Prosím o kontrolu, podezření na hack

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
basto
Návštěvník
Návštěvník
Příspěvky: 62
Registrován: 06 Lis 2008 15:08

Prosím o kontrolu, podezření na hack

#1 Příspěvek od basto »

Zdravím, prosím o kontrolu. V průběhu dvou dní se někdo dostal do dvou mých různých účtů (LinkedIn, Messenger) a to i přes kódy...

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-07-2026 01
Ran by jiria (administrator) on AMMERCEHOVINTB (LENOVO 82K2) (22-07-2026 09:12:33)
Running from C:\Users\jiria\Desktop\FRST64.exe
Loaded Profiles: jiria
Platform: Microsoft Windows 11 Pro Version 25H2 26200.8655 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe
(Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe
(Brother Industries, Ltd. -> Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Brother\BrUtilities\BrLogRx.exe
(C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe ->) (Brother Industries, Ltd. -> Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
(C:\Program Files\Avira\Endpoint Protection SDK\endpointprotection.exe ->) (Avira Operations GmbH -> Avira Operations GmbH) C:\Program Files\Avira\Endpoint Protection SDK\SentryEye.exe
(C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSSrcExt.exe
(C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\cncmd.exe
(C:\Users\jiria\AppData\Roaming\BitTorrent Web\btweb.exe ->) () [File not signed] C:\Users\jiria\AppData\Roaming\BitTorrent Web\crashpad_handler.exe
(C:\Users\jiria\AppData\Roaming\BitTorrent Web\btweb.exe ->) (BitTorrent Inc -> BitTorrent Inc.) C:\Users\jiria\AppData\Roaming\BitTorrent Web\helper\helper.exe
(C:\Users\jiria\AppData\Roaming\BitTorrent Web\btweb.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.65\msedgewebview2.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\FnHotkeyCapsLKNumLK.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\FnHotkeyUtility.exe
(DriverStore\FileRepository\u0417253.inf_amd64_a9b363c4f94f001d\B417132\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0417253.inf_amd64_a9b363c4f94f001d\B417132\atieclxx.exe
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(explorer.exe ->) (Avira Operations GmbH -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.WebAppHost.exe
(explorer.exe ->) (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Brother\SoftwareUpdateNotification\SoftwareUpdateNotificationService.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.ScreenSketch_11.2602.49.0_x64__8wekyb3d8bbwe\SnippingTool\SnippingTool.exe <3>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9366beb5d0043df3\RtkAudUService64.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <16>
(iPSMonitor) [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\iPSMonitor.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.98\msedgewebview2.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.65\msedgewebview2.exe <6>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoNotificationUx.exe
(NahimicService.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicAPO4Volume.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_b3badde551342cd6\Display.NvContainer\NVDisplay.Container.exe
(Rainberry Inc -> BitTorrent Limited) C:\Users\jiria\AppData\Roaming\BitTorrent Web\btweb.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\UsbAppControl\USBAppControl.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl\WorkflowAppControl.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0417253.inf_amd64_a9b363c4f94f001d\B417132\atiesrxx.exe
(services.exe ->) (Anthropic, PBC -> ) C:\Program Files\WindowsApps\Claude_1.20186.0.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe
(services.exe ->) (Avira Operations GmbH -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
(services.exe ->) (Avira Operations GmbH -> Avira Operations GmbH) C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe
(services.exe ->) (Avira Operations GmbH -> Avira Operations GmbH) C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe
(services.exe ->) (Avira Operations GmbH -> Avira Operations GmbH) C:\Program Files\Avira\Endpoint Protection SDK\endpointprotection.exe
(services.exe ->) (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BrYNSvc.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\13.743.3.6251-1784374787\EA Desktop\EABackgroundService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrsr.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_b3badde551342cd6\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9366beb5d0043df3\RtkAudUService64.exe
(services.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(SteelSeries France SASU -> A-Volute) C:\Windows\System32\NhNotifSys.exe
(svchost.exe ->) (Avira Operations GmbH -> Avira Operations GmbH) C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Systray.Application.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.Edge.GameAssist_1.0.3456.0_x64__8wekyb3d8bbwe\EdgeGameAssist.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2606.1001.29.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.302.5.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe <7>

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9366beb5d0043df3\RtkAudUService64.exe [1987544 2024-05-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [M17A] => C:\WINDOWS\twain_32\Brimm17a\Common\TwDsUiLaunch.exe [89168 2024-06-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [162600 2024-04-18] (Brother Industries, Ltd. -> Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4009984 2024-05-31] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [BrotherSoftwareUpdateNotification] => C:\Program Files (x86)\Brother\SoftwareUpdateNotification\SoftwareUpdateNotificationService.exe [3588608 2021-04-02] (Brother Industries, Ltd.) [File not signed]
HKLM\...\RunOnce: [msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}] => C:\Program Files (x86)\Microsoft\Edge\Application\150.0.4078.83\Installer\setup.exe [5379912 2026-07-18] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [btweb] => C:\Users\jiria\AppData\Roaming\BitTorrent Web\btweb.exe [9507944 2026-06-16] (Rainberry Inc -> BitTorrent Limited)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [5773976 2026-06-25] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [Spotify] => C:\Users\jiria\AppData\Roaming\Spotify\Spotify.exe [2916736 2026-05-20] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [f.lux] => C:\Users\jiria\AppData\Local\FluxSoftware\Flux\flux.exe [1535600 2025-03-14] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [Discord] => C:\Users\jiria\AppData\Local\Discord\Update.exe [1516408 2025-05-27] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [45052888 2026-06-24] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3352952 2026-07-18] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [] => [X]
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [MicrosoftEdgeAutoLaunch_73832D297F06EBCEA19791C06580FEE0] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\jiria\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [128938384 2026-07-11] (Microsoft Corporation -> Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\jiria\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) <==== ATTENTION
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\RunOnce: [Uninstall 26.106.0603.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\jiria\AppData\Local\Microsoft\OneDrive\26.106.0603.0003" (No File)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\MountPoints2: {e27270ad-b687-11f0-a89b-e160180bdc39} - "D:\autorun.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\150.0.7871.125\Installer\chrmstp.exe [7681176 2026-07-18] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Brother iPSMonitor.lnk [2026-07-02]
ShortcutTarget: Brother iPSMonitor.lnk -> C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\iPSMonitor.exe (iPSMonitor) [File not signed]

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {2ECABAA6-F4FE-4535-A033-13A1A4119A90} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {7E4249E9-D390-461B-908B-814375539845} - System32\Tasks\Avira_FallbackUpdater => C:\Windows\System32\sc.exe [102400 2025-07-12] (Microsoft Windows -> Microsoft Corporation) -> start AviraFallbackUpdater Delayed=false
Task: {8AFF11DC-6E4E-4B15-ABE0-49FC58C86364} - System32\Tasks\Avira_Security_Maintenance => Command(1): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> FallbackTelemetry
Task: {8AFF11DC-6E4E-4B15-ABE0-49FC58C86364} - System32\Tasks\Avira_Security_Maintenance => Command(2): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> ServiceWatchdog
Task: {8AFF11DC-6E4E-4B15-ABE0-49FC58C86364} - System32\Tasks\Avira_Security_Maintenance => Command(3): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> CrashCollector
Task: {E9AB497B-C72F-4BE6-A3D1-0BBA37AB8B4E} - System32\Tasks\Avira_Security_Service_SCM_Watchdog => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe [264040 2026-06-18] (Avira Operations GmbH -> Avira Operations GmbH)
Task: {A1491005-8F11-4160-8AC9-174D5C8D4440} - System32\Tasks\Avira_Security_Systray => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Systray.Application.exe [1801216 2026-06-18] (Avira Operations GmbH -> Avira Operations GmbH)
Task: {5570B6E1-68E4-421A-A405-0F15506DD5E2} - System32\Tasks\Avira_Security_Update => C:\Windows\System32\net.exe [81920 2025-11-12] (Microsoft Windows -> Microsoft Corporation)
Task: {ECF8F287-4A0E-41A8-B166-8766CE055C61} - System32\Tasks\AviraSystemSpeedupVerify => C:\Program Files (x86)\Avira\System Speedup\setup\avira_speedup_setup.exe [37089224 2026-01-26] (Avira Operations GmbH -> Avira Operations GmbH)
Task: {93AEC675-5938-47A2-BED4-964C49E04288} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{A1F9FCA2-8193-47A6-8774-FE3A841C6825} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC)
Task: {0C380F4F-A7A7-4D33-A897-17BEAE9D50C4} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC)
Task: {520CBAFF-B938-4993-9148-305267CBC4A5} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Metrics => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {542EA79E-EFA8-4872-954E-C5FEC31CDB8E} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3337328 2026-01-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A28712AB-B5C7-4338-9497-ACCD5D64F419} - System32\Tasks\Ubisoft\Ubisoft Connect Background Update => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe [17255600 2026-03-16] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
Task: {8A58571C-FC40-4770-9720-C8EB9F84FD2B} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-791795520-2065237621-642244014-1001 => C:\Users\jiria\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-26] (Zoom Communications, Inc. -> Zoom Communications, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}\0535953484F445542514059454: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}\6596B647F62796E602275637964656E63656: [DhcpNameServer] 10.0.1.138
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}\6596B647F62796E602275637964656E63656: [DhcpDomain] home
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}\65F6461666F6E656D283434414: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}\7696761636572656D2133313830333: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}\84E696A746F60223C243: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63f2ab49-6bdf-4680-b6f3-917172365e48}\84E696A746F60223C243: [DhcpDomain] home
Tcpip\..\Interfaces\{c5fbb261-deaf-4b99-a590-e17c50af87a6}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c5fbb261-deaf-4b99-a590-e17c50af87a6}: [DhcpDomain] home

FireFox:
========
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-06-24] (Adobe Inc. -> Adobe Systems Inc.)

Edge:
=======
Edge Profile: C:\Users\jiria\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-22]
Edge Extension: (Avira Safe Shopping) - C:\Users\jiria\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caiblelclndcckfafdaggpephhgfpoip [2026-06-04]
Edge Extension: (Avira Password Manager) - C:\Users\jiria\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\emgfgdclgfeldebanedpihppahgngnle [2026-04-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\jiria\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-06-30]
Edge Extension: (Edge relevant text changes) - C:\Users\jiria\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-04-05]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default [2026-07-22]
CHR Session Restore: Default -> is enabled.
CHR Extension: (Avira Password Manager) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2025-03-23]
CHR Extension: (Avira Safe Shopping) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2026-06-16]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-07-07]
CHR Extension: (I don't care about cookies) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2025-03-01]
CHR Extension: (Avira Browser Safety) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2025-12-28]
CHR Extension: (Dokumenty Google offline) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-06-30]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2026-07-22]
CHR Extension: (Calculator) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhhlmhdllknkepmabbkhnlbaddllabl [2025-03-01]
CHR Extension: (Grammarly: AI Writing Assistant and Grammar Checker App) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2026-07-10]
CHR Extension: (Marinara: Pomodoro® Assistant) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\lojgmehidjdhhbmpjfamhpkpodfcodef [2025-03-01]
CHR Extension: (Consent-O-Matic) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdjildafknihdffpkfmmpnpoiajfjnjd [2025-03-01]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2025-03-01]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-03-01]
CHR Profile: C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 1 [2026-07-06]
CHR Notifications: Profile 1 -> hxxps://www.youtube.com
CHR Extension: (Avira Password Manager) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2025-03-23]
CHR Extension: (Avira Safe Shopping) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2026-06-01]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-07-06]
CHR Extension: (Avira Browser Safety) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2026-01-12]
CHR Extension: (Dokumenty Google offline) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-03-23]
CHR Profile: C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 2 [2025-12-11]
CHR Session Restore: Profile 2 -> is enabled.
CHR Extension: (Avira Password Manager) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2025-05-29]
CHR Extension: (Avira Safe Shopping) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2025-12-06]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-12-11]
CHR Extension: (Avira Browser Safety) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2025-05-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\jiria\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-05-29]
CHR Profile: C:\Users\jiria\AppData\Local\Google\Chrome\User Data\System Profile [2026-06-30]
CHR HKU\S-1-5-21-791795520-2065237621-642244014-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
S2 AviraFallbackUpdater; C:\Program Files (x86)\Avira\Fallback Updater\Avira.Spotlight.FallbackUpdater.exe [6803256 2026-04-21] (Avira Operations GmbH -> Avira Operations GmbH)
R2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2977248 2024-07-16] (Avira Operations GmbH -> Avira Operations GmbH)
R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [404560 2026-07-01] (Avira Operations GmbH -> Avira Operations GmbH & Co. KG)
R2 AviraSecurity; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe [271128 2026-06-18] (Avira Operations GmbH -> Avira Operations GmbH)
S2 AviraSecurityUpdater; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Common.Updater.exe [302096 2026-06-18] (Avira Operations GmbH -> Avira Operations GmbH)
R2 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [512512 2026-01-07] (Brother Industries, Ltd.) [File not signed]
R2 CoworkVMService; C:\Program Files\WindowsApps\Claude_1.20186.0.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe [12664656 2026-07-09] (Anthropic, PBC -> )
R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [18076024 2026-07-18] (Electronic Arts, Inc. -> Electronic Arts)
S2 EndpointProtectionService; C:\Program Files\Avira\Endpoint Protection SDK\endpointprotection.exe [13616920 2026-07-18] (Avira Operations GmbH -> Avira Operations GmbH)
R3 EndpointProtectionService2; C:\Program Files\Avira\Endpoint Protection SDK\endpointprotection.exe [13616920 2026-07-18] (Avira Operations GmbH -> Avira Operations GmbH)
R2 LenovoFnAndFunctionKeys; C:\WINDOWS\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_5e21bf389d23855a\LenovoUtilityService.exe [199744 2026-03-09] (Lenovo -> Lenovo)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe [2009608 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1910192 2024-05-20] (SteelSeries France SASU -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_b3badde551342cd6\Display.NvContainer\NVDisplay.Container.exe [1275624 2026-01-22] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [877528 2026-06-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 UpcElevationService; C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher Core\UpcElevationService.exe [351928 2026-03-16] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
R2 USBAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\UsbAppControl\USBAppControl.exe [11776 2026-04-28] () [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe [4538400 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe [278320 2025-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WorkflowAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl\WorkflowAppControl.exe [20992 2026-04-28] () [File not signed]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdfendrmgr; C:\WINDOWS\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrmgr.sys [25672 2024-04-23] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0417253.inf_amd64_a9b363c4f94f001d\B417132\amdkmdag.sys [106597288 2025-07-14] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R2 amd_dpfc; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_b3badde551342cd6\amd_dpfc.sys [47848 2026-01-22] (NVIDIA Corporation -> Advanced Micro Devices)
R0 BdNet; C:\WINDOWS\System32\DRIVERS\BdNet.sys [179768 2025-02-19] (Microsoft Windows Hardware Compatibility Publisher -> Avira Operations GmbH)
R1 BdSentry; C:\WINDOWS\System32\DRIVERS\BdSentry.sys [223296 2025-02-19] (Microsoft Windows Hardware Compatibility Publisher -> Avira Operations GmbH)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [230896 2026-06-11] (Microsoft Windows -> Microsoft Corporation)
R3 hidgamepad; C:\WINDOWS\System32\DriverStore\FileRepository\hidgamepad.inf_amd64_56d2c8f6cb7b593e\hidgamepad.sys [61440 2026-06-11] (Microsoft Windows -> Microsoft Corporation)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-04-10] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [144872 2026-06-11] (Microsoft Windows -> Microsoft Corporation)
R3 MTKBTFilterx64; C:\WINDOWS\System32\DriverStore\FileRepository\mtkbtfilter.inf_amd64_56acba6f25d7988d\mtkbtfilterx.sys [368336 2024-06-06] (MEDIATEK INC. -> MediaTek Inc.)
R3 mtkwlex; C:\WINDOWS\System32\DriverStore\FileRepository\mtkwl6ex.inf_amd64_62674278b895f437\mtkwl6ex.sys [1710272 2024-06-06] (MEDIATEK INC. -> MediaTek Inc.)
R3 NahimicBTLink; C:\WINDOWS\System32\drivers\NahimicBTLink.sys [95856 2024-05-13] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [95896 2024-05-16] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
R1 netprotection_network_filter; C:\WINDOWS\System32\drivers\netprotection_network_filter.sys [117600 2025-02-19] (Avira Operations GmbH -> Avira Operations GmbH)
R3 nvpcf; C:\WINDOWS\System32\drivers\nvpcf.sys [303848 2026-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_3037ec512dc36c3a\rt68cx21x64.sys [656328 2023-02-15] (Realtek Semiconductor Corp. -> Realtek)
S3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
R1 rtp1; C:\WINDOWS\System32\DRIVERS\rtp1.sys [480064 2026-07-18] (Avira Operations GmbH -> Avira Operations GmbH)
R1 rtp2; C:\WINDOWS\System32\DRIVERS\rtp2.sys [480064 2026-07-18] (Avira Operations GmbH -> Avira Operations GmbH)
S0 rtp_elam; C:\WINDOWS\System32\DRIVERS\rtp_elam.sys [30168 2026-07-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Avira Operations GmbH)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2026-06-29] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [20016 2025-04-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [605576 2025-04-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-10] (Microsoft Windows -> Microsoft Corporation)
S3 netprotection_network_filter2; System32\drivers\netprotection_network_filter2.sys (No File)

==================== SvcHost (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-07-22 09:12 - 2026-07-22 09:13 - 000034015 _____ C:\Users\jiria\Desktop\FRST.txt
2026-07-22 09:12 - 2026-07-22 09:13 - 000000000 ____D C:\FRST
2026-07-22 09:11 - 2026-07-22 09:11 - 002450944 _____ (Farbar) C:\Users\jiria\Desktop\FRST64.exe
2026-07-20 19:46 - 2026-07-20 19:54 - 794915001 _____ C:\Users\jiria\Downloads\House.of.the.Dragon.S03E05.1080p.WEBRip.10Bit.DDP5.1.x265-NeoNoir.mkv
2026-07-19 13:21 - 2026-07-19 13:21 - 000222436 _____ C:\Users\jiria\Downloads\fa_MichalTyc_2026117.pdf
2026-07-19 10:12 - 2026-07-21 13:19 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-07-19 10:06 - 2026-07-19 10:12 - 000000000 ___HD C:\$WinREAgent
2026-07-18 20:19 - 2026-07-18 20:23 - 3963246571 _____ C:\Users\jiria\Downloads\Silo.S03E03.1080p.WEB.h264-ETHEL[EZTVx.to].mkv
2026-07-18 13:49 - 2026-07-18 13:54 - 1548619776 _____ C:\Users\jiria\Downloads\Silo S03E03 1080p HD WEB ENG MULTI SUBS.exe
2026-07-18 13:49 - 2026-07-18 13:53 - 1940037335 _____ C:\Users\jiria\Downloads\House of the Dragon S03E04 720p AMZN WEB-DL DDP5 1 H 264-NTb[EZTVx.to].mkv
2026-07-11 16:47 - 2026-07-11 16:47 - 000202580 _____ C:\Users\jiria\Downloads\20260010.pdf
2026-07-08 12:19 - 2026-07-08 12:19 - 000713018 _____ C:\WINDOWS\system32\perfh005.dat
2026-07-08 12:19 - 2026-07-08 12:19 - 000153196 _____ C:\WINDOWS\system32\perfc005.dat
2026-07-08 08:08 - 2026-07-08 08:08 - 000000000 ____D C:\Users\jiria\AppData\LocalLow\HiWarp
2026-07-07 15:46 - 2026-07-07 15:46 - 000668485 _____ C:\Users\jiria\Downloads\scénář_školení_KONFLIKTY_032026.pdf
2026-07-06 20:46 - 2026-07-21 13:19 - 000000000 ____D C:\Users\jiria\AppData\Roaming\CobaltCore
2026-07-06 13:31 - 2026-07-06 13:31 - 000000000 ____D C:\Users\jiria\AppData\LocalLow\Toukana Interactive
2026-07-06 13:30 - 2026-07-06 13:30 - 000000223 _____ C:\Users\jiria\Desktop\Naiad.url
2026-07-06 13:30 - 2026-07-06 13:30 - 000000223 _____ C:\Users\jiria\Desktop\Dorfromantik.url
2026-07-06 13:30 - 2026-07-06 13:30 - 000000223 _____ C:\Users\jiria\Desktop\Cobalt Core.url
2026-07-04 12:58 - 2026-07-04 12:58 - 000711535 _____ C:\Users\jiria\Downloads\Manuál žadatele - k tisku.pdf
2026-07-03 22:18 - 2026-07-03 22:18 - 000000000 ____D C:\Users\jiria\AppData\LocalLow\Amanita Design
2026-07-03 21:54 - 2026-07-03 21:54 - 000000223 _____ C:\Users\jiria\Desktop\Phonopolis.url
2026-07-02 14:42 - 2026-07-02 14:42 - 000001392 _____ C:\Users\Public\Desktop\Brother iPrint&Scan.lnk
2026-06-30 14:00 - 2026-06-30 14:00 - 000000000 ____D C:\Users\jiria\AppData\Local\DropDuchy
2026-06-30 13:56 - 2026-06-30 13:56 - 000000223 _____ C:\Users\jiria\Desktop\Drop Duchy.url
2026-06-30 12:46 - 2026-06-30 13:25 - 000000000 ____D C:\Users\jiria\AppData\Local\Cosmic_Wheel_of_Fortuna
2026-06-29 20:59 - 2026-06-29 20:59 - 000003888 _____ C:\WINDOWS\system32\Tasks\Avira_Security_Maintenance
2026-06-29 20:59 - 2026-06-29 20:59 - 000003428 _____ C:\WINDOWS\system32\Tasks\Avira_Security_Service_SCM_Watchdog
2026-06-29 20:59 - 2026-06-29 20:59 - 000002818 _____ C:\WINDOWS\system32\Tasks\Avira_Security_Systray
2026-06-29 18:49 - 2026-06-29 18:49 - 001887080 _____ C:\Users\jiria\Downloads\Nasili_v_rodine_FSS_podzim_2024.pptx
2026-06-29 18:46 - 2026-06-29 18:46 - 000000000 ____D C:\Users\jiria\AppData\Local\Claude-3p
2026-06-29 18:46 - 2026-06-29 18:46 - 000000000 ____D C:\ProgramData\Claude
2026-06-29 18:45 - 2026-06-29 18:45 - 007011488 _____ (Anthropic, PBC) C:\Users\jiria\Downloads\Claude Setup (1).exe
2026-06-29 18:44 - 2026-07-22 09:16 - 000000000 ____D C:\Users\jiria\AppData\Roaming\Claude
2026-06-29 18:44 - 2026-06-29 18:46 - 000000000 ____D C:\Users\jiria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anthropic
2026-06-29 18:42 - 2026-06-29 18:42 - 205712544 _____ (Anthropic PBC) C:\Users\jiria\Downloads\Claude Setup.exe
2026-06-26 20:57 - 2026-06-26 20:57 - 000000000 ____D C:\Users\jiria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2026-06-22 18:25 - 2026-06-22 18:25 - 000003786 _____ C:\WINDOWS\system32\Tasks\AviraSystemSpeedupVerify

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-07-22 09:16 - 2025-03-01 18:49 - 000000000 ____D C:\Users\jiria\AppData\Roaming\BitTorrent Web
2026-07-22 09:15 - 2025-03-01 17:25 - 000000000 ____D C:\Users\jiria\AppData\Local\D3DSCache
2026-07-22 09:10 - 2025-03-01 18:51 - 000000000 ____D C:\Program Files (x86)\Steam
2026-07-22 09:10 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-07-22 09:10 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-21 14:10 - 2026-02-10 14:10 - 000000000 ____D C:\Users\jiria\AppData\Local\Ubisoft Game Launcher
2026-07-21 13:19 - 2025-03-04 22:00 - 000000000 ____D C:\Users\jiria\AppData\Roaming\vlc
2026-07-20 19:54 - 2025-03-01 18:49 - 000000000 ____D C:\Users\jiria\AppData\Local\BitTorrentHelper
2026-07-20 19:52 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-07-20 12:48 - 2025-03-01 16:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-07-20 10:58 - 2025-03-01 17:25 - 000007952 _____ C:\WINDOWS\system32\Drivers\mtkRunTimeDataWdi.bin
2026-07-19 20:33 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-19 20:11 - 2025-03-01 16:51 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-19 20:11 - 2025-03-01 16:51 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-07-19 10:57 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-07-19 10:06 - 2025-03-01 16:51 - 000003714 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{C5AA6C03-B243-4C71-A0E3-9DAF3CD6DA51}
2026-07-19 10:06 - 2025-03-01 16:51 - 000003588 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{2C38339E-5890-4FF4-BD61-2D6E8EA9D830}
2026-07-18 20:17 - 2025-03-01 17:30 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-07-18 20:17 - 2025-03-01 17:30 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-07-18 13:51 - 2025-03-02 19:36 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-18 13:50 - 2026-03-05 21:31 - 000000000 ____D C:\Users\jiria\AppData\Local\Sentry
2026-07-18 13:42 - 2025-03-02 19:36 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-18 13:40 - 2025-12-27 22:26 - 000000000 ____D C:\ProgramData\EA Desktop
2026-07-18 13:38 - 2025-03-01 18:58 - 000000000 ____D C:\Users\jiria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2026-07-18 13:33 - 2025-03-01 17:43 - 005801552 _____ C:\WINDOWS\system32\rtp.db
2026-07-18 13:32 - 2025-03-01 17:42 - 000480064 _____ (Avira Operations GmbH) C:\WINDOWS\system32\Drivers\rtp2.sys
2026-07-18 13:32 - 2025-03-01 17:42 - 000480064 _____ (Avira Operations GmbH) C:\WINDOWS\system32\Drivers\rtp1.sys
2026-07-18 13:31 - 2025-03-01 17:42 - 000030168 _____ (Avira Operations GmbH) C:\WINDOWS\system32\Drivers\rtp_elam.sys
2026-07-11 13:34 - 2025-03-01 17:28 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-791795520-2065237621-642244014-1001
2026-07-11 13:34 - 2025-03-01 17:28 - 000003564 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-791795520-2065237621-642244014-1001
2026-07-11 13:34 - 2025-03-01 17:28 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-791795520-2065237621-642244014-1001
2026-07-11 13:34 - 2025-03-01 17:28 - 000002379 _____ C:\Users\jiria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-10 22:11 - 2025-08-28 20:59 - 000001897 _____ C:\Users\jiria\Desktop\BitTorrent Web.lnk
2026-07-10 22:11 - 2025-08-28 20:59 - 000001883 _____ C:\Users\jiria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent Web.lnk
2026-07-10 20:57 - 2025-06-03 20:11 - 000000000 ____D C:\Users\jiria\AppData\Roaming\discord
2026-07-10 20:48 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2026-07-10 08:00 - 2025-03-24 19:00 - 000004242 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-791795520-2065237621-642244014-1001
2026-07-08 21:24 - 2025-03-02 21:17 - 000000000 ____D C:\Users\jiria\AppData\Local\CrashDumps
2026-07-08 12:19 - 2025-03-01 16:57 - 001692324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-07-07 09:15 - 2025-10-29 13:50 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH
2026-07-03 22:17 - 2025-11-21 23:25 - 000000000 ____D C:\Users\jiria\AppData\Local\SplitFiction
2026-07-03 22:17 - 2025-04-13 21:22 - 000000000 ____D C:\Users\jiria\AppData\Roaming\Balatro
2026-07-03 13:39 - 2025-06-03 20:11 - 000000000 ____D C:\Users\jiria\AppData\Local\Discord
2026-07-02 14:42 - 2026-04-12 19:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
2026-07-02 14:42 - 2026-04-12 19:25 - 000000000 ____D C:\Program Files (x86)\Browny02
2026-07-02 14:42 - 2025-03-01 18:49 - 000000000 ____D C:\ProgramData\Package Cache
2026-06-30 14:00 - 2025-07-14 12:47 - 000000000 ____D C:\Users\jiria\AppData\Local\UnrealEngine
2026-06-30 11:43 - 2025-05-12 20:34 - 000000000 ____D C:\Users\jiria\AppData\Roaming\Spotify
2026-06-30 11:43 - 2025-05-12 20:34 - 000000000 ____D C:\Users\jiria\AppData\Local\Spotify
2026-06-30 09:09 - 2025-06-03 20:11 - 000002243 _____ C:\Users\jiria\Desktop\Discord.lnk
2026-06-30 00:35 - 2025-03-01 17:21 - 000000000 ____D C:\ProgramData\NVIDIA
2026-06-30 00:35 - 2025-03-01 17:19 - 000007300 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-06-30 00:34 - 2025-03-01 16:51 - 000012288 ___SH C:\DumpStack.log.tmp
2026-06-30 00:34 - 2025-03-01 16:51 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2026-06-30 00:34 - 2025-03-01 16:51 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-06-30 00:34 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ServiceState
2026-06-30 00:34 - 2024-04-01 09:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-06-30 00:33 - 2025-03-01 16:51 - 000297264 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-06-30 00:31 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-06-30 00:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-06-30 00:30 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2026-06-30 00:30 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-06-30 00:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-06-30 00:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-06-30 00:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-06-30 00:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-06-30 00:30 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-06-30 00:30 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-06-30 00:30 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-06-30 00:29 - 2025-03-01 17:21 - 000000000 ____D C:\Users\jiria
2026-06-29 20:59 - 2025-03-01 17:40 - 000003474 _____ C:\WINDOWS\system32\Tasks\Avira_Security_Update
2026-06-29 20:59 - 2025-03-01 17:40 - 000001078 _____ C:\Users\Public\Desktop\Avira.lnk
2026-06-29 20:59 - 2025-03-01 17:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2026-06-29 18:48 - 2026-05-13 12:49 - 000718296 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmusrv.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000615896 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmuidevices.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000599504 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmflexio.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000579048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmserial.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000517616 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsynthstor.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000456168 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsmb.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000439784 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmprox.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmdynmem.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000382440 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmiccore.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000329176 _____ (Microsoft Corporation) C:\WINDOWS\system32\vp9fs.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000329168 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmCrashDump.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000271832 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbusvdev.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000124392 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwpctrl.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000096576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmsvc.dll
2026-06-29 18:48 - 2026-05-13 12:49 - 000046544 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmcomputeeventlog.dll
2026-06-29 18:48 - 2026-04-14 20:49 - 000071144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NvAgent.dll
2026-06-29 18:48 - 2026-04-14 20:46 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\hcsdiag.exe
2026-06-29 18:48 - 2026-04-14 20:46 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmhbmgmt.dll
2026-06-29 18:48 - 2026-04-14 20:46 - 000108976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbresources.dll
2026-06-29 18:48 - 2025-09-10 07:45 - 000652160 _____ C:\WINDOWS\system32\secfw_GenuineIntel.dll
2026-06-29 18:48 - 2025-09-10 07:45 - 000190848 _____ C:\WINDOWS\system32\secfw_AuthenticAMD.dll
2026-06-29 18:48 - 2025-09-10 07:45 - 000144768 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdp4vs.dll
2026-06-29 18:48 - 2025-09-10 07:44 - 000132520 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwpevents.dll
2026-06-29 18:48 - 2025-06-11 04:47 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbusproxy.sys
2026-06-29 18:48 - 2025-06-11 04:47 - 000058824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hnswfpdriver.sys
2026-06-29 18:48 - 2025-06-11 04:47 - 000050592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmsvcext.sys
2026-06-29 18:48 - 2025-03-02 19:52 - 000050608 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsifproxystub.dll
2026-06-29 18:48 - 2024-10-05 02:11 - 000095664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pvhdparser.sys
2026-06-29 18:48 - 2024-10-05 02:11 - 000071088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\passthruparser.sys
2026-06-29 18:48 - 2024-10-05 02:11 - 000066992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocketcontrol.sys
2026-06-29 18:48 - 2024-10-05 02:11 - 000054576 _____ (Microsoft Corporation) C:\WINDOWS\system32\VrdUmed.dll
2026-06-29 18:48 - 2024-04-01 09:22 - 000006658 _____ C:\WINDOWS\system32\VmFirmwareHcl Third-Party Notices.txt
2026-06-29 18:48 - 2024-04-01 09:22 - 000006658 _____ C:\WINDOWS\system32\VmFirmware Third-Party Notices.txt
2026-06-29 18:46 - 2025-03-01 17:24 - 000000000 ____D C:\Users\jiria\AppData\Local\Packages
2026-06-29 18:46 - 2025-03-01 16:53 - 000000000 ____D C:\ProgramData\Packages
2026-06-29 18:44 - 2025-06-03 20:11 - 000000000 ____D C:\Users\jiria\AppData\Local\SquirrelTemp
2026-06-27 13:12 - 2025-03-24 19:00 - 000000000 ____D C:\Users\jiria\AppData\Roaming\Zoom
2026-06-26 20:54 - 2025-03-01 17:43 - 000002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-06-26 20:54 - 2025-03-01 17:43 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk

==================== Files in the root of some directories ========

2026-04-12 19:29 - 2026-04-12 19:29 - 000000000 _____ () C:\Users\jiria\AppData\Local\settingData.dat

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-07-2026 01
Ran by jiria (22-07-2026 09:16:28)
Running from C:\Users\jiria\Desktop
Microsoft Windows 11 Pro Version 25H2 26200.8655 (X64) (2025-03-01 14:53:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-791795520-2065237621-642244014-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-791795520-2065237621-642244014-503 - Limited - Disabled)
Guest (S-1-5-21-791795520-2065237621-642244014-501 - Limited - Disabled)
jiria (DisplayName: J*ří ****r) (S-1-5-21-791795520-2065237621-642244014-1001 - Administrators - Enabled) [MS Account] => C:\Users\jiria
WDAGUtilityAccount (S-1-5-21-791795520-2065237621-642244014-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Security (Enabled - Up to date) {37377C8F-9E83-D37F-7856-7D808BFF14B2}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 26.001.21691 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AppLogLibSetup (HKLM-x32\...\{52FB0C8F-DF05-4C61-AEB6-18C55F8C385F}) (Version: 1.0.3.0 - Brother Industries Ltd.) Hidden
Avira Fallback Updater (HKLM-x32\...\Avira Fallback Updater) (Version: - ) Hidden
Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.47.1.24783 - Avira Operations GmbH & Co. KG) Hidden
Avira Security (HKLM-x32\...\Avira Security_is1) (Version: 1.1.116.3442 - Avira Operations GmbH) Hidden
Avira Security (HKLM-x32\...\AviraSecurityUninstaller) (Version: - Avira Operations GmbH)
Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 7.5.0.552 - Avira Operations GmbH) Hidden
BitTorrent Web (HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\btweb) (Version: 1.6.0 - BitTorrent Limited)
BrLauncher (HKLM-x32\...\{D939DD00-5D96-4907-9657-8B22D8B4728C}) (Version: 2.0.36.0 - Brother Industries Ltd.) Hidden
BrLogRx (HKLM-x32\...\{190861E7-09C5-42D8-BB4B-0AFB234BCFC1}) (Version: 1.0.3.1 - Brother Industries Ltd.) Hidden
Brother iPrint&Scan (HKLM-x32\...\{B3652414-55F6-4AE6-820A-26A288DE0EBE}) (Version: 15.2.0.11 - Brother Industries, Ltd.) Hidden
Brother iPrint&Scan (HKLM-x32\...\{d12440b8-f4ee-4415-ad5e-033807a9fac1}) (Version: 15.2.0.11 - Brother Industries, Ltd.)
Brother Port Driver (HKLM-x32\...\{8F3A9A59-C40E-4867-81BC-0BDEE475C17A}) (Version: 1.0.15.1 - Brother Industries Ltd.) Hidden
Brother Printer Driver (HKLM-x32\...\{9DD5B471-A1EE-480C-A8F8-B07DCC394EB4}) (Version: 1.10.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (HKLM-x32\...\{AF476943-2E93-477D-A50C-EDCCD18D48CA}) (Version: 1.0.30.1 - Brother Industries Ltd.) Hidden
BrSupportTools (HKLM-x32\...\{F7447B09-1FB1-43D0-AF13-7FC986EC4662}) (Version: 1.0.44.0 - Brother Industries Ltd.) Hidden
ControlCenter4 (HKLM-x32\...\{D4571828-E2B5-4935-AB5E-2B4B216CF56D}) (Version: 4.6.49.1 - Brother Industries, Ltd.) Hidden
ControlCenter4 CSDK (HKLM-x32\...\{FD8A9511-BFC9-43B5-BB75-9CEC0EA03CF0}) (Version: 4.6.1.1 - Brother Industries, Ltd.) Hidden
Discord (HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Discord) (Version: 1.0.9244 - Discord Inc.)
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.743.3.6251 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{5bc9fb28-357f-4275-beea-a5da06c6bc74}) (Version: 13.743.3.6251 - Electronic Arts)
Endpoint Protection SDK (HKLM\...\{68E1CCB4-4965-4713-BDEB-77F6D6C9BF9D}_is1) (Version: 1.0.2502.5082 - Avira Operations GmbH) Hidden
f.lux (HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Flux) (Version: 4.140 - f.lux Software LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 150.0.7871.125 - Google LLC)
HowToGuide (HKLM-x32\...\{36580EEB-4EDF-4880-BBD4-097E2C645ECD}) (Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
HttpToUsbBridge (HKLM-x32\...\{D4BAB468-5801-489D-BC3C-7667BCAC812F}) (Version: 2.6.123.1 - Brother Industries Ltd.)
Microsoft .NET 8.0.19 - Windows Server Hosting (HKLM-x32\...\{59932048-58de-4541-8e3c-69701c17d9d3}) (Version: 8.0.19.25372 - Microsoft Corporation)
Microsoft .NET Host - 6.0.11 (x64) (HKLM\...\{B92B890A-04F2-4880-BA20-20D4364FB263}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.19 (x64) (HKLM\...\{B84443A1-BE1B-4C5E-B834-E12133604B12}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.19 (x86) (HKLM-x32\...\{D4D10C87-3601-4E52-91EE-A841D6C23424}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.11 (x64) (HKLM\...\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.19 (x64) (HKLM\...\{69A17DA9-300A-49B9-97F1-1EB7424570DE}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.19 (x86) (HKLM-x32\...\{2883A694-4739-411F-AFCD-E28C81932183}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.11 (x64) (HKLM\...\{C3DD1448-513A-4DB8-978D-6991562EA63D}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.19 (x64) (HKLM\...\{B9F7A454-0CCD-410C-A3E0-D1AAC300F150}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.19 (x86) (HKLM-x32\...\{83726A11-0834-46DA-A5EF-2F67E8D9AF19}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.19 Hosting Bundle Options (HKLM-x32\...\{72566518-E5FE-3AF2-8C4E-1361EB3F9E6B}) (Version: 8.0.19.25372 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.19 Shared Framework (x64) (HKLM\...\{23AD4455-B98F-3FC8-9FB9-28001FD3DF52}) (Version: 8.0.19.25372 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.19 Shared Framework (x86) (HKLM-x32\...\{D9E20384-E764-35CA-BD6E-F1A3A06E2A8F}) (Version: 8.0.19.25372 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.83 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.83 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\OneDriveSetup.exe) (Version: 26.113.0614.0004 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.50.35710 (HKLM\...\{9393725C-A0DA-47F1-8DB9-D1C223A0DD5A}) (Version: 14.50.35710 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.50.35710 (HKLM\...\{0BCFDDE2-AA44-4087-8E77-E0025551AC6E}) (Version: 14.50.35710 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35710 (HKLM-x32\...\{b2f5e2cc-18af-40da-9bb9-c296da1cb96c}) (Version: 14.50.35710.0 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM\...\{A39D4115-3A27-4245-AE92-3214B8B21932}) (Version: 48.47.50419 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM-x32\...\{c4846f79-a633-4ae4-92a3-92fdbeb33da2}) (Version: 6.0.11.31823 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.19 (x64) (HKLM\...\{A6EA542C-884C-4FE7-89E4-8C28E14B601C}) (Version: 64.76.37602 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.19 (x64) (HKLM-x32\...\{6b2575e2-0248-44c3-93f3-2eba040331ed}) (Version: 8.0.19.35118 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.19 (x86) (HKLM-x32\...\{35A67BFA-8CCC-408D-B39C-F53D3DC0B202}) (Version: 64.76.37602 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.19 (x86) (HKLM-x32\...\{8f05f7f9-d531-4b90-a8b4-5f0b61e78033}) (Version: 8.0.19.35118 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
NetworkRepairTool (HKLM-x32\...\{A7599C88-0008-4D11-8815-4D5AE38B81AE}) (Version: 1.2.29.0 - Brother Industries, Ltd.) Hidden
NVIDIA App 11.0.6.383 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.6.383 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.5.11821.36727370 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.5.11821.36727370 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.4.5.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.7 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 591.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 591.86 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
NVIDIA USBC Driver 1.52.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.52.831.832 - NVIDIA Corporation)
PlayStation® Accessories (HKLM\...\{A27B17B9-90C8-4B07-83C6-1303FC186B6B}) (Version: 2.2.1.2 - Sony Interactive Entertainment Inc.)
ScannerUtilityInstaller (HKLM-x32\...\{D94DD953-F38C-4220-A17C-9217106510A6}) (Version: 1.20.0.1 - Brother) Hidden
Sid Meier's Civilization IV Colonization (HKLM-x32\...\{EF36A836-BF89-4A4F-B079-057B0C68C1E0}) (Version: 1.00 - Firaxis Games)
SoftwareUpdateNotification (HKLM-x32\...\{E28A6F15-BFBE-4D20-8B5F-6EABAA1E545E}) (Version: 1.0.14.0 - Brother Industries, Ltd.) Hidden
Spotify (HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Spotify) (Version: 1.2.89.539.gfb3c63a3 - Spotify AB)
StatusMonitor (HKLM-x32\...\{4A3EDE8B-5791-4DCF-91FE-58E23FB4D429}) (Version: 1.42.0.0 - Brother Industries, Ltd.) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 169.5.13021 - Ubisoft)
Uninstall SpotifyBee (HKLM-x32\...\{920AC25F-79C4-473C-81D8-0F66FA3B35C6}_is1) (Version: 4.7.2 - iFoxPaw)
UsbRepairTool (HKLM-x32\...\{F8762A81-32B5-4144-9F3C-9274F515A651}) (Version: 1.4.0.0 - Brother Industries, Ltd.) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
Zoom Workplace (HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\ZoomUMX) (Version: 7.0.5 (38856) - Zoom Communications, Inc.)

Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-11] ()
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2026-06-26] ()
AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m [2025-07-29] (Advanced Micro Devices Inc.) [Startup Task]
Claude -> C:\Program Files\WindowsApps\Claude_1.20186.0.0_x64__pzs8sxrjxfjjc [2026-07-09] (Anthropic, PBC) [Startup Task]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-11-06] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.50.323.0_x64__dt26b99r8h8gj [2025-03-01] (Realtek Semiconductor Corp)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-791795520-2065237621-642244014-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-791795520-2065237621-642244014-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-791795520-2065237621-642244014-1001_Classes\CLSID\{5F86DC52-D653-4CFF-BAC7-C3A406AF8946}\localserver32 -> C:\Users\jiria\AppData\Roaming\Spotify\Spotify.exe (Spotify AB -> Spotify Ltd)
CustomCLSID: HKU\S-1-5-21-791795520-2065237621-642244014-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-06-08] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [SystemSpeedupFilesMenu] -> {14cb2bd0-2375-3d10-9b5d-5e18865c8959} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2026-01-20] (Avira Operations GmbH -> Avira Operations GmbH)
ContextMenuHandlers2: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL [2026-06-18] (Avira Operations GmbH -> Avira Operations GmbH)
ContextMenuHandlers3: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL [2026-06-18] (Avira Operations GmbH -> Avira Operations GmbH)
ContextMenuHandlers4: [SystemSpeedupFoldersMenu] -> {700866bb-c8e9-3e71-b359-abb28baed0e8} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2026-01-20] (Avira Operations GmbH -> Avira Operations GmbH)
ContextMenuHandlers5: [NvAppDesktopContext] -> {F2E8B4A1-9C7D-4F6E-B3A5-8D2C1F4E9B7A} => C:\Program Files\NVIDIA Corporation\NVIDIA App\NvCpl\nvui.dll [2026-01-16] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_b3badde551342cd6\nvshext.dll [2026-01-22] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers5: [SystemSpeedupDesktopMenu] -> {0cab5786-30e8-3185-9b3b-ccefbf1b8afe} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2026-01-20] (Avira Operations GmbH -> Avira Operations GmbH)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\jiria\Desktop\Jiří - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\jiria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Calculator.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=inhhlmhdllknkepmabbkhnlbaddllabl

==================== Loaded Modules (Whitelisted) =============

2026-02-10 14:18 - 2026-02-10 14:18 - 000000000 ____L ( (A-Volute SAS -> A-Volute)) [symlink -> C:\Program Files\NVIDIA Corporation\NVIDIA App\MessageBus\NvMessageBusBroadcast.dll] C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem\NvMessageBusBroadcast.dll
2026-04-27 13:30 - 2026-04-27 13:30 - 000604672 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\ADKCore.dll
2026-04-27 13:30 - 2026-04-27 13:30 - 000006144 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BfLogger.dll
2026-04-27 13:31 - 2026-04-27 13:31 - 000018432 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BfPlatformLib.Windows.dll
2025-12-15 13:56 - 2025-12-15 13:56 - 000108032 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BolService.dll
2026-04-27 13:31 - 2026-04-27 13:31 - 000024576 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BRAppDevKitCommon.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000397824 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BRAppDevKitQuery2.dll
2026-04-27 13:31 - 2026-04-27 13:31 - 000004608 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BRDevKitQuery2CommonDataLib.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000223744 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\cs\Rodem.UI.Wpf.Resources.resources.dll
2026-04-27 13:31 - 2026-04-27 13:31 - 000261120 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\cs\StatusMessageResourceLib.resources.dll
2015-02-22 14:00 - 2015-02-22 14:00 - 000323072 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Google.ProtocolBuffers.dll
2016-08-17 21:38 - 2016-08-17 21:38 - 000080896 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\MvvmCross.Core.dll
2016-08-17 21:38 - 2016-08-17 21:38 - 000080384 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\MvvmCross.Platform.dll
2025-07-03 17:36 - 2025-07-03 17:36 - 000030720 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\OfferingService.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000288256 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.ADK.WinDesktop.dll
2026-04-27 13:30 - 2026-04-27 13:30 - 000088576 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.Common.dll
2026-04-27 13:30 - 2026-04-27 13:30 - 000383488 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.Functions.dll
2026-04-27 13:30 - 2026-04-27 13:30 - 000135168 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.Libraries.Common.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000206848 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.Libraries.WinDesktop.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000150016 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.Libraries.Windows.dll
2026-04-27 13:30 - 2026-04-27 13:30 - 001524224 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.ProtocolBuffers.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 001064960 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.UI.Wpf.Resources.dll
2026-04-27 13:31 - 2026-04-27 13:31 - 000757760 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\StatusMessageResourceLib.dll
2016-11-25 10:18 - 2016-11-25 10:18 - 000139264 _____ () [File not signed] C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2026-01-07 17:16 - 2026-01-07 17:16 - 000829952 _____ () [File not signed] C:\Program Files (x86)\Browny02\BrMonitor.dll
2024-04-16 16:25 - 2024-04-16 16:25 - 000021504 _____ () [File not signed] C:\Program Files (x86)\Browny02\OfferingService.dll
2024-04-17 19:56 - 2024-04-17 19:56 - 000137728 _____ () [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcAssoc.dll
2017-08-18 11:23 - 2017-08-18 11:23 - 000087552 _____ () [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcDlgRc.dll
2017-08-18 11:23 - 2017-08-18 11:23 - 017974784 _____ () [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcGrImg.dll
2018-04-27 09:16 - 2018-04-27 09:16 - 000090112 _____ () [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcLCze.dll
2024-04-17 19:57 - 2024-04-17 19:57 - 000440832 _____ () [File not signed] C:\Program Files (x86)\ControlCenter4\Track.dll
2026-06-16 07:11 - 2026-06-16 07:11 - 001490944 _____ () [File not signed] C:\Users\jiria\AppData\Roaming\BitTorrent Web\avcodec-58.dll
2026-06-16 07:11 - 2026-06-16 07:11 - 000949248 _____ () [File not signed] C:\Users\jiria\AppData\Roaming\BitTorrent Web\avformat-58.dll
2026-06-16 07:11 - 2026-06-16 07:11 - 000635392 _____ () [File not signed] C:\Users\jiria\AppData\Roaming\BitTorrent Web\avutil-56.dll
2026-06-16 07:11 - 2026-06-16 07:11 - 000153088 _____ () [File not signed] C:\Users\jiria\AppData\Roaming\BitTorrent Web\swresample-3.dll
2026-04-28 16:25 - 2026-04-28 16:25 - 000028672 _____ (AppControl) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\AppControl.dll
2026-04-09 17:35 - 2026-04-09 17:35 - 000025299 _____ (Brother Industries, Ltd) [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\brlm03a.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 001009152 _____ (Brother Industries, Ltd.) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BRAdmin.Common.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 001844736 _____ (Brother Industries, Ltd.) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BRAdmin.PF.dll
2026-04-27 13:31 - 2026-04-27 13:31 - 000007680 _____ (Brother Industries, Ltd.) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BrotherUpdateCheck.dll
2026-04-27 13:31 - 2026-04-27 13:31 - 000045056 _____ (Brother Industries, Ltd.) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\BrotherUpdateCheck.PCL.dll
2026-04-27 13:30 - 2026-04-27 13:30 - 001416192 _____ (Brother Industries, Ltd.) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.UI.Core.dll
2016-04-12 10:07 - 2016-04-12 10:07 - 000067584 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Brother\AppLogLib\BrBFLogI.dll
2021-03-27 11:46 - 2021-03-27 11:46 - 000103424 _____ (hardcodet.net) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Hardcodet.NotifyIcon.Wpf.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000019968 _____ (iPSMonitor) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\cs\iPSMonitor.resources.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 001033728 _____ (iPSMonitor) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\iPSMonitor.dll
2015-10-05 18:37 - 2015-10-05 18:37 - 000135680 _____ (Microsoft Corporation) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Microsoft.Practices.Unity.dll
2022-11-10 23:30 - 2022-11-10 23:30 - 000135168 _____ (neuecc xin9le okazuki) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\ReactiveProperty.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000018944 _____ (Rodem.Notifier.Services) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.Notifier.Services.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000045568 _____ (Rodem.UI.Grpc) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.UI.Grpc.dll
2026-04-28 16:26 - 2026-04-28 16:26 - 000008704 _____ (Rodem.UI.Grpc.Server) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Rodem.UI.Grpc.Server.dll
2022-07-25 16:40 - 2022-07-25 16:40 - 000258048 _____ (The Apache Software Foundation) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\log4net.dll
2026-06-16 07:11 - 2026-06-16 07:11 - 002554880 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Users\jiria\AppData\Roaming\BitTorrent Web\libcrypto-1_1.dll
2026-06-16 07:11 - 2026-06-16 07:11 - 000537600 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Users\jiria\AppData\Roaming\BitTorrent Web\libssl-1_1.dll
2021-01-30 06:29 - 2021-01-30 06:29 - 000067584 _____ (Unity Open Source Project) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Unity.Abstractions.dll
2021-01-30 06:40 - 2021-01-30 06:40 - 000148480 _____ (Unity Open Source Project) [File not signed] [File is in use] C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\Unity.Container.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.0.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt68cx21x64.sys
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Wi-Fi: MediaTek Wi-Fi 6 MT7921 Wireless LAN Card -> mtkwl6ex.sys

vms_vsf: Hyper-V Virtual Switch Extension Filter
ms_l1vhlwf: Nested Network Virtualization
vms_vsp: Hyper-V Virtual Switch Extension Protocol

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-791795520-2065237621-642244014-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\jiria\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\4600601442455302793\134291778207977729.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{E584E8EC-0A15-434F-BDEC-F60422101820}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{DABF07B4-20E2-4712-9393-45A12DFBED68}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{25E5672D-7B99-4F3D-B35A-B2E5D98979B8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{8C9C698C-6F3B-436B-AB64-9C314237515B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{6496C6D7-C757-46D2-B8DF-E57F012BBA29}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [UDP Query User{BE73796F-4DCD-4CBE-92E6-EDCB1B1880C5}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [{21FD12F3-C729-484D-B64F-0417EDEB014C}] => (Allow) C:\Users\jiria\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
FirewallRules: [{EA26921E-D57D-4DDF-8802-97459B143556}] => (Allow) C:\Users\jiria\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{1E617870-3B72-4701-993C-E8D3D64A5EA2}] => (Allow) C:\Users\jiria\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{F50865D5-CE87-4A70-86FC-8B2180E04AD0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Balatro\Balatro.exe () [File not signed]
FirewallRules: [{02C26F65-ED05-4FD4-815A-CE08736DC4E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Balatro\Balatro.exe () [File not signed]
FirewallRules: [TCP Query User{C499F20D-1CE4-4F83-8DFA-5D8B363BBE5B}C:\users\jiria\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jiria\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{706404E3-2872-4697-B9E1-8D8A477D516B}C:\users\jiria\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jiria\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{ED9E3CE1-4723-4139-9B51-A00F4DF90F29}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{D8A1F228-E52B-4AE0-AEA5-BCC8186E3917}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{AC3782F8-4EC9-4161-9E7E-3D194C426C5F}] => (Allow) C:\Users\jiria\AppData\Roaming\BitTorrent Web\btweb.exe (Rainberry Inc -> BitTorrent Limited)
FirewallRules: [{363A6CB6-C2EB-4B50-9312-181ED4F400FD}] => (Allow) C:\Users\jiria\AppData\Roaming\BitTorrent Web\btweb.exe (Rainberry Inc -> BitTorrent Limited)
FirewallRules: [{74EA314E-304E-4FA1-BD15-E50B042A49B3}] => (Allow) C:\Program Files (x86)\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization\Colonization.exe (Firaxis Games) [File not signed]
FirewallRules: [{BEDE9E7E-6D9E-4871-AB64-937976095C1B}] => (Allow) C:\Program Files (x86)\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization\Colonization.exe (Firaxis Games) [File not signed]
FirewallRules: [{D5E4D0BB-C430-4D96-954B-FC8A467BE36C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Split Fiction\Split\Binaries\Win64\SplitFiction.exe (Hazelight Studios AB -> Hazelight Studios)
FirewallRules: [{51216062-2CCB-420D-9C8F-5B9F846FF6B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Split Fiction\Split\Binaries\Win64\SplitFiction.exe (Hazelight Studios AB -> Hazelight Studios)
FirewallRules: [{B53FCFA1-93C6-4823-840D-09813468F722}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Magicka\Magicka.exe (Arrowhead Game Studios AB) [File not signed]
FirewallRules: [{D84D607B-1FB7-4935-AFC8-6D61E22D1279}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Magicka\Magicka.exe (Arrowhead Game Studios AB) [File not signed]
FirewallRules: [TCP Query User{07040E2D-03A9-4FBA-ABE0-98541C362191}C:\users\jiria\appdata\roaming\spotify\spotifylauncher.exe] => (Allow) C:\users\jiria\appdata\roaming\spotify\spotifylauncher.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{917B550C-7FB6-4605-937D-7960D84C9C97}C:\users\jiria\appdata\roaming\spotify\spotifylauncher.exe] => (Allow) C:\users\jiria\appdata\roaming\spotify\spotifylauncher.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{F92D83F0-EC49-4ACE-A460-9941DC2DD896}C:\users\jiria\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\jiria\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{40774618-75A7-41EE-8E23-4441EF81046A}C:\users\jiria\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\jiria\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{9F9117F5-0745-45D5-B810-11BF22D74F04}C:\users\jiria\appdata\roaming\bittorrent web\btweb.exe] => (Block) C:\users\jiria\appdata\roaming\bittorrent web\btweb.exe (Rainberry Inc -> BitTorrent Limited)
FirewallRules: [UDP Query User{62C79FCC-D7E1-4A85-A5EB-9461FCEF9CF1}C:\users\jiria\appdata\roaming\bittorrent web\btweb.exe] => (Block) C:\users\jiria\appdata\roaming\bittorrent web\btweb.exe (Rainberry Inc -> BitTorrent Limited)
FirewallRules: [{0C3E1A64-77C3-45E0-82BA-74E284608665}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{AED40403-2619-44E3-B6B2-94D1895643F9}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{979F9251-8B52-4615-9D0F-130865BFF349}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{EFDF7C8A-79A1-425A-A109-65F0BA02C514}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{27847A8A-1324-4123-A3B5-51E45CE870F6}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{95FE525E-B11F-4DCE-B345-AC7BD4224B53}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{47324736-C009-415B-8972-5A86729B3FB1}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{87D8D12C-8C3E-4676-9ED1-5F5F2CAAE0B3}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{E3DF0E22-3C2E-43E0-8F4A-6C2D3FDE5032}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{95B8750C-5CEF-494D-A379-BD13A5497578}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{752B1470-5759-4413-9354-73B726CBDB83}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{15FDC022-D916-4400-BE75-C209AD26CAF3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B355EEB6-6B96-462D-B3E3-B1F172A0C6A8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{58C1C951-7948-44BD-B176-E58123EDFD7B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Feed the Scorchpot Demo\Scorchpot.exe (Failed to return cbHash #2, Error: 0x800700C1 -> YoYo Games Ltd) [File not signed]
FirewallRules: [{F7DBE626-5007-4304-A94F-4CE9A2003691}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Feed the Scorchpot Demo\Scorchpot.exe (Failed to return cbHash #2, Error: 0x800700C1 -> YoYo Games Ltd) [File not signed]
FirewallRules: [TCP Query User{6C9E99A9-222A-42F6-928E-A1CBD4D8122D}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe] => (Allow) C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe => No File
FirewallRules: [UDP Query User{57E9F972-2F56-40E3-816A-B1A64C702277}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe] => (Allow) C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe => No File
FirewallRules: [TCP Query User{871EBED7-DC0D-4CCE-8B99-F3E71D8D0681}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe] => (Allow) C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe => No File
FirewallRules: [UDP Query User{CEC04B81-F90F-4E16-9FE1-68C545E3B566}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe] => (Allow) C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3EFBE2DE-D783-4E3B-B0FD-D36814B3390D}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe] => (Block) C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe => No File
FirewallRules: [UDP Query User{4C37DDA5-337A-4895-9BC3-0D1C93E076FF}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe] => (Block) C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe => No File
FirewallRules: [{D39FB5D6-F6D4-42B9-9284-8B02EB75FEFF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Slay the Spire 2\SlayTheSpire2.exe () [File not signed]
FirewallRules: [{EB497844-41C5-4E88-984D-7FBD9B602C25}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Slay the Spire 2\SlayTheSpire2.exe () [File not signed]
FirewallRules: [{1CBFF230-4EBB-40FE-9BD9-1E0375541484}] => (Allow) C:\Program Files (x86)\Browny02\Brother\BrPrintFinishNotice\BrPrintFinishNotice.exe (Brother Industries, Ltd. -> )
FirewallRules: [{9CDC37C0-DF63-4573-9699-BEBB9E94B034}] => (Allow) C:\Program Files (x86)\Browny02\Brother\BrPrintFinishNotice\BrPrintFinishNotice.exe (Brother Industries, Ltd. -> )
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C7CCE5E1-3BA4-453A-9E3B-EC81831D3477}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Heroes of Might and Magic Olden Era\HeroesOldenEra.exe () [File not signed]
FirewallRules: [{E137817B-F263-4B49-B207-5D4A9ADF9905}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Heroes of Might and Magic Olden Era\HeroesOldenEra.exe () [File not signed]
FirewallRules: [{95A8FEE5-84A1-4E1E-A2A3-425F7A7E88B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Drop Duchy\DropDuchy.exe (Failed to return cbHash #2, Error: 0x800700C1 -> Epic Games, Inc.) [File not signed]
FirewallRules: [{442CEFFC-2FC5-419F-99BF-A494A9A1BF6B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Drop Duchy\DropDuchy.exe (Failed to return cbHash #2, Error: 0x800700C1 -> Epic Games, Inc.) [File not signed]
FirewallRules: [{35C0D639-F05F-45AE-B4AF-7B34E131CE27}] => (Allow) LPort=54950
FirewallRules: [{A731430F-ACDC-4EBA-AEAC-3412586CD228}] => (Allow) LPort=54955
FirewallRules: [{5554B521-FEBB-4F2F-83DE-97FAAE83676F}] => (Allow) C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\iPSMonitor.exe (iPSMonitor) [File not signed]
FirewallRules: [{46831479-2497-4D71-9BCD-9AFC8A9AC2EA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Phonopolis\Phonopolis.exe () [File not signed]
FirewallRules: [{30EEE7A8-4AA4-491C-ADFA-C1026F0897E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Phonopolis\Phonopolis.exe () [File not signed]
FirewallRules: [{A4943146-F7BA-432B-9295-42AF1C325B9D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dorfromantik\Dorfromantik.exe () [File not signed]
FirewallRules: [{9E8DA84B-36D6-41AD-8721-CE7078780D39}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dorfromantik\Dorfromantik.exe () [File not signed]
FirewallRules: [{21B608FC-1C67-4457-BD0F-2B264332F56C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Naiad\NAIAD.exe () [File not signed]
FirewallRules: [{35EFFD73-7F44-459A-B2D0-F009827DE0A8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Naiad\NAIAD.exe () [File not signed]
FirewallRules: [{EEDC4224-2D6D-4284-BB44-DFFC6E0D37E7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cobalt Core\CobaltCore.exe (CobaltCore) [File not signed]
FirewallRules: [{E753E57B-6756-4DBD-8012-D7764EA4DB0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cobalt Core\CobaltCore.exe (CobaltCore) [File not signed]
FirewallRules: [{53AFD4B4-7350-44F8-9AC1-37D791BEF0BE}] => (Allow) C:\Program Files\WindowsApps\Claude_1.20186.0.0_x64__pzs8sxrjxfjjc\app\Claude.exe (Anthropic, PBC -> Anthropic)
FirewallRules: [{BE372FB1-BE8C-4A82-89ED-01339EB55565}] => (Allow) C:\Program Files\WindowsApps\Claude_1.20186.0.0_x64__pzs8sxrjxfjjc\app\Claude.exe (Anthropic, PBC -> Anthropic)
FirewallRules: [{AFD1E6D3-5AFE-40C9-A965-E28BB9347234}] => (Allow) C:\Program Files\WindowsApps\Claude_1.20186.0.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe (Anthropic, PBC -> )
FirewallRules: [{D262DC68-71BC-48FD-9620-0CBF2A94B72D}] => (Allow) C:\Program Files\WindowsApps\Claude_1.20186.0.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe (Anthropic, PBC -> )
FirewallRules: [{9F2D1751-0327-448A-BB85-95205078B216}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{C510C56F-AF4C-40C3-8EEA-5DA4235BF24E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E2CC3F17-D81B-401B-937A-DC61D72C4CC7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B666D898-B0E0-44F8-AF8D-BE0F3EA71C91}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2543B142-48E1-4226-9718-CBD613E27DDC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

18-07-2026 13:42:16 Windows Update

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (07/18/2026 01:40:27 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: EABackgroundService.exe, verze: 13.743.0.6256, časové razítko: 0x6a487fcf
Název chybujícího modulu: EABackgroundService.exe, verze: 13.743.0.6256, časové razítko: 0x6a487fcf
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000729ed0
ID chybujícího procesu: 0x188c
Čas spuštění chybující aplikace: 0x1dd0f0f56f04a7a
Cesta k chybující aplikaci: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
Cesta k chybujícímu modulu: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
ID sestavy: c282fe4d-f259-4ee7-bd85-1fc589f60da2
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (07/08/2026 09:24:09 PM) (Source: Application Error) (EventID: 1000) (User: AMMERCEHOVINTB)
Description: Název chybující aplikace: EALaunchHelper.exe, verze: 13.743.0.6256, časové razítko: 0x6a488030
Název chybujícího modulu: EALaunchHelper.exe, verze: 13.743.0.6256, časové razítko: 0x6a488030
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000003cbe99
ID chybujícího procesu: 0x958
Čas spuštění chybující aplikace: 0x1dd0f0f564cba30
Cesta k chybující aplikaci: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe
Cesta k chybujícímu modulu: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe
ID sestavy: 4672b428-263a-481c-a579-3e6ec2fd4aa8
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (07/08/2026 09:24:07 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: EADestager.exe, verze: 13.743.0.6256, časové razítko: 0x6a487e5e
Název chybujícího modulu: EADestager.exe, verze: 13.743.0.6256, časové razítko: 0x6a487e5e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000188999
ID chybujícího procesu: 0x6750
Čas spuštění chybující aplikace: 0x1dd0f0f53946fbb
Cesta k chybující aplikaci: C:\Program Files\Electronic Arts\EA Desktop\13.743.0.6256-1783538619\Destager\EADestager.exe
Cesta k chybujícímu modulu: C:\Program Files\Electronic Arts\EA Desktop\13.743.0.6256-1783538619\Destager\EADestager.exe
ID sestavy: 5e06a252-ca00-4f1a-88bb-1b336dbca267
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (07/08/2026 09:24:06 PM) (Source: Application Error) (EventID: 1000) (User: AMMERCEHOVINTB)
Description: Název chybující aplikace: EALaunchHelper.exe, verze: 13.743.0.6256, časové razítko: 0x6a488030
Název chybujícího modulu: EALaunchHelper.exe, verze: 13.743.0.6256, časové razítko: 0x6a488030
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000003cc660
ID chybujícího procesu: 0x958
Čas spuštění chybující aplikace: 0x1dd0f0f564cba30
Cesta k chybující aplikaci: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe
Cesta k chybujícímu modulu: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe
ID sestavy: aac8e606-a0ea-4dc5-85ba-4aaf1d649444
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (07/08/2026 09:24:04 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: EADestager.exe, verze: 13.743.0.6256, časové razítko: 0x6a487e5e
Název chybujícího modulu: EADestager.exe, verze: 13.743.0.6256, časové razítko: 0x6a487e5e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000189160
ID chybujícího procesu: 0x6750
Čas spuštění chybující aplikace: 0x1dd0f0f53946fbb
Cesta k chybující aplikaci: C:\Program Files\Electronic Arts\EA Desktop\13.743.0.6256-1783538619\Destager\EADestager.exe
Cesta k chybujícímu modulu: C:\Program Files\Electronic Arts\EA Desktop\13.743.0.6256-1783538619\Destager\EADestager.exe
ID sestavy: d230c189-ba88-4f8f-90a9-700a36b6bd13
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (07/03/2026 08:31:19 PM) (Source: Application Error) (EventID: 1000) (User: AMMERCEHOVINTB)
Description: Název chybující aplikace: flux.exe, verze: 4.140.0.0, časové razítko: 0x67d3925a
Název chybujícího modulu: flux.exe, verze: 4.140.0.0, časové razítko: 0x67d3925a
Kód výjimky: 0xc000041d
Posun chyby: 0x0004b383
ID chybujícího procesu: 0x38f4
Čas spuštění chybující aplikace: 0x1dd085f4d0191fd
Cesta k chybující aplikaci: C:\Users\jiria\AppData\Local\FluxSoftware\Flux\flux.exe
Cesta k chybujícímu modulu: C:\Users\jiria\AppData\Local\FluxSoftware\Flux\flux.exe
ID sestavy: d129b65d-4a5d-4943-830f-45082deb1400
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (07/03/2026 02:43:35 PM) (Source: Application Error) (EventID: 1000) (User: AMMERCEHOVINTB)
Description: Název chybující aplikace: flux.exe, verze: 4.140.0.0, časové razítko: 0x67d3925a
Název chybujícího modulu: flux.exe, verze: 4.140.0.0, časové razítko: 0x67d3925a
Kód výjimky: 0xc0000005
Posun chyby: 0x0004b383
ID chybujícího procesu: 0x38f4
Čas spuštění chybující aplikace: 0x1dd085f4d0191fd
Cesta k chybující aplikaci: C:\Users\jiria\AppData\Local\FluxSoftware\Flux\flux.exe
Cesta k chybujícímu modulu: C:\Users\jiria\AppData\Local\FluxSoftware\Flux\flux.exe
ID sestavy: 784be2eb-7d6e-4f94-a967-178fd0f41760
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (06/29/2026 09:02:48 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: NT AUTHORITY)
Description: Systém Windows nemůže načíst knihovnu DLL rozšiřitelných čítačů C:\WINDOWS\system32\sysmain.dll (kód chyby Win32 126).


System errors:
=============
Error: (07/22/2026 09:13:46 AM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.Internal.AppCaptureShell vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.

Error: (07/21/2026 11:06:47 PM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.Internal.AppCaptureShell vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.

Error: (07/21/2026 11:02:46 PM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.Internal.AppCaptureShell vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.

Error: (07/21/2026 01:35:40 PM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.Internal.AppCaptureShell vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.

Error: (07/21/2026 01:31:39 PM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.AppCaptureManager vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.

Error: (07/21/2026 01:27:38 PM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.Internal.AppCaptureShell vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.

Error: (07/21/2026 01:23:38 PM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.AppCaptureManager vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.

Error: (07/20/2026 10:10:46 PM) (Source: DCOM) (EventID: 10029) (User: AMMERCEHOVINTB)
Description: U aktivace identifikátoru CLSID Windows.Media.Capture.Internal.AppCaptureShell vypršel časový limit během čekání na zastavení služby BcastDVRUserService_52c011.


Windows Defender:
================
CodeIntegrity:
===============
Date: 2026-07-22 09:16:39
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Avira\Endpoint Protection SDK\amsi\x64\avamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

BIOS: LENOVO H3CN47WW(V3.05) 04/15/2024
Motherboard: LENOVO LNVNB161216
Processor: AMD Ryzen 5 5500H with Radeon Graphics
Percentage of memory in use: 86%
Total physical RAM: 7532.07 MB
Available physical RAM: 1040.18 MB
Total Virtual: 21757.89 MB
Available Virtual: 2469.46 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:476.11 GB) (Free:177.05 GB) (Model: Micron MTFDKCD512QFM-1BD1AABLA) NTFS

\\?\Volume{62a5cb5d-396f-4bb4-a3ec-d9dfef429e7c}\ () (Fixed) (Total:0.71 GB) (Free:0.06 GB) NTFS
\\?\Volume{5b4059d5-8686-47e7-928c-ee32fbc17f04}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 476.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120044
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, podezření na hack

#2 Příspěvek od Rudy »

Zdravím!
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [] => [X]
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\jiria\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) <==== ATTENTION
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\RunOnce: [Uninstall 26.106.0603.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\jiria\AppData\Local\Microsoft\OneDrive\26.106.0603.0003" (No File)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\MountPoints2: {e27270ad-b687-11f0-a8Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)9b-e160180bdc39} - "D:\autorun.exe"
ask: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
S3 netprotection_network_filter2; System32\drivers\netprotection_network_filter2.sys (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
FirewallRules: [{8C9C698C-6F3B-436B-AB64-9C314237515B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{6496C6D7-C757-46D2-B8DF-E57F012BBA29}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [UDP Query User{BE73796F-4DCD-4CBE-92E6-EDCB1B1880C5}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [{ED9E3CE1-4723-4139-9B51-A00F4DF90F29}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{D8A1F228-E52B-4AE0-AEA5-BCC8186E3917}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [TCP Query User{6C9E99A9-222A-42F6-928E-A1CBD4D8122D}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe] => (Allow) C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe => No File
FirewallRules: [UDP Query User{57E9F972-2F56-40E3-816A-B1A64C702277}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe] => (Allow) C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe => No File
FirewallRules: [TCP Query User{871EBED7-DC0D-4CCE-8B99-F3E71D8D0681}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe] => (Allow) C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe => No File
FirewallRules: [UDP Query User{CEC04B81-F90F-4E16-9FE1-68C545E3B566}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe] => (Allow) C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3EFBE2DE-D783-4E3B-B0FD-D36814B3390D}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe] => (Block) C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe => No File
FirewallRules: [UDP Query User{4C37DDA5-337A-4895-9BC3-0D1C93E076FF}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe] => (Block) C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe => No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

basto
Návštěvník
Návštěvník
Příspěvky: 62
Registrován: 06 Lis 2008 15:08

Re: Prosím o kontrolu, podezření na hack

#3 Příspěvek od basto »

Fix result of Farbar Recovery Scan Tool (x64) Version: 19-07-2026 01
Ran by jiria (22-07-2026 14:05:53) Run:1
Running from C:\Users\jiria\Desktop
Loaded Profiles: jiria
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\Run: [] => [X]
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\jiria\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) <==== ATTENTION
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\RunOnce: [Uninstall 26.106.0603.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\jiria\AppData\Local\Microsoft\OneDrive\26.106.0603.0003" (No File)
HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\MountPoints2: {e27270ad-b687-11f0-a8Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)9b-e160180bdc39} - "D:\autorun.exe"
ask: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
S3 netprotection_network_filter2; System32\drivers\netprotection_network_filter2.sys (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
FirewallRules: [{8C9C698C-6F3B-436B-AB64-9C314237515B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{6496C6D7-C757-46D2-B8DF-E57F012BBA29}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [UDP Query User{BE73796F-4DCD-4CBE-92E6-EDCB1B1880C5}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [{ED9E3CE1-4723-4139-9B51-A00F4DF90F29}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{D8A1F228-E52B-4AE0-AEA5-BCC8186E3917}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [TCP Query User{6C9E99A9-222A-42F6-928E-A1CBD4D8122D}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe] => (Allow) C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe => No File
FirewallRules: [UDP Query User{57E9F972-2F56-40E3-816A-B1A64C702277}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe] => (Allow) C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe => No File
FirewallRules: [TCP Query User{871EBED7-DC0D-4CCE-8B99-F3E71D8D0681}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe] => (Allow) C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe => No File
FirewallRules: [UDP Query User{CEC04B81-F90F-4E16-9FE1-68C545E3B566}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe] => (Allow) C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3EFBE2DE-D783-4E3B-B0FD-D36814B3390D}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe] => (Block) C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe => No File
FirewallRules: [UDP Query User{4C37DDA5-337A-4895-9BC3-0D1C93E076FF}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe] => (Block) C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe => No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
"HKU\S-1-5-21-791795520-2065237621-642244014-1001\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKU\S-1-5-21-791795520-2065237621-642244014-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => removed successfully
"HKU\S-1-5-21-791795520-2065237621-642244014-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall 26.106.0603.0003" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\MountPoints2: {e27270ad-b687-11f0-a8{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)9b-e160180bdc39}" => not found
"C:\WINDOWS\HKU\S-1-5-21-791795520-2065237621-642244014-1001\...\MountPoints2: {e27270ad-b687-11f0-a8System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\TreeHKU\S-1-5-21-791795520-2065237621-642244014-1001\...\MountPoints2: {e27270ad-b687-11f0-a8\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => not found
ask: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) => Error: No automatic fix found for this entry.
HKLM\System\CurrentControlSet\Services\netprotection_network_filter2 => could not remove. Access Denied.
Could not move "C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8C9C698C-6F3B-436B-AB64-9C314237515B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6496C6D7-C757-46D2-B8DF-E57F012BBA29}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BE73796F-4DCD-4CBE-92E6-EDCB1B1880C5}C:\program files (x86)\steam\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ED9E3CE1-4723-4139-9B51-A00F4DF90F29}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D8A1F228-E52B-4AE0-AEA5-BCC8186E3917}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6C9E99A9-222A-42F6-928E-A1CBD4D8122D}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{57E9F972-2F56-40E3-816A-B1A64C702277}C:\users\jiria\downloads\broadchurch s01-s03 2013-2107 720p bluray h265 bone\cairn\cairn.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{871EBED7-DC0D-4CCE-8B99-F3E71D8D0681}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CEC04B81-F90F-4E16-9FE1-68C545E3B566}C:\users\jiria\downloads\dispatch\dispatch\binaries\win64\dispatch-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3EFBE2DE-D783-4E3B-B0FD-D36814B3390D}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4C37DDA5-337A-4895-9BC3-0D1C93E076FF}C:\users\jiria\downloads\clank\clank\clank.build.15322799\clank.exe" => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 30597328 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 828103172 B
Windows/system/drivers => 6348076 B
Edge => 266585769 B
Chrome => 2183396582 B
Firefox => 0 B
Opera => 0 B

Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 478791 B
systemprofile32 => 0 B
LocalService => 1311298 B
NetworkService => 41948 B
jiria => 6109295 B

RecycleBin => 0 B
EmptyTemp: => 3.1 GB temporary data Removed.

================================

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120044
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, podezření na hack

#4 Příspěvek od Rudy »

Smazáno, nebo opraveno. Log již vypadá OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

basto
Návštěvník
Návštěvník
Příspěvky: 62
Registrován: 06 Lis 2008 15:08

Re: Prosím o kontrolu, podezření na hack

#5 Příspěvek od basto »

Díky moc!

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120044
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, podezření na hack

#6 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno