Podezřelý soubor Vyřešeno

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod jaro3 » 28 čer 2021 19:00

Vypni antivir i firewall, RogueKiller, Malwarebytes Antimalware, windowsDefender
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe
https://uloz.to/file/nFH1LwSrGioP/zoek1-rar

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.


Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Můžeš si zatrhnout i vytvoření bodu obnovy:
Klikni na ozubené kolečko , poté na „Skenování“ a zatrhni „vytvářet body obnovy“.
Vrať se zpět ( klikni na domeček).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Další“. Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, objeví se tisková zpráva , zkopíruj sem celý obsah té zprávy.
Jinak můžeš zprávy vidět , když klikneš vpravo nahoře na „ zprávy“.


Vlož nový log z HJT + informuj o problémech ( hlášení ap.)
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 19:27

Zoek běžel cca 10 minut.

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by Vaclav on 28.06.2021 at 19:07:20,16.
Microsoft Windows 10 Pro 10.0.19043 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vaclav\Desktop\zoek (1).exe [Scan all users] [Script inserted]

==== System Restore Info ======================

28.06.2021 19:08:21 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\ssh deleted successfully
C:\Users\Vaclav\AppData\Local\PeerDistRepub deleted successfully
C:\Users\Vaclav\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Vaclav\AppData\Roaming\Mozilla\Firefox\Profiles\are7et6e.default-release\prefs.js:

Added to C:\Users\Vaclav\AppData\Roaming\Mozilla\Firefox\Profiles\are7et6e.default-release\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\Users\Vaclav\AppData\Roaming\.tlauncher deleted
C:\PROGRA~3\Package Cache deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\CM29153.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-1235f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12361.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12363.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12365.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12367.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12379.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-1237b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-1237d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-1237f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12381.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12383.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12394.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12396.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-12398.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-1239a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-1239c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-123ae.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-123b0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-13dc-13e0-123b2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21bf.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21d0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21d2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21d4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21da.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21ec.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21ee.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21f0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d21f2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d2204.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d2206.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d2208.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d220a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d220c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d221d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d221f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2894-134c-d2221.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d776.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d778.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d77a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d78c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d78e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d790.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7a1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7a3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7a5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7a7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7a9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7ab.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7ad.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7bf.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7c1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7c3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7d4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2d7c-37a8-20d7d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f23.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f35.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f37.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f39.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f4a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f4c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f4e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f50.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f62.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f64.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f66.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f68.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f6a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f7b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f7d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f7f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f81.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f93.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eac-3164-168f95.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d7b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d7d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d7f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d81.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d83.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d95.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d97.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d99.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d9b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d9d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5d9f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5da1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5db2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5db4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5db6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5dc8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5dca.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5dcc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2eec-2ee0-e5dce.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b3468.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b347a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b347c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b347e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b3480.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b3491.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b3493.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34a5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34b7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34b9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34bb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34bd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34ce.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34d0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34d2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34d4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34e8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-3464-3458-1b34ea.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b269.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b29a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b30a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b31b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b32d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b34e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b350.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b362.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b373.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b385.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b3a6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b3d7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b3d9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b40a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b43b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b43d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b45e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b47f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-ed0-d48-9b491.tmp deleted
"C:\DumpStack.log.tmp" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cookies" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cookies-journal" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\lockfile" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cache\data_0" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cache\data_1" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cache\data_2" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cache\data_3" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cache\index" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Dictionaries\cs-CZ-3-0.bdic" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\GPUCache\data_0" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\GPUCache\data_1" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\GPUCache\data_2" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\GPUCache\data_3" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\GPUCache\index" deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\000003.log" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\LOCK" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\LOG" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\MANIFEST-000001" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\000003.log" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\LOCK" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\LOG" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\MANIFEST-000001" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cache" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Dictionaries" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\GPUCache" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb" not deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Vaclav\AppData\Roaming\Mozilla\Firefox\Profiles\are7et6e.default-release
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

==== Firefox Plugins ======================


==== Chromium Look ======================

Chrome Media Router - Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Outlook - Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb
Word - Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi
PowerPoint - Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02

==== Reset Google Chrome ======================

C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Preferences was reset successfully
C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Secure Preferences was reset successfully
C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Web Data was reset successfully
C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vaclav\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Vaclav\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Vaclav\AppData\Local\Mozilla\Firefox\Profiles\are7et6e.default-release\cache2 emptied successfully

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=517 folders=192 268502264 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Vaclav\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Vaclav\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\DumpStack.log.tmp" not deleted
"C:\Users\Vaclav\AppData\Roaming\discord\Cookies" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Cookies-journal" not found
"C:\Users\Vaclav\AppData\Roaming\discord\lockfile" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Dictionaries\cs-CZ-3-0.bdic" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\000003.log" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\LOCK" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\LOG" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Session Storage\MANIFEST-000001" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\000003.log" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\LOCK" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\LOG" not found
"C:\Users\Vaclav\AppData\Roaming\discord\Local Storage\leveldb\MANIFEST-000001" not found
"C:\Users\Vaclav\AppData\Roaming\discord" not found

==== EOF on 28.06.2021 at 19:18:34,92 ======================
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 19:27

Informace o kontroly
Název produktu    :  Zemana AntiMalware
Stav kontroly    :  Dokončena
Datum kontroly    :  28.06.2021 19:23:22
Typ kontroly    :  Inteligentní kontrola
Čas trvání    :  00:00:10
Zkontrolované objekty    :  1870
Zjištěné objekty    :  0
Vyloučené objekty    :  0
Automatické odesílání    :  Ano
Operační systém    :  Windows 10 x64
Procesor    :  12X AMD Ryzen 5 3600 6-Core Processor
Režim systému BIOS    :  UEFI
Informace o doméně    :  WORKGROUP,False,NetSetupWorkgroupName
CUID    :  14B45E14935E0193599260
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 19:28

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:26:14, on 28.06.2021
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.0001)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
C:\Program Files (x86)\Razer\Synapse3\Service\..\UserProcess\Razer Synapse Service Process.exe
C:\Users\Vaclav\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Users\Vaclav\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_291\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_291\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Vaclav\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Synapse3] "C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe" /StartMinimized
O4 - HKCU\..\Run: [EpicGamesLauncher] "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Synapse3] C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe /StartMinimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Synapse3] C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe /StartMinimized (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_4260f - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: EasyAntiCheat - Epic Games, Inc - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epic Online Services (EpicOnlineServices) - Epic Games, Inc. - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) (GoogleChromeElevationService) - Google LLC - C:\Program Files\Google\Chrome\Application\91.0.4472.124\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4a746d937e6a7240\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Razer Game Manager (Razer Game Manager Service) - Razer Inc - C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
O23 - Service: Razer Synapse Service - Razer Inc. - C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
O23 - Service: RogueKiller RTP (rkrtservice) - Unknown owner - C:\Program Files\RogueKiller\RogueKillerSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Razer Central Service (RzActionSvc) - Razer Inc. - C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9810 bytes
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 19:33

Problémy žádné nejspíš nejsou, bylo to jen pro ujištění, že PC není infikován.

Nějaký čas po stažení nebezpečného souboru se ale v prohlížeči událostí ukázala tato chyba.
Snímek obrazovky (8).png


Při běhu zoeku se tam ukazovaly tyto chyby.
Snímek obrazovky (10).png
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod jaro3 » 28 čer 2021 20:21

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"


ještě jeden nástroj:

Vypni antivir i firewall.
Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
další odkaz:
http://www.bleepingcomputer.com/downloa ... scan-tool/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 20:52

HJT - fixnuto
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 20:53

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2021
Ran by Vaclav (administrator) on DESKTOP-62TPSHE (Micro-Star International Co., Ltd. MS-7C91) (28-06-2021 20:50:55)
Running from C:\Users\Vaclav\Desktop
Loaded Profiles: Vaclav
Platform: Windows 10 Pro Version 21H1 19043.1081 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Vaclav\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <8>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4a746d937e6a7240\Display.NvContainer\NVDisplay.Container.exe <2>
(Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe
(Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
(Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe <2>

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3519096 2021-06-15] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33249248 2021-06-25] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3519096 2021-06-15] (Razer USA Ltd. -> Razer Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\91.0.4472.124\Installer\chrmstp.exe [2021-06-28] (Google LLC -> Google LLC)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0E3B677C-0B20-4404-B60A-0092693B2014} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-28] (Google LLC -> Google LLC)
Task: {3B368C1C-80A3-4E55-9B1B-10CC6BB9ACE6} - System32\Tasks\AMHelper => C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe [682008 2021-03-30] (Zemana D.O.O. Sarajevo -> Zemana Ltd.)
Task: {529BED77-277A-49B0-AF5E-6E06E1E2ED37} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [690616 2021-06-22] (Mozilla Corporation -> Mozilla Foundation)
Task: {B2C07040-DF87-4B15-AD6F-B8183D9C1A47} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [792120 2021-05-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {DBA019C2-E0D0-4B24-BC3E-5574A0C543C9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-28] (Google LLC -> Google LLC)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{45db6890-098c-4042-85b7-cbc620e48088}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{cacc3b76-960b-41c7-9a69-9a444f7b7133}: [DhcpNameServer] 192.168.0.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default [2021-06-28]
Edge Extension: (Outlook) - C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb [2021-06-25]
Edge Extension: (Word) - C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi [2021-06-25]
Edge Extension: (PowerPoint) - C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf [2021-06-25]

FireFox:
========
FF DefaultProfile: 0xr5n6lo.default
FF ProfilePath: C:\Users\Vaclav\AppData\Roaming\Mozilla\Firefox\Profiles\0xr5n6lo.default [2021-06-28]
FF ProfilePath: C:\Users\Vaclav\AppData\Roaming\Mozilla\Firefox\Profiles\are7et6e.default-release [2021-06-28]
FF NewTab: Mozilla\Firefox\Profiles\are7et6e.default-release -> about:newtab
FF Plugin: @java.com/DTPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\dtplugin\npDeployJava1.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\plugin2\npjp2.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.291.2 -> C:\Program Files (x86)\Java\jre1.8.0_291\bin\dtplugin\npDeployJava1.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.291.2 -> C:\Program Files (x86)\Java\jre1.8.0_291\bin\plugin2\npjp2.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)

Chrome:
=======
CHR Profile: C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default [2021-06-28]
CHR Extension: (Slides) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-06-28]
CHR Extension: (Google Drive) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-06-28]
CHR Extension: (YouTube) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-06-28]
CHR Extension: (Sheets) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-06-28]
CHR Extension: (Google Docs Offline) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-28]
CHR Extension: (Gmail) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-06-28]
CHR Extension: (Chrome Media Router) - C:\Users\Vaclav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-28]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8901968 2021-06-25] (BattlEye Innovations e.K. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [818304 2021-06-25] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [926176 2021-03-16] (Epic Games Inc. -> Epic Games, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7391408 2021-06-28] (Malwarebytes Inc -> Malwarebytes)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [254224 2021-03-22] (Razer USA Ltd. -> Razer Inc)
R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [294520 2021-06-10] (Razer USA Ltd. -> Razer Inc.)
S3 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13921616 2021-06-28] (Adlice -> )
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [533808 2021-01-29] (Razer USA Ltd. -> Razer Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5395360 2021-06-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2105.5-0\NisSrv.exe [2644776 2021-06-25] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2105.5-0\MsMpEng.exe [136656 2021-06-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4a746d937e6a7240\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4a746d937e6a7240\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 amsdk; C:\Windows\system32\drivers\amsdk.sys [232792 2021-06-28] (Zemana D.O.O. Sarajevo -> Copyright 2018.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [199128 2021-06-28] (Malwarebytes Inc -> Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [220752 2021-06-28] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2021-06-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [198888 2021-06-28] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [69016 2021-06-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248992 2021-06-28] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [156880 2021-06-28] (Malwarebytes Inc -> Malwarebytes)
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 RzCommon; C:\Windows\System32\drivers\RzCommon.sys [54632 2021-03-30] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_006e; C:\Windows\System32\drivers\RzDev_006e.sys [56152 2021-03-22] (Razer USA Ltd. -> Razer Inc)
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [38032 2021-06-28] (Adlice -> )
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [49568 2021-06-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [425184 2021-06-25] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [76000 2021-06-25] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-06-28 20:50 - 2021-06-28 20:51 - 000013343 _____ C:\Users\Vaclav\Desktop\FRST.txt
2021-06-28 20:50 - 2021-06-28 20:51 - 000000000 ____D C:\FRST
2021-06-28 20:49 - 2021-06-28 20:49 - 002300416 _____ (Farbar) C:\Users\Vaclav\Desktop\FRST64.exe
2021-06-28 20:48 - 2021-06-28 20:48 - 000000000 ____D C:\Users\Vaclav\Desktop\backups
2021-06-28 20:43 - 2021-06-28 20:43 - 000000000 ____D C:\Users\Vaclav\AppData\LocalLow\IGDump
2021-06-28 20:40 - 2021-06-28 20:40 - 003086696 _____ C:\Users\Vaclav\Downloads\instspeedfan452.exe
2021-06-28 20:40 - 2021-06-28 20:40 - 000000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2021-06-28 20:36 - 2021-06-28 20:36 - 000220752 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2021-06-28 20:36 - 2021-06-28 20:36 - 000198888 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2021-06-28 20:36 - 2021-06-28 20:36 - 000156880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2021-06-28 20:36 - 2021-06-28 20:36 - 000069016 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2021-06-28 19:43 - 2021-06-28 19:43 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Comms
2021-06-28 19:25 - 2021-06-28 19:25 - 000388608 _____ (Trend Micro Inc.) C:\Users\Vaclav\Desktop\hijackthis.exe
2021-06-28 19:20 - 2021-06-28 20:51 - 000091005 _____ C:\Windows\ZAM.krnl.trace
2021-06-28 19:20 - 2021-06-28 19:20 - 000232792 _____ (Copyright 2018.) C:\Windows\system32\Drivers\amsdk.sys
2021-06-28 19:20 - 2021-06-28 19:20 - 000003560 _____ C:\Windows\system32\Tasks\AMHelper
2021-06-28 19:20 - 2021-06-28 19:20 - 000001333 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2021-06-28 19:20 - 2021-06-28 19:20 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Zemana
2021-06-28 19:20 - 2021-06-28 19:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2021-06-28 19:20 - 2021-06-28 19:20 - 000000000 ____D C:\Program Files (x86)\Zemana
2021-06-28 19:19 - 2021-06-28 19:20 - 000000000 ____D C:\Users\Vaclav\AppData\Local\AMSDK
2021-06-28 19:19 - 2021-06-28 19:19 - 013922376 _____ (Zemana Ltd. ) C:\Users\Vaclav\Desktop\AntiMalware_Setup.exe
2021-06-28 19:19 - 2021-06-28 19:19 - 000022518 _____ C:\Users\Vaclav\Desktop\zoek-results.txt
2021-06-28 19:18 - 2021-06-28 20:36 - 000038032 _____ C:\Windows\system32\Drivers\truesight.sys
2021-06-28 19:18 - 2021-06-28 19:25 - 000000000 ____D C:\Users\Vaclav\AppData\Local\VirtualStore
2021-06-28 19:17 - 2014-02-13 23:59 - 000024064 _____ C:\Windows\zoek-delete.exe
2021-06-28 19:07 - 2021-06-28 19:16 - 000000000 ____D C:\zoek_backup
2021-06-28 19:07 - 2020-09-07 00:04 - 002038755 _____ C:\Users\Vaclav\Desktop\zoek (1).exe
2021-06-28 19:06 - 2021-06-28 19:06 - 001800862 _____ C:\Users\Vaclav\Downloads\zoek1.rar
2021-06-28 19:06 - 2021-06-28 19:06 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\WinRAR
2021-06-28 19:06 - 2021-06-28 19:06 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-06-28 19:06 - 2021-06-28 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-06-28 18:49 - 2021-06-28 18:49 - 001310832 _____ (Google LLC) C:\Users\Vaclav\Downloads\ChromeSetup.exe
2021-06-28 18:49 - 2021-06-28 18:49 - 000003472 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2021-06-28 18:49 - 2021-06-28 18:49 - 000003348 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2021-06-28 18:49 - 2021-06-28 18:49 - 000002323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-06-28 18:49 - 2021-06-28 18:49 - 000002282 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-06-28 18:49 - 2021-06-28 18:49 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Google
2021-06-28 18:49 - 2021-06-28 18:49 - 000000000 ____D C:\Program Files\Google
2021-06-28 18:49 - 2021-06-28 18:49 - 000000000 ____D C:\Program Files (x86)\Google
2021-06-28 18:44 - 2021-06-28 18:44 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2021-06-28 18:43 - 2021-06-28 19:18 - 000000000 ____D C:\ProgramData\RogueKiller
2021-06-28 18:43 - 2021-06-28 18:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2021-06-28 18:43 - 2021-06-28 18:44 - 000000000 ____D C:\Program Files\RogueKiller
2021-06-28 18:42 - 2021-06-28 18:43 - 041847456 _____ (Adlice Software ) C:\Users\Vaclav\Desktop\RogueKiller_setup.exe
2021-06-28 18:41 - 2021-06-28 18:41 - 000000878 _____ C:\Users\Vaclav\Desktop\JRT.txt
2021-06-28 18:38 - 2021-06-28 18:38 - 001790024 _____ (Malwarebytes) C:\Users\Vaclav\Desktop\JRT.exe
2021-06-28 16:44 - 2021-06-28 16:44 - 000001677 _____ C:\Users\Vaclav\Desktop\malwarebytes.txt
2021-06-28 16:42 - 2021-06-28 16:42 - 002094168 _____ (Malwarebytes) C:\Users\Vaclav\Desktop\MBSetup(1).exe
2021-06-28 16:42 - 2021-06-28 16:42 - 000248992 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2021-06-28 16:42 - 2021-06-28 16:42 - 000199128 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2021-06-28 16:42 - 2021-06-28 16:42 - 000019912 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2021-06-28 16:42 - 2021-06-28 16:42 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-06-28 16:42 - 2021-06-28 16:42 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-06-28 16:42 - 2021-06-28 16:42 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-06-28 16:42 - 2021-06-28 16:42 - 000000000 ____D C:\Program Files\Malwarebytes
2021-06-28 16:41 - 2021-06-28 16:41 - 000001405 _____ C:\Users\Vaclav\Desktop\AdwCleaner[S00].txt
2021-06-28 16:40 - 2021-06-28 16:41 - 000000000 ____D C:\AdwCleaner
2021-06-28 16:40 - 2021-06-28 16:40 - 008534696 _____ (Malwarebytes) C:\Users\Vaclav\Desktop\AdwCleaner.exe
2021-06-28 16:39 - 2021-06-28 16:39 - 000000000 ____D C:\Users\Vaclav\AppData\Local\CEF
2021-06-28 16:37 - 2021-06-28 16:37 - 000448512 _____ (OldTimer Tools) C:\Users\Vaclav\Downloads\TFC.exe
2021-06-28 16:35 - 2021-06-28 16:35 - 000050688 _____ (Atribune.org) C:\Users\Vaclav\Downloads\ATF-Cleaner.exe
2021-06-28 16:31 - 2021-06-28 16:31 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2021-06-28 16:31 - 2021-06-28 16:31 - 000000000 ____D C:\Program Files (x86)\Realtek
2021-06-28 16:31 - 2021-06-20 21:20 - 001152000 _____ (Realtek ) C:\Windows\system32\Drivers\rt640x64.sys
2021-06-28 16:26 - 2021-06-28 16:30 - 004956227 _____ C:\Users\Vaclav\Downloads\Install_Win10_10050_06222021.zip
2021-06-28 16:13 - 2021-06-28 16:34 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\audacity
2021-06-28 16:12 - 2021-06-28 16:12 - 029534144 _____ (Audacity Team ) C:\Users\Vaclav\Downloads\audacity-win-3.0.2.exe
2021-06-28 13:29 - 2021-06-28 20:50 - 000000000 ____D C:\ProgramData\Mozilla
2021-06-28 13:29 - 2021-06-28 20:49 - 000000000 ____D C:\Users\Vaclav\AppData\LocalLow\Mozilla
2021-06-28 13:29 - 2021-06-28 13:29 - 000333072 _____ (Mozilla) C:\Users\Vaclav\Downloads\Firefox Installer.exe
2021-06-28 13:29 - 2021-06-28 13:29 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-06-28 13:29 - 2021-06-28 13:29 - 000000993 _____ C:\Users\Public\Desktop\Firefox.lnk
2021-06-28 13:29 - 2021-06-28 13:29 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2021-06-28 13:29 - 2021-06-28 13:29 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Mozilla
2021-06-28 13:29 - 2021-06-28 13:29 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Mozilla
2021-06-28 13:29 - 2021-06-28 13:29 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-06-28 13:29 - 2021-06-28 13:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-06-27 20:57 - 2021-06-27 20:57 - 002371072 _____ C:\Windows\system32\rdpnano.dll
2021-06-27 20:57 - 2021-06-27 20:57 - 002260992 _____ C:\Windows\system32\TextInputMethodFormatter.dll
2021-06-27 20:57 - 2021-06-27 20:57 - 001823304 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2021-06-27 20:57 - 2021-06-27 20:57 - 001393504 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2021-06-27 20:57 - 2021-06-27 20:57 - 001314128 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2021-06-27 20:57 - 2021-06-27 20:57 - 000570880 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2021-06-27 20:57 - 2021-06-27 20:57 - 000452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2021-06-27 20:57 - 2021-06-27 20:57 - 000097792 _____ C:\Windows\system32\Drivers\cimfs.sys
2021-06-27 20:57 - 2021-06-27 20:57 - 000084992 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2021-06-27 20:57 - 2021-06-27 20:57 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2021-06-27 20:57 - 2021-06-27 20:57 - 000060928 _____ C:\Windows\system32\runexehelper.exe
2021-06-27 20:57 - 2021-06-27 20:57 - 000011333 _____ C:\Windows\system32\DrtmAuthTxt.wim
2021-06-27 20:23 - 2021-06-28 16:43 - 000000000 ____D C:\Users\Vaclav\AppData\Local\CrashDumps
2021-06-26 21:07 - 2021-06-26 21:07 - 002094168 _____ (Malwarebytes) C:\Users\Vaclav\Downloads\MBSetup.exe
2021-06-26 21:07 - 2021-06-26 21:07 - 000000000 ____D C:\Users\Vaclav\AppData\Local\mbam
2021-06-26 20:59 - 2021-06-28 18:55 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Discord
2021-06-26 20:59 - 2021-06-26 20:59 - 070858912 _____ (Discord Inc.) C:\Users\Vaclav\Downloads\DiscordSetup.exe
2021-06-26 20:59 - 2021-06-26 20:59 - 000002236 _____ C:\Users\Vaclav\Desktop\Discord.lnk
2021-06-26 20:59 - 2021-06-26 20:59 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2021-06-26 20:59 - 2021-06-26 20:59 - 000000000 ____D C:\Users\Vaclav\AppData\Local\SquirrelTemp
2021-06-26 14:00 - 2021-06-26 14:00 - 002079496 _____ (Oracle Corporation) C:\Users\Vaclav\Downloads\JavaSetup8u291.exe
2021-06-26 14:00 - 2021-06-26 14:00 - 000164640 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2021-06-26 14:00 - 2021-06-26 14:00 - 000000000 ____D C:\Program Files (x86)\Java
2021-06-26 14:00 - 2021-06-26 13:41 - 000191776 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll
2021-06-26 13:41 - 2021-06-26 13:41 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Sun
2021-06-26 10:48 - 2021-06-28 20:19 - 000003144 _____ C:\Windows\system32\Tasks\MSIAfterburner
2021-06-26 10:41 - 2021-06-26 10:43 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2021-06-26 10:41 - 2021-06-26 10:42 - 000000000 ____D C:\Windows\SysWOW64\directx
2021-06-26 10:41 - 2021-06-26 10:41 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2021-06-26 10:40 - 2021-06-26 10:52 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2021-06-26 10:40 - 2021-06-26 10:40 - 054261822 _____ C:\Users\Vaclav\Downloads\MSIAfterburnerSetup.zip
2021-06-26 10:40 - 2021-06-26 10:40 - 000001159 _____ C:\Users\Vaclav\Desktop\MSI Afterburner.lnk
2021-06-26 10:40 - 2021-06-26 10:40 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2021-06-26 10:20 - 2021-06-26 13:41 - 000191776 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2021-06-26 10:20 - 2021-06-26 10:20 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\java
2021-06-26 10:20 - 2021-06-26 10:20 - 000000000 ____D C:\Users\Vaclav\AppData\LocalLow\Oracle
2021-06-26 10:20 - 2021-06-26 10:20 - 000000000 ____D C:\ProgramData\Sun
2021-06-26 10:19 - 2021-06-26 20:15 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\.minecraft
2021-06-26 10:19 - 2021-06-26 14:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2021-06-26 10:19 - 2021-06-26 13:43 - 000000000 ____D C:\Program Files\Java
2021-06-26 10:19 - 2021-06-26 10:19 - 019640768 _____ (TLauncher Inc.) C:\Users\Vaclav\Downloads\TLauncher-2.8-Installer-0.7.exe
2021-06-26 10:19 - 2021-06-26 10:19 - 000001962 _____ C:\Users\Public\Desktop\TLauncher.lnk
2021-06-26 10:19 - 2021-06-26 10:19 - 000000000 ____D C:\Users\Vaclav\AppData\LocalLow\Sun
2021-06-26 10:19 - 2021-06-26 10:19 - 000000000 ____D C:\ProgramData\Oracle
2021-06-25 20:55 - 2021-06-25 20:55 - 000000000 ___SH C:\Users\Public\Shared Files
2021-06-25 20:44 - 2021-06-27 21:10 - 000000000 ____D C:\Windows\Panther
2021-06-25 20:42 - 2021-06-25 21:01 - 000000000 ____D C:\Users\Vaclav\AppData\Local\NVIDIA
2021-06-25 20:42 - 2021-06-25 20:42 - 000000000 ____D C:\Windows\system32\lxss
2021-06-25 20:42 - 2021-06-25 20:42 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2021-06-25 20:41 - 2021-06-21 10:43 - 000037664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
2021-06-25 20:40 - 2021-06-22 03:25 - 001858680 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2021-06-25 20:40 - 2021-06-22 03:25 - 001858680 _____ C:\Windows\system32\vulkaninfo.exe
2021-06-25 20:40 - 2021-06-22 03:25 - 001474336 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2021-06-25 20:40 - 2021-06-22 03:25 - 001438824 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-06-25 20:40 - 2021-06-22 03:25 - 001438824 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2021-06-25 20:40 - 2021-06-22 03:25 - 001212192 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2021-06-25 20:40 - 2021-06-22 03:25 - 001097832 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2021-06-25 20:40 - 2021-06-22 03:25 - 001097832 _____ C:\Windows\system32\vulkan-1.dll
2021-06-25 20:40 - 2021-06-22 03:25 - 000951912 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2021-06-25 20:40 - 2021-06-22 03:25 - 000951912 _____ C:\Windows\SysWOW64\vulkan-1.dll
2021-06-25 20:40 - 2021-06-22 03:21 - 001519384 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2021-06-25 20:40 - 2021-06-22 03:21 - 001170224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2021-06-25 20:40 - 2021-06-22 03:21 - 000715568 _____ C:\Windows\system32\nvofapi64.dll
2021-06-25 20:40 - 2021-06-22 03:21 - 000675088 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2021-06-25 20:40 - 2021-06-22 03:21 - 000641328 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2021-06-25 20:40 - 2021-06-22 03:21 - 000575792 _____ C:\Windows\SysWOW64\nvofapi.dll
2021-06-25 20:40 - 2021-06-22 03:21 - 000563992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2021-06-25 20:40 - 2021-06-22 03:20 - 002111264 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2021-06-25 20:40 - 2021-06-22 03:20 - 001594656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2021-06-25 20:40 - 2021-06-22 03:20 - 000917280 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2021-06-25 20:40 - 2021-06-22 03:20 - 000748832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2021-06-25 20:40 - 2021-06-22 03:20 - 000704792 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2021-06-25 20:40 - 2021-06-22 03:19 - 008852760 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2021-06-25 20:40 - 2021-06-22 03:19 - 007918872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2021-06-25 20:40 - 2021-06-22 03:19 - 004986648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2021-06-25 20:40 - 2021-06-22 03:19 - 002924304 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2021-06-25 20:40 - 2021-06-22 03:19 - 000446744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2021-06-25 20:40 - 2021-06-22 03:18 - 000848672 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2021-06-25 20:40 - 2021-06-22 03:17 - 006215312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2021-06-25 20:40 - 2021-06-21 10:43 - 000082968 _____ C:\Windows\system32\nvinfo.pb
2021-06-25 20:39 - 2021-06-25 20:40 - 754973760 _____ (NVIDIA Corporation) C:\Users\Vaclav\Downloads\471.11-desktop-win10-64bit-international-dch-whql.exe
2021-06-25 20:36 - 2021-06-25 20:36 - 000000000 ____D C:\Users\Vaclav\AppData\Local\FortniteGame
2021-06-25 20:36 - 2021-06-25 20:36 - 000000000 ____D C:\Users\Vaclav\AppData\Local\CrashReportClient
2021-06-25 20:35 - 2021-06-25 20:35 - 000000354 _____ C:\Users\Vaclav\Desktop\Fortnite.url
2021-06-25 20:35 - 2021-06-25 20:35 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\EasyAntiCheat
2021-06-25 20:35 - 2021-06-25 20:35 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2021-06-25 20:18 - 2021-06-25 20:18 - 000001270 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2021-06-25 20:18 - 2021-06-25 20:18 - 000001258 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2021-06-25 20:18 - 2021-06-25 20:18 - 000000000 ____D C:\Users\Vaclav\AppData\Local\UnrealEngineLauncher
2021-06-25 20:18 - 2021-06-25 20:18 - 000000000 ____D C:\Users\Vaclav\AppData\Local\EpicGamesLauncher
2021-06-25 20:17 - 2021-06-25 20:17 - 000000000 ____D C:\Windows\system32\appmgmt
2021-06-25 20:11 - 2021-06-25 20:36 - 000000000 ____D C:\Users\Vaclav\AppData\Local\NVIDIA Corporation
2021-06-25 20:10 - 2021-06-25 20:36 - 000000000 ____D C:\Users\Vaclav\AppData\Local\UnrealEngine
2021-06-25 20:10 - 2021-06-25 20:19 - 000000000 ____D C:\ProgramData\Epic
2021-06-25 20:10 - 2021-06-25 20:18 - 000000000 ____D C:\Program Files (x86)\Epic Games
2021-06-25 20:10 - 2021-06-25 20:10 - 056791040 _____ C:\Users\Vaclav\Downloads\EpicInstaller-12.1.7.msi
2021-06-25 20:03 - 2021-06-26 19:46 - 000001446 _____ C:\Users\Vaclav\Desktop\Roblox Studio.lnk
2021-06-25 20:03 - 2021-06-26 19:46 - 000000254 _____ C:\Users\Vaclav\AppData\LocalLow\rbxcsettings.rbx
2021-06-25 20:03 - 2021-06-26 19:46 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2021-06-25 20:03 - 2021-06-26 19:46 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Roblox
2021-06-25 20:03 - 2021-06-25 20:03 - 001655688 _____ (Roblox Corporation) C:\Users\Vaclav\Downloads\RobloxPlayerLauncher.exe
2021-06-25 20:03 - 2021-06-25 20:03 - 000001426 _____ C:\Users\Vaclav\Desktop\Roblox Player.lnk
2021-06-25 20:02 - 2021-06-28 20:36 - 000000000 ____D C:\ProgramData\NVIDIA
2021-06-25 20:02 - 2021-06-25 20:02 - 000002922 _____ C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2021-06-25 20:02 - 2021-06-25 20:02 - 000002916 _____ C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2021-06-25 20:02 - 2021-06-25 20:02 - 000002910 _____ C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Word.lnk
2021-06-25 19:56 - 2021-06-25 19:56 - 002755584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2021-06-25 19:56 - 2021-06-25 19:56 - 002755584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2021-06-25 19:56 - 2021-06-25 19:56 - 002260480 _____ (The ICU Project) C:\Windows\system32\icu.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 002254336 _____ C:\Windows\system32\dwmscene.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 001864192 _____ (The ICU Project) C:\Windows\SysWOW64\icu.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 001687040 _____ C:\Windows\system32\libcrypto.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 001333760 _____ C:\Windows\SysWOW64\TextInputMethodFormatter.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 001163776 _____ C:\Windows\system32\MBR2GPT.EXE
2021-06-25 19:56 - 2021-06-25 19:56 - 000729600 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2021-06-25 19:56 - 2021-06-25 19:56 - 000700928 _____ C:\Windows\system32\FsNVSDeviceSource.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000657464 _____ C:\Windows\system32\WindowManagementAPI.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000611952 _____ C:\Windows\SysWOW64\TextShaping.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000581120 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2021-06-25 19:56 - 2021-06-25 19:56 - 000575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hhctrl.ocx
2021-06-25 19:56 - 2021-06-25 19:56 - 000544768 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr
2021-06-25 19:56 - 2021-06-25 19:56 - 000480256 _____ C:\Windows\system32\AssignedAccessCsp.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000469504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000468440 _____ C:\Windows\SysWOW64\WindowManagementAPI.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000446976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2021-06-25 19:56 - 2021-06-25 19:56 - 000330752 _____ C:\Windows\SysWOW64\ssdm.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000304128 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2021-06-25 19:56 - 2021-06-25 19:56 - 000266240 _____ C:\Windows\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000240640 _____ C:\Windows\SysWOW64\CoreMas.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000238592 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000235520 _____ C:\Windows\SysWOW64\HeatCore.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000234496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2021-06-25 19:56 - 2021-06-25 19:56 - 000231248 _____ C:\Windows\system32\containerdevicemanagement.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000223744 _____ C:\Windows\SysWOW64\TpmTool.exe
2021-06-25 19:56 - 2021-06-25 19:56 - 000190976 _____ C:\Windows\system32\BthpanContextHandler.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2021-06-25 19:56 - 2021-06-25 19:56 - 000157184 _____ C:\Windows\system32\uwfcsp.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000153600 _____ C:\Windows\system32\uwfcfgmgmt.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000152064 _____ C:\Windows\system32\EoAExperiences.exe
2021-06-25 19:56 - 2021-06-25 19:56 - 000138056 _____ C:\Windows\system32\HvsiManagementApi.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VBICodec.ax
2021-06-25 19:56 - 2021-06-25 19:56 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\ncpa.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000101704 _____ C:\Windows\SysWOW64\HvsiManagementApi.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncpa.cpl
2021-06-25 19:56 - 2021-06-25 19:56 - 000095744 _____ C:\Windows\system32\VirtualMonitorManager.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2021-06-25 19:56 - 2021-06-25 19:56 - 000072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2021-06-25 19:56 - 2021-06-25 19:56 - 000067072 _____ C:\Windows\system32\BWContextHandler.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000053760 _____ C:\Windows\SysWOW64\BWContextHandler.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000048640 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000039936 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2021-06-25 19:56 - 2021-06-25 19:56 - 000010752 _____ C:\Windows\SysWOW64\agentactivationruntimestarter.exe
2021-06-25 19:56 - 2021-06-25 19:56 - 000001370 _____ C:\Windows\system32\ThirdPartyNoticesBySHS.txt
2021-06-25 19:55 - 2021-06-25 19:55 - 000707016 _____ C:\Windows\system32\TextShaping.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000563712 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2021-06-25 19:55 - 2021-06-25 19:55 - 000455168 _____ C:\Windows\system32\ssdm.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000363520 _____ C:\Windows\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000306688 _____ C:\Windows\system32\HeatCore.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000287232 _____ C:\Windows\system32\CoreMas.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000272384 _____ C:\Windows\system32\TpmTool.exe
2021-06-25 19:55 - 2021-06-25 19:55 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2021-06-25 19:55 - 2021-06-25 19:55 - 000165888 _____ C:\Windows\system32\DataStoreCacheDumpTool.exe
2021-06-25 19:55 - 2021-06-25 19:55 - 000089088 _____ C:\Windows\system32\windows.applicationmodel.conversationalagent.proxystub.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000074240 _____ C:\Windows\system32\rdsxvmaudio.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000073216 _____ C:\Windows\system32\windows.applicationmodel.conversationalagent.internal.proxystub.dll
2021-06-25 19:55 - 2021-06-25 19:55 - 000013312 _____ C:\Windows\system32\agentactivationruntimestarter.exe
2021-06-25 19:52 - 2021-06-28 12:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2021-06-25 19:52 - 2021-06-26 12:54 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2021-06-25 19:52 - 2021-06-25 20:42 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2021-06-25 19:52 - 2021-06-25 19:52 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Synapse3
2021-06-25 19:52 - 2021-06-25 19:52 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Razer
2021-06-25 19:52 - 2021-06-25 19:52 - 000000000 ____D C:\temp
2021-06-25 19:52 - 2021-06-25 19:52 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-06-25 19:51 - 2021-06-25 19:51 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-06-25 19:51 - 2021-06-22 03:17 - 007279232 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2021-06-25 19:51 - 2021-06-21 10:43 - 000136472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2021-06-25 19:51 - 2020-10-07 13:32 - 005519600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2021-06-25 19:50 - 2021-06-27 20:03 - 000000000 ____D C:\Users\Vaclav\AppData\Local\D3DSCache
2021-06-25 19:50 - 2021-06-25 20:01 - 000000000 ____D C:\Program Files (x86)\Razer
2021-06-25 19:50 - 2021-06-25 19:53 - 000000000 ____D C:\ProgramData\Razer
2021-06-25 19:50 - 2021-06-25 19:51 - 000000000 ____D C:\Windows\system32\MRT
2021-06-25 19:50 - 2021-06-25 19:50 - 000000000 ___HD C:\$WinREAgent
2021-06-25 19:50 - 2020-10-20 23:31 - 000079376 _____ (Razer Inc) C:\Windows\system32\RazerS3Coinstaller.dll
2021-06-25 19:49 - 2021-06-27 20:21 - 000000000 ____D C:\Users\Vaclav\AppData\Local\PlaceholderTileLogoFolder
2021-06-25 19:49 - 2021-06-25 19:49 - 000003382 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3554629397-3815353969-3522257156-1001
2021-06-25 19:49 - 2021-06-25 19:49 - 000000000 ___RD C:\Users\Vaclav\OneDrive
2021-06-25 19:48 - 2021-06-25 19:48 - 000000000 ____D C:\Windows\CSC
2021-06-25 19:47 - 2021-06-28 16:39 - 000000000 ____D C:\Users\Vaclav\AppData\Local\ConnectedDevicesPlatform
2021-06-25 19:47 - 2021-06-28 13:17 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Packages
2021-06-25 19:47 - 2021-06-26 10:49 - 000000000 ____D C:\Users\Vaclav
2021-06-25 19:47 - 2021-06-25 19:49 - 000002368 _____ C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-06-25 19:47 - 2021-06-25 19:47 - 000000020 ___SH C:\Users\Vaclav\ntuser.ini
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Šablony
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Soubory cookie
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Poslední
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Okolní tiskárny
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Okolní síť
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Nabídka Start
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Dokumenty
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Documents\Obrázky
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Documents\Hudba
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Documents\Filmy
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\Data aplikací
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 _SHDL C:\Users\Vaclav\AppData\Local\Data aplikací
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 ___RD C:\Users\Vaclav\3D Objects
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 ____D C:\Users\Vaclav\AppData\Roaming\Adobe
2021-06-25 19:47 - 2021-06-25 19:47 - 000000000 ____D C:\Users\Vaclav\AppData\Local\Publishers
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Public\Documents\Obrázky
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Public\Documents\Hudba
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Public\Documents\Filmy
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Šablony
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Soubory cookie
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Poslední
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Okolní tiskárny
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Okolní síť
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Nabídka Start
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Dokumenty
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Documents\Obrázky
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Documents\Hudba
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Documents\Filmy
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\Data aplikací
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\ProgramData\Šablony
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\ProgramData\Plocha
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\ProgramData\Nabídka Start
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\ProgramData\Dokumenty
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\ProgramData\Data aplikací
2021-06-25 19:46 - 2021-06-25 19:46 - 000000000 _SHDL C:\Documents and Settings
2021-06-25 19:45 - 2021-06-25 19:45 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2021-06-25 19:44 - 2021-06-28 20:36 - 000008192 ___SH C:\DumpStack.log.tmp
2021-06-25 19:44 - 2021-06-25 19:44 - 000002858 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3554629397-3815353969-3522257156-500

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-06-28 20:43 - 2020-11-19 01:55 - 001605602 _____ C:\Windows\system32\PerfStringBackup.INI
2021-06-28 20:43 - 2019-12-07 16:43 - 000682238 _____ C:\Windows\system32\perfh005.dat
2021-06-28 20:43 - 2019-12-07 16:43 - 000137054 _____ C:\Windows\system32\perfc005.dat
2021-06-28 20:43 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2021-06-28 20:37 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-06-28 20:36 - 2020-11-19 01:46 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-06-28 20:19 - 2019-12-07 11:03 - 002359296 _____ C:\Windows\system32\config\BBI
2021-06-28 19:18 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2021-06-28 18:37 - 2020-11-19 00:46 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-06-28 16:48 - 2019-12-07 11:03 - 000032768 _____ C:\Windows\system32\config\ELAM
2021-06-28 16:42 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2021-06-28 13:17 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-06-27 21:00 - 2020-11-19 00:46 - 000258176 _____ C:\Windows\system32\FNTCACHE.DAT
2021-06-27 20:59 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\setup
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\Provisioning
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2021-06-27 20:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2021-06-27 20:59 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2021-06-27 20:30 - 2020-11-19 01:50 - 000000000 ____D C:\ProgramData\Packages
2021-06-27 20:30 - 2020-11-19 01:48 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-06-27 20:30 - 2020-11-19 01:48 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-06-26 10:41 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-06-26 10:21 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\appcompat
2021-06-25 20:55 - 2019-12-07 11:14 - 000000000 __SHD C:\Users\Public\Libraries
2021-06-25 20:44 - 2019-12-07 11:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2021-06-25 20:01 - 2020-11-19 01:46 - 000000000 ____D C:\Windows\system32\Drivers\wd
2021-06-25 20:01 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\PrintDialog
2021-06-25 20:01 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-06-25 19:59 - 2019-12-07 16:47 - 000000000 ___SD C:\Windows\system32\AppV
2021-06-25 19:59 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2021-06-25 19:59 - 2019-12-07 16:47 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2021-06-25 19:59 - 2019-12-07 16:44 - 000000000 ____D C:\Windows\system32\OpenSSH
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ___SD C:\Windows\system32\UNP
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ___SD C:\Windows\system32\F12
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Keywords
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Com
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Sysprep
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\migwiz
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\lv-LV
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\lt-LT
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Keywords
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\et-EE
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\es-MX
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Com
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\AdvancedInstallers
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellExperiences
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellComponents
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\IME
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\DiagTrack
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2021-06-25 19:59 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2021-06-25 19:59 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\servicing
2021-06-25 19:58 - 2019-12-07 16:47 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2021-06-25 19:55 - 2020-11-19 01:48 - 002877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2021-06-25 19:49 - 2020-11-19 01:48 - 000003584 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-06-25 19:49 - 2020-11-19 01:48 - 000003460 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-06-25 19:49 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\USOPrivate
2021-06-25 19:48 - 2019-12-07 16:45 - 000000000 ____D C:\Windows\system32\FxsTmp
2021-06-25 19:47 - 2020-11-19 01:50 - 000000000 __RHD C:\Users\Public\AccountPictures
2021-06-25 19:46 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2021-06-25 19:46 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Windows NT

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 20:53

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-06-2021
Ran by Vaclav (28-06-2021 20:51:56)
Running from C:\Users\Vaclav\Desktop
Windows 10 Pro Version 21H1 19043.1081 (X64) (2021-06-25 17:46:26)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3554629397-3815353969-3522257156-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3554629397-3815353969-3522257156-503 - Limited - Disabled)
Guest (S-1-5-21-3554629397-3815353969-3522257156-501 - Limited - Disabled)
Vaclav (S-1-5-21-3554629397-3815353969-3522257156-1001 - Administrator - Enabled) => C:\Users\Vaclav
WDAGUtilityAccount (S-1-5-21-3554629397-3815353969-3522257156-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Discord (HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\Discord) (Version: 1.0.9002 - Discord Inc.)
Epic Games Launcher (HKLM-x32\...\{A7BBC0A6-3DB0-41CC-BCED-DDFC5D4F3060}) (Version: 1.2.17.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{0B736177-814A-4ADE-81D1-66A0FDD55BB4}) (Version: 1.1.11.0 - Epic Games, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 91.0.4472.124 - Google LLC)
Java 8 Update 291 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180291F0}) (Version: 8.0.2910.10 - Oracle Corporation)
Java 8 Update 291 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180291F0}) (Version: 8.0.2910.10 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Malwarebytes version 4.4.0.117 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.0.117 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 91.0.864.59 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\OneDriveSetup.exe) (Version: 21.109.0530.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{E5A95BC5-81DF-4F0C-B910-B59DD012F037}) (Version: 2.81.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mozilla Firefox 89.0.2 (x64 cs) (HKLM\...\Mozilla Firefox 89.0.2 (x64 cs)) (Version: 89.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 89.0.2 - Mozilla)
MSI Afterburner 4.6.4 Beta 3 (HKLM-x32\...\Afterburner) (Version: 4.6.4 Beta 3 - MSI Co., LTD)
NVIDIA Ovladač HD audia 1.3.38.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.60 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 471.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 471.11 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Outlook (HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\6b0f23e57a39ebfbf2814acb1a24293d) (Version: 1.0 - Outlook)
PowerPoint (HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\319814cb56b667dff88f54e08be8f51f) (Version: 1.0 - PowerPoint)
Razer Synapse (HKLM-x32\...\Razer Synapse) (Version: 3.6.0624.061513 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.50.511.2021 - Realtek)
RivaTuner Statistics Server 7.3.2 Beta 2 (HKLM-x32\...\RTSS) (Version: 7.3.2 Beta 2 - Unwinder)
Roblox Player for Vaclav (HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\roblox-player) (Version: - Roblox Corporation)
Roblox Studio for Vaclav (HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\roblox-studio) (Version: - Roblox Corporation)
RogueKiller version 15.0.4.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 15.0.4.0 - Adlice Software)
WinRAR 6.02 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.02.0 - win.rar GmbH)
Word (HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\...\1b837d0bf93d01407352736c91b7bf50) (Version: 1.0 - Word)
Zemana AntiMalware verze 3.2.28 (HKLM-x32\...\{4E1F3677-C72E-4F7D-B66E-85467B1A289E}_is1) (Version: 3.2.28 - Zemana)

Packages:
=========
Excel -> C:\Program Files\WindowsApps\excel.office.com-4362FB92_1.0.0.0_neutral__2vp2pd36ganw2 [2021-06-28] (excel.office.com)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-06-26] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-06-26] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.6151.0_x64__8wekyb3d8bbwe [2021-06-27] (Microsoft Studios) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.961.0_x64__56jybvy8sckqj [2021-06-25] (NVIDIA Corp.)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0 [2021-06-25] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2021-03-30] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-06-28] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4a746d937e6a7240\nvshext.dll [2021-06-22] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2021-03-30] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-06-28] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bjhmmnoficofgoiacjaajpkfndojknpb
ShortcutWithArgument: C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=opfacbhaojodjaojgocnibmklknchehf
ShortcutWithArgument: C:\Users\Vaclav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Word.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=hikhggiobiflkdfdgdajcfklmcibbopi

==================== Loaded Modules (Whitelisted) =============

2021-04-05 00:10 - 2021-04-05 00:10 - 000232960 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTCore.dll
2021-04-05 00:10 - 2021-04-05 00:10 - 000057344 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTFC.dll
2021-04-06 16:05 - 2021-04-06 16:05 - 000668672 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
2021-04-05 00:10 - 2021-04-05 00:10 - 000074240 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
2021-04-05 00:10 - 2021-04-05 00:10 - 000371712 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTUI.dll
2021-04-05 17:43 - 2021-04-05 17:43 - 000057344 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll
2021-04-05 17:43 - 2021-04-05 17:43 - 000074240 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll
2021-04-05 17:43 - 2021-04-05 17:43 - 000368640 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [9130]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

SearchScopes: HKU\S-1-5-21-3554629397-3815353969-3522257156-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_291\bin\ssv.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_291\bin\jp2ssv.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_291\bin\ssv.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_291\bin\jp2ssv.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2021-06-28 20:48 - 000000813 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common
HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Vaclav\Desktop\pozadi.JPG
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{46E5CACD-D9FE-4B02-B9AB-8D540A6F94C9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{C5798F6C-8A0F-4AC9-83F8-E5E5242F84E4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E383F325-E6C4-49C6-86AB-D43BA82144D7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E0021A06-CBFC-4FCB-B609-CBC3170C08D2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{2E5C26F2-E64B-489C-87B5-A579EACF849E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D2B5FE29-8C9B-4BFF-995B-7FBB66D3F5C3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{2BF588E2-F6AC-4CED-87A2-7108C33AA9A0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{623F2CB9-A8B5-41A3-BDD1-B7A5E5659863}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.161.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{F670F7C1-3177-4BF8-B5B6-12EB6CF29865}D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{7923B762-8912-4198-8F80-7818EA3CCC2D}D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{C6AF9F36-3034-4BAD-AA18-112AB2615FF7}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe => No File
FirewallRules: [UDP Query User{08BD91C6-0BA0-4E85-B8E9-D8CA2725DD09}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe => No File
FirewallRules: [TCP Query User{1BBA2439-A7A4-4D81-BD4F-BCFE3253B5B5}C:\users\vaclav\appdata\roaming\.minecraft\runtime\java-runtime-alpha\windows\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.minecraft\runtime\java-runtime-alpha\windows\java-runtime-alpha\bin\javaw.exe
FirewallRules: [UDP Query User{7894F924-ECE7-4C94-B886-F19A479C54B7}C:\users\vaclav\appdata\roaming\.minecraft\runtime\java-runtime-alpha\windows\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.minecraft\runtime\java-runtime-alpha\windows\java-runtime-alpha\bin\javaw.exe
FirewallRules: [{D345AA91-6C5E-413B-93AC-CCAF8352A829}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{6857287C-5066-49BD-9747-0600ABDA0222}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AF719F65-2266-47A1-85FA-95D6DF306DC6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8EDAD142-2D5D-4A83-A178-7B1854464F66}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BCAC68ED-7CF6-474D-B457-168D8B5E7151}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{7EB8EBFA-30E0-4D59-9217-C83910BAC910}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F1807719-E720-4AEC-90DF-329395B59F50}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

28-06-2021 16:31:18 Instalováno Realtek Ethernet Controller Driver
28-06-2021 18:40:53 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (06/28/2021 04:43:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: mbamtray.exe, verze: 4.0.0.1023, časové razítko: 0x60be8592
Název chybujícího modulu: Qt5Core.dll, verze: 5.14.1.0, časové razítko: 0x603971ce
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000219dc5
ID chybujícího procesu: 0xf30
Čas spuštění chybující aplikace: 0x01d76c2be0a3aa12
Cesta k chybující aplikaci: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
Cesta k chybujícímu modulu: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
ID zprávy: 063bac3f-7c90-4e7d-8db8-21c2f5d64d48
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (06/27/2021 08:30:09 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.

Error: (06/27/2021 08:30:09 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]

Error: (06/27/2021 08:24:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AMS.exe, verze: 0.0.0.0, časové razítko: 0x5d026d54
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x2c340000
ID chybujícího procesu: 0x3a4c
Čas spuštění chybující aplikace: 0x01d76b8191e003b5
Cesta k chybující aplikaci: C:\Program Files\WindowsApps\A278AB0D.AsphaltXtreme_1.7.3.8_x86__h6adky7gbf63m\AMS.exe
Cesta k chybujícímu modulu: unknown
ID zprávy: 52ba9f99-fa46-403b-af70-81e49b119c79
Úplný název chybujícího balíčku: A278AB0D.AsphaltXtreme_1.7.3.8_x86__h6adky7gbf63m
ID aplikace související s chybujícím balíčkem: App

Error: (06/27/2021 08:24:14 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: AMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: kód výjimky c0000005, adresa výjimky 2C340000

Error: (06/27/2021 08:23:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AMS.exe, verze: 0.0.0.0, časové razítko: 0x5d026d54
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x23c40000
ID chybujícího procesu: 0x3060
Čas spuštění chybující aplikace: 0x01d76b818bd8e249
Cesta k chybující aplikaci: C:\Program Files\WindowsApps\A278AB0D.AsphaltXtreme_1.7.3.8_x86__h6adky7gbf63m\AMS.exe
Cesta k chybujícímu modulu: unknown
ID zprávy: cc5cd107-b656-4c06-aa36-102f21e8c49c
Úplný název chybujícího balíčku: A278AB0D.AsphaltXtreme_1.7.3.8_x86__h6adky7gbf63m
ID aplikace související s chybujícím balíčkem: App

Error: (06/27/2021 08:23:43 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: AMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: kód výjimky c0000005, adresa výjimky 23C40000

Error: (06/27/2021 08:23:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AMS.exe, verze: 0.0.0.0, časové razítko: 0x5d026d54
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x28940000
ID chybujícího procesu: 0xc2c
Čas spuštění chybující aplikace: 0x01d76b817104d7e7
Cesta k chybující aplikaci: C:\Program Files\WindowsApps\A278AB0D.AsphaltXtreme_1.7.3.8_x86__h6adky7gbf63m\AMS.exe
Cesta k chybujícímu modulu: unknown
ID zprávy: 49193a71-1ac0-43f4-a118-3a92a6ced6a1
Úplný název chybujícího balíčku: A278AB0D.AsphaltXtreme_1.7.3.8_x86__h6adky7gbf63m
ID aplikace související s chybujícím balíčkem: App


System errors:
=============
Error: (06/28/2021 07:15:57 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2021 07:15:57 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2021 07:15:57 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2021 07:15:57 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2021 07:15:56 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/28/2021 06:40:59 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Display Container LS byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (06/28/2021 04:37:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Razer Game Manager byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (06/28/2021 04:18:07 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Služba DCOM zjistila chybu 1115 při pokusu o spuštění služby SecurityHealthService s argumenty Není k dispozici za účelem spuštění serveru:
{8C9C0DB7-2CBA-40F1-AFE0-C55740DD91A0}


Windows Defender:
================
Date: 2021-06-26 20:57:45
Description:
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:MSIL/AgentTesla.FO!MTB
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: containerfile:_C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Cache\f_001071; file:_C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Cache\f_001071->setup.exe
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Uživatel
Uživatel: DESKTOP-62TPSHE\Vaclav
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.341.1478.0, AS: 1.341.1478.0, NIS: 1.341.1478.0
Verze modulu: AM: 1.1.18200.4, NIS: 1.1.18200.4

Date: 2021-06-26 20:42:47
Description:
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:MSIL/AgentTesla.FO!MTB
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: containerfile:_C:\Users\Vaclav\Downloads\setup.rar; file:_C:\Users\Vaclav\Downloads\setup.rar->setup.exe; webfile:_C:\Users\Vaclav\Downloads\setup.rar|https://puu.sh/HRVtJ/322268c80e.rar|pid:15532,ProcessStart:132692065654476555
Původ detekce: Internet
Typ detekce: FastPath
Zdroj detekce: Soubory ke stažení a přílohy
Uživatel: DESKTOP-62TPSHE\Vaclav
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.341.1478.0, AS: 1.341.1478.0, NIS: 1.341.1478.0
Verze modulu: AM: 1.1.18200.4, NIS: 1.1.18200.4

CodeIntegrity:
===============
Date: 2021-06-28 16:43:06
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Mozilla Firefox\firefox.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends International, LLC. A.50 01/15/2021
Motherboard: Micro-Star International Co., Ltd. MAG B550 TOMAHAWK (MS-7C91)
Processor: AMD Ryzen 5 3600 6-Core Processor
Percentage of memory in use: 30%
Total physical RAM: 16310.22 MB
Available physical RAM: 11371.71 MB
Total Virtual: 19254.22 MB
Available Virtual: 12060.12 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.16 GB) (Free:411.49 GB) NTFS
Drive d: (DATA) (Fixed) (Total:465.76 GB) (Free:321.9 GB) NTFS

\\?\Volume{bb290285-54a1-4949-b2e5-3150eb0475bd}\ () (Fixed) (Total:0.49 GB) (Free:0.08 GB) NTFS
\\?\Volume{e6830c2b-8111-4502-9644-5ab97893e5d6}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: 67789823)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 28 čer 2021 20:54

FRST při prvním spuštění vyhodil tuto hlášku. Dal jsem další informace - přesto spustit
Přílohy
Snímek obrazovky (11).png
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod jaro3 » 29 čer 2021 00:41

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CreateRestorePoint:
CloseProcesses:
Task: {0E3B677C-0B20-4404-B60A-0092693B2014} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-28] (Google LLC -> Google LLC)
Task: {DBA019C2-E0D0-4B24-BC3E-5574A0C543C9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-28] (Google LLC -> Google LLC)
C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
SearchScopes: HKU\S-1-5-21-3554629397-3815353969-3522257156-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
FirewallRules: [TCP Query User{C6AF9F36-3034-4BAD-AA18-112AB2615FF7}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe => No File
FirewallRules: [UDP Query User{08BD91C6-0BA0-4E85-B8E9-D8CA2725DD09}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe => No File
C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Cache\f_001071->setup.exe
C:\Users\Vaclav\Downloads\setup.rar

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Václav Polák
Level 2.5
Level 2.5
Příspěvky: 345
Registrován: prosinec 20
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: Podezřelý soubor

Příspěvekod Václav Polák » 29 čer 2021 12:22

Soubor fixlist se po restaru smazal.

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-06-2021
Ran by Vaclav (29-06-2021 12:19:40) Run:2
Running from C:\Users\Vaclav\Desktop
Loaded Profiles: Vaclav
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
Task: {0E3B677C-0B20-4404-B60A-0092693B2014} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-28] (Google LLC -> Google LLC)
Task: {DBA019C2-E0D0-4B24-BC3E-5574A0C543C9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-28] (Google LLC -> Google LLC)
C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
SearchScopes: HKU\S-1-5-21-3554629397-3815353969-3522257156-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
FirewallRules: [TCP Query User{C6AF9F36-3034-4BAD-AA18-112AB2615FF7}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe => No File
FirewallRules: [UDP Query User{08BD91C6-0BA0-4E85-B8E9-D8CA2725DD09}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe => No File
C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Cache\f_001071->setup.exe
C:\Users\Vaclav\Downloads\setup.rar

EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E3B677C-0B20-4404-B60A-0092693B2014}" => not found
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DBA019C2-E0D0-4B24-BC3E-5574A0C543C9}" => not found
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => not found
"C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore" => not found
HKU\S-1-5-21-3554629397-3815353969-3522257156-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C6AF9F36-3034-4BAD-AA18-112AB2615FF7}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{08BD91C6-0BA0-4E85-B8E9-D8CA2725DD09}C:\users\vaclav\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe" => not found
"C:\Users\Vaclav\AppData\Local\Microsoft\Edge\User Data\Default\Cache\f_001071->setup.exe" => not found
"C:\Users\Vaclav\Downloads\setup.rar" => not found

=========== EmptyTemp: ==========

BITS transfer queue => 7626752 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8462667 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 1196 B
Edge => 0 B
Chrome => 0 B
Firefox => 23794419 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 4266 B
NetworkService => 4266 B
Vaclav => 650167 B

RecycleBin => 0 B
EmptyTemp: => 38.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 12:19:53 ====
CPU: AMD Ryzen 3600
GPU: EVGA GeForce GTX 1060 3G GAMING
MB: MSI MAG B550 TOMAHAWK
RAM: Crucial Ballistix Black 16GB (2x8GB) DDR4 3600 MHz CL16
PSU: Seasonic CORE GC-650 - 650W
1x Kingston KC2500 PCIe NVMe M.2 - 500GB
1x WD Blue 500 GB SATA SSD
1x Segate 500 GB SATA HDD


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 6 hostů