prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 02 srp 2023 16:38

OK , téma nech ještě pár dní otevřené a pak se ozvi.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
MariTopHigh
nováček
Příspěvky: 31
Registrován: červenec 23
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod MariTopHigh » 03 srp 2023 15:41

tak problém s padáním AOE bez chyby to nevyřešilo.. asi tedy zkusím čistou instalaci na jiný disk...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 03 srp 2023 23:34

Zkoušel si přeinstalovat program?

Vypni antivir i firewall.
Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
další odkaz:
http://www.bleepingcomputer.com/downloa ... scan-tool/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

MariTopHigh
nováček
Příspěvky: 31
Registrován: červenec 23
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod MariTopHigh » 03 srp 2023 23:58

ano, zkoušel jsem i přeinstalovat na jiný disk..

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-08-2023
Ran by sampo (03-08-2023 23:50:01)
Running from C:\Users\sampo\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.3208 (X64) (2020-09-19 20:25:48)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-952769170-1753500190-2317307712-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-952769170-1753500190-2317307712-503 - Limited - Disabled)
Guest (S-1-5-21-952769170-1753500190-2317307712-501 - Limited - Disabled)
sampo (S-1-5-21-952769170-1753500190-2317307712-1001 - Administrator - Enabled) => C:\Users\sampo
WDAGUtilityAccount (S-1-5-21-952769170-1753500190-2317307712-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 23.003.20244 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AlecaFrame (HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\Overwolf_afmcagbpgggkpdkokjhjkllpegnadmkignlonpjm) (Version: 2.4.32 - Overwolf app)
Anno 1800 (HKLM-x32\...\Uplay Install 4553) (Version: - Ubisoft)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Call of Duty(R) 2 (HKLM-x32\...\InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.3 - Activision)
CORSAIR iCUE 4 Software (HKLM\...\{63F06D1A-E07D-4022-9284-2C4F4580E506}) (Version: 4.29.203 - Corsair)
CPUID CPU-Z 1.98 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.98 - CPUID, Inc.)
CrystalDiskInfo 9.1.1 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.1.1 - Crystal Dew World)
Diablo IV (HKLM-x32\...\Diablo IV) (Version: - Blizzard Entertainment)
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 12.251.0.5508 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{3334fbf5-65e0-4fde-8578-77988a93f0c1}) (Version: 12.251.0.5508 - Electronic Arts)
ENE_DRAM_RGB_AURA42 (HKLM\...\{BC5E0A82-C638-44CB-8129-20C8ED70DE7A}) (Version: 1.00.02 - Ene Tech.) Hidden
ENE_DRAM_RGB_AURA42 (HKLM-x32\...\{f3d7fb09-b93f-4c01-a765-0b0adc5bc746}) (Version: 1.00.02 - Ene Tech.) Hidden
Epic Games Launcher (HKLM-x32\...\{FAC47927-1A6A-4C6E-AD7D-E9756794A4BC}) (Version: 1.3.23.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{758842D2-1538-4008-A8E3-66F65A061C52}) (Version: 2.0.33.0 - Epic Games, Inc.)
FlatOut2 (HKLM-x32\...\{D4006E71-FF32-44FF-AD5A-B5EE4389B825}_is1) (Version: 1.0 - US - ACTION, s.r.o.)
Google Chrome (HKLM\...\{CCFFC2EC-F561-3EF1-8038-F3608B52F935}) (Version: 115.0.5790.110 - Google LLC)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Heaven Benchmark version 4.0 (HKLM-x32\...\Unigine Heaven Benchmark (Basic Edition)_is1) (Version: 4.0 - Unigine Corp.)
HWiNFO64 Version 7.16 (HKLM\...\HWiNFO64_is1) (Version: 7.16 - Martin Malik - REALiX)
Kinect for Windows Speech Recognition Language Pack (de-DE) (HKLM-x32\...\{898AA67F-99B8-4C7F-9611-B11F98EF6E78}) (Version: 11.0.7413.611 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (en-AU) (HKLM-x32\...\{48CEC0A3-AE10-4EE3-AC62-76D3D58792E5}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (en-CA) (HKLM-x32\...\{9C5505DA-F9C1-46CB-9F8F-AC38F8EA518A}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (en-GB) (HKLM-x32\...\{A0186231-0A8B-455A-8A25-B64AABCC11A6}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (en-IE) (HKLM-x32\...\{998D5259-3BED-4710-98FF-D63387B5429E}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (en-NZ) (HKLM-x32\...\{07FC9CAD-FCEC-4186-BB83-EF7CCC9372BA}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (en-US) (HKLM-x32\...\{8AAA44BB-487E-4D01-AF76-484ACB90DBFE}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (es-ES) (HKLM-x32\...\{F49AF755-A5C3-4252-A190-5772B2669C3B}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (es-MX) (HKLM-x32\...\{E8F3B154-03CE-4120-8B9D-9E83ED5F3AD7}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (fr-CA) (HKLM-x32\...\{7D179500-CA0C-4456-B624-C15876B15F39}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (fr-FR) (HKLM-x32\...\{4CC174AA-25BC-46FF-B1E2-13B24AFB6142}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (it-IT) (HKLM-x32\...\{969D900A-3481-4A77-B888-D24160D4D727}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kinect for Windows Speech Recognition Language Pack (ja-JP) (HKLM-x32\...\{EDA8693D-9E82-4FD1-98C8-0DC4F9141E0F}) (Version: 11.0.7400.336 - Microsoft Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 115.0.1901.188 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 115.0.1901.188 - Microsoft Corporation)
Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 12.181.137.0 - Microsoft Corporation)
Microsoft Office 2019 pro studenty a domácnosti - cs-cz (HKLM\...\HomeStudent2019Retail - cs-cz) (Version: 16.0.16626.20134 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 23.142.0709.0001 - Microsoft Corporation)
Microsoft PowerPoint 2016 - cs-cz (HKLM\...\PowerPointRetail - cs-cz) (Version: 16.0.16626.20134 - Microsoft Corporation)
Microsoft Server Speech Platform Runtime (x64) (HKLM\...\{3B433087-E62E-4BF5-97F9-4AF6E1C2409C}) (Version: 11.0.7400.345 - Microsoft Corporation)
Microsoft Server Speech Recognition Language - TELE (en-IN) (HKLM-x32\...\{3B06AC90-DE68-44A9-95EB-0A3C1AF1514F}) (Version: 11.0.7400.335 - Microsoft Corporation)
Microsoft Server Speech Recognition Language - TELE (pl-PL) (HKLM-x32\...\{BEFB9378-5E88-4266-8EB1-C92869449885}) (Version: 11.0.7400.335 - Microsoft Corporation)
Microsoft Server Speech Recognition Language - TELE (pt-BR) (HKLM-x32\...\{F6B5EB21-0ABF-487C-B9A9-D9DB259C4403}) (Version: 11.0.7400.335 - Microsoft Corporation)
Microsoft Server Speech Recognition Language - TELE (ru-RU) (HKLM-x32\...\{9419B7EA-6A4B-4A57-8E2A-3BDD4676118F}) (Version: 11.0.7400.335 - Microsoft Corporation)
Microsoft Server Speech Recognition Language - TELE (zh-CN) (HKLM-x32\...\{BAD2A75A-1708-47BA-A498-20890D2C78A7}) (Version: 11.0.7400.335 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{BB052C53-34CB-42DE-AF41-66FDFCEEC868}) (Version: 3.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29334 (HKLM-x32\...\{a9cfe9c7-e54f-46cd-9c5c-542ff8e3e8c4}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30139 (HKLM-x32\...\{2c673fb6-3e65-4751-965d-33d30b68a8a6}) (Version: 14.29.30139.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30139 (HKLM-x32\...\{8d5fdf81-7022-423f-bd8b-b513a1050ae1}) (Version: 14.29.30139.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.29.30139 (HKLM-x32\...\{1AEA8854-7597-4CD3-948F-8DE364D94E07}) (Version: 14.29.30139 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.29.30139 (HKLM-x32\...\{1679EF65-55F3-4248-B91E-6B3BE1A69CDF}) (Version: 14.29.30139 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 3.6.2115.31769 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MSI Afterburner 4.6.4 Beta 3 (HKLM-x32\...\Afterburner) (Version: 4.6.4 Beta 3 - MSI Co., LTD)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.27.0.112 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.27.0.112 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 536.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 536.40 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
NZXT CAM 4.53.2 (HKLM\...\ac0666ae-ee66-5310-ac01-9d6348133b2d) (Version: 4.53.2 - NZXT, Inc.)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.16626.20118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.16626.20118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.16626.20118 - Microsoft Corporation) Hidden
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.228.0.21 - Overwolf Ltd.)
Paradox Launcher v2 (HKLM\...\{986898D9-7C26-4E7F-814C-9B5472FA3209}) (Version: 2.0.0.0 - Paradox Interactive)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
Quake III Gold (HKLM-x32\...\1441704920_is1) (Version: 2.0.0.2 - GOG.com)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9282.1 - Realtek Semiconductor Corp.)
REDlauncher (HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\{7258BA11-600C-430E-A759-27E2C691A335}-REDlauncher_is1) (Version: - GOG.com)
RivaTuner Statistics Server 7.3.2 Beta 2 (HKLM-x32\...\RTSS) (Version: 7.3.2 Beta 2 - Unwinder)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.71.1428 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.1.7.0 - Rockstar Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.3.0 - TeamSpeak Systems GmbH)
TechPowerUp GPU-Z (HKLM-x32\...\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1) (Version: - TechPowerUp)
The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.97.62.1020 - Electronic Arts Inc.)
Tom Clancy's The Division 2 (HKLM-x32\...\Uplay Install 4932) (Version: - Ubisoft)
TP-Link Archer T3U Plus Driver (HKLM-x32\...\{C93FD3E7-E450-46ED-B2B2-6F86B479BDBE}) (Version: 2.1.0 - TP-Link)
TP-LINK TL-WDN4800 Driver (HKLM-x32\...\{70D605C7-C823-4750-BA72-BEB835713612}) (Version: 1.3.1 - TP-LINK)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 91.0 - Ubisoft)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{C22F49B1-0F67-47DC-A490-E8B4B6558EA9}) (Version: 8.91.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.18 - VideoLAN)
WinRAR 6.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.21.0 - win.rar GmbH)

Packages:
=========
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-06-17] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-08-04] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-08-04] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-07-01] (NVIDIA Corp.)
Ovládací centrum grafiky Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5131.0_x64__8j3eq9eme6ctt [2023-07-07] (INTEL CORP) [Startup Task]
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.38.277.0_x64__dt26b99r8h8gj [2023-03-29] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.17.7270.0_x64__8wekyb3d8bbwe [2023-08-03] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0 [2023-07-26] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncShell64.dll [2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5b6e4554b945d508\nvshext.dll [2023-06-26] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2023-05-12] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2023-05-12] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2023-07-27 18:27 - 2023-07-26 23:06 - 001569280 _____ () [File not signed] \\?\C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\CTITSDKDeviceTool.dll
2021-04-05 00:10 - 2021-04-05 00:10 - 000232960 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTCore.dll
2021-04-05 00:10 - 2021-04-05 00:10 - 000057344 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTFC.dll
2021-04-06 16:05 - 2021-04-06 16:05 - 000668672 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
2021-04-05 00:10 - 2021-04-05 00:10 - 000074240 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
2021-04-05 00:10 - 2021-04-05 00:10 - 000371712 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTUI.dll
2021-04-05 17:43 - 2021-04-05 17:43 - 000057344 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll
2021-04-05 17:43 - 2021-04-05 17:43 - 000074240 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll
2021-04-05 17:43 - 2021-04-05 17:43 - 000368640 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll
2023-07-27 18:27 - 2023-07-26 23:06 - 002882560 _____ () [File not signed] C:\Program Files\NZXT CAM\ffmpeg.dll
2023-07-27 18:27 - 2023-07-26 23:06 - 000480768 _____ () [File not signed] C:\Program Files\NZXT CAM\libegl.dll
2023-07-27 18:27 - 2023-07-26 23:06 - 007625728 _____ () [File not signed] C:\Program Files\NZXT CAM\libglesv2.dll
2021-12-26 09:59 - 2023-07-26 23:06 - 005334528 _____ () [File not signed] C:\Program Files\NZXT CAM\vk_swiftshader.dll
2022-04-10 22:57 - 2022-04-10 22:57 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll
2022-04-10 22:57 - 2022-04-10 22:57 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll
2023-07-27 18:27 - 2023-07-26 23:06 - 000083456 _____ (Silicon Laboratories, Inc.) [File not signed] \\?\C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\nzxt-device\SiUSBXp64.dll
2022-08-09 10:29 - 2022-08-09 10:29 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files\Corsair\CORSAIR iCUE 4 Software\SiUSBXp.dll
2023-08-03 14:53 - 2023-08-03 14:53 - 002849280 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\libcrypto-1_1-x64.dll
2023-08-03 14:53 - 2023-08-03 14:53 - 000685056 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\libssl-1_1-x64.dll
2023-08-03 14:53 - 2023-08-03 14:53 - 000046592 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\bearer\qgenericbearer.dll
2023-08-03 14:53 - 2023-08-03 14:53 - 006270976 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\Qt5Core.dll
2023-08-03 14:53 - 2023-08-03 14:53 - 001389568 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\Qt5Network.dll
2023-08-03 14:53 - 2023-08-03 14:53 - 000157184 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\Qt5WebSockets.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\WINDOWS\tracing:? [34]
AlternateDataStreams: C:\Users\sampo\Data aplikací:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\sampo\Downloads\CrystalDiskInfo9_1_1.exe:MBAM.Zone.Identifier [251]
AlternateDataStreams: C:\Users\sampo\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2023-08-02 07:42 - 2023-08-02 07:42 - 000000841 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-952769170-1753500190-2317307712-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\sampo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{07003901-3941-4166-BA89-040968A94444}] => (Allow) E:\Hry\Steam\steamapps\common\Age2HD\Launcher.exe (TODO: <Company name>) [File not signed]
FirewallRules: [{6C37758E-B9A6-48C1-8BBB-3E0E178168F7}] => (Allow) E:\Hry\Steam\steamapps\common\Age2HD\Launcher.exe (TODO: <Company name>) [File not signed]
FirewallRules: [{D8F6A13B-CDC8-4263-BC26-90FD911EDC21}] => (Allow) E:\Hry\Steam\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [{9FABAD70-D8D6-40E8-A08D-7A692737AEC0}] => (Allow) E:\Hry\Steam\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [UDP Query User{6CF338B0-4C1C-49A3-B13C-9B3F89045A46}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [TCP Query User{48B0CB28-ECEF-4462-BA54-6D86ECB2BACC}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [{3265815A-A3D8-4F00-8F3B-E416A9ACA71F}] => (Allow) E:\Hry\Steam\steamapps\common\Business Tour\BusinessTour.exe () [File not signed]
FirewallRules: [{A7E64A16-4D2E-49A0-8443-8E715C74364D}] => (Allow) E:\Hry\Steam\steamapps\common\Business Tour\BusinessTour.exe () [File not signed]
FirewallRules: [UDP Query User{1E86AD68-C6BE-4FF2-8E2F-7F7028A9B202}E:\hry\steam\steamapps\common\new world public test\bin64\javelin_x64.exe] => (Allow) E:\hry\steam\steamapps\common\new world public test\bin64\javelin_x64.exe (Amazon.com Services LLC -> Amazon.com, Inc.)
FirewallRules: [TCP Query User{0FB5718F-BA4A-4A5E-9B82-268F3B6551C3}E:\hry\steam\steamapps\common\new world public test\bin64\javelin_x64.exe] => (Allow) E:\hry\steam\steamapps\common\new world public test\bin64\javelin_x64.exe (Amazon.com Services LLC -> Amazon.com, Inc.)
FirewallRules: [{DB4A5A39-BF82-4517-B8BE-836B85A59800}] => (Allow) E:\Hry\Steam\steamapps\common\New World Public Test\NewWorldLauncher.exe (Amazon.com Services LLC -> EasyAntiCheat Ltd)
FirewallRules: [{95BD2B98-2B24-4975-9FDD-896039A4E46A}] => (Allow) E:\Hry\Steam\steamapps\common\New World Public Test\NewWorldLauncher.exe (Amazon.com Services LLC -> EasyAntiCheat Ltd)
FirewallRules: [{E4E49511-61ED-4274-B676-A28C1A7BE8BC}] => (Allow) E:\Hry\Steam\steamapps\common\Planet Zoo\PlanetZoo.exe (Frontier Developments) [File not signed]
FirewallRules: [{E3587EBD-9411-4F2C-AC3B-C32504E770BE}] => (Allow) E:\Hry\Steam\steamapps\common\Planet Zoo\PlanetZoo.exe (Frontier Developments) [File not signed]
FirewallRules: [{4A6EA8DB-5132-475D-8135-3588403ED2F4}] => (Allow) E:\Hry\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{EC2A5022-77B6-4B91-A14A-89A81334052D}] => (Allow) E:\Hry\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{3AB73666-C131-4AAE-9091-BE0820EE06EB}] => (Allow) E:\Hry\Steam\steamapps\common\Fall Guys\FallGuys_client.exe (EasyAntiCheat Oy -> Epic Games, Inc)
FirewallRules: [{90DA491F-EDAB-49DF-A75D-5C553E4F36FA}] => (Allow) E:\Hry\Steam\steamapps\common\Fall Guys\FallGuys_client.exe (EasyAntiCheat Oy -> Epic Games, Inc)
FirewallRules: [{D3B2F9D5-ED7B-48B3-9FFF-F0C8BCEA39CF}] => (Allow) E:\Hry\Steam\steamapps\common\TPH\TPH.exe () [File not signed]
FirewallRules: [{09F6ABA4-F985-4E3E-A0A0-B26E21DABACB}] => (Allow) E:\Hry\Steam\steamapps\common\TPH\TPH.exe () [File not signed]
FirewallRules: [{50397C2A-EACA-4B55-B657-0C8A7A82CBE0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [{4650CF71-DA50-4BCB-B5BD-762BD669C182}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [{0250DFFE-CA76-4586-A76A-1AB3235EE9D2}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{D3374B68-322A-4BC2-B586-14E7ED1E5914}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{C4DF3161-C345-4DA5-8232-858AFE080BF4}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B5E39D5A-29F1-4C13-9E0E-07C55C2C9224}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E6E327FE-A80C-482F-9C4B-75DCF953F3B4}] => (Allow) E:\Hry\Steam\steamapps\common\The Witcher 3\bin\x64\witcher3.exe (CD Projekt Red) [File not signed]
FirewallRules: [{4BCF4AA4-1831-4B1C-8177-82751EAAE622}] => (Allow) E:\Hry\Steam\steamapps\common\The Witcher 3\bin\x64\witcher3.exe (CD Projekt Red) [File not signed]
FirewallRules: [TCP Query User{8B703173-F565-4C78-A003-F67BE9945825}C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe] => (Allow) C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe () [File not signed]
FirewallRules: [UDP Query User{B7678BF5-D218-4226-BDB0-C3580DBD9779}C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe] => (Allow) C:\program files (x86)\activision\call of duty 2\cod2mp_s.exe () [File not signed]
FirewallRules: [TCP Query User{B4ED8E11-4BD1-4C92-89B8-BB3E14AFC849}E:\warcraft iii_cz\war3.exe] => (Allow) E:\warcraft iii_cz\war3.exe (Blizzard Entertainment) [File not signed]
FirewallRules: [UDP Query User{E93D9756-C26A-4209-920F-AB686975D574}E:\warcraft iii_cz\war3.exe] => (Allow) E:\warcraft iii_cz\war3.exe (Blizzard Entertainment) [File not signed]
FirewallRules: [{E026ABE9-682B-44B4-9468-F3541BFC11A7}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{D6C40478-7132-4746-B3FB-60D9ECBAEE87}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{0F3A570D-D3FE-417A-8843-F6045F46BE62}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{32B346B6-6239-4902-8CF2-4B2956EBCAE5}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{E62CB012-B3D9-45BC-AE44-F83E448E8766}] => (Allow) E:\Hry\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [{A009518A-C6E2-4554-BC6F-A3E13499F7B3}] => (Allow) E:\Hry\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [TCP Query User{8B43D687-D981-44F6-9C91-4A3294D2EFD9}E:\hry\steam\steamapps\common\fifa 21\fifa21_trial.exe] => (Allow) E:\hry\steam\steamapps\common\fifa 21\fifa21_trial.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [UDP Query User{2A2DB858-2CD8-44C5-BEA4-34F985519874}E:\hry\steam\steamapps\common\fifa 21\fifa21_trial.exe] => (Allow) E:\hry\steam\steamapps\common\fifa 21\fifa21_trial.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [TCP Query User{8D240EED-BBEB-47FA-8F4F-BA93ECDBC99C}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [UDP Query User{EBAA14D6-190F-4FA9-88C1-537C341F62E6}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [{262DF444-4641-4246-BB4E-34048CFA6EAD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe (Digital Extremes Ltd. -> Digital Extremes)
FirewallRules: [{D7FFE48C-4B45-4F40-8473-D3BD3EADA435}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes)
FirewallRules: [{1FF09438-F69E-425F-B851-7200B9C0427E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes)
FirewallRules: [{913CE68F-BB17-41D8-BFF7-3BEE7FEBA64D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe (Digital Extremes Ltd. -> )
FirewallRules: [{BDEA5C2F-22E9-4C1B-B968-D8C54CD4854C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe (Digital Extremes Ltd. -> Digital Extremes)
FirewallRules: [{018523B0-1AA9-4D3D-89B9-E51C0317231A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes)
FirewallRules: [{444F1BBF-7212-4BC4-ABF6-9333108C8481}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes)
FirewallRules: [{6DCCEBD1-40AC-4DE3-86FD-DBC301575556}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe (Digital Extremes Ltd. -> )
FirewallRules: [{9423C2BB-B329-4CB4-9981-8E31E87E057A}] => (Allow) E:\Hry\Steam\steamapps\common\Mafia III\Launcher.exe (2K Games) [File not signed]
FirewallRules: [{1C3EA23B-4A4A-4F32-B7EB-2F6EBBD6E7A6}] => (Allow) E:\Hry\Steam\steamapps\common\Mafia III\Launcher.exe (2K Games) [File not signed]
FirewallRules: [{B566B99A-D1F6-4E6B-A076-507AE4684E70}] => (Allow) E:\Hry\Steam\steamapps\common\Scavengers\Scavengers_Launcher.exe (Epic Games, Inc) [File not signed]
FirewallRules: [{648A0156-130E-4B6B-83EB-54ED00DD0353}] => (Allow) E:\Hry\Steam\steamapps\common\Scavengers\Scavengers_Launcher.exe (Epic Games, Inc) [File not signed]
FirewallRules: [{4CBC12AE-655A-4A06-8C74-99C401F6894B}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{49F8FBE4-DE14-4C49-8382-2D1757F84172}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{885B2726-5CD8-479B-82CF-E85491ABABA3}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{6F5C7965-0C20-4411-85D9-05498E43FAFE}] => (Allow) E:\Hry\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{62D6B899-1FA0-456A-A70D-E882FB1713BF}] => (Allow) E:\Hry\Steam\steamapps\common\Cities_Skylines\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{3FE29F92-91F7-42E7-AC58-0252C97D0CDF}] => (Allow) E:\Hry\Steam\steamapps\common\Cities_Skylines\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{B46C8428-F820-4F08-96E7-60C78D0320A5}] => (Allow) E:\Hry\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [{29A867B0-792E-4B61-BB12-01816F8ECCC3}] => (Allow) E:\Hry\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [{F7EB944F-E12C-4B99-9571-DCCCB822ACA8}] => (Allow) E:\Hry\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.)
FirewallRules: [{92E5705C-1313-4004-801B-DE35EEDE8449}] => (Allow) E:\Hry\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.)
FirewallRules: [{C14E1334-AC87-40F7-9C2D-1E89831B4CB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Business Tour\BusinessTour.exe () [File not signed]
FirewallRules: [{70A95C44-10DD-486A-B88B-297D22302BB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Business Tour\BusinessTour.exe () [File not signed]
FirewallRules: [{3D1FD695-702D-4505-9D08-094C6326F333}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TPH\TPH.exe () [File not signed]
FirewallRules: [{B186D5C6-9C52-41BC-B807-CCDA81227390}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TPH\TPH.exe () [File not signed]
FirewallRules: [TCP Query User{4A5C1E46-6ECC-469C-9A2A-469593036BE2}C:\gog games\quake iii\quake3.exe] => (Allow) C:\gog games\quake iii\quake3.exe () [File not signed]
FirewallRules: [UDP Query User{A3E07028-DCCB-4C56-9610-4914DF626D90}C:\gog games\quake iii\quake3.exe] => (Allow) C:\gog games\quake iii\quake3.exe () [File not signed]
FirewallRules: [{C89C085E-6786-47DD-A39E-DDF63A747DA0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Foundation\foundation.exe (Polymorph Games) [File not signed]
FirewallRules: [{9FF6EB34-6228-47E8-8887-E0115530B3B3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Foundation\foundation.exe (Polymorph Games) [File not signed]
FirewallRules: [{54305240-F392-4E15-81DF-30C48AF9566E}] => (Allow) E:\Hry\steamlib\steamapps\common\The Witcher 3\bin\x64\witcher3.exe (CD PROJEKT SPÓŁKA AKCYJNA -> CD Projekt Red)
FirewallRules: [{E3A12C44-538B-45BD-92D6-545BC3F5C1A5}] => (Allow) E:\Hry\steamlib\steamapps\common\The Witcher 3\bin\x64\witcher3.exe (CD PROJEKT SPÓŁKA AKCYJNA -> CD Projekt Red)
FirewallRules: [{59271CA4-CDC0-4A3D-9A43-89F967EEF308}] => (Allow) E:\Hry\steamlib\steamapps\common\Fall Guys\FallGuys_client.exe () [File not signed]
FirewallRules: [{70A93300-8CA8-4974-9B34-9B2CA6783E21}] => (Allow) E:\Hry\steamlib\steamapps\common\Fall Guys\FallGuys_client.exe () [File not signed]
FirewallRules: [{A8849A70-9621-4C0C-AB64-7EEBE599B427}] => (Allow) F:\SteamLibrary\steamapps\common\Lonely Mountains - Downhill\LMD_Win_x64.exe () [File not signed]
FirewallRules: [{146717EC-CB54-4CD3-80B8-B4242A7F2F0D}] => (Allow) F:\SteamLibrary\steamapps\common\Lonely Mountains - Downhill\LMD_Win_x64.exe () [File not signed]
FirewallRules: [{0E4BDED6-759A-46A0-ABA4-B72CDCDD449C}] => (Allow) F:\SteamLibrary\steamapps\common\Horizon Zero Dawn\HorizonZeroDawn.exe () [File not signed]
FirewallRules: [{DF5A9B54-1991-4382-9E7A-6CCF9971C0C0}] => (Allow) F:\SteamLibrary\steamapps\common\Horizon Zero Dawn\HorizonZeroDawn.exe () [File not signed]
FirewallRules: [{18DC3C31-621D-4218-A951-42E22C6A89F1}] => (Allow) F:\Hry\uplay\Anno 1800\Bin\Win64\Anno1800.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{85FA548F-DECA-4206-8BAC-426F63B05423}] => (Allow) F:\SteamLibrary\steamapps\common\Project Hospital\ProjectHospital.exe () [File not signed]
FirewallRules: [{94905FA3-3F79-4B8A-B998-2D759400F0C2}] => (Allow) F:\SteamLibrary\steamapps\common\Project Hospital\ProjectHospital.exe () [File not signed]
FirewallRules: [{52C9B324-8F65-4B88-B905-09B5C799E4B0}] => (Allow) F:\SteamLibrary\steamapps\common\ForzaHorizon5\ForzaHorizon5.exe (Microsoft Corporation -> )
FirewallRules: [{8CA63884-546A-4AB5-8019-29EC7760BDDF}] => (Allow) F:\SteamLibrary\steamapps\common\ForzaHorizon5\ForzaHorizon5.exe (Microsoft Corporation -> )
FirewallRules: [{21A0931E-12BF-43A2-8919-48B10C131B11}] => (Allow) F:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve Corp. -> )
FirewallRules: [{EA076EEC-DB0F-4821-BA37-DBDD92295DB0}] => (Allow) F:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve Corp. -> )
FirewallRules: [{6B81F9A3-1054-468B-AC5F-03A7921CC4F5}] => (Allow) F:\SteamLibrary\steamapps\common\SongsOfConquest\SongsOfConquest.exe () [File not signed]
FirewallRules: [{E506436F-C0DE-41DB-A5DE-960A98600041}] => (Allow) F:\SteamLibrary\steamapps\common\SongsOfConquest\SongsOfConquest.exe () [File not signed]
FirewallRules: [{0C0BC0C0-20E5-4182-8ED9-2C2564659CBD}] => (Allow) E:\Hry\steamlib\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [{E5557F90-9D21-42CB-8650-6530BC78A725}] => (Allow) E:\Hry\steamlib\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [TCP Query User{0C017EC8-407C-4FCB-AD96-90FFA3D2D8CD}F:\steamlibrary\steamapps\common\battlefield 2042\bf2042.exe] => (Allow) F:\steamlibrary\steamapps\common\battlefield 2042\bf2042.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [UDP Query User{833E3F7B-FB3F-4B90-8840-A63210148EBF}F:\steamlibrary\steamapps\common\battlefield 2042\bf2042.exe] => (Allow) F:\steamlibrary\steamapps\common\battlefield 2042\bf2042.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [TCP Query User{6980F38D-F115-457A-BB54-FF9362805EE7}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{CE5D5426-54BA-4DD6-ADA0-D6745F1D86BD}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{B3577363-2A45-4B30-B587-4D0F5EA3D96A}] => (Allow) F:\SteamLibrary\steamapps\common\Banished\Application-steam-x64.exe () [File not signed]
FirewallRules: [{46C1E2A4-8C18-4480-976B-88FB55A54208}] => (Allow) F:\SteamLibrary\steamapps\common\Banished\Application-steam-x64.exe () [File not signed]
FirewallRules: [{70AF4224-5F16-4F8C-9E36-DB1015FCB40C}] => (Allow) F:\SteamLibrary\steamapps\common\Farthest Frontier\Farthest Frontier.exe () [File not signed]
FirewallRules: [{D837A77A-1A27-493C-9664-9D1919A30627}] => (Allow) F:\SteamLibrary\steamapps\common\Farthest Frontier\Farthest Frontier.exe () [File not signed]
FirewallRules: [{77C564E1-E14B-488A-B857-A015ADD3A3C3}] => (Allow) F:\SteamLibrary\steamapps\common\Cyberpunk 2077\REDprelauncher.exe (GOG sp. z o.o -> GOG.com)
FirewallRules: [{DE9A1947-984A-4140-8F77-88880E167E48}] => (Allow) F:\SteamLibrary\steamapps\common\Cyberpunk 2077\REDprelauncher.exe (GOG sp. z o.o -> GOG.com)
FirewallRules: [{D7FB2506-10BD-41DB-B41D-D684E661D403}] => (Allow) LPort=26820
FirewallRules: [TCP Query User{AFB6F14C-6A75-4982-A197-B6BFEB727DE6}F:\steamlibrary\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) F:\steamlibrary\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe (CD PROJEKT SPÓŁKA AKCYJNA -> CD PROJEKT S.A.)
FirewallRules: [UDP Query User{4F048852-225D-4CD6-AC06-9386720D92F3}F:\steamlibrary\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) F:\steamlibrary\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe (CD PROJEKT SPÓŁKA AKCYJNA -> CD PROJEKT S.A.)
FirewallRules: [{6629F64F-1D09-480E-8069-448A701D3C37}] => (Allow) LPort=26822
FirewallRules: [{6C10FF5F-5C30-4D97-A178-1D46C2324293}] => (Allow) LPort=32682
FirewallRules: [{F0594D84-C733-4984-8537-A090AEE20C3D}] => (Allow) F:\SteamLibrary\steamapps\common\1428\1428.exe () [File not signed]
FirewallRules: [{6451C16E-972C-49A9-B228-C41A4F33D29A}] => (Allow) F:\SteamLibrary\steamapps\common\1428\1428.exe () [File not signed]
FirewallRules: [{C2EF5765-4AD0-421B-AFBA-7F15E3636BF1}] => (Allow) F:\SteamLibrary\steamapps\common\Sherlock Holmes Chapter One\SH9\Binaries\Win64\SHCO.exe (Frogwares Ireland ltd -> Frogwares)
FirewallRules: [{4286F8AE-68B7-4381-943C-4A5F2A641522}] => (Allow) F:\SteamLibrary\steamapps\common\Sherlock Holmes Chapter One\SH9\Binaries\Win64\SHCO.exe (Frogwares Ireland ltd -> Frogwares)
FirewallRules: [{1F2906EE-8F2A-4EF2-83EB-C125615BE624}] => (Allow) E:\Hry\steamlib\steamapps\common\Uncharted Legacy of Thieves Collection\u4.exe () [File not signed]
FirewallRules: [{C4CCEEF2-DC17-4F67-8E64-DD18C3D0B26E}] => (Allow) E:\Hry\steamlib\steamapps\common\Uncharted Legacy of Thieves Collection\u4.exe () [File not signed]
FirewallRules: [{872ADA1C-6C10-46D6-ACC2-EEA855869FA4}] => (Allow) E:\Hry\steamlib\steamapps\common\Red Dead Redemption 2\PlayRDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{6F07E5F3-6147-494C-81CA-8DE8D4F39295}] => (Allow) E:\Hry\steamlib\steamapps\common\Red Dead Redemption 2\PlayRDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{98595BE1-1FC2-41C2-BF08-9CF190C8C6AE}] => (Allow) E:\Hry\steamlib\steamapps\common\The Witcher 3\REDprelauncher.exe (GOG sp. z o.o -> GOG.com)
FirewallRules: [{72FD28B9-A3E0-4D83-AB4C-93E5C4F236B1}] => (Allow) E:\Hry\steamlib\steamapps\common\The Witcher 3\REDprelauncher.exe (GOG sp. z o.o -> GOG.com)
FirewallRules: [{355CDD97-E697-4D81-958B-1ED20EEBF159}] => (Allow) F:\SteamLibrary\steamapps\common\3DMark\bin\x64\3DMark.exe (Underwriters Laboratories Inc. -> )
FirewallRules: [{2A38967C-1390-4984-AE00-6114FDE52575}] => (Allow) F:\SteamLibrary\steamapps\common\3DMark\bin\x64\3DMark.exe (Underwriters Laboratories Inc. -> )
FirewallRules: [{7CA6397A-C1A0-4A9F-9E85-413305FEE8C4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\PlayGTAIV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{6F655BBF-098F-4D21-87DA-DEA87E8F9262}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\PlayGTAIV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{71E8D25D-7C3E-4994-AAA9-C6A9D2DEB2E0}] => (Allow) F:\SteamLibrary\steamapps\common\Crusader Kings III\launcher\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{B64E4D01-595D-4DEE-9917-9E10AB322C7F}] => (Allow) F:\SteamLibrary\steamapps\common\Crusader Kings III\launcher\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{A007E694-F703-4C2B-9C6B-1347DB71680B}] => (Allow) E:\Hry\steamlib\steamapps\common\Surviving Mars\MarsSteam.exe (Haemimont Games) [File not signed]
FirewallRules: [{AC565053-67A2-4DFE-998F-7E57709D6A61}] => (Allow) E:\Hry\steamlib\steamapps\common\Surviving Mars\MarsSteam.exe (Haemimont Games) [File not signed]
FirewallRules: [{057221A8-1046-4464-A148-E8C86EE20C8F}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{4E5BD4CF-443F-4AC9-B898-615F84D7DB33}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{C93B8DA0-8714-4CBE-992C-D1E73C568A5D}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{50D4A6AE-6101-4157-9D87-75AF970BB87E}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{360793B4-39C2-4876-8676-726F1614E546}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{0B3AE3D1-D1C4-4D39-8AEA-9DC7C9AFB932}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)

MariTopHigh
nováček
Příspěvky: 31
Registrován: červenec 23
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod MariTopHigh » 03 srp 2023 23:58

F288A-0E7C-4F38-B748-8E3473F8EA0B}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{73B6FC0E-0A16-4095-87E2-F5A9488EF10F}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{908B8AA5-C0ED-4AEC-B007-E8FB18A364E6}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{12E7D3EB-E2BF-4A51-83B8-87639908F83F}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{A3CE06FF-157A-422A-A148-5F442BFABC29}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{74AB1FA2-FFA9-4B42-B872-DC6699EB1AA4}] => (Allow) D:\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{65C49B56-FDA7-4B07-8813-AD54D005DDE0}] => (Allow) D:\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{7088786A-CCF2-4F66-A041-9499CEB98FB4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{D4CC7C87-F953-4289-BAF6-597E8186B3DB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{843B534D-5283-439B-AECA-5A4B6670732B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{DEA6D03C-1C64-4BF6-A766-0178E0E6E685}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{BF419D62-BA43-4E40-A6A9-8DA0C46804B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{2C2F16AE-9C33-4FB2-AD56-F9B4DA613F8E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{A46EC5B8-1295-43CF-8A20-EB224E18BBEB}D:\hry\uplaywebcore.exe] => (Allow) D:\hry\uplaywebcore.exe (Ubisoft Entertainment Sweden AB -> Ubisoft)
FirewallRules: [UDP Query User{49D44DC2-43CA-4041-A831-CD9753B00573}D:\hry\uplaywebcore.exe] => (Allow) D:\hry\uplaywebcore.exe (Ubisoft Entertainment Sweden AB -> Ubisoft)
FirewallRules: [{D8D276BA-2FB8-4C82-9878-84F9D92E8125}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F60A6B13-8F83-44C2-8719-AB12D9403A50}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{3A8614B1-6546-4A16-979D-2CA9C75B8CF3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A7FAAEE2-5B03-4D65-B064-0F80F5B5827F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FEED9427-9984-4E78-8578-1BA2909B2B7F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A738AD1A-C0F5-425F-8683-8500BA72C1A0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{02FB2E37-4B3E-4E17-9C2B-C984DBDADCD4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BF798CFA-68F5-4A73-A8E0-3B2A466878F4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1A788199-E0CE-4418-8238-47C57B40F0CC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1B76CD47-B8AC-44F0-A70D-75779002FDC3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.215.828.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B2D50DB3-4887-40C0-AD72-791F7F8D707E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BB75A140-04B7-4C42-AAF7-30669865529E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{25009850-8149-4BAA-9972-50AF9392A9D2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F79F2EB3-DF54-4457-A668-1C984AA78237}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{22B719AD-FD59-416B-894E-F84D98C1D16E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{9B2BD541-F1DA-41EC-BF78-C3A1A5A2D2FC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{17E97059-5DB0-4D17-896A-4FA994EE2644}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2D2482C0-3186-40F0-A871-F7753B130A87}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D13BA777-5619-46D5-8E8A-0F97FCF639D5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{87847035-8FF3-4B0B-B40E-00637D74C0BC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.216.947.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{32DB5E25-1F01-4F3D-BF01-6DD570FA8A07}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{C861BF70-92B6-4921-8E2C-7F019090B029}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\115.0.1901.188\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{EE34783B-87D6-4AC3-AB34-C6377BCD9695}] => (Allow) F:\SteamLibrary\steamapps\common\AoE2DE\AoE2DE_s.exe (Wicked Witch Software Pty Ltd -> Microsoft Corporation)
FirewallRules: [{1B4423D4-AE0C-4E8E-B0F0-888AE045F7F4}] => (Allow) F:\SteamLibrary\steamapps\common\AoE2DE\AoE2DE_s.exe (Wicked Witch Software Pty Ltd -> Microsoft Corporation)
FirewallRules: [{E938D3DC-565E-4427-B039-CAC5634FBA22}] => (Allow) F:\SteamLibrary\steamapps\common\AoE2DE\BattleServer\BattleServer.exe () [File not signed]
FirewallRules: [{9AC6CEB4-D81C-4AE4-8A8A-39186977C757}] => (Allow) F:\SteamLibrary\steamapps\common\AoE2DE\BattleServer\BattleServer.exe () [File not signed]
FirewallRules: [{0AB96220-22AF-4432-80B0-F7AACD1684DA}] => (Allow) C:\Program Files (x86)\Overwolf\0.228.0.20\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{BF13221B-0589-4CC0-86F7-A366227FA358}] => (Allow) C:\Program Files (x86)\Overwolf\0.228.0.20\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{8BE2400E-9CEA-483C-A0CA-6FA2F75131E9}] => (Block) C:\Program Files (x86)\Overwolf\0.228.0.20\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{53B98A9E-5235-4570-8B71-241C12D88D24}] => (Block) C:\Program Files (x86)\Overwolf\0.228.0.20\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{42582738-CDF5-4D5E-989F-2207A9B91764}] => (Allow) C:\Program Files (x86)\Overwolf\0.221.109.14\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{9AA4A9D1-E23F-48ED-B5AB-6C6595F887E4}] => (Allow) C:\Program Files (x86)\Overwolf\0.221.109.14\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{3E647F87-EDAF-42BE-BAA8-D0A418357689}] => (Block) C:\Program Files (x86)\Overwolf\0.221.109.14\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{F43A7992-ACC3-4E00-8C26-7E327AB64DE0}] => (Block) C:\Program Files (x86)\Overwolf\0.221.109.14\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{4A91F421-B99D-4F9D-8E5E-A6DC070441AD}] => (Allow) C:\Program Files (x86)\Overwolf\0.228.0.21\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{636DDEE6-61D0-4771-B74D-49AF71CF3EAF}] => (Allow) C:\Program Files (x86)\Overwolf\0.228.0.21\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)

==================== Restore Points =========================

02-08-2023 19:43:55 End of disinfection
02-08-2023 19:46:17 Removed Sophos Virus Removal Tool.
03-08-2023 14:43:32 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices ============

Name: VPN Client Adapter - VPN
Description: VPN Client Adapter - VPN
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: SoftEther Corporation
Service: Neo_VPN
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (08/03/2023 03:51:33 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.

Error: (08/03/2023 03:51:33 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]

Error: (08/03/2023 03:51:33 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.

Error: (08/03/2023 03:51:33 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]

Error: (08/03/2023 03:38:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AoE2DE_s.exe, verze: 101.102.24724.0, časové razítko: 0x64be191d
Název chybujícího modulu: MessageBus.dll, verze: 1.22.2758.1620, časové razítko: 0x5dc56514
Kód výjimky: 0x80000003
Posun chyby: 0x00000000001aaf4e
ID chybujícího procesu: 0x4de8
Čas spuštění chybující aplikace: 0x01d9c60dc40b29e0
Cesta k chybující aplikaci: F:\SteamLibrary\steamapps\common\AoE2DE\AoE2DE_s.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\NvContainer\MessageBus.dll
ID zprávy: 65252b4b-4340-41d7-a6d9-1a538af95319
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/03/2023 03:23:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: EALaunchHelper.exe, verze: 12.251.0.5508, časové razítko: 0x64c81859
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.19041.789, časové razítko: 0x2bd748bf
Kód výjimky: 0xc0000409
Posun chyby: 0x000000000007286e
ID chybujícího procesu: 0x2aa8
Čas spuštění chybující aplikace: 0x01d9c60daab777e7
Cesta k chybující aplikaci: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID zprávy: 297d9edd-c842-4a66-94cd-abd0b2305739
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/02/2023 11:04:51 PM) (Source: CAM Service) (EventID: 1) (User: )
Description: request thread encountered an error: Failed to send result: io error: Přesměrování se uzavírá. (os error 232)

Error: (08/02/2023 07:45:27 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Centru zabezpečení se nepodařilo ověřit volajícího s chybou %1.


System errors:
=============
Error: (08/03/2023 03:53:28 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Služba DCOM zjistila chybu 1115 při pokusu o spuštění služby SecurityHealthService s argumenty Není k dispozici za účelem spuštění serveru:
{8C9C0DB7-2CBA-40F1-AFE0-C55740DD91A0}

Error: (08/03/2023 02:43:51 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80073d02): 9NMPJ99VJBWV-Microsoft.YourPhone.

Error: (08/02/2023 07:44:46 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba CCleaner Performance Optimizer Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (08/02/2023 07:53:29 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (08/02/2023 07:53:29 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (08/02/2023 07:53:29 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (08/02/2023 07:53:29 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (08/02/2023 07:53:29 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


Windows Defender:
================
Date: 2023-07-31 16:19:37
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {D4AF1BCB-5D32-42E2-9484-93FC504C9389}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2023-07-30 12:54:38
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {B69AB1D9-A259-451A-928F-2128E199F612}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2023-07-16 19:44:14
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {0B68D016-4529-4F66-AEE5-7E9EC38A178B}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2023-07-07 21:39:04
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {15C23F3A-9CD1-4CBB-AA92-2E6642C228F9}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2022-07-05 13:04:50
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {7F28B9B1-09DC-4B20-BFBC-EF84697E7FA2}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Event[0]:

Date: 2023-08-01 18:11:48
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 1.393.1993.0
Předchozí verze bezpečnostních informací: 1.393.1942.0
Zdroj aktualizace: Uživatel
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.23060.1005
Předchozí verze modulu: 1.1.23060.1005
Kód chyby: 0x80501102
Popis chyby: Došlo k neočekávaným potížím. Nainstalujte všechny dostupné aktualizace a potom opakujte spuštění programu. Informace o instalaci aktualizací naleznete v nápovědě a podpoře.

Date: 2023-08-01 18:11:48
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 1.393.1993.0
Předchozí verze bezpečnostních informací: 1.393.1942.0
Zdroj aktualizace: Uživatel
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.23060.1005
Předchozí verze modulu: 1.1.23060.1005
Kód chyby: 0x80501102
Popis chyby: Došlo k neočekávaným potížím. Nainstalujte všechny dostupné aktualizace a potom opakujte spuštění programu. Informace o instalaci aktualizací naleznete v nápovědě a podpoře.

Date: 2023-08-01 06:21:06
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.393.1942.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.23060.1005
Kód chyby: 0x80070102
Popis chyby: Vypršel časový limit operace čekání.

Date: 2023-08-01 06:21:06
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.393.1942.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.23060.1005
Kód chyby: 0x80070102
Popis chyby: Vypršel časový limit operace čekání.

Date: 2023-07-26 18:20:25
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.393.1479.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.23060.1005
Kód chyby: 0x80070643
Popis chyby: Při instalaci došlo k závažné chybě.

CodeIntegrity:
===============
Date: 2023-08-03 20:01:26
Description:
Code Integrity determined that a process (\Device\HarddiskVolume9\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-07-26 18:32:48
Description:
Code Integrity determined that a process (\Device\HarddiskVolume9\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume9\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2023-07-26 18:32:48
Description:
Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\AVG\Antivirus\AVGSvc.exe) attempted to load \Device\HarddiskVolume9\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-07-26 18:08:15
Description:
Code Integrity determined that a process (\Device\HarddiskVolume9\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. 1.B0 10/12/2020
Motherboard: Micro-Star International Co., Ltd. MPG Z390 GAMING PRO CARBON (MS-7B17)
Processor: Intel(R) Core(TM) i9-9900KF CPU @ 3.60GHz
Percentage of memory in use: 40%
Total physical RAM: 16318.23 MB
Available physical RAM: 9713.59 MB
Total Virtual: 41918.23 MB
Available Virtual: 27006.5 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:476.41 GB) (Free:223.37 GB) (Model: XPG GAMMIX S11 Pro) NTFS
Drive d: (Nový svazek) (Fixed) (Total:222.94 GB) (Free:115.87 GB) (Model: KINGSTON SHSS37A240G) NTFS
Drive e: () (Fixed) (Total:931.5 GB) (Free:172.2 GB) (Model: SAMSUNG HD103UJ) NTFS
Drive f: (Hry) (Fixed) (Total:931.5 GB) (Free:230.18 GB) (Model: Samsung SSD 970 EVO 1TB) NTFS

\\?\Volume{54972566-ad40-4f62-b413-07395e7c8921}\ () (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{8365fd1f-d2d9-4394-9281-f543e9917ced}\ (Obnovení) (Fixed) (Total:0.52 GB) (Free:0.5 GB) NTFS
\\?\Volume{e1cd9e29-8499-4111-ad8c-914c1c155aa1}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 476.9 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 2 (Size: 223.6 GB) (Disk ID: 45DA2510)

Partition: GPT.

==========================================================
Disk: 3 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 9C69F461)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=0F Extended)

==================== End of Addition.txt =======================

MariTopHigh
nováček
Příspěvky: 31
Registrován: červenec 23
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod MariTopHigh » 03 srp 2023 23:59

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-08-2023
Ran by sampo (administrator) on DESKTOP-CDF7F25 (Micro-Star International Co., Ltd. MS-7B17) (03-08-2023 23:49:07)
Running from C:\Users\sampo\Desktop\FRST64 (1).exe
Loaded Profiles: sampo
Platform: Microsoft Windows 10 Pro Version 22H2 19045.3208 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
(C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
(C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.CpuIdRemote64.exe
(C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.DisplayAdapter.exe
(C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\MKCHelper.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(C:\Program Files\NZXT CAM\NZXT CAM.exe ->) (NZXT, Inc. -> ) C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\cam_helper.exe <3>
(C:\Windows\runSW.exe ->) (Realtek Semiconductor Corp. -> Realtek) C:\Windows\SwUSB.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <15>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (NZXT, Inc. -> NZXT, Inc.) C:\Program Files\NZXT CAM\NZXT CAM.exe <5>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.292\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.292\GoogleCrashHandler64.exe
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.03\atkexComSvc.exe
(services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe
(services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe
(services.exe ->) (Corsair Memory, Inc. -> Corsair) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUEDevicePluginHost.exe <8>
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
(services.exe ->) (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_08f11cc9a4c9585a\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_724e05bd98458fe4\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5b6e4554b945d508\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NZXT, Inc. -> ) C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> ) C:\Windows\runSW.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_550508a90a3c9a47\RtkAudUService64.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2210.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21524.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21524.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_550508a90a3c9a47\RtkAudUService64.exe [1618320 2022-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [CORSAIR iCUE 4 Software] => C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE Launcher.exe [185384 2022-10-07] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2607520 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [2671208 2023-08-03] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4374376 2023-07-28] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\Run: [NZXT.CAM] => C:\Program Files\NZXT CAM\NZXT CAM.exe [162104256 2023-07-26] (NZXT, Inc. -> NZXT, Inc.)
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\Run: [Battle.net] => C:\Program Files (x86)\Battle.net\Battle.net.exe [1090168 2023-07-28] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\MountPoints2: {2fd055ed-c4ec-11e9-ba0c-806e6f6e6963} - "F:\Autorun.exe"
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\MountPoints2: {ce987094-3ccb-11ec-bacc-e0d55e2002ee} - "I:\setup\rsrc\Autorun.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\115.0.5790.110\Installer\chrmstp.exe [2023-07-26] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {4E6BDA16-85E4-411E-996B-3FA03E63A665} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.)
Task: {049BB3A9-1290-4263-BC08-954C65C8A039} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-17] (Google Inc -> Google LLC)
Task: {BD972EC3-FE1F-4F92-997D-C80F2BE90AE5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-17] (Google Inc -> Google LLC)
Task: {B7D1198B-93AE-4E1B-90CC-2312ED84A163} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel(R) Corporation)
Task: {FB1A6E3B-04A3-48B1-8934-63D15514DE87} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {40D12799-0098-4045-B8FF-86859BBEC187} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26656184 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {3D1426E9-6800-489B-B067-57129D4AEAB4} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26656184 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {7D38F527-F285-4652-B790-5EA319C63329} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124312 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {F470709E-E394-472E-BBE5-D1E6780FE3ED} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124312 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {E4206D2D-B101-4A38-A6E1-12B933EB5D43} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E834CDD6-4E4A-41E4-9DC3-FDC5D1355602} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {35CC0E1D-AF5C-4E2F-A018-696BA2650158} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {70A94FD0-A49F-4480-9C1B-4067985AF463} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BACDD143-4CF9-4210-BBFB-56B432F98E87} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2646160 2019-10-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {4E5352E3-6533-4BB9-8A8A-711CFB236E1D} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2043016 2019-10-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {B75D7CF3-5CAC-4E40-A26B-039BAA5DFB4A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2177464 2019-10-16] (Microsoft Corporation -> Microsoft)
Task: {6A78FEF1-C835-44DB-98DC-50795AFB26A2} - System32\Tasks\Microsoft_MKC_Logon_Task_ceip.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ceip.exe [32696 2019-10-16] (Microsoft Corporation -> Microsoft)
Task: {4A2785D1-D01E-4690-BA6C-2076609B0A1B} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2646160 2019-10-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {CD1B1268-F654-4C6B-B854-9854BDD1375B} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2043016 2019-10-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {875F26AB-F66B-479A-9CD8-B301698D8891} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [792120 2021-05-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {452E74EE-678D-4439-9887-64ADC84577F1} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {FF4F91AE-0903-4403-BD3B-BB32037CECA2} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation)
Task: {41E23BA1-A91D-4DF5-BCF5-28A66AB26CEA} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F363BFB3-4033-4B03-AD25-A7AB0B4741D9} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {007DBD3D-B3AD-4018-B870-7595D6C1618E} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CC12D06A-FBA9-4035-A54B-4788594216EE} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CEA6E74F-D642-4C8B-BC41-25A0314E799F} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9465FA01-C6B6-4247-AD47-EC5F73AE5A8A} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AFA93710-C6DE-48B2-B2C8-796C7271E321} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C261AF13-1B34-4899-9612-1F66CE17A888} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4125576 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {BF3503F5-F40E-4FBF-99E8-3969DA71CC0A} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-952769170-1753500190-2317307712-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4125576 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {148969FE-D2E0-41F2-AD6B-E8BDB9ED3248} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2641416 2023-08-03] (Overwolf Ltd -> Overwolf LTD)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Intel PTT EK Recertification.job => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{7adfea59-1933-47d8-992a-990dc35d8ff0}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{7adfea59-1933-47d8-992a-990dc35d8ff0}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{ba561924-7ba9-4f76-b9dc-c5e202681083}: [DhcpNameServer] 192.168.0.1

Edge:
=======
Edge DefaultProfile: Default

FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.15 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-07-03] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\sampo\AppData\Local\Google\Chrome\User Data\Default [2023-08-03]
CHR Extension: (Adobe Acrobat: nástroje pro úpravu, převod a podpis souborů PDF) - C:\Users\sampo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2023-08-02]
CHR Extension: (Dokumenty Google offline) - C:\Users\sampo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\sampo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-08-02]
CHR HKU\S-1-5-21-952769170-1753500190-2317307712-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.)
S3 AntiCheatExpert Service; C:\Program Files\AntiCheatExpert\SGuard\x64\SGuardSvc64.exe [2688544 2022-07-06] (PUBG CORPORATION -> )
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.03\atkexComSvc.exe [449336 2021-01-15] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [313008 2020-10-21] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [9880840 2022-12-13] (BattlEye Innovations e.K. -> )
R2 CAMService; C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\service.exe [652736 2023-07-26] (NZXT, Inc. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11867104 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 CorsairGamingAudioConfig; C:\Windows\System32\CorsairGamingAudioCfgService64.exe [613944 2022-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe [238632 2022-10-07] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 CorsairService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe [84008 2022-10-07] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
S2 CorsairUniwillService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueUniwillService.exe [108072 2022-10-07] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [11519592 2023-08-03] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-09-28] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029456 2022-10-05] (Epic Games Inc. -> Epic Games, Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncHelper.exe [3447736 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
R3 iCUEDevicePluginHost; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUEDevicePluginHost.exe [459816 2022-10-07] (Corsair Memory, Inc. -> Corsair)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\23.142.0709.0001\OneDriveUpdaterService.exe [3783544 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2641416 2023-08-03] (Overwolf Ltd -> Overwolf LTD)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2020-01-18] (Even Balance, Inc. -> )
S3 Rockstar Service; E:\Hry\Launcher\RockstarService.exe [1846768 2023-04-05] (Rockstar Games, Inc. -> Rockstar Games)
R2 RunSwUSB; C:\Windows\runSW.exe [59232 2019-08-19] (Realtek Semiconductor Corp. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402216 2023-07-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe [5964328 2023-02-02] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\NisSrv.exe [3244928 2023-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe [133576 2023-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [12184416 2023-05-19] (KRAFTON, Inc. -> KRAFTON, Inc)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5b6e4554b945d508\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5b6e4554b945d508\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACE-BASE; C:\WINDOWS\system32\drivers\ACE-BASE.sys [2178912 2022-09-06] (PUBG CORPORATION -> ANTICHEATEXPERT.COM)
S3 ACE-GAME; C:\WINDOWS\system32\drivers\ACE-GAME.sys [914760 2022-09-06] (PUBG CORPORATION -> ANTICHEATEXPERT.COM)
R1 Asusgio2; C:\WINDOWS\system32\drivers\AsIO2.sys [33832 2019-04-09] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\WINDOWS\system32\drivers\AsIO3.sys [43920 2020-12-16] (ASUSTeK Computer Inc. -> )
S3 athr; C:\WINDOWS\System32\drivers\athwbx.sys [3880448 2013-11-13] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros Communications, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 CorsairGamingAudioService; C:\WINDOWS\system32\DRIVERS\CorsairGamingAudio64.sys [63032 2022-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAccessC2D033F14715AA7325305EA42FBFC65BF867CC1D; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairLLAccess64.sys [21752 2022-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [47032 2022-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [22968 2022-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 cpuz154; C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys [40976 2023-08-03] (Microsoft Windows Hardware Compatibility Publisher -> CPUID)
R3 cpuz157; C:\WINDOWS\temp\cpuz157\cpuz157_x64.sys [43568 2023-08-03] (Microsoft Windows Hardware Compatibility Publisher -> CPUID)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2019-11-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2019-11-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 EneTechIo; C:\WINDOWS\system32\drivers\ene.sys [20992 2020-05-12] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2019-08-19] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 gdrv; C:\WINDOWS\gdrv.sys [25640 2021-09-03] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
R1 HWiNFO_160; C:\WINDOWS\system32\drivers\HWiNFO64A_160.SYS [64536 2021-06-05] (Martin Malik - REALiX -> REALiX(tm))
S3 logi_audio_surround; C:\WINDOWS\system32\drivers\logi_audio_surround.sys [44488 2021-11-09] (Logitech Inc -> Logitech)
S3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [44880 2022-11-17] (Logitech Inc -> Logitech)
S3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [32080 2022-11-17] (Logitech Inc -> Logitech)
S3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [73040 2022-11-17] (Logitech Inc -> Logitech)
R3 MpKsl5b1e86d9; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7D1DC120-16A0-4603-A1C5-C09570566EBD}\MpKslDrv.sys [221480 2023-08-03] (Microsoft Windows -> Microsoft Corporation)
R1 MSIO; C:\WINDOWS\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [86224 2022-08-19] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [37824 2020-03-21] (SoftEther Corporation -> SoftEther Corporation)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8231912 2019-12-03] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2023-07-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [498944 2023-07-26] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99608 2023-07-26] (Microsoft Windows -> Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [1447240 2023-05-30] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S1 amsdk; \??\C:\WINDOWS\system32\drivers\amsdk.sys [X]
S3 cpuz145; \??\C:\WINDOWS\temp\cpuz145\cpuz145_x64.sys [X]
S3 cpuz150; \??\C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys [X]
S3 cpuz152; \??\C:\WINDOWS\temp\cpuz152\cpuz152_x64.sys [X]
S3 HWiNFO_150; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_150.SYS [X] <==== ATTENTION
S3 HWiNFO_161; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_161.SYS [X] <==== ATTENTION
S3 HWiNFO_162; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_162.SYS [X] <==== ATTENTION
S3 HWiNFO_165; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_165.SYS [X] <==== ATTENTION
S3 semav6msr64; \??\C:\WINDOWS\system32\drivers\semav6msr64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-08-03 23:49 - 2023-08-03 23:49 - 000031746 _____ C:\Users\sampo\Desktop\FRST.txt
2023-08-03 23:49 - 2023-08-03 23:49 - 000000000 ____D C:\FRST
2023-08-03 23:47 - 2023-08-03 23:47 - 002700800 _____ (Farbar) C:\Users\sampo\Downloads\FRST64.exe
2023-08-03 23:47 - 2023-08-03 23:47 - 002700800 _____ (Farbar) C:\Users\sampo\Desktop\FRST64 (1).exe
2023-08-03 14:49 - 2023-08-03 14:49 - 000000000 ____D C:\Users\sampo\AppData\Local\PeerDistRepub
2023-08-02 19:42 - 2023-08-02 19:42 - 000781312 _____ C:\Users\sampo\Downloads\delfix_1.010 (1).exe
2023-08-02 07:58 - 2023-08-03 19:18 - 000000000 ____D C:\Users\sampo\AppData\Roaming\NZXT CAM
2023-08-02 07:58 - 2023-08-02 07:59 - 013922376 _____ (Zemana Ltd. ) C:\Users\sampo\Downloads\Zemana.AntiMalware.Setup.exe
2023-08-02 07:58 - 2023-08-02 07:58 - 000000000 ____D C:\Users\sampo\AppData\Local\DBG
2023-08-02 07:56 - 2014-02-13 23:59 - 000024064 _____ C:\WINDOWS\zoek-delete.exe
2023-08-01 18:16 - 2023-08-01 21:35 - 000165077 _____ C:\Users\sampo\Downloads\Data k posouzení úvěru - TAURUM finance.xlsx
2023-08-01 18:12 - 2023-08-01 18:12 - 000003780 _____ C:\WINDOWS\system32\poslední.txt
2023-08-01 00:29 - 2019-12-07 02:51 - 000013657 _____ C:\Users\sampo\Desktop\manual.html
2023-08-01 00:28 - 2023-08-01 00:28 - 000017671 _____ C:\Users\sampo\Downloads\MemTest.zip
2023-07-31 23:49 - 2023-07-31 23:49 - 185115928 _____ (Sophos Limited) C:\Users\sampo\Downloads\Sophos Virus Removal Tool.exe
2023-07-31 18:25 - 2023-07-31 18:25 - 005793080 _____ (Crystal Dew World ) C:\Users\sampo\Downloads\CrystalDiskInfo9_1_1.exe
2023-07-31 15:35 - 2023-07-31 15:35 - 000000222 _____ C:\Users\sampo\Desktop\Age of Empires II Definitive Edition.url
2023-07-26 18:38 - 2023-07-26 18:38 - 000848374 _____ C:\Users\sampo\OneDrive\Dokumenty\cc_20230726_183801.reg
2023-07-26 18:30 - 2023-07-31 18:15 - 000000000 ____D C:\ProgramData\AVG
2023-07-26 18:28 - 2023-07-26 18:29 - 056724008 _____ (Piriform Software Ltd) C:\Users\sampo\Downloads\ccsetup614.exe
2023-07-12 17:01 - 2023-07-12 17:01 - 000000000 ___HD C:\$WinREAgent
2023-07-05 12:32 - 2023-07-05 19:19 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-08-03 23:48 - 2019-11-15 23:35 - 000000000 ____D C:\Program Files (x86)\Steam
2023-08-03 23:47 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-08-03 23:47 - 2019-08-04 16:00 - 000000000 ____D C:\Users\sampo\AppData\Roaming\TS3Client
2023-08-03 23:04 - 2021-12-16 18:12 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-08-03 23:04 - 2019-08-04 16:48 - 000000000 ____D C:\Program Files (x86)\Google
2023-08-03 22:38 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-08-03 22:02 - 2022-08-21 10:17 - 000000000 ____D C:\ProgramData\NVIDIA
2023-08-03 22:01 - 2020-09-19 22:21 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-08-03 21:58 - 2022-09-24 19:03 - 000000000 ____D C:\Users\sampo\AppData\Local\Battle.net
2023-08-03 21:54 - 2023-05-14 09:54 - 000000000 ____D C:\Program Files (x86)\Overwolf
2023-08-03 19:18 - 2019-08-04 15:45 - 000000000 ___RD C:\Users\sampo\OneDrive
2023-08-03 16:24 - 2021-08-29 19:30 - 000003142 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner
2023-08-03 16:00 - 2020-09-19 22:30 - 001693140 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-08-03 16:00 - 2019-12-07 16:43 - 000716770 _____ C:\WINDOWS\system32\perfh005.dat
2023-08-03 16:00 - 2019-12-07 16:43 - 000144948 _____ C:\WINDOWS\system32\perfc005.dat
2023-08-03 16:00 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2023-08-03 15:53 - 2021-11-06 00:21 - 000008192 ___SH C:\DumpStack.log.tmp
2023-08-03 15:53 - 2021-06-05 21:34 - 000000000 ____D C:\Intel
2023-08-03 15:53 - 2020-09-19 22:25 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-08-03 15:53 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2023-08-03 15:52 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-08-03 15:38 - 2019-10-04 15:10 - 000000000 ____D C:\Users\sampo\AppData\Local\CrashDumps
2023-08-03 14:43 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-08-02 20:23 - 2019-08-04 16:00 - 000000000 ____D C:\Program Files\TeamSpeak 3 Client
2023-08-02 19:46 - 2021-10-17 09:05 - 000000000 ____D C:\Users\sampo\AppData\Local\AMSDK
2023-08-02 19:46 - 2019-11-17 23:07 - 001487665 _____ C:\WINDOWS\ZAM.krnl.trace
2023-08-02 19:45 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-08-02 19:44 - 2021-10-19 16:26 - 000001185 _____ C:\DelFix.txt
2023-08-01 21:31 - 2022-01-30 19:35 - 000000000 ____D C:\Users\sampo\AppData\Roaming\Microsoft\Excel
2023-08-01 18:21 - 2022-01-30 19:31 - 000000000 ____D C:\Users\sampo\AppData\Roaming\Microsoft\Word
2023-08-01 18:16 - 2019-08-04 15:43 - 000000000 ____D C:\Users\sampo\AppData\Local\Packages
2023-08-01 18:12 - 2022-04-10 22:53 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2023-08-01 06:59 - 2020-09-19 22:25 - 000003768 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-08-01 06:59 - 2020-09-19 22:25 - 000003644 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-07-31 23:45 - 2022-03-22 22:23 - 000000000 ____D C:\Users\sampo\AppData\Local\ForzaHorizon5
2023-07-31 18:25 - 2020-04-08 21:31 - 000001828 _____ C:\Users\sampo\Desktop\CrystalDiskInfo.lnk
2023-07-31 18:25 - 2020-04-08 21:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2023-07-31 18:25 - 2020-04-08 21:31 - 000000000 ____D C:\Program Files\CrystalDiskInfo
2023-07-31 18:16 - 2020-09-19 22:21 - 000440752 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-07-31 18:15 - 2022-01-31 15:53 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2023-07-30 12:26 - 2022-08-21 10:11 - 000000000 ____D C:\Users\sampo\AppData\Local\D3DSCache
2023-07-30 09:05 - 2023-01-18 15:52 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-07-30 09:05 - 2022-09-24 19:02 - 000000000 ____D C:\Program Files (x86)\Battle.net
2023-07-30 09:05 - 2020-06-10 15:29 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-07-27 21:17 - 2022-01-30 19:22 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2023-07-27 21:17 - 2022-01-30 19:22 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-07-27 21:17 - 2021-12-11 19:21 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-952769170-1753500190-2317307712-1001
2023-07-27 18:31 - 2019-08-04 16:56 - 000918960 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2023-07-27 18:27 - 2021-12-26 09:59 - 000000000 ____D C:\Program Files\NZXT CAM
2023-07-26 18:31 - 2021-11-13 11:55 - 000000000 ____D C:\WINDOWS\Minidump
2023-07-26 18:11 - 2019-11-17 23:13 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-07-26 18:11 - 2019-11-17 23:13 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-07-26 18:08 - 2019-08-04 15:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2023-07-20 15:57 - 2019-08-04 21:42 - 000000000 ____D C:\Users\sampo\AppData\Local\Ubisoft Game Launcher
2023-07-12 23:58 - 2020-09-19 22:21 - 000000000 ____D C:\Users\sampo
2023-07-12 21:37 - 2021-07-05 15:06 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2023-07-12 21:27 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-07-12 21:27 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-07-12 21:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2023-07-12 21:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2023-07-12 21:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2023-07-12 21:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2023-07-12 21:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-07-12 21:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-07-12 17:04 - 2020-09-19 22:25 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-07-12 17:01 - 2019-08-04 16:57 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-07-12 16:59 - 2019-08-04 16:57 - 173351160 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-07-12 16:35 - 2021-08-16 21:35 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2023-07-11 16:32 - 2023-01-14 09:01 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2023-07-11 16:32 - 2023-01-14 09:00 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2023-07-11 16:32 - 2023-01-14 09:00 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2023-07-08 13:37 - 2019-10-04 15:09 - 000000000 ____D C:\Users\sampo\OneDrive\Dokumenty\Anno 1800
2023-07-08 12:26 - 2023-05-30 22:47 - 000001429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio Installer.lnk
2023-07-08 12:26 - 2023-05-30 22:47 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2023-07-07 16:59 - 2019-08-04 19:17 - 000000000 ____D C:\Users\sampo\OneDrive\Dokumenty\my games
2023-07-05 21:34 - 2020-09-19 22:25 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-07-05 21:34 - 2020-09-19 22:25 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-07-05 19:21 - 2022-07-16 23:08 - 000000000 ____D C:\ProgramData\Norton
2023-07-05 19:19 - 2019-12-07 11:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2023-07-05 19:18 - 2019-10-17 14:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2023-07-05 18:04 - 2019-08-04 16:54 - 000000000 ____D C:\Users\sampo\AppData\Local\Warframe

==================== Files in the root of some directories ========

2021-07-05 14:56 - 2022-01-16 18:18 - 001065984 _____ () C:\Users\sampo\AppData\Local\file__0.localstorage
2021-10-20 20:57 - 2021-10-20 20:57 - 000002730 _____ () C:\Users\sampo\AppData\Local\recently-used.xbel

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 04 srp 2023 01:04

AV: Windows Defender (Enabled - Up to date)

Psal jsem vypnout antivir!

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CreateRestorePoint:
CloseProcesses:
AlternateDataStreams: C:\WINDOWS\tracing:? [34]
AlternateDataStreams: C:\Users\sampo\Data aplikací:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\sampo\Downloads\CrystalDiskInfo9_1_1.exe:MBAM.Zone.Identifier [251]
AlternateDataStreams: C:\Users\sampo\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\MountPoints2: {2fd055ed-c4ec-11e9-ba0c-806e6f6e6963} - "F:\Autorun.exe"
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\MountPoints2: {ce987094-3ccb-11ec-bacc-e0d55e2002ee} - "I:\setup\rsrc\Autorun.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {049BB3A9-1290-4263-BC08-954C65C8A039} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-17] (Google Inc -> Google LLC)
Task: {BD972EC3-FE1F-4F92-997D-C80F2BE90AE5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-17] (Google Inc -> Google LLC)
Task: {FB1A6E3B-04A3-48B1-8934-63D15514DE87} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.15 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
S3 cpuz145; \??\C:\WINDOWS\temp\cpuz145\cpuz145_x64.sys [X]
S3 cpuz150; \??\C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys [X]
S3 HWiNFO_150; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_150.SYS [X] <==== ATTENTION
S3 HWiNFO_161; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_161.SYS [X] <==== ATTENTION
S3 HWiNFO_162; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_162.SYS [X] <==== ATTENTION
S3 HWiNFO_165; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_165.SYS [X] <==== ATTENTION
C:\ProgramData\AVG
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\ProgramData\Norton

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Date: 2023-07-26 18:32:48
Description:
Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\AVG\Antivirus\AVGSvc.exe) attempted to load \Device\HarddiskVolume9\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Pokud jsou tam zbytky AVG a Norton, pak použít třeba program Revo Uninstaller ( fce hledat) a smazat.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

MariTopHigh
nováček
Příspěvky: 31
Registrován: červenec 23
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod MariTopHigh » 04 srp 2023 19:10

omlouvám se, už jsem z toho který anitivir je puštěný jelen

Fix result of Farbar Recovery Scan Tool (x64) Version: 01-08-2023
Ran by sampo (04-08-2023 18:29:02) Run:1
Running from C:\Users\sampo\Desktop
Loaded Profiles: sampo
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
AlternateDataStreams: C:\WINDOWS\tracing:? [34]
AlternateDataStreams: C:\Users\sampo\Data aplikací:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\sampo\Downloads\CrystalDiskInfo9_1_1.exe:MBAM.Zone.Identifier [251]
AlternateDataStreams: C:\Users\sampo\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\MountPoints2: {2fd055ed-c4ec-11e9-ba0c-806e6f6e6963} - "F:\Autorun.exe"
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\...\MountPoints2: {ce987094-3ccb-11ec-bacc-e0d55e2002ee} - "I:\setup\rsrc\Autorun.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {049BB3A9-1290-4263-BC08-954C65C8A039} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-17] (Google Inc -> Google LLC)
Task: {BD972EC3-FE1F-4F92-997D-C80F2BE90AE5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-17] (Google Inc -> Google LLC)
Task: {FB1A6E3B-04A3-48B1-8934-63D15514DE87} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.15 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN)
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
S3 cpuz145; \??\C:\WINDOWS\temp\cpuz145\cpuz145_x64.sys [X]
S3 cpuz150; \??\C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys [X]
S3 HWiNFO_150; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_150.SYS [X] <==== ATTENTION
S3 HWiNFO_161; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_161.SYS [X] <==== ATTENTION
S3 HWiNFO_162; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_162.SYS [X] <==== ATTENTION
S3 HWiNFO_165; \??\C:\Users\sampo\AppData\Local\Temp\HWiNFO64A_165.SYS [X] <==== ATTENTION
C:\ProgramData\AVG
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\ProgramData\Norton

EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
C:\WINDOWS\tracing => ":?" ADS removed successfully
C:\Users\sampo\Data aplikací => ":00e481b5e22dbe1f649fcddd505d3eb7" ADS removed successfully
C:\Users\sampo\Downloads\CrystalDiskInfo9_1_1.exe => ":MBAM.Zone.Identifier" ADS removed successfully
"C:\Users\sampo\AppData\Roaming" => ":00e481b5e22dbe1f649fcddd505d3eb7" ADS not found.
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2fd055ed-c4ec-11e9-ba0c-806e6f6e6963} => removed successfully
HKU\S-1-5-21-952769170-1753500190-2317307712-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce987094-3ccb-11ec-bacc-e0d55e2002ee} => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{049BB3A9-1290-4263-BC08-954C65C8A039}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{049BB3A9-1290-4263-BC08-954C65C8A039}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD972EC3-FE1F-4F92-997D-C80F2BE90AE5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD972EC3-FE1F-4F92-997D-C80F2BE90AE5}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FB1A6E3B-04A3-48B1-8934-63D15514DE87}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB1A6E3B-04A3-48B1-8934-63D15514DE87}" => removed successfully
C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => removed successfully
HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.7.1 => removed successfully
C:\Program Files\VideoLAN\VLC\npvlc.dll => moved successfully
HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.8 => removed successfully
"C:\Program Files\VideoLAN\VLC\npvlc.dll" => not found
HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.11 => removed successfully
"C:\Program Files\VideoLAN\VLC\npvlc.dll" => not found
HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.15 => removed successfully
"C:\Program Files\VideoLAN\VLC\npvlc.dll" => not found
HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.16 => removed successfully
"C:\Program Files\VideoLAN\VLC\npvlc.dll" => not found
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz145 => removed successfully
cpuz145 => service removed successfully
HKLM\System\CurrentControlSet\Services\cpuz150 => removed successfully
cpuz150 => service removed successfully
HKLM\System\CurrentControlSet\Services\HWiNFO_150 => removed successfully
HWiNFO_150 => service removed successfully
HKLM\System\CurrentControlSet\Services\HWiNFO_161 => removed successfully
HWiNFO_161 => service removed successfully
HKLM\System\CurrentControlSet\Services\HWiNFO_162 => removed successfully
HWiNFO_162 => service removed successfully
HKLM\System\CurrentControlSet\Services\HWiNFO_165 => removed successfully
HWiNFO_165 => service removed successfully

"C:\ProgramData\AVG" folder move:

C:\ProgramData\AVG => moved successfully
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found

"C:\ProgramData\Norton" folder move:

C:\ProgramData\Norton => moved successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 45522292 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 536593565 B
Windows/system/drivers => 72335651 B
Edge => 0 B
Chrome => 448485069 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 20276 B
NetworkService => 24940 B
sampo => 31692158 B

RecycleBin => 0 B
EmptyTemp: => 1.1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:29:18 ====

zkusil jsem to revo, ale nikde jsem nenašel ani zmínku o AVG nebo Nortonu..

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 04 srp 2023 22:07

Nevadí , je to až v profi verzi.

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

MariTopHigh
nováček
Příspěvky: 31
Registrován: červenec 23
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod MariTopHigh » 05 srp 2023 11:04

zatím se tváří, že asi dobrý, přes víkend testnu a dám vědět.. napadá tě nějaký jiný free program, přes který odinstalovávat aplikace, aby tam nic nezůstávalo? Máte tu nějakou pokladničku, jako poděkování za pomoc?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 05 srp 2023 15:22

OK. programy:
https://www.google.com/search?client=op ... 8&oe=UTF-8

V mém podpisu klik ma "podpora fóra".
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

MariTopHigh
nováček
Příspěvky: 31
Registrován: červenec 23
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod MariTopHigh » 09 srp 2023 15:12

tak sice je frekvence nevysvětlitelných pádů podstatně nižší, ale stejně se občas přihodí.. a jelikož hraji ranked hry, tak mi to pak štve a stejně mi asi tedy nic jiného, než zkusit přeinstalovat systém na jiný disk nezbyde..


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 39 hostů