Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-08-2026
Ran by Administrator1682026 (29-08-2026 09:26:13)
Running from C:\Users\Administrator180826\Desktop
Microsoft Windows 10 IoT Enterprise LTSC Version 21H2 19044.7663 (X64) (2026-08-16 17:15:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3027844117-2545590462-1958035622-500 - Administrators - Disabled)
Administrator1682026 (S-1-5-21-3027844117-2545590462-1958035622-1001 - Administrators - Enabled) => C:\Users\Administrator180826
DefaultAccount (S-1-5-21-3027844117-2545590462-1958035622-503 - Limited - Disabled)
Guest (S-1-5-21-3027844117-2545590462-1958035622-501 - Limited - Disabled)
Rocky671RZ (S-1-5-21-3027844117-2545590462-1958035622-1002 - Limited - Enabled) => C:\Users\Rocky671RZ
WDAGUtilityAccount (S-1-5-21-3027844117-2545590462-1958035622-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AIDA64 Engineer v8.35 (HKLM\...\AIDA64 Engineer_is1) (Version: 8.35 - FinalWire Ltd.)
AIMP (HKLM\...\AIMP) (Version: 5.40.2725 - Artem Izmaylov)
Allavsoft 3.29.4.9698 (HKLM-x32\...\{6EBED4D8-13D9-4370-8D44-B57DDB7A787C}_is1) (Version:  - Allavsoft Corporation)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.136 - Advanced Micro Devices, Inc.) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 8.08.12.551 - Advanced Micro Devices, Inc.)
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.40.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.1.13 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Master SDK (HKLM\...\{DBD50508-5F75-416B-995D-C42433A00944}) (Version: 2.1.0.1236 - Advanced Micro Devices, Inc.)
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.44 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 26.5.2 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{5af2fedb-5a3e-4b58-882b-67587757e90b}) (Version: 8.08.12.551 - Advanced Micro Devices, Inc.) Hidden
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 152.1.94.117 - Autori prehliadača Brave)
Bulk Image Downloader v6.50.0.0 (64 bit) (HKLM\...\Bulk Image Downloader (64 bit)_is1) (Version: 6.50 - Antibody Software)
Dell Peripheral Manager (HKLM\...\Dell Peripheral Manager) (Version: 1.7.7 - Dell Inc.)
eM Client (HKLM-x32\...\{D02EF4EB-EA81-4689-9733-C3CB9BB5DF1D}) (Version: 10.4.5674.0 - eM Client s.r.o.)
EncryptOnClick (HKLM-x32\...\EncryptOnClick_is1) (Version: 2.4.16.0 - 2BrightSparks)
ESET Security (HKLM\...\{2805A756-BA57-4FA9-A870-1175D7019FA5}) (Version: 19.2.7.0 - ESET, spol. s r.o.)
ESET VPN (HKLM\...\{ac2ff246-998c-4014-bea8-b20edd0a2eda}_is1) (Version: 1.6.12 - ESET, spol. s r.o.)
FastStone MaxView 3.5 (HKLM-x32\...\FastStone MaxView) (Version: 3.5 - FastStone Corporation)
FastStone Photo Resizer 4.5 (HKLM-x32\...\FastStone Photo Resizer) (Version: 4.5 - FastStone Corporation)
FolderIco 6.2.1 (HKLM\...\{22C37D82-6137-40BF-8625-7A846ED65F3A}_is1) (Version:  - teorex)
Hard Disk Sentinel PRO (HKLM-x32\...\Hard Disk Sentinel_is1) (Version: 6.40 - Janos Mathe)
Inpaint 8.1 (HKLM\...\{5808866F-D115-46B2-8123-BB6801968101}_is1) (Version:  - Teorex)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: 6.43.10 - Tonec Inc.)
Macrium Reflect Free (HKLM\...\{A302C59F-C733-4DA0-9611-1286A9051D15}) (Version: 8.0.7783 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7783 - Paramount Software (UK) Ltd.)
Micron Storage Executive (HKU\S-1-5-21-3027844117-2545590462-1958035622-1001\...\Micron Storage Executive 11.08.082025.00) (Version: 11.08.082025.00 - Micron Technology)
Microsoft Edge (HKLM-x32\...\{97FFF1CD-ACA4-3EBB-AA8F-A9AD5E6935D8}) (Version: 151.0.4129.107 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 151.0.4129.101 - Microsoft Corporation)
Microsoft Office LTSC Professional Plus 2021 - sk-sk (HKLM\...\ProPlus2021Volume - sk-sk) (Version: 16.0.14334.20848 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.51.36247 (HKLM\...\{6FA797CF-6B76-4B6D-87EE-768F92008720}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.51.36247 (HKLM\...\{931A2CF0-2404-45EA-82F5-345735AE6A90}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.51.36247 (HKLM-x32\...\{582BA719-E6F1-4651-A873-049E6A0DDDAF}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.51.36247 (HKLM-x32\...\{4BF7CE18-E151-449F-9190-6CDBED0BB4A2}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.51.36247 (HKLM-x32\...\{0e3bb569-69d6-4c34-bff9-c2f81db5e5f0}) (Version: 14.51.36247.0 - Microsoft Corporation)
Microsoft Visual C++ v14 Redistributable (x86) - 14.51.36247 (HKLM-x32\...\{9a6ce18d-11c0-4452-aa35-9f2b8437c686}) (Version: 14.51.36247.0 - Microsoft Corporation)
MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 3.0.1.05 - MSI)
NVIDIA Grafický ovládač 581.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 581.57 - NVIDIA Corporation)
NVIDIA Ovládač zvuku HD 1.4.5.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.0 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14334.20848 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14334.20848 - Microsoft Corporation) Hidden
PhotoScissors 6.1 (HKLM\...\{1BB49C60-8D5D-439C-BEC1-BDCCF003AB40}_is1) (Version:  - teorex)
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 26.08.19.0 - Kakao Corp.)
PowerShell 7-x64 (HKLM\...\{499CA787-2899-40D2-A793-087E08EB227D}) (Version: 7.6.5.0 - Microsoft Corporation)
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.5.0 - Advanced Micro Devices, Inc.) Hidden
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 5.2.3 - The qBittorrent project)
Quick Share (HKLM\...\{CF9A0A2E-4CB4-4087-9800-194027911C30}) (Version: 1.0.2600.1 - Google LLC)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.80.20.407 - Realtek)
Revo Uninstaller Pro 5.5.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.5.2 - VS Revo Group, Ltd.)
SereneScreen Marine Aquarium 3 (HKLM-x32\...\SereneScreen Marine Aquarium 3_is1) (Version: 3.3 - Prolific Publishing, Inc.)
Shutter Encoder (64bit) (HKLM-x32\...\{AC8B2037-70E7-46C7-92B9-DC797E4F4674}_is1) (Version: 20.2 - Paul Pacifico)
SumatraPDF (HKU\S-1-5-21-3027844117-2545590462-1958035622-1002\...\SumatraPDF) (Version: 3.6.1 - Krzysztof Kowalczyk)
VideoProc Converter AI (HKLM-x32\...\VideoProc Converter AI) (Version: 7.7 - Digiarty, Inc.)
WhoCrashed 7.10 (HKLM\...\WhoCrashed_is1) (Version: 7.10 - Resplendence Software Projects Sp.)
Windows 7 Games for Windows 11, 10 and 8 (HKLM\...\Windows 7 Games for Windows 11, 10 and 8_is1) (Version: 4.3 - winaero.com)
WinRAR 7.23 (64-bitová verzia) (HKLM\...\WinRAR archiver) (Version: 7.23.0 - win.rar GmbH)
ZD Screen Recorder 11.7.7 (HKLM-x32\...\{C0A67ACE-D1F5-4E02-920A-AB1C34E95169}) (Version: 11.7.7.0 - ZD Soft)

Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2026-08-28] (NVIDIA Corp.)
Quick Share -> C:\Program Files\Google\NearbyShare [2026-08-19] (Google LLC)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3027844117-2545590462-1958035622-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
CustomCLSID: HKU\S-1-5-21-3027844117-2545590462-1958035622-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> C:\Program Files\ESET\ESET Security\egui.exe (ESET, spol. s r.o. -> ESET)
ShellIconOverlayIdentifiers: [			IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2021-03-02] (Tonec Inc. -> Tonec FZE)
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu64.dll [2026-08-27] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-06-22] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2026-06-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2026-06-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-06-22] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu64.dll [2026-08-27] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispsi.inf_amd64_671c0a23616db704\nvshext.dll [2025-10-10] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-06-22] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [Folderico] -> {CC0C45C5-EFDE-4B8A-A8B0-9ED733D9E6AC} => C:\Program Files\FolderIco\FolderIco.dll [2019-02-21] (Maxim Gapchenko -> TeoreX)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2026-06-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2026-06-27] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2021-11-07] (Tonec Inc. -> Internet Download Manager, Tonec Inc.)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2021-11-07] (Tonec Inc. -> Internet Download Manager, Tonec Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-08-20] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2019-12-07 11:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 1.1.1.1 - 1.0.0.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3027844117-2545590462-1958035622-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator180826\Pictures\Tapeta\Windows 10.png
HKU\S-1-5-21-3027844117-2545590462-1958035622-1002\Control Panel\Desktop\\Wallpaper -> D:\Obrázky\Tapety na plochu\Obľúbené\Platená tapetaupr.png
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 5) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "Reflect UI"
HKLM\...\StartupApproved\Run: => "Nearby Share"
HKLM\...\StartupApproved\Run32: => "Command Center"
HKLM\...\StartupApproved\Run32: => "DriveUtilitiesHelper"
HKU\S-1-5-21-3027844117-2545590462-1958035622-1001\...\StartupApproved\Run: => "ESET VPN"
HKU\S-1-5-21-3027844117-2545590462-1958035622-1001\...\StartupApproved\Run: => "IDMan"
HKU\S-1-5-21-3027844117-2545590462-1958035622-1002\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_0D3A46B562E7F5B8C059975C9FD6A406"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{501A05E0-2DFF-42EB-B9AB-B4F62AC8540D}M:\aplikácie\portable apps\driver search\sdi_x64_r2309.exe] => (Allow) M:\aplikácie\portable apps\driver search\sdi_x64_r2309.exe => No File
FirewallRules: [UDP Query User{8D780CD1-5CF3-4188-BAC1-D7687838C42F}M:\aplikácie\portable apps\driver search\sdi_x64_r2309.exe] => (Allow) M:\aplikácie\portable apps\driver search\sdi_x64_r2309.exe => No File
FirewallRules: [{E8AA68BF-96C5-425D-96E5-340F95CCA1CF}] => (Allow) C:\Program Files\Google\NearbyShare\nearby_share.exe (Google LLC -> Google)
FirewallRules: [{81136EBA-6F86-4D90-89C6-5CF8CE0984A6}] => (Allow) C:\Program Files\Google\NearbyShare\nearby_share.exe (Google LLC -> Google)
FirewallRules: [{7CDAA297-4C2A-4BAB-A88F-6ACCCD156E3B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B820C8C9-C9E6-429F-AD9F-56FF602FBD47}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{59FCE44C-D155-43E3-9DCF-82ED3B1D91D8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{365F4E98-7449-4F17-9D60-5491BD49A65F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{48C8680E-8C7A-46F6-AE51-FFB28E08A22E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{42D0797B-4483-4939-B6CA-86A84B540781}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{7111938C-97F2-44CF-A24A-4DC9090BBF97}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E7C0BA70-D0D2-438F-A7CF-D6BB6F9A0D22}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{F17024C4-7FCD-47FC-A7B8-4944F475C833}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A658742B-B796-40C7-A088-55343F94E486}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{1ACE94C5-BAD6-4D38-9E42-D5133C6D5D43}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{8911A4FA-343E-4573-8206-AA4B498292AA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{528E8AFC-CDBF-46C0-BF8A-79EC78E62FF3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.296.518.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{88E329F5-344C-4DC6-9EC1-9C33A1EC980E}] => (Block) C:\Program Files\FinalWire\AIDA64 Engineer\aida64.exe (FinalWire Kft. -> FinalWire Ltd.)
FirewallRules: [{A69903CE-B25D-4123-96AE-D91D92198417}] => (Block) C:\Program Files\FinalWire\AIDA64 Engineer\aida64.exe (FinalWire Kft. -> FinalWire Ltd.)
FirewallRules: [TCP Query User{74E6B81E-DFB8-4672-BE25-0A9854AD4FDD}C:\program files\micron technology\micron storage executive\java\bin\javaw.exe] => (Block) C:\program files\micron technology\micron storage executive\java\bin\javaw.exe
FirewallRules: [UDP Query User{BA989A85-8E83-4806-A244-4281529BA137}C:\program files\micron technology\micron storage executive\java\bin\javaw.exe] => (Block) C:\program files\micron technology\micron storage executive\java\bin\javaw.exe
FirewallRules: [{8FE0A6ED-403B-46B3-A09C-E22A046B8B77}] => (Block) C:\Program Files\Dell\Dell Peripheral Manager\DPM.exe (IndiLogic LLC -> Dell Inc.)
FirewallRules: [{EE9A959B-4CAF-4FF1-9AED-BC89F4643125}] => (Block) C:\Program Files\Dell\Dell Peripheral Manager\DPM.exe (IndiLogic LLC -> Dell Inc.)
FirewallRules: [{BDB5A26E-CBCF-4DB6-B67C-3D3C0C2AB93D}] => (Block) C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe (IndiLogic LLC -> )
FirewallRules: [{33A6AA86-7F9C-4F84-AD18-5E50A55E3558}] => (Block) C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe (IndiLogic LLC -> )
FirewallRules: [{967354B5-A0AE-49A7-AA5C-12A67EA62641}] => (Block) C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe (IndiLogic LLC -> Dell Inc.)
FirewallRules: [{7702BDBC-566D-4989-A9F0-67B4FFFC22DD}] => (Block) C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe (IndiLogic LLC -> Dell Inc.)
FirewallRules: [{3539986C-65C4-4137-A993-2AECF0EDE321}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{8C59B780-8EFC-4236-BBA6-5E187C50416A}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{EAB947B7-2B24-4E59-84BE-355DBF3C9992}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9BD0AF40-D5B2-4D1E-8D8D-1FCF4D7E8A85}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0B2138BC-4E2C-450A-95B1-0B3194767576}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{EFBAC2A1-C59B-4509-A7EA-61D339CE657C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{92378541-DA81-4D38-9E06-1588834ED516}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0A0D24AA-B7C6-483C-B64E-351F542B412D}] => (Allow) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)

==================== Restore Points =========================

24-08-2026 07:42:16 Micron SSD Cache 1.3.3.4 install
25-08-2026 10:26:01 Installed PowerShell 7-x64
25-08-2026 16:08:19 Eset-nastavenia systému
25-08-2026 17:03:17 Micron SSD Cache 1.7.3.2 removal
26-08-2026 20:58:41 Installed eM Client

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (08/28/2026 06:50:52 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress..

Error: (08/28/2026 06:50:52 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (08/28/2026 06:50:52 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress..

Error: (08/28/2026 06:50:52 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (08/27/2026 11:06:07 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiska nemohol dokončiť opätovné vystrihnutie v Data (D:), pretože: Hardvér, ktorý podporuje tento zväzok, nepodporuje požadovanú operáciu. (0x8900002A)

Error: (08/25/2026 07:39:07 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "F:\Software do počítača\eset_internet_security_live_installer.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.7663_none_60b9ed0b71f50c93.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.7663_none_a86723e286713599.manifest.

Error: (08/25/2026 07:37:25 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "F:\Software do počítača\eset_internet_security_live_installer.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.7663_none_60b9ed0b71f50c93.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.7663_none_a86723e286713599.manifest.

Error: (08/24/2026 05:21:04 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "M:\Software do počítača\eset_internet_security_live_installer.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.7663_none_60b9ed0b71f50c93.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.7663_none_a86723e286713599.manifest.


System errors:
=============
Error: (08/28/2026 03:14:57 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (08/28/2026 03:14:50 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (08/28/2026 03:14:47 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service TokenBroker with arguments "Unavailable" in order to run the server:
Windows.Internal.Security.Authentication.Web.TokenBrokerInternal

Error: (08/28/2026 03:14:44 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service TokenBroker with arguments "Unavailable" in order to run the server:
Windows.Internal.Security.Authentication.Web.TokenBrokerInternal

Error: (08/28/2026 03:14:42 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service TokenBroker with arguments "Unavailable" in order to run the server:
Windows.Internal.Security.Authentication.Web.TokenBrokerInternal

Error: (08/28/2026 03:14:41 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service netprofm with arguments "Unavailable" in order to run the server:
{A47979D2-C419-11D9-A5B4-001185AD2B89}

Error: (08/28/2026 03:14:41 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service netprofm with arguments "Unavailable" in order to run the server:
{A47979D2-C419-11D9-A5B4-001185AD2B89}

Error: (08/28/2026 03:14:41 PM) (Source: DCOM) (EventID: 10005) (User: MSI-PC-ROCKY671)
Description: DCOM got error "1084" attempting to start the service netprofm with arguments "Unavailable" in order to run the server:
{A47979D2-C419-11D9-A5B4-001185AD2B89}


Windows Defender:
================
TimeCreated : 19. 8. 2026 10:33:20
Message     : Microsoft Defender Antivirus scan has been stopped before completion.
Scan ID: {19C398AB-FC37-400C-9163-7C29D29633E1}
Scan Type: Antimalware
Scan Parameters: Quick Scan
User: NT AUTHORITY\SYSTEM
Stop Reason: RPC connection rundown


CodeIntegrity:
===============
Date: 2026-08-29 09:04:12
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2026-08-29 09:01:39
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

BIOS: American Megatrends International, LLC. 2.PB 08/20/2026
Motherboard: MSI B350M GAMING PRO (MS-7A39)
Processor: AMD Ryzen 5 3400G with Radeon Vega Graphics 
Percentage of memory in use: 23%
Total physical RAM: 14254.88 MB
Available physical RAM: 10913.73 MB
Total Virtual: 29102.88 MB
Available Virtual: 24975.88 MB

==================== Drives ================================

Disk 1 - Drive c: () (Fixed) (Total:476.33 GB) (Free:395.02 GB) (Model: Micron_2450_MTFDKBA512TFK) NTFS
Disk 0 - Drive d: (Data) (Fixed) (Total:931.51 GB) (Free:469.59 GB) (Model: WDC WD10EUCX-63YZ1Y0) NTFS
Disk 2 - Drive e: (MACRIUM_PE) (Removable) (Total:1 GB) (Free:0.69 GB) FAT32

Disk 1 - \\?\Volume{f84ef170-ab4b-44f3-8072-2d2b10dfe4c9}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS
Disk 1 - \\?\Volume{0f49566f-db99-41a9-9009-410f526d7b6e}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C4ACCF9F)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 476.9 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 57.3 GB) (Disk ID: 00085116)
Partition 1: (Active) - (Size=1 GB) - (Type=FAT32)

==================== End of Addition.txt =======================