Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2026
Ran by Lenovo (administrator) on NOŤAS (LENOVO 20251) (28-05-2026 11:25:16)
Running from C:\Users\Lenovo\Downloads\FRST64 (1).exe
Loaded Profiles: Lenovo
Platform: Microsoft Windows 10 Home Version 1903 18362.720 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe ->) (NETGEAR TAIWAN CO., LTD -> ) C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
(C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe ->) (Adobe Inc. -> Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat DC\Acrobat\acrotray.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(C:\Program Files\Elantech\ETDCtrl.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(C:\Program Files\Elantech\ETDService.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\125.0.0.0\crashpad_handler.exe
(C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe <8>
(C:\Program Files\LibreOffice\program\scalc.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.exe
(C:\Program Files\LibreOffice\program\soffice.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.bin
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Thunderbird\thunderbird.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Thunderbird\crashhelper.exe
(C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(C:\Users\Lenovo\AppData\Local\MEGAsync\MEGAsync.exe ->) (Mega Limited -> ) C:\Users\Lenovo\AppData\Local\MEGAsync\mega-desktop-app-gfxworker.exe
(C:\Users\Lenovo\AppData\Local\Programs\Messenger\Messenger.exe ->) (Facebook, Inc. -> ) C:\Users\Lenovo\AppData\Local\Programs\Messenger\CrashpadHandlerWindows.exe
(explorer.exe ->) () [File not signed] C:\Program Files (x86)\Codebox\BitMeter\BitMeter2.exe
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(explorer.exe ->) (Ashampoo GmbH & Co. KG -> ) C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 11\UI11Guard.exe
(explorer.exe ->) (Big Nerd Software, LLC -> ) C:\Users\Lenovo\AppData\Local\ScreenPal\NoSplashScreen\ScreenPal.exe <3>
(explorer.exe ->) (Facebook, Inc. -> Meta Platforms, Inc.) C:\Users\Lenovo\AppData\Local\Programs\Messenger\Messenger.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <42>
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe <2>
(explorer.exe ->) (NETGEAR TAIWAN CO., LTD -> NETGEAR Inc.) C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe
(explorer.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\scalc.exe
(explorer.exe ->) (Winstep Software Technologies) [File not signed] C:\Program Files (x86)\Winstep\Nexus-Ultimate.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Mega Limited -> Mega Limited) C:\Users\Lenovo\AppData\Local\MEGAsync\MEGAsync.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <5>
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte Ltd) C:\Program Files (x86)\2BrightSparks\SyncBackFree\SchedulesMonitor.exe
(services.exe ->) (ABBYY Development Inc. -> ABBYY Development, Inc.) C:\Program Files\Common Files\ABBYY\FineReader\16\Licensing\NetworkLicenseServer.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe
(services.exe ->) (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NZXT, Inc. -> ) C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\rust-cam\dist\native\target\release\service.exe
(svchost.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\WindowsApps\AdobeNotificationClient_6.0.0.1_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(svchost.exe ->) (Adobe Systems Incorporated -> ) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Skype Software Sarl -> ) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Ashampoo Uninstaller Guard] => C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 11\UI11Guard.exe [4184264 2022-07-05] (Ashampoo GmbH & Co. KG -> )
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [133128 2026-01-28] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2526688 2026-04-17] (Adobe Inc. -> Adobe Inc.)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe [75838616 2026-05-13] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe [75838616 2026-05-13] (Google LLC -> Google LLC.)
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [NeXuS-Ultimate] => C:\Program Files (x86)\Winstep\Nexus-Ultimate.exe [14558848 2011-10-11] (Winstep Software Technologies) [File not signed]
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe [75838616 2026-05-13] (Google LLC -> Google LLC.)
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [Thunderbird] => C:\Program Files\Mozilla Thunderbird\thunderbird.exe [480896 2026-05-24] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45227312 2024-10-15] (Gen Digital Inc. -> Piriform Software Ltd)
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [Bonus.SSR.FR16] => C:\Program Files\ABBYY FineReader 16\screenshotreader.exe [3096832 2023-07-30] (ABBYY Development, Inc. -> ABBYY Development, Inc.)
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [ScreenPal Tray] => C:\Users\Lenovo\AppData\Local\ScreenPal\NoSplashScreen\ScreenPal.exe [1878160 2024-10-16] (Big Nerd Software, LLC -> )
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [SwitchRunOnStartup] => C:\Program Files (x86)\NCH Software\Switch\switch.exe [6151680 2026-02-21] (NCH Software, Inc. -> NCH Software)
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [com.messenger] => C:\Users\Lenovo\AppData\Local\Programs\Messenger\Messenger.exe messenger://openAtLogin (No File)
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42087896 2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe [75838616 2026-05-13] (Google LLC -> Google LLC.)
HKLM\...\Windows x64\Print Processors\Canon G2010 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDEG.DLL [506368 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\HP1020PrintProc: C:\Windows\System32\spool\prtprocs\x64\pphp1020.dll [65024 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Windows x64\Print Processors\HP1120PrintProc: C:\Windows\System32\spool\prtprocs\x64\HP1120PP.DLL [65024 2012-12-07] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [203936 2026-04-12] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\Canon BJ Language Monitor G2010 series: C:\Windows\system32\CNMLMEG.DLL [1325568 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\HP LJ M1120 MFP LM: C:\Windows\system32\ZLM1120.dll [167424 2012-12-07] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
HKLM\...\Print\Monitors\HPLJ1020LM: C:\Windows\system32\zlhp1020.dll [192512 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{1AF2F041-3692-46D4-B786-0C435D73C749}] -> C:\Program Files\ABBYY FineReader 16\ScreenshotReader.exe [3096832 2023-07-30] (ABBYY Development, Inc. -> ABBYY Development, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3971224 2026-04-18] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\148.0.7778.179\Installer\chrmstp.exe [7621272 2026-05-22] (Google LLC -> Google LLC)
Startup: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2020-02-29]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Lenovo\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bitmeter2.lnk [2020-01-13]
ShortcutTarget: Bitmeter2.lnk -> C:\Program Files (x86)\Codebox\BitMeter\BitMeter2.exe () [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\netgear genie.lnk [2024-04-19]
ShortcutTarget: netgear genie.lnk -> C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe (NETGEAR TAIWAN CO., LTD -> NETGEAR Inc.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {95AC5DE9-30C1-49E7-B9A3-5B4EE5BFFA3F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {C6FCE5DA-4AEA-4D70-85D4-551DE2933CE3} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{636BF8F4-CEB1-4BD9-A839-FCFF28146FA6} => C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe [8770200 2026-04-28] (Google LLC -> Google LLC)
Task: {5F669DD2-D1E2-49CD-B7AE-EE482C9CBA73} - System32\Tasks\Launch Adobe CCXProcess => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [194112 2026-04-23] (Adobe Inc. -> Adobe Inc.)
Task: {D9AC0F1C-C24A-46B4-9CF4-2F2600CFC00A} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-760426430-1322398698-3842268529-1001 => C:\Users\Lenovo\AppData\Local\MEGAsync\MEGAupdater.exe [1768464 2026-05-24] (Mega Limited -> )
Task: {370546D7-29C1-40A6-8610-5E8CB7F38441} - System32\Tasks\Meta\Messenger-SL-Helper-S-1-5-21-760426430-1322398698-3842268529-1001 => C:\Users\Lenovo\AppData\Local\Programs\Messenger\MessengerHelper.exe [2171640 2024-03-23] (Facebook, Inc. -> Meta Platforms, Inc.)
Task: {5C4D55AE-D06D-45BC-A96C-44BDE8187243} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.6-0\MpCmdRun.exe [480272 2020-03-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5846F0E5-0884-470C-BD0B-F6BF74C3B9B8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.6-0\MpCmdRun.exe [480272 2020-03-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DE2AA4F3-D094-4B05-A85E-FE8DFD096B93} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.6-0\MpCmdRun.exe [480272 2020-03-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {23FA26BB-C039-4F85-A5B3-F0136F87928D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.6-0\MpCmdRun.exe [480272 2020-03-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {12426418-AEDE-4A73-9532-D0222D284CE5} - System32\Tasks\NCH Software\SwitchUpdateCheck => C:\Program Files (x86)\NCH Software\Switch\switch.exe [6151680 2026-02-21] (NCH Software, Inc. -> NCH Software)
Task: {E9EAA716-1B75-4968-B734-18CD5B05E683} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {BD4395F8-86CE-425B-AD64-DCACBD9F5B81} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {1B1B0A1C-9A1E-40A9-857B-2E4FAA1D7438} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-06-15] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1694ECC5-1ADD-403E-BFA8-B4CA890C416D} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {400C6EAA-B4C1-4D9F-AABA-E756695D4E52} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0D7E29A1-0063-4992-86CA-E71E7637D9B4} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {223E454A-5C6B-46F2-9064-2396DF6B3D96} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1A983045-28E6-4302-B607-5EB850694847} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3050377B-9BA6-4FC7-BCB6-BF6B27AECE0D} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BF4601C6-D83B-4923-BEED-08DAD2855F0F} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-19] => Proxy is enabled.
ProxyServer: [S-1-5-19] => 127.0.0.1:8080
ProxyEnable: [S-1-5-20] => Proxy is enabled.
ProxyServer: [S-1-5-20] => 127.0.0.1:8080
ProxyServer: [S-1-5-21-760426430-1322398698-3842268529-1001] => 127.0.0.1:8080
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 62.129.50.20 85.135.32.100
Tcpip\..\Interfaces\{23c03b2f-2a1b-40ac-97ab-a0e1451634ce}: [DhcpNameServer] 62.129.50.20 85.135.32.100
Tcpip\..\Interfaces\{23c03b2f-2a1b-40ac-97ab-a0e1451634ce}\05166756C67237027416C616879702143333025374: [DhcpNameServer] 192.168.152.6
Tcpip\..\Interfaces\{23c03b2f-2a1b-40ac-97ab-a0e1451634ce}\255646D69602E4F64756021313020527F6025374: [DhcpNameServer] 192.168.193.86
Tcpip\..\Interfaces\{23c03b2f-2a1b-40ac-97ab-a0e1451634ce}\44166796467237027416C616879702142333025374: [DhcpNameServer] 192.168.187.15
Tcpip\..\Interfaces\{23c03b2f-2a1b-40ac-97ab-a0e1451634ce}\4556E64616F5836433445403: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{23c03b2f-2a1b-40ac-97ab-a0e1451634ce}\4556E64616F5836433445403: [DhcpDomain] tendawifi.com
Tcpip\..\Interfaces\{b5f4ac6c-0ec6-49e1-92b2-0dc8b9aefa8d}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{b5f4ac6c-0ec6-49e1-92b2-0dc8b9aefa8d}: [DhcpDomain] tendawifi.com
Tcpip\..\Interfaces\{d22bb9ac-ab75-40ee-9000-0d9611b37417}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{d22bb9ac-ab75-40ee-9000-0d9611b37417}: [DhcpDomain] tendawifi.com
Tcpip\..\Interfaces\{d22bb9ac-ab75-40ee-9000-0d9611b37417}\461627D6F64656A603: [DhcpNameServer] 192.168.150.237 192.168.3.1
Tcpip\..\Interfaces\{d22bb9ac-ab75-40ee-9000-0d9611b37417}\461627D6F64656A623: [DhcpNameServer] 192.168.150.237 192.168.1.1
Tcpip\..\Interfaces\{d22bb9ac-ab75-40ee-9000-0d9611b37417}\84551475549402058302C6964756: [DhcpNameServer] 192.168.43.1
FireFox:
========
FF DefaultProfile: a7v043dk.default-release-1607556120122 -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\v8ckfixm.default [2023-05-08]
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\a7v043dk.default-release-1607556120122 [2025-12-31]
FF NewTab: Mozilla\Firefox\Profiles\a7v043dk.default-release-1607556120122 -> about:newtab
FF Extension: (SaveFrom.net helper) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\a7v043dk.default-release-1607556120122\Extensions\helper@savefrom.net.xpi [2024-05-31]
FF Extension: (To Google Translate) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\a7v043dk.default-release-1607556120122\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2021-06-22]
FF Extension: (Playmaker – Balanced) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\a7v043dk.default-release-1607556120122\Extensions\playmaker-balanced-colorway@mozilla.org.xpi [2023-05-24]
FF Extension: (Open bookmarks in new tab) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\a7v043dk.default-release-1607556120122\Extensions\{02503e58-2fea-4dc4-893b-d35e36b92437}.xpi [2024-05-13]
FF Extension: (Open Link in New Tab) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\a7v043dk.default-release-1607556120122\Extensions\{c064b4e8-a82e-415f-9d31-8516e613182e}.xpi [2024-05-13]
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2026-03-17] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-04-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-04-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.12 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2026-03-17] (Adobe Inc. -> Adobe Systems)
Edge:
=======
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2026-05-24]
Edge Extension: (Dokumenty Google offline) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-05-11]
Edge Extension: (Edge relevant text changes) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-01-20]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default [2026-05-28]
CHR Notifications: Default -> hxxps://androidforum.cz; hxxps://app.todoist.com; hxxps://aukro.cz; hxxps://best.aliexpress.com; hxxps://calendar.google.com; hxxps://cuqh8u6071bc73a6s270.mergeconnection.co.in; hxxps://cz.pinterest.com; hxxps://drive.google.com; hxxps://fastshare.cz; hxxps://fzkepfawhfhb19.mergeconnection.co.in; hxxps://gw.lightinthebox.com; hxxps://joblpdcvik99hs.mergeconnection.co.in; hxxps://outbyte.com; hxxps://sk8o6.aurobis.co.in; hxxps://trading.1market.eu; hxxps://web.whatsapp.com; hxxps://www.aliexpress.com; hxxps://www.bezrealitky.cz; hxxps://www.hitpaw.com; hxxps://www.hitpaw.net; hxxps://www.instagram.com; hxxps://www.kupi.cz; hxxps://www.lidl.cz; hxxps://www.messenger.com; hxxps://www.namaximum.cz; hxxps://www.roboticky-vysavac.cz
CHR HomePage: Default -> hxxp://www.google.cz/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.google.com ... oogle.com/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Lynote - YouTube Transcript Generator) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpdecpnpoaahhdlfjnpokjpemdnjhekf [2026-05-09]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-17]
CHR Extension: (Save as Shortcut) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\flehofiklehmnnolpjcamplcnmhgcbkk [2024-11-26]
CHR Extension: (Dokumenty Google offline) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-05-28]
CHR Extension: (Inoreader - RSS, News and Social Reader) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhglljfmpijadbpkalkclnhlncncdono [2019-12-10]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2026-05-24]
CHR Extension: (Tab Activate) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlmadbnpnnolpaljadgakjilggigioaj [2022-05-21]
CHR Extension: (Save as PDF) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdjmbiefanbdgnkcikhllpmjnnllbbc [2025-06-13]
CHR Extension: (gLinks) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\leanhbopikglhiejeckmchmobphcpphm [2019-12-10]
CHR Extension: (Spouštěč aplikací pro Disk (od Googlu)) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-08-24]
CHR Extension: (Video Downloader PLUS) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\njgehaondchbmjmajphnhlojfnbfokng [2025-08-04]
CHR Extension: (Rozšíření Odběry RSS (od Googlu)) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2024-07-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Custom Cursor for Chrome™ - Vlastní kurzor) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogdlpmhglpejoiomcodnpjnfgcpmgale [2026-05-24]
CHR Extension: (Web to PDF - Webová stránka do PDF) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pamnlaoeobcmhkliljfaofekeddpmfoh [2026-05-27]
CHR Extension: (RSS Feed Reader) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2026-02-11]
CHR HKU\S-1-5-21-760426430-1322398698-3842268529-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKU\S-1-5-21-760426430-1322398698-3842268529-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-760426430-1322398698-3842268529-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.16.0; C:\Program Files\Common Files\ABBYY\FineReader\16\Licensing\NetworkLicenseServer.exe [1528968 2023-01-18] (ABBYY Development Inc. -> ABBYY Development, Inc.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [944608 2026-03-17] (Adobe Inc. -> Adobe Inc.)
R2 CAMService; C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\rust-cam\dist\native\target\release\service.exe [553600 2020-04-01] (NZXT, Inc. -> )
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1087792 2024-10-15] (Gen Digital Inc. -> Piriform Software Ltd)
R2 CIJSRegister; C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe [153736 2017-03-02] (Canon Inc. -> CANON INC.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460992 2025-04-18] (Canon Inc. -> )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11481720 2026-05-18] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-03-03] (Malwarebytes Inc. -> Malwarebytes)
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [233456 2017-07-04] (Netgear Incorporated -> NETGEAR)
S4 SpyEmrgHealth; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe [379192 2015-03-20] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
S4 SpyEmrgSrv; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe [3335008 2015-03-20] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
R2 SyncBackFreeSchedulesMonitor; C:\Program Files (x86)\2BrightSparks\SyncBackFree\SchedulesMonitor.exe [3447536 2024-02-19] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte Ltd)
S3 wuauserv; C:\Windows\system32\svchost.exe [53744 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 wuauserv; C:\Windows\SysWOW64\svchost.exe [45448 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [159808 2026-05-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944 2020-12-05] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R2 googledrivefs31931; C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2025-05-14] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2020-12-05] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R0 klupd_0d9f16ffa_arkmon; C:\Windows\System32\Drivers\klupd_0d9f16ffa_arkmon.sys [398112 2024-11-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 klupd_0d9f16ffa_klark; C:\Windows\System32\Drivers\klupd_0d9f16ffa_klark.sys [362456 2024-11-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R0 klupd_0d9f16ffa_klbg; C:\Windows\System32\Drivers\klupd_0d9f16ffa_klbg.sys [198728 2024-11-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 klupd_0d9f16ffa_mark; C:\Windows\System32\Drivers\klupd_0d9f16ffa_mark.sys [265816 2024-11-17] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [235584 2026-05-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-03-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\Drivers\farflt.sys [215656 2026-05-24] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\Drivers\mbam.sys [81000 2026-05-24] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [245864 2026-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [190096 2026-05-24] (Malwarebytes Inc -> Malwarebytes)
R2 npf; C:\Windows\system32\drivers\npf.sys [36600 2024-03-21] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 ObDrvHWDuSrv; C:\Program Files (x86)\Outbyte\Driver Updater\DrvHWX64.sys [101248 2025-03-24] (Outbyte Computing Pty Ltd -> Outbyte)
S3 Revoflt; C:\Windows\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SpyEmrg; C:\Windows\System32\Drivers\spyemrg.sys [17240 2011-04-21] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
S3 SpyEmrgAccess; C:\Windows\System32\Drivers\spyemrg_access.sys [24408 2011-04-21] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
S3 SpyEmrgGuard; C:\Windows\System32\Drivers\spyemrg_guard.sys [19768 2015-03-09] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
R2 UI5IFS; C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 16\IFS64.sys [40400 2020-10-28] (Ashampoo GmbH & Co. KG -> )
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [648872 2015-09-03] (Microsoft Windows Hardware Compatibility Publisher -> Vimicro Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [45960 2020-03-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-20] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-05-28 11:23 - 2026-05-28 11:23 - 002449408 _____ (Farbar) C:\Users\Lenovo\Downloads\FRST64 (1).exe
2026-05-28 11:20 - 2026-05-28 11:20 - 000000000 ____D C:\Users\Lenovo\AppData\LocalLow\IGDump
2026-05-27 12:54 - 2026-05-27 12:56 - 000000093 ____H C:\Users\Lenovo\Desktop\.~lock.Stolice.ods#
2026-05-27 12:53 - 2026-05-27 12:53 - 000000093 ____H C:\Users\Lenovo\Desktop\.~lock.Nový Textový dokument OpenDocument.odt#
2026-05-25 00:21 - 2026-05-25 00:22 - 000000000 ____D C:\Program Files (x86)\Setup
2026-05-25 00:15 - 2026-05-25 00:15 - 000190096 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2026-05-24 23:16 - 2026-05-25 00:11 - 000000000 ____D C:\Users\Lenovo\Downloads\Atomic Alarm Clock 6 264 Free Latest
2026-05-24 22:54 - 2026-05-24 22:54 - 000005790 _____ C:\Users\Lenovo\Documents\License2.txt
2026-05-24 22:34 - 2026-05-24 22:37 - 000000000 ____D C:\Users\Lenovo\Documents\Č L Á N K Y
2026-05-24 21:59 - 2026-05-24 22:01 - 000000000 ____D C:\Users\Lenovo\Documents\Abbyy FineReader PDF
2026-05-24 21:46 - 2026-05-24 21:46 - 000000642 _____ C:\Users\Lenovo\Desktop\Nový Textový dokument OpenDocument.odt
2026-05-08 07:21 - 2019-12-15 05:18 - 000001097 _____ C:\Users\Lenovo\Desktop\Nexus Ultimate.lnk
2026-05-07 23:56 - 2026-05-07 23:56 - 000671160 _____ C:\Users\Lenovo\Desktop\Souhrn údajů evidovaných k zákaznikovi.pdf
2026-04-29 11:30 - 2026-04-29 11:30 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Sentry
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-05-28 11:26 - 2025-12-31 15:19 - 000036026 _____ C:\Users\Lenovo\Downloads\FRST.txt
2026-05-28 11:26 - 2020-01-13 23:38 - 000000000 ____D C:\ProgramData\Bitmeter2
2026-05-28 11:25 - 2025-02-19 16:40 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Malwarebytes
2026-05-28 11:25 - 2020-05-18 19:13 - 000000000 ____D C:\FRST
2026-05-28 11:21 - 2019-12-11 08:06 - 000000000 ____D C:\Users\Lenovo\AppData\Local\CrashDumps
2026-05-28 11:12 - 2019-12-12 05:08 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-05-28 11:12 - 2019-11-27 19:44 - 000000000 ___SD C:\Users\Lenovo\AppData\Roaming\Microsoft\Credentials
2026-05-28 07:42 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-05-27 16:02 - 2025-12-08 09:32 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Messenger
2026-05-27 12:56 - 2024-02-25 14:15 - 000105023 _____ C:\Users\Lenovo\Desktop\Stolice.ods
2026-05-27 12:55 - 2019-11-27 19:51 - 000000000 ____D C:\ProgramData\NVIDIA
2026-05-27 12:53 - 2019-12-10 19:45 - 000000000 ___RD C:\Users\Lenovo\Disk Google
2026-05-25 00:26 - 2020-02-29 13:31 - 000000000 ____D C:\Users\Lenovo\AppData\Local\MEGAsync
2026-05-25 00:25 - 2022-10-31 14:17 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-05-25 00:24 - 2025-01-23 21:21 - 000000000 ____D C:\Users\Lenovo\AppData\Local\ScreenPal-v3
2026-05-25 00:24 - 2024-11-15 04:04 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2026-05-25 00:24 - 2021-02-27 09:23 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2026-05-25 00:24 - 2020-01-02 23:10 - 000000000 ____D C:\Users\Lenovo\AppData\Local\NETGEARGenie
2026-05-25 00:24 - 2019-12-12 05:20 - 000000000 ____D C:\Users\Lenovo
2026-05-25 00:23 - 2019-11-27 20:03 - 000000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2026-05-24 23:56 - 2020-01-14 00:07 - 000000000 ____D C:\Users\Lenovo\AppData\Local\D3DSCache
2026-05-23 19:27 - 2023-01-03 10:18 - 000000000 ____D C:\Windows\SystemTemp
2026-05-22 23:26 - 2026-01-20 20:49 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-05-22 23:26 - 2026-01-20 20:49 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-05-22 23:25 - 2019-12-10 18:23 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-05-18 13:59 - 2026-03-03 13:20 - 000159808 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys
2026-05-17 11:55 - 2026-04-15 12:44 - 000002090 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller.lnk
2026-05-17 11:55 - 2026-01-31 19:15 - 000002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-05-17 11:55 - 2026-01-31 19:15 - 000002067 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2026-05-13 23:36 - 2026-03-03 17:21 - 000024515 _____ C:\Users\Lenovo\Desktop\Cigára.ods
2026-05-13 22:55 - 2021-09-08 17:14 - 000002179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2026-05-13 22:55 - 2021-09-08 17:14 - 000002014 _____ C:\Users\Default\Desktop\Google Slides.lnk
2026-05-13 22:55 - 2021-09-08 17:14 - 000002014 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2026-05-13 22:55 - 2021-09-08 17:14 - 000002002 _____ C:\Users\Default\Desktop\Google Docs.lnk
2026-05-12 10:07 - 2025-09-11 23:45 - 000000000 ____D C:\ProgramData\CanonIJPLM
2026-05-10 01:22 - 2019-03-19 13:55 - 000718198 _____ C:\Windows\system32\perfh005.dat
2026-05-10 01:22 - 2019-03-19 13:55 - 000145242 _____ C:\Windows\system32\perfc005.dat
2026-05-10 01:22 - 2019-03-19 06:50 - 000000000 ____D C:\Windows\INF
2026-05-10 01:22 - 2016-04-27 08:54 - 001693452 _____ C:\Windows\system32\PerfStringBackup.INI
2026-05-10 01:17 - 2019-12-15 09:38 - 000000000 ___RD C:\Users\Lenovo\Desktop\Zástupci
2026-05-09 10:04 - 2024-09-22 13:58 - 000081128 _____ C:\Users\Lenovo\Desktop\Rozpočet.ods
2026-05-08 10:16 - 2021-03-29 18:52 - 000000000 ____D C:\Users\Lenovo\Documents\M A N U Á L Y
2026-05-07 16:39 - 2019-12-11 21:53 - 000000000 ____D C:\Users\Lenovo\AppData\Local\ElevatedDiagnostics
2026-05-04 02:26 - 2024-08-12 19:48 - 000000000 ____D C:\Users\Lenovo\Documents\NÁVODY
2026-05-02 08:51 - 2023-01-07 20:16 - 000003714 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{5C0C20A9-9348-4269-BBEC-43F7F7B2331E}
2026-05-02 08:51 - 2023-01-07 20:16 - 000003588 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{2BA3E877-26FE-4A85-82FA-9F5007A3BFFD}
2026-04-29 18:07 - 2020-02-20 23:54 - 000000000 ____D C:\Program Files\Common Files\Adobe
2026-04-28 10:59 - 2020-03-29 08:16 - 000000000 ____D C:\Users\Lenovo\Documents\D O K L A D Y
==================== Files in the root of some directories ========
2024-11-05 15:38 - 2024-11-05 15:38 - 000000008 ____H () C:\ProgramData\ed115it41.dat
2024-11-05 15:39 - 2024-11-07 21:36 - 000000004 ____H () C:\ProgramData\ed115rc41.dat
2024-11-05 15:38 - 2024-11-05 15:38 - 000000128 ____H () C:\ProgramData\ed115resa.dat
2024-11-05 15:38 - 2024-11-05 15:38 - 000000128 ____H () C:\ProgramData\ed115resb.dat
2024-11-05 15:38 - 2024-11-05 15:38 - 000893608 _____ (AutoIt Team) C:\Users\Public\Guard.exe
2024-11-05 15:39 - 2019-03-19 06:47 - 000046632 _____ (Microsoft Corporation) C:\Users\Public\jsc.exe
2019-12-11 08:41 - 2020-01-02 17:50 - 000000132 _____ () C:\Users\Lenovo\AppData\Roaming\Adobe PNG Format CS6 Prefs
2022-02-20 10:54 - 2022-01-26 14:04 - 000000701 _____ () C:\Users\Lenovo\AppData\Roaming\nefcodec.dll
2022-02-20 10:54 - 2022-02-20 10:54 - 000000019 _____ () C:\Users\Lenovo\AppData\Roaming\settingnef.ini
2020-03-30 14:27 - 2020-03-30 14:27 - 139261152 _____ (Wondershare Software ) C:\Users\Lenovo\AppData\Roaming\video-converter-ultimate_full495.exe
2025-09-18 04:52 - 2025-09-18 04:52 - 000003584 _____ () C:\Users\Lenovo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2024-11-05 15:39 - 2024-11-05 15:39 - 000000010 _____ () C:\Users\Lenovo\AppData\Local\ledger_timestamp
2020-02-21 19:38 - 2024-05-05 15:59 - 000000615 _____ () C:\Users\Lenovo\AppData\Local\oobelibMkey.log
2024-10-28 19:01 - 2024-10-28 19:01 - 000002173 _____ () C:\Users\Lenovo\AppData\Local\recently-used.xbel
2019-11-27 20:29 - 2019-11-27 20:29 - 000007605 _____ () C:\Users\Lenovo\AppData\Local\Resmon.ResmonCfg
2020-03-13 21:38 - 2020-03-13 21:38 - 000893608 _____ (AutoIt Team) C:\Users\Lenovo\AppData\Local\wintmp.exe
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-05-2026
Ran by Lenovo (28-05-2026 11:26:49)
Running from C:\Users\Lenovo\Downloads
Microsoft Windows 10 Home Version 1903 18362.720 (X64) (2019-12-12 03:28:02)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-760426430-1322398698-3842268529-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-760426430-1322398698-3842268529-503 - Limited - Disabled)
Guest (S-1-5-21-760426430-1322398698-3842268529-501 - Limited - Disabled)
Lenovo (S-1-5-21-760426430-1322398698-3842268529-1001 - Administrators - Enabled) => C:\Users\Lenovo
WDAGUtilityAccount (S-1-5-21-760426430-1322398698-3842268529-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4K Video Downloader (HKLM\...\{44E23473-28B4-47E2-BD69-46E9307294DB}) (Version: 4.33.5.0172 - Open Media LLC) Hidden
4K Video Downloader (HKLM-x32\...\{ceabdf45-a262-45f9-9621-7a45be3dc900}) (Version: 4.33.5.172 - Open Media LLC)
4K Video Downloader+ (HKLM\...\{13810AF2-CEE9-4573-A89E-F57563DC416C}) (Version: 26.1.1.0355 - InterPromo GMBH) Hidden
4K Video Downloader+ (HKLM-x32\...\{37d72c8b-b6b5-4fc0-a862-6db4d77c193f}) (Version: 26.1.0.336 - InterPromo GMBH)
ABBYY FineReader PDF (HKLM\...\{F16000FE-0003-6400-0000-074957833700}) (Version: 16.0.7300 - ABBYY Development, Inc.) Hidden
ABBYY FineReader PDF (HKLM-x32\...\{82df8653-ea3b-49b5-b113-47c13f8bfaa9}) (Version: 16.0.7300 - ABBYY Development, Inc.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-FFFF-7760-BC15014EA700}) (Version: 26.001.21563 - Adobe)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 6.9.1.1 - Adobe Inc.)
Adobe Lightroom Classic CC (HKLM-x32\...\LTRM_8_1) (Version: 8.1 - Adobe Systems Incorporated)
Adobe Photoshop 2020 (HKLM-x32\...\PHSP_21_0_2) (Version: 21.0.2 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Aegisub 3.2.2 (HKLM\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.2.2 - Aegisub Team)
AIDA64 Extreme v5.99 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.99 - FinalWire Ltd.)
AIMP (HKLM-x32\...\AIMP) (Version: v4.60.2180, 25.03.2020 - AIMP DevTeam)
Apeaksoft Free HEIC Converter 1.0.18 (HKLM-x32\...\{3937AA40-E034-4137-AC6C-B111D518FEE2}_is1) (Version: 1.0.18 - Apeaksoft Studio)
Ashampoo UnInstaller 11 (HKLM-x32\...\{4209F371-B84B-F321-6BD3-1D91E2505732}_is1) (Version: 11.00.16 - Ashampoo GmbH & Co. KG)
Ashampoo UnInstaller 16 (HKLM-x32\...\{0A11EA01-8308-C82C-D4C4-5BC03ED52D9F}_is1) (Version: 16.00.02 - Ashampoo GmbH & Co. KG)
Atomic Alarm Clock 6 264 Free Latest.exe version 1.0.0.0 (HKLM-x32\...\Atomic Alarm Clock 6 264 Free Latest.exe_is1) (Version: 1.0.0.0 - )
Audacity 2.3.3 (HKLM-x32\...\Audacity_is1) (Version: 2.3.3 - Audacity Team)
Avidemux VC++ 64bits (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\{2799a4bd-577f-45de-a7eb-330cdd2c2ab0}) (Version: 2.7.5 - Mean)
Backup and Sync from Google (HKLM\...\{696895F7-52C7-4C9E-998B-C7E0CC907092}) (Version: 3.57.4256.0809 - Google, Inc.)
BitMeter (HKLM-x32\...\BitMeter) (Version: - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 7.35.317.3 - Broadcom Corporation)
Canon G2010 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_G2010_series) (Version: 1.03 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.110.1.09 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.4.0.16 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.7.0 - Canon Inc.)
CapCut (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\CapCut) (Version: 5.0.0.1886 - Bytedance Pte. Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 6.29 - Piriform)
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1651.5 - Piriform Software) Hidden
CodeTwo QR Code Desktop Reader & Generator (HKLM-x32\...\{AF7E31D6-980C-4788-B80C-47F1837CF44C}) (Version: 1.1.2.4 - CodeTwo)
CPUID HWMonitor 1.41 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.41 - CPUID, Inc.)
EasyCutStudio 6.0.3 (HKLM-x32\...\EasyCutStudio_is1) (Version: - )
ELAN Touchpad 11.15.0.18_X64 (HKLM\...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
FastStone Image Viewer 7.4 (HKLM-x32\...\FastStone Image Viewer) (Version: 7.4 - FastStone Soft)
FileZilla 3.67.1 (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\FileZilla Client) (Version: 3.67.1 - Tim Kosse)
Free Desktop Clock 3.0 (HKLM\...\Free Desktop Clock_is1) (Version: - Drive Software Company)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 125.0.0.0 - Google LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 148.0.7778.179 - Google LLC)
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software)
inSSIDer (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\inSSIDer) (Version: 5.2.14 - MetaGeek, LLC)
Java 8 Update 251 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180251F0}) (Version: 8.0.2510.8 - Oracle Corporation)
LAV Filters 0.74.1 (HKLM-x32\...\lavfilters_is1) (Version: 0.74.1 - Hendrik Leppkes)
LibreOffice 6.4 Help Pack (Czech) (HKLM\...\{AE983296-8590-4589-84E0-80B8C30ED803}) (Version: 6.4.0.3 - The Document Foundation)
LibreOffice 7.1.1.2 (HKLM\...\{14E9DACB-8945-4B62-A19B-2C6245D48490}) (Version: 7.1.1.2 - The Document Foundation)
LinuxLive USB Creator (HKLM-x32\...\LinuxLive USB Creator) (Version: 2.9 - Thibaut Lauziere)
Malwarebytes version 5.5.6.254 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.5.6.254 - Malwarebytes)
MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited)
Messenger (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\c1b3adcf-2068-5e8d-b25d-30ce588e3a4c) (Version: 208.0.580469446 - Facebook, Inc.)
Metric Collection SDK 35 (HKLM-x32\...\{C2B5B5B0-2545-4E94-B4BA-548D4BF0B196}) (Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 148.0.3967.83 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 148.0.3967.83 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft_VC80_CRT_x86 (HKLM-x32\...\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{08D2E121-7F6A-43EB-97FD-629B44903403}) (Version: 1.00.0000 - Adobe) Hidden
MKVToolNix 43.0.0 (64-bit) (HKLM-x32\...\MKVToolNix) (Version: 43.0.0 - Moritz Bunkus)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 122.0 (x64 cs)) (Version: 122.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 78.8.0 - Mozilla)
Mozilla Thunderbird ESR (x64 cs) (HKLM\...\Mozilla Thunderbird 140.10.2 ESR (x64 cs)) (Version: 140.10.2 - Mozilla)
Mp3tag v3.01 (HKLM-x32\...\Mp3tag) (Version: 3.01 - Florian Heidenreich)
NAPS2 (HKLM\...\NAPS2 - Not Another PDF Scanner_is1) (Version: 8.1.1 - NAPS2 Software)
NEF To JPG Converter V1 (HKLM-x32\...\NEF To JPG Converter_is1) (Version: - PDFZilla.com)
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.60.00 - NETGEAR Inc.)
Nexus Ultimate 11.6 (HKLM-x32\...\Nexus Ultimate_is1) (Version: - )
NVIDIA FrameView SDK 1.1.4923.29968894 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29968894 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.23.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.23.0.74 - NVIDIA Corporation)
NZXT CAM 4.4.2 (HKLM\...\ac0666ae-ee66-5310-ac01-9d6348133b2d) (Version: 4.4.2 - NZXT, Inc.)
osrss (HKLM-x32\...\{1BA1133B-1C7A-41A0-8CBF-9B993E63D296}) (Version: 1.0.0 - Microsoft Corporation) Hidden
PC Štítky 2.xx (HKLM-x32\...\PC Štítky 2.xx_is1) (Version: - LAN Consult, spol. s r.o.)
Pixillion Image Converter (HKLM-x32\...\Pixillion) (Version: 5.12 - NCH Software)
Planet - SoftLabel (HKLM-x32\...\{99E50E6B-8C7D-4D1D-A7CE-65128D76AD2C}) (Version: 1.1.61 - Abanet)
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 26.04.01.0 - Kakao Corp.)
Recepty doma (HKLM-x32\...\Recepty doma_is1) (Version: - Martin Roubec)
Registrace tiskárny (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.2 - Canon Inc.)
Revo Uninstaller Pro 5.3.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.3.2 - VS Revo Group, Ltd.)
ScreenPal Web Launcher v3.1.10.1 (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\ScreenPal v3 (WebLauncher)) (Version: v3.1.10.1 - ScreenPal)
SharePoint Client Components (HKLM\...\{95150004-1163-0409-1000-0000000FF1CE}) (Version: 15.0.4711.1001 - Microsoft Corporation)
Skype verze 8.99 (HKLM-x32\...\Skype_is1) (Version: 8.99 - Skype Technologies S.A.)
SoftPerfect Network Scanner version 7.2.6 (HKLM\...\{8083C3D9-F400-48FA-B060-CF55F25E2D4B}_is1) (Version: 7.2.6 - SoftPerfect Pty Ltd)
Speedtest by Ookla (HKLM\...\{708BC0F0-18DD-4951-A531-18E7CE473BCE}) (Version: 1.8.154.001 - Ookla)
Spy Emergency 2017-24.0.620 (HKLM\...\Spy Emergency_is1) (Version: - NETGATE Technologies s.r.o.)
Subtitle Edit 3.5.13 (HKLM\...\SubtitleEdit_is1) (Version: 3.5.13.0 - Nikse)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1048 - SUPERAntiSpyware.com)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 14.03 - NCH Software)
SyncBackFree (HKLM-x32\...\SyncBackFree_is1) (Version: 11.3.7.0 - 2BrightSparks)
Televzr Light (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\5a86d928-e527-5a16-9156-f025bf9f7e0e) (Version: 1.20.0 - LTQ DIGITAL LIMITED COMPANY)
Tisk Obalek 3.2.2.9 (HKLM-x32\...\Tisk Obalek_is1) (Version: 3.2.2.9 - Mgr. Radovan Kraus)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{3BAE4496-6F6C-4330-A8AA-B93D3D346FA5}) (Version: 2.53.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{F339C545-24DC-4870-AA32-6EB6B0500B95}) (Version: 1.24.0.0 - Microsoft Corporation) Hidden
Videoder 1.0.9 (HKLM-x32\...\808fc302-3d01-59ce-8094-e0443a55877e) (Version: 1.0.9 - GlennioTech)
Vistumbler (HKLM-x32\...\Vistumbler) (Version: 10.6.5 - Vistumbler.net)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.12 - VideoLAN)
VueScan x64 (HKLM\...\VueScan x64) (Version: 9.8.52.18 - Hamrick Software)
WhatsApp (Outdated) (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\WhatsApp) (Version: 2.2326.10 - WhatsApp)
WiFi Scanner (HKLM-x32\...\{1224CE90-0AA3-41AF-B51F-61C8C796C401}) (Version: 0.8.626 - AccessAgility)
Windows Installer (HKLM-x32\...\{798E61D4-8923-4E77-A74B-2DF264394A48}) (Version: 5.0.4 - AdvancedWindowsManager) Hidden
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
Chrome apps:
============
Správce hesel Google (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\999f44d80d35096af8c638a664313fbd) (Version: 1.0 - Google\Chrome)
YouTube (HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\f7dc6435b15fa8a7d14797683a3fd873) (Version: 1.0 - Google\Chrome)
Packages:
=========
Acrobat Notification Client -> C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2026-04-22] (Adobe Systems Incorporated)
Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_6.0.0.1_x86__enpm4xejd91yc [2024-05-21] (Adobe Systems Incorporated)
Adobe Reader Touch -> C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobeReader_3.1.8.7675_x86__ynb6jyjzte8ga [2020-01-13] (Adobe Systems Incorporated)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.164.200.0_x86__kgqvnymyfvs32 [2020-03-19] (king.com)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.4081.0_x64__rz1tebttyb220 [2020-02-04] (Dolby Laboratories)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-12-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-12-12] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-12] (Microsoft Studios) [MS Ad]
Microsoft Zprávy -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20503.0_x64__8wekyb3d8bbwe [2020-03-06] (Microsoft Corporation) [MS Ad]
MSN Sport -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
One Calendar -> C:\Program Files\WindowsApps\64885BlueEdge.OneCalendar_2020.229.1.0_x64__8kea50m9krsh2 [2020-03-06] (Code Spark)
One Task -> C:\Program Files\WindowsApps\64885BlueEdge.OneTask_2018.1124.1.0_x64__8kea50m9krsh2 [2020-03-13] (Code Spark)
WiFi Analyzer -> C:\Program Files\WindowsApps\19965MATTHAFNER.WIFIANALYZER_2.5.1.0_x64__gs5k5vmxr2ste [2020-01-14] (Matt Hafner)
Wifi Analyzer and Scanner -> C:\Program Files\WindowsApps\28877WebProvider.WifiAnalyzerandScanner_1.2.1.0_x64__gdrx0g078t8zg [2019-12-29] (WebProvider)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{0AC68F4B-F9F7-475B-A5B4-383171479500} -> [MEGA] => C:\Users\Lenovo\Documents\MEGA [2020-02-29 13:36]
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{54FD8C11-9F42-4A0F-BE2C-9E3A4158A705}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{9B1F8A90-DF55-4BB6-B78F-77F8C4632B37}\localserver32 -> C:\Program Files\ABBYY FineReader 16\FineUpdate.exe (ABBYY Development, Inc. -> ABBYY Development, Inc.)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{9f0c474b-de34-42ec-af28-eb091c7982ff}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{B1D050AE-282F-DC81-EDA8-31C953EEDD86}\InprocServer32 -> C:\Program Files\Common Files\System\ole32.dll => No File
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{D5621537-2364-45C2-9F3F-C2329CFFF29D} -> [MEGA] => C:\Users\Lenovo\Documents\MEGA [2020-02-29 13:36]
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2026-01-28] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2026-01-28] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2026-01-28] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google)
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2026-01-28] (Adobe Inc. -> )
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2020-05-12] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers1: [ContextMenuHandlerFilmora] -> {5F542218-AF8A-4CF8-8ACA-DF63B73C528D} => C:\Windows\system32\FilmoraContextMenu.dll [2024-10-10] () [File not signed]
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ContextMenuHandlers1: [FineReader16ContextMenu] -> {DCACA03D-01CA-410C-8F35-FBEB05CA8BF0} => C:\Program Files\ABBYY FineReader 16\FRIntegration.dll [2023-07-30] (ABBYY Development, Inc. -> ABBYY Development, Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2022-02-01] (Google LLC -> Google)
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ContextMenuHandlers1: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-03-27] (Florian Heidenreich) [File not signed]
ContextMenuHandlers1: [SpyEmergency] -> {2E9FFF5C-4375-494d-951F-098BAA42239E} => C:\Program Files\NETGATE\Spy Emergency\menuext.dll [2013-03-11] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ContextMenuHandlers2: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-03-27] (Florian Heidenreich) [File not signed]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-05-18] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2020-05-12] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2022-02-01] (Google LLC -> Google)
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Lenovo\AppData\Local\MEGAsync\ShellExtX64.dll [2026-05-24] (Mega Limited -> )
ContextMenuHandlers4: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-03-27] (Florian Heidenreich) [File not signed]
ContextMenuHandlers4: [SpyEmergency] -> {2E9FFF5C-4375-494d-951F-098BAA42239E} => C:\Program Files\NETGATE\Spy Emergency\menuext.dll [2013-03-11] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\125.0.0.0\drivefsext.dll [2026-05-13] (Google LLC -> Google LLC.)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2026-01-28] (Adobe Inc. -> )
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers6: [FineReader16ContextMenu] -> {DCACA03D-01CA-410C-8F35-FBEB05CA8BF0} => C:\Program Files\ABBYY FineReader 16\FRIntegration.dll [2023-07-30] (ABBYY Development, Inc. -> ABBYY Development, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-05-18] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2022-04-04] (VS Revo Group Ltd. -> VS Revo Group)
ContextMenuHandlers6: [SpyEmergency] -> {2E9FFF5C-4375-494d-951F-098BAA42239E} => C:\Program Files\NETGATE\Spy Emergency\menuext.dll [2013-03-11] (NETGATE Technologies s.r.o. -> NETGATE Technologies s.r.o.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kajebgjangihfbkjfejcanhanjmmbcfd\Správce hesel Google.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=kajebgjangihfbkjfejcanhanjmmbcfd
==================== Loaded Modules (Whitelisted) =============
2016-03-03 06:17 - 2016-03-03 06:17 - 000136704 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll
2016-03-03 06:17 - 2016-03-03 06:17 - 000146944 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll
2016-01-15 04:06 - 2016-01-15 04:06 - 000057344 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll
2016-02-22 10:25 - 2016-02-22 10:25 - 000116224 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll
2015-08-24 10:41 - 2015-08-24 10:41 - 002360622 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\drivers\libntgr_api.dll
2019-05-22 10:09 - 2019-05-22 10:09 - 000713728 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll
2018-07-20 06:31 - 2018-07-20 06:31 - 000168448 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll
2018-07-20 06:31 - 2018-07-20 06:31 - 000591872 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll
2019-05-15 10:07 - 2019-05-15 10:07 - 006903808 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll
2018-07-20 06:36 - 2018-07-20 06:36 - 002980352 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_MyMedia.dll
2019-05-15 10:07 - 2019-05-15 10:07 - 000967168 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll
2019-04-19 08:38 - 2019-04-19 08:38 - 001259520 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll
2018-11-22 03:58 - 2018-11-22 03:58 - 011973632 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll
2019-05-15 10:05 - 2019-05-15 10:05 - 002683392 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll
2019-05-22 11:51 - 2019-05-22 11:51 - 000278528 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll
2019-05-22 10:14 - 2019-05-22 10:14 - 000888832 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll
2018-11-20 12:34 - 2018-11-20 12:34 - 000422400 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll
2018-12-12 12:36 - 2018-12-12 12:36 - 000633344 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll
2018-07-20 06:33 - 2018-07-20 06:33 - 000433664 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll
2014-12-21 18:07 - 2014-12-21 18:07 - 000119822 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll
2014-12-21 18:07 - 2014-12-21 18:07 - 001026062 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\libstdc++-6.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 000111616 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\libvlc.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 002285056 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\libvlccore.dll
2016-03-03 06:17 - 2016-03-03 06:17 - 000074752 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 000219648 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\plugins\access\libdshow_plugin.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 000049664 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libaout_directx_plugin.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 000051200 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libwaveout_plugin.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 000051200 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\plugins\control\libhotkeys_plugin.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 001235456 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\plugins\misc\libxml_plugin.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 000037376 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\plugins\mmxext\libmemcpymmxext_plugin.dll
2012-06-28 00:23 - 2012-06-28 00:23 - 000070144 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\plugins\video_output\libdirectx_plugin.dll
2016-02-26 12:07 - 2016-02-26 12:07 - 000049152 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll
2016-08-15 10:28 - 2016-08-15 10:28 - 001125888 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\qwt.dll
2019-05-22 10:13 - 2019-05-22 10:13 - 001701376 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll
2016-03-03 06:17 - 2016-03-03 06:17 - 000072192 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.dll
2016-01-15 04:23 - 2016-01-15 04:23 - 000026112 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll
2016-04-12 08:13 - 2016-04-12 08:13 - 000067072 _____ () [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll
2021-02-01 21:49 - 2021-02-01 21:49 - 000010240 _____ () [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\AcroTray.cze
2024-10-29 22:27 - 2024-10-11 00:35 - 000754688 _____ () [File not signed] C:\Windows\system32\FilmoraContextMenu.dll
2025-12-06 23:34 - 2025-12-06 23:34 - 000030720 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\Acrobat Elements\ContextMenuShim64.cze
2020-03-27 18:50 - 2020-03-27 18:50 - 000398336 _____ (Florian Heidenreich) [File not signed] C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll
2014-12-21 18:07 - 2014-12-21 18:07 - 000049152 _____ (MingW-W64 Project. All rights reserved.) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\libwinpthread-1.dll
2013-02-19 08:46 - 2013-02-19 08:46 - 000220160 _____ (NETGEAR Inc.) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\drivers\NETGEAR_PLC_L2_API.dll
2014-03-24 04:32 - 2014-03-24 04:32 - 000060273 _____ (Open Source Software community project) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\pthreadGC2.dll
2021-02-26 11:36 - 2021-02-26 11:36 - 000073728 _____ (Python Software Foundation) [File not signed] C:\Program Files\LibreOffice\program\python-core-3.8.4\lib\_socket.pyd
2021-02-26 11:36 - 2021-02-26 11:36 - 000020992 _____ (Python Software Foundation) [File not signed] C:\Program Files\LibreOffice\program\python-core-3.8.4\lib\select.pyd
2021-02-26 16:00 - 2021-02-26 16:00 - 000476160 _____ (The Document Foundation) [File not signed] C:\Program Files\LibreOffice\program\pyuno.pyd
2013-02-11 03:35 - 2013-02-11 03:35 - 001178624 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\LIBEAY32.dll
2013-02-11 03:35 - 2013-02-11 03:35 - 000269824 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\ssleay32.dll
2015-10-12 21:44 - 2015-10-12 21:44 - 000033280 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qgif.dll
2015-10-12 21:45 - 2015-10-12 21:45 - 000034816 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qico.dll
2015-10-12 21:45 - 2015-10-12 21:45 - 000246784 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qjpeg.dll
2015-10-12 21:58 - 2015-10-12 21:58 - 000366592 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qmng.dll
2015-10-12 21:48 - 2015-10-12 21:48 - 000028672 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qsvg.dll
2015-10-12 21:58 - 2015-10-12 21:58 - 000027648 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qtga.dll
2015-10-12 21:58 - 2015-10-12 21:58 - 000433664 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qtiff.dll
2015-10-12 21:58 - 2015-10-12 21:58 - 000027136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qwbmp.dll
2015-10-12 21:46 - 2015-10-12 21:46 - 001413632 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\platforms\qwindows.dll
2015-10-12 21:47 - 2015-10-12 21:47 - 000044544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\printsupport\windowsprintersupport.dll
2015-11-19 06:54 - 2015-11-19 06:54 - 005391360 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5Core.dll
2015-10-12 21:31 - 2015-10-12 21:31 - 005334528 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5Gui.dll
2015-10-12 21:26 - 2015-10-12 21:26 - 001528832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5Network.dll
2015-10-12 21:42 - 2015-10-12 21:42 - 000334848 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5OpenGL.dll
2016-04-13 04:52 - 2016-04-13 04:52 - 000357888 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5PrintSupport.dll
2015-10-12 21:48 - 2015-10-12 21:48 - 000331776 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5Svg.dll
2015-10-12 21:37 - 2015-10-12 21:37 - 006541824 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5Widgets.dll
2015-10-12 21:25 - 2015-10-12 21:25 - 000237056 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\NETGEAR Genie\bin\Qt5Xml.dll
2019-12-15 05:18 - 2011-05-26 19:20 - 000025088 _____ (Winstep Software Technologies) [File not signed] C:\Program Files (x86)\Winstep\WsxMMTimer.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\0d9f16ff.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\0d9f16ff.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\ssv.dll [2020-04-16] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\jp2ssv.dll [2020-04-16] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
IE Session Restore: HKU\S-1-5-21-760426430-1322398698-3842268529-1001 -> is enabled.
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-30 09:24 - 2026-04-17 15:09 - 000000735 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
2019-12-11 00:22 - 2020-01-01 21:30 - 000000446 _____ C:\Windows\system32\drivers\etc\hosts.ics
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 62.129.50.20 - 85.135.32.100
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Qualcomm Atheros AR8172/8176/8178 PCI-E Fast Ethernet Controller (NDIS 6.30) -> L1C63x64.sys
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Wi-Fi: Síťový adaptér Broadcom 802.11n -> bcmwl63a.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter;;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKCU\Environment\\Path -> C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Windows\System32\OpenSSH\;C:\Users\Lenovo\AppData\Local\Microsoft\WindowsApps
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\Control Panel\Desktop\\Wallpaper ->
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 0) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|C:\Program Files (x86)\Common Files\Acronis\TrueImageHome\TrueImageHomeService.exe
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe"
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\StartupApproved\Run: => "AtomicAlarmClock6"
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\StartupApproved\Run: => "CCXProcess"
HKU\S-1-5-21-760426430-1322398698-3842268529-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{51CD8B13-C161-4AA3-9D9C-ECCA1E9127C3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E93BA065-E320-40F8-9037-D61F84DCCA17}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{8A5D56B0-A3AA-4D45-9A96-6BDA5305D721}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{CCBBDA7F-E030-4D56-B4A9-3FB611C4B13C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{69E0CBFD-18B6-4005-9FD0-A0668760395C}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe (NETGEAR TAIWAN CO., LTD -> NETGEAR Inc.)
FirewallRules: [UDP Query User{FDF815F9-202B-4C72-9DC4-2F7267662A34}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe (NETGEAR TAIWAN CO., LTD -> NETGEAR Inc.)
FirewallRules: [TCP Query User{E4B9757F-1A41-4FD0-BBAC-5AF4CEC63EEF}C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe] => (Allow) C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe (Kastelo AB -> The Syncthing Authors)
FirewallRules: [UDP Query User{0AEB44B9-512C-4883-93FF-AC00848676D0}C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe] => (Allow) C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe (Kastelo AB -> The Syncthing Authors)
FirewallRules: [{2AD33F00-D99B-4A75-B96A-0B3A2C590268}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1C653BB6-22A9-498C-9A9E-BD9FC8D11DD3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{69CC26C3-C176-4998-864F-D6238211EF3B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{594CE807-87B7-4A0C-8C3F-2CA276A9033B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{EE542E4B-1D2E-4A70-A7D9-7E289BCB200B}C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe] => (Block) C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe (Kastelo AB -> The Syncthing Authors)
FirewallRules: [UDP Query User{5F3C8115-83D4-4FD3-988B-9B5F3CBDAFA2}C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe] => (Block) C:\program files\syncthing\syncthing-windows-amd64-v1.2.1\syncthing.exe (Kastelo AB -> The Syncthing Authors)
FirewallRules: [TCP Query User{388A03EB-C8D7-49C9-B933-4E1ED83B133B}C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{6CBD64CD-7B23-49A6-8CBF-BD92FD526019}C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [{0875530A-F03B-4426-84FD-A998ED2A2337}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{5ED983EB-FB69-4B8C-9723-582FF87ECDD6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{05D0274B-4C6A-4B17-9A42-0C1082BCBE2C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{11952E1A-D31F-4AC6-9D48-D1F8804E898F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{7E9B9F37-9659-42CD-882E-C3CEA8518031}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{CA1ADAF0-C506-4D23-9A58-4E7290421AA9}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{6926C79B-ED8A-4C84-9E55-0195CDD5F40E}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{44BEC590-9EC4-468C-9459-FD53497E74D2}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
FirewallRules: [UDP Query User{9239168C-0DB3-4DE5-9C77-1C0F79716338}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
FirewallRules: [{39787F56-B091-4446-A9C5-BA5B128FD0D7}] => (Allow) C:\Program Files\VueScan\vuescan.exe (Hamrick Software -> Hamrick Software)
FirewallRules: [{82D01800-E33C-4309-8A8D-D7D2AEAD44A4}] => (Allow) C:\Program Files\VueScan\vuescan.exe (Hamrick Software -> Hamrick Software)
FirewallRules: [{C54FFFF2-42C5-48EA-A2E0-C3646599C7A3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
05-05-2026 13:11:22 Naplánovaný kontrolní bod
15-05-2026 11:27:27 Naplánovaný kontrolní bod
24-05-2026 16:39:44 Naplánovaný kontrolní bod
==================== Faulty Device Manager Devices ============
Name: Android ADB Interface
Description: Android ADB Interface
Class Guid: {3f966bd9-fa04-4ec5-991c-d326973b5128}
Manufacturer: Google, Inc.
Service: WinUSB
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: ========================
Application errors:
==================
Error: (05/28/2026 11:21:01 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Systém Windows nemůže získat přístup k souboru z jednoho z těchto důvodů:
došlo k problému s připojením k síti, s diskem, na kterém je soubor uložen, nebo
s ovladači ukládání nainstalovanými v tomto počítači; nebo disk chybí.
Systém Windows kvůli této chybě ukončil program Windows Command Processor.
Program: Windows Command Processor
Soubor:
Hodnota chyby je uvedena v části Další údaje.
Akce uživatele
1. Otevřete soubor znovu.
Může se jednat o dočasný problém, který se při novém spuštění programu nebude opakovat.
2.
Pokud k souboru stále nelze získat přístup a:
- Nachází se v síti,
měl by správce sítě ověřit, zda nedošlo k problému se sítí a zda lze server kontaktovat.
- Je na vyměnitelném disku (například disketě nebo disku CD-ROM), ověřte, zda je disk správně vložen do počítače.
3. Zkontrolujte a opravte systém souborů pomocí nástroje CHKDSK. Ten lze spustit tak, že kliknete na tlačítko Start a příkaz Spustit, zadáte příkaz CMD a kliknete na tlačítko OK. Do příkazového řádku zadejte příkaz CHKDSK /F a stiskněte klávesu ENTER.
4. Pokud potíže potrvají, obnovte soubor ze záložní kopie.
5. Zjistěte, zda lze otevřít jiné soubory na stejném disku. Pokud ne, může být disk poškozen. Jedná-li se o pevný disk, obraťte se na správce nebo na dodavatele počítačového hardwaru
se žádostí o pomoc.
Další údaje
Hodnota chyby: 00000000
Typ disku: 0
Error: (05/28/2026 11:21:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: cmd.exe, verze: 10.0.18362.449, časové razítko: 0x98868d68
Název chybujícího modulu: cmd.exe, verze: 10.0.18362.449, časové razítko: 0x98868d68
Kód výjimky: 0xc000001d
Posun chyby: 0x00000000000182b0
ID chybujícího procesu: 0x3500
Čas spuštění chybující aplikace: 0x01dcee834cc9c73d
Cesta k chybující aplikaci: C:\Windows\system32\cmd.exe
Cesta k chybujícímu modulu: C:\Windows\system32\cmd.exe
ID zprávy: 286cf445-d291-4703-9079-4c28b209e4d1
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (05/28/2026 11:16:39 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1480,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\Windows\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).
Error: (05/28/2026 11:15:47 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Systém Windows nemůže získat přístup k souboru z jednoho z těchto důvodů:
došlo k problému s připojením k síti, s diskem, na kterém je soubor uložen, nebo
s ovladači ukládání nainstalovanými v tomto počítači; nebo disk chybí.
Systém Windows kvůli této chybě ukončil program Windows Command Processor.
Program: Windows Command Processor
Soubor:
Hodnota chyby je uvedena v části Další údaje.
Akce uživatele
1. Otevřete soubor znovu.
Může se jednat o dočasný problém, který se při novém spuštění programu nebude opakovat.
2.
Pokud k souboru stále nelze získat přístup a:
- Nachází se v síti,
měl by správce sítě ověřit, zda nedošlo k problému se sítí a zda lze server kontaktovat.
- Je na vyměnitelném disku (například disketě nebo disku CD-ROM), ověřte, zda je disk správně vložen do počítače.
3. Zkontrolujte a opravte systém souborů pomocí nástroje CHKDSK. Ten lze spustit tak, že kliknete na tlačítko Start a příkaz Spustit, zadáte příkaz CMD a kliknete na tlačítko OK. Do příkazového řádku zadejte příkaz CHKDSK /F a stiskněte klávesu ENTER.
4. Pokud potíže potrvají, obnovte soubor ze záložní kopie.
5. Zjistěte, zda lze otevřít jiné soubory na stejném disku. Pokud ne, může být disk poškozen. Jedná-li se o pevný disk, obraťte se na správce nebo na dodavatele počítačového hardwaru
se žádostí o pomoc.
Další údaje
Hodnota chyby: 00000000
Typ disku: 0
Error: (05/28/2026 11:15:47 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: cmd.exe, verze: 10.0.18362.449, časové razítko: 0x98868d68
Název chybujícího modulu: cmd.exe, verze: 10.0.18362.449, časové razítko: 0x98868d68
Kód výjimky: 0xc000001d
Posun chyby: 0x00000000000182b0
ID chybujícího procesu: 0x1a68
Čas spuštění chybující aplikace: 0x01dcee8291b33f46
Cesta k chybující aplikaci: C:\Windows\system32\cmd.exe
Cesta k chybujícímu modulu: C:\Windows\system32\cmd.exe
ID zprávy: 5f960e2b-f7a3-4141-bcfb-55f11a0780cf
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (05/28/2026 07:40:24 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Systém Windows nemůže získat přístup k souboru z jednoho z těchto důvodů:
došlo k problému s připojením k síti, s diskem, na kterém je soubor uložen, nebo
s ovladači ukládání nainstalovanými v tomto počítači; nebo disk chybí.
Systém Windows kvůli této chybě ukončil program Windows Command Processor.
Program: Windows Command Processor
Soubor:
Hodnota chyby je uvedena v části Další údaje.
Akce uživatele
1. Otevřete soubor znovu.
Může se jednat o dočasný problém, který se při novém spuštění programu nebude opakovat.
2.
Pokud k souboru stále nelze získat přístup a:
- Nachází se v síti,
měl by správce sítě ověřit, zda nedošlo k problému se sítí a zda lze server kontaktovat.
- Je na vyměnitelném disku (například disketě nebo disku CD-ROM), ověřte, zda je disk správně vložen do počítače.
3. Zkontrolujte a opravte systém souborů pomocí nástroje CHKDSK. Ten lze spustit tak, že kliknete na tlačítko Start a příkaz Spustit, zadáte příkaz CMD a kliknete na tlačítko OK. Do příkazového řádku zadejte příkaz CHKDSK /F a stiskněte klávesu ENTER.
4. Pokud potíže potrvají, obnovte soubor ze záložní kopie.
5. Zjistěte, zda lze otevřít jiné soubory na stejném disku. Pokud ne, může být disk poškozen. Jedná-li se o pevný disk, obraťte se na správce nebo na dodavatele počítačového hardwaru
se žádostí o pomoc.
Další údaje
Hodnota chyby: 00000000
Typ disku: 0
Error: (05/28/2026 07:40:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: cmd.exe, verze: 10.0.18362.449, časové razítko: 0x98868d68
Název chybujícího modulu: cmd.exe, verze: 10.0.18362.449, časové razítko: 0x98868d68
Kód výjimky: 0xc000001d
Posun chyby: 0x00000000000182b0
ID chybujícího procesu: 0xc34
Čas spuštění chybující aplikace: 0x01dcee647b29bcd3
Cesta k chybující aplikaci: C:\Windows\system32\cmd.exe
Cesta k chybujícímu modulu: C:\Windows\system32\cmd.exe
ID zprávy: 8d7146ae-2fce-45db-a93c-d3e9cdccc307
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (05/28/2026 07:26:30 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 13 5.100.168.192.in-addr.arpa. PTR No-as.local.
System errors:
=============
Error: (05/28/2026 11:27:07 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba wuauserv byla ukončena s následující chybou:
Systém nemůže nalézt uvedený soubor.
Error: (05/28/2026 11:27:07 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.
Error: (05/28/2026 11:25:07 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba wuauserv byla ukončena s následující chybou:
Systém nemůže nalézt uvedený soubor.
Error: (05/28/2026 11:25:07 AM) (Source: DCOM) (EventID: 10010) (User: NOŤAS)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.
Error: (05/28/2026 11:23:07 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba wuauserv byla ukončena s následující chybou:
Systém nemůže nalézt uvedený soubor.
Error: (05/28/2026 11:23:07 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.
Error: (05/28/2026 11:21:07 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba wuauserv byla ukončena s následující chybou:
Systém nemůže nalézt uvedený soubor.
Error: (05/28/2026 11:21:07 AM) (Source: DCOM) (EventID: 10010) (User: NOŤAS)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.
Windows Defender:
================
Date: 2020-03-21 22:41:36.104
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {98657F1E-8680-4CCE-94A1-A077C5F66E0C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2020-03-19 20:57:46.592
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {FE8D7ADF-2D72-431B-8B91-AB63E279CA6A}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2020-03-18 19:47:18.566
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {36D017AC-1B3D-4AA8-8D42-0564EC175D29}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2020-03-18 18:21:07.747
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Tiggre!rfn
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\Lenovo\AppData\Local\Temp\Kill.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-AJUSQ3V\Lenovo
Název procesu: C:\Users\Lenovo\Desktop\Patch\Patch\Acronis True Image 2020 v24 Patch.exe
Verze bezpečnostních informací: AV: 1.311.1479.0, AS: 1.311.1479.0, NIS: 1.311.1479.0
Verze modulu: AM: 1.1.16800.2, NIS: 1.1.16800.2
Date: 2020-03-18 14:17:52.463
Description:
Antivirová ochrana v programu Windows Defender zjistil podezřelé chování.
Název: Behavior:Win32/ModifiedBootRecord
Závažnost: Nízké
Kategorie: Podezřelé chování
Nalezená cesta: file:_C:\Users\Lenovo\AppData\Local\Temp\un5005.exe; process:_1932
Původ detekce: Místní počítač
Typ detekce: Podezřelý
Zdroj detekce: Ochrana v reálném čase
Stav: Provádění
Uživatel: DESKTOP-AJUSQ3V\Lenovo
Název procesu: C:\Users\Lenovo\AppData\Local\Temp\un5005.exe
ID bezpečnostních informací: 23858570787236
Verze bezpečnostních informací: AV: 1.311.1454.0, AS: 1.311.1454.0
Verze modulu: 1.1.16800.2
Štítek věrnosti: Střední
Název cílového souboru:
==================== Memory info ===========================
BIOS: LENOVO 7ACN24WW 06/25/2013
Motherboard: LENOVO G700
Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 51%
Total physical RAM: 16263.35 MB
Available physical RAM: 7884 MB
Total Virtual: 26503.35 MB
Available Virtual: 14971.46 MB
==================== Drives ================================
Drive c: (MASTER) (Fixed) (Total:931.02 GB) (Free:801.82 GB) (Model: Samsung SSD 860 QVO 1TB) NTFS
Drive g: (Google Drive) (Fixed) (Total:15 GB) (Free:2.5 GB) (Model: Samsung SSD 860 QVO 1TB) FAT32
\\?\Volume{d5ebbff9-0000-0000-0000-100000000000}\ () (Fixed) (Total:0.49 GB) (Free:0.46 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: D5EBBFF9)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
==================== End of Addition.txt =======================

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Neobvyklé chování notebooku
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Ivošisko
- Návštěvník

- Příspěvky: 417
- Registrován: 04 říj 2006 11:26
- Bydliště: Ostrava/Jeseníky
- Kontaktovat uživatele:
Neobvyklé chování notebooku
Dík, Ivo.
- Rudy
- Site Admin

- Příspěvky: 119955
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Neobvyklé chování notebooku
Zdravím!
Mohl byster upřesnit, co si mám představit pod pojmem "neobvyklé"? Jinak zatím vyčistíme.
Otevřte poznámkový blok a zkopírujte do něj:
Mohl byster upřesnit, co si mám představit pod pojmem "neobvyklé"? Jinak zatím vyčistíme.
Otevřte poznámkový blok a zkopírujte do něj:
Uložte do C:\Users\Lenovo\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
S3 wuauserv; C:\Windows\system32\svchost.exe [53744 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 wuauserv; C:\Windows\SysWOW64\svchost.exe [45448 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
C:\Users\Lenovo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{B1D050AE-282F-DC81-EDA8-31C953EEDD86}\InprocServer32 -> C:\Program Files\Common Files\System\ole32.dll => No File
FirewallRules: [TCP Query User{44BEC590-9EC4-468C-9459-FD53497E74D2}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
FirewallRules: [UDP Query User{9239168C-0DB3-4DE5-9C77-1C0F79716338}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
C:\Users\Lenovo\AppData\Local\Temp\Kill.exe
EmptyTemp:
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
- Ivošisko
- Návštěvník

- Příspěvky: 417
- Registrován: 04 říj 2006 11:26
- Bydliště: Ostrava/Jeseníky
- Kontaktovat uživatele:
Re: Neobvyklé chování notebooku
Pod pojmem "neobvyklé" se např. skrývá blbnutí myši, kterou musím restartovat, vyskakování okýnek hlásících, že přestal pracovat Chrome či nějaká systémová část Win, je pomalejší na pokyny Enteru jak z klávesnice tak z myši, je obecně pomalejší atd.
Fix result of Farbar Recovery Scan Tool (x64) Version: 22-05-2026
Ran by Lenovo (29-05-2026 03:24:06) Run:11
Running from C:\Users\Lenovo\Downloads
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
*****************
==== End of Fixlog 03:24:06 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 22-05-2026
Ran by Lenovo (29-05-2026 03:24:06) Run:11
Running from C:\Users\Lenovo\Downloads
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
*****************
==== End of Fixlog 03:24:06 ====
Dík, Ivo.
- Rudy
- Site Admin

- Příspěvky: 119955
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Neobvyklé chování notebooku
OK, děkuji. To, co jste mi tu předložil, není ovšem fixlog, ale nějaý paskvil. Fixlog vypadá asi takto: https://forum.viry.cz/viewtopic.php?p=1 ... g#p1560863 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
- Ivošisko
- Návštěvník

- Příspěvky: 417
- Registrován: 04 říj 2006 11:26
- Bydliště: Ostrava/Jeseníky
- Kontaktovat uživatele:
Re: Neobvyklé chování notebooku
Fix result of Farbar Recovery Scan Tool (x64) Version: 22-05-2026
Ran by Lenovo (29-05-2026 11:22:10) Run:12
Running from C:\Users\Lenovo\Downloads
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
S3 wuauserv; C:\Windows\system32\svchost.exe [53744 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 wuauserv; C:\Windows\SysWOW64\svchost.exe [45448 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
C:\Users\Lenovo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{B1D050AE-282F-DC81-EDA8-31C953EEDD86}\InprocServer32 -> C:\Program Files\Common Files\System\ole32.dll => No File
FirewallRules: [TCP Query User{44BEC590-9EC4-468C-9459-FD53497E74D2}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
FirewallRules: [UDP Query User{9239168C-0DB3-4DE5-9C77-1C0F79716338}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
C:\Users\Lenovo\AppData\Local\Temp\Kill.exe
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\System\CurrentControlSet\Services\wuauserv => removed successfully
wuauserv => service removed successfully
wuauserv => service not found.
C:\Users\Lenovo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{B1D050AE-282F-DC81-EDA8-31C953EEDD86} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{44BEC590-9EC4-468C-9459-FD53497E74D2}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9239168C-0DB3-4DE5-9C77-1C0F79716338}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe" => removed successfully
"C:\Users\Lenovo\AppData\Local\Temp\Kill.exe" => not found
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 115149621 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 5907859 B
Edge => 144565065 B
Chrome => 1441046302 B
Firefox => 0 B
Opera => 0 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 3902 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Lenovo => 94017744 B
WgaUtilAcc => 0 B
RecycleBin => 368781563 B
EmptyTemp: => 2 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 11:23:04 ====
Ran by Lenovo (29-05-2026 11:22:10) Run:12
Running from C:\Users\Lenovo\Downloads
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
S3 wuauserv; C:\Windows\system32\svchost.exe [53744 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 wuauserv; C:\Windows\SysWOW64\svchost.exe [45448 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
C:\Users\Lenovo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
CustomCLSID: HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{B1D050AE-282F-DC81-EDA8-31C953EEDD86}\InprocServer32 -> C:\Program Files\Common Files\System\ole32.dll => No File
FirewallRules: [TCP Query User{44BEC590-9EC4-468C-9459-FD53497E74D2}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
FirewallRules: [UDP Query User{9239168C-0DB3-4DE5-9C77-1C0F79716338}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe] => (Block) C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe => No File
C:\Users\Lenovo\AppData\Local\Temp\Kill.exe
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\System\CurrentControlSet\Services\wuauserv => removed successfully
wuauserv => service removed successfully
wuauserv => service not found.
C:\Users\Lenovo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
HKU\S-1-5-21-760426430-1322398698-3842268529-1001_Classes\CLSID\{B1D050AE-282F-DC81-EDA8-31C953EEDD86} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{44BEC590-9EC4-468C-9459-FD53497E74D2}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9239168C-0DB3-4DE5-9C77-1C0F79716338}C:\program files\common files\adobe\adobe desktop common\hex\creative cloud ui helper.exe" => removed successfully
"C:\Users\Lenovo\AppData\Local\Temp\Kill.exe" => not found
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 115149621 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 5907859 B
Edge => 144565065 B
Chrome => 1441046302 B
Firefox => 0 B
Opera => 0 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 3902 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Lenovo => 94017744 B
WgaUtilAcc => 0 B
RecycleBin => 368781563 B
EmptyTemp: => 2 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 11:23:04 ====
Dík, Ivo.
- Rudy
- Site Admin

- Příspěvky: 119955
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Neobvyklé chování notebooku
Tohle je jiná káva.
Bylo smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Přispějete na provoz fóra?