Prosim o o kontrolu logu - dle Gmail malware v zařízení/podežrelá aktivita
Napsal: 06 led 2023 08:52
Ahoj,
poprosím o kontrolu logu. Při přihlášení do Gmailu na mě vyškočil error -"Někdo zřejmě získal přístup k mému účtu Google prostředníctvím malwaru v některém z mých zařízenÍ." Prosím o kontrolu
PS: Blokovane URL v Hosts pls nemazat, mám je tam už dlouho.
Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.26
Platform: x64 Windows 10 (Home), 10.0.19045.2364 (ReleaseId: 2009), Service Pack: 0
Time: 06.01.2023 - 08:47 (UTC+01:00)
Language: OS: Czech (0x405). Display: Czech (0x405). Non-Unicode: Czech (0x405)
Elevated: Yes
Ran by: marti (group: Administrator) on MTA-M5RC994, FirstRun: yes
Chrome: 108.0.5359.125
Firefox: 108.0.1.8384
Internet Explorer: 11.0.19041.1566
Default: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --single-argument %1 (Google Chrome)
Boot mode: Normal
Running processes:
Number | Path
1 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
1 C:\Program Files (x86)\GZ Systems\Atom\AtomService\Atom.SDK.WindowsService.exe
24 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
1 C:\Program Files (x86)\KeyScrambler\KeyScrambler.exe
1 C:\Program Files (x86)\KeyScrambler\x64\KeyScrambler.exe
1 C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe
1 C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe
1 C:\Program Files (x86)\TREZOR Bridge\trezord.exe
1 C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe
1 C:\Program Files\CCleaner\CCleaner64.exe
1 C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
1 C:\Program Files\DAEMON Tools Lite\DTAgent.exe
1 C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
1 C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
1 C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
3 C:\Program Files\Everything\Everything.exe
4 C:\Program Files\Fing\Fing.exe
1 C:\Program Files\Fing\resources\extraResources\fingagent.exe
7 C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe
2 C:\Program Files\Google\Drive File Stream\68.0.2.0\crashpad_handler.exe
1 C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
1 C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
1 C:\Program Files\Microsoft OneDrive\OneDrive.exe
2 C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
3 C:\Program Files\Privax\HMA VPN\Vpn.exe
1 C:\Program Files\Privax\HMA VPN\VpnSvc.exe
3 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
1 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
1 C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
1 C:\Program Files\SUPERAntiSpyware\SASCore64.exe
1 C:\Program Files\Sandboxie-Plus\SandMan.exe
1 C:\Program Files\Sandboxie-Plus\SbieSvc.exe
1 C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2248.9.0_x64__cv1g1gvanyjgm\WhatsApp.exe
1 C:\Program Files\WindowsApps\61545TimGrabinat.wAPPerforGmail_3.6.5.0_x64__rcb0qdgx4z9ca\EasyMail.UwpApp.exe
1 C:\Program Files\WindowsApps\61545TimGrabinat.wAPPerforGmail_3.6.5.0_x64__rcb0qdgx4z9ca\EasyMail.Win32\EasyMail.Win32.exe
1 C:\Program Files\WindowsApps\AppleInc.iCloud_13.4.101.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe
1 C:\Program Files\WindowsApps\AppleInc.iTunes_12127.1.57051.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
1 C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.14326.21146.0_x64__8wekyb3d8bbwe\onenoteim.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe
1 C:\ProgramData\iMobieDNA\AppleDriver\AppleMobileDeviceProcess.exe
5 C:\Users\marti\AppData\Local\0install.net\implementations\sha256new_WNVUT4A7COIHUPNX3HWQQZD5BU3GEPFRMM3BLVJW4ICRXIJEKBJQ\CefSharp.BrowserSubprocess.exe
1 C:\Users\marti\AppData\Local\0install.net\implementations\sha256new_WV5TRETXUBOQ6LZJA35T7HWCPRK37DFDDMEP2CXC765WUMVMIUYQ\DeepL.exe
1 C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe
1 C:\Users\marti\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
2 C:\Users\marti\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe
1 C:\Users\marti\AppData\Local\WebEx\WebEx64\Meetings\atmgr.exe
1 C:\Users\marti\AppData\Local\WebEx\WebexHost.exe
1 C:\Users\marti\Desktop\HiJackThis\HiJackThis.exe
1 C:\Windows\ImmersiveControlPanel\SystemSettings.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_38cfab2b652e4701\igfxCUIService.exe
1 C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_38cfab2b652e4701\igfxEM.exe
1 C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c2ac023763d5d3ad\OneApp.IGCC.WinService.exe
1 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHDCPSvc.exe
1 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHeciSvc.exe
1 C:\Windows\System32\Intel\DPTF\dptf_helper.exe
1 C:\Windows\System32\Intel\DPTF\esif_uf.exe
6 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\SgrmBroker.exe
2 C:\Windows\System32\WUDFHost.exe
1 C:\Windows\System32\cmd.exe
3 C:\Windows\System32\conhost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dasHost.exe
1 C:\Windows\System32\dllhost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\ibtsiva.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\oobe\UserOOBEBroker.exe
1 C:\Windows\System32\rundll32.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
83 C:\Windows\System32\svchost.exe
2 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\System32\wlanext.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\explorer.exe
1 C:\webOS_TV_SDK\Resources\Jre\bin\javaw.exe
O1 - Hosts: 127.0.0.1 xvideos.com
O1 - Hosts: 127.0.0.1 pornhub.com
O1 - Hosts: 127.0.0.1 freevideo.cz
O1 - Hosts: 127.0.0.1 redtube.com
O1 - Hosts: 127.0.0.1 www.xvideos.com
O1 - Hosts: 127.0.0.1 www.pornhub.com
O1 - Hosts: 127.0.0.1 www. freevideo.cz
O1 - Hosts: 127.0.0.1 www.redtube.com
O1 - Hosts.ICS: .168.137.163 LGwebOSTV.mshome.net # 2020 9 1 14 10 36 30 653
O1 - Hosts.ICS: 192.168.137.8 Samsung.mshome.net # 2020 9 2 8 14 54 51 728
O1 - Hosts.ICS: 28
O2 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\BHO\ie_to_edge_bho_64.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_241\bin\jp2ssv.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_241\bin\ssv.dll
O2-32 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\BHO\ie_to_edge_bho.dll
O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HMA VPN.lnk -> C:\Program Files (x86)\Privax\HMA VPN\Vpn.exe /nogui
O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk -> C:\Program Files (x86)\Stickies\stickies.exe
O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TREZOR Bridge.lnk -> C:\Program Files (x86)\TREZOR Bridge\trezord.exe -v -l "%APPDATA%\TREZOR Bridge\trezord.log"
O4 - HKCU\..\Run: [AirBackupHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe
O4 - HKCU\..\Run: [AllMyNotes] = C:\Program Files (x86)\AllMyNotes Organizer\AllMyNotes.exe -autostartup
O4 - HKCU\..\Run: [AnyTransToolHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AnyTransToolHelper.exe
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O4 - HKCU\..\Run: [CiscoMeetingDaemon] = C:\Users\marti\AppData\Local\WebEx\WebexHost.exe /daemon /runFrom=autorun
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] = C:\Program Files\DAEMON Tools Lite\DTAgent.exe -autorun
O4 - HKCU\..\Run: [Fences] = c:\program files (x86)\stardock\fences\Fences.exe /startup
O4 - HKCU\..\Run: [Freedom] = C:\Program Files (x86)\Freedom\FreedomBlocker.exe
O4 - HKCU\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKCU\..\Run: [HP ENVY 4500 series (NET)] = C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe -deviceID "CN44T1409W060D:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background (Microsoft)
O4 - HKCU\..\Run: [ProtonVPN] = C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.exe
O4 - HKCU\..\Run: [SandboxiePlus_AutoRun] = C:\Program Files\Sandboxie-Plus\SandMan.exe -autorun
O4 - HKCU\..\Run: [Screencast-O-Matic Tray] = C:\Users\marti\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe tray
O4 - HKCU\..\Run: [electron.app.Fing] = C:\Program Files\Fing\Fing.exe --processStart "Fing.exe" --process-start-args "--hidden" (file missing)
O4 - HKCU\..\Run: [f.lux] = C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe /noshow
O4 - HKLM\..\Run: [Everything] = C:\Program Files\Everything\Everything.exe -startup
O4 - HKLM\..\Run: [Fences] = C:\Program Files (x86)\Stardock\Fences\Fences.exe /startup
O4 - HKLM\..\Run: [KeePass 2 PreLoad] = C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe --preload
O4 - HKLM\..\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
O4 - HKLM\..\Run: [RtHDVBg_Dolby] = C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4
O4 - HKLM\..\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] = C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /LENOVO_DOLBYDRAGON
O4 - HKU\.DEFAULT\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKU\S-1-5-19\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKU\S-1-5-20\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [AirBackupHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [AnyTransToolHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AnyTransToolHelper.exe (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [Fences] = c:\program files (x86)\stardock\fences\Fences.exe /startup (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [MicrosoftEdgeAutoLaunch_E7AE71D0E9E7CF799E14C4AE10DD0FD3] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start /prefetch:5 (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Delete Cached Standalone Update Binary] = C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Delete Cached Update Binary] = C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background /setautostart (Microsoft) (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Uninstall 19.043.0304.0013\amd64] = C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\amd64" (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Uninstall 19.043.0304.0013] = C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\19.043.0304.0013" (User 'Visitor')
O4 - User Startup: C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoUpdate_tv.bat
O4 - User Startup: C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk -> C:\Users\marti\AppData\Roaming\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe
O4-32 - HKLM\..\Run: [AirBackupHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe
O4-32 - HKLM\..\Run: [KeyScrambler] = C:\Program Files (x86)\KeyScrambler\keyscrambler.exe /a
O4-32 - HKLM\..\Run: [Lightshot] = C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver: (default) = C:\Windows\system32\GPhotos.scr (file missing)
O8 - Context menu item: HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver: (default) = C:\Windows\system32\GPhotos.scr (file missing)
O15 - Trusted Zone: https://deedu-files.sharepoint.com
O15 - Trusted Zone: https://deedu-myfiles.sharepoint.com
O17 - DHCP DNS 1: 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{4d161afd-f3c9-4150-827c-085301fb0062}: [NameServer] = 100.120.35.1
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveCloudOverlayIconHandler: GoogleDriveCloudOverlayIconHandler - {A8E52322-8734-481D-A7E2-27B309EF8D56} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveMirrorBlacklistedOverlayIconHandler: GoogleDriveMirrorBlacklistedOverlayIconHandler - {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDrivePinnedOverlayIconHandler: GoogleDrivePinnedOverlayIconHandler - {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveProgressOverlayIconHandler: GoogleDriveProgressOverlayIconHandler - {C973DA94-CBDF-4E77-81D1-E5B794FBD146} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveBlacklisted: Google Drive Shell extension - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} - C:\Program Files\Google\Drive\googledrivesync64.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveSynced: Google Drive Shell extension - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} - C:\Program Files\Google\Drive\googledrivesync64.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveSyncing: Google Drive Shell extension - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} - C:\Program Files\Google\Drive\googledrivesync64.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\00asw: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\00avg: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)
O22 - Task (.job): (Not scheduled) Driver Easy Scheduled Scan.job - C:\Program Files\Easeware\DriverEasy\DriverEasy.exe --scan
O22 - Task (.job): (Not scheduled) update-S-1-5-21-2686290433-1851989028-3160282163-1001.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task (.job): (Not scheduled) update-sys.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe /NoUACCheck
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\WINDOWS\system32\MusNotification.exe /RunOnAC RebootDialog (Microsoft)
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\WINDOWS\system32\MusNotification.exe /RunOnBattery RebootDialog (Microsoft)
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\WINDOWS\System32\Autopilot.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\WINDOWS\System32\Autopilot.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Task: (disabled) \S-1-5-21-2686290433-1851989028-3160282163-1001\DataSenseLiveTileTask - C:\WINDOWS\System32\DataUsageLiveTileTask.exe
O22 - Task: (telemetry) \Microsoft\Office\Office Subscription Maintenance - C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe (Microsoft)
O22 - Task: (telemetry) \Microsoft\Office\OfficeTelemetryAgentFallBack2016 - C:\Program Files\Microsoft Office\root\Office16\msoia.exe scan upload mininterval:2880 (Microsoft)
O22 - Task: (telemetry) \Microsoft\Office\OfficeTelemetryAgentLogOn2016 - C:\Program Files\Microsoft Office\root\Office16\msoia.exe scan upload (Microsoft)
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Task: (update) \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\WINDOWS\system32\MusNotification.exe (Microsoft)
O22 - Task: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe
O22 - Task: CCleanerSkipUAC - marti - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task: Driver Easy Scheduled Scan - C:\Program Files\Easeware\DriverEasy\DriverEasy.exe --scan
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: HMA VPN Update - C:\Program Files\Privax\HMA VPN\VpnUpdate.exe
O22 - Task: IcarusPrivaxVpnUpgrade - C:\Program Files\Privax\HMA VPN\setup\privax_vpn_online_setup.exe /silent /ShowVpnGui=0 /RestartUpdaterTaskName=IcarusPrivaxVpnUpgrade /RestartUpdaterAppExe="C:\Program Files\Privax\HMA VPN\setup\privax_vpn_online_setup.exe" (file missing)
O22 - Task: OneDrive Per-Machine Standalone Update Task - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1017 - C:\Users\marti\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (file missing)
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1021 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1022 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Task: Opera scheduled Autoupdate 1592437018 - C:\Users\marti\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: Opera scheduled assistant Autoupdate 1592437027 - C:\Users\marti\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\marti\AppData\Local\Programs\Opera\assistant" $(Arg0)
O22 - Task: \Lenovo\Lenovo Service Bridge\S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\Users\marti\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe
O22 - Task: \Microsoft\Office\Office Performance Monitor - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe (Microsoft)
O22 - Task: \Microsoft\Windows\AppListBackup\Backup - {E0DCC2CC-3354-45F2-8914-519E07809082} - C:\WINDOWS\system32\AppListBackupLauncher.dll (Microsoft)
O22 - Task: \Microsoft\Windows\Printing\PrinterCleanupTask - {C56F065E-DE49-4E42-BE7C-305C45609D25} - C:\WINDOWS\System32\PrinterCleanupTask.dll (Microsoft)
O22 - Task: \Microsoft\Windows\Shell\ThemesSyncedImageDownload - {79F8E185-4E45-4B74-8182-02AA430661E4} - C:\WINDOWS\System32\Themes.SsfDownload.ScheduledTask.dll (Microsoft)
O22 - Task: \Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
O22 - Task: \Privax\HMA VPN Bug Report - C:\Program Files\Privax\HMA VPN\AvBugReport.exe --filter "*.dmp;*.mdmp;icarus.log" --send "dumps|report" --silent --product 78 --programpath "C:\Program Files\Privax\HMA VPN" --configpath "C:\ProgramData\Privax\HMA VPN" --path "C:\ProgramData\Privax\HMA VPN\log" --path "C:\ProgramData\Privax\Icarus\Logs" --logpath "C:\ProgramData\Privax\HMA VPN\log" --guid fd7fda8c-604e-4ceb-9283-63a19c630776
O22 - Task: \Privax\HMA VPN Update - C:\Program Files\Common Files\Privax\Icarus\privax-vpn\icarus.exe /update:privax-vpn /silent
O22 - Task: \RobotFramework\Amazon - Firefox - D:\Robot Framework\win10firefox_taskscheduler.bat (file missing)
O22 - Task: \RobotFramework\Amazon - chrome - D:\Robot Framework\win10CHROME.bat (file missing)
O22 - Task: \RobotFramework\Amazon IE - D:\Robot Framework\win10IE_taskscheduler.bat (file missing)
O22 - Task: \RobotFramework\Everything - C:\Program Files\Everything\Everything.exe
O22 - Task: npcapwatchdog - C:\Program Files\Npcap\CheckStatus.bat
O22 - Task: update-S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task: update-sys - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service R2: Atom Service - (AtomService) - C:\Program Files (x86)\GZ Systems\Atom\AtomService\Atom.SDK.WindowsService.exe
O23 - Service R2: Dolby DAX API Service - C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
O23 - Service R2: Everything - C:\Program Files\Everything\Everything.exe -svc
O23 - Service R2: Fing.Agent - C:\Program Files\Fing\resources\extraResources\fingagent.exe --servicemode Fing.Agent --agentroot "C:\Users\marti\AppData\Roaming"
O23 - Service R2: HMA VPN - (HmaProVpn) - C:\Program Files\Privax\HMA VPN\VpnSvc.exe
O23 - Service R2: HP Print Scan Doctor Service - (HPPrintScanDoctorService) - C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
O23 - Service R2: Intel Bluetooth Service - (ibtsiva) - C:\WINDOWS\system32\ibtsiva.exe
O23 - Service R2: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHDCPSvc.exe
O23 - Service R2: Intel(R) Dynamic Platform and Thermal Framework service - (esifsvc) - C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe
O23 - Service R2: Intel(R) Graphics Command Center Service - (igccservice) - C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c2ac023763d5d3ad\OneApp.IGCC.WinService.exe
O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_38cfab2b652e4701\igfxCUIService.exe
O23 - Service R2: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
O23 - Service R2: Realtek Audio Service - (RtkAudioService) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service R2: SAS Core Service - (!SASCORE) - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service R2: Sandboxie Service - (SbieSvc) - C:\Program Files\Sandboxie-Plus\SbieSvc.exe
O23 - Service R3: Disc Soft Lite Bus Service - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service R3: Intel(R) Content Protection HECI Service - (cphs) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHeciSvc.exe
O23 - Service R3: ProtonVPN Update Service - C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe
O23 - Service S2: OSSEC HIDS - (OssecSvc) - C:\Program Files (x86)\ossec-agent\ossec-agent.exe
O23 - Service S2: Služba Aktualizace Google (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: CCleaner Performance Optimizer Service - (CCleanerPerformanceOptimizerService) - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
O23 - Service S3: FileSyncHelper - C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncHelper.exe
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.125\elevation_service.exe
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service S3: Office 64 Source Engine - (ose64) - c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
O23 - Service S3: OneDrive Updater Service - C:\Program Files\Microsoft OneDrive\22.238.1114.0002\OneDriveUpdaterService.exe
O23 - Service S3: ProtonVPN Service - C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe
O23 - Service S3: QFX Software Update Service - (QFXUpdateService) - C:\Program Files (x86)\KeyScrambler\x64\QFXUpdateService.exe
O23 - Service S3: Služba Aktualizace Google (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
--
End of file - Time spent: 32,5 sec. - 55920 bytes, CRC32: FFFFFFFF. Sign: 祔⡜
poprosím o kontrolu logu. Při přihlášení do Gmailu na mě vyškočil error -"Někdo zřejmě získal přístup k mému účtu Google prostředníctvím malwaru v některém z mých zařízenÍ." Prosím o kontrolu
PS: Blokovane URL v Hosts pls nemazat, mám je tam už dlouho.
Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.26
Platform: x64 Windows 10 (Home), 10.0.19045.2364 (ReleaseId: 2009), Service Pack: 0
Time: 06.01.2023 - 08:47 (UTC+01:00)
Language: OS: Czech (0x405). Display: Czech (0x405). Non-Unicode: Czech (0x405)
Elevated: Yes
Ran by: marti (group: Administrator) on MTA-M5RC994, FirstRun: yes
Chrome: 108.0.5359.125
Firefox: 108.0.1.8384
Internet Explorer: 11.0.19041.1566
Default: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --single-argument %1 (Google Chrome)
Boot mode: Normal
Running processes:
Number | Path
1 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
1 C:\Program Files (x86)\GZ Systems\Atom\AtomService\Atom.SDK.WindowsService.exe
24 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
1 C:\Program Files (x86)\KeyScrambler\KeyScrambler.exe
1 C:\Program Files (x86)\KeyScrambler\x64\KeyScrambler.exe
1 C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe
1 C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe
1 C:\Program Files (x86)\TREZOR Bridge\trezord.exe
1 C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe
1 C:\Program Files\CCleaner\CCleaner64.exe
1 C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
1 C:\Program Files\DAEMON Tools Lite\DTAgent.exe
1 C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
1 C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
1 C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
3 C:\Program Files\Everything\Everything.exe
4 C:\Program Files\Fing\Fing.exe
1 C:\Program Files\Fing\resources\extraResources\fingagent.exe
7 C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe
2 C:\Program Files\Google\Drive File Stream\68.0.2.0\crashpad_handler.exe
1 C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
1 C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
1 C:\Program Files\Microsoft OneDrive\OneDrive.exe
2 C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
3 C:\Program Files\Privax\HMA VPN\Vpn.exe
1 C:\Program Files\Privax\HMA VPN\VpnSvc.exe
3 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
1 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
1 C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
1 C:\Program Files\SUPERAntiSpyware\SASCore64.exe
1 C:\Program Files\Sandboxie-Plus\SandMan.exe
1 C:\Program Files\Sandboxie-Plus\SbieSvc.exe
1 C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2248.9.0_x64__cv1g1gvanyjgm\WhatsApp.exe
1 C:\Program Files\WindowsApps\61545TimGrabinat.wAPPerforGmail_3.6.5.0_x64__rcb0qdgx4z9ca\EasyMail.UwpApp.exe
1 C:\Program Files\WindowsApps\61545TimGrabinat.wAPPerforGmail_3.6.5.0_x64__rcb0qdgx4z9ca\EasyMail.Win32\EasyMail.Win32.exe
1 C:\Program Files\WindowsApps\AppleInc.iCloud_13.4.101.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe
1 C:\Program Files\WindowsApps\AppleInc.iTunes_12127.1.57051.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
1 C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.14326.21146.0_x64__8wekyb3d8bbwe\onenoteim.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe
1 C:\ProgramData\iMobieDNA\AppleDriver\AppleMobileDeviceProcess.exe
5 C:\Users\marti\AppData\Local\0install.net\implementations\sha256new_WNVUT4A7COIHUPNX3HWQQZD5BU3GEPFRMM3BLVJW4ICRXIJEKBJQ\CefSharp.BrowserSubprocess.exe
1 C:\Users\marti\AppData\Local\0install.net\implementations\sha256new_WV5TRETXUBOQ6LZJA35T7HWCPRK37DFDDMEP2CXC765WUMVMIUYQ\DeepL.exe
1 C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe
1 C:\Users\marti\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
2 C:\Users\marti\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe
1 C:\Users\marti\AppData\Local\WebEx\WebEx64\Meetings\atmgr.exe
1 C:\Users\marti\AppData\Local\WebEx\WebexHost.exe
1 C:\Users\marti\Desktop\HiJackThis\HiJackThis.exe
1 C:\Windows\ImmersiveControlPanel\SystemSettings.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_38cfab2b652e4701\igfxCUIService.exe
1 C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_38cfab2b652e4701\igfxEM.exe
1 C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c2ac023763d5d3ad\OneApp.IGCC.WinService.exe
1 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHDCPSvc.exe
1 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHeciSvc.exe
1 C:\Windows\System32\Intel\DPTF\dptf_helper.exe
1 C:\Windows\System32\Intel\DPTF\esif_uf.exe
6 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\SgrmBroker.exe
2 C:\Windows\System32\WUDFHost.exe
1 C:\Windows\System32\cmd.exe
3 C:\Windows\System32\conhost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dasHost.exe
1 C:\Windows\System32\dllhost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\ibtsiva.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\oobe\UserOOBEBroker.exe
1 C:\Windows\System32\rundll32.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
83 C:\Windows\System32\svchost.exe
2 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\System32\wlanext.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\explorer.exe
1 C:\webOS_TV_SDK\Resources\Jre\bin\javaw.exe
O1 - Hosts: 127.0.0.1 xvideos.com
O1 - Hosts: 127.0.0.1 pornhub.com
O1 - Hosts: 127.0.0.1 freevideo.cz
O1 - Hosts: 127.0.0.1 redtube.com
O1 - Hosts: 127.0.0.1 www.xvideos.com
O1 - Hosts: 127.0.0.1 www.pornhub.com
O1 - Hosts: 127.0.0.1 www. freevideo.cz
O1 - Hosts: 127.0.0.1 www.redtube.com
O1 - Hosts.ICS: .168.137.163 LGwebOSTV.mshome.net # 2020 9 1 14 10 36 30 653
O1 - Hosts.ICS: 192.168.137.8 Samsung.mshome.net # 2020 9 2 8 14 54 51 728
O1 - Hosts.ICS: 28
O2 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\BHO\ie_to_edge_bho_64.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_241\bin\jp2ssv.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_241\bin\ssv.dll
O2-32 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\BHO\ie_to_edge_bho.dll
O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HMA VPN.lnk -> C:\Program Files (x86)\Privax\HMA VPN\Vpn.exe /nogui
O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk -> C:\Program Files (x86)\Stickies\stickies.exe
O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TREZOR Bridge.lnk -> C:\Program Files (x86)\TREZOR Bridge\trezord.exe -v -l "%APPDATA%\TREZOR Bridge\trezord.log"
O4 - HKCU\..\Run: [AirBackupHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe
O4 - HKCU\..\Run: [AllMyNotes] = C:\Program Files (x86)\AllMyNotes Organizer\AllMyNotes.exe -autostartup
O4 - HKCU\..\Run: [AnyTransToolHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AnyTransToolHelper.exe
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O4 - HKCU\..\Run: [CiscoMeetingDaemon] = C:\Users\marti\AppData\Local\WebEx\WebexHost.exe /daemon /runFrom=autorun
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] = C:\Program Files\DAEMON Tools Lite\DTAgent.exe -autorun
O4 - HKCU\..\Run: [Fences] = c:\program files (x86)\stardock\fences\Fences.exe /startup
O4 - HKCU\..\Run: [Freedom] = C:\Program Files (x86)\Freedom\FreedomBlocker.exe
O4 - HKCU\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKCU\..\Run: [HP ENVY 4500 series (NET)] = C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe -deviceID "CN44T1409W060D:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background (Microsoft)
O4 - HKCU\..\Run: [ProtonVPN] = C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.exe
O4 - HKCU\..\Run: [SandboxiePlus_AutoRun] = C:\Program Files\Sandboxie-Plus\SandMan.exe -autorun
O4 - HKCU\..\Run: [Screencast-O-Matic Tray] = C:\Users\marti\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe tray
O4 - HKCU\..\Run: [electron.app.Fing] = C:\Program Files\Fing\Fing.exe --processStart "Fing.exe" --process-start-args "--hidden" (file missing)
O4 - HKCU\..\Run: [f.lux] = C:\Users\marti\AppData\Local\FluxSoftware\Flux\flux.exe /noshow
O4 - HKLM\..\Run: [Everything] = C:\Program Files\Everything\Everything.exe -startup
O4 - HKLM\..\Run: [Fences] = C:\Program Files (x86)\Stardock\Fences\Fences.exe /startup
O4 - HKLM\..\Run: [KeePass 2 PreLoad] = C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe --preload
O4 - HKLM\..\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
O4 - HKLM\..\Run: [RtHDVBg_Dolby] = C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4
O4 - HKLM\..\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] = C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /LENOVO_DOLBYDRAGON
O4 - HKU\.DEFAULT\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKU\S-1-5-19\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKU\S-1-5-20\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe --startup_mode
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [AirBackupHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [AnyTransToolHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AnyTransToolHelper.exe (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [Fences] = c:\program files (x86)\stardock\fences\Fences.exe /startup (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Run: [MicrosoftEdgeAutoLaunch_E7AE71D0E9E7CF799E14C4AE10DD0FD3] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start /prefetch:5 (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Delete Cached Standalone Update Binary] = C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Delete Cached Update Binary] = C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background /setautostart (Microsoft) (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Uninstall 19.043.0304.0013\amd64] = C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\amd64" (User 'Visitor')
O4 - HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\RunOnce: [Uninstall 19.043.0304.0013] = C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Visitor\AppData\Local\Microsoft\OneDrive\19.043.0304.0013" (User 'Visitor')
O4 - User Startup: C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoUpdate_tv.bat
O4 - User Startup: C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk -> C:\Users\marti\AppData\Roaming\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe
O4-32 - HKLM\..\Run: [AirBackupHelper] = C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe
O4-32 - HKLM\..\Run: [KeyScrambler] = C:\Program Files (x86)\KeyScrambler\keyscrambler.exe /a
O4-32 - HKLM\..\Run: [Lightshot] = C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver: (default) = C:\Windows\system32\GPhotos.scr (file missing)
O8 - Context menu item: HKU\S-1-5-21-2686290433-1851989028-3160282163-1021\..\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver: (default) = C:\Windows\system32\GPhotos.scr (file missing)
O15 - Trusted Zone: https://deedu-files.sharepoint.com
O15 - Trusted Zone: https://deedu-myfiles.sharepoint.com
O17 - DHCP DNS 1: 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{4d161afd-f3c9-4150-827c-085301fb0062}: [NameServer] = 100.120.35.1
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveCloudOverlayIconHandler: GoogleDriveCloudOverlayIconHandler - {A8E52322-8734-481D-A7E2-27B309EF8D56} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveMirrorBlacklistedOverlayIconHandler: GoogleDriveMirrorBlacklistedOverlayIconHandler - {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDrivePinnedOverlayIconHandler: GoogleDrivePinnedOverlayIconHandler - {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveProgressOverlayIconHandler: GoogleDriveProgressOverlayIconHandler - {C973DA94-CBDF-4E77-81D1-E5B794FBD146} - C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveBlacklisted: Google Drive Shell extension - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} - C:\Program Files\Google\Drive\googledrivesync64.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveSynced: Google Drive Shell extension - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} - C:\Program Files\Google\Drive\googledrivesync64.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ GoogleDriveSyncing: Google Drive Shell extension - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} - C:\Program Files\Google\Drive\googledrivesync64.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\00asw: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\00avg: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)
O22 - Task (.job): (Not scheduled) Driver Easy Scheduled Scan.job - C:\Program Files\Easeware\DriverEasy\DriverEasy.exe --scan
O22 - Task (.job): (Not scheduled) update-S-1-5-21-2686290433-1851989028-3160282163-1001.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task (.job): (Not scheduled) update-sys.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe /NoUACCheck
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\WINDOWS\system32\MusNotification.exe /RunOnAC RebootDialog (Microsoft)
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\WINDOWS\system32\MusNotification.exe /RunOnBattery RebootDialog (Microsoft)
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\WINDOWS\System32\Autopilot.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\WINDOWS\System32\Autopilot.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Task: (disabled) \S-1-5-21-2686290433-1851989028-3160282163-1001\DataSenseLiveTileTask - C:\WINDOWS\System32\DataUsageLiveTileTask.exe
O22 - Task: (telemetry) \Microsoft\Office\Office Subscription Maintenance - C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe (Microsoft)
O22 - Task: (telemetry) \Microsoft\Office\OfficeTelemetryAgentFallBack2016 - C:\Program Files\Microsoft Office\root\Office16\msoia.exe scan upload mininterval:2880 (Microsoft)
O22 - Task: (telemetry) \Microsoft\Office\OfficeTelemetryAgentLogOn2016 - C:\Program Files\Microsoft Office\root\Office16\msoia.exe scan upload (Microsoft)
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Task: (update) \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\WINDOWS\system32\MusNotification.exe (Microsoft)
O22 - Task: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe
O22 - Task: CCleanerSkipUAC - marti - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task: Driver Easy Scheduled Scan - C:\Program Files\Easeware\DriverEasy\DriverEasy.exe --scan
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: HMA VPN Update - C:\Program Files\Privax\HMA VPN\VpnUpdate.exe
O22 - Task: IcarusPrivaxVpnUpgrade - C:\Program Files\Privax\HMA VPN\setup\privax_vpn_online_setup.exe /silent /ShowVpnGui=0 /RestartUpdaterTaskName=IcarusPrivaxVpnUpgrade /RestartUpdaterAppExe="C:\Program Files\Privax\HMA VPN\setup\privax_vpn_online_setup.exe" (file missing)
O22 - Task: OneDrive Per-Machine Standalone Update Task - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1017 - C:\Users\marti\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (file missing)
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1021 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Task: OneDrive Reporting Task-S-1-5-21-2686290433-1851989028-3160282163-1022 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Task: Opera scheduled Autoupdate 1592437018 - C:\Users\marti\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: Opera scheduled assistant Autoupdate 1592437027 - C:\Users\marti\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\marti\AppData\Local\Programs\Opera\assistant" $(Arg0)
O22 - Task: \Lenovo\Lenovo Service Bridge\S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\Users\marti\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe
O22 - Task: \Microsoft\Office\Office Performance Monitor - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe (Microsoft)
O22 - Task: \Microsoft\Windows\AppListBackup\Backup - {E0DCC2CC-3354-45F2-8914-519E07809082} - C:\WINDOWS\system32\AppListBackupLauncher.dll (Microsoft)
O22 - Task: \Microsoft\Windows\Printing\PrinterCleanupTask - {C56F065E-DE49-4E42-BE7C-305C45609D25} - C:\WINDOWS\System32\PrinterCleanupTask.dll (Microsoft)
O22 - Task: \Microsoft\Windows\Shell\ThemesSyncedImageDownload - {79F8E185-4E45-4B74-8182-02AA430661E4} - C:\WINDOWS\System32\Themes.SsfDownload.ScheduledTask.dll (Microsoft)
O22 - Task: \Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
O22 - Task: \Privax\HMA VPN Bug Report - C:\Program Files\Privax\HMA VPN\AvBugReport.exe --filter "*.dmp;*.mdmp;icarus.log" --send "dumps|report" --silent --product 78 --programpath "C:\Program Files\Privax\HMA VPN" --configpath "C:\ProgramData\Privax\HMA VPN" --path "C:\ProgramData\Privax\HMA VPN\log" --path "C:\ProgramData\Privax\Icarus\Logs" --logpath "C:\ProgramData\Privax\HMA VPN\log" --guid fd7fda8c-604e-4ceb-9283-63a19c630776
O22 - Task: \Privax\HMA VPN Update - C:\Program Files\Common Files\Privax\Icarus\privax-vpn\icarus.exe /update:privax-vpn /silent
O22 - Task: \RobotFramework\Amazon - Firefox - D:\Robot Framework\win10firefox_taskscheduler.bat (file missing)
O22 - Task: \RobotFramework\Amazon - chrome - D:\Robot Framework\win10CHROME.bat (file missing)
O22 - Task: \RobotFramework\Amazon IE - D:\Robot Framework\win10IE_taskscheduler.bat (file missing)
O22 - Task: \RobotFramework\Everything - C:\Program Files\Everything\Everything.exe
O22 - Task: npcapwatchdog - C:\Program Files\Npcap\CheckStatus.bat
O22 - Task: update-S-1-5-21-2686290433-1851989028-3160282163-1001 - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task: update-sys - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service R2: Atom Service - (AtomService) - C:\Program Files (x86)\GZ Systems\Atom\AtomService\Atom.SDK.WindowsService.exe
O23 - Service R2: Dolby DAX API Service - C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
O23 - Service R2: Everything - C:\Program Files\Everything\Everything.exe -svc
O23 - Service R2: Fing.Agent - C:\Program Files\Fing\resources\extraResources\fingagent.exe --servicemode Fing.Agent --agentroot "C:\Users\marti\AppData\Roaming"
O23 - Service R2: HMA VPN - (HmaProVpn) - C:\Program Files\Privax\HMA VPN\VpnSvc.exe
O23 - Service R2: HP Print Scan Doctor Service - (HPPrintScanDoctorService) - C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
O23 - Service R2: Intel Bluetooth Service - (ibtsiva) - C:\WINDOWS\system32\ibtsiva.exe
O23 - Service R2: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHDCPSvc.exe
O23 - Service R2: Intel(R) Dynamic Platform and Thermal Framework service - (esifsvc) - C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe
O23 - Service R2: Intel(R) Graphics Command Center Service - (igccservice) - C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c2ac023763d5d3ad\OneApp.IGCC.WinService.exe
O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_38cfab2b652e4701\igfxCUIService.exe
O23 - Service R2: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
O23 - Service R2: Realtek Audio Service - (RtkAudioService) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service R2: SAS Core Service - (!SASCORE) - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service R2: Sandboxie Service - (SbieSvc) - C:\Program Files\Sandboxie-Plus\SbieSvc.exe
O23 - Service R3: Disc Soft Lite Bus Service - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service R3: Intel(R) Content Protection HECI Service - (cphs) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_51f685305808e3a5\IntelCpHeciSvc.exe
O23 - Service R3: ProtonVPN Update Service - C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe
O23 - Service S2: OSSEC HIDS - (OssecSvc) - C:\Program Files (x86)\ossec-agent\ossec-agent.exe
O23 - Service S2: Služba Aktualizace Google (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: CCleaner Performance Optimizer Service - (CCleanerPerformanceOptimizerService) - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
O23 - Service S3: FileSyncHelper - C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncHelper.exe
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.125\elevation_service.exe
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service S3: Office 64 Source Engine - (ose64) - c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
O23 - Service S3: OneDrive Updater Service - C:\Program Files\Microsoft OneDrive\22.238.1114.0002\OneDriveUpdaterService.exe
O23 - Service S3: ProtonVPN Service - C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe
O23 - Service S3: QFX Software Update Service - (QFXUpdateService) - C:\Program Files (x86)\KeyScrambler\x64\QFXUpdateService.exe
O23 - Service S3: Služba Aktualizace Google (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
--
End of file - Time spent: 32,5 sec. - 55920 bytes, CRC32: FFFFFFFF. Sign: 祔⡜