Files\CCleaner
2022-12-04 19:44 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-12-04 13:04 - 2019-10-19 18:48 - 000000000 ____D C:\Program Files\Java
2022-12-04 12:42 - 2017-04-20 17:44 - 000000000 ____D C:\Program Files (x86)\Google
2022-12-04 12:36 - 2018-09-17 12:29 - 000000000 ____D C:\ProgramData\Zoom Player
2022-12-03 21:31 - 2017-03-25 21:03 - 000000000 ____D C:\Users\Otto\AppData\Roaming\uTorrent
2022-12-03 20:30 - 2022-08-02 19:01 - 000004128 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-12-03 19:43 - 2022-02-18 20:43 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2022-12-03 18:44 - 2017-03-25 16:41 - 000000000 ____D C:\Users\Otto\AppData\LocalLow\Mozilla
2022-12-03 18:38 - 2022-02-11 13:12 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-12-03 18:37 - 2021-10-16 13:52 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-12-03 17:56 - 2017-03-24 18:03 - 000000000 ____D C:\Users\Otto
2022-12-03 16:21 - 2018-06-14 16:50 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-12-03 16:21 - 2018-06-14 16:50 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-12-03 16:13 - 2017-03-27 19:34 - 000003554 _____ C:\Windows\system32\Tasks\GarminUpdaterTask
2022-12-03 16:09 - 2017-03-27 19:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2022-12-03 16:09 - 2017-03-27 19:35 - 000000000 ____D C:\ProgramData\Garmin
2022-12-03 16:09 - 2017-03-27 19:35 - 000000000 ____D C:\Program Files (x86)\Garmin
2022-12-02 10:03 - 2022-01-21 21:14 - 000000879 _____ C:\Users\Otto\Desktop\EZ CD Audio Converter.lnk
2022-11-29 19:32 - 2020-06-29 17:43 - 000000000 ____D C:\Users\Otto\Documents\Cestovní náhrady
2022-11-29 19:18 - 2020-12-28 12:59 - 000117248 _____ C:\Users\Otto\Desktop\Cestovní náhrady Listopad. 2022.xls
2022-11-29 17:53 - 2022-06-28 12:23 - 000040448 _____ C:\Users\Otto\Desktop\Náhrada jízdních výdajů (AUV) 2022 _ Žofka.xls
2022-11-29 17:33 - 2018-09-17 12:29 - 000000000 ____D C:\Program Files (x86)\LAV Filters
2022-11-29 17:33 - 2018-09-17 12:29 - 000000000 ____D C:\Program Files (x86)\Bass Audio Decoder
2022-11-29 17:33 - 2017-05-08 12:46 - 000000000 ____D C:\Program Files\Defraggler
2022-11-29 17:32 - 2022-05-14 07:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2022-11-29 17:32 - 2018-09-17 12:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoom Player
2022-11-29 17:32 - 2018-09-17 12:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LAV Filters
2022-11-29 17:32 - 2018-09-17 12:29 - 000000000 ____D C:\Program Files (x86)\Zoom Player
2022-11-29 17:32 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\registration
2022-11-29 17:32 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2022-11-27 21:54 - 2017-03-25 16:46 - 000000000 ____D C:\Users\Otto\AppData\Local\ElevatedDiagnostics
2022-11-23 21:01 - 2022-05-14 07:11 - 000002804 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC - Otto
2022-11-23 20:51 - 2022-05-14 07:12 - 000000000 ____D C:\ProgramData\Piriform
2022-11-23 20:50 - 2022-05-14 07:09 - 000000782 _____ C:\Users\Public\Desktop\CCleaner.lnk
2022-11-17 19:39 - 2009-07-14 06:08 - 000032614 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2022-11-11 21:11 - 2022-09-24 17:14 - 000000000 ____D C:\Users\Otto\Downloads\Roxor - Než skončí show 2020
2022-11-06 18:49 - 2022-09-01 13:59 - 000000000 ____D C:\Users\Otto\Desktop\HDCamera 1

==================== Files in the root of some directories ========

2017-04-14 16:05 - 2018-09-26 18:16 - 000007859 _____ () C:\Users\Otto\AppData\Roaming\pcouffin.cat
2017-04-14 16:05 - 2018-09-26 18:16 - 000001167 _____ () C:\Users\Otto\AppData\Roaming\pcouffin.inf
2017-04-14 16:05 - 2018-09-26 18:16 - 000082816 _____ (VSO Software) C:\Users\Otto\AppData\Roaming\pcouffin.sys
2021-06-20 14:52 - 2021-06-20 14:52 - 000007605 _____ () C:\Users\Otto\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2022-11-30 14:30
==================== End of FRST.txt ========================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 04 pro 2022 21:13

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CreateRestorePoint:
CloseProcesses:
ContextMenuHandlers1: [DriveFS 28 or later] -> [CC]{EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers1: [EzCd] -> [CC]{E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => -> No File
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers4: [DriveFS 28 or later] -> [CC]{EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers4: [EzCd] -> [CC]{E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => -> No File
ContextMenuHandlers4: [ZPShellExt] -> [CC]{ABE00001-0123-ABED-1248-0248ADFA1909} => -> No File
ContextMenuHandlers6: [RUShellExt] -> [CC]{2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => -> No File
ContextMenuHandlers6: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
AlternateDataStreams: C:\ProgramData\TEMP:D735933A [128]
Task: {21389857-41C3-4C93-A1A1-F0F91A8B93A1} - \Microsoft\Windows\Management\Provisioning\8X9JmlVg\A22FA271-2F0F-4E4C-BB5D-EA0D8B08EEEB -> No File <==== ATTENTION
Task: {A383FBAE-81E0-4970-92B3-0C089EBEBF42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
Task: {A4F5FB34-082F-4C90-8ACE-8FC79E9BC358} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
CHR HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Error: (11/17/2022 07:56:30 PM) (Source: ESENT) (EventID: 454) (User: )
Description: taskhost (2396) WebCacheLocal: Při zotavení či obnovení databáze došlo k neočekávané chybě -551.

Error: (11/17/2022 07:56:30 PM) (Source: ESENT) (EventID: 517) (User: )
Description: taskhost (2396) WebCacheLocal: Obnovení databáze se nezdařilo a došlo k chybě -551, protože byly zjištěny odkazy na databázi C:\Users\Otto\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat, která se neshoduje s aktuální sadou protokolů. Databázový stroj nepovolí dokončení obnovení pro tuto instanci, dokud nebude znovu vytvořena instance neshodné databáze. Pokud databáze již skutečně není k dispozici nebo není již nadále požadována, získáte pokyny týkající se odstranění této chyby ve znalostní bázi Microsoft Knowledge Base nebo po klepnutí na odkaz Další informace na konci této zprávy.

Error: (11/17/2022 07:56:29 PM) (Source: ESENT) (EventID: 465) (User: )
Description: taskhost (2396) WebCacheLocal: Při částečném obnovení byl zjištěn poškozený soubor protokolu C:\Users\Otto\AppData\Local\Microsoft\Windows\WebCache\V01.log. Záznam s chybou kontrolního součtu je umístěn na pozici END. Data neodpovídající záznamům protokolu se poprvé vyskytla v sektoru 690 (0x000002B2). Soubor je poškozený a nelze jej použít.

Stáhni si CrystalDiskInfo
https://www.stahuj.cz/utility_a_ostatni ... ldiskinfo/
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

OTAS
Level 3
Level 3
Příspěvky: 484
Registrován: červenec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod OTAS » 04 pro 2022 22:05

Fix result of Farbar Recovery Scan Tool (x64) Version: 04-12-2022
Ran by Otto (04-12-2022 21:52:26) Run:1
Running from C:\Users\Otto\Desktop
Loaded Profiles: Otto & UpdatusUser
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
ContextMenuHandlers1: [DriveFS 28 or later] -> [CC]{EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers1: [EzCd] -> [CC]{E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => -> No File
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers4: [DriveFS 28 or later] -> [CC]{EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers4: [EzCd] -> [CC]{E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => -> No File
ContextMenuHandlers4: [ZPShellExt] -> [CC]{ABE00001-0123-ABED-1248-0248ADFA1909} => -> No File
ContextMenuHandlers6: [RUShellExt] -> [CC]{2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => -> No File
ContextMenuHandlers6: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
AlternateDataStreams: C:\ProgramData\TEMP:D735933A [128]
Task: {21389857-41C3-4C93-A1A1-F0F91A8B93A1} - \Microsoft\Windows\Management\Provisioning\8X9JmlVg\A22FA271-2F0F-4E4C-BB5D-EA0D8B08EEEB -> No File <==== ATTENTION
Task: {A383FBAE-81E0-4970-92B3-0C089EBEBF42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
Task: {A4F5FB34-082F-4C90-8ACE-8FC79E9BC358} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
CHR HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\DriveFS 28 or later => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\EzCd => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\DriveFS 28 or later => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\EzCd => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ZPShellExt => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\RUShellExt => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 => removed successfully
C:\ProgramData\TEMP => ":D735933A" ADS removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{21389857-41C3-4C93-A1A1-F0F91A8B93A1}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21389857-41C3-4C93-A1A1-F0F91A8B93A1}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Management\Provisioning\8X9JmlVg\A22FA271-2F0F-4E4C-BB5D-EA0D8B08EEEB" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A383FBAE-81E0-4970-92B3-0C089EBEBF42}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A383FBAE-81E0-4970-92B3-0C089EBEBF42}" => removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A4F5FB34-082F-4C90-8ACE-8FC79E9BC358}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4F5FB34-082F-4C90-8ACE-8FC79E9BC358}" => removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
HKU\S-1-5-21-2781758306-2679381193-3636559717-1000\SOFTWARE\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6261831 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 109094 B
Edge => 0 B
Chrome => 378856334 B
Firefox => 17264362 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 128 B
NetworkService => 128 B
Otto => 1064877 B
UpdatusUser => 1064877 B

RecycleBin => 0 B
EmptyTemp: => 385.9 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:54:04 ====

OTAS
Level 3
Level 3
Příspěvky: 484
Registrován: červenec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod OTAS » 04 pro 2022 22:17

CrystalDiskInfo 8.17.11 (C) 2008-2022 hiyohiyo
Crystal Dew World: https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Ultimate SP1 [6.1 Build 7601] (x64)
Date : 2022/12/04 22:17:02

-- Controller Map ----------------------------------------------------------
+ PCI Standardní dvoukanálový řadič IDE [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ PCI Standardní dvoukanálový řadič IDE [ATA]
+ ATA Channel 0 (0)
- WDC WD5000AAKX-00ERMA0 ATA Device
+ ATA Channel 1 (1)
- HL-DT-ST DVDRAM GH24NS95 ATA Device

-- Disk List ---------------------------------------------------------------
(01) WDC WD5000AAKX-00ERMA0 : 500,1 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(01) WDC WD5000AAKX-00ERMA0
----------------------------------------------------------------------------
Model : WDC WD5000AAKX-00ERMA0
Firmware : 15.01H15
Serial Number : WD-WCC2ER064388
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : 16384 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/300 | SATA/600
Power On Hours : 10446 hodin
Power On Count : 4469 krát
Temperature : 36 C (96 F)
Health Status : Dobrý
Features : S.M.A.R.T., NCQ, GPL
APM Level : ----
AAM Level : ----
Drive Letter : C:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000037 Počet chyb čtení
03 141 139 _21 000000000F5D Čas na roztočení ploten
04 _96 _96 __0 00000000117B Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _86 _86 __0 0000000028CE Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _96 _96 __0 000000001175 Počet cyklů zapnutí zařízení
C0 200 200 __0 00000000006A Počet vypnutí disku
C1 199 199 __0 000000001110 Počet cyklů načítání/vymazání
C2 107 _98 __0 000000000024 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 200 200 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000001 Počet chyb v kontrolním součtu UltraDMA
C8 200 200 __0 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000 Bz?..7.......?......
010: 2020 2020 2057 442D 5743 4332 4552 3036 3433 3838 WD-WCC2ER064388
020: 0000 8000 0032 3135 2E30 3148 3135 5744 4320 5744 .....215.01H15WDC WD
030: 3530 3030 4141 4B58 2D30 3045 524D 4130 2020 2020 5000AAKX-00ERMA0
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00 ..../.
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0110 @.......?....?......
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000 ...........x.x.x.x..
070: 0000 0000 0000 0000 0000 001F 170E 0004 0044 0040 .................D.@
080: 01FE 0000 746B 7D61 4123 7469 BC41 4123 207F 0026 ....tk}aA#ti.AA# ..&
090: 0026 0000 FFFE 0000 0000 0000 0000 0000 0000 0000 .&..................
100: 6030 3A38 0000 0000 0000 0000 0000 0000 5001 4EE2 `0:8............P.N.
110: 5D1A 46D4 0000 0000 0000 0000 0000 0000 0000 4018 ].F...............@.
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000 @................)..
130: 0000 0000 0000 16FE 0179 0000 0000 0000 0000 0000 .........y..........
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000 ....................
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
200: 0000 0000 0000 0000 0000 0000 3037 0000 0000 0000 ............07......
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000 .....>..............
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000 ....................
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 ....................
250: 0000 0000 0000 0000 0000 D5A5 ............

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 37 00 00 00 00 00 00 03 27 .../...7.......'
010: 00 8D 8B 5D 0F 00 00 00 00 00 04 32 00 60 60 7B ...].......2.``{
020: 11 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00 .......3........
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32 ...............2
040: 00 56 56 CE 28 00 00 00 00 00 0A 32 00 64 64 00 .VV.(......2.dd.
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00 .......2.dd.....
060: 00 00 0C 32 00 60 60 75 11 00 00 00 00 00 C0 32 ...2.``u.......2
070: 00 C8 C8 6A 00 00 00 00 00 00 C1 32 00 C7 C7 10 ...j.......2....
080: 11 00 00 00 00 00 C2 22 00 6B 62 24 00 00 00 00 .......".kb$....
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32 ...2...........2
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 C8 C8 00 ...........0....
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 01 00 00 00 00 .......2........
0C0: 00 00 C8 08 00 C8 C8 00 00 00 00 00 00 00 00 00 ................
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
160: 00 00 00 00 00 00 00 00 00 00 84 00 88 1D 01 7B ...............{
170: 03 00 01 00 02 4D 05 00 00 00 00 00 00 00 00 00 .....M..........
180: 00 00 01 02 00 00 00 00 00 00 00 00 00 00 00 00 ................
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F2 ................

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 00 00 00 00 00 00 00 00 03 15 ...3............
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 ................
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00 ................
030: 00 00 07 00 C8 C8 00 00 00 00 00 00 00 00 09 00 ................
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00 ................
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00 ................
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00 ................
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00 ................
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00 ................
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00 ................
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00 ................
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00 ................
0C0: 00 00 C8 00 C8 C8 00 00 00 00 00 00 00 00 00 00 ................
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D ................

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 04 pro 2022 23:54

Error: (11/17/2022 07:56:30 PM) (Source: ESENT) (EventID: 454) (User: )
Description: taskhost (2396) WebCacheLocal: Při zotavení či obnovení databáze došlo k neočekávané chybě -551.

Error: (11/17/2022 07:56:30 PM) (Source: ESENT) (EventID: 517) (User: )
Description: taskhost (2396) WebCacheLocal: Obnovení databáze se nezdařilo a došlo k chybě -551, protože byly zjištěny odkazy na databázi C:\Users\Otto\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat, která se neshoduje s aktuální sadou protokolů. Databázový stroj nepovolí dokončení obnovení pro tuto instanci, dokud nebude znovu vytvořena instance neshodné databáze. Pokud databáze již skutečně není k dispozici nebo není již nadále požadována, získáte pokyny týkající se odstranění této chyby ve znalostní bázi Microsoft Knowledge Base nebo po klepnutí na odkaz Další informace na konci této zprávy.

Error: (11/17/2022 07:56:29 PM) (Source: ESENT) (EventID: 465) (User: )
Description: taskhost (2396) WebCacheLocal: Při částečném obnovení byl zjištěn poškozený soubor protokolu C:\Users\Otto\AppData\Local\Microsoft\Windows\WebCache\V01.log. Záznam s chybou kontrolního součtu je umístěn na pozici END. Data neodpovídající záznamům protokolu se poprvé vyskytla v sektoru 690 (0x000002B2). Soubor je poškozený a nelze jej použít.


Příčinou bude asi nejnovější Chrome a jeho nekompabilita s windows7.

Soumrak nad Windows 7 a 8.1. Chrome 111 je už nebude podporovat

https://www.zive.cz/clanky/soumrak-nad- ... fault.aspx

Viry to není.

Stáhni si zde DelFix
Další odkazy:
https://toolslib.net/downloads/viewdownload/2-delfix/
http://ccm.net/download/download-24087-delfix
https://www.bleepingcomputer.com/download/delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7, 8 a10 musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

OTAS
Level 3
Level 3
Příspěvky: 484
Registrován: červenec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod OTAS » 06 pro 2022 20:15

# DelFix v1.013 - Logfile created 06/12/2022 at 20:11:55
# Updated 17/04/2016 by Xplode
# Username : Otto - OTTO-PC
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\Users\Otto\Desktop\adwcleaner(1).exe
Deleted : C:\Users\Otto\Desktop\AdwCleaner.exe
Deleted : C:\Users\Otto\Desktop\Fixlog.txt
Deleted : C:\Users\Otto\Desktop\FRST64.exe
Deleted : C:\Users\Otto\Desktop\HijackThis.exe
Deleted : C:\Users\Otto\Desktop\RogueKiller_setup.exe
Deleted : C:\Users\Otto\Desktop\TFC.exe
Deleted : C:\Users\Public\Desktop\RogueKiller.lnk
Deleted : C:\Users\Otto\Downloads\JRT.exe

~ Cleaning system restore ...

Deleted : RP #574 [Operace obnovení | 11/29/2022 16:26:11]
Deleted : RP #575 [JRT Pre-Junkware Removal | 12/03/2022 00:13:16]
Deleted : RP #576 [Installed Sophos Virus Removal Tool. | 12/03/2022 00:23:13]
Deleted : RP #577 [Garmin Express | 12/03/2022 15:05:07]
Deleted : RP #578 [zoek.exe restore point | 12/03/2022 16:42:06]
Deleted : RP #579 [Removed 4K Video Downloader | 12/03/2022 18:59:27]
Deleted : RP #581 [Restore Point Created by FRST | 12/04/2022 20:52:29]

New restore point created !

########## - EOF - ##########

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 06 pro 2022 23:22

Co problémy? Zda se to týká jen Chrome , tak viz výše. Jinak:
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

OTAS
Level 3
Level 3
Příspěvky: 484
Registrován: červenec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod OTAS » 08 pro 2022 17:27

Ještě když spustím PC tak trvá dlouho tak 7 minut než se muže používat . Spouští se i nějaké programy a počítač je zpomalený.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 08 pro 2022 19:38

To viry nebude.

Stáhni si na svojí plochu StartupLite .exe by MalwareBytes

Tento program identifikuje a dává volbu k odstranění nepotřebných položek k vyprázdnění paměti.
Poklepej na ikonu StartupLite.exe (by MalwareBytes ) ke spuštění programu. Ve vistě a windows 7 spusť jako správce (pravým klik na ikonu a vyber-spustit jako správce).Vytvoří se list nepotřebných vstupů po spuštění. Nech všechny položky jako deaktivované a klikni na Continue . Restartuj PC.

případně si sám vyjmi :
Start , napiš:
msconfig
v okně klikni na config pravým a vyber : spustit jako správce.
V okně /záložce "po spuštění"
odeber zatržítko u některých programů , které nepotřebuješ mít zapnuté při startu.

Stáhni si Memtest
http://www.stahuj.cz/utility_a_ostatni/ ... i/memtest/

Políčko , ve kterém je napsáno:
All unused RAM ponech.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.
poklepej na Memtest , pak znovu a znovu , do políček všech Memtestů napiš 2048 , pak dej u všech Memtestů "Start".
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

OTAS
Level 3
Level 3
Příspěvky: 484
Registrován: červenec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod OTAS » 11 pro 2022 21:50

RAM hlásí 0 errors


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 8 hostů