Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vyskakujici trojsky kun ?? Prosím o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
shotik
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 10 kvě 2005 18:28

Vyskakujici trojsky kun ?? Prosím o kontrolu

#1 Příspěvek od shotik »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-10-2025
Ran by Aleš (12-10-2025 17:16:48)
Running from C:\Users\Katka\Downloads
Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) (2023-10-17 12:29:27)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-517974313-2919254220-300314987-500 - Administrator - Disabled)
Aleš (S-1-5-21-517974313-2919254220-300314987-1002 - Administrator - Enabled) => C:\Users\Aleš
DefaultAccount (S-1-5-21-517974313-2919254220-300314987-503 - Limited - Disabled)
Guest (S-1-5-21-517974313-2919254220-300314987-501 - Limited - Disabled)
Katka (S-1-5-21-517974313-2919254220-300314987-1003 - Limited - Enabled) => C:\Users\Katka
WDAGUtilityAccount (S-1-5-21-517974313-2919254220-300314987-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 23.01 (x64) (HKLM\...\7-Zip) (Version: 23.01 - Igor Pavlov)
Autodesk Fusion (HKU\S-1-5-21-517974313-2919254220-300314987-1002\...\73e72ada57b7480280f7a6f4a289729f) (Version: 2604.0.316 - Autodesk, Inc.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 25.9.10453.3120 - Gen Digital Inc.)
Balíček ovladače systému Windows - Prusa Research s.r.o. Original Prusa CW1 (02/13/2013 1.0.0.0) (HKLM\...\B10CCB939D59F72AA817B257D84328FC4A1DC752) (Version: 02/13/2013 1.0.0.0 - Prusa Research s.r.o.)
Balíček ovladače systému Windows - Prusa Research s.r.o. Original Prusa i3 MK2 (02/13/2013 1.0.0.0) (HKLM\...\E6CFEF5357DD0E2F987E98779FD6603959DA391B) (Version: 02/13/2013 1.0.0.0 - Prusa Research s.r.o.)
Balíček ovladače systému Windows - Prusa Research s.r.o. Original Prusa i3 MK3 Multi Material 2.0 upgrade (02/13/2013 1.0.0.0) (HKLM\...\FA562E43945E7D9CAC76A811E49088FF2255A11A) (Version: 02/13/2013 1.0.0.0 - Prusa Research s.r.o.)
Balíček ovladače systému Windows - Prusa Research s.r.o. Prusa i3 Plus MK3 3D printer (02/13/2013 1.0.0.0) (HKLM\...\890B56493F7CACBCA0E70EA8EBFD9A18BC780C34) (Version: 02/13/2013 1.0.0.0 - Prusa Research s.r.o.)
Balíček ovladače systému Windows - UltiMachine 3D Printer (RAMBo) (02/13/2013 1.0.0.0) (HKLM\...\D77EC126405DC217C7BF7DA6669B51E297D5CF23) (Version: 02/13/2013 1.0.0.0 - UltiMachine)
Bambu Studio (HKLM\...\Bambu Studio) (Version: 02.02.02.56 - Bambulab)
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.0.984.1153 - Piriform)
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1990.6 - Piriform Software) Hidden
CrystalDiskMark 8.0.4c (HKLM\...\CrystalDiskMark8_is1) (Version: 8.0.4c - Crystal Dew World)
Česká lokalizace pro Autodesk® Fusion 360 verze V8.4 (HKLM-x32\...\Česká lokalizace pro Autodesk® Fusion 360_is1) (Version: V8.4 - )
Dell ControlVault Host Components Installer 64 bit (HKLM\...\{0C642DDD-65AD-4408-BE4A-5ED6CB441893}) (Version: 4.12.5.8 - Broadcom Limited)
Dell SupportAssist (HKLM\...\{0307D6D7-56E0-408C-B8D9-D3C6AFEBDDB9}) (Version: 4.10.1.42635 - Dell Inc.)
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM\...\{6EBF5DC4-FA0B-4692-A954-E7470146943D}) (Version: 5.5.14.0 - Dell Inc.) Hidden
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM-x32\...\{d0ab664c-e704-4396-b9bc-ad1a7327731f}) (Version: 5.5.14.0 - Dell Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 10.3201.101.216 - ALPSALPINE CO., LTD.)
GearDXF (HKLM-x32\...\{B6FBFF5B-00DE-4618-A8E7-40BC5B2C54CF}) (Version: 3.2.2 - Forest Moon Productions)
Google Chrome (HKLM\...\{087CC47A-894D-368A-ABB9-DECB15910C6B}) (Version: 141.0.7390.66 - Google LLC)
HappyFoto smart moments 1.17.1 (HKU\S-1-5-21-517974313-2919254220-300314987-1003\...\6bd89b96-088f-5cd6-b726-d60a7bac81f7) (Version: 1.17.1 - )
iCloud Outlook (HKLM\...\{AC76D136-36CC-4606-8361-4939FE5D2381}) (Version: 14.2.0.108 - Apple Inc.)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2325.5.9.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{39BB0BC3-68F2-4966-AA5A-4D7CE2BCABDD}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{6D0BDF97-92E4-4E40-8E1B-757CC2B4B8C8}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Driver (HKLM\...\{D9AC5DE5-C384-4CE8-8770-4EC1D2DC749D}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Service Client x64 (HKLM\...\{C9552825-7BF2-4344-BA91-D3CD46F4C442}) (Version: 1.66.712.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.66.712.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{b6e20498-6533-4bb9-8102-77ace49ffe78}) (Version: 1.66.712.0 - Intel Corporation) Hidden
Intel® Software Installer (HKLM-x32\...\{d7ef8d9d-bcfe-4b24-9d00-dcd597e0fae2}) (Version: 22.130.0.5 - Intel Corporation) Hidden
Malwarebytes version 5.4.1.215 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.4.1.215 - Malwarebytes)
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.13058.0 - Waves Audio Ltd.) Hidden
Microsoft .NET Host - 6.0.28 (x64) (HKLM\...\{CA84969C-64F9-4606-A998-E692A5DA9B9F}) (Version: 48.112.10439 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.11 (x64) (HKLM\...\{362B4D0D-8438-44DA-86B2-FEC44E000FCA}) (Version: 64.44.23191 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.20 (x64) (HKLM\...\{76FA02FF-603F-48BB-9E3F-17ED5DB861E8}) (Version: 48.83.63169 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.28 (x64) (HKLM\...\{7C4254A1-17EE-4840-B9D3-7CA9B34C75CD}) (Version: 48.112.10439 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.11 (x64) (HKLM\...\{F59C11F0-D73F-452B-8D1D-8C33B82D8507}) (Version: 64.44.23191 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.20 (x64) (HKLM\...\{6CE8AD8C-E6D5-4BF7-91C3-7F8106A5CD93}) (Version: 48.83.63169 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.20 (x64) (HKLM-x32\...\{403b0cfe-5969-462d-8eb2-aafde344360e}) (Version: 6.0.20.32620 - Microsoft Corporation)
Microsoft .NET Runtime - 6.0.28 (x64) (HKLM\...\{4BCC5DFD-5D10-4ACC-AAA9-8A1578A9F0C6}) (Version: 48.112.10439 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.11 (x64) (HKLM\...\{9C80213E-9079-4561-8D57-1FDD0D62251F}) (Version: 64.44.23191 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.71 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 141.0.3537.71 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2021 - cs-cz (HKLM\...\ProPlus2021Retail - cs-cz) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 25.179.0914.0003 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-517974313-2919254220-300314987-1002\...\Teams) (Version: 1.5.00.30767 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-517974313-2919254220-300314987-1003\...\Teams) (Version: 1.8.00.17054 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{80BA3AFA-05DE-4771-AF68-A762E19E49DA}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{31D92EF6-075E-4BC8-8C0C-9265FD3EC624}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.28 (x64) (HKLM\...\{443A7BE8-E5BE-4514-BDAB-0A872E3E846B}) (Version: 48.112.10435 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.28 (x64) (HKLM-x32\...\{bd3c5800-9256-43b9-97a7-eb349fc38d78}) (Version: 6.0.28.33420 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.11 (x64) (HKLM\...\{C0790AA0-0F40-4836-85B2-677B87625E63}) (Version: 64.44.23253 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.11 (x64) (HKLM-x32\...\{bd40e761-3e88-4202-9b53-26c6bed3d467}) (Version: 8.0.11.34221 - Microsoft Corporation)
OBJ Converter for Autodesk Fusion 360 (HKLM\...\{D8D302CD-96E7-3BBA-CEFD-0697AC6492C9}) (Version: 22.5.0.0 - Visionworkplace Software Solutions)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.19231.20072 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.19029.20208 - Microsoft Corporation) Hidden
OpenVPN 2.2.1 (HKLM-x32\...\OpenVPN) (Version: 2.2.1 - )
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9107.1 - Realtek Semiconductor Corp.)
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.5.0.30767 - Microsoft Corporation)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.57.5 - TeamViewer)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.19 - VideoLAN)
webOS Dev Manager (HKLM\...\{9CC6E2C9-67C7-4280-9B64-9B40731BE1A1}) (Version: 1.99.5 - webosbrew)
Win32DiskImager version 1.0.0 (HKLM-x32\...\{3DFFA293-DF2C-4B23-92E5-3433BDC310E1}}_is1) (Version: 1.0.0 - ImageWriter Developers)

Packages:
=========
Dell SupportAssist -> C:\Program Files\WindowsApps\Dell.SupportAssistforPCs_4.10.3.0_x64__18ctm2993j0dg [2025-10-11] (Dell Inc)
iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_15.4.210.0_x64__nzyj5cx40ttqa [2025-09-30] (Apple Inc.) [Startup Task]
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa [2025-09-26] (Apple Inc.) [Startup Task]
Local Artificial Intelligence Manager -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2025-10-09] ()
Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2025-10-09] ()
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2025-10-09] ()
Ovládací centrum grafiky Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-09-07] (INTEL CORP) [Startup Task]
Spotify – hudba a podcasty -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0 [2025-10-12] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-517974313-2919254220-300314987-1002_Classes\CLSID\{04271989-C4D2-9E57-913D-CF2C3480690E} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
CustomCLSID: HKU\S-1-5-21-517974313-2919254220-300314987-1002_Classes\CLSID\{3A6222E0-60A3-42D1-9A7E-D33996911F06} -> [iCloud Drive] => C:\Users\Aleš\iCloudDrive [2023-10-17 15:38]
CustomCLSID: HKU\S-1-5-21-517974313-2919254220-300314987-1002_Classes\CLSID\{41DC107C-CA19-4920-B1D1-F96D4E0EA782} -> [Fotky na iCloudu] => C:\Users\Aleš\Pictures\iCloud Photos\Photos [2024-02-01 21:40]
CustomCLSID: HKU\S-1-5-21-517974313-2919254220-300314987-1002_Classes\CLSID\{C4F0910E-E0B4-4E68-8086-452730C7A26A}\InprocServer32 -> C:\Users\Aleš\AppData\Local\Autodesk\webdeploy\production\ca305acf3852cfce8e837ee5435adf649bc398ca\NPreview10.dll (Autodesk, Inc. -> )
CustomCLSID: HKU\S-1-5-21-517974313-2919254220-300314987-1003_Classes\CLSID\{04271989-C4D2-4190-AD8F-8C44DE7377BA} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
CustomCLSID: HKU\S-1-5-21-517974313-2919254220-300314987-1003_Classes\CLSID\{a9872fee-5a55-4ecb-9b0f-b06fedcf14d1}\localserver32 -> C:\Program Files\Waves\MaxxAudio\MaxxAudioPro.exe (Waves Inc -> Waves Audio Ltd)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-12] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncShell64.dll [2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-12] (Malwarebytes Inc -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Aleš\Downloads\Bambu_Studio_win-v02.00.02.57.exe:MBAM.Zone.Identifier [145]
AlternateDataStreams: C:\Users\Aleš\Downloads\MediaTester.exe:MBAM.Zone.Identifier [621]
AlternateDataStreams: C:\Users\Aleš\Downloads\rufus-4.7p.exe:MBAM.Zone.Identifier [595]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-10-05] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2019-12-07 11:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

2023-10-27 11:47 - 2025-10-04 18:43 - 000000445 _____ C:\Windows\system32\drivers\etc\hosts.ics

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.1.1
Windows Firewall is enabled.

Network Binding:
=============
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Ethernet: Intel(R) Ethernet Connection (4) I219-LM -> e1d.sys
Ethernet 2: TAP-Win32 Adapter V9 -> tap0901.sys
Wi-Fi: Intel(R) Dual Band Wireless-AC 8265 -> Netwtw06.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-517974313-2919254220-300314987-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Aleš\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\949073915356318045\134047538273054347.jpg
HKU\S-1-5-21-517974313-2919254220-300314987-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Katka\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\8045263259821902092\133706278514530622.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{60734307-E6DE-4326-9C62-E10054C589E0}C:\program files\bambu studio\bambu-studio.exe] => (Allow) C:\program files\bambu studio\bambu-studio.exe (Shenzhen Tuozhu Technology Co., Ltd. -> Bambu Research)
FirewallRules: [UDP Query User{AA6BE182-69DE-4DD5-BE85-20C379EED2A9}C:\program files\bambu studio\bambu-studio.exe] => (Allow) C:\program files\bambu studio\bambu-studio.exe (Shenzhen Tuozhu Technology Co., Ltd. -> Bambu Research)
FirewallRules: [{FA9A2EC5-0FA1-4166-901B-2F8F9658FA81}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{DDD4F285-78ED-4DCA-A18A-FD22C1ED60E1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B086BA17-7FA3-4E39-97A9-7BB2433B40B8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F6869DA4-7FBD-4979-A279-BB73C40F0C98}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{77EAA140-DDF2-4FCE-ABE4-A5E4C1236A53}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{C9658434-F975-4A9D-9183-043886F225FF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2B8116E2-843C-4146-894C-08D2BB91A059}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{791CED52-8286-4DC9-954B-4E2932C86B78}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{35C9A821-9BE9-454C-9E2D-0CAABA81F363}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{51D88321-EA23-4204-815E-B4F465EA77D9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.244.405.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{E65D5D96-765C-476F-8B6F-CE32C47F3140}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{93E6555C-3151-46EF-B70A-59C80CF21C58}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{23C9CC1A-4E7F-46E1-8B29-3520A51B374E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{D0EAF1E3-31D5-4B67-BFBD-4FD9C293AFE0}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{2A59EFB4-9240-46D0-8CF0-99FDDFDA8841}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe => No File
FirewallRules: [UDP Query User{C50620AB-61A4-4F3F-9519-AB9A1B87A35F}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe => No File
FirewallRules: [{78B41B2B-EA79-42D2-AD26-86049AE0F39B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{CA7841D4-D103-4DEC-9F76-585DA3865DE3}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{51914E4B-53CC-4114-A5AE-0BF8CEC38C8E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{76B03375-2F31-4633-A8EE-0BBD5BB9DFFB}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{5AA1AE64-B696-4D41-A855-0E82CFCF44E7}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{39D65F4D-A491-4FBB-AA1D-470C15A739CF}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{AF6DF204-063C-4E0A-AAEA-BC9724A76435}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{84F0A772-8195-485C-BA89-A47E853AE543}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{72AAA360-F77A-4707-95F1-E5AB9C8162C4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0D81241B-3C8B-4F8B-9FB8-F0ECA2FFBD5E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{41863C96-0C75-48F0-BF8E-2D18370A5672}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{031F5DEF-C038-4AEE-9D02-B598A9C8B98E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6B726BC9-042A-4C94-91D9-8B513970B5B3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1B243194-7A46-4F87-AA65-89E218E6299A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{033F8FF8-161A-4067-A6E6-EF442B5EC2A9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{7F6728C7-9EBC-49E9-940E-253ECDA74FFA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{12BF9BEB-9FD3-4AEC-9298-B4618FE4DD30}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{357B7691-49F8-41D3-9A3B-20EC803D0D1B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D10520EA-34E1-41CD-B4A1-48974357F9C1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{41535120-797C-4A9B-9BBE-0143B21717E1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{ECD428D6-59BD-419A-B4D8-DE0965C893B4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{C3FE7832-3A7D-4B8B-9E7B-AC7E94E98490}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{025E635E-F3B6-404C-86D1-55F6E5B064EC}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{EF67B8F9-8CD0-4892-A9BA-567AFA76233F}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{7B17E29F-A4D9-43C9-997C-D025D13E0B9E}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)

==================== Restore Points =========================

10-10-2025 18:35:07 Dell SupportAssist OS Recovery Plugin for Dell Update
12-10-2025 17:08:41 AdwCleaner_BeforeCleaning_12/10/2025_17:08:41

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (10/12/2025 05:09:07 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..

Error: (10/12/2025 05:09:07 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]

Error: (10/12/2025 05:09:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Dell.TechHub.Diagnostics.SubAgent.exe, verze: 1.9.1.303, časové razítko: 0x684a0000
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000000000
ID chybujícího procesu: 0x4928
Čas spuštění chybující aplikace: 0x01dc39ff9f02ef00
Cesta k chybující aplikaci: C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe
Cesta k chybujícímu modulu: unknown
ID zprávy: ee90de8f-e84c-4513-8fc5-5fe901d6caca
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (10/12/2025 05:09:02 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: Dell.TechHub.Diagnostics.SubAgent.exe
CoreCLR Version: 8.0.1124.51707
.NET Version: 8.0.11
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 0000000000000000

Error: (10/05/2025 03:17:23 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: U-VGHH32PTEV5SF)
Description: Aplikaci nebo službu MMGA Server nelze ukončit.

Error: (10/04/2025 09:49:45 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..

Error: (10/04/2025 09:49:45 AM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]

Error: (10/01/2025 06:48:10 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: U-VGHH32PTEV5SF)
Description: Aplikaci nebo službu MMGA Server nelze ukončit.


System errors:
=============
Error: (10/12/2025 05:14:49 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (10/12/2025 05:14:49 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Zabezpečené spouštění není v tomto počítači zapnuto.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (10/12/2025 05:12:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/12/2025 05:12:02 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (10/12/2025 05:08:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Dell TechHub byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (10/12/2025 05:08:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Microsoft Office Click-to-Run Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.

Error: (10/12/2025 05:08:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Graphics Command Center Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/12/2025 05:08:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Waves Audio Services byla neočekávaně ukončena. Tento stav nastal již 1krát.


Windows Defender:
================
Date: 2025-10-12 15:35:39
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{E582B67C-7867-4BB8-B602-58D174508A02}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вŠĉђэδџŀêđ śĉąŋ щªѕ ŝќïрρęđ ъęćâџŝĕ ţħĕ ℓάšť ѕµ¢¢ëšśƒùļ ѕсǻπ ẃāš ẅīтђĭń τћз ļàśť 7 δαýŝ

Date: 2025-10-09 08:40:02
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{C21EFAEC-0DE6-42B6-A6F6-515FAD6E07E0}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ

Date: 2025-10-09 08:35:01
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{5BF62F2E-B09A-4854-8C50-CF1ED2E735C3}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ

Date: 2025-10-04 09:15:06
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{47801122-FFE5-4B2A-B8A3-7173352772EC}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ

Date: 2025-09-30 20:16:17
Description:
Antivirová ochrana v programu Microsoft Defender šĉàŋ ђåŝ ъėëп şţǿрρєđ ъεƒõŕė ςόмφℓеŧιοл.%ñ %ŧЅċǻⁿ ĨĎ:%ъ{365A69E7-B0B0-4184-8A67-EB26BF385EB7}%и %ţŠ¢åή Ŧγρэ:%ьAntimalwarový program%ñ %τŜčдⁿ Рâŕǻмет℮гş:%ъRychlé prohledávání%л %тŮŝέя:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞťορ Ŗèǻśõп:%вЯΡĊ ¢óņпęçτϊõп гůńđоẁπ
Event[0]:

Date: 2025-04-25 23:56:20
Description:
Microsoft Defender Antivirus narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 1.427.456.0
Předchozí verze bezpečnostních informací: 1.427.220.0
Zdroj aktualizace: User
Typ bezpečnostních informací: AntiSpyware
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.25030.1
Předchozí verze modulu: 1.1.25030.1
Kód chyby: 0x80501102
Popis chyby: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.

Date: 2025-04-25 23:56:20
Description:
Microsoft Defender Antivirus narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 1.427.456.0
Předchozí verze bezpečnostních informací: 1.427.220.0
Zdroj aktualizace: User
Typ bezpečnostních informací: AntiVirus
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.25030.1
Předchozí verze modulu: 1.1.25030.1
Kód chyby: 0x80501102
Popis chyby: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.

Date: 2024-05-16 16:41:59
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.411.26.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24040.1
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

Date: 2024-05-16 16:41:59
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.411.26.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24040.1
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

Date: 2024-05-16 16:41:59
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.411.26.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24040.1
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

CodeIntegrity:
===============
Date: 2025-10-12 16:48:08
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Avast Software\Avast\AvastSvc.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2025-04-27 13:33:13
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.

Date: 2025-04-26 21:19:42
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: Dell Inc. 1.33.0 07/06/2023
Motherboard: Dell Inc. 09386V
Processor: Intel(R) Core(TM) i5-8350U CPU @ 1.70GHz
Percentage of memory in use: 42%
Total physical RAM: 16262.14 MB
Available physical RAM: 9411.32 MB
Total Virtual: 20102.14 MB
Available Virtual: 13490.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:237.85 GB) (Free:51.62 GB) (Model: KXG60ZNV256G NVMe TOSHIBA 256GB) NTFS

\\?\Volume{7be7d491-79eb-4f67-a78f-b59381ce6e50}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{14a26543-2b0c-46b3-b991-bfcb6a2f9f64}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: F1D6E1F7)

Partition: GPT.

==================== End of Addition.txt =======================

shotik
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 10 kvě 2005 18:28

Re: Vyskakujici trojsky kun ?? Prosím o kontrolu

#2 Příspěvek od shotik »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-10-2025
Ran by Aleš (administrator) on U-VGHH32PTEV5SF (Dell Inc. Latitude 7390) (12-10-2025 17:15:45)
Running from C:\Users\Katka\Downloads\FRST64.exe
Loaded Profiles: Aleš & Katka
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApntEx.exe
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.UserProcess.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> ) C:\Program Files (x86)\Dell\UpdateService\DCF\Dell.Update.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> ) C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TechHub\Dell.CoreServices.Client.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\AnalyticsSubAgent\Dell.TechHub.Analytics.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\DataManagerSubAgent\Dell.TechHub.DataManager.SubAgent.exe
(C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApMsgFwd.exe
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\hidfind.exe
(DellTPad\Apoint.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\ApRemote.exe
(DellTPad\HidMonitorSvc.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\Apoint.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_0bd497310795eeb4\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0bd497310795eeb4\igfxEM.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <11>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(services.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\HidMonitorSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Dell Technologies Inc. -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(services.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TechHub\Dell.TechHub.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0bd497310795eeb4\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_4d06d7f3655985a2\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_30c72947a1f2fc36\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_30c72947a1f2fc36\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_6c1db4160fc7f113\Intel_PIE_Service.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ) C:\Windows\System32\UshUpgradeService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation) C:\Windows\System32\HostControlService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation) C:\Windows\System32\HostStorageService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102816 2021-01-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3618096 2021-01-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => c:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1236688 2020-12-04] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [845992 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" [92395880 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-517974313-2919254220-300314987-1002\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4728168 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-517974313-2919254220-300314987-1002\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe --launch-background-mode (No File)
HKU\S-1-5-21-517974313-2919254220-300314987-1002\...\MountPoints2: {549ec44d-801c-11ef-9a38-f4d108c3f95a} - "D:\LaunchU3.exe" -a
HKU\S-1-5-21-517974313-2919254220-300314987-1003\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4728168 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-517974313-2919254220-300314987-1003\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Katka\AppData\Local\Microsoft\Teams\Update.exe [2583584 2025-07-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-517974313-2919254220-300314987-1003\...\Run: [MicrosoftEdgeAutoLaunch_2A7C7472A3D5FB7F5B75531017E53B20] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4265000 2025-10-09] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\141.0.7390.66\Installer\chrmstp.exe [2025-10-11] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{E5931AF4-2A8F-48A5-AFC8-CE9B79C4B19D}] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {D6D54E88-8C64-4A3E-AB6E-6880A616F804} - System32\Tasks\AdwCleaner_onReboot => C:\Users\Katka\Downloads\adwcleaner.exe [9616736 2025-10-12] (Malwarebytes Inc -> Malwarebytes)
Task: {1ABA1BDA-01EF-4D79-BAA1-281273B2193A} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [9072352 2025-09-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {15C83B27-CA0A-47E6-BB5B-283664D824B9} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5573800 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {0EDBCC07-5723-4A31-8634-7736EAAFCA47} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2977504 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {A741E433-DECB-43B0-B67B-8396BD55A13B} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [1260184 2025-09-12] (Dell Technologies Inc. -> Dell Inc.) -> C:\Program Files\Dell\SupportAssistAgent\bin\AutoUpdate
Task: {55964664-D700-4886-8D39-DF29FCB8400F} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem142.0.7416.0{A247F6D7-1308-4FDA-8B84-1B649648912D} => C:\Program Files (x86)\Google\GoogleUpdater\142.0.7416.0\updater.exe [6863512 2025-09-15] (Google LLC -> Google LLC)
Task: {FDCA9025-9C06-4EB2-9705-1B6B293571B4} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [16954752 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {4A817B92-FFBC-4372-992D-21FC36D79C08} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29038432 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {3E005989-AD00-45C6-9884-C4DEB6FA3045} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\opushutil.exe [70464 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {55339CA9-9313-4771-B859-FB40A26AA804} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29038432 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {41567E3E-7A47-4E96-B4FE-54C1134E608E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [318720 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {0F6747C3-A3D8-4425-9E73-D6A54BF38636} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [318720 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {0A1A6926-7518-4417-AE7D-52FA055BFCE9} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [1365304 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {15355D8D-9ADA-4437-AAC6-46355A22B33E} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4232552 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {7EA9BFF9-6BA6-4314-A501-E6D2C41B8947} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-517974313-2919254220-300314987-1000 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {C82878CD-6612-456C-93D1-603EC5146D9D} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-517974313-2919254220-300314987-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4232552 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {13680798-E2DE-460E-AB32-D91D8F46B1C3} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-517974313-2919254220-300314987-1003 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4232552 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {5EE7B2DD-E80B-40E3-8370-9C6E8314FE48} - System32\Tasks\OneDrive Startup Task-S-1-5-21-517974313-2919254220-300314987-1002 => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\OneDriveLauncher.exe [725864 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {2493038F-68C3-407B-B960-E90B8274F82A} - System32\Tasks\OneDrive Startup Task-S-1-5-21-517974313-2919254220-300314987-1003 => C:\Program Files\Microsoft OneDrive\25.179.0914.0003\OneDriveLauncher.exe [725864 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {3CC9C745-8834-4AD4-ADF5-C9164B96DF69} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-517974313-2919254220-300314987-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {A386214E-5D5C-44B6-B5E8-AC850FAB5D6A} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-517974313-2919254220-300314987-1003 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {A165120B-DA2D-455C-83D5-88417869C6F8} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6243960 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {B95D999D-34B4-4291-AEF2-694E524AD98A} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [8971064 2025-10-02] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3cbd9a67-72a2-4b6a-9302-1d7cdd6254c3}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3cbd9a67-72a2-4b6a-9302-1d7cdd6254c3}: [DhcpDomain] home
Tcpip\..\Interfaces\{3cbd9a67-72a2-4b6a-9302-1d7cdd6254c3}\0584: [DhcpNameServer] 192.168.200.2 192.168.200.201
Tcpip\..\Interfaces\{3cbd9a67-72a2-4b6a-9302-1d7cdd6254c3}\0584: [DhcpDomain] ph.vtdata.cz
Tcpip\..\Interfaces\{3cbd9a67-72a2-4b6a-9302-1d7cdd6254c3}\759464940214D4: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3cbd9a67-72a2-4b6a-9302-1d7cdd6254c3}\759464940214D4: [DhcpDomain] home
Tcpip\..\Interfaces\{3cbd9a67-72a2-4b6a-9302-1d7cdd6254c3}\D42716A7B6F6679602537486A7: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{4ccd00a6-8980-4c71-82fc-d0d2e694dbc8}: [DhcpNameServer] 192.168.0.36
Tcpip\..\Interfaces\{4ccd00a6-8980-4c71-82fc-d0d2e694dbc8}: [DhcpDomain] office.e-fractal.cz
Tcpip\..\Interfaces\{719da59f-9cc8-4e62-8f4e-6b8d880344b5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{719da59f-9cc8-4e62-8f4e-6b8d880344b5}: [DhcpDomain] home

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Aleš\AppData\Local\Microsoft\Edge\User Data\Default [2025-07-17]
Edge Extension: (Dokumenty Google offline) - C:\Users\Aleš\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-07-17]
Edge Extension: (Edge relevant text changes) - C:\Users\Aleš\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-01]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-09-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-09-10] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default [2025-10-12]
CHR Notifications: Default -> hxxps://mophiciderst.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR Session Restore: Default -> is enabled.
CHR Extension: (Převodník měn) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnpalipgomknhgbmgelaplknnmckljaf [2024-12-28]
CHR Extension: (Nimble capture) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2024-10-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-09-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-17]
CHR Extension: (Hesla na iCloudu) - C:\Users\Aleš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pejdijmoenmkgeppbflobdenhhabjlaj [2025-09-03]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ApHidMonitorService; C:\Windows\system32\DellTPad\HidMonitorSvc.exe [894880 2021-05-24] (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7785640 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [1036456 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2598568 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1089704 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2025-10-12] (Avast Software s.r.o. -> AVAST Software)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [28280440 2025-10-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13343584 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [49952 2025-09-10] (Dell Technologies Inc. -> )
R2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [153288 2025-07-03] (Dell Technologies Inc. -> Dell)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.179.0914.0003\FileSyncHelper.exe [3627896 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
R2 hostcontrolsvc; C:\Windows\System32\HostControlService.exe [815616 2019-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation)
R2 hoststoragesvc; C:\Windows\System32\HostStorageService.exe [161280 2019-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9608720 2025-10-12] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-10-12] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe [2009656 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.179.0914.0003\OneDriveUpdaterService.exe [3912056 2025-10-12] (Microsoft Corporation -> Microsoft Corporation)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [14848 2011-07-01] () [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-08-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [162456 2025-09-12] (Dell Technologies Inc. -> Dell Inc.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [22442808 2024-09-03] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 ushupgradesvc; C:\Windows\System32\UshUpgradeService.exe [265728 2019-12-20] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\NisSrv.exe [4414464 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe [282480 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ApHidfiltrService; C:\Windows\System32\drivers\ApHidfiltrSW.sys [362512 2021-05-24] (WDKTestCert CHT1HTSH3180,132475688214743128 -> ALPSALPINE Co., Ltd.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [21088 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [244832 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [390752 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [299616 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [85600 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\Windows\System32\drivers\aswElam.sys [29144 2025-10-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [29792 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [284768 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [574048 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [92232 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [71240 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [876104 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [1282632 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\Windows\System32\drivers\aswStm.sys [201824 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [391776 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 bcmnfcusb; C:\Windows\System32\drivers\bcmnfcusb.sys [50016 2019-12-20] (Broadcom Corporation -> Broadcom Corporation.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R3 DellInstrumentation; C:\Windows\System32\drivers\DellInstrumentation.sys [35896 2025-02-13] (Microsoft Windows Hardware Compatibility Publisher -> Dell)
R3 e1dexpress; C:\Windows\System32\DriverStore\FileRepository\e1d.inf_amd64_9b9691c91d28fd9b\e1d.sys [625296 2025-05-09] (Intel Corporation -> Intel Corporation)
S3 GuiHidUsbDevLowerFFB; C:\Windows\system32\DRIVERS\GuiHidUsbDevLowerFFB.sys [196776 2023-09-15] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2020. All rights reserved.)
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [333216 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [234072 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2025-10-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [244800 2025-10-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 tap0901; C:\Windows\System32\drivers\tap0901.sys [31232 2011-07-01] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tmResetMin; C:\Windows\System32\Drivers\tmResetMin.sys [51368 2023-09-15] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2022. All rights reserved.)
S3 tmwbulk; C:\Windows\System32\Drivers\tmwbulk.sys [383008 2022-09-08] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2022. All rights reserved.)
R3 wbfcvusbdrv; C:\Windows\System32\Drivers\wbfcvusbdrv.sys [20320 2019-12-20] (Broadcom Corporation -> Broadcom Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [20880 2025-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [627104 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [102816 2025-09-18] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-10-12 17:15 - 2025-10-12 17:16 - 000030779 _____ C:\Users\Katka\Downloads\FRST.txt
2025-10-12 17:14 - 2025-10-12 17:16 - 000000000 ____D C:\FRST
2025-10-12 17:14 - 2025-10-12 17:14 - 002442752 _____ (Farbar) C:\Users\Katka\Downloads\FRST64.exe
2025-10-12 17:12 - 2025-10-12 17:12 - 000003944 _____ C:\Windows\system32\Tasks\Dell SupportAssistAgent AutoUpdate
2025-10-12 17:10 - 2025-10-12 17:10 - 000000000 ____D C:\Users\Katka\AppData\Roaming\CCleaner
2025-10-12 17:08 - 2025-10-12 17:08 - 000003162 _____ C:\Windows\system32\Tasks\AdwCleaner_onReboot
2025-10-12 17:07 - 2025-10-12 17:07 - 000000000 ____D C:\Users\Aleš\AppData\Local\Malwarebytes
2025-10-12 17:06 - 2025-10-12 17:08 - 000000000 ____D C:\AdwCleaner
2025-10-12 17:06 - 2025-10-12 17:06 - 009616736 _____ (Malwarebytes) C:\Users\Katka\Downloads\adwcleaner.exe
2025-10-12 17:02 - 2025-10-12 17:02 - 000000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\MMC
2025-10-12 16:54 - 2025-10-12 16:54 - 000000000 ____D C:\Users\Katka\AppData\Local\Malwarebytes
2025-10-12 16:53 - 2025-10-12 16:53 - 002844576 _____ (Malwarebytes) C:\Users\Katka\Downloads\MBSetup.exe
2025-10-12 16:53 - 2025-10-12 16:53 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2025-10-12 16:53 - 2025-10-12 16:53 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2025-10-12 16:53 - 2025-10-12 16:53 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-10-12 16:53 - 2025-10-12 16:53 - 000000000 ____D C:\Program Files\Malwarebytes
2025-10-12 16:49 - 2025-10-12 16:49 - 000000000 ____D C:\Users\Aleš\AppData\Local\Avast Software
2025-10-12 16:48 - 2025-10-12 16:48 - 000002202 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2025-10-12 16:48 - 2025-10-12 16:48 - 000002190 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2025-10-12 16:48 - 2025-10-12 16:48 - 000000000 ____D C:\Users\Aleš\AppData\Roaming\Avast Software
2025-10-12 16:47 - 2025-10-12 17:10 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2025-10-12 16:47 - 2025-10-12 16:47 - 000322216 _____ (Gen Digital Inc.) C:\Windows\system32\aswBoot.exe
2025-10-12 16:47 - 2025-10-12 16:47 - 000249080 _____ (Gen Digital Inc.) C:\Users\Aleš\Downloads\online_instalační_soubor_aplikace_avast_free_antivirus.exe
2025-10-12 16:47 - 2025-10-12 16:47 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-10-12 16:47 - 2025-10-12 16:47 - 000000000 ____D C:\Program Files\Avast Software
2025-10-12 16:43 - 2025-10-12 16:43 - 000002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 7.lnk
2025-10-12 16:43 - 2025-10-12 16:43 - 000002140 _____ C:\Users\Public\Desktop\CCleaner 7.lnk
2025-10-12 16:43 - 2025-10-12 16:43 - 000000000 ____D C:\Windows\system32\Tasks\Piriform
2025-10-12 16:43 - 2025-10-12 16:43 - 000000000 ____D C:\Users\Aleš\AppData\Roaming\CCleaner
2025-10-12 16:42 - 2025-10-12 16:47 - 000056128 _____ (Gen Digital Inc.) C:\Windows\system32\icarus_rvrt.exe
2025-10-12 16:42 - 2025-10-12 16:42 - 000000000 ____D C:\Program Files\Piriform
2025-10-12 16:42 - 2025-10-12 16:42 - 000000000 ____D C:\Program Files\Common Files\Piriform
2025-10-10 19:12 - 2025-10-10 19:12 - 000330084 _____ C:\Users\Aleš\Downloads\NBC+-+Rotopax+cap.stl
2025-10-10 18:02 - 2025-10-10 18:02 - 000276184 _____ C:\Users\Aleš\Downloads\NBC.3+-+Rotopax+holder+v2.stl
2025-10-10 18:01 - 2025-10-10 18:01 - 000736684 _____ C:\Users\Aleš\Downloads\NBC+-+Rotopax+holder+nut.stl
2025-10-10 18:01 - 2025-10-10 18:01 - 000073684 _____ C:\Users\Aleš\Downloads\NBC+-+Rotopax+cap+tip.stl
2025-10-10 18:00 - 2025-10-10 18:00 - 001280184 _____ C:\Users\Aleš\Downloads\NBC+-+Rotopax_1_75g.stl
2025-10-10 17:58 - 2025-10-10 17:58 - 001154484 _____ C:\Users\Aleš\Downloads\NBC+-+Rotopax_2g.stl
2025-10-05 18:30 - 2025-10-05 18:30 - 000033284 _____ C:\Users\Aleš\Downloads\front stand.stl
2025-10-05 18:28 - 2025-10-05 18:28 - 000033284 _____ C:\Users\Aleš\Downloads\Rear stand (1).stl
2025-10-05 15:19 - 2025-10-05 15:19 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-10-05 15:05 - 2025-10-05 15:05 - 000026684 _____ C:\Users\Aleš\Downloads\stands-no brx (1).stl
2025-10-02 19:12 - 2025-10-02 19:12 - 000093984 _____ C:\Users\Aleš\Downloads\Sand_paddle_mounting_clips.stl
2025-10-02 19:06 - 2025-10-02 19:06 - 001100884 _____ C:\Users\Aleš\Downloads\V2_Sand_paddle_Defender.stl
2025-09-30 19:08 - 2025-09-30 19:08 - 000026684 _____ C:\Users\Aleš\Downloads\stands-no brx.stl
2025-09-30 19:07 - 2025-09-30 19:07 - 000033284 _____ C:\Users\Aleš\Downloads\Rear stand.stl
2025-09-30 19:06 - 2025-09-30 19:06 - 000201295 _____ C:\Users\Aleš\Downloads\brx02 esc. kudu lighttray.stl
2025-09-30 19:06 - 2025-09-30 19:06 - 000005284 _____ C:\Users\Aleš\Downloads\easy-stand-leg.stl
2025-09-30 18:56 - 2025-09-30 18:56 - 000000000 ____D C:\Users\Aleš\AppData\Local\BambuStudio
2025-09-30 18:55 - 2025-09-30 18:55 - 000001783 _____ C:\Users\Public\Desktop\Bambu Studio.lnk
2025-09-30 18:55 - 2025-09-30 18:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bambu Studio
2025-09-30 18:54 - 2025-09-30 18:55 - 000000000 ____D C:\Program Files\Bambu Studio
2025-09-30 18:26 - 2025-09-30 18:26 - 000034444 _____ C:\Users\Aleš\Downloads\BULK HEAD FILL PLATE 1.stl
2025-09-30 06:57 - 2025-09-30 06:58 - 261769216 _____ C:\Users\Aleš\Downloads\Bambu_Studio_win-v02.02.02.56.exe
2025-09-28 16:59 - 2025-09-28 16:59 - 004354584 _____ C:\Users\Aleš\Downloads\Headlight lens 3.0.stl
2025-09-27 10:57 - 2025-09-27 10:57 - 000029043 _____ C:\Users\Aleš\Downloads\DEF okno storage.3mf
2025-09-27 10:55 - 2025-09-27 10:55 - 000060084 _____ C:\Users\Aleš\Downloads\Headlight ring D110.stl
2025-09-20 14:59 - 2025-09-20 14:59 - 001722284 _____ C:\Users\Aleš\Downloads\nbc-rotopax-rx-2d.stl
2025-09-20 09:58 - 2025-09-20 15:07 - 000021484 _____ C:\Users\Aleš\Downloads\DEF okno storage.stl
2025-09-20 09:37 - 2025-09-20 09:37 - 000180591 _____ C:\Users\Aleš\Downloads\10th+Scale+RotoPax_stls.zip
2025-09-20 09:37 - 2025-09-20 09:37 - 000000000 ____D C:\Users\Aleš\Downloads\kanistr
2025-09-19 16:59 - 2025-09-19 16:59 - 000960784 _____ C:\Users\Aleš\Downloads\brx02 engine bay v7.stl

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-10-12 17:12 - 2023-05-05 14:28 - 000000000 ____D C:\Windows\SystemTemp
2025-10-12 17:10 - 2025-02-06 19:18 - 000003540 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-517974313-2919254220-300314987-1003
2025-10-12 17:10 - 2025-02-06 19:18 - 000003540 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-517974313-2919254220-300314987-1002
2025-10-12 17:10 - 2025-01-17 08:49 - 000002132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-10-12 17:10 - 2024-02-21 19:54 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-10-12 17:10 - 2024-02-21 19:52 - 000000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\Teams
2025-10-12 17:10 - 2024-02-19 22:11 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-10-12 17:10 - 2023-10-17 21:24 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-517974313-2919254220-300314987-1003
2025-10-12 17:10 - 2023-10-17 21:23 - 000000000 __SHD C:\Users\Katka\IntelGraphicsProfiles
2025-10-12 17:10 - 2023-10-17 14:42 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-517974313-2919254220-300314987-1002
2025-10-12 17:10 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2025-10-12 17:09 - 2023-10-27 07:35 - 000000000 ____D C:\Program Files\TeamViewer
2025-10-12 17:09 - 2023-10-17 14:49 - 000000000 ____D C:\ProgramData\Avast Software
2025-10-12 17:09 - 2023-10-17 12:59 - 000000000 ____D C:\Intel
2025-10-12 17:09 - 2023-10-17 12:55 - 000165023 _____ C:\Windows\system32\CVFirmwareUpgradeLog.txt
2025-10-12 17:09 - 2023-10-17 12:33 - 000008192 ___SH C:\DumpStack.log.tmp
2025-10-12 17:09 - 2023-10-17 12:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-10-12 17:09 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2025-10-12 17:09 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-12 17:09 - 2019-12-07 11:03 - 001835008 _____ C:\Windows\system32\config\BBI
2025-10-12 17:08 - 2023-10-28 09:35 - 000000000 ____D C:\Users\Aleš\Documents\Dell
2025-10-12 17:08 - 2023-10-19 18:32 - 000000000 ____D C:\ProgramData\Dell
2025-10-12 16:53 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2025-10-12 16:53 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2025-10-12 16:42 - 2025-04-12 17:19 - 000000000 ____D C:\ProgramData\Piriform
2025-10-12 16:42 - 2025-04-12 17:18 - 000000000 ____D C:\Program Files\CCleaner
2025-10-12 16:42 - 2024-01-01 19:16 - 000000000 ____D C:\Users\Aleš\AppData\Roaming\BambuStudio
2025-10-12 16:42 - 2023-10-17 12:33 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-10-12 15:40 - 2023-10-27 07:33 - 000002376 ____H C:\Users\Katka\Documents\Default.rdp
2025-10-12 15:35 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2025-10-12 15:10 - 2019-12-07 16:45 - 000000000 ____D C:\Windows\system32\FxsTmp
2025-10-12 10:24 - 2023-10-17 12:33 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-10-11 10:01 - 2023-10-17 14:45 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-10-11 10:01 - 2023-10-17 14:45 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-10-11 10:01 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-11 10:00 - 2023-10-17 21:23 - 000000000 ____D C:\Users\Katka\AppData\Local\Packages
2025-10-10 18:35 - 2023-10-19 18:32 - 000000000 ____D C:\ProgramData\Package Cache
2025-10-10 18:35 - 2023-10-19 18:32 - 000000000 ____D C:\Program Files\Dell
2025-10-10 18:05 - 2023-10-17 14:40 - 000000000 ____D C:\Users\Aleš\AppData\Local\Packages
2025-10-10 18:05 - 2023-10-17 12:35 - 000000000 ____D C:\ProgramData\Packages
2025-10-10 18:02 - 2023-10-19 18:32 - 000000000 ____D C:\Program Files (x86)\Dell
2025-10-10 17:54 - 2023-10-17 15:38 - 000000000 ___RD C:\Users\Aleš\iCloudDrive
2025-10-05 18:39 - 2023-10-17 12:33 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-10-05 18:39 - 2023-10-17 12:33 - 000003514 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-10-05 15:17 - 2024-02-19 22:06 - 000000000 ____D C:\Program Files\Microsoft Office
2025-10-05 15:04 - 2023-10-17 14:40 - 000000000 __SHD C:\Users\Aleš\IntelGraphicsProfiles
2025-10-04 18:45 - 2023-10-17 12:39 - 001694140 _____ C:\Windows\system32\PerfStringBackup.INI
2025-10-04 18:45 - 2019-12-07 16:43 - 000719734 _____ C:\Windows\system32\perfh005.dat
2025-10-04 18:45 - 2019-12-07 16:43 - 000145860 _____ C:\Windows\system32\perfc005.dat
2025-10-04 18:43 - 2023-10-27 11:47 - 000000445 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2025-10-04 11:26 - 2023-11-14 21:49 - 000001198 _____ C:\Users\Katka\Desktop\OpenVPN GUI.lnk
2025-10-02 19:08 - 2023-10-17 14:40 - 000000000 ____D C:\Users\Aleš\AppData\Local\D3DSCache
2025-10-01 18:00 - 2023-10-17 12:33 - 000902200 _____ C:\Windows\system32\FNTCACHE.DAT
2025-09-18 17:38 - 2023-10-17 21:23 - 000000000 ____D C:\Users\Katka\AppData\Local\D3DSCache
2025-09-18 17:21 - 2023-10-17 12:33 - 000000000 ____D C:\Windows\system32\Drivers\wd

==================== Files in the root of some directories ========

2023-11-10 16:44 - 2023-11-10 16:44 - 000000218 _____ () C:\Users\Aleš\AppData\Local\recently-used.xbel

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

shotik
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 10 kvě 2005 18:28

Re: Vyskakujici trojsky kun ?? Prosím o kontrolu

#3 Příspěvek od shotik »

řeším kvůli tomuto
Bez názvu.png
Bez názvu.png (463.37 KiB) Zobrazeno 437 x

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Vyskakujici trojsky kun ?? Prosím o kontrolu

#4 Příspěvek od JaRon »

Ahoj,
prescanuj PC s NPE https://support.norton.com/sp/static/ex ... s/npe.html
To co mas zobrazene byva casto podvrh
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

shotik
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 10 kvě 2005 18:28

Re: Vyskakujici trojsky kun ?? Prosím o kontrolu

#5 Příspěvek od shotik »

NPE mělo jeden problem. Po restartu bez problemu v NPE ale okno stale vyskakuje .

edit: snad vyreseno. Nejakym zpusobem se dostala do edge povolena notifikace na pochybne stranky. Zakazano. Zatim funkcni

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Vyskakujici trojsky kun ?? Prosím o kontrolu

#6 Příspěvek od JaRon »

Presne :thumbsup: zakazat upozornenia v Edge :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět