Password reset and notification emails are now sending correctly.
If you recently requested a password reset, please check your inbox (and spam folder just in case).
You can now reset your password and log in as normal.
Welcome back to PCHF, and thank you for your patience during our migration process!
— The PCHF Team
Welcome to PC Help Forum!
You’re viewing our community as a guest.
That means you can browse posts, but can’t yet reply or start new topics.
Join us today — it's completely free!
As a member, you'll be able to:
✅ Get personalized tech support from trusted volunteers
🦠 Work one-on-one with our Malware Removal Specialists
Hello, malwarebytes spams me with these mesages, can anybody tell me what is it,
how did it get to my pc, and how to get rid of it please?
I have read on the Internet that it is some kind of traffic counter and it could also collect sensitive information like credit card numbers, passwords, depth of color, display resolution.
Is it true?
Thanks
If you receive any security warnings, or the User Account Control warning opens at any time whilst using FRST you can safely allow FRST to proceed.
FRST will open with two dialogue boxes, accept the disclaimer.
Frst will take a few minutes to scan your computer, and when finished will produce two log files on your desktop, FRST.txt, and Addition.txt. They will display immediately on the desktop, but can be reopened later as a notepad file.
[HEADING=1]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 3-07-2019
Ran by Administrátor (09-07-2019 01:09:02)
Running from C:\Users\Administrátor\Desktop
Windows 10 Home Version 1803 17134.829 (X64) (2018-08-17 19:38:09)
Boot Mode: Normal[/HEADING]
==================== Accounts: =============================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Kaspersky Free (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Error: (07/06/2019 02:12:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program chromodo.exe verze 49.13.20.402 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.
ID procesu: 32c4
Čas spuštění: 01d531d6be259fd0
Čas ukončení: 4294967295
Cesta k aplikaci: C:\Program Files (x86)\Comodo\Chromodo\chromodo.exe
ID hlášení: 4f28b51d-3a20-40dc-bb2b-29ccebac963c
Úplný název balíčku s chybou:
ID aplikace související s balíčkem s chybou:
Error: (07/06/2019 12:47:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program MicrosoftEdgeCP.exe verze 11.0.17134.799 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.
ID procesu: 7910
Čas spuštění: 01d533e6eb50c0ff
Čas ukončení: 22
Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wek yb3d8bbwe\MicrosoftEdgeCP.exe
ID hlášení: 6e4e0b28-4972-4cab-940e-afac035d61c4
Úplný název balíčku s chybou: Microsoft.MicrosoftEdge_42.17134.1.0_neutral__8wek yb3d8bbwe
ID aplikace související s balíčkem s chybou: ContentProcess
Error: (07/06/2019 12:34:58 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program MicrosoftEdgeCP.exe verze 11.0.17134.799 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.
ID procesu: 4b98
Čas spuštění: 01d531d7fe3a0b16
Čas ukončení: 4294967295
Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wek yb3d8bbwe\MicrosoftEdgeCP.exe
ID hlášení: 88becf91-1494-4f6c-8c8c-de9bceaeba8f
Úplný název balíčku s chybou: Microsoft.MicrosoftEdge_42.17134.1.0_neutral__8wek yb3d8bbwe
ID aplikace související s balíčkem s chybou: ContentProcess
Error: (07/08/2019 10:16:27 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-V6VDE39)
Description: Server Microsoft.MicrosoftEdge_42.17134.1.0_neutral__8wek yb3d8bbwe!ContentProcess#{00031404-0001-0000-F1E4-000000000000} se v daném časovém limitu neregistroval u služby DCOM.
Error: (07/08/2019 10:09:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NGIService service failed to start due to the following error:
Systém nemůže nalézt uvedený soubor.
Error: (07/08/2019 10:09:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The avast! Antivirus service failed to start due to the following error:
Systém nemůže nalézt uvedený soubor.
Error: (07/08/2019 10:09:34 PM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk1\DR1 má chybný blok.
Error: (07/08/2019 10:09:34 PM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk1\DR1 má chybný blok.
Error: (07/08/2019 10:09:34 PM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk1\DR1 má chybný blok.
Error: (07/08/2019 10:09:34 PM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk1\DR1 má chybný blok.
[HEADING=1]Windows Defender:[/HEADING]
Date: 2019-06-29 09:59:40.574
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.263.48.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.
Date: 2019-06-29 09:59:40.574
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.263.48.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.
Date: 2019-06-29 09:59:40.574
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.263.48.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.
Date: 2019-06-29 09:59:40.434
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.263.48.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.
Date: 2019-05-05 23:25:45.666
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.263.48.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.
[HEADING=1]CodeIntegrity:[/HEADING]
Date: 2018-12-27 16:30:23.549
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-27 16:27:43.233
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-23 17:35:08.422
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-23 17:35:04.585
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-23 15:33:04.427
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-23 15:33:00.773
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-23 13:31:15.577
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-23 13:31:11.612
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Kaspersky Lab\AVP19.0.0\Data\updater\supd_aea4581\updater.kd l that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. P1.70 09/07/2010
Motherboard: ASRock M3A770DE
Processor: AMD Phenom™ II X4 965 Processor
Percentage of memory in use: 54%
Total physical RAM: 12287.3 MB
Available physical RAM: 5559.58 MB
Total Virtual: 32767.3 MB
Available Virtual: 25687.79 MB
Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system. Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
Please download AdwCleaner by Xplode onto your desktop.
[ul]
[li]Close all open programs and internet browsers.[/li][li]Right Click on adwcleaner.exe and run as admin to run the tool.[/li][li]Click on Scan button.[/li][li]When the scan has finished click on Clean button.[/li][li]Your computer will be rebooted automatically. A text file will open after the restart.[/li][li]Please post the contents of that logfile with your next reply.[/li][li]You can find the logfile at C:\AdwCleaner[S1].txt as well.[/li][/ul]
[COLOR=rgb(255, 255, 255)] problem has disappeared in Microsoft edge , but it came back when i start browsing with chromodo browser, it also came back in
[COLOR=rgb(255, 255, 255)]
[HEADING=1]Fix result of Farbar Recovery Scan Tool (x64) Version: 3-07-2019
Ran by Administrátor (09-07-2019 12:55:57) Run:1
Running from C:\Users\Administrátor\Desktop
Loaded Profiles: Administrátor & Administrator (Available Profiles: Administrátor & Administrator)
Boot Mode: Normal[/HEADING]
fixlist content:
Start
Closeprocesses:
CreateRestorePoint:
Emptytemp:
VirusTotal: C:\Windows\system32\drivers\vasdDev.sys
HKLM...\Run: [AvastUI.exe] => “C:\Program Files\AVAST Software\Avast\AvLaunch.exe” /gui
HKLM-x32...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle America, Inc. → Oracle Corporation)
HKU\S-1-5-21-3472240800-3569865723-1055443696-1001...\Policies\Explorer: [NoLowDiskSpaceChecks] False
HKU\S-1-5-21-3472240800-3569865723-1055443696-1001...\MountPoints2: {aa2e3823-ad33-11e8-9346-00252281e08d} - “G:\setup.exe”
GroupPolicy: Restriction ? <==== ATTENTION
CHR Extension: (Platby Internetov�ho obchodu Chrome) - C:\Users\Administr�tor\AppData\Local\Google\Chrome \User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2018-08-18]
Task: {05F42D32-9EC0-4F0E-B32E-66114E0F58D9} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2281944 2019-06-04] (AVAST Software s.r.o. → AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip..\Interfaces{8bc03728-6a4b-499c-9bc3-b24c4b66c9f6}: [DhcpNameServer] 192.168.0.1 192.168.0.1
CHR Extension: (Chrome Media Router) - C:\Users\Administr�tor\AppData\Local\Google\Chrome \User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm [2019-06-19]
S2 avast! Antivirus; “C:\Program Files\AVAST Software\Avast\AvastSvc.exe”
S2 NGIService; “C:\Program Files (x86)\Common Files\McAfee\NGI\Service\NGIService.exe” StartAsNGIService
S3 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [201240 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [230344 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [201768 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswblog; C:\Windows\System32\drivers\aswbloga.sys [346592 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [59496 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
R0 aswElam; C:\Windows\System32\drivers\aswElam.sys [15360 2018-12-28] (Microsoft Windows Early Launch Anti-malware Publisher → AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [239840 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46384 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42288 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [163208 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [111800 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [87432 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1028680 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [469272 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [208472 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
S3 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [380464 2018-12-28] (AVAST Software s.r.o. → AVAST Software)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2019-06-29] (Adlice → )
U3 aswbdisk; no ImagePath
2019-06-06 01:54 - 2019-06-06 01:54 - 000003584 _____ () C:\Users\Administr�tor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2019-03-04 01:52 - 2019-03-04 01:52 - 000000218 _____ () C:\Users\Administr�tor\AppData\Local\recently-used.xbel
ShellIconOverlayIdentifiers: [00asw] → {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll → No File
ContextMenuHandlers1: [avast] → {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll → No File
ContextMenuHandlers3: [00asw] → {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll → No File
ContextMenuHandlers6: [avast] → {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll → No File
HKU\S-1-5-21-3472240800-3569865723-1055443696-1001\Software\Classes\regfile: regedit.exe “%1” <==== ATTENTION
Shortcut: C:\Users\Administr�tor\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\VirtualDJ\Online Help.lnk → hxxp://www.virtualdj.com/wiki
Shortcut: C:\Users\Administr�tor\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\VirtualDJ[www.virtualdj.com.lnk](http://www.virtualdj.com.lnk) → hxxp://www.virtualdj.com
C:\Windows\System32\Tasks\Uninstaller_SkipUac_Admi nistr�tor
C:\Windows\Tasks\Uninstaller_SkipUac_Administr�tor .job
C:\Windows\System32\drivers\aswVmm.sys
C:\Windows\System32\drivers\aswStm.sys
C:\Windows\System32\drivers\aswSP.sys
C:\Windows\System32\drivers\aswSnx.sys
C:\Windows\System32\drivers\aswRvrt.sys
C:\Windows\System32\drivers\aswRdr2.sys
C:\Windows\System32\drivers\aswMonFlt.sys
C:\Windows\System32\drivers\aswKbd.sys
C:\Windows\System32\drivers\aswHwid.sys
C:\Windows\System32\drivers\aswHdsKe.sys
C:\Windows\System32\drivers\aswElam.sys
C:\Windows\System32\drivers\aswbloga.sys
C:\Windows\System32\drivers\aswbidsha.sys
C:\Windows\System32\drivers\aswbidsdrivera.sys
C:\Program Files\AVAST Software
C:\Program Files\Common Files\AVAST Software
C:\Program Files (x86)\Common Files\McAfee
Folder: C:\Users\Administr�tor\source
VirusTotal: C:\Users\Administr�tor\Downloads\vs_community__142 9971524.1561737004.exe
C:\WINDOWS\system32\drivers\etc\hosts
Hosts:
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
end
Processes closed successfully.
Error: (0) Failed to create a restore point.
VirusTotal: C:\Windows\system32\drivers\vasdDev.sys => VirusTotal
“HKLM\Software\Microsoft\Windows\CurrentVersion\Ru n\AvastUI.exe” => could not remove
“HKLM\Software\WOW6432Node\Microsoft\Windows\Curre ntVersion\Run\SunJavaUpdateSched” => removed successfully
“HKU\S-1-5-21-3472240800-3569865723-1055443696-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoLowDiskSpaceChecks” => removed successfully
HKU\S-1-5-21-3472240800-3569865723-1055443696-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2{aa2e3823-ad33-11e8-9346-00252281e08d} => removed successfully
HKLM\Software\Classes\CLSID{aa2e3823-ad33-11e8-9346-00252281e08d} => not found
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
CHR Extension: (Platby Internetov�ho obchodu Chrome) - C:\Users\Administr�tor\AppData\Local\Google\Chrome \User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2018-08-18] => Error: No automatic fix found for this entry.
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot{05F42D32-9EC0-4F0E-B32E-66114E0F58D9}” => removed successfully
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{05F42D3 2-9EC0-4F0E-B32E-66114E0F58D9}” => removed successfully
C:\Windows\System32\Tasks\Avast Software\Overseer => moved successfully
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer” => removed successfully
“HKLM\System\CurrentControlSet\Services\Tcpip\Para meters\DhcpNameServer” => removed successfully
“HKLM\System\CurrentControlSet\Services\Tcpip\Para meters\Interfaces{8bc03728-6a4b-499c-9bc3-b24c4b66c9f6}\DhcpNameServer” => removed successfully
CHR Extension: (Chrome Media Router) - C:\Users\Administr�tor\AppData\Local\Google\Chrome \User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm [2019-06-19] => Error: No automatic fix found for this entry.
HKLM\System\CurrentControlSet\Services\avast! Antivirus => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\NGIService => removed successfully
NGIService => service removed successfully
HKLM\System\CurrentControlSet\Services\aswArPot => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswbidsdriv er => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswbidsh => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswblog => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswbuniv => could not remove, key could be protected
aswElam => Unable to stop service.
HKLM\System\CurrentControlSet\Services\aswElam => removed successfully
aswElam => service removed successfully
aswHdsKe => Unable to stop service.
HKLM\System\CurrentControlSet\Services\aswHdsKe => removed successfully
aswHdsKe => service removed successfully
HKLM\System\CurrentControlSet\Services\aswHwid => could not remove, key could be protected
aswKbd => Unable to stop service.
HKLM\System\CurrentControlSet\Services\aswKbd => could not remove, key could be protected
aswMonFlt => Unable to stop service.
HKLM\System\CurrentControlSet\Services\aswMonFlt => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswRdr => could not remove, key could be protected
aswRvrt => Unable to stop service.
HKLM\System\CurrentControlSet\Services\aswRvrt => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswSnx => could not remove, key could be protected
aswSP => Unable to stop service.
HKLM\System\CurrentControlSet\Services\aswSP => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswStm => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswVmm => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\TrueSight => removed successfully
TrueSight => service removed successfully
HKLM\System\CurrentControlSet\Services\aswbdisk => could not remove, key could be protected
“C:\Users\Administr�tor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini” => not found
“C:\Users\Administr�tor\AppData\Local\recently-used.xbel” => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\CLSID{472083B0-C522-11CF-8763-00608CC02F24} => removed successfully
HKLM\Software\Classes*\ShellEx\ContextMenuHandlers \avast => removed successfully
HKLM\Software\Classes\CLSID{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx \ContextMenuHandlers\00asw => removed successfully
HKLM\Software\Classes\CLSID{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHa ndlers\avast => removed successfully
HKLM\Software\Classes\CLSID{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKU\S-1-5-21-3472240800-3569865723-1055443696-1001\Software\Classes\regfile => removed successfully
“C:\Users\Administr�tor\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\VirtualDJ\Online Help.lnk” => not found
“C:\Users\Administr�tor\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\VirtualDJ[www.virtualdj.com.lnk](http://www.virtualdj.com.lnk)” => not found
“C:\Windows\System32\Tasks\Uninstaller_SkipUac_Adm inistr�tor” => not found
“C:\Windows\Tasks\Uninstaller_SkipUac_Administr�to r.job” => not found
Could not move “C:\Windows\System32\drivers\aswVmm.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswStm.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswSP.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswSnx.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswRvrt.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswRdr2.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswMonFlt.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswKbd.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswHwid.sys” => Scheduled to move on reboot.
C:\Windows\System32\drivers\aswHdsKe.sys => moved successfully
C:\Windows\System32\drivers\aswElam.sys => moved successfully
Could not move “C:\Windows\System32\drivers\aswbloga.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswbidsha.sys” => Scheduled to move on reboot.
Could not move “C:\Windows\System32\drivers\aswbidsdrivera.sys” => Scheduled to move on reboot.
“C:\Program Files\AVAST Software” folder move:
Could not move “C:\Program Files\AVAST Software” => Scheduled to move on reboot.
C:\Program Files\Common Files\AVAST Software => moved successfully
“C:\Program Files (x86)\Common Files\McAfee” => not found
========================= Folder: C:\Users\Administr�tor\source ========================
not found.
====== End of Folder: ======
“VirusTotal: C:\Users\Administr�tor\Downloads\vs_community__142 9971524.1561737004.exe” => not found
C:\WINDOWS\system32\drivers\etc\hosts => moved successfully
Hosts restored successfully.
========= RemoveProxy: =========
“HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVer sion\Internet Settings\Connections\DefaultConnectionSettings” => removed successfully
“HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVer sion\Internet Settings\Connections\SavedLegacySettings” => removed successfully
“HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Inter net Settings\Connections\DefaultConnectionSettings” => removed successfully
“HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Inter net Settings\Connections\SavedLegacySettings” => removed successfully
“HKU\S-1-5-21-3472240800-3569865723-1055443696-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings” => removed successfully
“HKU\S-1-5-21-3472240800-3569865723-1055443696-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings” => removed successfully
========= End of RemoveProxy: =========
========= netsh advfirewall reset =========
Ok.
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Ok.
========= End of CMD: =========
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
[HEADING=1]=========== EmptyTemp: ==========
BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 390494910 B
Java, Flash, Steam htmlcache => 1110 B
Windows/system/drivers => 69582864 B
Edge => 37394426 B
Chrome => 23147028 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 79836 B
LocalService => 0 B
NetworkService => 68526 B
NetworkService => 0 B
Administrátor => 174779419 B
Administrator => 49477304 B
RecycleBin => 0 B
EmptyTemp: => 720.5 MB temporary data Removed.[/HEADING]
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 09-07-2019 12:58:15)
C:\Windows\System32\drivers\aswVmm.sys => Could not move
C:\Windows\System32\drivers\aswStm.sys => Could not move
C:\Windows\System32\drivers\aswSP.sys => Could not move
C:\Windows\System32\drivers\aswSnx.sys => Could not move
C:\Windows\System32\drivers\aswRvrt.sys => Could not move
C:\Windows\System32\drivers\aswRdr2.sys => Could not move
C:\Windows\System32\drivers\aswMonFlt.sys => Could not move
C:\Windows\System32\drivers\aswKbd.sys => Could not move
C:\Windows\System32\drivers\aswHwid.sys => Could not move
C:\Windows\System32\drivers\aswbloga.sys => Could not move
C:\Windows\System32\drivers\aswbidsha.sys => Could not move
C:\Windows\System32\drivers\aswbidsdrivera.sys => Could not move
C:\Program Files\AVAST Software => Is moved successfully
Result of scheduled keys to remove after reboot:
HKLM\System\CurrentControlSet\Services\avast! Antivirus => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswArPot => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswbidsdriv er => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswbidsh => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswblog => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswbuniv => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswHwid => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswKbd => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswMonFlt => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswRdr => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswRvrt => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswSnx => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswSP => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswStm => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswVmm => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\aswbdisk => could not remove, key could be protected
==== End of Fixlog 12:58:16 ====[/color][/color]
Finally I’ve figured out how it approximately works.
I found that it works on Czech sites(www.seznam.cz,www.recepty.cz,www.csfd.cz,www .novinky.cz) and i must visit them through chromodo browser to activate the popup. After that it starts poping in Microsoft Edge too.
Ok, seems that Avast is being stubborn and will not remove, you should not have two antivirus applications on one machine.
[HEADING=1][ol]
[li]Download avastclear.exe on your desktop[/li][li]Start Windows in Safe Mode[/li][li]Open (execute) the uninstall utility[/li][li]If you installed Avast in a different folder than the default, browse for it. (Note: Be careful! The content of any folder you choose will be deleted!)[/li][li]Click REMOVE[/li][li]Restart your computer[/li][/ol][/HEADING]
Once you have done that please run this so I can make sure that nothing is lurking on your machine.
Create your ad-blocking DNS server that will protect your personal data, prevent tracking and allow you to control access to specific content on the Internet.
You can quickly change your DNS server with DNS Jumper.
Download DNS jumper by clicking here.
Unzip it to your desktop.
Double click the folder containing DNS Jumper
Right Click the program and run as Administrator.
Click and place a check in the Custom DNS box.
Copy these DNS servers ==== 176.103.130.130 ====== 176.103.130.131 and paste them into the highlighted boxes.
Click on Apply DNS
I did avastclear in safe mode, but AvastUI.exe probably still in my pc… This path “C:\Program Files\AVAST Software\Avast\AvLaunch.exe” doesnt exist or isnt visible for me, anyway i see AVLaunch startup in my Task manager.
Ok, we will remove any traces of it with this tool. It needs to be removed because it will use a lot of system resources when two antivirus applications are installed.
Download Quick Diag to your desktop.
Very Important!! – Make sure program is on your desktop.
Disable your Antivirus/Antispyware prior to scanning.
Right Click Run as Administrator.
Select the Quick Scan.
Time Zone : (UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague
[Administrátor (Administrator)] - [DESKTOP-V6VDE39] (S-1-5-21-3472240800-3569865723-1055443696-1001)
System: Microsoft Windows 10 Home - - (10.0.17134) - BuildType: Multiprocessor Free - OSLanguage: 1029 (0405) → (1803)
System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
Boot : Microsoft Windows 10 Home|C:\Windows|\Device\Harddisk0\Partition2
Boot : Normal boot
PC: To Be Filled By O.E.M. - To Be Filled By O.E.M. - IdNumber: To Be Filled By O.E.M. - UUID: 03000200-0400-0500-0006-000700080009
Processor : X64 - 3393 Mhz - AMD Phenom™ II X4 965 Processor
Default System BIOS - - American Megatrends Inc. - S/N: To Be Filled By O.E.M. - P1.70 - 090710 - 20100907
CoreTemp : ? Celsius
----------| Quick
---------- | SoundDevice
Zvukové zařízení High Definition Audio - Status: OK - Manufacturer: Microsoft - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0012&SUBSYS_10DE0101& REV_1001\5&1827189B&0&0001
Zvukové zařízení High Definition Audio - Status: OK - Manufacturer: Microsoft - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0012&SUBSYS_10DE0101& REV_1001\5&1827189B&0&0101
Zvukové zařízení High Definition Audio - Status: OK - Manufacturer: Microsoft - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0012&SUBSYS_10DE0101& REV_1001\5&1827189B&0&0201
Zvukové zařízení High Definition Audio - Status: OK - Manufacturer: Microsoft - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0012&SUBSYS_10DE0101& REV_1001\5&1827189B&0&0301
USB Audio Class 1.0 and 2.0 Device Driver With MS Effect - Status: OK - Manufacturer: C-MEDIA Inc. - PNPDeviceID: USB\VID_0D8C&PID_0319&MI_00\6&37873258&0&0000
Zvukové zařízení High Definition Audio - Status: OK - Manufacturer: Microsoft - PNPDeviceID: HDAUDIO\FUNC_01&VEN_1106&DEV_0397&SUBSYS_18490397& REV_1000\4&61D13CD&0&0001
DeviceID: \.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 2 Part. - PnPID : IDE\DISKKINGSTON_SA400S37480G___________________SB FK71E0\5&11EE6D0C&0&0.0.0
DeviceID: \.\PHYSICALDRIVE1 - Status: OK - IDE - Fixed hard disk media - 1 Part. - PnPID : IDE\DISKWDC_WD20EARS-00S8B1_____________________80.00A80\5&3ACF866E&0&1 .1.0
---------- | Windows updates - Activation - License
AS : Windows Defender Disabled
FW : WINDOWS Firewall
WMI : OK
WU: Windows Update Service [Manual(3)] = stopped
AS: Windows Defender [Manual(3)] = stopped
WMI: Windows Management Instrumentation [Auto(2)] = Running
---------- | Running processes
528 | [Owner : SYSTEM | Parent : 4(System) | ???] - (.Microsoft Corporation - Windows Session Manager.) - (10.0.17134.590) = C:\Windows\System32\smss.exe [12/02/2019 22:04:33] CPU Usage:0 %
708 | [Owner : SYSTEM | Parent : 688() | ???] - (.Microsoft Corporation - Client Server Runtime Process.) - (10.0.17134.1) = C:\Windows\System32\csrss.exe [12/04/2018 01:34:22] CPU Usage:0 %
808 | [Owner : SYSTEM | Parent : 688() | ???] - (.Microsoft Corporation - Windows Start-Up Application.) - (10.0.17134.1) = C:\Windows\System32\wininit.exe [12/04/2018 01:34:22] CPU Usage:0 %
816 | [Owner : SYSTEM | Parent : 788() | ???] - (.Microsoft Corporation - Client Server Runtime Process.) - (10.0.17134.1) = C:\Windows\System32\csrss.exe [12/04/2018 01:34:22] CPU Usage:0 %
880 | [Owner : SYSTEM | Parent : 808(wininit.exe) | ???] - (.Microsoft Corporation - Services and Controller app.) - (10.0.17134.191) = C:\Windows\System32\services.exe [18/08/2018 00:30:31] CPU Usage:0 %
892 | [Owner : SYSTEM | Parent : 808(wininit.exe) | 17.47 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (10.0.17134.376) = C:\Windows\System32\lsass.exe [07/11/2018 19:26:18] CPU Usage:0 %
968 | [Owner : SYSTEM | Parent : 788() | 11.64 Mo] - (.Microsoft Corporation - Windows Log-on Application.) - (10.0.17134.319) = C:\Windows\System32\winlogon.exe [01/10/2018 12:43:49] CPU Usage:0 %
540 | [Owner : SYSTEM | Parent : 880(services.exe) | 3.97 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
696 | [Owner : UMFD-0 | Parent : 808(wininit.exe) | 3.93 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.17134.765) = C:\Windows\System32\fontdrvhost.exe [14/05/2019 23:19:36] CPU Usage:0 %
700 | [Owner : UMFD-1 | Parent : 968(winlogon.exe) | 16.6 Mo] - (.Microsoft Corporation - Usermode Font Driver Host.) - (10.0.17134.765) = C:\Windows\System32\fontdrvhost.exe [14/05/2019 23:19:36] CPU Usage:0 %
944 | [Owner : SYSTEM | Parent : 880(services.exe) | 26.72 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1064 | [Owner : NETWORK SERVICE | Parent : 880(services.exe) | 14.33 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1108 | [Owner : SYSTEM | Parent : 880(services.exe) | 8.23 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1168 | [Owner : DWM-1 | Parent : 968(winlogon.exe) | 58.86 Mo] - (.Microsoft Corporation - Desktop Window Manager.) - (10.0.17134.1) = C:\Windows\System32\dwm.exe [12/04/2018 01:34:19] CPU Usage:0 %
1272 | [Owner : SYSTEM | Parent : 880(services.exe) | 9.64 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1328 | [Owner : SYSTEM | Parent : 880(services.exe) | 6.2 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1420 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 11.38 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1452 | [Owner : SYSTEM | Parent : 880(services.exe) | 10.6 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1508 | [Owner : SYSTEM | Parent : 880(services.exe) | 15.2 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1560 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 19.62 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1620 | [Owner : SYSTEM | Parent : 880(services.exe) | 9.19 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1656 | [Owner : SYSTEM | Parent : 880(services.exe) | 13.72 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.2.0.0) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [11/11/2018 15:40:18] CPU Usage:0 %
1680 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 8.94 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1708 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 7.72 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1788 | [Owner : SYSTEM | Parent : 880(services.exe) | 5.95 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1796 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 7.82 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1872 | [Owner : NETWORK SERVICE | Parent : 880(services.exe) | 10.78 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1912 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 18.15 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1940 | [Owner : SYSTEM | Parent : 880(services.exe) | 8.05 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1984 | [Owner : SYSTEM | Parent : 880(services.exe) | 8.27 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1992 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 7.62 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1408 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 8.73 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2192 | [Owner : SYSTEM | Parent : 1656(NVDisplay.Container.exe) | 41.8 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.2.0.0) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [11/11/2018 15:40:18] CPU Usage:0 %
2268 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 16.7 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2404 | [Owner : SYSTEM | Parent : 880(services.exe) | 13.28 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2460 | [Owner : NETWORK SERVICE | Parent : 880(services.exe) | 8.19 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2468 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 6.34 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2476 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 8.75 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2536 | [Owner : SYSTEM | Parent : 880(services.exe) | 11.65 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2616 | [Owner : SYSTEM | Parent : 880(services.exe) | 14.66 Mo] - (.Microsoft Corporation - Spooler SubSystem App.) - (10.0.17134.1) = C:\Windows\System32\spoolsv.exe [12/04/2018 01:34:41] CPU Usage:0 %
2680 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 7.39 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2724 | [Owner : NETWORK SERVICE | Parent : 880(services.exe) | 8.05 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2808 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 17.39 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2916 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 17.69 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2924 | [Owner : SYSTEM | Parent : 880(services.exe) | 7.7 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2932 | [Owner : SYSTEM | Parent : 880(services.exe) | 23.44 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2940 | [Owner : NETWORK SERVICE | Parent : 880(services.exe) | 12.17 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2948 | [Owner : SYSTEM | Parent : 880(services.exe) | 17.9 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2956 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 6.58 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3028 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 8.01 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3044 | [Owner : SYSTEM | Parent : 880(services.exe) | 5.85 Mo] - (.VIA Technologies, Inc. - Service binary.) - (0.1.0.0) = C:\Windows\System32\ViakaraokeSrv.exe [11/09/2015 05:06:52] CPU Usage:0 %
3052 | [Owner : SYSTEM | Parent : 880(services.exe) | 20.2 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3060 | [Owner : SYSTEM | Parent : 880(services.exe) | 5.71 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2288 | [Owner : SYSTEM | Parent : 880(services.exe) | 6.74 Mo] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - (1.824.31.1644) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [17/12/2018 04:29:48] CPU Usage:0 %
3096 | [Owner : SYSTEM | Parent : 880(services.exe) | 13.61 Mo] - (.Microsoft Corporation - Windows IP Over USB PC Service.) - (10.0.10586.15) = C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [20/11/2015 04:47:22] CPU Usage:0 %
3132 | [Owner : NETWORK SERVICE | Parent : 880(services.exe) | 12.37 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.10.2354.7482) = C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [11/11/2018 15:40:49] CPU Usage:0 %
3140 | [Owner : SYSTEM | Parent : 880(services.exe) | ???] - (.Microsoft Corporation - Windows Security Health Service.) - (4.13.17134.191) = C:\Windows\System32\SecurityHealthService.exe [18/08/2018 00:30:41] CPU Usage:0 %
3200 | [Owner : SYSTEM | Parent : 880(services.exe) | 13.64 Mo] - (.Comodo - Chromodo.) - (1.0.0.1) = C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [11/05/2016 13:39:58] CPU Usage:0 %
3272 | [Owner : SYSTEM | Parent : 880(services.exe) | 8.79 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3308 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 5.58 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3448 | [Owner : SYSTEM | Parent : 880(services.exe) | 12.03 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3540 | [Owner : SYSTEM | Parent : 880(services.exe) | 5.86 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3572 | [Owner : SYSTEM | Parent : 880(services.exe) | 11.88 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
3960 | [Owner : SYSTEM | Parent : 880(services.exe) | 22.73 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
4188 | [Owner : LOCAL SERVICE | Parent : 2268(svchost.exe) | 13.12 Mo] - (.Microsoft Corporation - Windows Audio Device Graph Isolation.) - (10.0.17134.829) = C:\Windows\System32\audiodg.exe [12/06/2019 19:29:29] CPU Usage:0 %
4432 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 5.6 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2912 | [Owner : SYSTEM | Parent : 880(services.exe) | 14.57 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
5768 | [Owner : SYSTEM | Parent : 944(svchost.exe) | 17.85 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.17134.1) = C:\Windows\System32\wbem\WmiPrvSE.exe [12/04/2018 01:34:40] CPU Usage:0 %
4976 | [Owner : Administrátor | Parent : 1620(svchost.exe) | 25.74 Mo] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.17134.1) = C:\Windows\System32\sihost.exe [12/04/2018 01:34:12] CPU Usage:0 %
4876 | [Owner : Administrátor | Parent : 880(services.exe) | 19.48 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
828 | [Owner : Administrátor | Parent : 880(services.exe) | 29.68 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
4596 | [Owner : Administrátor | Parent : 1508(svchost.exe) | 6.81 Mo] - (.Microsoft Corporation - Host Process for Windows Tasks.) - (10.0.17134.619) = C:\Windows\System32\taskhostw.exe [15/03/2019 17:04:46] CPU Usage:0 %
1440 | [Owner : SYSTEM | Parent : 880(services.exe) | 7.8 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1632 | [Owner : Administrátor | Parent : 1440(svchost.exe) | 14.94 Mo] - (.Microsoft Corporation - CTF Loader.) - (10.0.17134.1) = C:\Windows\System32\ctfmon.exe [12/04/2018 01:34:37] CPU Usage:0 %
3040 | [Owner : Administrátor | Parent : 3244() | 118.78 Mo] - (.Microsoft Corporation - Windows Explorer.) - (10.0.17134.677) = C:\Windows\explorer.exe [09/04/2019 19:41:05] CPU Usage:0 %
3120 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 17.22 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1280 | [Owner : Administrátor | Parent : 944(svchost.exe) | 22.62 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.17134.1) = C:\Windows\System32\dllhost.exe [12/04/2018 01:34:22] CPU Usage:0 %
6568 | [Owner : Administrátor | Parent : 944(svchost.exe) | 81.62 Mo] - (.Microsoft Corporation - Windows Shell Experience Host.) - (10.0.17134.753) = C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2t xyewy\ShellExperienceHost.exe [14/05/2019 23:19:45] CPU Usage:0 %
6784 | [Owner : Administrátor | Parent : 944(svchost.exe) | 162.11 Mo] - (.Microsoft Corporation - Search and Cortana application.) - (10.0.17134.829) = C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\SearchUI.exe [12/06/2019 19:29:49] CPU Usage:0 %
6840 | [Owner : Administrátor | Parent : 944(svchost.exe) | 22.29 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17134.1) = C:\Windows\System32\RuntimeBroker.exe [12/04/2018 01:34:06] CPU Usage:0 %
7144 | [Owner : Administrátor | Parent : 944(svchost.exe) | 20.37 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17134.1) = C:\Windows\System32\RuntimeBroker.exe [12/04/2018 01:34:06] CPU Usage:0 %
6044 | [Owner : Administrátor | Parent : 944(svchost.exe) | 124.26 Mo] - (.Microsoft Corporation - SkypeApp.) - (8.48.0.51) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x6 4__kzf8qxf38zg5c\SkypeApp.exe [28/06/2019 16:07:44] CPU Usage:0 %
6520 | [Owner : Administrátor | Parent : 944(svchost.exe) | 11.99 Mo] - (.-.) - (8.48.0.51) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x6 4__kzf8qxf38zg5c\SkypeBackgroundHost.exe [28/06/2019 16:07:44] CPU Usage:0 %
6564 | [Owner : Administrátor | Parent : 944(svchost.exe) | 20.59 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17134.1) = C:\Windows\System32\RuntimeBroker.exe [12/04/2018 01:34:06] CPU Usage:0 %
7192 | [Owner : Administrátor | Parent : 944(svchost.exe) | 12.97 Mo] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (10.0.17134.753) = C:\Windows\System32\SettingSyncHost.exe [14/05/2019 23:19:39] CPU Usage:0 %
7744 | [Owner : Administrátor | Parent : 944(svchost.exe) | 26.21 Mo] - (.Microsoft Corporation - Runtime Broker.) - (10.0.17134.1) = C:\Windows\System32\RuntimeBroker.exe [12/04/2018 01:34:06] CPU Usage:0 %
7928 | [Owner : Administrátor | Parent : 944(svchost.exe) | 13.57 Mo] - (.Microsoft Corporation - COM Surrogate.) - (10.0.17134.1) = C:\Windows\System32\dllhost.exe [12/04/2018 01:34:22] CPU Usage:0 %
1308 | [Owner : SYSTEM | Parent : 880(services.exe) | 37.11 Mo] - (.Microsoft Corporation - Microsoft Windows Search Indexer.) - (7.0.17134.677) = C:\Windows\System32\SearchIndexer.exe [09/04/2019 19:41:04] CPU Usage:0 %
8124 | [Owner : SYSTEM | Parent : 880(services.exe) | 12.06 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
8388 | [Owner : SYSTEM | Parent : 880(services.exe) | 9.61 Mo] - (.Disc Soft Ltd - Disc Soft Bus Service.) - (5.0.1.406) = C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [26/02/2015 11:15:54] CPU Usage:0 %
7524 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 7.31 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
9384 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 10 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
9924 | [Owner : Administrátor | Parent : 7744(RuntimeBroker.exe) | 48.81 Mo] - (.Microsoft Corporation - SkypeBridge.) - (8.48.0.51) = C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x6 4__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe [28/06/2019 16:07:44] CPU Usage:0 %
9948 | [Owner : SYSTEM | Parent : 880(services.exe) | 9.17 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
9372 | [Owner : NETWORK SERVICE | Parent : 880(services.exe) | 15.54 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
9064 | [Owner : Administrátor | Parent : 3084() | 27.65 Mo] - (.IObit - UninstallerMonitor.) - (8.0.2.1608) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe [18/08/2018 18:30:55] CPU Usage:0 %
7360 | [Owner : SYSTEM | Parent : 880(services.exe) | 9.71 Mo] - (.Microsoft Corporation - sedsvc.) - (10.0.17134.10066) = C:\Program Files\rempl\sedsvc.exe [11/06/2019 11:37:42] CPU Usage:0 %
6720 | [Owner : SYSTEM | Parent : 880(services.exe) | ???] - (.Microsoft Corporation - Služba Zprostředkovatel monitorování Ochrany System Guard v režimu runtime.) - (10.0.17134.1) = C:\Windows\System32\SgrmBroker.exe [12/04/2018 01:34:04] CPU Usage:0 %
8020 | [Owner : SYSTEM | Parent : 880(services.exe) | 8.43 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1392 | [Owner : Administrátor | Parent : 880(services.exe) | 11.59 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
5840 | [Owner : Administrátor | Parent : 944(svchost.exe) | 23.62 Mo] - (.Microsoft Corporation - Application Frame Host.) - (10.0.17134.1) = C:\Windows\System32\ApplicationFrameHost.exe [12/04/2018 01:34:18] CPU Usage:0 %
7252 | [Owner : SYSTEM | Parent : 880(services.exe) | 8.1 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
4532 | [Owner : SYSTEM | Parent : 880(services.exe) | 6.7 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
8532 | [Owner : Administrátor | Parent : 944(svchost.exe) | 33.67 Mo] - (.Microsoft Corporation - Windows Defender SmartScreen.) - (10.0.17134.677) = C:\Windows\System32\smartscreen.exe [09/04/2019 19:41:07] CPU Usage:0 %
9184 | [Owner : SYSTEM | Parent : 944(svchost.exe) | 9.34 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.17134.1) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [12/04/2018 01:34:55] CPU Usage:0 %
7028 | [Owner : NETWORK SERVICE | Parent : 944(svchost.exe) | 9.15 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.17134.1) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [12/04/2018 01:34:55] CPU Usage:0 %
8432 | [Owner : SYSTEM | Parent : 880(services.exe) | 7.3 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
1556 | [Owner : SYSTEM | Parent : 880(services.exe) | ???] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
7204 | [Owner : SYSTEM | Parent : 880(services.exe) | 15.48 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
2200 | [Owner : SYSTEM | Parent : 880(services.exe) | 6.55 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
8040 | [Owner : LOCAL SERVICE | Parent : 880(services.exe) | 6.62 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
8572 | [Owner : SYSTEM | Parent : 880(services.exe) | 5.77 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (10.0.17134.556) = C:\Windows\System32\svchost.exe [12/02/2019 22:04:35] CPU Usage:0 %
8304 | [Owner : Administrátor | Parent : 3040(explorer.exe) | 59.39 Mo] - (.SosVirus - QuickDiag.) - (27.2.19.1) = C:\Users\Administrátor\Desktop\quickdiag_V5_27.02. 19.1.exe [09/07/2019 17:51:39] CPU Usage:0 %
3252 | [Owner : NETWORK SERVICE | Parent : 944(svchost.exe) | 9.39 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (10.0.17134.1) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [12/04/2018 01:34:55] CPU Usage:0 %
Pinging google.com [172.217.23.238] with 32 bytes of data:
Reply from 172.217.23.238: bytes=32 time=8ms TTL=54
Reply from 172.217.23.238: bytes=32 time=8ms TTL=54
Reply from 172.217.23.238: bytes=32 time=8ms TTL=54
Reply from 172.217.23.238: bytes=32 time=8ms TTL=54
Ping statistics for 172.217.23.238:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 8ms, Maximum = 8ms, Average = 8ms
First please create a restore point!
Right click on Quick Diag Run as Admin.
Copy the content of the code box below to your clipboard.
Click on the S within the User Interface of the program.
Then click on Script.
Allow completion.
Post the log created in your next reply.
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also acknowledge that this forum may be hosted outside your country and you consent to the collection, storage, and processing of your data in the country where this forum is hosted.
Comment