prosím o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
havranec
Návštěvník
Návštěvník
Příspěvky: 156
Registrován: 02 Bře 2008 09:01

prosím o kontrolu

#1 Příspěvek od havranec »

Ahoj, po tejto hláške som nevedel spustiľ PC.
Prosím o kontrolu. Ďakujem
IMG_20260624_053832.jpg
IMG_20260624_053832.jpg (35.52 KiB) Zobrazeno 60 x
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-06-2026
Ran by User (administrator) on MOJEPC (LENOVO F0CM001FCK) (24-06-2026 07:13:32)
Running from C:\Users\User\Desktop\FRST64.exe
Loaded Profiles: User
Platform: Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) Language: Čeština (Česká republika) -> Slovenčina (Slovensko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\Avast Software\Avast\aswToolsSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\su_worker.exe
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Avast Software\Avast\AvLaunch.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe
(C:\Program Files\Avast Software\Avast\su_worker.exe ->) (Gen Digital Inc. -> OPSWAT, Inc.) C:\Program Files\Avast Software\Avast\wa_3rd_party_host_32.exe
(C:\Program Files\Avast Software\Avast\su_worker.exe ->) (Gen Digital Inc. -> OPSWAT, Inc.) C:\Program Files\Avast Software\Avast\wa_3rd_party_host_64.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_eaf2229d3baf8a09\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_eaf2229d3baf8a09\igfxEM.exe
(explorer.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvLaunch.exe
(explorer.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Cleanup\TuneupUI.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <3>
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Cleanup\TuneupUI.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <31>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvla.inf_amd64_a6a2da7e042e0376\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Cleanup\TuneupSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_eaf2229d3baf8a09\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_d8d8130c2588d45b\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_cff0174c1abadd0d\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_cff0174c1abadd0d\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_00637c565008e749\RstMwService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvla.inf_amd64_a6a2da7e042e0376\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Qualcomm Atheros, Inc. -> ) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.6465_none_7e0fb53c7c8be091\TiWorker.exe

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19573704 2024-12-01] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3619040 2024-12-01] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [1063080 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\...\Run: [Avast Cleanup UI] => C:\Program Files\Avast Software\Cleanup\TuneupUI.exe [7612640 2026-06-13] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM-x32\...\Run: [Lenovo Silver Silk Wireless Keyboard] => C:\Program Files (x86)\Lenovo\Lenovo Silver Silk Wireless Keyboard\skd8861.exe [1742336 2013-08-14] (Lenovo) [File not signed]
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [132587352 2025-02-01] (Western Digital Technologies, Inc. -> Western Digital Corporation)
HKLM-x32\...\Run: [eID_Client] => C:\Program Files (x86)\eID_klient\eID_Client.exe [23224728 2026-01-23] (Ministerstvo vnútra Slovenskej republiky -> )
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [751240 2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2581240 2026-05-14] (Wargaming Group Limited -> Wargaming.net)
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4751208 2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\Run: [Disig Web Signer] => C:\Program Files (x86)\Disig\Web Signer\WebSignerTray.exe [274296 2025-06-23] (Disig a.s. -> Disig a.s.)
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\Run: [LenovoVantage] => C:\ProgramData\Lenovo\Vantage\Addins\LenovoCompanionAppAddin\1.0.0.50\LenovoVantage.exe [39496 2025-12-09] (Lenovo -> Lenovo)
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\Run: [MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5304648 2026-06-17] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4464792 2026-06-19] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\149.0.7827.196\Installer\chrmstp.exe [7665304 2026-06-24] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {65E7CC0B-0268-4F30-B3C0-2706A190F737} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [9711840 2026-05-20] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {4C1A83BC-515D-4DD3-9485-1F0C16F17159} - System32\Tasks\Avast Software\Avast Cleanup BugReport => C:\Program Files\Avast Software\Cleanup\AvBugReport.exe [6618336 2026-06-13] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --silent --product 62 --programpath "C:\Program Files\Avast Software\Cleanup" --configpath "C:\ProgramData\Avast Software\Cleanup" --path "C:\ProgramData\Avast Software\Cleanup\log" --path "C:\ProgramData\Avast Software\Icarus\Logs" --logpath "C:\ProgramData\Avast Software\Cle (the data entry has 53 more characters).
Task: {7F1CA212-CC24-48C6-8ADE-7756404C6E4B} - System32\Tasks\Avast Software\Avast Cleanup Update => C:\Program Files\Common Files\Avast Software\Icarus\avast-tu\icarus.exe [9711840 2026-05-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {8E84954E-FB06-4FEC-887B-71080951EA3E} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5790376 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {5DE4F256-C57F-4940-86C9-A7621E5ED063} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2977504 2025-10-13] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {D2B549F9-D26B-451C-B053-E5A4B160AC80} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-1496144255-991381806-58249036-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [8070264 2026-06-03] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {84617B3D-4191-45FD-9FDC-1C4E28561A8F} - System32\Tasks\DUpdaterTask => C:\Program Files (x86)\Ditec\DUpdater\DUpdater.exe [5229632 2025-11-13] (DITEC, a.s. -> DITEC, a.s.)
Task: {D0912D07-99C6-4443-A51A-6D5331A05F02} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{5EBC45A7-52B9-417B-A0F7-4BE9F09C7039} => "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --wake --system (No File)
Task: {0FF6E57B-2A4C-4E64-9759-201C5648BA63} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem150.0.7863.0{0105E292-0EB7-46B3-B306-A1551D1A7FEE} => C:\Program Files (x86)\Google\GoogleUpdater\150.0.7863.0\updater.exe [6666392 2026-06-16] (Google LLC -> Google LLC)
Task: {A25AE7DD-1A09-404D-B63C-3E504BAA313F} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4464792 2026-06-19] (Google LLC -> Google LLC)
Task: {494B926E-FC40-4AB3-8DC2-903DE9CD286E} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Metrics => C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4464792 2026-06-19] (Google LLC -> Google LLC)
Task: {C63AB5A5-CF2B-470E-B85C-1EA3E4A51372} - System32\Tasks\IObit B5Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\b5en.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {6ADB1C86-4E22-4539-9D8D-55573E606557} - System32\Tasks\IObit DB2024B5 (One-Time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\dbrpop.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {5D9685BA-ED63-49D0-9BD1-8A66C864E96D} - System32\Tasks\IObit XM2024Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\xmsale.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {33A6F03E-0CB2-4443-9D12-3E5477AAFB0D} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [94496 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {CF8D520D-DF44-4698-B44E-DC2C975B0AD4} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => C:\WINDOWS\system32\sc.exe [72192 2019-12-07] (Microsoft Windows -> Microsoft Corporation) -> START ImControllerService
Task: {42D95DB7-BAF3-41D0-9B73-9A4EC2189C17} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => C:\WINDOWS\System32\reg.exe [77312 2019-12-07] (Microsoft Windows -> Microsoft Corporation) -> add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {5DAE9983-0805-4DF6-B673-287D52D89F6F} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\5526e6bb-d3eb-44cc-97e6-b269b76dd001 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {86879F1A-0DC5-4F16-8A65-4BA6D56550A1} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\7db5aa9e-b0ab-462d-b090-33d9d4801a62 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {0858D7B6-7B4D-4119-8309-D3ECC3902826} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\e3cb6407-5517-4c57-9e03-17407ae58e35 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {F8A94A1F-34E0-4851-B599-7C584E98585D} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-1496144255-991381806-58249036-1001 => C:\Users\User\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [91416 2025-04-29] (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {BC36B622-2CB0-48CA-866D-803BB502A423} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => C:\WINDOWS\system32\sc.exe [72192 2019-12-07] (Microsoft Windows -> Microsoft Corporation) -> start LenovoVantageService
Task: {42862E00-85B4-4AD7-8B8F-0E7DB8B25787} - System32\Tasks\Lenovo\Vantage\Schedule\BatteryGaugeAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {F731E14D-9362-4C3C-9689-8759AE053F57} - System32\Tasks\Lenovo\Vantage\Schedule\DailyTelemetryTransmission => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {CB6B57BC-7B65-4228-A158-01E3B0C1F3F9} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {742DE86E-71E2-4017-8D75-EA0ED8B87157} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin_Pulsation => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {7330C5E1-8706-4BDB-8550-C3D638ABE6BA} - System32\Tasks\Lenovo\Vantage\Schedule\HeartbeatAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {6AAE34A8-F0AF-4E51-9A89-70E4AD38DF44} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe Lenovo.Vantage.SmartPerformance.MonthlyReport (No File)
Task: {FC1DB179-5447-45D7-B682-82EBBB394DCD} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {72820E16-2B19-45E9-B58F-84C89FE9FC32} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {927D9F15-F4C5-4701-9064-4FCCCC44C848} - System32\Tasks\Lenovo\Vantage\Schedule\NotificationCenter => C:\Program Files (x86)\Lenovo\VantageService\3.13.72.0\ScheduleEventAction.exe NotificationCenter (No File)
Task: {87437392-2217-4F1C-8B1F-8A5AB94A7C31} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe SmartPerformance.ExpireReminder (No File)
Task: {8C0C6D18-534C-4A85-9506-28AD7380FA2A} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {EE0DF440-28CD-4196-A71D-3563CD2BD0EE} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinIdleScheduleTask => C:\ProgramData\Lenovo\Vantage\Addins\VantageCoreAddin\1.1.0.7\x86\IdleScheduleEventAction.exe [172104 2025-10-22] (Lenovo -> )
Task: {7D40F046-6B17-43C8-9C20-59199706DEF2} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinWeekScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\ScheduleEventAction.exe [276032 2025-12-03] (Lenovo -> Lenovo)
Task: {7FE9601A-A828-4954-A149-982C7C199F97} - System32\Tasks\Lenovo\Vantage\StartupFixPlan => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\\uninstall.exe /repair (No File)
Task: {FCA7A2B6-7DC6-43F1-B8B6-B93F1C320C82} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4406672 2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {E77DC8E4-CB4B-4AA6-9133-5504C09957A9} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1496144255-991381806-58249036-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4406672 2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {06C38258-BF1A-4AB2-8795-2079F9C73F6A} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1496144255-991381806-58249036-1001 => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\OneDriveLauncher.exe [761192 2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {A655C4FB-9FFB-4B94-B1BE-F4EA6D84A52D} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-1496144255-991381806-58249036-1001 => {201600D8-6EFF-48CE-B842-E14D37A0682D} C:\WINDOWS\System32\wpninprc.dll [24064 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {510A5CDE-77E7-44E3-9B3F-C1672652E879} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-1496144255-991381806-58249036-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [8070264 2026-06-03] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {066A7A8E-00FD-442A-8767-1742CEE5A924} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-1496144255-991381806-58249036-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [8070264 2026-06-03] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {4A4F5BF8-44D3-402A-A9E2-0C76E351DA0B} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6633736 2026-06-03] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {9CA05492-FFD2-4C57-9C30-EF2A1E4FCE49} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9274080 2026-01-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {F812F5C2-862D-4D15-9E8C-BA64A9EFA57F} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )
Task: {B8957A03-9264-47A3-A75D-0B1D03961031} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )
Task: {FD7C237A-D11D-457D-AFB1-EDD99DF42763} - System32\Tasks\WD Device Agent Task user => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Device Agent.exe [727384 2025-02-01] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
Task: {15097160-8BC1-449E-AEE7-DD51A4375499} - System32\Tasks\WD Discovery Service Task user => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [82264 2025-02-01] (Western Digital Technologies, Inc. -> )

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 88.212.8.8 88.212.8.88
Tcpip\..\Interfaces\{5c362e89-8288-4ab5-958b-95c3bff238f2}: [DhcpNameServer] 88.212.8.8 88.212.8.88
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}: [DhcpNameServer] 88.212.8.8 88.212.8.88
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}\445636F6F543735334: [DhcpNameServer] 192.168.68.1
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}\4505D2C494E4B4F573733414: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c8a8dfcb-a889-48f8-9307-d49bd92c8e62}\4505D2C494E4B4F583234323: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.491.2 -> C:\Program Files\Java\jre1.8.0_491\bin\dtplugin\npDeployJava1.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.491.2 -> C:\Program Files\Java\jre1.8.0_491\bin\plugin2\npjp2.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-31] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: ditec.sk/DitecNMc -> C:\PROGRA~2\Ditec\DLAUNC~1\NPDITE~1.DLL [2025-09-19] (DITEC, a.s. -> DITEC, a.s.)

Edge:
=======
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2026-06-24]
Edge Extension: (Dokumenty Google v režime offline) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-06-16]
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2026-06-24]
CHR Notifications: Default -> hxxps://gw.lightinthebox.com; hxxps://www.aliexpress.com; hxxps://www.wrenoin.com
CHR Session Restore: Default -> is enabled.
CHR Extension: (Authenticator) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhghoamapcdpbohphigoooaddinpkbai [2024-08-28]
CHR Extension: (Adblock pre Youtube™) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2026-06-10]
CHR Extension: (Split Screen for Google Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnollkdkikklpdganoecjcmmlddbennb [2025-11-26]
CHR Extension: (D.Bridge 2) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngbdhimbgbonhlibfmiemipheabfdmj [2026-03-17]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-06-18]
CHR Extension: (AVG SafePrice) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2026-06-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Guest Profile [2025-07-05]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\System Profile [2024-12-24]
CHR HKU\S-1-5-21-1496144255-991381806-58249036-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]

Opera:
=======
OPR DefaultProfile: Opera Stable
OPR Profile: C:\Users\User\AppData\Roaming\Opera Software\Opera Stable [2026-05-22]
OPR DefaultSearchURL: Opera Stable -> hxxps://www.google.com/search?client=opera&q={s ... utEncoding}
OPR DefaultSearchKeyword: Opera Stable -> g
OPR Extension: (Rich Hints Agent) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2023-09-22]
OPR Extension: (Opera Wallet) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\gojhcdgcpbpfigcaejpfhfegekdgiblk [2023-09-22]
OPR Extension: (Aria) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\igpdmclhhlcpoindmhkhillbfhdgoegm [2023-09-22]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8029864 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [1042600 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2747560 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1095336 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvastCleanupSvc; C:\Program Files\Avast Software\Cleanup\TuneupSvc.exe [22259936 2026-06-13] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2026-01-20] (Avast Software s.r.o. -> AVAST Software)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [30663800 2026-06-03] (Gen Digital Inc. -> Gen Digital Inc.)
S4 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [189464 2020-06-02] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
S4 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncHelper.exe [3616616 2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
S4 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\4.2511.18.0\LenovoVantageService.exe [34368 2025-12-03] (Lenovo -> Lenovo)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpDefenderCoreService.exe [2063376 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.106.0603.0003\OneDriveUpdaterService.exe [4026728 2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [189808 2023-03-19] (Qualcomm Atheros, Inc. -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\NisSrv.exe [4426832 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe [290704 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 GoogleUpdaterInternalService138.0.7194.0; "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --system --windows-service --service=update-internal (No File)
S2 GoogleUpdaterService138.0.7194.0; "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --system --windows-service --service=update (No File)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvla.inf_amd64_a6a2da7e042e0376\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvla.inf_amd64_a6a2da7e042e0376\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [21088 2026-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [259160 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [451168 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [315488 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [87136 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [29144 2026-01-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [34912 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [294496 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [636512 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [100960 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [71768 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [911456 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1292896 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [250464 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [472672 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 GemCCID; C:\WINDOWS\System32\DriverStore\FileRepository\gemccid.inf_amd64_526ec61d10ad09ec\GemCCID.sys [162992 2025-05-15] (Thales DIS CPL USA, Inc. -> Gemalto)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333192 2025-11-18] (Microsoft Windows -> Microsoft Corporation)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [347224 2024-12-01] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [21928 2025-12-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [635272 2025-12-18] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102792 2025-12-18] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)

==================== SvcHost (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-06-24 05:53 - 2026-06-24 07:14 - 000033798 ____C C:\Users\User\Desktop\FRST.txt
2026-06-24 05:52 - 2026-06-24 07:13 - 000000000 ___DC C:\FRST
2026-06-24 05:52 - 2026-06-24 05:52 - 002449920 ____C (Farbar) C:\Users\User\Desktop\FRST64.exe
2026-06-20 19:35 - 2026-06-20 19:35 - 000447104 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-06-18 16:28 - 2026-06-18 16:28 - 000001036 ____C C:\Users\User\Desktop\Telegram.lnk
2026-06-16 07:56 - 2026-06-16 07:58 - 000000000 ___DC C:\Users\User\Desktop\svetla
2026-06-16 07:55 - 2026-06-16 08:36 - 000000000 ___DC C:\Users\User\Desktop\obklad
2026-06-16 07:55 - 2026-06-16 07:55 - 000000000 ___DC C:\Users\User\Desktop\modra led
2026-06-16 07:54 - 2026-06-16 07:59 - 000000000 ___DC C:\Users\User\Desktop\nakupy
2026-06-12 13:40 - 2026-06-12 13:41 - 000000000 ___DC C:\Users\User\AppData\Local\Viber
2026-06-08 06:37 - 2026-06-08 06:37 - 025747456 ____C C:\Users\User\Downloads\5adca1d3-57ca-4218-851b-1e35da035e0d.tmp
2026-06-08 05:21 - 2026-06-08 05:21 - 000000000 ____D C:\WINDOWS\Panther
2026-06-02 12:10 - 2026-06-02 12:10 - 000324264 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2026-06-01 08:04 - 2026-06-01 08:04 - 000118325 ____C C:\Users\User\Downloads\1967764502_67-L764502.PDF

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-06-24 07:12 - 2019-05-30 22:02 - 000000000 _SHDC C:\Users\User\IntelGraphicsProfiles
2026-06-24 06:04 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-06-24 06:04 - 2019-05-30 21:42 - 000000000 ____D C:\ProgramData\NVIDIA
2026-06-24 06:03 - 2025-07-14 05:58 - 000001255 ____C C:\Users\User\Desktop\TreeSize Free.lnk
2026-06-24 06:03 - 2022-12-28 12:40 - 000001091 ____C C:\Users\User\Desktop\EseeCloud.lnk
2026-06-24 05:51 - 2020-12-06 08:56 - 001693350 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-06-24 05:51 - 2019-12-07 16:41 - 000716770 _____ C:\WINDOWS\system32\perfh005.dat
2026-06-24 05:51 - 2019-12-07 16:41 - 000144948 _____ C:\WINDOWS\system32\perfc005.dat
2026-06-24 05:51 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2026-06-24 05:49 - 2025-07-09 07:18 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-06-24 05:49 - 2025-07-09 07:18 - 000002030 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-06-24 05:49 - 2025-07-09 07:17 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-06-24 05:49 - 2025-02-07 19:47 - 000003534 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-1496144255-991381806-58249036-1001
2026-06-24 05:49 - 2021-12-17 21:08 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-06-24 05:49 - 2021-12-11 08:21 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1496144255-991381806-58249036-1001
2026-06-24 05:48 - 2022-09-13 06:31 - 000000000 ____D C:\WINDOWS\Minidump
2026-06-24 05:48 - 2019-10-10 07:51 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps
2026-06-24 05:47 - 2025-10-17 15:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH
2026-06-24 05:44 - 2020-12-06 08:52 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-06-24 05:44 - 2020-12-06 08:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-06-24 05:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2026-06-24 05:44 - 2019-05-30 21:47 - 000000000 __HDC C:\Intel
2026-06-24 05:23 - 2019-06-05 11:06 - 000002320 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-06-23 12:42 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-06-21 16:30 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-06-21 12:04 - 2019-06-05 11:35 - 000000000 ___DC C:\Users\User\AppData\Roaming\ViberPC
2026-06-21 10:59 - 2019-06-25 09:44 - 000000000 ____D C:\Users\User\AppData\Local\D3DSCache
2026-06-21 06:16 - 2025-12-14 11:16 - 000002394 _____ C:\WINDOWS\system32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-1496144255-991381806-58249036-1001
2026-06-21 06:16 - 2024-12-04 08:38 - 000002738 _____ C:\WINDOWS\system32\Tasks\IObit XM2024Sale (One-time)
2026-06-21 06:16 - 2024-12-01 08:59 - 000002734 _____ C:\WINDOWS\system32\Tasks\IObit DB2024B5 (One-Time)
2026-06-21 06:16 - 2024-12-01 08:59 - 000002726 _____ C:\WINDOWS\system32\Tasks\IObit B5Sale (One-time)
2026-06-21 06:16 - 2020-12-06 08:52 - 000003568 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-06-21 06:16 - 2020-12-06 08:52 - 000003342 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-06-21 06:16 - 2020-12-06 08:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2026-06-21 05:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2026-06-20 18:40 - 2020-06-10 10:27 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-06-18 16:28 - 2021-10-26 17:34 - 000000000 ___DC C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
2026-06-18 16:28 - 2021-10-26 17:33 - 000000000 ____D C:\Users\User\AppData\Roaming\Telegram Desktop
2026-06-18 04:32 - 2025-07-09 17:19 - 000000000 ___DC C:\Users\User\Documents\ViberDownloads
2026-06-16 05:59 - 2019-05-30 22:02 - 000000000 ___DC C:\Users\User\AppData\Local\Packages
2026-06-13 06:22 - 2019-05-30 21:40 - 000000000 ____D C:\ProgramData\Package Cache
2026-06-12 13:53 - 2019-06-05 11:35 - 000000000 ___DC C:\Users\User\AppData\Roaming\Microsoft\Spelling
2026-06-12 06:55 - 2019-06-05 03:17 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-06-12 06:53 - 2019-06-05 03:17 - 222431176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-06-07 17:52 - 2019-06-05 11:36 - 000000000 ___DC C:\Users\User\AppData\Roaming\uTorrent
2026-06-06 09:58 - 2019-06-07 07:24 - 000000000 ___DC C:\Users\User\AppData\Roaming\Microsoft\Excel
2026-06-03 05:08 - 2019-06-05 07:13 - 000000000 ____D C:\ProgramData\Packages
2026-06-03 05:02 - 2020-01-08 07:08 - 000000000 ____D C:\ProgramData\AVAST Software
2026-06-03 05:01 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-06-02 13:18 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-06-02 12:10 - 2026-01-20 07:47 - 001292896 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSP.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000911456 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSnx.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000636512 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswNetHub.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000472672 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswVmm.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000451168 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000315488 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000294496 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000259160 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswArPot.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000100960 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000087136 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000071768 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2026-06-02 12:10 - 2026-01-20 07:47 - 000034912 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswKbd.sys
2026-05-29 06:49 - 2019-06-05 15:55 - 000000000 ___DC C:\Users\User\AppData\Roaming\Microsoft\Word

==================== Files in the root of some directories ========

2025-12-20 20:55 - 2025-12-20 20:57 - 000000156 _____ () C:\Users\User\AppData\Local\Support.ini

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-06-2026
Ran by User (24-06-2026 07:14:30)
Running from C:\Users\User\Desktop
Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) (2020-12-06 06:52:43)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-1496144255-991381806-58249036-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-1496144255-991381806-58249036-503 - Limited - Disabled)
Guest (S-1-5-21-1496144255-991381806-58249036-501 - Limited - Disabled)
User (S-1-5-21-1496144255-991381806-58249036-1001 - Administrators - Enabled) => C:\Users\User
WDAGUtilityAccount (S-1-5-21-1496144255-991381806-58249036-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 26.01 (HKLM-x32\...\{23170F69-40C1-2701-2601-000001000000}) (Version: 26.01.00.0 - Igor Pavlov)
Aktualizácia Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-041B-0000-0000000FF1CE}_ENTERPRISE_{9A8C39B0-D27F-4F81-BE74-2FECF164707E}) (Version: - Microsoft)
Aktualizácia Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-041B-0000-0000000FF1CE}_ENTERPRISE_{CE23B3DC-18CC-46FC-A309-81D6670F8D3D}) (Version: - Microsoft)
Aktualizácia Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-041B-0000-0000000FF1CE}_ENTERPRISE_{D6DBF512-87C0-4F6A-8FB9-AC3A389D9DE5}) (Version: - Microsoft)
Asistent pri aktualizácii na Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.19041.2183 - Microsoft Corporation)
Avast Cleanup Premium (HKLM\...\Avast Cleanup) (Version: 26.6.18763.23678 - Gen Digital Inc.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 26.5.10994.3655 - Gen Digital Inc.)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1697.6 - AVAST Software) Hidden
Balík softvéru eID (HKLM-x32\...\{d2c66c1e-5862-43e7-abe2-9c895312112c}) (Version: 1.0.0.0 - Ministerstvo vnútra Slovenskej republiky) Hidden
Bit4id - miniLector (HKLM-x32\...\Bit4id - miniLector) (Version: 3.7 - Bit4id)
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.8.1355.1753 - Piriform)
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1208.2 - Piriform Software) Hidden
D.Launcher 2 (x86) (HKLM-x32\...\{CFE4937D-8637-4B4B-98C0-2881D62C852A}) (Version: 2.0.6 - DITEC, a.s.)
D.Signer .NET (x86) (HKLM-x32\...\{C01F20C6-781C-4C84-B590-A722FD900F6D}) (Version: 5.0.6 - DITEC, a.s.)
D.Suite/eIDAS (x86) (HKLM-x32\...\{4eebacc2-e9c3-416e-bd0c-977032af626c}) (Version: 2.0.6 - DITEC, a.s.)
D.Updater (x86) (HKLM-x32\...\{E9AA3192-DFC8-409A-A6C3-0187FBE75E5C}) (Version: 1.0.11 - DITEC, a.s.)
D.Viewer .NET (x86) (HKLM-x32\...\{6D6056AE-69E6-417A-9A67-B89A755FD10F}) (Version: 5.0.5 - DITEC, a.s.)
Disig Web Signer (HKLM-x32\...\{E3783679-5BB4-42BD-825D-7E83005D7D1D}) (Version: 2.5.2 - Disig)
Dolby Audio X2 Windows API SDK (HKLM\...\{FA0735B6-9E18-437A-A1CD-9152650FC52B}) (Version: 0.8.8.90 - Dolby Laboratories, Inc.)
Dolby Audio X2 Windows APP (HKLM\...\{D0D32569-4680-490A-905C-5117CEAAB3EF}) (Version: 0.8.8.76 - Dolby Laboratories, Inc.)
eID Klient (x86) (HKLM-x32\...\{B350DDA1-0243-4E2C-B18B-DC7C15126E97}) (Version: 5.3.0 - MV SR)
EseeCloud 3.0.3 (HKLM-x32\...\EseeCloud) (Version: 3.0.3 - My company, Inc.)
GemPcCCID (HKLM\...\{C2C14C20-A217-4FCA-B668-89B6C70B6EFF}) (Version: 2.0.7 - Gemalto)
Google Chrome (HKLM\...\{9E87E7EE-9308-35AF-9824-D9F2919C9AAF}) (Version: 149.0.7827.196 - Google LLC)
Intel(R) Chipset Device Software (HKLM\...\{94E05108-3E4E-4F2E-AC5F-33A1B22B779C}) (Version: 10.1.1.44 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2105.15.0.2157 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{A9B23394-82C4-4885-92F6-5C21D2AFAF14}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{AF5173C2-31A0-45CF-A5DF-F964F35B4034}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Driver (HKLM\...\{322B58FC-7AB5-43B6-B27C-1635DD3A573C}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) ME UninstallLegacy (HKLM\...\{E9B9A1A5-6398-4C99-8FDE-10794F6505C5}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.7757 - Intel Corporation)
Intel(R) Trusted Connect Service Client x64 (HKLM\...\{C9552825-7BF2-4344-BA91-D3CD46F4C442}) (Version: 1.62.321.1 - Intel Corporation) Hidden
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.62.321.1 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{c3964069-17c1-45dd-85a5-949576ceeaa3}) (Version: 1.62.321.1 - Intel Corporation) Hidden
Java 8 Update 491 (64-bit) (HKLM\...\{71024AE4-039E-4CA4-87B4-2F64180491F0}) (Version: 8.0.4910.10 - Oracle Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Lenovo Service Bridge (HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 5.0.2.18 - Lenovo)
Lenovo Silver Silk Wireless Keyboard (HKLM-x32\...\{B88AD4F5-58A6-425D-9282-92228FEB7067}) (Version: 1.05 - Lenovo) Hidden
Lenovo Silver Silk Wireless Keyboard (HKLM-x32\...\InstallShield_{B88AD4F5-58A6-425D-9282-92228FEB7067}) (Version: 1.05 - Lenovo)
Lenovo System Update (HKLM-x32\...\TVSU_is1) (Version: 5.08.03.59 - Lenovo)
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 4.2511.18.0 - Lenovo Group Ltd.)
Microsoft Edge (HKLM-x32\...\{C3BC0439-C155-3FDC-BE20-61B3E52E9E6C}) (Version: 149.0.4022.80 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 149.0.4022.80 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0015-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0016-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0018-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0019-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001A-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001B-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-041B-1000-0000000FF1CE}_ENTERPRISE_{8382BA92-20E3-47B6-971B-F673F0492D4E}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0044-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-006E-041B-0000-0000000FF1CE}_ENTERPRISE_{8382BA92-20E3-47B6-971B-F673F0492D4E}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-00A1-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-00BA-041B-0000-0000000FF1CE}_ENTERPRISE_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0015-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Excel MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0016-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (Slovak) 2007 (HKLM-x32\...\{90120000-00BA-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0044-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Slovak) 2007 (HKLM-x32\...\{90120000-00A1-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Slovak) 2007 (HKLM-x32\...\{90120000-001A-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0018-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Hungarian) 2007 (HKLM-x32\...\{90120000-001F-040E-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Slovak) 2007 (HKLM-x32\...\{90120000-002C-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1039 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-040E-0000-0000000FF1CE}_ENTERPRISE_{0AD4BB83-13B4-4C9D-9BAC-7F64E0B2D5D7}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}) (Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (Slovak) 2007 (HKLM-x32\...\{90120000-0019-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Slovak) 2007 (HKLM\...\{90120000-002A-041B-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Slovak) 2007 (HKLM-x32\...\{90120000-006E-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Slovak) 2007 (HKLM-x32\...\{90120000-001B-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.106.0603.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{FEA4AB50-D01D-4E6C-AC61-B2ACF1501CEE}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{4E004F00-9000-4EBC-8660-2C10404143ED}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.51.36247 (HKLM\...\{6FA797CF-6B76-4B6D-87EE-768F92008720}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.51.36247 (HKLM\...\{931A2CF0-2404-45EA-82F5-345735AE6A90}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.51.36247 (HKLM-x32\...\{582BA719-E6F1-4651-A873-049E6A0DDDAF}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.51.36247 (HKLM-x32\...\{4BF7CE18-E151-449F-9190-6CDBED0BB4A2}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.51.36247 (HKLM-x32\...\{0e3bb569-69d6-4c34-bff9-c2f81db5e5f0}) (Version: 14.51.36247.0 - Microsoft Corporation)
Microsoft Visual C++ v14 Redistributable (x86) - 14.51.36247 (HKLM-x32\...\{9a6ce18d-11c0-4452-aa35-9f2b8437c686}) (Version: 14.51.36247.0 - Microsoft Corporation)
neroxml (HKLM-x32\...\{56C049BE-79E9-4502-BEA7-9754A3E60F9B}) (Version: 1.0.0 - Nero AG) Hidden
NirSoft Wireless Network Watcher (HKLM-x32\...\NirSoft Wireless Network Watcher) (Version: - )
NVIDIA Ovladače grafiky 531.68 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 531.68 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
OptaneDowngradeGuard (HKLM\...\{86B0E6C1-32E0-42CC-BC4F-BF3C0730CECB}) (Version: 18.0.0.0 - Intel Corporation) Hidden
PDF PW Locker Remover (HKLM-x32\...\{25889EF9-CD9A-4A83-96F1-1AC7371429DE}) (Version: 3.3.2 - PDF Protect Free)
Qualcomm Atheros 11ac Wireless LAN Installer (HKLM-x32\...\{20CA507E-24AA-4741-87CF-CC1B250790B7}) (Version: 11.0.10442 - Qualcomm)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.29093 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.19.627.2017 - Realtek)
RstDowngradeGuard (HKLM\...\{13C2A26E-7AD4-4D82-BB4F-DEA6E871B958}) (Version: 18.0.0.0 - Intel Corporation) Hidden
TAP-Windows 9.24.2 (HKLM\...\TAP-Windows) (Version: 9.24.2 - OpenVPN Technologies, Inc.)
Telegram Desktop (HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 6.9.3 - Telegram FZ-LLC)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 11.57 - Ghisler Software GmbH)
TreeSize Free V4.8.1 (HKLM\...\TreeSize Free_is1) (Version: 4.8.1 - JAM Software)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
Viber (HKLM-x32\...\{BCFF3282-3299-47F2-95C3-3C0165260EB2}) (Version: 10.3.0.36 - Viber Media S.a.r.l) Hidden
Viber (HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\{8ce90cb2-6f65-4b26-bd5c-e9627995f807}) (Version: 28.1.0.0 - Viber Media S.a.r.l)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-2) (Version: 1.0.54.1 - LunarG, Inc.) Hidden
Wargaming.net Game Center (HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\Wargaming.net Game Center) (Version: 26.2.0.2387 - Wargaming.net)
WD Desktop App 2.1.0.335 (HKLM-x32\...\{fdd55732-32b6-4783-9b31-db9ad9f96792}) (Version: 2.1.0.335 - Western Digital Corporation) Hidden
WD Desktop App 2.1.0.335 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.335 - Western Digital Corporation) Hidden
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 5.1.618 - Western Digital Technologies, Inc.)
WD SES Driver Setup (HKLM-x32\...\{D9ABF771-729C-471F-A6DF-1010527DB376}) (Version: 2.1.0 - Western Digital) Hidden
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
World of Tanks EU (HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\2314027414) (Version: - Wargaming.net)
World_of_Warships (HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\WOWS.WW.PRODUCTION) (Version: - Wargaming.net)

Packages:
=========
Adobe Acrobat Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC [2025-09-03] ()
Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1042.0_x64__8j3eq9eme6ctt [2025-05-05] (INTEL CORP)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2603.12.0_x64__k1h2ywk1493x8 [2026-04-27] (LENOVO INC.)
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_3.0.43.0_x64__w1wdnht996qgy [2025-12-20] (LinkedIn) [Startup Task]
Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.19127.20622.0_x86__8wekyb3d8bbwe [2026-05-18] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-06-05] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-06-05] (Microsoft Corporation) [MS Ad]
Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.19127.20622.0_x86__8wekyb3d8bbwe [2026-05-18] (Microsoft Corporation)
Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.19127.20622.0_x86__8wekyb3d8bbwe [2026-05-18] (Microsoft Corporation)
Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.19127.20622.0_x86__8wekyb3d8bbwe [2026-05-18] (Microsoft Corporation)
Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.19127.20622.0_x86__8wekyb3d8bbwe [2026-05-18] (Microsoft Corporation)
Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.19127.20622.0_x86__8wekyb3d8bbwe [2026-05-18] (Microsoft Corporation)
Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.19127.20622.0_x86__8wekyb3d8bbwe [2026-05-18] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-11-16] (NVIDIA Corp.)
Ovládacie centrum pre grafiku Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2024-11-16] (INTEL CORP) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1496144255-991381806-58249036-1001_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1496144255-991381806-58249036-1001_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1496144255-991381806-58249036-1001_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1496144255-991381806-58249036-1001_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1496144255-991381806-58249036-1001_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1496144255-991381806-58249036-1001_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1496144255-991381806-58249036-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
SSODL: WDFSMountNotificator-wdfsconnect2017 - {B7221D65-6632-4B2A-926A-00386CBCE4DF} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {B7221D65-6632-4B2A-926A-00386CBCE4DF} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects: Virtual Storage Mount Notification -> {B7221D65-6632-4B2A-926A-00386CBCE4DF} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects-x32: Virtual Storage Mount Notification -> {B7221D65-6632-4B2A-926A-00386CBCE4DF} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2217832 2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2026-04-27] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [Avast Cleanup Premium] -> {13004120-FCAF-4232-A255-807EAD6E7D01} => C:\Program Files\Avast Software\Cleanup\tucontextmenu.dll [2026-05-22] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [WDDesktopContextMenu] -> {f97d48aa-d72e-39ad-bf37-0b90de70ca2a} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-08-22] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-08-22] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2026-04-27] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [Avast Cleanup Premium] -> {13004120-FCAF-4232-A255-807EAD6E7D01} => C:\Program Files\Avast Software\Cleanup\tucontextmenu.dll [2026-05-22] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers4: [WDDesktopContextMenu] -> {f97d48aa-d72e-39ad-bf37-0b90de70ca2a} => C:\Program Files\WD Desktop App\kda.DLL [2022-09-29] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.106.0603.0003\FileSyncShell64.dll [2026-06-24] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvla.inf_amd64_a6a2da7e042e0376\nvshext.dll [2023-05-26] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2026-04-27] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers6: [Avast Cleanup Premium] -> {13004120-FCAF-4232-A255-807EAD6E7D01} => C:\Program Files\Avast Software\Cleanup\tucontextmenu.dll [2026-05-22] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-08-22] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-08-22] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1496144255-991381806-58249036-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_491\bin\ssv.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_491\bin\jp2ssv.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-09-29 15:46 - 2017-09-29 15:44 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2023-08-29 06:56 - 2023-08-29 06:56 - 000000446 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 88.212.8.8 - 88.212.8.88
Windows Firewall is enabled.

Network Binding:
=============
Připojení k místní síti: TAP-Windows Adapter V9 -> tap0901.sys
Wi-Fi: Qualcomm Atheros QCA9377 Wireless Network Adapter -> Qcamain10x64.sys
Síťové připojení Bluetooth 3: Bluetooth Device (Personal Area Network) #3 -> bthpan.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\java8path;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;c:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;c:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\eID_klient\;C:\Program Files (x86)\eID_klient\redist_x64\
HKU\S-1-5-21-1496144255-991381806-58249036-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\9502458037340498332\133665610328138647.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\StartupFolder: => "Cloudflare WARP.lnk"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "RtHDVBg_Dolby"
HKLM\...\StartupApproved\Run: => "RTHDVCPL"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKLM\...\StartupApproved\Run32: => "Lenovo Silver Silk Wireless Keyboard"
HKLM\...\StartupApproved\Run32: => "EAC_MW_klient"
HKLM\...\StartupApproved\Run32: => "WDDiscovery"
HKLM\...\StartupApproved\Run32: => "eID_Client"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_EA977365BF5B2185FA52414E130E9AF9"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "Wargaming.net Game Center"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "eyeBeam SIP Client"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "Disig Web Signer"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "LenovoVantage"
HKU\S-1-5-21-1496144255-991381806-58249036-1001\...\StartupApproved\Run: => "AvastBrowserAutoLaunch_DD3B34B51295CA4CE249213732CEC2F8"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{2A0F24BE-0417-4B7C-82E0-AEA49A5356A2}C:\users\user\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\user\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [TCP Query User{3EFEAA9B-8E1C-466F-9831-189CE8295854}C:\users\user\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\user\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [UDP Query User{6080D66F-0A15-409F-B9A3-D282267C8458}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [TCP Query User{517FA03E-29DF-4BDE-95D1-91029A573004}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{019D165E-A783-4C39-86D3-0A8FD000C4D1}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [TCP Query User{D4A89DBE-2E5C-4FBE-93ED-9F06AF475218}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [TCP Query User{D7BB254C-3614-49B3-A3BB-BE7E93812E12}C:\users\user\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\user\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [UDP Query User{9758F37C-1793-44E7-A5B7-D2D28DF780EF}C:\users\user\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\user\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [TCP Query User{CEDD63DE-AE5E-4D08-84FE-3220C65B3BB0}C:\games\world_of_tanks_eu\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{64DCF168-9DCF-4125-BDB5-E881E6203267}C:\games\world_of_tanks_eu\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [TCP Query User{44905811-9B97-4AE0-B73F-958796A7B300}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{E5EA4172-128A-49AE-BD0F-4CA1CE87067D}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [{BC60B747-848A-47CF-B5BF-6089E8D7CFF4}] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [{CFE743D3-8BF9-4736-B25C-C035E8E17071}] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [TCP Query User{D50A21ED-BEFD-495C-9E92-52774C1256E6}C:\users\user\appdata\local\viber\viber.exe] => (Allow) C:\users\user\appdata\local\viber\viber.exe (Viber Media S.a r.l. -> Viber Media S.à r.l.)
FirewallRules: [UDP Query User{4C422C61-43B3-47DA-80B6-4B31EFA74A69}C:\users\user\appdata\local\viber\viber.exe] => (Allow) C:\users\user\appdata\local\viber\viber.exe (Viber Media S.a r.l. -> Viber Media S.à r.l.)
FirewallRules: [TCP Query User{AB882D7B-A6FD-4E27-8CD1-81130BCFB503}C:\users\user\appdata\roaming\telegram desktop\telegram.exe] => (Allow) C:\users\user\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
FirewallRules: [UDP Query User{7F80D843-15C9-429D-89A2-1345EABCE936}C:\users\user\appdata\roaming\telegram desktop\telegram.exe] => (Allow) C:\users\user\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
FirewallRules: [{6CC495C7-51BD-4B6B-AF14-8BF90DAC3E5A}] => (Block) C:\users\user\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
FirewallRules: [{B44FBF90-BE2C-490A-B5C0-86409A6D627F}] => (Block) C:\users\user\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
FirewallRules: [TCP Query User{B457D1F4-52DC-4E29-B4B0-A3868001E334}C:\program files (x86)\eseecloud\eseecloud.exe] => (Allow) C:\program files (x86)\eseecloud\eseecloud.exe (Guangzhou Yuege Electronic Trading Co., Ltd. -> comelit, Inc.)
FirewallRules: [UDP Query User{D058892F-FE80-4A14-8BB8-86F9BED7B59B}C:\program files (x86)\eseecloud\eseecloud.exe] => (Allow) C:\program files (x86)\eseecloud\eseecloud.exe (Guangzhou Yuege Electronic Trading Co., Ltd. -> comelit, Inc.)
FirewallRules: [{8847DA20-9CC3-4A2C-B9E8-1ABF180D68E8}] => (Block) C:\program files (x86)\eseecloud\eseecloud.exe (Guangzhou Yuege Electronic Trading Co., Ltd. -> comelit, Inc.)
FirewallRules: [{AC6B875D-0DE8-4C93-9305-4AD521DF65FF}] => (Block) C:\program files (x86)\eseecloud\eseecloud.exe (Guangzhou Yuege Electronic Trading Co., Ltd. -> comelit, Inc.)
FirewallRules: [TCP Query User{8F808F16-DDBE-4245-9211-B9C0E544C7ED}C:\program files\java\jre1.8.0_361\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_361\bin\javaw.exe => No File
FirewallRules: [UDP Query User{64AEE14F-13BC-4878-AC7C-9CFB18A8CE1B}C:\program files\java\jre1.8.0_361\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_361\bin\javaw.exe => No File
FirewallRules: [TCP Query User{1E105D05-C78A-461F-BDFE-00B9839E5A25}C:\users\user\appdata\local\viber\viber.exe] => (Block) C:\users\user\appdata\local\viber\viber.exe (Viber Media S.a r.l. -> Viber Media S.à r.l.)
FirewallRules: [UDP Query User{1B184AAA-3CEE-4291-81B1-888517BCE708}C:\users\user\appdata\local\viber\viber.exe] => (Block) C:\users\user\appdata\local\viber\viber.exe (Viber Media S.a r.l. -> Viber Media S.à r.l.)
FirewallRules: [{28E67EDD-6A95-493E-97F1-9524FF6B3CEE}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{9867829F-8B67-4F3A-B07B-933892544728}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{AD85D06D-F212-439A-84D6-4D74F4A1449A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.137.3425.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8D055B55-8AE6-4D94-B8C2-FBD037D56CE2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.137.3425.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E71BCC52-ABCE-4B5F-B8D1-0CE45A4D5C2B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.137.3425.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E800EC33-1417-4DA9-AA90-E49B004D86BE}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.137.3425.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{784F98AC-8CCC-485F-99E9-BC501D33AFCB}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{68F4CFC3-E6EB-483E-BAE3-80F888AA6685}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{BC265D4B-D118-4B20-BB57-DE5C5AE7DFD0}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.19127.20622.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F39C8260-6582-4661-8555-D236780F7600}] => (Allow) C:\Program Files\Avast Software\Cleanup\TuneupUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{A7E31BE2-9BB5-4FE2-8DDC-0E914797E643}] => (Allow) C:\Program Files\Avast Software\Cleanup\TuneupUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{2B1DB8AF-2DA7-4769-B04D-153DB26B1DA4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============
Name: Qualcomm Atheros QCA9377 Bluetooth
Description: Qualcomm Atheros QCA9377 Bluetooth
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Qualcomm
Service: BTHUSB
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: ========================

Application errors:
==================
Error: (06/22/2026 04:10:40 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiska nemohol dokončiť opakovat operaci trim v (D:), pretože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (06/21/2026 04:37:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: wmplayer.exe, verzia: 12.0.19041.3636, časová značka: 0xd2d3ea02
Názov chybujúceho modulu: combase.dll, verzia: 10.0.19041.6456, časová značka: 0x56ffdb9e
Kód výnimky: 0xc0000005
Odstup chyby: 0x00143154
Identifikácia chybujúceho procesu: 0xc90
Čas spustenia chybujúcej aplikácie: 0x01dd018b66f384f0
Cesta chybujúcej aplikácie: C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Cesta chybujúceho modulu: C:\WINDOWS\System32\combase.dll
Identifikácia hlásenia: 556e8186-ef43-45b1-8c73-ed85f52c7e07
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (06/21/2026 04:36:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: wmplayer.exe, verzia: 12.0.19041.3636, časová značka: 0xd2d3ea02
Názov chybujúceho modulu: combase.dll, verzia: 10.0.19041.6456, časová značka: 0x56ffdb9e
Kód výnimky: 0xc0000005
Odstup chyby: 0x00143154
Identifikácia chybujúceho procesu: 0x40d4
Čas spustenia chybujúcej aplikácie: 0x01dd018b626964aa
Cesta chybujúcej aplikácie: C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Cesta chybujúceho modulu: C:\WINDOWS\System32\combase.dll
Identifikácia hlásenia: 3f7c6411-90f6-402b-9afd-0d78af360eb6
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (06/21/2026 04:23:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: wmplayer.exe, verzia: 12.0.19041.3636, časová značka: 0xd2d3ea02
Názov chybujúceho modulu: combase.dll, verzia: 10.0.19041.6456, časová značka: 0x56ffdb9e
Kód výnimky: 0xc0000005
Odstup chyby: 0x00143154
Identifikácia chybujúceho procesu: 0x33ac
Čas spustenia chybujúcej aplikácie: 0x01dd01897562af1b
Cesta chybujúcej aplikácie: C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Cesta chybujúceho modulu: C:\WINDOWS\System32\combase.dll
Identifikácia hlásenia: 62855a59-6419-4940-ae1a-950abf10586d
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (06/21/2026 05:04:37 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Windows\System32\svchost.exe, PID: 8964, ProfSvc PID: 2016.

Error: (06/21/2026 05:04:37 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Program Files\Avast Software\Avast\aswToolsSvc.exe, PID: 3864, ProfSvc PID: 2016.

Error: (06/21/2026 05:04:37 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe, PID: 5144, ProfSvc PID: 2016.

Error: (06/20/2026 07:37:32 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe, PID: 5976, ProfSvc PID: 2164.


System errors:
=============
Error: (06/24/2026 05:49:55 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: FirmwareVersion:O2NKT14A;OEMManufacturerName:LENOVO;OEMModelSKU:LENOVO_MT_F0CM_BU_LENOVO_FM_ideacentre AIO 720-24IKB;OSArchitecture:amd64;
BucketId: 666424fb88d879e464b4c5fbe0b478add39bfe73d674c4a70cae0a1138dd7269
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (06/24/2026 05:46:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby Služba Aktualizace Google (gupdate) zlyhalo kvôli nasledujúcej chybe:
The service did not respond to the start or control request in a timely fashion.

Error: (06/24/2026 05:46:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Počas čakania na pripojenie služby Služba Aktualizace Google (gupdate) bol dosiahnutý časový limit (60000 ms).

Error: (06/24/2026 05:45:09 AM) (Source: BugCheck) (EventID: 1001) (User: )
Description: Počítač sa po kontrole chýb reštartoval. Kontrola chýb: 0x00000124 (0x0000000000000010, 0xffffa78a84ed8028, 0xffffa78a6b69609c, 0xffffa78a6b65b1a0). Výpis sa uložil do súboru: C:\WINDOWS\MEMORY.DMP. Identifikácia hlásenia: eb9b6918-7369-41b8-b4c1-23f8b7862e66.

Error: (06/24/2026 05:44:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby GoogleUpdaterInternalService138.0.7194.0 zlyhalo kvôli nasledujúcej chybe:
The system cannot find the file specified.

Error: (06/24/2026 05:44:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby GoogleUpdaterService138.0.7194.0 zlyhalo kvôli nasledujúcej chybe:
The system cannot find the file specified.

Error: (06/24/2026 05:44:54 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:52:15 on ‎23.‎06.‎2026 was unexpected.

Error: (06/24/2026 05:26:28 AM) (Source: DCOM) (EventID: 10010) (User: MOJEPC)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.

Error: (06/16/2026 09:49:37 AM) (Source: disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR2.

Error: (06/16/2026 09:49:34 AM) (Source: disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR2.

Error: (06/08/2026 06:47:21 PM) (Source: disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk3\DR3.


Windows Defender:
================
Date: 2026-01-19 11:27:55
Description:
Antivirová ochrana v programu Microsoft Defender scan has been stopped before completion.
Scan Type: Antimalwarový program
Scan Parameters: Rychlé prohledávání
Stop Reason: Şĉĥеδũĺέđ şĉāⁿ ŵāѕ ŝĸïφрёď вëčάùśε ŧĥе ℓдśт ŝůĉčęśśƒűł ѕčåñ щāś ώϊţђĭи ŧĥě ℓàŝт 7 ďàŷѕ

Date: 2026-01-18 06:04:06
Description:
Antivirová ochrana v programu Microsoft Defender scan has been stopped before completion.
Scan Type: Antimalwarový program
Scan Parameters: Rychlé prohledávání
Stop Reason: Şĉĥеδũĺέđ şĉāⁿ ŵāѕ ŝĸïφрёď вëčάùśε ŧĥе ℓдśт ŝůĉčęśśƒűł ѕčåñ щāś ώϊţђĭи ŧĥě ℓàŝт 7 ďàŷѕ

Date: 2026-01-17 20:25:01
Description:
Antivirová ochrana v programu Microsoft Defender scan has been stopped before completion.
Scan Type: Antimalwarový program
Scan Parameters: Rychlé prohledávání
Stop Reason: Şĉĥеδũĺέđ şĉāⁿ ŵāѕ ŝĸïφрёď вëčάùśε ŧĥе ℓдśт ŝůĉčęśśƒűł ѕčåñ щāś ώϊţђĭи ŧĥě ℓàŝт 7 ďàŷѕ

Date: 2026-01-16 06:36:48
Description:
Antivirová ochrana v programu Microsoft Defender scan has been stopped before completion.
Scan Type: Antimalwarový program
Scan Parameters: Rychlé prohledávání
Stop Reason: ΓΡ€ çоňиέčťíбʼn ŗúⁿδόώй

Date: 2026-01-16 06:04:30
Description:
Antivirová ochrana v programu Microsoft Defender scan has been stopped before completion.
Scan Type: Antimalwarový program
Scan Parameters: Rychlé prohledávání
Stop Reason: ΓΡ€ çоňиέčťíбʼn ŗúⁿδόώй
Event[0]:

Date: 2025-07-15 11:22:48
Description:
Antivirová ochrana v programu Microsoft Defender has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Aktuální
Error Code: 0x80070003
Error description: Systém nemůže nalézt uvedenou cestu.
Security intelligence Version: 0.0.0.0;0.0.0.0
Engine Version: 0.0.0.0

Date: 2025-07-14 18:59:53
Description:
Antivirová ochrana v programu Microsoft Defender has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Aktuální
Error Code: 0x80070003
Error description: Systém nemůže nalézt uvedenou cestu.
Security intelligence Version: 0.0.0.0;0.0.0.0
Engine Version: 0.0.0.0

Date: 2025-07-01 19:09:06
Description:
Antivirová ochrana v programu Microsoft Defender has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Aktuální
Error Code: 0x80501102
Error description: Došlo k neočekávaným potížím. Nainstalujte všechny dostupné aktualizace a potom opakujte spuštění programu. Informace o instalaci aktualizací naleznete v nápovědě a podpoře.
Security intelligence Version: 1.431.331.0;1.431.331.0
Engine Version: 1.1.25050.6

Date: 2025-06-30 08:06:59
Description:
Antivirová ochrana v programu Microsoft Defender has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Zálohování
Error Code: 0x80004004
Error description: Operace přerušena
Security intelligence Version: 1.431.283.0;1.431.283.0
Engine Version: 1.1.25050.6

Date: 2025-06-30 08:06:59
Description:
Antivirová ochrana v programu Microsoft Defender has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Aktuální
Error Code: 0x80004004
Error description: Operace přerušena
Security intelligence Version: 1.431.300.0;1.431.300.0
Engine Version: 1.1.25050.6

CodeIntegrity:
===============
Date: 2026-06-13 05:50:55
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Avast Software\Avast\AvastSvc.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: LENOVO O2NKT14A 12/06/2016
Motherboard: LENOVO 0x36BF
Processor: Intel(R) Core(TM) i7-7700 CPU @ 3.60GHz
Percentage of memory in use: 84%
Total physical RAM: 8091.23 MB
Available physical RAM: 1215.02 MB
Total Virtual: 16795.23 MB
Available Virtual: 8866.78 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:117.89 GB) (Free:5.41 GB) (Model: SAMSUNG MZVLW128HEGR-000L1) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:644.36 GB) (Model: WDC WD10EZEX-08WN4A0) NTFS
Drive e: (Elements) (Fixed) (Total:1862.98 GB) (Free:67.36 GB) (Model: WD Elements 2620 USB Device) NTFS

\\?\Volume{4bac9e1f-892f-4d84-8532-a01cb260de31}\ (WinRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.27 GB) NTFS
\\?\Volume{003ce010-b35e-46c2-9700-b79d3c51d944}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: FB131764)

Partition: GPT.

==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: FB131755)

Partition: GPT.

==========================================================
Disk: 2 (Size: 1863 GB) (Disk ID: 16F2A91F)

Partition: GPT.

==================== End of Addition.txt =======================

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120014
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosím o kontrolu

#2 Příspěvek od Rudy »

Zdravím!
Hláška znamená "Kontrola medií, start PXE =přes Ipv 4"

Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [751240 2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {D0912D07-99C6-4443-A51A-6D5331A05F02} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{5EBC45A7-52B9-417B-A0F7-4BE9F09C7039} => "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --wake --system (No File)
Task: {C63AB5A5-CF2B-470E-B85C-1EA3E4A51372} - System32\Tasks\IObit B5Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\b5en.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {6ADB1C86-4E22-4539-9D8D-55573E606557} - System32\Tasks\IObit DB2024B5 (One-Time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\dbrpop.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {5D9685BA-ED63-49D0-9BD1-8A66C864E96D} - System32\Tasks\IObit XM2024Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\xmsale.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {927D9F15-F4C5-4701-9064-4FCCCC44C848} - System32\Tasks\Lenovo\Vantage\Schedule\NotificationCenter => C:\Program Files (x86)\Lenovo\VantageService\3.13.72.0\ScheduleEventAction.exe NotificationCenter (No File)
Task: {87437392-2217-4F1C-8B1F-8A5AB94A7C31} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe SmartPerformance.ExpireReminder (No File)
ask: {6AAE34A8-F0AF-4E51-9A89-70E4AD38DF44} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe Lenovo.Vantage.SmartPerformance.MonthlyReport (No File)
Task: {7FE9601A-A828-4954-A149-982C7C199F97} - System32\Tasks\Lenovo\Vantage\StartupFixPlan => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\\uninstall.exe /repair (No File)
S2 GoogleUpdaterInternalService138.0.7194.0; "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --system --windows-service --service=update-internal (No File)
C C:\Users\User\Downloads\5adca1d3-57ca-4218-851b-1e35da035e0d.tmp
FirewallRules: [TCP Query User{8F808F16-DDBE-4245-9211-B9C0E544C7ED}C:\program files\java\jre1.8.0_361\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_361\bin\javaw.exe => No File
FirewallRules: [UDP Query User{64AEE14F-13BC-4878-AC7C-9CFB18A8CE1B}C:\program files\java\jre1.8.0_361\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_361\bin\javaw.exe => No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

havranec
Návštěvník
Návštěvník
Příspěvky: 156
Registrován: 02 Bře 2008 09:01

Re: prosím o kontrolu

#3 Příspěvek od havranec »

Fix result of Farbar Recovery Scan Tool (x64) Version: 24-06-2026
Ran by User (24-06-2026 15:37:06) Run:1
Running from C:\Users\User\Desktop
Loaded Profiles: User
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [751240 2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {D0912D07-99C6-4443-A51A-6D5331A05F02} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{5EBC45A7-52B9-417B-A0F7-4BE9F09C7039} => "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --wake --system (No File)
Task: {C63AB5A5-CF2B-470E-B85C-1EA3E4A51372} - System32\Tasks\IObit B5Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\b5en.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {6ADB1C86-4E22-4539-9D8D-55573E606557} - System32\Tasks\IObit DB2024B5 (One-Time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\dbrpop.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {5D9685BA-ED63-49D0-9BD1-8A66C864E96D} - System32\Tasks\IObit XM2024Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\xmsale.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {927D9F15-F4C5-4701-9064-4FCCCC44C848} - System32\Tasks\Lenovo\Vantage\Schedule\NotificationCenter => C:\Program Files (x86)\Lenovo\VantageService\3.13.72.0\ScheduleEventAction.exe NotificationCenter (No File)
Task: {87437392-2217-4F1C-8B1F-8A5AB94A7C31} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe SmartPerformance.ExpireReminder (No File)
ask: {6AAE34A8-F0AF-4E51-9A89-70E4AD38DF44} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe Lenovo.Vantage.SmartPerformance.MonthlyReport (No File)
Task: {7FE9601A-A828-4954-A149-982C7C199F97} - System32\Tasks\Lenovo\Vantage\StartupFixPlan => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\\uninstall.exe /repair (No File)
S2 GoogleUpdaterInternalService138.0.7194.0; "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --system --windows-service --service=update-internal (No File)
C C:\Users\User\Downloads\5adca1d3-57ca-4218-851b-1e35da035e0d.tmp
FirewallRules: [TCP Query User{8F808F16-DDBE-4245-9211-B9C0E544C7ED}C:\program files\java\jre1.8.0_361\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_361\bin\javaw.exe => No File
FirewallRules: [UDP Query User{64AEE14F-13BC-4878-AC7C-9CFB18A8CE1B}C:\program files\java\jre1.8.0_361\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_361\bin\javaw.exe => No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D0912D07-99C6-4443-A51A-6D5331A05F02}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0912D07-99C6-4443-A51A-6D5331A05F02}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{5EBC45A7-52B9-417B-A0F7-4BE9F09C7039} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{5EBC45A7-52B9-417B-A0F7-4BE9F09C7039}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C63AB5A5-CF2B-470E-B85C-1EA3E4A51372}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C63AB5A5-CF2B-470E-B85C-1EA3E4A51372}" => removed successfully
C:\WINDOWS\System32\Tasks\IObit B5Sale (One-time) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IObit B5Sale (One-time)" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6ADB1C86-4E22-4539-9D8D-55573E606557}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6ADB1C86-4E22-4539-9D8D-55573E606557}" => removed successfully
C:\WINDOWS\System32\Tasks\IObit DB2024B5 (One-Time) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IObit DB2024B5 (One-Time)" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5D9685BA-ED63-49D0-9BD1-8A66C864E96D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D9685BA-ED63-49D0-9BD1-8A66C864E96D}" => removed successfully
C:\WINDOWS\System32\Tasks\IObit XM2024Sale (One-time) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IObit XM2024Sale (One-time)" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{927D9F15-F4C5-4701-9064-4FCCCC44C848}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927D9F15-F4C5-4701-9064-4FCCCC44C848}" => removed successfully
C:\WINDOWS\System32\Tasks\Lenovo\Vantage\Schedule\NotificationCenter => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\Vantage\Schedule\NotificationCenter" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87437392-2217-4F1C-8B1F-8A5AB94A7C31}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87437392-2217-4F1C-8B1F-8A5AB94A7C31}" => removed successfully
C:\WINDOWS\System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder" => removed successfully
ask: {6AAE34A8-F0AF-4E51-9A89-70E4AD38DF44} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe Lenovo.Vantage.SmartPerformance.MonthlyReport (No File) => Error: No automatic fix found for this entry.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7FE9601A-A828-4954-A149-982C7C199F97}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7FE9601A-A828-4954-A149-982C7C199F97}" => removed successfully
C:\WINDOWS\System32\Tasks\Lenovo\Vantage\StartupFixPlan => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\Vantage\StartupFixPlan" => removed successfully
HKLM\System\CurrentControlSet\Services\GoogleUpdaterInternalService138.0.7194.0 => removed successfully
GoogleUpdaterInternalService138.0.7194.0 => service removed successfully
C C:\Users\User\Downloads\5adca1d3-57ca-4218-851b-1e35da035e0d.tmp => Error: No automatic fix found for this entry.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8F808F16-DDBE-4245-9211-B9C0E544C7ED}C:\program files\java\jre1.8.0_361\bin\javaw.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{64AEE14F-13BC-4878-AC7C-9CFB18A8CE1B}C:\program files\java\jre1.8.0_361\bin\javaw.exe" => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 786432 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 24342544 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 1935650 B
Edge => 2085400 B
Chrome => 596290311 B
Firefox => 0 B
Opera => 0 B

Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 52400 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
User => 234662245 B

RecycleBin => 79104526 B
EmptyTemp: => 895.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 15:37:51 ====

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120014
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosím o kontrolu

#4 Příspěvek od Rudy »

Bylo smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

havranec
Návštěvník
Návštěvník
Příspěvky: 156
Registrován: 02 Bře 2008 09:01

Re: prosím o kontrolu

#5 Příspěvek od havranec »

Zatiaľ nevidím žiadny problém. Ďakujem

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120014
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosím o kontrolu

#6 Příspěvek od Rudy »

OK, nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět