kontrola logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
kontrola logu
Zdravím, prosím o kontrolu logu, pokus o bankovní podvod- Do PC byl nainstalován program ScreenConnect Client, který jsem odinstalovala )vProgram files něcozůstako, nejde smazat). PC pročištěno CCleanerem, Malwarebytes, SUPERantispyware a AdwCleaner.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2026
Ran by Lenovo (administrator) on DTP-S4LA1306 (LENOVO 30BGS6660R) (28-07-2026 11:05:54)
Running from C:\Users\Lenovo\Desktop\FRST64.exe
Loaded Profiles: Lenovo
Platform: Microsoft Windows 11 Pro Version 24H2 26100.8894 (X64) Language: Čeština (Česko)
Default browser: "C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Bitdefender Agent\ProductAgentService.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\27.1.1.41\DiscoverySrv.exe
(C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdntwrk.exe
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bduserhost.exe <3>
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (S.C. BITDEFENDER S.R.L. -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\wsccommunicator.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Lenovo\AppData\Local\Programs\Opera\125.0.5729.49\opera_crashreporter.exe
(DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxEM.exe
(explorer.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnapp.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Glarysoft Ltd -> Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities\Integrator.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\Installer\setup.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.99\msedgewebview2.exe <5>
(Opera Norway AS -> Opera Software) C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe <38>
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\redline\bdredline.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\Safepay\bdservicehost.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe <3>
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Glarysoft Ltd -> Glarysoft Ltd) C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe
(services.exe ->) (Glarysoft Ltd -> Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities\x64\MemfilesService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a0f482a0fd3e2e74\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d7a222f6ce13d429\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_8559c34713c70ce4\RstMwService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (RealDefense LLC -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot_proxy.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.336.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <5>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18387904 2017-12-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Cm108Sound] => C:\windows\syswow64\RunDll32.exe C:\windows\Syswow64\cm108.dll,CMICtrlWnd [12935168 2012-11-30] (C-Media Corporation) [File not signed]
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe [1099664 2026-07-08] (Bitdefender SRL -> Bitdefender)
HKLM\...\Run: [BdVpnApp] => C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe [500968 2026-04-22] (Bitdefender SRL -> Bitdefender)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4751720 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [12460120 2026-07-27] (RealDefense LLC -> SUPERAntiSpyware)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42087896 2026-04-29] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [Opera Stable] => C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe [2088408 2025-12-22] (Opera Norway AS -> Opera Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\150.0.7871.187\Installer\chrmstp.exe [7691928 2026-07-27] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.168\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level (No File)
HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-7589-DBF523A60F4D}] ->
BootExecute: autocheck autochk *
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {BB6EC972-0BC5-4628-B522-B4D6A047B386} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {8AAA95F1-CD27-4E76-BE0F-0568EE92276E} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\27.1.1.41\WatchDog.exe [1191048 2026-05-18] (Bitdefender SRL -> Bitdefender) -> C:\Program Files\Bitdefender Agent\27.1.1.41\repair
Task: {C59BCD97-4735-41D9-9C8B-07C065FE03CD} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [7746960 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {CEBFE14F-7527-414F-B038-C90F50D288A7} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [3385624 2026-07-15] (Microsoft Windows -> Microsoft Corporation)
Task: {561288A1-F443-44B6-90E7-E24800846644} - System32\Tasks\GlaryInitialize => C:\Program Files (x86)\Glary Utilities\Initialize.exe [143760 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
Task: {F44FF247-AEA0-42D1-A630-7DDDAEF31D94} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{C897EE46-BE9B-417E-91DE-5A7C07821726} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC)
Task: {65804F8A-DEC7-43D2-927A-F5545C410A1A} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500 => "C:\Users\Administrator\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe" (No File)
Task: {E56EF78F-88A6-4B97-9129-AD450B3AB852} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [11419480 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B7C549E6-6D10-490C-AB02-35D37AA09090} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {3738FAD5-639C-4B54-AE92-39BAB1A9FDE2} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\opushutil.exe [61280 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {90456870-DB15-44B8-883E-9D3C88A155BC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {BDE97274-8E1B-43E0-8207-CC3DF371BB05} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {C7CA1A70-4171-417D-AEED-576D817CA33A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {BE7CB453-4108-49EE-902D-72CD8ED0079D} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {9DEC1041-7CEE-45B7-86E1-AA1055FCED87} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {71607933-2DD7-478B-869B-4F01A3B703D3} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {120CA2B4-B7B5-452B-B64F-61CC0204C9AE} - System32\Tasks\OneDrive Startup Task-S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDriveLauncher.exe [761192 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {41F43DCD-D56B-49CF-BED2-76690D118DDE} - System32\Tasks\Opera scheduled assistant Autoupdate 1740505846 => C:\Users\Lenovo\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [6233560 2025-12-18] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --installdir="C:\Users\Lenovo\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {2E73F38C-8963-4577-B14E-D24641FEF47F} - System32\Tasks\Opera scheduled Autoupdate 1740505841 => C:\Users\Lenovo\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [6233560 2025-12-18] (Opera Norway AS -> Opera Software)
Task: {851474A4-60AC-42EE-8CD1-791DF6104A40} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [7746960 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {579F5FBC-674A-4875-826C-9D9287666021} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [7746960 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B041F8CA-A55F-4E4A-B5A7-4A52863366D4} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6635408 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {7BB6D05E-3C31-4AF3-88B7-4B422BAA8C19} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9274080 2026-01-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {26784175-317B-4ABB-8F42-E519152BD787} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )
Task: {CB3F8AEF-344B-4F4F-880F-931D0C394F12} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{40e968a8-5273-41b2-bce6-fa0bb4804094}: [DhcpNameServer] 192.168.128.80
Tcpip\..\Interfaces\{40e968a8-5273-41b2-bce6-fa0bb4804094}: [DhcpDomain] PC24.local
Tcpip\..\Interfaces\{e3207adb-087c-4416-99ee-c0074ab3b678}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext [2026-03-09] [Legacy] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-28]
Edge Notifications: Default -> hxxps://cvn65ge071bc7385nqpg.potentialconnection.co.in; hxxps://hydpyxyerubegw.potentialconnection.co.in; hxxps://www.facebook.com
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-07-27]
Edge Extension: (Bitdefender Anti-tracker) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dbconhplchnbippmjabbcedokimacfjl [2026-06-21]
Edge Extension: (Dokumenty Google offline) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-27]
Edge Extension: (Edge relevant text changes) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-03]
Edge Extension: (Word Replacer Max) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\neomjojkfljeeikfheknkihheflgbmnm [2026-07-27]
Edge Extension: (Blokátor reklam AdGuard) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2026-05-15]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [dbconhplchnbippmjabbcedokimacfjl]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default [2026-07-28]
CHR Extension: (Blokátor reklam AdGuard) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2025-07-13]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-07-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-01-03]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-119869544-2784913804-2825771880-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [khndhdhbebhaddchcgnalcjlaekbbeof]
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [374872 2026-07-27] (RealDefense LLC -> SUPERAntiSpyware.com)
S3 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 BDAppSrv; C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2966176 2023-07-20] (Bitdefender SRL -> Bitdefender)
R2 bdredline_agent; C:\Program Files\Bitdefender Agent\redline\bdredline.exe [2426992 2025-07-03] (Bitdefender SRL -> Bitdefender)
R2 BDSafepaySrv; C:\Program Files\Bitdefender\Bitdefender Security App\Safepay\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 bdvpnservice; C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe [496840 2026-04-22] (Bitdefender SRL -> Bitdefender)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [30785424 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13288288 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncHelper.exe [3619176 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
R2 GUBootService; C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe [888200 2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
R2 GUMemfilesService; C:\Program Files (x86)\Glary Utilities\x64\MemfilesService.exe [416136 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
S3 GUPMService; C:\Program Files (x86)\Glary Utilities\GUPMService.exe [76688 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
S2 Koinly; C:\Program Files\Koinly\Koinly.exe [369808 2026-07-27] (Bayside Computer Systems Inc -> Purslane Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-28] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-27] (Malwarebytes Inc -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe [2088128 2026-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDriveUpdaterService.exe [4030312 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [772624 2026-05-18] (Bitdefender SRL -> Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [877528 2026-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [321272 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe [4451664 2026-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe [290704 2026-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 atc; C:\windows\System32\drivers\atc.sys [9168984 2026-06-25] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA)
R2 BdDci4; C:\windows\System32\drivers\bddci4.sys [1385040 2026-04-08] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S0 bdelam; C:\windows\System32\drivers\bdelam.sys [26064 2026-04-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
R3 bdprivmon; C:\windows\System32\drivers\bdprivmon.sys [49208 2025-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 bduefiscan; C:\windows\System32\drivers\bduefiscan.sys [53808 2025-08-13] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R3 bdvpn_callout; C:\Program Files\Bitdefender\Bitdefender VPN\Drivers\x64\netfilter.sys [119392 2025-06-27] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 BthA2dp; C:\windows\System32\drivers\BthA2dp.sys [569344 2024-10-25] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\windows\System32\drivers\bthhfenum.sys [200704 2024-10-25] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\windows\System32\drivers\bthmodem.sys [110592 2024-10-25] (Microsoft Corporation) [File not signed]
R0 CRUWBlocker; C:\windows\System32\drivers\CRUWBlocker.sys [40152 2018-08-29] (CRU Acquisition Group, LLC -> CRU Acquisition Group, LLC)
R3 e1dexpress; C:\windows\System32\DriverStore\FileRepository\e1d.inf_amd64_4b6c75e305805698\e1d.sys [615504 2025-12-02] (Intel Corporation -> Intel Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae.sys [159296 2026-07-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 Gemma; C:\windows\System32\DRIVERS\gemma.sys [1793112 2025-06-26] (Microsoft Windows Hardware Compatibility Publisher -> BitDefender S.R.L. Bucharest, ROMANIA)
R1 GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [23744 2026-01-13] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd)
R3 HKKbdFltr; C:\windows\System32\drivers\HKKbdFltr.sys [40320 2019-03-05] (WDKTestCert stone.cheng,131963286194994418 -> Insyde Software Corp.)
R2 Ignisv2; C:\windows\System32\drivers\ignisv2.sys [1155160 2026-07-08] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 KslD; C:\windows\System32\drivers\wd\KslD.sys [82352 2026-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 LBAI; C:\windows\System32\Drivers\LBAI.sys [22392 2025-12-02] (Microsoft Windows Hardware Compatibility Publisher -> Lenovo)
R2 mbamchameleon; C:\windows\System32\Drivers\MbamChameleon.sys [235624 2026-07-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\windows\System32\DRIVERS\MbamElam.sys [22120 2026-07-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\Drivers\farflt11.sys [216680 2026-07-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\windows\System32\Drivers\mbam.sys [132712 2026-07-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [246376 2026-07-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\windows\system32\DRIVERS\mwac.sys [190096 2026-07-28] (Malwarebytes Inc -> Malwarebytes)
R3 RtlWlanu; C:\windows\System32\drivers\rtwlanu.sys [12434304 2026-01-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [23072 2024-08-23] (RealDefense LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [15600 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; C:\windows\System32\Drivers\SmartDefragDriver.sys [30744 2025-04-22] (IObit Information Technology -> IObit)
R2 Trufos; C:\windows\System32\drivers\Trufos.sys [636504 2026-05-25] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 vlflt; C:\windows\System32\drivers\vlflt.sys [1445440 2025-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S0 vmci; C:\windows\System32\drivers\vmci.sys [105016 2024-09-07] (Microsoft Windows Hardware Compatibility Publisher -> VMware, Inc.)
S3 WdBoot; C:\windows\system32\drivers\wd\WdBoot.sys [21888 2026-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\windows\system32\drivers\wd\WdFilter.sys [641416 2026-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [103816 2026-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\windows\System32\drivers\wireguard.sys [489368 2026-04-01] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
U3 FamilySvc; no ImagePath
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-07-28 11:05 - 2026-07-28 11:06 - 000030060 _____ C:\Users\Lenovo\Desktop\FRST.txt
2026-07-28 11:03 - 2026-07-28 11:06 - 000000000 ____D C:\FRST
2026-07-28 10:59 - 2026-07-28 10:59 - 000711764 _____ C:\windows\system32\perfh005.dat
2026-07-28 10:59 - 2026-07-28 10:59 - 000152978 _____ C:\windows\system32\perfc005.dat
2026-07-28 10:54 - 2026-07-28 10:54 - 000190096 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2026-07-28 10:54 - 2026-07-28 10:54 - 000000000 ____D C:\Users\Lenovo\AppData\LocalLow\IGDump
2026-07-28 00:30 - 2026-07-28 00:31 - 081359168 _____ C:\Users\Lenovo\Desktop\ccsetup641.zip
2026-07-27 23:58 - 2026-07-28 10:59 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Malwarebytes
2026-07-27 23:58 - 2026-07-27 23:58 - 000002060 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-27 23:58 - 2026-07-27 23:58 - 000002048 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-07-27 23:58 - 2026-07-27 23:58 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Sentry
2026-07-27 23:58 - 2026-07-27 23:58 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-27 23:57 - 2026-07-27 23:58 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-27 23:54 - 2026-07-27 23:56 - 457683976 _____ (Malwarebytes) C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe
2026-07-27 23:42 - 2026-07-28 11:02 - 002449920 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2026-07-27 22:53 - 2026-07-27 22:53 - 009630992 _____ (Malwarebytes) C:\Users\Lenovo\Desktop\adwcleaner.exe
2026-07-27 22:42 - 2026-07-27 22:42 - 000000000 ____D C:\ProgramData\!SASCORE
2026-07-27 22:40 - 2026-07-27 22:40 - 000000000 ____D C:\ProgramData\SUPERSetup
2026-07-27 22:36 - 2026-07-27 22:36 - 028389544 _____ (Glarysoft Ltd) C:\Users\Lenovo\Downloads\Glary_Utilities_v6.45.0.49.exe
2026-07-27 17:38 - 2026-07-28 08:47 - 000000000 ____D C:\Program Files (x86)\ScreenConnect Client (4959b9d0db00aad9)
2026-07-27 17:36 - 2026-07-27 17:35 - 013455360 _____ C:\Users\Lenovo\Desktop\ScreenConnect.ClientSetup (9).msi
2026-07-27 17:32 - 2026-07-27 19:02 - 000000000 ____D C:\Users\Lenovo\.hoptodesk
2026-07-27 17:32 - 2026-07-27 17:32 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\HopToDesk
2026-07-27 17:15 - 2026-07-27 17:15 - 000000000 ____D C:\Program Files\Koinly
2026-07-27 17:14 - 2026-07-27 17:14 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Koinly
2026-07-27 17:14 - 2026-07-27 17:14 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Koinly
2026-07-24 09:46 - 2026-07-28 10:32 - 000000000 ____D C:\windows\CbsTemp
2026-07-23 20:49 - 2026-07-23 20:49 - 000005120 _____ C:\Users\Lenovo\Downloads\Microsoft.Services.Store.winmd
2026-07-23 19:25 - 2026-07-23 19:25 - 000000000 ____D C:\Users\Lenovo\AppData\Local\CDex
2026-07-23 19:24 - 2026-07-23 19:24 - 000001043 _____ C:\Users\Public\Desktop\CDex.lnk
2026-07-23 19:24 - 2026-07-23 19:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex
2026-07-23 19:24 - 2026-07-23 19:24 - 000000000 ____D C:\Program Files (x86)\CDex
2026-07-23 19:10 - 2026-07-23 19:10 - 000000000 ____D C:\Users\Lenovo\AppData\Local\ashampoo
2026-07-23 19:09 - 2026-07-23 19:10 - 000000000 ____D C:\ProgramData\Ashampoo
2026-07-23 19:09 - 2026-07-23 19:09 - 000001383 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio FREE.lnk
2026-07-23 19:09 - 2026-07-23 19:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2026-07-23 19:09 - 2026-07-23 19:09 - 000000000 ____D C:\Program Files (x86)\Ashampoo
2026-07-23 19:06 - 2026-07-23 19:07 - 095865568 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Lenovo\Downloads\ashampoo_burning_studio_free_24045.exe
2026-07-23 18:34 - 2006-07-13 17:12 - 000090112 _____ C:\Users\Lenovo\Downloads\Spiritus.exe
2026-07-23 18:34 - 2006-07-13 17:12 - 000036864 _____ C:\Users\Lenovo\Downloads\Nitro.exe
2026-07-23 18:34 - 2006-07-13 17:12 - 000028672 _____ C:\Users\Lenovo\Downloads\CoreLib.dll
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Tools
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Template
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Languages
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Definitions
2026-07-23 18:34 - 2006-07-08 14:55 - 000000000 ____D C:\Users\Lenovo\Downloads\NSIS
2026-07-23 18:34 - 2006-07-07 20:03 - 000000000 ____D C:\Users\Lenovo\Downloads\Tmp
2026-07-23 18:33 - 2026-07-23 18:33 - 000487004 _____ C:\Users\Lenovo\Downloads\neroLite_0.1.2_ALPHA.rar
2026-07-21 14:52 - 2026-07-21 14:52 - 012307978 _____ C:\Users\Lenovo\Downloads\22_07_2026.pdf
2026-07-17 19:07 - 2026-07-17 19:07 - 076866460 _____ C:\Users\Lenovo\Downloads\CODA - Seš vůl (Official Music Video).mp4
2026-07-16 23:40 - 2026-07-17 00:33 - 000000000 ____D C:\Users\Lenovo\Documents\REHA - kolena
2026-07-15 10:28 - 2026-07-15 10:28 - 000191589 _____ C:\Users\Lenovo\Downloads\vysledek-vypoctu (1).pdf
2026-07-13 22:56 - 2026-07-13 23:44 - 000000000 ____D C:\Users\Lenovo\Desktop\jízdní řády
2026-07-05 20:33 - 2026-07-05 20:33 - 000002073 _____ C:\Users\Lenovo\Downloads\1727502248_oznámení.html
2026-07-02 10:20 - 2026-07-02 10:20 - 014943599 _____ C:\Users\Lenovo\Downloads\34006056_HCR3818DNMM_manual_CZSKHU.pdf
2026-07-01 23:33 - 2026-07-01 23:33 - 000962566 _____ C:\Users\Lenovo\Downloads\4024237049.pdf
2026-06-30 09:59 - 2026-06-30 09:59 - 027359624 _____ C:\Users\Lenovo\Documents\ebook-pruvodce-Botanic.pdf
2026-06-29 19:15 - 2026-06-29 19:15 - 028389448 _____ (Glarysoft Ltd) C:\Users\Lenovo\Downloads\Glary_Utilities_v6.44.0.48.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-07-28 11:02 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemTemp
2026-07-28 11:02 - 2024-04-01 09:26 - 000000000 ____D C:\windows\AppReadiness
2026-07-28 11:02 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-28 10:59 - 2025-08-12 15:14 - 000000000 ___HD C:\Users\Lenovo\Downloads\.opera
2026-07-28 10:59 - 2025-08-12 15:14 - 000000000 ___HD C:\Users\Lenovo\.opera
2026-07-28 10:59 - 2024-10-02 09:30 - 001692324 _____ C:\windows\system32\PerfStringBackup.INI
2026-07-28 10:59 - 2024-04-01 09:24 - 000000000 ____D C:\windows\INF
2026-07-28 10:54 - 2025-02-11 18:14 - 000000000 ____D C:\Program Files (x86)\Glary Utilities
2026-07-28 10:54 - 2025-01-03 15:01 - 000000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2026-07-28 10:54 - 2024-10-02 09:23 - 000084680 _____ C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-07-28 10:53 - 2024-10-02 09:23 - 000000006 ____H C:\windows\Tasks\SA.DAT
2026-07-28 10:53 - 2024-10-02 09:22 - 000012288 ___SH C:\DumpStack.log.tmp
2026-07-28 10:53 - 2024-04-01 09:26 - 000000000 ___HD C:\windows\ELAMBKUP
2026-07-28 10:53 - 2024-04-01 09:21 - 001048576 _____ C:\windows\system32\config\BBI
2026-07-28 09:26 - 2025-01-03 15:01 - 000000000 ____D C:\Users\Lenovo\AppData\Local\D3DSCache
2026-07-28 08:36 - 2024-04-01 09:21 - 000065536 _____ C:\windows\system32\config\ELAM
2026-07-28 02:08 - 2025-02-22 22:51 - 000000000 ____D C:\Users\Lenovo\Documents\CC - zálohy
2026-07-28 02:04 - 2025-02-20 01:13 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\XnView
2026-07-28 01:42 - 2025-04-06 19:28 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Word
2026-07-28 01:16 - 2025-04-30 22:43 - 000000000 ____D C:\Users\Lenovo\AppData\Local\CrashDumps
2026-07-27 23:58 - 2025-01-03 15:01 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Packages
2026-07-27 23:58 - 2024-10-02 09:27 - 000000000 ____D C:\ProgramData\Packages
2026-07-27 23:58 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-27 22:45 - 2025-12-11 02:16 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-07-27 22:44 - 2025-12-11 15:01 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2026-07-27 22:37 - 2025-02-11 18:14 - 000003272 _____ C:\windows\system32\Tasks\GlaryInitialize
2026-07-27 22:37 - 2025-02-11 18:14 - 000001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities.lnk
2026-07-27 22:37 - 2025-02-11 18:14 - 000001142 _____ C:\Users\Public\Desktop\Glary Utilities.lnk
2026-07-27 22:35 - 2025-03-07 11:36 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Mp3tag
2026-07-27 22:34 - 2025-12-05 11:41 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows Photo Viewer
2026-07-27 17:32 - 2025-01-03 15:01 - 000000000 ____D C:\Users\Lenovo
2026-07-27 14:08 - 2024-10-02 09:22 - 000000000 ____D C:\windows\system32\SleepStudy
2026-07-26 18:04 - 2024-10-02 09:24 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-24 08:10 - 2025-04-06 18:59 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Nero
2026-07-24 08:10 - 2025-01-03 15:07 - 000000000 ____D C:\Users\Lenovo\AppData\Local\PlaceholderTileLogoFolder
2026-07-23 21:03 - 2025-06-23 09:51 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\MyPhoneExplorer
2026-07-23 19:10 - 2025-04-06 17:06 - 000000000 ____D C:\ProgramData\Package Cache
2026-07-23 18:02 - 2025-02-25 19:45 - 000000000 ____D C:\Users\Lenovo\Desktop\XRecode III 1.59 32-64 bit Portable [elladajarek]
2026-07-21 17:56 - 2024-10-02 09:24 - 000003714 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{5B822D49-CBB9-4192-A464-F6834914AD0A}
2026-07-21 17:56 - 2024-10-02 09:24 - 000003588 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{2AF2D925-44DF-4EA4-B305-206436DD09BC}
2026-07-21 11:53 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemResources
2026-07-21 11:53 - 2024-04-01 09:26 - 000000000 ____D C:\windows\BrowserCore
2026-07-21 11:53 - 2024-04-01 09:26 - 000000000 ____D C:\windows\bcastdvr
2026-07-21 11:36 - 2025-07-14 13:46 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Deployment
2026-07-19 09:46 - 2024-10-02 09:25 - 003367936 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll
2026-07-17 00:34 - 2025-01-03 15:08 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\vlc
2026-07-15 13:27 - 2024-10-02 09:22 - 000484496 _____ C:\windows\system32\FNTCACHE.DAT
2026-07-15 13:25 - 2024-04-01 18:30 - 000000000 ____D C:\windows\system32\Microsoft-Edge-WebView
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ___RD C:\windows\ImmersiveControlPanel
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\setup
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\Dism
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\setup
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\SecureBootUpdates
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\oobe
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\Dism
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\PolicyDefinitions
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-07-15 13:25 - 2024-04-01 09:21 - 000000000 ____D C:\windows\servicing
2026-07-15 08:16 - 2024-10-02 10:04 - 000000000 ____D C:\windows\system32\MRT
2026-07-15 08:14 - 2024-10-02 10:04 - 228534800 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2026-07-08 16:04 - 2026-04-01 15:34 - 001155160 _____ (Bitdefender) C:\windows\system32\Drivers\Ignisv2.sys
2026-07-07 23:36 - 2026-05-13 00:04 - 000000000 ____D C:\windows\SecureBoot
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\UUS
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\WinMetadata
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\vi-VN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ur-PK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ug-CN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\tt-RU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\te-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ta-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\sq-AL
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\quz-PE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\qps-plocm
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\qps-ploc
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\pa-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\or-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\oobe
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\nn-NO
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ne-NP
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mt-MT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mr-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ml-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mk-MK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mi-NZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\migwiz
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lv-LV
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lt-LT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lo-LA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lb-LU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kok-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\km-KH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kk-KZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ka-GE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\is-IS
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\InstallShield
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\id-ID
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\hy-AM
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\hi-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gu-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gl-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gd-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ga-IE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\fil-PH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\fa-IR
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\eu-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\et-EE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\es-MX
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\cy-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ca-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\bn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\be-BY
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\as-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\am-ET
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\af-ZA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\WinMetadata
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\WinBioPlugIns
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\vi-VN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ur-PK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ug-CN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\tt-RU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\te-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ta-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\Sysprep
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\sq-AL
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ShellExperiences
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\quz-PE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\qps-plocm
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\qps-ploc
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\PerceptionSimulation
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\pa-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\or-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\nn-NO
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ne-NP
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mt-MT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mr-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ml-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mk-MK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mi-NZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\migwiz
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lv-LV
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lt-LT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lo-LA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lb-LU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kok-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\km-KH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kk-KZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ka-GE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\is-IS
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\id-ID
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\hy-AM
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\hi-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\HealthAttestationClient
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gu-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gl-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gd-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ga-IE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\fil-PH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\fa-IR
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\eu-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\et-EE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\es-MX
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\cy-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ca-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\bn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\be-BY
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\as-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\appraiser
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\am-ET
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\af-ZA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\ShellExperiences
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\ShellComponents
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\Provisioning
2026-07-07 23:35 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemApps
2026-07-07 09:18 - 2025-04-09 15:12 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-07-06 19:42 - 2025-04-06 19:22 - 000003194 _____ C:\windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-07-06 19:42 - 2025-04-06 19:22 - 000001990 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-06 19:42 - 2025-02-06 12:31 - 000003546 _____ C:\windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-119869544-2784913804-2825771880-1006
2026-07-06 19:42 - 2025-01-03 15:03 - 000003592 _____ C:\windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-1006
==================== Files in the root of some directories ========
2025-12-23 23:06 - 2025-12-23 23:06 - 000007311 _____ () C:\Users\Lenovo\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2026
Ran by Lenovo (administrator) on DTP-S4LA1306 (LENOVO 30BGS6660R) (28-07-2026 11:05:54)
Running from C:\Users\Lenovo\Desktop\FRST64.exe
Loaded Profiles: Lenovo
Platform: Microsoft Windows 11 Pro Version 24H2 26100.8894 (X64) Language: Čeština (Česko)
Default browser: "C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Bitdefender Agent\ProductAgentService.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\27.1.1.41\DiscoverySrv.exe
(C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdntwrk.exe
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bduserhost.exe <3>
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (S.C. BITDEFENDER S.R.L. -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\wsccommunicator.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Lenovo\AppData\Local\Programs\Opera\125.0.5729.49\opera_crashreporter.exe
(DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxEM.exe
(explorer.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnapp.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Glarysoft Ltd -> Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities\Integrator.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\Installer\setup.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.99\msedgewebview2.exe <5>
(Opera Norway AS -> Opera Software) C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe <38>
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\redline\bdredline.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\Safepay\bdservicehost.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe <3>
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Glarysoft Ltd -> Glarysoft Ltd) C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe
(services.exe ->) (Glarysoft Ltd -> Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities\x64\MemfilesService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a0f482a0fd3e2e74\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d7a222f6ce13d429\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_8559c34713c70ce4\RstMwService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (RealDefense LLC -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot_proxy.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.336.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <5>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18387904 2017-12-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Cm108Sound] => C:\windows\syswow64\RunDll32.exe C:\windows\Syswow64\cm108.dll,CMICtrlWnd [12935168 2012-11-30] (C-Media Corporation) [File not signed]
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe [1099664 2026-07-08] (Bitdefender SRL -> Bitdefender)
HKLM\...\Run: [BdVpnApp] => C:\Program Files\Bitdefender\Bitdefender VPN\BdVpnApp.exe [500968 2026-04-22] (Bitdefender SRL -> Bitdefender)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4751720 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [12460120 2026-07-27] (RealDefense LLC -> SUPERAntiSpyware)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42087896 2026-04-29] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Run: [Opera Stable] => C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe [2088408 2025-12-22] (Opera Norway AS -> Opera Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\150.0.7871.187\Installer\chrmstp.exe [7691928 2026-07-27] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.168\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level (No File)
HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-7589-DBF523A60F4D}] ->
BootExecute: autocheck autochk *
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {BB6EC972-0BC5-4628-B522-B4D6A047B386} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {8AAA95F1-CD27-4E76-BE0F-0568EE92276E} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\27.1.1.41\WatchDog.exe [1191048 2026-05-18] (Bitdefender SRL -> Bitdefender) -> C:\Program Files\Bitdefender Agent\27.1.1.41\repair
Task: {C59BCD97-4735-41D9-9C8B-07C065FE03CD} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [7746960 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {CEBFE14F-7527-414F-B038-C90F50D288A7} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [3385624 2026-07-15] (Microsoft Windows -> Microsoft Corporation)
Task: {561288A1-F443-44B6-90E7-E24800846644} - System32\Tasks\GlaryInitialize => C:\Program Files (x86)\Glary Utilities\Initialize.exe [143760 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
Task: {F44FF247-AEA0-42D1-A630-7DDDAEF31D94} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{C897EE46-BE9B-417E-91DE-5A7C07821726} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC)
Task: {65804F8A-DEC7-43D2-927A-F5545C410A1A} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500 => "C:\Users\Administrator\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe" (No File)
Task: {E56EF78F-88A6-4B97-9129-AD450B3AB852} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [11419480 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B7C549E6-6D10-490C-AB02-35D37AA09090} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {3738FAD5-639C-4B54-AE92-39BAB1A9FDE2} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\opushutil.exe [61280 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {90456870-DB15-44B8-883E-9D3C88A155BC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {BDE97274-8E1B-43E0-8207-CC3DF371BB05} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {C7CA1A70-4171-417D-AEED-576D817CA33A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {BE7CB453-4108-49EE-902D-72CD8ED0079D} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {9DEC1041-7CEE-45B7-86E1-AA1055FCED87} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {71607933-2DD7-478B-869B-4F01A3B703D3} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {120CA2B4-B7B5-452B-B64F-61CC0204C9AE} - System32\Tasks\OneDrive Startup Task-S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDriveLauncher.exe [761192 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {41F43DCD-D56B-49CF-BED2-76690D118DDE} - System32\Tasks\Opera scheduled assistant Autoupdate 1740505846 => C:\Users\Lenovo\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [6233560 2025-12-18] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --installdir="C:\Users\Lenovo\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {2E73F38C-8963-4577-B14E-D24641FEF47F} - System32\Tasks\Opera scheduled Autoupdate 1740505841 => C:\Users\Lenovo\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [6233560 2025-12-18] (Opera Norway AS -> Opera Software)
Task: {851474A4-60AC-42EE-8CD1-791DF6104A40} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [7746960 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {579F5FBC-674A-4875-826C-9D9287666021} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-119869544-2784913804-2825771880-1006 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [7746960 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B041F8CA-A55F-4E4A-B5A7-4A52863366D4} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6635408 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {7BB6D05E-3C31-4AF3-88B7-4B422BAA8C19} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9274080 2026-01-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {26784175-317B-4ABB-8F42-E519152BD787} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )
Task: {CB3F8AEF-344B-4F4F-880F-931D0C394F12} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{40e968a8-5273-41b2-bce6-fa0bb4804094}: [DhcpNameServer] 192.168.128.80
Tcpip\..\Interfaces\{40e968a8-5273-41b2-bce6-fa0bb4804094}: [DhcpDomain] PC24.local
Tcpip\..\Interfaces\{e3207adb-087c-4416-99ee-c0074ab3b678}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext [2026-03-09] [Legacy] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-28]
Edge Notifications: Default -> hxxps://cvn65ge071bc7385nqpg.potentialconnection.co.in; hxxps://hydpyxyerubegw.potentialconnection.co.in; hxxps://www.facebook.com
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-07-27]
Edge Extension: (Bitdefender Anti-tracker) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dbconhplchnbippmjabbcedokimacfjl [2026-06-21]
Edge Extension: (Dokumenty Google offline) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-27]
Edge Extension: (Edge relevant text changes) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-03]
Edge Extension: (Word Replacer Max) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\neomjojkfljeeikfheknkihheflgbmnm [2026-07-27]
Edge Extension: (Blokátor reklam AdGuard) - C:\Users\Lenovo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2026-05-15]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [dbconhplchnbippmjabbcedokimacfjl]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default [2026-07-28]
CHR Extension: (Blokátor reklam AdGuard) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2025-07-13]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-07-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-01-03]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-119869544-2784913804-2825771880-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [khndhdhbebhaddchcgnalcjlaekbbeof]
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [374872 2026-07-27] (RealDefense LLC -> SUPERAntiSpyware.com)
S3 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 BDAppSrv; C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2966176 2023-07-20] (Bitdefender SRL -> Bitdefender)
R2 bdredline_agent; C:\Program Files\Bitdefender Agent\redline\bdredline.exe [2426992 2025-07-03] (Bitdefender SRL -> Bitdefender)
R2 BDSafepaySrv; C:\Program Files\Bitdefender\Bitdefender Security App\Safepay\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 bdvpnservice; C:\Program Files\Bitdefender\Bitdefender VPN\bdvpnservice.exe [496840 2026-04-22] (Bitdefender SRL -> Bitdefender)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [30785424 2026-07-15] (Gen Digital Inc. -> Gen Digital Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13288288 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncHelper.exe [3619176 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
R2 GUBootService; C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe [888200 2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
R2 GUMemfilesService; C:\Program Files (x86)\Glary Utilities\x64\MemfilesService.exe [416136 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
S3 GUPMService; C:\Program Files (x86)\Glary Utilities\GUPMService.exe [76688 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
S2 Koinly; C:\Program Files\Koinly\Koinly.exe [369808 2026-07-27] (Bayside Computer Systems Inc -> Purslane Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-28] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-27] (Malwarebytes Inc -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe [2088128 2026-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDriveUpdaterService.exe [4030312 2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [772624 2026-05-18] (Bitdefender SRL -> Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [877528 2026-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [321272 2026-07-08] (Bitdefender SRL -> Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858432 2026-07-08] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe [4451664 2026-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe [290704 2026-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 atc; C:\windows\System32\drivers\atc.sys [9168984 2026-06-25] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA)
R2 BdDci4; C:\windows\System32\drivers\bddci4.sys [1385040 2026-04-08] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S0 bdelam; C:\windows\System32\drivers\bdelam.sys [26064 2026-04-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
R3 bdprivmon; C:\windows\System32\drivers\bdprivmon.sys [49208 2025-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 bduefiscan; C:\windows\System32\drivers\bduefiscan.sys [53808 2025-08-13] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R3 bdvpn_callout; C:\Program Files\Bitdefender\Bitdefender VPN\Drivers\x64\netfilter.sys [119392 2025-06-27] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 BthA2dp; C:\windows\System32\drivers\BthA2dp.sys [569344 2024-10-25] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\windows\System32\drivers\bthhfenum.sys [200704 2024-10-25] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\windows\System32\drivers\bthmodem.sys [110592 2024-10-25] (Microsoft Corporation) [File not signed]
R0 CRUWBlocker; C:\windows\System32\drivers\CRUWBlocker.sys [40152 2018-08-29] (CRU Acquisition Group, LLC -> CRU Acquisition Group, LLC)
R3 e1dexpress; C:\windows\System32\DriverStore\FileRepository\e1d.inf_amd64_4b6c75e305805698\e1d.sys [615504 2025-12-02] (Intel Corporation -> Intel Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae.sys [159296 2026-07-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 Gemma; C:\windows\System32\DRIVERS\gemma.sys [1793112 2025-06-26] (Microsoft Windows Hardware Compatibility Publisher -> BitDefender S.R.L. Bucharest, ROMANIA)
R1 GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [23744 2026-01-13] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd)
R3 HKKbdFltr; C:\windows\System32\drivers\HKKbdFltr.sys [40320 2019-03-05] (WDKTestCert stone.cheng,131963286194994418 -> Insyde Software Corp.)
R2 Ignisv2; C:\windows\System32\drivers\ignisv2.sys [1155160 2026-07-08] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 KslD; C:\windows\System32\drivers\wd\KslD.sys [82352 2026-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 LBAI; C:\windows\System32\Drivers\LBAI.sys [22392 2025-12-02] (Microsoft Windows Hardware Compatibility Publisher -> Lenovo)
R2 mbamchameleon; C:\windows\System32\Drivers\MbamChameleon.sys [235624 2026-07-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\windows\System32\DRIVERS\MbamElam.sys [22120 2026-07-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\Drivers\farflt11.sys [216680 2026-07-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\windows\System32\Drivers\mbam.sys [132712 2026-07-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [246376 2026-07-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\windows\system32\DRIVERS\mwac.sys [190096 2026-07-28] (Malwarebytes Inc -> Malwarebytes)
R3 RtlWlanu; C:\windows\System32\drivers\rtwlanu.sys [12434304 2026-01-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [23072 2024-08-23] (RealDefense LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [15600 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; C:\windows\System32\Drivers\SmartDefragDriver.sys [30744 2025-04-22] (IObit Information Technology -> IObit)
R2 Trufos; C:\windows\System32\drivers\Trufos.sys [636504 2026-05-25] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 vlflt; C:\windows\System32\drivers\vlflt.sys [1445440 2025-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S0 vmci; C:\windows\System32\drivers\vmci.sys [105016 2024-09-07] (Microsoft Windows Hardware Compatibility Publisher -> VMware, Inc.)
S3 WdBoot; C:\windows\system32\drivers\wd\WdBoot.sys [21888 2026-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\windows\system32\drivers\wd\WdFilter.sys [641416 2026-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [103816 2026-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\windows\System32\drivers\wireguard.sys [489368 2026-04-01] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
U3 FamilySvc; no ImagePath
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-07-28 11:05 - 2026-07-28 11:06 - 000030060 _____ C:\Users\Lenovo\Desktop\FRST.txt
2026-07-28 11:03 - 2026-07-28 11:06 - 000000000 ____D C:\FRST
2026-07-28 10:59 - 2026-07-28 10:59 - 000711764 _____ C:\windows\system32\perfh005.dat
2026-07-28 10:59 - 2026-07-28 10:59 - 000152978 _____ C:\windows\system32\perfc005.dat
2026-07-28 10:54 - 2026-07-28 10:54 - 000190096 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2026-07-28 10:54 - 2026-07-28 10:54 - 000000000 ____D C:\Users\Lenovo\AppData\LocalLow\IGDump
2026-07-28 00:30 - 2026-07-28 00:31 - 081359168 _____ C:\Users\Lenovo\Desktop\ccsetup641.zip
2026-07-27 23:58 - 2026-07-28 10:59 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Malwarebytes
2026-07-27 23:58 - 2026-07-27 23:58 - 000002060 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-27 23:58 - 2026-07-27 23:58 - 000002048 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-07-27 23:58 - 2026-07-27 23:58 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Sentry
2026-07-27 23:58 - 2026-07-27 23:58 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-27 23:57 - 2026-07-27 23:58 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-27 23:54 - 2026-07-27 23:56 - 457683976 _____ (Malwarebytes) C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe
2026-07-27 23:42 - 2026-07-28 11:02 - 002449920 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2026-07-27 22:53 - 2026-07-27 22:53 - 009630992 _____ (Malwarebytes) C:\Users\Lenovo\Desktop\adwcleaner.exe
2026-07-27 22:42 - 2026-07-27 22:42 - 000000000 ____D C:\ProgramData\!SASCORE
2026-07-27 22:40 - 2026-07-27 22:40 - 000000000 ____D C:\ProgramData\SUPERSetup
2026-07-27 22:36 - 2026-07-27 22:36 - 028389544 _____ (Glarysoft Ltd) C:\Users\Lenovo\Downloads\Glary_Utilities_v6.45.0.49.exe
2026-07-27 17:38 - 2026-07-28 08:47 - 000000000 ____D C:\Program Files (x86)\ScreenConnect Client (4959b9d0db00aad9)
2026-07-27 17:36 - 2026-07-27 17:35 - 013455360 _____ C:\Users\Lenovo\Desktop\ScreenConnect.ClientSetup (9).msi
2026-07-27 17:32 - 2026-07-27 19:02 - 000000000 ____D C:\Users\Lenovo\.hoptodesk
2026-07-27 17:32 - 2026-07-27 17:32 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\HopToDesk
2026-07-27 17:15 - 2026-07-27 17:15 - 000000000 ____D C:\Program Files\Koinly
2026-07-27 17:14 - 2026-07-27 17:14 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Koinly
2026-07-27 17:14 - 2026-07-27 17:14 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Koinly
2026-07-24 09:46 - 2026-07-28 10:32 - 000000000 ____D C:\windows\CbsTemp
2026-07-23 20:49 - 2026-07-23 20:49 - 000005120 _____ C:\Users\Lenovo\Downloads\Microsoft.Services.Store.winmd
2026-07-23 19:25 - 2026-07-23 19:25 - 000000000 ____D C:\Users\Lenovo\AppData\Local\CDex
2026-07-23 19:24 - 2026-07-23 19:24 - 000001043 _____ C:\Users\Public\Desktop\CDex.lnk
2026-07-23 19:24 - 2026-07-23 19:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex
2026-07-23 19:24 - 2026-07-23 19:24 - 000000000 ____D C:\Program Files (x86)\CDex
2026-07-23 19:10 - 2026-07-23 19:10 - 000000000 ____D C:\Users\Lenovo\AppData\Local\ashampoo
2026-07-23 19:09 - 2026-07-23 19:10 - 000000000 ____D C:\ProgramData\Ashampoo
2026-07-23 19:09 - 2026-07-23 19:09 - 000001383 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio FREE.lnk
2026-07-23 19:09 - 2026-07-23 19:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2026-07-23 19:09 - 2026-07-23 19:09 - 000000000 ____D C:\Program Files (x86)\Ashampoo
2026-07-23 19:06 - 2026-07-23 19:07 - 095865568 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Lenovo\Downloads\ashampoo_burning_studio_free_24045.exe
2026-07-23 18:34 - 2006-07-13 17:12 - 000090112 _____ C:\Users\Lenovo\Downloads\Spiritus.exe
2026-07-23 18:34 - 2006-07-13 17:12 - 000036864 _____ C:\Users\Lenovo\Downloads\Nitro.exe
2026-07-23 18:34 - 2006-07-13 17:12 - 000028672 _____ C:\Users\Lenovo\Downloads\CoreLib.dll
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Tools
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Template
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Languages
2026-07-23 18:34 - 2006-07-13 17:12 - 000000000 ____D C:\Users\Lenovo\Downloads\Definitions
2026-07-23 18:34 - 2006-07-08 14:55 - 000000000 ____D C:\Users\Lenovo\Downloads\NSIS
2026-07-23 18:34 - 2006-07-07 20:03 - 000000000 ____D C:\Users\Lenovo\Downloads\Tmp
2026-07-23 18:33 - 2026-07-23 18:33 - 000487004 _____ C:\Users\Lenovo\Downloads\neroLite_0.1.2_ALPHA.rar
2026-07-21 14:52 - 2026-07-21 14:52 - 012307978 _____ C:\Users\Lenovo\Downloads\22_07_2026.pdf
2026-07-17 19:07 - 2026-07-17 19:07 - 076866460 _____ C:\Users\Lenovo\Downloads\CODA - Seš vůl (Official Music Video).mp4
2026-07-16 23:40 - 2026-07-17 00:33 - 000000000 ____D C:\Users\Lenovo\Documents\REHA - kolena
2026-07-15 10:28 - 2026-07-15 10:28 - 000191589 _____ C:\Users\Lenovo\Downloads\vysledek-vypoctu (1).pdf
2026-07-13 22:56 - 2026-07-13 23:44 - 000000000 ____D C:\Users\Lenovo\Desktop\jízdní řády
2026-07-05 20:33 - 2026-07-05 20:33 - 000002073 _____ C:\Users\Lenovo\Downloads\1727502248_oznámení.html
2026-07-02 10:20 - 2026-07-02 10:20 - 014943599 _____ C:\Users\Lenovo\Downloads\34006056_HCR3818DNMM_manual_CZSKHU.pdf
2026-07-01 23:33 - 2026-07-01 23:33 - 000962566 _____ C:\Users\Lenovo\Downloads\4024237049.pdf
2026-06-30 09:59 - 2026-06-30 09:59 - 027359624 _____ C:\Users\Lenovo\Documents\ebook-pruvodce-Botanic.pdf
2026-06-29 19:15 - 2026-06-29 19:15 - 028389448 _____ (Glarysoft Ltd) C:\Users\Lenovo\Downloads\Glary_Utilities_v6.44.0.48.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-07-28 11:02 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemTemp
2026-07-28 11:02 - 2024-04-01 09:26 - 000000000 ____D C:\windows\AppReadiness
2026-07-28 11:02 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-28 10:59 - 2025-08-12 15:14 - 000000000 ___HD C:\Users\Lenovo\Downloads\.opera
2026-07-28 10:59 - 2025-08-12 15:14 - 000000000 ___HD C:\Users\Lenovo\.opera
2026-07-28 10:59 - 2024-10-02 09:30 - 001692324 _____ C:\windows\system32\PerfStringBackup.INI
2026-07-28 10:59 - 2024-04-01 09:24 - 000000000 ____D C:\windows\INF
2026-07-28 10:54 - 2025-02-11 18:14 - 000000000 ____D C:\Program Files (x86)\Glary Utilities
2026-07-28 10:54 - 2025-01-03 15:01 - 000000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2026-07-28 10:54 - 2024-10-02 09:23 - 000084680 _____ C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-07-28 10:53 - 2024-10-02 09:23 - 000000006 ____H C:\windows\Tasks\SA.DAT
2026-07-28 10:53 - 2024-10-02 09:22 - 000012288 ___SH C:\DumpStack.log.tmp
2026-07-28 10:53 - 2024-04-01 09:26 - 000000000 ___HD C:\windows\ELAMBKUP
2026-07-28 10:53 - 2024-04-01 09:21 - 001048576 _____ C:\windows\system32\config\BBI
2026-07-28 09:26 - 2025-01-03 15:01 - 000000000 ____D C:\Users\Lenovo\AppData\Local\D3DSCache
2026-07-28 08:36 - 2024-04-01 09:21 - 000065536 _____ C:\windows\system32\config\ELAM
2026-07-28 02:08 - 2025-02-22 22:51 - 000000000 ____D C:\Users\Lenovo\Documents\CC - zálohy
2026-07-28 02:04 - 2025-02-20 01:13 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\XnView
2026-07-28 01:42 - 2025-04-06 19:28 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Word
2026-07-28 01:16 - 2025-04-30 22:43 - 000000000 ____D C:\Users\Lenovo\AppData\Local\CrashDumps
2026-07-27 23:58 - 2025-01-03 15:01 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Packages
2026-07-27 23:58 - 2024-10-02 09:27 - 000000000 ____D C:\ProgramData\Packages
2026-07-27 23:58 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-27 22:45 - 2025-12-11 02:16 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-07-27 22:44 - 2025-12-11 15:01 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2026-07-27 22:37 - 2025-02-11 18:14 - 000003272 _____ C:\windows\system32\Tasks\GlaryInitialize
2026-07-27 22:37 - 2025-02-11 18:14 - 000001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities.lnk
2026-07-27 22:37 - 2025-02-11 18:14 - 000001142 _____ C:\Users\Public\Desktop\Glary Utilities.lnk
2026-07-27 22:35 - 2025-03-07 11:36 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Mp3tag
2026-07-27 22:34 - 2025-12-05 11:41 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows Photo Viewer
2026-07-27 17:32 - 2025-01-03 15:01 - 000000000 ____D C:\Users\Lenovo
2026-07-27 14:08 - 2024-10-02 09:22 - 000000000 ____D C:\windows\system32\SleepStudy
2026-07-26 18:04 - 2024-10-02 09:24 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-24 08:10 - 2025-04-06 18:59 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\Nero
2026-07-24 08:10 - 2025-01-03 15:07 - 000000000 ____D C:\Users\Lenovo\AppData\Local\PlaceholderTileLogoFolder
2026-07-23 21:03 - 2025-06-23 09:51 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\MyPhoneExplorer
2026-07-23 19:10 - 2025-04-06 17:06 - 000000000 ____D C:\ProgramData\Package Cache
2026-07-23 18:02 - 2025-02-25 19:45 - 000000000 ____D C:\Users\Lenovo\Desktop\XRecode III 1.59 32-64 bit Portable [elladajarek]
2026-07-21 17:56 - 2024-10-02 09:24 - 000003714 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{5B822D49-CBB9-4192-A464-F6834914AD0A}
2026-07-21 17:56 - 2024-10-02 09:24 - 000003588 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{2AF2D925-44DF-4EA4-B305-206436DD09BC}
2026-07-21 11:53 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemResources
2026-07-21 11:53 - 2024-04-01 09:26 - 000000000 ____D C:\windows\BrowserCore
2026-07-21 11:53 - 2024-04-01 09:26 - 000000000 ____D C:\windows\bcastdvr
2026-07-21 11:36 - 2025-07-14 13:46 - 000000000 ____D C:\Users\Lenovo\AppData\Local\Deployment
2026-07-19 09:46 - 2024-10-02 09:25 - 003367936 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll
2026-07-17 00:34 - 2025-01-03 15:08 - 000000000 ____D C:\Users\Lenovo\AppData\Roaming\vlc
2026-07-15 13:27 - 2024-10-02 09:22 - 000484496 _____ C:\windows\system32\FNTCACHE.DAT
2026-07-15 13:25 - 2024-04-01 18:30 - 000000000 ____D C:\windows\system32\Microsoft-Edge-WebView
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ___RD C:\windows\ImmersiveControlPanel
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\setup
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\Dism
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\setup
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\SecureBootUpdates
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\oobe
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\Dism
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\windows\PolicyDefinitions
2026-07-15 13:25 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-07-15 13:25 - 2024-04-01 09:21 - 000000000 ____D C:\windows\servicing
2026-07-15 08:16 - 2024-10-02 10:04 - 000000000 ____D C:\windows\system32\MRT
2026-07-15 08:14 - 2024-10-02 10:04 - 228534800 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2026-07-08 16:04 - 2026-04-01 15:34 - 001155160 _____ (Bitdefender) C:\windows\system32\Drivers\Ignisv2.sys
2026-07-07 23:36 - 2026-05-13 00:04 - 000000000 ____D C:\windows\SecureBoot
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\UUS
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\WinMetadata
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\vi-VN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ur-PK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ug-CN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\tt-RU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\te-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ta-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\sq-AL
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\quz-PE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\qps-plocm
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\qps-ploc
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\pa-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\or-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\oobe
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\nn-NO
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ne-NP
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mt-MT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mr-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ml-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mk-MK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mi-NZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\migwiz
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lv-LV
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lt-LT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lo-LA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lb-LU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kok-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\km-KH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kk-KZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ka-GE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\is-IS
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\InstallShield
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\id-ID
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\hy-AM
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\hi-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gu-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gl-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gd-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ga-IE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\fil-PH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\fa-IR
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\eu-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\et-EE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\es-MX
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\cy-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ca-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\bn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\be-BY
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\as-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\am-ET
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\af-ZA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\WinMetadata
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\WinBioPlugIns
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\vi-VN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ur-PK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ug-CN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\tt-RU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\te-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ta-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\Sysprep
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\sq-AL
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ShellExperiences
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\quz-PE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\qps-plocm
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\qps-ploc
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\PerceptionSimulation
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\pa-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\or-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\nn-NO
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ne-NP
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mt-MT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mr-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ml-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mk-MK
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mi-NZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\migwiz
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lv-LV
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lt-LT
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lo-LA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lb-LU
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kok-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\km-KH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kk-KZ
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ka-GE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\is-IS
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\id-ID
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\hy-AM
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\hi-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\HealthAttestationClient
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gu-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gl-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gd-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ga-IE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\fil-PH
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\fa-IR
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\eu-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\et-EE
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\es-MX
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\cy-GB
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ca-ES
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\bn-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\be-BY
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\as-IN
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\appraiser
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\am-ET
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\af-ZA
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\ShellExperiences
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\ShellComponents
2026-07-07 23:36 - 2024-04-01 09:26 - 000000000 ____D C:\windows\Provisioning
2026-07-07 23:35 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemApps
2026-07-07 09:18 - 2025-04-09 15:12 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-07-06 19:42 - 2025-04-06 19:22 - 000003194 _____ C:\windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-07-06 19:42 - 2025-04-06 19:22 - 000001990 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-06 19:42 - 2025-02-06 12:31 - 000003546 _____ C:\windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-119869544-2784913804-2825771880-1006
2026-07-06 19:42 - 2025-01-03 15:03 - 000003592 _____ C:\windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-1006
==================== Files in the root of some directories ========
2025-12-23 23:06 - 2025-12-23 23:06 - 000007311 _____ () C:\Users\Lenovo\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
- Rudy
- Site Admin

- Příspěvky: 120050
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: kontrola logu
Zdravím§
Přidejte ještě log Addition, abych mohl provést prohlídku komplexně. Najdete ho na ploše v souboru addition.txt. Děkuji.
Přidejte ještě log Addition, abych mohl provést prohlídku komplexně. Najdete ho na ploše v souboru addition.txt. Děkuji.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: kontrola logu
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-07-2026
Ran by Lenovo (28-07-2026 11:07:46)
Running from C:\Users\Lenovo\Desktop
Microsoft Windows 11 Pro Version 24H2 26100.8894 (X64) (2024-11-08 12:32:50)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-119869544-2784913804-2825771880-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-119869544-2784913804-2825771880-503 - Limited - Disabled)
Guest (S-1-5-21-119869544-2784913804-2825771880-501 - Limited - Disabled)
Lenovo (DisplayName: ) (S-1-5-21-119869544-2784913804-2825771880-1006 - Administrators - Enabled) => C:\Users\Lenovo
WDAGUtilityAccount (S-1-5-21-119869544-2784913804-2825771880-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {57FC340E-A75D-133C-CE37-7EC3762140D5}
FW: Bitdefender Firewall (Enabled) {6FC7B52B-ED32-1264-E568-D7F688F207AE}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 23.01 (x64) (HKLM\...\7-Zip) (Version: 23.01 - Igor Pavlov)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-FF00-7760-BC15014EA700}) (Version: 26.001.21529 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AIDA64 Extreme v8.00 (HKLM\...\AIDA64 Extreme_is1) (Version: 8.00 - FinalWire Ltd.)
Ashampoo Burning Studio FREE (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.24.13 - Ashampoo GmbH & Co. KG)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 27.1.1.41 - Bitdefender)
Bitdefender Internet Security (HKLM\...\Bitdefender) (Version: 27.0.57.313 - Bitdefender)
Bitdefender VPN (HKLM\...\Bitdefender VPN) (Version: 27.3.3.6 - Bitdefender)
Canon MP Navigator EX 1.0 (HKLM-x32\...\MP Navigator EX 1.0) (Version: - )
CanoScan LiDE 90 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2412) (Version: - )
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.9.1432.1847 - Piriform)
CDex - Digital Audio CD Extractor and Converter (HKLM-x32\...\CDex) (Version: 2.24.0.2020 - CDex.mu)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 150.0.4078.96 - Microsoft Corporation)
Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
Glary Utilities 6.45 (HKLM-x32\...\Glary Utilities) (Version: 6.45.0.49 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 150.0.7871.187 - Google LLC)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Lenovo System Update (HKLM-x32\...\TVSU_is1) (Version: 5.08.03.59 - Lenovo)
Malwarebytes version 5.6.2.268 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.2.268 - Malwarebytes)
MediaCoder 0.8.65 (HKLM\...\MediaCoder) (Version: 0.8.65 - Mediatronic)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.99 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.105 - Microsoft Corporation) Hidden
Microsoft Office 2019 pro domácnosti a podnikatele - cs-cz (HKLM\...\HomeBusiness2019Retail - cs-cz) (Version: 16.0.19127.20302 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.108.0607.0002 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.25503 - Microsoft)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.23.27820 (HKLM-x32\...\{852adda4-4c78-4a38-b583-c0b360a329d6}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.30.30704 (HKLM-x32\...\{4d8dcf8c-a72a-43e1-9833-c12724db736e}) (Version: 14.30.30704.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.23.27820 (HKLM\...\{9CA7111B-263D-45DE-B898-61FAD30B3237}) (Version: 14.23.27820 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.23.27820 (HKLM\...\{A94EC1B2-932B-49D7-8AF2-4FBD29FF314B}) (Version: 14.23.27820 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.30.30704 (HKLM-x32\...\{BF08E976-B92E-4336-B56F-2171179476C4}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.30.30704 (HKLM-x32\...\{F6080405-9FA8-4CAA-9982-14E95D1A3DAC}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Windows Media Video 9 VCM (HKLM-x32\...\WMV9_VCM) (Version: - )
Mp3tag v3.28 (HKLM\...\Mp3tag) (Version: 3.28 - Florian Heidenreich)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 2.3 - F.J. Wechselberger)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20302 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.14026.20302 - Microsoft Corporation) Hidden
Opera Stable 125.0.5729.49 (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Opera 125.0.5729.49) (Version: 125.0.5729.49 - Opera Software)
PhotoFiltre Studio X (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\PhotoFiltre Studio X) (Version: - )
SUPER (C) v2022.Build.80+3D+Recorder verze released on (Decembe (HKLM-x32\...\{834EABE0-62B9-65D3-E51C-56EAE21F0306B}_is1) (Version: released on (December 12, 2022), - eRightSoft)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 10.0.1288 - SUPERAntiSpyware.com)
USB PnP Sound Device (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F392006300}) (Version: 1.00.0002 - C-Media Electronics, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Winaero Tweaker (HKLM\...\Winaero Tweaker_is1) (Version: 1.63.0.0 - Winaero)
XnView (HKLM-x32\...\XnView_is1) (Version: 2.52.0 - Gougelet Pierre-e)
Chrome apps:
============
Disk Google (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\550e56caa900f8771cb22a5956bbdcd2) (Version: 1.0 - Google\Chrome)
Dokumenty (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\7ba3920e0ae7d693c285409374d6b3b5) (Version: 1.0 - Google\Chrome)
Gmail (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\bd88beb1175a770fc559287bc7a186b7) (Version: 1.0 - Google\Chrome)
Prezentace (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\6731c2be06451a81494ec2d3821398e6) (Version: 1.0 - Google\Chrome)
YouTube (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\f7dc6435b15fa8a7d14797683a3fd873) (Version: 1.0 - Google\Chrome)
Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3624.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\windows\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-02] ()
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\windows\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-02] ()
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3912.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\windows\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-02] ()
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2026-05-05] ()
Bitdefender CL Contextual Menu -> C:\Program Files\Bitdefender\Bitdefender Security App [2026-07-28] (Bitdefender)
Local Artificial Intelligence Manager -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\AI [2025-12-10] ()
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2026-07-28] ()
Microsoft.Office.ActionsServer -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\ActionsServer [2025-12-10] ()
Mp3tag -> C:\Program Files\Mp3tag [2025-12-10] (Florian Heidenreich)
Nero Express 365 -> C:\Program Files\WindowsApps\NeroAG.NeroExpress365_1.0.33.0_x86__k5ye2zvjqqeaw [2026-07-24] (Nero AG)
OfficePushNotificationsUtility -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16 [2025-12-10] ()
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-119869544-2784913804-2825771880-1006_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-119869544-2784913804-2825771880-1006_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Program Files (x86)\MyPhoneExplorer\DLL\ShellMgr.dll [2010-03-30] (F.J. Wechselberger) [File not signed]
ContextMenuHandlers1: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\windows\System32\IObitSmartDefragExtension.dll [2025-04-22] (IObit Information Technology -> IObit)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxDTCM.dll [2019-01-22] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\windows\System32\IObitSmartDefragExtension.dll [2025-04-22] (IObit Information Technology -> IObit)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\i420vfw.dll [70656 2004-01-24] (www.helixcommunity.org) [File not signed]
HKLM\...\Drivers32: [vidc.yv12] => C:\Windows\SysWOW64\yv12vfw.dll [70656 2004-01-24] (www.helixcommunity.org) [File not signed]
HKLM\...\Drivers32-x32: [VIDC.WMV3] => wmv9vcm.dll
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2025-08-15 04:15 - 2025-08-15 04:15 - 000030720 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\Acrobat Elements\ContextMenuShim64.cze
2025-01-03 15:03 - 2023-06-20 10:00 - 000101376 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:MBAM.Zone.Identifier [450]
AlternateDataStreams: C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\bitdefender_windows_90e9d651-86a0-4e28-a60b-ae7baf2bf12d.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.40.0.44.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.41.0.45.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Microsoft Photos Installer.exe:BDU [0]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ScreenConnect Client (4959b9d0db00aad9) => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2026-05-14 18:07 - 2026-05-14 18:07 - 000000827 _____ C:\windows\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi: TP-Link Wireless USB Adapter -> rtwlanu.sys
Ethernet: Intel(R) Ethernet Connection (2) I219-LM -> e1d.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\Control Panel\Desktop\\Wallpaper -> C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\LiteTouch.lnk
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_5EF70F99B4529735F3564FFE246DB961"
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{51B2B774-25EF-4A32-B09F-C5C09D379223}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{1AC62852-73C6-4057-9F47-0B205C0CD2D8}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{EED0E80F-2C32-4AAE-A5B2-203B5560F3F9}] => (Allow) C:\Program Files (x86)\Nero\Nero 2021\Nero Burning ROM\StartNBR.exe (Nero AG -> Nero AG)
FirewallRules: [{D8491E57-DC9A-48DF-8612-6847B2941E46}] => (Allow) C:\Program Files (x86)\Nero\Nero 2021\Nero MediaHome\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [{C428B7C7-398F-41B1-8E9C-A35A3FCF0273}] => (Allow) C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{9F878849-2EF2-4CA9-9578-37857A7AAFAD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{16F7099B-1197-4137-B4C3-2F49EE225316}] => (Allow) C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\windows\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B3F96FCD-26A1-467A-9B7A-B823CCC777B3}] => (Allow) C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{A44C7758-3E77-40DC-AA7A-3E7B7FE67ABE}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{35051DC1-2DB6-4ACF-B32B-64A34C725A43}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B57E75CD-D79D-4561-9123-4D4C9B7E2BDD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6439BFFB-2AC4-4689-8954-CE1E37BD6F0A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{80626F66-AB5D-4E28-BC88-C18D9D048C4E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{74B46C87-7F5B-43F5-89A1-2DCF8C3A1841}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
27-07-2026 13:31:27 Naplánovaný kontrolní bod
27-07-2026 17:37:18 Installed ScreenConnect Client (4959b9d0db00aad9)
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (07/28/2026 11:06:28 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 11:06:28 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 10:55:01 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://NTC-KeyId-1591d4b6eaf98d0104864 ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Tue, 28 Jul 2026 08:55:00 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 9772756d-9f51-452b-b31b-ce1cf1626e8c
Metoda: POST(3328ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/28/2026 08:44:23 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 08:44:23 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 08:33:12 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://NTC-KeyId-1591d4b6eaf98d0104864 ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Tue, 28 Jul 2026 06:33:10 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 6455bce1-8260-4a25-83a4-37c6c8ced406
Metoda: POST(3906ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/28/2026 01:28:34 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 01:28:33 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
System errors:
=============
Error: (07/28/2026 10:53:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Koinly neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Error: (07/28/2026 10:53:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Koinly bylo dosaženo časového limitu (45000 ms).
Error: (07/28/2026 08:31:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Koinly neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Error: (07/28/2026 08:31:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Koinly bylo dosaženo časového limitu (45000 ms).
Error: (07/28/2026 02:05:12 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (07/28/2026 12:37:28 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (07/28/2026 12:35:59 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (07/28/2026 12:32:38 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Windows Defender:
================
CodeIntegrity:
===============
Date: 2026-07-28 11:05:46
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender Security\bdamsi\dlls_267059357120000000\antimalware_provider64.dll that did not meet the Windows signing level requirements.
Date: 2026-07-28 11:05:46
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO S06KT67A 01/12/2024
Motherboard: LENOVO 103D
Processor: Intel(R) Xeon(R) CPU E3-1225 v5 @ 3.30GHz
Percentage of memory in use: 24%
Total physical RAM: 32652.05 MB
Available physical RAM: 24574.94 MB
Total Virtual: 34700.05 MB
Available Virtual: 27150.23 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:471.56 GB) (Free:219.21 GB) (Model: SK hynix SC313 HFS512G32TNF-N3A0A) NTFS
Drive e: (Nový svazek) (Fixed) (Total:931.51 GB) (Free:704.89 GB) (Model: ST1000DM003-1SB102) NTFS
\\?\Volume{4741ca1b-4dbf-43ea-b518-b760bdfd27da}\ (Recovery) (Fixed) (Total:4.77 GB) (Free:4.04 GB) NTFS
\\?\Volume{ba5fbc33-b5dd-4468-b9fb-349269ef43b8}\ (Bitdefender Virtual Disk) (Fixed) (Total:0.03 GB) (Free:0.02 GB) NTFS
\\?\Volume{048f2854-5f7e-4977-b719-6470b88f7754}\ (BOOT) (Fixed) (Total:0.48 GB) (Free:0.45 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 00EA67FA)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: CCABD939)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
==========================================================
Disk: 2 (Protective MBR) (Size: 32 MB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
Ran by Lenovo (28-07-2026 11:07:46)
Running from C:\Users\Lenovo\Desktop
Microsoft Windows 11 Pro Version 24H2 26100.8894 (X64) (2024-11-08 12:32:50)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-119869544-2784913804-2825771880-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-119869544-2784913804-2825771880-503 - Limited - Disabled)
Guest (S-1-5-21-119869544-2784913804-2825771880-501 - Limited - Disabled)
Lenovo (DisplayName: ) (S-1-5-21-119869544-2784913804-2825771880-1006 - Administrators - Enabled) => C:\Users\Lenovo
WDAGUtilityAccount (S-1-5-21-119869544-2784913804-2825771880-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {57FC340E-A75D-133C-CE37-7EC3762140D5}
FW: Bitdefender Firewall (Enabled) {6FC7B52B-ED32-1264-E568-D7F688F207AE}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 23.01 (x64) (HKLM\...\7-Zip) (Version: 23.01 - Igor Pavlov)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-FF00-7760-BC15014EA700}) (Version: 26.001.21529 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AIDA64 Extreme v8.00 (HKLM\...\AIDA64 Extreme_is1) (Version: 8.00 - FinalWire Ltd.)
Ashampoo Burning Studio FREE (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.24.13 - Ashampoo GmbH & Co. KG)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 27.1.1.41 - Bitdefender)
Bitdefender Internet Security (HKLM\...\Bitdefender) (Version: 27.0.57.313 - Bitdefender)
Bitdefender VPN (HKLM\...\Bitdefender VPN) (Version: 27.3.3.6 - Bitdefender)
Canon MP Navigator EX 1.0 (HKLM-x32\...\MP Navigator EX 1.0) (Version: - )
CanoScan LiDE 90 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2412) (Version: - )
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.9.1432.1847 - Piriform)
CDex - Digital Audio CD Extractor and Converter (HKLM-x32\...\CDex) (Version: 2.24.0.2020 - CDex.mu)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 150.0.4078.96 - Microsoft Corporation)
Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
Glary Utilities 6.45 (HKLM-x32\...\Glary Utilities) (Version: 6.45.0.49 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 150.0.7871.187 - Google LLC)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Lenovo System Update (HKLM-x32\...\TVSU_is1) (Version: 5.08.03.59 - Lenovo)
Malwarebytes version 5.6.2.268 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.2.268 - Malwarebytes)
MediaCoder 0.8.65 (HKLM\...\MediaCoder) (Version: 0.8.65 - Mediatronic)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.99 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.105 - Microsoft Corporation) Hidden
Microsoft Office 2019 pro domácnosti a podnikatele - cs-cz (HKLM\...\HomeBusiness2019Retail - cs-cz) (Version: 16.0.19127.20302 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.108.0607.0002 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.25503 - Microsoft)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.23.27820 (HKLM-x32\...\{852adda4-4c78-4a38-b583-c0b360a329d6}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.30.30704 (HKLM-x32\...\{4d8dcf8c-a72a-43e1-9833-c12724db736e}) (Version: 14.30.30704.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.23.27820 (HKLM\...\{9CA7111B-263D-45DE-B898-61FAD30B3237}) (Version: 14.23.27820 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.23.27820 (HKLM\...\{A94EC1B2-932B-49D7-8AF2-4FBD29FF314B}) (Version: 14.23.27820 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.30.30704 (HKLM-x32\...\{BF08E976-B92E-4336-B56F-2171179476C4}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.30.30704 (HKLM-x32\...\{F6080405-9FA8-4CAA-9982-14E95D1A3DAC}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Windows Media Video 9 VCM (HKLM-x32\...\WMV9_VCM) (Version: - )
Mp3tag v3.28 (HKLM\...\Mp3tag) (Version: 3.28 - Florian Heidenreich)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 2.3 - F.J. Wechselberger)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20302 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.14026.20302 - Microsoft Corporation) Hidden
Opera Stable 125.0.5729.49 (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\Opera 125.0.5729.49) (Version: 125.0.5729.49 - Opera Software)
PhotoFiltre Studio X (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\PhotoFiltre Studio X) (Version: - )
SUPER (C) v2022.Build.80+3D+Recorder verze released on (Decembe (HKLM-x32\...\{834EABE0-62B9-65D3-E51C-56EAE21F0306B}_is1) (Version: released on (December 12, 2022), - eRightSoft)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 10.0.1288 - SUPERAntiSpyware.com)
USB PnP Sound Device (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F392006300}) (Version: 1.00.0002 - C-Media Electronics, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Winaero Tweaker (HKLM\...\Winaero Tweaker_is1) (Version: 1.63.0.0 - Winaero)
XnView (HKLM-x32\...\XnView_is1) (Version: 2.52.0 - Gougelet Pierre-e)
Chrome apps:
============
Disk Google (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\550e56caa900f8771cb22a5956bbdcd2) (Version: 1.0 - Google\Chrome)
Dokumenty (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\7ba3920e0ae7d693c285409374d6b3b5) (Version: 1.0 - Google\Chrome)
Gmail (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\bd88beb1175a770fc559287bc7a186b7) (Version: 1.0 - Google\Chrome)
Prezentace (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\6731c2be06451a81494ec2d3821398e6) (Version: 1.0 - Google\Chrome)
YouTube (HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\f7dc6435b15fa8a7d14797683a3fd873) (Version: 1.0 - Google\Chrome)
Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3624.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\windows\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-02] ()
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\windows\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-02] ()
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3912.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\windows\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-02] ()
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2026-05-05] ()
Bitdefender CL Contextual Menu -> C:\Program Files\Bitdefender\Bitdefender Security App [2026-07-28] (Bitdefender)
Local Artificial Intelligence Manager -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\AI [2025-12-10] ()
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2026-07-28] ()
Microsoft.Office.ActionsServer -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\ActionsServer [2025-12-10] ()
Mp3tag -> C:\Program Files\Mp3tag [2025-12-10] (Florian Heidenreich)
Nero Express 365 -> C:\Program Files\WindowsApps\NeroAG.NeroExpress365_1.0.33.0_x86__k5ye2zvjqqeaw [2026-07-24] (Nero AG)
OfficePushNotificationsUtility -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16 [2025-12-10] ()
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-119869544-2784913804-2825771880-1006_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-119869544-2784913804-2825771880-1006_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Program Files (x86)\MyPhoneExplorer\DLL\ShellMgr.dll [2010-03-30] (F.J. Wechselberger) [File not signed]
ContextMenuHandlers1: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\windows\System32\IObitSmartDefragExtension.dll [2025-04-22] (IObit Information Technology -> IObit)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-06] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2dda3b1147a3a572\igfxDTCM.dll [2019-01-22] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-01-17] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\windows\System32\IObitSmartDefragExtension.dll [2025-04-22] (IObit Information Technology -> IObit)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\i420vfw.dll [70656 2004-01-24] (www.helixcommunity.org) [File not signed]
HKLM\...\Drivers32: [vidc.yv12] => C:\Windows\SysWOW64\yv12vfw.dll [70656 2004-01-24] (www.helixcommunity.org) [File not signed]
HKLM\...\Drivers32-x32: [VIDC.WMV3] => wmv9vcm.dll
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2025-08-15 04:15 - 2025-08-15 04:15 - 000030720 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\Acrobat Elements\ContextMenuShim64.cze
2025-01-03 15:03 - 2023-06-20 10:00 - 000101376 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:MBAM.Zone.Identifier [450]
AlternateDataStreams: C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\bitdefender_windows_90e9d651-86a0-4e28-a60b-ae7baf2bf12d.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.40.0.44.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.41.0.45.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Microsoft Photos Installer.exe:BDU [0]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ScreenConnect Client (4959b9d0db00aad9) => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-08] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2026-05-14 18:07 - 2026-05-14 18:07 - 000000827 _____ C:\windows\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi: TP-Link Wireless USB Adapter -> rtwlanu.sys
Ethernet: Intel(R) Ethernet Connection (2) I219-LM -> e1d.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\Control Panel\Desktop\\Wallpaper -> C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\LiteTouch.lnk
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_5EF70F99B4529735F3564FFE246DB961"
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-119869544-2784913804-2825771880-1006\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{51B2B774-25EF-4A32-B09F-C5C09D379223}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{1AC62852-73C6-4057-9F47-0B205C0CD2D8}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{EED0E80F-2C32-4AAE-A5B2-203B5560F3F9}] => (Allow) C:\Program Files (x86)\Nero\Nero 2021\Nero Burning ROM\StartNBR.exe (Nero AG -> Nero AG)
FirewallRules: [{D8491E57-DC9A-48DF-8612-6847B2941E46}] => (Allow) C:\Program Files (x86)\Nero\Nero 2021\Nero MediaHome\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [{C428B7C7-398F-41B1-8E9C-A35A3FCF0273}] => (Allow) C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{9F878849-2EF2-4CA9-9578-37857A7AAFAD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{16F7099B-1197-4137-B4C3-2F49EE225316}] => (Allow) C:\Users\Lenovo\AppData\Local\Programs\Opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\windows\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B3F96FCD-26A1-467A-9B7A-B823CCC777B3}] => (Allow) C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{A44C7758-3E77-40DC-AA7A-3E7B7FE67ABE}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{35051DC1-2DB6-4ACF-B32B-64A34C725A43}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B57E75CD-D79D-4561-9123-4D4C9B7E2BDD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6439BFFB-2AC4-4689-8954-CE1E37BD6F0A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{80626F66-AB5D-4E28-BC88-C18D9D048C4E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.47051.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{74B46C87-7F5B-43F5-89A1-2DCF8C3A1841}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
27-07-2026 13:31:27 Naplánovaný kontrolní bod
27-07-2026 17:37:18 Installed ScreenConnect Client (4959b9d0db00aad9)
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (07/28/2026 11:06:28 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 11:06:28 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 10:55:01 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://NTC-KeyId-1591d4b6eaf98d0104864 ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Tue, 28 Jul 2026 08:55:00 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 9772756d-9f51-452b-b31b-ce1cf1626e8c
Metoda: POST(3328ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/28/2026 08:44:23 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 08:44:23 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 08:33:12 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://NTC-KeyId-1591d4b6eaf98d0104864 ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Tue, 28 Jul 2026 06:33:10 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 6455bce1-8260-4a25-83a4-37c6c8ced406
Metoda: POST(3906ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/28/2026 01:28:34 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
Error: (07/28/2026 01:28:33 AM) (Source: MsiInstaller) (EventID: 11730) (User: DTP-S4LA1306)
Description: Product: Adobe Refresh Manager -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an administrator, or contact your technical support group for assistance.
System errors:
=============
Error: (07/28/2026 10:53:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Koinly neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Error: (07/28/2026 10:53:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Koinly bylo dosaženo časového limitu (45000 ms).
Error: (07/28/2026 08:31:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Koinly neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Error: (07/28/2026 08:31:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Koinly bylo dosaženo časového limitu (45000 ms).
Error: (07/28/2026 02:05:12 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (07/28/2026 12:37:28 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (07/28/2026 12:35:59 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (07/28/2026 12:32:38 AM) (Source: DCOM) (EventID: 10000) (User: DTP-S4LA1306)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
Windows Defender:
================
CodeIntegrity:
===============
Date: 2026-07-28 11:05:46
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender Security\bdamsi\dlls_267059357120000000\antimalware_provider64.dll that did not meet the Windows signing level requirements.
Date: 2026-07-28 11:05:46
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO S06KT67A 01/12/2024
Motherboard: LENOVO 103D
Processor: Intel(R) Xeon(R) CPU E3-1225 v5 @ 3.30GHz
Percentage of memory in use: 24%
Total physical RAM: 32652.05 MB
Available physical RAM: 24574.94 MB
Total Virtual: 34700.05 MB
Available Virtual: 27150.23 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:471.56 GB) (Free:219.21 GB) (Model: SK hynix SC313 HFS512G32TNF-N3A0A) NTFS
Drive e: (Nový svazek) (Fixed) (Total:931.51 GB) (Free:704.89 GB) (Model: ST1000DM003-1SB102) NTFS
\\?\Volume{4741ca1b-4dbf-43ea-b518-b760bdfd27da}\ (Recovery) (Fixed) (Total:4.77 GB) (Free:4.04 GB) NTFS
\\?\Volume{ba5fbc33-b5dd-4468-b9fb-349269ef43b8}\ (Bitdefender Virtual Disk) (Fixed) (Total:0.03 GB) (Free:0.02 GB) NTFS
\\?\Volume{048f2854-5f7e-4977-b719-6470b88f7754}\ (BOOT) (Fixed) (Total:0.48 GB) (Free:0.45 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 00EA67FA)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: CCABD939)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
==========================================================
Disk: 2 (Protective MBR) (Size: 32 MB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
- Rudy
- Site Admin

- Příspěvky: 120050
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: kontrola logu
OK, děkuji. Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:MBAM.Zone.Identifier [450]
AlternateDataStreams: C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\bitdefender_windows_90e9d651-86a0-4e28-a60b-ae7baf2bf12d.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.40.0.44.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.41.0.45.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Microsoft Photos Installer.exe:BDU [0]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.168\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level (No File)
HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-7589-DBF523A60F4D}] ->
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {65804F8A-DEC7-43D2-927A-F5545C410A1A} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500 => "C:\Users\Administrator\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe" (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {71607933-2DD7-478B-869B-4F01A3B703D3} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
U3 FamilySvc; no ImagePath
C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
EmptyTemp:
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: kontrola logu
Akce dolončena, nový log z RSIT:
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2026
Ran by Lenovo (28-07-2026 16:33:07) Run:1
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:MBAM.Zone.Identifier [450]
AlternateDataStreams: C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\bitdefender_windows_90e9d651-86a0-4e28-a60b-ae7baf2bf12d.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.40.0.44.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.41.0.45.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Microsoft Photos Installer.exe:BDU [0]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.168\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level (No File)
HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-7589-DBF523A60F4D}] ->
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {65804F8A-DEC7-43D2-927A-F5545C410A1A} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500 => "C:\Users\Administrator\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe" (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {71607933-2DD7-478B-869B-4F01A3B703D3} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
U3 FamilySvc; no ImagePath
C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
EmptyTemp:
End
*****************
Processes closed successfully.
C:\Users\Lenovo\Desktop\FRST64.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Desktop\FRST64.exe => ":MBAM.Zone.Identifier" ADS removed successfully
C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\bitdefender_windows_90e9d651-86a0-4e28-a60b-ae7baf2bf12d.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\Glary_Utilities_v6.40.0.44.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\Glary_Utilities_v6.41.0.45.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\Microsoft Photos Installer.exe => ":BDU" ADS removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{6FF59A85-BC37-4CD4-7589-DBF523A60F4D} => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{65804F8A-DEC7-43D2-927A-F5545C410A1A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65804F8A-DEC7-43D2-927A-F5545C410A1A}" => removed successfully
C:\windows\System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
C:\windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71607933-2DD7-478B-869B-4F01A3B703D3}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71607933-2DD7-478B-869B-4F01A3B703D3}" => removed successfully
C:\windows\System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500" => removed successfully
HKLM\System\CurrentControlSet\Services\FamilySvc => removed successfully
FamilySvc => service removed successfully
Could not move "C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 682276929 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 7197908 B
Edge => 358266373 B
Chrome => 15734977 B
Firefox => 0 B
Opera => 801518106 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 3 B
ProgramData => 0 B
Public => 0 B
systemprofile => 474483 B
systemprofile32 => 1090 B
LocalService => 479915 B
NetworkService => 4 B
Lenovo => 12484376 B
RecycleBin => 596 B
EmptyTemp: => 1.8 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 28-07-2026 16:37:12)
C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 16:37:12 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2026
Ran by Lenovo (28-07-2026 16:33:07) Run:1
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Desktop\FRST64.exe:MBAM.Zone.Identifier [450]
AlternateDataStreams: C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\bitdefender_windows_90e9d651-86a0-4e28-a60b-ae7baf2bf12d.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.40.0.44.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Glary_Utilities_v6.41.0.45.exe:BDU [0]
AlternateDataStreams: C:\Users\Lenovo\Downloads\Microsoft Photos Installer.exe:BDU [0]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.168\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level (No File)
HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-7589-DBF523A60F4D}] ->
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {65804F8A-DEC7-43D2-927A-F5545C410A1A} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500 => "C:\Users\Administrator\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe" (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {71607933-2DD7-478B-869B-4F01A3B703D3} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
U3 FamilySvc; no ImagePath
C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
EmptyTemp:
End
*****************
Processes closed successfully.
C:\Users\Lenovo\Desktop\FRST64.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Desktop\FRST64.exe => ":MBAM.Zone.Identifier" ADS removed successfully
C:\Users\Lenovo\Desktop\MBSetup-076981.076981-5.5.7.255.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\bitdefender_windows_90e9d651-86a0-4e28-a60b-ae7baf2bf12d.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\Glary_Utilities_v6.40.0.44.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\Glary_Utilities_v6.41.0.45.exe => ":BDU" ADS removed successfully
C:\Users\Lenovo\Downloads\Microsoft Photos Installer.exe => ":BDU" ADS removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{6FF59A85-BC37-4CD4-7589-DBF523A60F4D} => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{65804F8A-DEC7-43D2-927A-F5545C410A1A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65804F8A-DEC7-43D2-927A-F5545C410A1A}" => removed successfully
C:\windows\System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\Lenovo Service Bridge\S-1-5-21-119869544-2784913804-2825771880-500" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
C:\windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71607933-2DD7-478B-869B-4F01A3B703D3}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71607933-2DD7-478B-869B-4F01A3B703D3}" => removed successfully
C:\windows\System32\Tasks\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Reporting Task-S-1-5-21-119869544-2784913804-2825771880-500" => removed successfully
HKLM\System\CurrentControlSet\Services\FamilySvc => removed successfully
FamilySvc => service removed successfully
Could not move "C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 682276929 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 7197908 B
Edge => 358266373 B
Chrome => 15734977 B
Firefox => 0 B
Opera => 801518106 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 3 B
ProgramData => 0 B
Public => 0 B
systemprofile => 474483 B
systemprofile32 => 1090 B
LocalService => 479915 B
NetworkService => 4 B
Lenovo => 12484376 B
RecycleBin => 596 B
EmptyTemp: => 1.8 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 28-07-2026 16:37:12)
C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 16:37:12 ====
- Rudy
- Site Admin

- Příspěvky: 120050
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: kontrola logu
Bylo smazáno. Log by již měl být OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: kontrola logu
Toto tam zůstalo, nejde smazat.
C:\Program Files (x86)\ScreenConnect Client (4959b9d0db00aad9)
ScreenConnect.WindowsAuthenticationPackage.dll
C:\Program Files (x86)\ScreenConnect Client (4959b9d0db00aad9)
ScreenConnect.WindowsAuthenticationPackage.dll
- Rudy
- Site Admin

- Příspěvky: 120050
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: kontrola logu
Ono by to nemělo být nebezpečné, pokud chybí zápis v registry. Pak je to nefunkční a zabírá jen místo ne disku. Zkusíme toto:
Otevřte poznámkový blok a zkopírujte do něj:
Ta dynamická knihovna (WindowsAuthenticationPackage.dll), pokud je v adresáři, který mažeme, zmizí současně s ním, V opačném případě bude třeba ji najít a pak teprve s tím můžeme něco dělat.
Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
C:\Program Files (x86)\ScreenConnect Client
EmptyTemp:
End
Ta dynamická knihovna (WindowsAuthenticationPackage.dll), pokud je v adresáři, který mažeme, zmizí současně s ním, V opačném případě bude třeba ji najít a pak teprve s tím můžeme něco dělat.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: kontrola logu
log z RSIT:
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2026
Ran by Lenovo (28-07-2026 20:45:10) Run:2
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
C:\Program Files (x86)\ScreenConnect Client
EmptyTemp:
End
*****************
Processes closed successfully.
"C:\Program Files (x86)\ScreenConnect Client" => not found
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 786432 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12715594 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 1658782 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 58392451 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 1 B
ProgramData => 0 B
Public => 0 B
systemprofile => 469089 B
systemprofile32 => 1 B
LocalService => 6084 B
NetworkService => 0 B
Lenovo => 30449677 B
RecycleBin => 0 B
EmptyTemp: => 99.6 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 20:46:06 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2026
Ran by Lenovo (28-07-2026 20:45:10) Run:2
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
C:\Program Files (x86)\ScreenConnect Client
EmptyTemp:
End
*****************
Processes closed successfully.
"C:\Program Files (x86)\ScreenConnect Client" => not found
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 786432 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12715594 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 1658782 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 58392451 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 1 B
ProgramData => 0 B
Public => 0 B
systemprofile => 469089 B
systemprofile32 => 1 B
LocalService => 6084 B
NetworkService => 0 B
Lenovo => 30449677 B
RecycleBin => 0 B
EmptyTemp: => 99.6 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 20:46:06 ====
Re: kontrola logu
Nesmazalo se to, pořád to tam je.
- Rudy
- Site Admin

- Příspěvky: 120050
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: kontrola logu
To vidím. Zkuste restartovat do nouz. režimu a smazato v něm. Další možností je obnova systému před datum, kdy byl do PC nainstalován. Tento způsob odstraní vše, co bylo nainstalováno po tomto datu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: kontrola logu
Bohužel nejde to smazat v nouzovém režimu a ani nelze se vrátit do požadovaného datunu obnovení systému.
- Rudy
- Site Admin

- Příspěvky: 120050
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: kontrola logu
Obnova systému by měla fungovat, pokud ji nemáte vypnutou. Zde: https://www.easeus.cz/manage-partitions ... leted.html jsou možnosti, jak toho dosáhnout. Také je možná obnova systému do výchozího nastavení.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?