Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-08-2026
Ran by alett (administrator) on DESKTOP-18KJ18D (LENOVO 80EC) (29-08-2026 19:18:19)
Running from C:\Users\alett\Desktop\FRST64.exe
Loaded Profiles: alett
Platform: Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2613.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe <2>
(DriverStore\FileRepository\c0380462.inf_amd64_3f0d0d0e3189ddd8\B378995\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0380462.inf_amd64_3f0d0d0e3189ddd8\B378995\atieclxx.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2613.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(explorer.exe ->) (FxSound, LLC -> FxSound LLC) C:\Program Files\FxSound LLC\FxSound\FxSound.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek semiconductor) C:\Windows\RTFTrack.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe <5>
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(services.exe ->) () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0380462.inf_amd64_3f0d0d0e3189ddd8\B378995\atiesrxx.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\NisSrv.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\alett\AppData\Local\Microsoft\OneDrive\26.074.0420.0001\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6613896 2016-06-24] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5175568 2016-09-02] (Realtek Semiconductor Corp -> Realtek semiconductor)
ShortcutTarget: FxSound.lnk -> C:\Program Files\FxSound LLC\FxSound\FxSound.exe (FxSound, LLC -> FxSound LLC)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {11B91C8D-8F9D-46D9-9DC0-9EC98846FE63} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [6089584 2025-10-16] (Microsoft Windows -> Microsoft Corporation)
Task: {5992543B-8DED-4A49-BABA-9321E84FBFCF} - System32\Tasks\Driver Booster Scheduler => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\Scheduler.exe" /scheduler (No File) <==== ATTENTION
Task: {03601331-AB81-4392-BD09-7E791C01AFD6} - System32\Tasks\Driver Booster SkipUAC (alett) => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\DriverBooster.exe" /skipuac (No File) <==== ATTENTION
Task: {3A8458F8-8B45-45ED-A85E-D415C9304C4C} - System32\Tasks\Driver Booster Update => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\AutoUpdate.exe" /auto (No File) <==== ATTENTION
Task: {FC1A6BAF-1516-4664-A4B1-02E786E3A32A} - System32\Tasks\IObit ANNI2025Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\annien.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
Task: {FE490A87-6BE4-4CED-B8A2-7638004B9204} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C5B5F0D7-A394-464B-94ED-DAF020DC5567} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C8C955C6-DDBB-427B-A1E3-CEEB0AD1BFBA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0D84468A-5644-4EF3-97C6-B7AD2D3D141C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-14] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FD1B38DB-3400-46C2-8B37-3B6BAC3781DD} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2352176125-4167586948-3626731281-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-05-21] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {B7E87E32-CDEE-4C75-A055-AD132BC156BA} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-05-21] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{74bef707-a945-416d-b798-16d1e682c972}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: 7feanb34.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\alett\AppData\Roaming\Mozilla\Firefox\Profiles\cccehida.default [2025-05-03]
FF ProfilePath: C:\Users\alett\AppData\Roaming\Mozilla\Firefox\Profiles\7feanb34.default-release [2026-08-29]
FF Session Restore: Mozilla\Firefox\Profiles\7feanb34.default-release -> is enabled.
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\alett\AppData\Local\Microsoft\Edge\User Data\Default [2025-05-14]
Edge Extension: (Dokumenty Google offline) - C:\Users\alett\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-05-04]
Edge Extension: (Edge relevant text changes) - C:\Users\alett\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-05-04]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [138752 2016-06-24] () [File not signed]
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpDefenderCoreService.exe [2088128 2026-04-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\NisSrv.exe [5183648 2026-08-29] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MsMpEng.exe [291352 2026-08-29] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R3 FXVAD; C:\WINDOWS\system32\drivers\fxvad.sys [326656 2024-11-25] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 RevoProcessDetector; C:\WINDOWS\System32\DRIVERS\RevoProcessDetector.sys [19504 2024-03-28] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [51224 2026-08-29] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21632 2026-08-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [625688 2026-08-29] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [111640 2026-08-29] (Microsoft Windows -> Microsoft Corporation)
S3 cpuz154; \??\C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys (No File) <==== ATTENTION
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-08-29 19:18 - 2026-08-29 19:22 - 000011505 _____ C:\Users\alett\Desktop\FRST.txt
2026-08-29 19:17 - 2026-08-29 19:21 - 000000000 ____D C:\FRST
2026-08-29 19:16 - 2026-08-29 19:16 - 002451456 _____ (Farbar) C:\Users\alett\Desktop\FRST64.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-08-29 19:24 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-08-29 19:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-08-29 19:22 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-08-29 19:21 - 2025-05-03 16:18 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-08-29 19:14 - 2026-05-21 15:33 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-08-29 19:13 - 2025-05-03 17:49 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-08-29 19:13 - 2025-05-03 17:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-08-29 19:12 - 2025-05-04 13:30 - 000000000 ____D C:\Users\alett\AppData\Local\D3DSCache
2026-08-29 19:11 - 2023-12-04 04:53 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-08-29 19:10 - 2025-05-03 17:38 - 000000000 ___RD C:\Users\alett\OneDrive
2026-08-29 19:08 - 2025-05-03 17:22 - 000000000 ___SD C:\Users\alett\AppData\Roaming\Microsoft\Protect
2026-08-29 19:07 - 2025-05-03 17:22 - 000000000 ____D C:\Users\alett
2026-08-29 19:06 - 2025-05-03 16:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-08-29 19:06 - 2025-05-03 16:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-08-29 19:06 - 2024-12-20 19:14 - 000008192 ___SH C:\DumpStack.log.tmp
2026-08-29 18:59 - 2025-05-03 16:19 - 000003638 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-08-29 18:59 - 2025-05-03 16:19 - 000003512 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-08-29 18:58 - 2025-09-08 00:19 - 000004212 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{27793B60-8C00-4148-86B8-F7ED4EB527EB}
2026-08-29 18:56 - 2025-05-05 19:55 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-08-29 18:48 - 2025-05-05 19:54 - 220340424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2025-05-03 18:20 - 2026-05-19 19:03 - 000012447 _____ () C:\Users\alett\AppData\Local\PlariumPlay.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-08-2026
Ran by alett (29-08-2026 19:26:25)
Running from C:\Users\alett\Desktop
Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) (2025-05-03 15:08:58)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2352176125-4167586948-3626731281-500 - Administrators - Disabled)
alett (S-1-5-21-2352176125-4167586948-3626731281-1001 - Administrators - Enabled) => C:\Users\alett
DefaultAccount (S-1-5-21-2352176125-4167586948-3626731281-503 - Limited - Disabled)
Guest (S-1-5-21-2352176125-4167586948-3626731281-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2352176125-4167586948-3626731281-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-2352176125-4167586948-3626731281-1001\...\uTorrent) (Version: 3.6.0.47224 - BitTorrent Limited)
AMD Radeon Settings (HKLM\...\WUCCCApp) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.)
FxSound (HKLM\...\{95D08662-48ED-4C02-AD94-BEF0C45B26D3}) (Version: 1.2.6.0 - FxSound LLC)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.2.3.29 - PandoraTV)
Microsoft .NET Host - 6.0.10 (x64) (HKLM\...\{0222FFF1-57A3-48A6-9AD2-0D6B5D0172B3}) (Version: 48.43.48869 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.19 (x64) (HKLM\...\{B84443A1-BE1B-4C5E-B834-E12133604B12}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.10 (x64) (HKLM\...\{A93C4E12-1BAB-4CFB-ADBC-9CE0B93176FF}) (Version: 48.43.48869 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.19 (x64) (HKLM\...\{69A17DA9-300A-49B9-97F1-1EB7424570DE}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.10 (x64) (HKLM\...\{A2A39CB9-677D-4299-8537-C00B99F3D4A4}) (Version: 48.43.48869 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.19 (x64) (HKLM\...\{B9F7A454-0CCD-410C-A3E0-D1AAC300F150}) (Version: 64.76.37566 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 148.0.3967.70 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 148.0.3967.70 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-2352176125-4167586948-3626731281-1001\...\OneDriveSetup.exe) (Version: 26.074.0420.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (HKLM\...\{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (HKLM\...\{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (HKLM-x32\...\{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (HKLM-x32\...\{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29334 (HKLM-x32\...\{a9cfe9c7-e54f-46cd-9c5c-542ff8e3e8c4}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29334 (HKLM\...\{2E11EF4E-901F-4B2D-B68E-3DB2A566C857}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29334 (HKLM\...\{8A3F7D5B-422D-49D9-84F7-8DC1B7782967}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.10 (x64) (HKLM\...\{3EC7701F-54F2-491D-AFD1-0395F465BC5A}) (Version: 48.43.48870 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.10 (x64) (HKLM-x32\...\{ff748137-9c9a-4056-be0a-48c7e465453c}) (Version: 6.0.10.31726 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.19 (x64) (HKLM\...\{A6EA542C-884C-4FE7-89E4-8C28E14B601C}) (Version: 64.76.37602 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.19 (x64) (HKLM-x32\...\{6b2575e2-0248-44c3-93f3-2eba040331ed}) (Version: 8.0.19.35118 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox) (Version: 151.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 138.0.1 - Mozilla)
Revo Uninstaller 2.6.2 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.6.2 - VS Revo Group, Ltd.)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
WinRAR 7.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 7.11.0 - win.rar GmbH)
Packages:
=========
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2613.101.0_x64__cv1g1gvanyjgm [2026-04-14] (WhatsApp Inc.) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{1672a7e6-aef7-3fea-bdee-11e3c4f385c5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{2dd027a4-a8e8-922d-96c0-aa46aafba94b}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.12.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{6c6dbf09-c70a-f34a-40ff-fadf01a7d9e3}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.10.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{86e284f6-e80f-91a3-6696-66857031699e}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a60a69eb-f2d8-a8c8-c1e6-05124a7a4583}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.13.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a76ea925-1a29-cfb7-3c9c-7bcce1f50ad5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.4.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{bbff93c6-f654-b750-cd81-d4c6e1781211}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e0428f4f-b32a-5cda-dbdd-f00c0d260a9a}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.9.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e87f042f-e297-5318-d18a-82839ea089ce}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.8.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{f73df601-0d90-6c94-f782-a39ed9fa2293}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.3.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{fa9e8d52-0884-0af0-8a20-e43483db9ded}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2025-03-20] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2025-03-20] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll [2025-05-04] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2025-03-20] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2025-03-20] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32-x32: [vidc.XVID] => xvidvfw.dll
HKLM\...\Drivers32-x32: [VIDC.VP80] => vp8vfw.dll
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2015-06-25 16:53 - 2015-06-25 16:53 - 000011776 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2015-06-25 16:51 - 2015-06-25 16:51 - 002013696 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2015-06-25 17:34 - 2015-06-25 17:34 - 000014336 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2015-06-25 17:37 - 2015-06-25 17:37 - 000739840 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-06-25 17:38 - 2015-06-25 17:38 - 000071168 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-06-25 17:35 - 2015-06-25 17:35 - 000014336 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2015-06-25 17:20 - 2015-06-25 17:20 - 000049664 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qdds.dll
2015-06-25 17:15 - 2015-06-25 17:15 - 000029696 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qgif.dll
2015-06-25 17:20 - 2015-06-25 17:20 - 000037376 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qicns.dll
2015-06-25 17:15 - 2015-06-25 17:15 - 000030208 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qico.dll
2015-06-25 17:20 - 2015-06-25 17:20 - 000459776 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qjp2.dll
2015-06-25 17:15 - 2015-06-25 17:15 - 000236544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qjpeg.dll
2015-06-25 17:20 - 2015-06-25 17:20 - 000275456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qmng.dll
2015-06-25 17:17 - 2015-06-25 17:17 - 000023552 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qsvg.dll
2015-06-25 17:20 - 2015-06-25 17:20 - 000022528 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qtga.dll
2015-06-25 17:20 - 2015-06-25 17:20 - 000351744 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qtiff.dll
2015-06-25 17:20 - 2015-06-25 17:20 - 000021504 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwbmp.dll
2015-06-25 17:21 - 2015-06-25 17:21 - 000374784 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwebp.dll
2015-06-25 17:14 - 2015-06-25 17:14 - 001212416 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\platforms\qwindows.dll
2015-07-02 12:58 - 2015-07-02 12:58 - 005496320 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2015-06-25 17:03 - 2015-06-25 17:03 - 005804544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2015-06-25 05:13 - 2015-06-25 05:13 - 000912384 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Charts.dll
2015-06-25 17:00 - 2015-06-25 17:00 - 001061376 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2015-06-25 17:23 - 2015-06-25 17:23 - 003187712 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2015-06-25 17:28 - 2015-06-25 17:28 - 002924544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2015-06-25 17:16 - 2015-06-25 17:16 - 000310784 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2015-06-25 17:08 - 2015-06-25 17:08 - 005444608 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2015-06-25 17:58 - 2015-06-25 17:58 - 000277504 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2015-06-25 16:59 - 2015-06-25 16:59 - 000193024 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 11:14 - 2019-12-07 11:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi: Qualcomm Atheros AR956x Wireless Network Adapter -> athw10x.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\alett\Desktop\keet.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{F3272DFA-542D-4AE8-B5D3-73B8E4A5E7CC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{2DCA01C4-023A-48F6-A780-63F56474E839}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{45F65D89-BCE1-4374-A42F-790DD33F5C2A}] => (Allow) C:\Users\alett\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{DF6ECF9A-4B02-4A78-9DAF-6273F58281D2}] => (Allow) C:\Users\alett\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [TCP Query User{7846A660-E697-4CD5-ADFC-B5632A4119B2}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{87C551FD-CCF4-44CB-9E6C-188E258CE7DA}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{78374F80-394C-42BA-8AEA-820188060A34}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{1F0F7F7E-F471-4C23-BE42-43B4A131DF1C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{343C2649-F2EE-4CE8-98B7-FF70212D97EB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{191AFD7D-2117-433A-8E09-DB0F522FADBC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{09C92C33-23F1-4484-9798-8DFC91A7A804}] => (Allow) C:\GOG Games\Diablo\Diablo.exe => No File
FirewallRules: [TCP Query User{D64A1F9D-05BA-4F0E-BD66-15DCF41369E7}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
FirewallRules: [UDP Query User{46A7CCA7-C670-49B9-9484-A047EBB4028F}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
==================== Restore Points =========================
06-04-2026 18:57:01 Naplánovaný kontrolní bod
15-04-2026 17:29:05 Naplánovaný kontrolní bod
19-05-2026 18:27:58 Revo Uninstaller's restore point - Stronghold Crusader: Definitive Edition
19-05-2026 18:32:30 Revo Uninstaller's restore point - Stronghold Crusader: Definitive Edition
19-05-2026 18:44:55 Revo Uninstaller's restore point - Steam
19-05-2026 18:50:45 Revo Uninstaller's restore point - Discord
19-05-2026 18:53:11 Revo Uninstaller's restore point - Discord
19-05-2026 18:57:15 Revo Uninstaller's restore point - Plarium Play
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (08/29/2026 07:14:02 PM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: )
Description: Event-ID 5
Error: (08/29/2026 07:08:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_FrameServer, verze: 10.0.19041.5794, časové razítko: 0x11bd0919
Název chybujícího modulu: RsProvider.dll, verze: 1.23.0.0, časové razítko: 0x56fb7e54
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000007bded
ID chybujícího procesu: 0xa5c
Čas spuštění chybující aplikace: 0x01dd37d90026a501
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\Program Files\Realtek\RsProviders\RsProvider.dll
ID zprávy: 0a80a4ce-e398-465f-bf61-32e688961f0f
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (08/29/2026 07:06:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_FrameServer, verze: 10.0.19041.5794, časové razítko: 0x11bd0919
Název chybujícího modulu: RsProvider.dll, verze: 1.23.0.0, časové razítko: 0x56fb7e54
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000007bded
ID chybujícího procesu: 0x4d0
Čas spuštění chybující aplikace: 0x01dd37d8be0afec5
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\Program Files\Realtek\RsProviders\RsProvider.dll
ID zprávy: bc69b12d-8653-4d25-b968-7d25497c0de4
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (08/29/2026 07:01:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_FrameServer, verze: 10.0.19041.5794, časové razítko: 0x11bd0919
Název chybujícího modulu: RsProvider.dll, verze: 1.23.0.0, časové razítko: 0x56fb7e54
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000007bded
ID chybujícího procesu: 0x4cc
Čas spuštění chybující aplikace: 0x01dd37d7f5e6565a
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\Program Files\Realtek\RsProviders\RsProvider.dll
ID zprávy: 970e26a1-6055-410c-834e-b8b0fda7ce9c
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (05/21/2026 07:16:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_FrameServer, verze: 10.0.19041.5794, časové razítko: 0x11bd0919
Název chybujícího modulu: RsProvider.dll, verze: 1.23.0.0, časové razítko: 0x56fb7e54
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000007bded
ID chybujícího procesu: 0x2d44
Čas spuštění chybující aplikace: 0x01dce9459c5fdb6e
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\Program Files\Realtek\RsProviders\RsProvider.dll
ID zprávy: 4994d814-ac26-493d-8137-d01db20a4541
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (05/21/2026 03:32:39 PM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: )
Description: Event-ID 5
Error: (05/21/2026 03:28:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_FrameServer, verze: 10.0.19041.5794, časové razítko: 0x11bd0919
Název chybujícího modulu: RsProvider.dll, verze: 1.23.0.0, časové razítko: 0x56fb7e54
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000007bded
ID chybujícího procesu: 0x27fc
Čas spuštění chybující aplikace: 0x01dce925ba666623
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\Program Files\Realtek\RsProviders\RsProvider.dll
ID zprávy: 66932a59-0007-4bd2-b74d-a49f2207fe29
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:
Error: (05/19/2026 06:58:43 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač..
Operace:
Spouštění asynchronní operace
Kontext:
Aktuální stav: DoSnapshotSet
System errors:
=============
Error: (08/29/2026 07:11:40 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: FirmwareVersion:A4CN29WW (V 1.50);OEMManufacturerName:LENOVO;OEMModelSKU:LENOVO_MT_80EC0_BU_idea_FM_Lenovo Z50-75;OSArchitecture:amd64;
BucketId: 2b48b08592045cc320ea2c5c5b1bb2b7e687d036445ee798a1643cd0905ad482
BucketConfidenceLevel:
UpdateType: 0
HResult: 0
Error: (08/29/2026 07:08:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Windows Camera Frame Server byla neočekávaně ukončena. Tento stav nastal již 2krát.
Error: (08/29/2026 07:08:12 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Windows Camera Frame Server byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (08/29/2026 07:06:55 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba NcbService byla ukončena s následující chybou:
Zařízení připojené k systému nefunguje.
Error: (08/29/2026 07:06:35 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (18:48:04, 29.08.2026) bylo neočekávané.
Error: (08/29/2026 07:01:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Windows Camera Frame Server byla neočekávaně ukončena. Tento stav nastal již 56krát.
Error: (08/29/2026 06:59:21 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-18KJ18D)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.
Error: (08/29/2026 06:59:17 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-18KJ18D)
Description: Server Microsoft.Windows.ContentDeliveryManager_10.0.19041.4239_neutral_neutral_cw5n1h2txyewy!App.AppXw3qcpc7p849541dp39vvqd01bn7z9ybh.mca se v daném časovém limitu neregistroval u služby DCOM.
Windows Defender:
================
TimeCreated : 29.08.2026 19:21:31
Message : Antivirová ochrana v programu Microsoft Defender ŝćáñ нαš ъēěñ şţôρρéď ъĕƒǿґз ĉōмφℓэţїöň.%ʼn %ţŚ¢дʼn ЇĎ:%в{
258832F6-D556-42AD-828C-3F5D76F59C8E}%ή %ţŚçăή Ťýφĕ:%вAntimalwarový program%ŋ %ŧЅćăл Ρǻřâmèťĕřş:%ьRychlé
prohledávání%и %ťÙŝĕг:%вNT AUTHORITY\NETWORK SERVICE%ņ %ťŜťор Гёăŝθπ:%ьÜʼnķлõщⁿ
CodeIntegrity:
===============
Date: 2026-03-23 13:14:06
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\fcon.dll because the set of per-page image hashes could not be found on the system.
Date: 2026-03-23 13:13:52
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\aepic.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
BIOS: LENOVO A4CN29WW (V 1.50) 07/22/2014
Motherboard: LENOVO Lancer 5B3
Processor: AMD FX-7500 Radeon R7, 10 Compute Cores 4C+6G
Percentage of memory in use: 56%
Total physical RAM: 7098.61 MB
Available physical RAM: 3090.56 MB
Total Virtual: 11194.61 MB
Available Virtual: 6875.18 MB
==================== Drives ================================
Disk 0 - Drive c: () (Fixed) (Total:465.1 GB) (Free:355.62 GB) (Model: HGST HTS725050A7E630) NTFS
Disk 0 - \\?\Volume{fba817d0-3f49-49c0-bd45-305c9dcf41a2}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS
Disk 0 - \\?\Volume{b6d6265e-124c-45f9-b4f6-c057b1790e10}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 3E5C01AD)
Partition: GPT.
==================== End of Addition.txt =======================
Pomalý a starý notebook
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin

- Příspěvky: 120092
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Pomalý a starý notebook
Zdravím!
Otevřte poznámkový blok a zkopírujte do něj:
Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
Task: {5992543B-8DED-4A49-BABA-9321E84FBFCF} - System32\Tasks\Driver Booster Scheduler => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\Scheduler.exe" /scheduler (No File) <==== ATTENTION
Task: {03601331-AB81-4392-BD09-7E791C01AFD6} - System32\Tasks\Driver Booster SkipUAC (alett) => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\DriverBooster.exe" /skipuac (No File) <==== ATTENTION
Task: {3A8458F8-8B45-45ED-A85E-D415C9304C4C} - System32\Tasks\Driver Booster Update => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\AutoUpdate.exe" /auto (No File) <==== ATTENTION
Task: {FC1A6BAF-1516-4664-A4B1-02E786E3A32A} - System32\Tasks\IObit ANNI2025Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\annien.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
S3 cpuz154; \??\C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys (No File) <==== ATTENTION
C:\DumpStack.log.tmp
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{1672a7e6-aef7-3fea-bdee-11e3c4f385c5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{2dd027a4-a8e8-922d-96c0-aa46aafba94b}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.12.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{6c6dbf09-c70a-f34a-40ff-fadf01a7d9e3}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.10.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{86e284f6-e80f-91a3-6696-66857031699e}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a60a69eb-f2d8-a8c8-c1e6-05124a7a4583}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.13.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a76ea925-1a29-cfb7-3c9c-7bcce1f50ad5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.4.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{bbff93c6-f654-b750-cd81-d4c6e1781211}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e0428f4f-b32a-5cda-dbdd-f00c0d260a9a}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.9.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e87f042f-e297-5318-d18a-82839ea089ce}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.8.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{f73df601-0d90-6c94-f782-a39ed9fa2293}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.3.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{fa9e8d52-0884-0af0-8a20-e43483db9ded}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
FirewallRules: [{78374F80-394C-42BA-8AEA-820188060A34}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{1F0F7F7E-F471-4C23-BE42-43B4A131DF1C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{343C2649-F2EE-4CE8-98B7-FF70212D97EB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{191AFD7D-2117-433A-8E09-DB0F522FADBC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{09C92C33-23F1-4484-9798-8DFC91A7A804}] => (Allow) C:\GOG Games\Diablo\Diablo.exe => No File
FirewallRules: [TCP Query User{D64A1F9D-05BA-4F0E-BD66-15DCF41369E7}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
FirewallRules: [UDP Query User{46A7CCA7-C670-49B9-9484-A047EBB4028F}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
EmptyTemp:
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Pomalý a starý notebook
Fix result of Farbar Recovery Scan Tool (x64) Version: 29-08-2026
Ran by alett (29-08-2026 20:04:47) Run:1
Running from C:\Users\alett\Desktop
Loaded Profiles: alett
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
Task: {5992543B-8DED-4A49-BABA-9321E84FBFCF} - System32\Tasks\Driver Booster Scheduler => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\Scheduler.exe" /scheduler (No File) <==== ATTENTION
Task: {03601331-AB81-4392-BD09-7E791C01AFD6} - System32\Tasks\Driver Booster SkipUAC (alett) => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\DriverBooster.exe" /skipuac (No File) <==== ATTENTION
Task: {3A8458F8-8B45-45ED-A85E-D415C9304C4C} - System32\Tasks\Driver Booster Update => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\AutoUpdate.exe" /auto (No File) <==== ATTENTION
Task: {FC1A6BAF-1516-4664-A4B1-02E786E3A32A} - System32\Tasks\IObit ANNI2025Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\annien.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
S3 cpuz154; \??\C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys (No File) <==== ATTENTION
C:\DumpStack.log.tmp
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{1672a7e6-aef7-3fea-bdee-11e3c4f385c5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{2dd027a4-a8e8-922d-96c0-aa46aafba94b}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.12.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{6c6dbf09-c70a-f34a-40ff-fadf01a7d9e3}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.10.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{86e284f6-e80f-91a3-6696-66857031699e}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a60a69eb-f2d8-a8c8-c1e6-05124a7a4583}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.13.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a76ea925-1a29-cfb7-3c9c-7bcce1f50ad5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.4.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{bbff93c6-f654-b750-cd81-d4c6e1781211}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e0428f4f-b32a-5cda-dbdd-f00c0d260a9a}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.9.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e87f042f-e297-5318-d18a-82839ea089ce}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.8.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{f73df601-0d90-6c94-f782-a39ed9fa2293}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.3.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{fa9e8d52-0884-0af0-8a20-e43483db9ded}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
FirewallRules: [{78374F80-394C-42BA-8AEA-820188060A34}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{1F0F7F7E-F471-4C23-BE42-43B4A131DF1C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{343C2649-F2EE-4CE8-98B7-FF70212D97EB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{191AFD7D-2117-433A-8E09-DB0F522FADBC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{09C92C33-23F1-4484-9798-8DFC91A7A804}] => (Allow) C:\GOG Games\Diablo\Diablo.exe => No File
FirewallRules: [TCP Query User{D64A1F9D-05BA-4F0E-BD66-15DCF41369E7}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
FirewallRules: [UDP Query User{46A7CCA7-C670-49B9-9484-A047EBB4028F}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5992543B-8DED-4A49-BABA-9321E84FBFCF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5992543B-8DED-4A49-BABA-9321E84FBFCF}" => removed successfully
C:\WINDOWS\System32\Tasks\Driver Booster Scheduler => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03601331-AB81-4392-BD09-7E791C01AFD6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03601331-AB81-4392-BD09-7E791C01AFD6}" => removed successfully
C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (alett) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (alett)" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3A8458F8-8B45-45ED-A85E-D415C9304C4C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A8458F8-8B45-45ED-A85E-D415C9304C4C}" => removed successfully
C:\WINDOWS\System32\Tasks\Driver Booster Update => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FC1A6BAF-1516-4664-A4B1-02E786E3A32A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC1A6BAF-1516-4664-A4B1-02E786E3A32A}" => removed successfully
C:\WINDOWS\System32\Tasks\IObit ANNI2025Sale (One-time) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IObit ANNI2025Sale (One-time)" => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz154 => removed successfully
cpuz154 => service removed successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{1672a7e6-aef7-3fea-bdee-11e3c4f385c5} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{2dd027a4-a8e8-922d-96c0-aa46aafba94b} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{6c6dbf09-c70a-f34a-40ff-fadf01a7d9e3} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{86e284f6-e80f-91a3-6696-66857031699e} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a60a69eb-f2d8-a8c8-c1e6-05124a7a4583} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a76ea925-1a29-cfb7-3c9c-7bcce1f50ad5} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{bbff93c6-f654-b750-cd81-d4c6e1781211} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e0428f4f-b32a-5cda-dbdd-f00c0d260a9a} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e87f042f-e297-5318-d18a-82839ea089ce} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{f73df601-0d90-6c94-f782-a39ed9fa2293} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{fa9e8d52-0884-0af0-8a20-e43483db9ded} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{78374F80-394C-42BA-8AEA-820188060A34}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1F0F7F7E-F471-4C23-BE42-43B4A131DF1C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{343C2649-F2EE-4CE8-98B7-FF70212D97EB}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{191AFD7D-2117-433A-8E09-DB0F522FADBC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{09C92C33-23F1-4484-9798-8DFC91A7A804}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D64A1F9D-05BA-4F0E-BD66-15DCF41369E7}C:\users\alett\downloads\downloader_diablo2_enus.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{46A7CCA7-C670-49B9-9484-A047EBB4028F}C:\users\alett\downloads\downloader_diablo2_enus.exe" => removed successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 246506024 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 564134439 B
Windows/system/drivers => 100370952 B
Edge => 63598479 B
Firefox => 505334042 B
Opera => 0 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 4 B
ProgramData => 0 B
Public => 0 B
systemprofile => 466558 B
systemprofile32 => 0 B
LocalService => 4 B
NetworkService => 352344 B
alett => 931261243 B
RecycleBin => 0 B
EmptyTemp: => 2.2 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 29-08-2026 20:10:16)
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 20:10:17 ====
Ran by alett (29-08-2026 20:04:47) Run:1
Running from C:\Users\alett\Desktop
Loaded Profiles: alett
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
Task: {5992543B-8DED-4A49-BABA-9321E84FBFCF} - System32\Tasks\Driver Booster Scheduler => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\Scheduler.exe" /scheduler (No File) <==== ATTENTION
Task: {03601331-AB81-4392-BD09-7E791C01AFD6} - System32\Tasks\Driver Booster SkipUAC (alett) => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\DriverBooster.exe" /skipuac (No File) <==== ATTENTION
Task: {3A8458F8-8B45-45ED-A85E-D415C9304C4C} - System32\Tasks\Driver Booster Update => "C:\Program Files (x86)\IObit\Driver Booster\12.4.0\AutoUpdate.exe" /auto (No File) <==== ATTENTION
Task: {FC1A6BAF-1516-4664-A4B1-02E786E3A32A} - System32\Tasks\IObit ANNI2025Sale (One-time) => "C:\Program Files (x86)\IObit\Driver Booster\Pub\annien.exe" -> C:\Program Files (x86)\IObit\Driver Booster\Pub\\/rpop <==== ATTENTION
S3 cpuz154; \??\C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys (No File) <==== ATTENTION
C:\DumpStack.log.tmp
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{1672a7e6-aef7-3fea-bdee-11e3c4f385c5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{2dd027a4-a8e8-922d-96c0-aa46aafba94b}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.12.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{6c6dbf09-c70a-f34a-40ff-fadf01a7d9e3}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.10.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{86e284f6-e80f-91a3-6696-66857031699e}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a60a69eb-f2d8-a8c8-c1e6-05124a7a4583}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.13.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a76ea925-1a29-cfb7-3c9c-7bcce1f50ad5}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.4.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{bbff93c6-f654-b750-cd81-d4c6e1781211}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.7.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e0428f4f-b32a-5cda-dbdd-f00c0d260a9a}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.9.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e87f042f-e297-5318-d18a-82839ea089ce}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.8.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{f73df601-0d90-6c94-f782-a39ed9fa2293}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.3.0-0.0.0\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{fa9e8d52-0884-0af0-8a20-e43483db9ded}\localserver32 -> "C:\Users\alett\AppData\Local\PlariumPlay\10.11.0-0.0.1\dotnet\PlariumPlay.NetHost.exe" -ToastActivated => No File
FirewallRules: [{78374F80-394C-42BA-8AEA-820188060A34}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{1F0F7F7E-F471-4C23-BE42-43B4A131DF1C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{343C2649-F2EE-4CE8-98B7-FF70212D97EB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{191AFD7D-2117-433A-8E09-DB0F522FADBC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{09C92C33-23F1-4484-9798-8DFC91A7A804}] => (Allow) C:\GOG Games\Diablo\Diablo.exe => No File
FirewallRules: [TCP Query User{D64A1F9D-05BA-4F0E-BD66-15DCF41369E7}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
FirewallRules: [UDP Query User{46A7CCA7-C670-49B9-9484-A047EBB4028F}C:\users\alett\downloads\downloader_diablo2_enus.exe] => (Allow) C:\users\alett\downloads\downloader_diablo2_enus.exe => No File
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5992543B-8DED-4A49-BABA-9321E84FBFCF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5992543B-8DED-4A49-BABA-9321E84FBFCF}" => removed successfully
C:\WINDOWS\System32\Tasks\Driver Booster Scheduler => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03601331-AB81-4392-BD09-7E791C01AFD6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03601331-AB81-4392-BD09-7E791C01AFD6}" => removed successfully
C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (alett) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (alett)" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3A8458F8-8B45-45ED-A85E-D415C9304C4C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A8458F8-8B45-45ED-A85E-D415C9304C4C}" => removed successfully
C:\WINDOWS\System32\Tasks\Driver Booster Update => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FC1A6BAF-1516-4664-A4B1-02E786E3A32A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC1A6BAF-1516-4664-A4B1-02E786E3A32A}" => removed successfully
C:\WINDOWS\System32\Tasks\IObit ANNI2025Sale (One-time) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IObit ANNI2025Sale (One-time)" => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz154 => removed successfully
cpuz154 => service removed successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{1672a7e6-aef7-3fea-bdee-11e3c4f385c5} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{2dd027a4-a8e8-922d-96c0-aa46aafba94b} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{6c6dbf09-c70a-f34a-40ff-fadf01a7d9e3} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{86e284f6-e80f-91a3-6696-66857031699e} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a60a69eb-f2d8-a8c8-c1e6-05124a7a4583} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{a76ea925-1a29-cfb7-3c9c-7bcce1f50ad5} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{bbff93c6-f654-b750-cd81-d4c6e1781211} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e0428f4f-b32a-5cda-dbdd-f00c0d260a9a} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{e87f042f-e297-5318-d18a-82839ea089ce} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{f73df601-0d90-6c94-f782-a39ed9fa2293} => removed successfully
HKU\S-1-5-21-2352176125-4167586948-3626731281-1001_Classes\CLSID\{fa9e8d52-0884-0af0-8a20-e43483db9ded} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{78374F80-394C-42BA-8AEA-820188060A34}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1F0F7F7E-F471-4C23-BE42-43B4A131DF1C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{343C2649-F2EE-4CE8-98B7-FF70212D97EB}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{191AFD7D-2117-433A-8E09-DB0F522FADBC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{09C92C33-23F1-4484-9798-8DFC91A7A804}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D64A1F9D-05BA-4F0E-BD66-15DCF41369E7}C:\users\alett\downloads\downloader_diablo2_enus.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{46A7CCA7-C670-49B9-9484-A047EBB4028F}C:\users\alett\downloads\downloader_diablo2_enus.exe" => removed successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 246506024 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 564134439 B
Windows/system/drivers => 100370952 B
Edge => 63598479 B
Firefox => 505334042 B
Opera => 0 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 4 B
ProgramData => 0 B
Public => 0 B
systemprofile => 466558 B
systemprofile32 => 0 B
LocalService => 4 B
NetworkService => 352344 B
alett => 931261243 B
RecycleBin => 0 B
EmptyTemp: => 2.2 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 29-08-2026 20:10:16)
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 20:10:17 ====
- Rudy
- Site Admin

- Příspěvky: 120092
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Pomalý a starý notebook
Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Pomalý a starý notebook
Děkuji. Je to lepší ale furt je využití disku hrozně vysoké.. okolo 90%.
je to starý ntb a snažím se ho trochu zprovoznit.
je to starý ntb a snažím se ho trochu zprovoznit.
- Rudy
- Site Admin

- Příspěvky: 120092
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Pomalý a starý notebook
Který proces má nejvyšší využití?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?