Zdravím, synovi vyskakuje na ntb hláška stále o připojování k serveru infrid.com. Prosím o kontrolu.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2026
Ran by keram (administrator) on MAREK (HP HP Laptop 15-fc0xxx) (05-09-2026 14:33:48)
Running from C:\Users\keram\Desktop\FRST64.exe
Loaded Profiles: keram
Platform: Microsoft Windows 11 Home Version 25H2 26200.9278 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe
(Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe
(C:\Program Files (x86)\ Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\ Steam\bin\cef\cef.win64\steamwebhelper.exe
(C:\Program Files\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <2>
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\McAfee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.24.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.24.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe
(C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe ->) (Advanced Micro Devices -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m\radeonsoftware\cncmd.exe
(cmd.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(cmd.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\BridgeCommunication.exe
(DriverStore\FileRepository\u0200911.inf_amd64_7fba98db80c63bd8\B026001\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0200911.inf_amd64_7fba98db80c63bd8\B026001\atieclxx.exe
(ETDService.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_ef58a27152e818c4\RtkAudUService64.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\ Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <16>
(HP Inc. -> ) C:\Program Files\WindowsApps\AD2F1837.myHP_60.52634.13225.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe
(HP Inc. -> HP Inc) C:\Program Files\WindowsApps\AD2F1837.myHP_60.52634.13225.0_x64__v10z8vjag6ke6\win32\HP.ContextAware.exe
(HP Inc. -> HP Inc.) C:\Program Files\HP\HP Media Network\HPMediaNetwork.exe
(HP Inc. -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.24.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe
(HP Inc. -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\152.0.4191.66\msedgewebview2.exe <5>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_ef58a27152e818c4\RtkAudUService64.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0200911.inf_amd64_7fba98db80c63bd8\B026001\atiesrxx.exe
(services.exe ->) (DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\SysInfoCap.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\MsMpEng.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\System32\DriverStore\FileRepository\rtkbtfilter.inf_amd64_a91f769b382735d4\RtkBtManServ.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_ef58a27152e818c4\RtkAudUService64.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(services.exe ->) (Zinlab Technologies -> ) C:\Users\Public\AppData\Roaming\Flixmate\flixmate.service.exe
(services.exe ->) (Zinlab Technologies -> ) C:\Users\Public\AppData\Roaming\Flixmate\update\Flixmate.UpdateService.exe
(sihost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> ) C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.6.2.0_x64__v10z8vjag6ke6\DialogHost\ReconsentNotification.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MixedRealityLink_26.8200.8060.0_x64__8wekyb3d8bbwe\Platform\MixedRealityPairingHelper.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\Overlay\OverlayHelper.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\SystemOptimizer\SystemOptimizer.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.380.2.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Valve Corp. -> Valve Corporation) C:\Program Files (x86)\ Steam\bin\cef\cef.win64\steamwebhelper.exe <6>
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_ef58a27152e818c4\RtkAudUService64.exe [3378216 2026-04-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-1877878918-3685700731-2616821082-1001\...\Run: [HPSEU_Host_Launcher] => C:\Program Files\HP\HP System Event Utility\Host Launcher\HpseuHostLauncher.exe [545864 2026-07-13] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1877878918-3685700731-2616821082-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4753768 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1877878918-3685700731-2616821082-1001\...\Run: [Steam] => C:\Program Files (x86)\ Steam\steam.exe [5775512 2026-09-03] (Valve Corp. -> Valve Corporation)
HKLM\Software\...\AppCompatFlags\Custom\AsusDialService.exe: [{22221111-1111-1111-1111-111111111111}.sdb] -> Microsoft Windows Application Compatibility Fix Database
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\152.0.7977.83\Installer\chrmstp.exe [7936664 2026-09-05] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {F285D50A-E19F-4C53-8C66-818627BCA0E1} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{A83B8239-1143-44D7-BF4D-6FDA3BB2F550} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC)
Task: {D43CE42A-05D7-4B49-9B43-F4C019D8C256} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [1026632 2026-08-13] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {600FE796-D52D-451E-AB51-3F213E09748C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2026-08-13] (HP Inc. -> HP Inc.)
Task: {B16466D4-375C-4102-A3DD-EFD16F7CFD85} - System32\Tasks\HP\Consent Manager Launcher => C:\windows\system32\sc.exe [102400 2025-09-15] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice
Task: {0014902D-203D-4351-B7FA-6A157B26AA5E} - System32\Tasks\HP\HPX Support\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HPX Support\Resources\HPSFReport.exe [108104 2026-07-14] (HP Inc. -> HP Inc.)
Task: {65D423F2-1C1B-48CB-B8A7-AA01206E2A0F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2401792 2026-08-22] () [File not signed]
Task: {405FF32E-BD46-494C-B488-A8115DC223DF} - System32\Tasks\McAfee\WPS\McAfee Sync Agent Pilot => \\?\C:\Program Files\McAfee\wps\SyncAgent\1.1.17.1\mc-sync-agent.exe /collect (No File)
Task: {6D3D9075-284E-4000-A094-EDFB419FA16D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21920576 2026-08-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {65BE9D79-B4D5-4E6E-BD1E-32D0625E0ED6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21920576 2026-08-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {B6F65BCE-7CBE-4C1A-A67F-450C4C3D35BD} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143728 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {752EBC96-1F44-4323-B144-8F7967700238} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143728 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {CA367F3B-047E-49B6-A9B9-2317075EF62B} - System32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [76296 2026-09-03] (HP Inc. -> HP Inc.)
Task: {5B94567D-0394-4949-A4EE-13ED1EE6F157} - System32\Tasks\OmenInstallMonitor-sid-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [76296 2026-09-03] (HP Inc. -> HP Inc.)
Task: {ACE5B868-A97F-417A-83F7-85BA9798705B} - System32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [68104 2026-09-03] (HP Inc. -> HP Inc.)
Task: {5E57AEEE-CA7D-4F41-9AF5-B63D9510CFCB} - System32\Tasks\OmenOverlay-sid-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [68104 2026-09-03] (HP Inc. -> HP Inc.)
Task: {A7E722E7-E9D4-4C7F-841A-F05B8491E1FE} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4408208 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {F85BB571-96F9-4CB8-B35A-7ED69D2F5242} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4408208 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {36EEEB2A-A602-429D-B15D-01F3797F0C88} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1877878918-3685700731-2616821082-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {0D557374-01F9-4779-89AA-8AB8A222E3FA} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\OneDriveLauncher.exe [858984 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF5F164A-7DED-4F35-BC34-4A5BEAF281B9} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1877878918-3685700731-2616821082-500 => C:\Users\Administrator\AppData\Local\Microsoft\OneDrive\25.087.0506.0001\OneDriveLauncher.exe /startInstances (No File)
Task: {5DE0D577-5527-4D8E-A654-C9CD495CB3F0} - System32\Tasks\SystemOptimizerCustomEvent-sid-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\HP\SystemOptimizer\SystemOptimizer.exe [168456 2026-09-03] (HP Inc. -> HP Inc.)
Task: {F890FCF1-3D8B-4E63-8620-3DC889C780D5} - System32\Tasks\SystemOptimizer-sid-S-1-5-21-1877878918-3685700731-2616821082-1001 => C:\Program Files\HP\SystemOptimizer\SystemOptimizer.exe [168456 2026-09-03] (HP Inc. -> HP Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{4aa3cb3b-d146-46bc-aa59-446a9f87f0fa}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Edge:
=======
Edge Profile: C:\Users\keram\AppData\Local\Microsoft\Edge\User Data\Default [2026-08-24]
Edge Extension: (Dokumenty Google offline) - C:\Users\keram\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-08-06]
Edge Extension: (Edge relevant text changes) - C:\Users\keram\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-07-06]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Chrome:
=======
CHR Profile: C:\Users\keram\AppData\Local\Google\Chrome\User Data\Default [2026-09-05]
CHR Extension: (CRX Emulator) - C:\Users\keram\AppData\Local\Google\Chrome\User Data\Default\Extensions\bekkpoinfafbjglppgdobfdeckghdhlo [2026-08-25]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\keram\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2026-09-05]
CHR Extension: (Dokumenty Google offline) - C:\Users\keram\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-08-24]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\keram\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2026-09-05]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\keram\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2026-07-09]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9214352 2026-08-05] (Microsoft Corporation -> Microsoft Corporation)
R2 DtsApo4Service; C:\windows\System32\DTS\PC\APO4x\DtsApo4Service.exe [514528 2026-01-21] (DTS, Inc. -> DTS Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncHelper.exe [3761000 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
R2 Flixmate.UpdateService; C:\Users\Public\AppData\Roaming\Flixmate\update\Flixmate.UpdateService.exe [25752 2026-02-24] (Zinlab Technologies -> )
R2 FlixmateService; C:\Users\Public\AppData\Roaming\Flixmate\flixmate.service.exe [194712 2026-02-24] (Zinlab Technologies -> )
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [462856 2025-04-25] (HP Inc. -> HP Inc.)
R2 HPAppHelperCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\AppHelperCap.exe [932032 2026-07-08] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\DiagsCap.exe [929984 2026-07-08] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\NetworkCap.exe [925888 2026-07-08] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\SysInfoCap.exe [1029832 2026-07-08] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe [639824 2025-09-18] (HP Inc. -> HP Inc.)
S3 IsolationSession; C:\windows\System32\IsoSessionServer.dll [1015808 2026-09-05] (Microsoft Windows -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11671792 2026-09-05] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-09-05] (Malwarebytes Inc -> Malwarebytes)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [888024 2026-08-22] (McAfee, LLC -> McAfee, LLC)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\MpDefenderCoreService.exe [2307816 2026-09-03] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 MixedRealityLinkSvc; C:\Program Files\WindowsApps\Microsoft.MixedRealityLink_26.8200.8060.0_x64__8wekyb3d8bbwe\Platform\MixedRealityLinkSvc.exe [1142072 2026-08-30] (Microsoft Corporation -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.153.0809.0004\OneDriveUpdaterService.exe [4054888 2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
R2 RtkBtManServ; C:\windows\System32\DriverStore\FileRepository\rtkbtfilter.inf_amd64_a91f769b382735d4\RtkBtManServ.exe [321864 2026-03-12] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\NisSrv.exe [5311736 2026-09-03] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\MsMpEng.exe [291360 2026-09-03] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AMDAfdAudioService; C:\windows\System32\DriverStore\FileRepository\amdacpafd.inf_amd64_ce2b2bc149703709\amdacpafd.sys [436080 2025-09-15] (Advanced Micro Devices -> Advanced Micro Devices)
R3 amdfendrmgr; C:\windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrmgr.sys [25672 2024-04-24] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\windows\System32\DriverStore\FileRepository\u0200911.inf_amd64_7fba98db80c63bd8\B026001\amdkmdag.sys [107992080 2026-05-19] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
R3 amdwirelessbutton; C:\windows\System32\drivers\amdwirelessbutton.sys [49448 2025-09-09] (Advanced Micro Devices -> Advanced Micro Devices, Inc)
S3 BthA2dp; C:\windows\System32\drivers\BthA2dp.sys [602112 2025-10-18] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\windows\System32\drivers\bthhfenum.sys [204800 2025-10-18] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\windows\System32\drivers\bthmodem.sys [114688 2025-09-15] (Microsoft Corporation) [File not signed]
R1 ESProtectionDriver; \??\C:\windows\system32\drivers\mbae.sys [159296 2026-09-05] (Microsoft Windows Hardware Compatibility Publisher -> )
R0 fse; C:\windows\System32\drivers\fse.sys [230888 2026-09-05] (Microsoft Windows -> Microsoft Corporation)
R3 HPCustomCapDriver; C:\windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [36424 2024-04-02] (HP Inc. -> HP Inc.)
R2 HpReadHWData; \??\C:\windows\system32\drivers\HpReadHWData.sys [65192 2026-08-19] (HP Inc. -> )
R3 KslD; C:\windows\System32\drivers\wd\KslD.sys [83008 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\windows\System32\drivers\l1vhlwf.sys [144864 2026-09-05] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\windows\System32\Drivers\MbamChameleon.sys [235624 2026-09-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\windows\System32\DRIVERS\MbamElam.sys [22120 2026-09-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\Drivers\farflt11.sys [217192 2026-09-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\windows\System32\Drivers\mbam.sys [132712 2026-09-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [246376 2026-09-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; \??\C:\windows\system32\DRIVERS\mwac.sys [190096 2026-09-05] (Malwarebytes Inc -> )
R3 RtkBtFilter2; C:\windows\System32\DriverStore\FileRepository\rtkbtfilter.inf_amd64_a91f769b382735d4\RtkBtFilter2.sys [210784 2026-03-12] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corporation)
R3 RtkBthLeVDspService; C:\windows\System32\DriverStore\FileRepository\rtkbthlevdsp.inf_amd64_527ad146b8893b71\RtkBthLeVDsp.sys [257832 2025-10-17] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corporation)
S3 rtu53cx22x64; C:\windows\System32\DriverStore\FileRepository\rtu53cx22x64.inf_amd64_852e6443bd48bdd3\rtu53cx22x64.sys [1158112 2025-06-29] (Realtek Semiconductor Corp. -> Realtek Corporation)
S3 rtucx21x64; C:\windows\System32\DriverStore\FileRepository\rtucx21x64.inf_amd64_286645bc82b2f9fb\rtucx21x64.sys [1359360 2024-04-01] (Microsoft Windows -> Realtek Corporation)
S3 tap0901; C:\windows\System32\drivers\tap0901.sys [51192 2026-07-06] (OpenVPN Inc. -> The OpenVPN Project)
S3 vmbusproxy; C:\windows\system32\drivers\vmbusproxy.sys [98304 2026-01-04] (Microsoft Windows -> Microsoft Corporation)
S4 WdAiNisDrv; C:\windows\System32\drivers\wd\WdAiNisDrv.sys [51224 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\windows\System32\drivers\wd\WdBoot.sys [21672 2026-09-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\windows\System32\drivers\wd\WdFilter.sys [660504 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [137240 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-09-05 14:33 - 2026-09-05 14:34 - 000027266 _____ C:\Users\keram\Desktop\FRST.txt
2026-09-05 14:33 - 2026-09-05 14:34 - 000000000 ____D C:\FRST
2026-09-05 14:32 - 2026-09-05 14:32 - 002450944 _____ (Farbar) C:\Users\keram\Desktop\FRST64.exe
2026-09-05 14:31 - 2026-09-05 14:31 - 000000000 ____D C:\Users\Default\AppData\Local\Malwarebytes
2026-09-05 14:30 - 2026-09-05 14:30 - 000190096 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2026-09-05 14:03 - 2026-09-05 14:11 - 000000000 ____D C:\windows\CbsTemp
2026-09-05 14:01 - 2026-09-05 14:01 - 000039215 _____ C:\windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-09-05 14:01 - 2026-09-05 14:01 - 000039215 _____ C:\windows\system32\IntegratedServicesRegionPolicySet.json
2026-09-05 14:01 - 2026-09-05 14:01 - 000014689 _____ C:\windows\system32\ecoscore_config.json
2026-09-05 14:01 - 2026-09-05 14:01 - 000004646 _____ C:\windows\system32\ResPriUHMImageList
2026-09-05 14:01 - 2026-09-05 14:01 - 000004646 _____ C:\windows\system32\ResPriLMImageList
2026-09-05 14:01 - 2026-09-05 14:01 - 000004646 _____ C:\windows\system32\ResPriImageList
2026-09-05 14:01 - 2026-09-05 14:01 - 000004646 _____ C:\windows\system32\ResPriHMImageList
2026-09-05 14:01 - 2026-09-05 14:01 - 000004555 _____ C:\windows\system32\ResPriImageListLowCost
2026-09-05 14:01 - 2026-09-05 14:01 - 000004555 _____ C:\windows\system32\ResPriHMImageListLowCost
2026-09-05 13:43 - 2026-09-05 14:33 - 000000000 ____D C:\Users\keram\AppData\Local\Malwarebytes
2026-09-05 13:43 - 2026-09-05 13:43 - 000002100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-09-05 13:43 - 2026-09-05 13:43 - 000002088 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-09-05 13:43 - 2026-09-05 13:43 - 000000000 ____D C:\Users\keram\AppData\Local\Sentry
2026-09-05 13:42 - 2026-09-05 13:42 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-09-05 13:42 - 2026-09-05 13:42 - 000000000 ____D C:\Program Files\Malwarebytes
2026-09-05 13:41 - 2026-09-05 13:41 - 002886560 _____ (Malwarebytes) C:\Users\keram\Downloads\MBSetup-8.8.exe
2026-09-05 13:40 - 2026-09-05 13:40 - 000712638 _____ C:\windows\system32\perfh005.dat
2026-09-05 13:40 - 2026-09-05 13:40 - 000162850 _____ C:\windows\system32\perfc005.dat
2026-09-05 13:34 - 2026-09-05 13:34 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2026-09-05 13:33 - 2026-09-05 13:33 - 000002524 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000002518 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000002490 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000002483 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000002416 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000002412 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2026-09-05 13:33 - 2026-09-05 13:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2026-09-05 13:31 - 2026-09-05 13:33 - 000000000 ____D C:\Program Files\Microsoft Office
2026-09-05 13:31 - 2026-09-05 13:31 - 000000000 ____D C:\Program Files\Microsoft Office 15
2026-09-01 16:03 - 2026-09-01 16:03 - 004799839 _____ C:\Users\keram\Downloads\strojka-online.pdf
2026-08-27 08:24 - 2026-08-27 08:24 - 000000000 ____D C:\ProgramData\Propagation
2026-08-27 08:24 - 2026-08-27 08:24 - 000000000 ____D C:\ProgramData\AMD
2026-08-25 09:30 - 2026-09-05 13:35 - 000000000 ____D C:\Users\Public\Temp
2026-08-25 09:30 - 2026-09-05 13:35 - 000000000 ____D C:\Users\Public\AppData\Flixmate
2026-08-25 09:30 - 2026-08-31 08:23 - 000000000 ____D C:\Users\Public\AppData\Roaming\Flixmate
2026-08-25 09:25 - 2026-08-25 09:25 - 330780264 _____ C:\Users\keram\Downloads\Flixmate-1.3.8.0-x64.exe
2026-08-24 19:18 - 2026-08-24 19:18 - 000000000 ____D C:\Users\keram\Documents\Vlastní šablony Office
2026-08-24 18:57 - 2026-08-24 18:57 - 000003300 _____ C:\windows\system32\Tasks\klcp_update
2026-08-24 18:57 - 2026-08-24 18:57 - 000000000 ____D C:\Users\keram\AppData\Roaming\MPC-HC
2026-08-24 18:56 - 2026-08-24 18:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2026-08-24 18:56 - 2026-08-24 18:56 - 000000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2026-08-24 18:55 - 2026-08-24 18:55 - 041157706 _____ (KLCP ) C:\Users\keram\Downloads\K-Lite_Codec_Pack_1995_Standard.exe
2026-08-20 10:02 - 2026-08-20 10:02 - 000000000 ____H C:\windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2026-08-15 15:53 - 2026-08-15 15:53 - 000000000 ____D C:\Users\keram\AppData\LocalLow\Santa Goat
2026-08-09 20:21 - 2026-09-05 13:35 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-08-08 17:27 - 2026-08-24 19:18 - 000000000 ____D C:\Users\keram\AppData\Roaming\Microsoft\UProof
2026-08-08 17:23 - 2026-08-08 17:23 - 000000000 ____D C:\Users\keram\AppData\Roaming\Microsoft\Excel
2026-08-08 17:22 - 2026-08-08 17:22 - 000000000 ____D C:\Users\keram\AppData\Roaming\Microsoft\Proof
2026-08-08 17:17 - 2026-09-05 13:25 - 000003194 _____ C:\windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-08-08 17:17 - 2026-09-05 13:25 - 000002030 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-08-08 17:17 - 2026-08-08 17:17 - 000000000 ___RD C:\Users\Default\OneDrive
2026-08-06 09:57 - 2026-08-06 09:57 - 000000000 ____D C:\Users\keram\AppData\LocalLow\tinyBuild Games
2026-08-06 09:54 - 2026-08-06 09:54 - 000000224 _____ C:\Users\keram\Desktop\Tinykin.url
2026-08-06 09:45 - 2026-08-06 09:45 - 000000000 ____D C:\Users\keram\AppData\Roaming\com.innersloth.henry.HenryFlash
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-09-05 14:33 - 2026-07-06 11:25 - 000000000 ____D C:\Users\keram\AppData\Local\OGH
2026-09-05 14:32 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemTemp
2026-09-05 14:31 - 2026-07-31 19:11 - 000000000 ____D C:\Program Files (x86)\ Steam
2026-09-05 14:31 - 2024-04-01 09:26 - 000000000 ____D C:\windows\AppReadiness
2026-09-05 14:31 - 2024-04-01 09:24 - 000000000 ____D C:\windows\INF
2026-09-05 14:30 - 2026-07-06 12:14 - 000000000 ____D C:\ProgramData\Realtek
2026-09-05 14:30 - 2026-07-06 09:40 - 000003358 _____ C:\windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-09-05 14:30 - 2025-10-18 00:52 - 000012288 ___SH C:\DumpStack.log.tmp
2026-09-05 14:30 - 2025-10-18 00:52 - 000000006 ____H C:\windows\Tasks\SA.DAT
2026-09-05 14:30 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-09-05 14:29 - 2025-10-18 00:55 - 000001623 _____ C:\windows\system32\config\VSMIDK
2026-09-05 14:29 - 2024-04-01 09:21 - 000786432 _____ C:\windows\system32\config\BBI
2026-09-05 14:28 - 2025-10-18 00:52 - 000596208 _____ C:\windows\system32\FNTCACHE.DAT
2026-09-05 14:27 - 2026-07-06 11:07 - 000000000 ____D C:\windows\system32\NarratorMCAT
2026-09-05 14:27 - 2025-09-15 21:48 - 000000000 ____D C:\windows\system32\ruxim
2026-09-05 14:27 - 2025-09-15 21:48 - 000000000 ____D C:\windows\InboxApps
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ___SD C:\windows\system32\F12
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ___RD C:\windows\ImmersiveControlPanel
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\UUS
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\WinMetadata
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\oobe
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\migwiz
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\InstallShield
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\Dism
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\AdvancedInstallers
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SystemResources
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\WinMetadata
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\WinBioPlugIns
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\Sysprep
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ShellExperiences
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\SecureBootUpdates
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\PerceptionSimulation
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\oobe
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\migwiz
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\HealthAttestationClient
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\Dism
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\appraiser
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\AdvancedInstallers
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\ShellExperiences
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\ShellComponents
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\Provisioning
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\L2Schemas
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\BrowserCore
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\windows\bcastdvr
2026-09-05 14:27 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-09-05 14:27 - 2024-04-01 09:21 - 000000000 ____D C:\windows\servicing
2026-09-05 14:25 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-09-05 14:13 - 2026-01-04 04:49 - 000000000 ____D C:\Program Files\McAfee
2026-09-05 14:06 - 2026-07-09 15:12 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-09-05 14:06 - 2026-07-09 15:12 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-09-05 14:01 - 2025-10-18 01:01 - 003379712 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll
2026-09-05 13:52 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2026-09-05 13:43 - 2026-07-06 11:17 - 000000000 ____D C:\Users\keram\AppData\Local\Packages
2026-09-05 13:43 - 2025-10-18 00:55 - 000000000 ____D C:\ProgramData\Packages
2026-09-05 13:43 - 2024-04-01 09:26 - 000000000 ___HD C:\windows\ELAMBKUP
2026-09-05 13:40 - 2025-10-18 01:01 - 001707668 _____ C:\windows\system32\PerfStringBackup.INI
2026-09-05 13:34 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2026-09-05 13:26 - 2026-07-06 11:25 - 000004474 _____ C:\windows\system32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-05 13:26 - 2026-07-06 11:25 - 000004414 _____ C:\windows\system32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-05 13:26 - 2026-07-06 11:25 - 000004072 _____ C:\windows\system32\Tasks\OmenInstallMonitor-sid-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-05 13:26 - 2026-07-06 11:25 - 000004012 _____ C:\windows\system32\Tasks\OmenOverlay-sid-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-05 13:25 - 2026-07-06 11:23 - 000003596 _____ C:\windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-05 13:25 - 2026-07-06 11:23 - 000003552 _____ C:\windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-05 13:24 - 2026-07-06 11:20 - 000000000 ____D C:\Users\keram\AppData\Local\D3DSCache
2026-09-05 13:24 - 2025-10-18 00:59 - 000000000 ____D C:\Program Files\HP
2026-09-05 13:24 - 2025-10-18 00:53 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-09-05 13:24 - 2025-10-18 00:53 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-09-05 13:23 - 2026-07-09 19:41 - 000004448 _____ C:\windows\system32\Tasks\SystemOptimizerCustomEvent-sid-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-05 13:23 - 2026-07-09 19:41 - 000004048 _____ C:\windows\system32\Tasks\SystemOptimizer-sid-S-1-5-21-1877878918-3685700731-2616821082-1001
2026-09-03 18:14 - 2025-10-18 00:52 - 000000000 ____D C:\windows\system32\SleepStudy
2026-09-03 16:41 - 2025-10-18 00:53 - 000000000 ____D C:\windows\system32\Drivers\wd
2026-09-03 16:28 - 2026-07-06 11:22 - 000000000 ____D C:\Users\keram\AppData\Local\HP
2026-09-03 16:28 - 2026-01-04 05:06 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2026-09-03 16:26 - 2025-10-18 00:53 - 000003714 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{50F00C63-3BC6-436A-B188-D81F14BCF314}
2026-09-03 16:26 - 2025-10-18 00:53 - 000003588 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{05500C68-23E2-47B7-A8EF-3A1EDFE37B4F}
2026-09-01 16:42 - 2024-04-01 09:26 - 000000000 ____D C:\windows\LiveKernelReports
2026-08-27 08:29 - 2026-07-06 11:20 - 000000000 ____D C:\Users\keram\AppData\Local\AMD
2026-08-27 08:29 - 2024-04-01 09:26 - 000000000 ____D C:\windows\appcompat
2026-08-19 15:37 - 2026-01-04 04:48 - 000065192 _____ (Windows (R) Win 7 DDK provider) C:\windows\system32\Drivers\HpReadHWData.sys
2026-08-15 16:05 - 2026-08-01 09:24 - 000000000 ____D C:\Users\keram\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2026-08-12 19:57 - 2026-07-06 11:07 - 000000000 ____D C:\windows\SecureBoot
2026-08-12 19:57 - 2024-04-01 10:09 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2026-08-12 19:57 - 2024-04-01 10:08 - 000000000 ____D C:\windows\system32\OpenSSH
2026-08-12 19:57 - 2024-04-01 10:08 - 000000000 ____D C:\windows\system32\Microsoft-Edge-WebView
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ___SD C:\windows\SysWOW64\F12
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files (x86)\Windows Defender
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\vi-VN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ur-PK
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ug-CN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\tt-RU
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\te-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ta-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\sq-AL
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\quz-PE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\qps-plocm
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\qps-ploc
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\PerceptionSimulation
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\pa-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\or-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\nn-NO
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ne-NP
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mt-MT
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mr-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ml-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mk-MK
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\mi-NZ
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lv-LV
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lt-LT
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lo-LA
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\lb-LU
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kok-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kn-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\km-KH
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\kk-KZ
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ka-GE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\is-IS
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\id-ID
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\hy-AM
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\hi-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gu-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gl-ES
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\gd-GB
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ga-IE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\fil-PH
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\fa-IR
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\eu-ES
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\et-EE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\es-MX
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\DDFs
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\cy-GB
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\ca-ES
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\bn-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\be-BY
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\as-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\am-ET
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\SysWOW64\af-ZA
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\vi-VN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ur-PK
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ug-CN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\tt-RU
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\te-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ta-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\sq-AL
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\quz-PE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\qps-plocm
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\qps-ploc
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\pa-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\or-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\nn-NO
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ne-NP
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mt-MT
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mr-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ml-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mk-MK
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\mi-NZ
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lv-LV
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lt-LT
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lo-LA
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\lb-LU
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kok-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kn-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\km-KH
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\kk-KZ
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ka-GE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\is-IS
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\id-ID
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\hy-AM
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\hi-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gu-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gl-ES
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\gd-GB
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ga-IE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\fil-PH
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\fa-IR
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\eu-ES
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\et-EE
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\es-MX
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\DDFs
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\cy-GB
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\ca-ES
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\bn-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\be-BY
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\as-IN
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\am-ET
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\system32\af-ZA
2026-08-12 19:57 - 2024-04-01 09:26 - 000000000 ____D C:\windows\DiagTrack
2026-08-12 14:54 - 2026-07-06 11:37 - 000000000 ____D C:\windows\system32\MRT
2026-08-12 14:52 - 2026-07-06 11:37 - 228836432 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2026-08-08 17:42 - 2026-07-06 11:44 - 000000000 ____D C:\ProgramData\Whesvc
2026-08-08 17:27 - 2026-07-09 19:40 - 000000000 ____D C:\Users\keram\AppData\Roaming\Microsoft\Office
2026-08-08 17:12 - 2026-07-06 11:17 - 000000000 ____D C:\Users\keram
2026-08-08 17:12 - 2026-01-04 04:49 - 000000000 ____D C:\ProgramData\McAfee
2026-08-08 17:07 - 2026-07-06 11:17 - 000000000 ____D C:\Users\keram\AppData\Roaming\Microsoft\Spelling
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2026
Ran by keram (05-09-2026 14:35:41)
Running from C:\Users\keram\Desktop
Microsoft Windows 11 Home Version 25H2 26200.9278 (X64) (2026-07-06 07:34:37)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-1877878918-3685700731-2616821082-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-1877878918-3685700731-2616821082-503 - Limited - Disabled)
Guest (S-1-5-21-1877878918-3685700731-2616821082-501 - Limited - Disabled)
keram (S-1-5-21-1877878918-3685700731-2616821082-1001 - Administrators - Enabled) [MS Account] => C:\Users\keram
WDAGUtilityAccount (S-1-5-21-1877878918-3685700731-2616821082-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 152.0.4191.64 - Microsoft Corporation)
Flixmate (HKLM-x32\...\Flixmate - Multimedia Toolkit) (Version: 1.3.8 - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 152.0.7977.83 - Google LLC)
HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.21.0 - HP Inc)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
K-Lite Codec Pack 19.9.5 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 19.9.5 - KLCP)
Malwarebytes version 5.6.5.306 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.5.306 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 152.0.4191.62 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 152.0.4191.66 - Microsoft Corporation) Hidden
Microsoft Office Installer version 1.0 (HKLM-x32\...\Microsoft Office Installer_is1) (Version: 1.0 - )
Microsoft Office LTSC Professional Plus 2021 - cs-cz (HKLM\...\ProPlus2021Volume - cs-cz) (Version: 16.0.14334.20848 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.153.0809.0004 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Windows Application Compatibility Fix Database (HKLM\...\{22221111-1111-1111-1111-111111111111}.sdb) (Version: - )
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14334.20848 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14334.20848 - Microsoft Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
WebAdvisor od společnosti McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.2.111 - McAfee, LLC)
Packages:
=========
AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19012.0_x64__0a9344xs7nr4m [2026-07-06] (Advanced Micro Devices Inc.) [Startup Task]
Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_23.4.38.0_x64__xbfy0k16fey96 [2026-08-02] (Dropbox Inc.)
HP -> C:\Program Files\WindowsApps\AD2F1837.myHP_60.52634.13225.0_x64__v10z8vjag6ke6 [2026-08-30] (HP Inc.) [Startup Task]
HP Inc. Energy Star -> C:\Program Files\WindowsApps\AD2F1837.HPInc.EnergyStar_2.0.11.0_x64__v10z8vjag6ke6 [2026-07-13] (HP Inc.)
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_3.2.0.0_x64__v10z8vjag6ke6 [2026-08-06] (HP Inc.)
HP PC Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.6.2.0_x64__v10z8vjag6ke6 [2026-08-06] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_166.1.1185.0_x64__v10z8vjag6ke6 [2026-08-13] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.55.10.0_x64__v10z8vjag6ke6 [2026-08-24] (HP Inc.)
HP System Event Utility -> C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.24.0_x64__v10z8vjag6ke6 [2026-07-13] (HP Inc.)
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2026-09-05] ()
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.103.0_x64__8wekyb3d8bbwe [2025-10-17] (Microsoft Corp.)
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_55.20329.227.0_x64__8wekyb3d8bbwe [2025-10-17] (Microsoft Corporation)
Microsoft.MixedRealityLink -> C:\Program Files\WindowsApps\Microsoft.MixedRealityLink_26.8200.8060.0_x64__8wekyb3d8bbwe [2026-08-30] (Microsoft Corporation) [Startup Task]
OMEN Gaming Hub -> C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6 [2026-09-03] (HP Inc.) [Startup Task]
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8002.4.0.0_x64__8wekyb3d8bbwe [2026-08-25] (Microsoft Corp.)
Windows App Runtime DDLM 8000.806.2252.0-x6 -> C:\Program Files\WindowsApps\Microsoft.WinAppRuntime.DDLM.8000.806.2252.0-x6_8000.806.2252.0_x64__8wekyb3d8bbwe [2026-07-06] (Microsoft Corporation)
Windows App Runtime DDLM 8000.806.2252.0-x8 -> C:\Program Files\WindowsApps\Microsoft.WinAppRuntime.DDLM.8000.806.2252.0-x8_8000.806.2252.0_x86__8wekyb3d8bbwe [2026-07-06] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1877878918-3685700731-2616821082-1001_Classes\CLSID\{7d043d4e-4259-f459-3630-7b434fd7752c}\localserver32 -> C:\Program Files\HP\HP Media Network\HPMediaNetwork.exe (HP Inc. -> HP Inc.)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-09-05] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.153.0809.0004\FileSyncShell64.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-09-05] (Malwarebytes Inc -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2026-07-31 19:13 - 2026-07-24 19:40 - 002291712 _____ () [File not signed] C:\Program Files (x86)\ Steam\libpyrowave-shared-0.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2026-08-13] (HP Inc. -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2026-08-13] (HP Inc. -> HP Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-09-05] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2026-07-31 19:55 - 000000822 _____ C:\windows\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi 5: Realtek 8852BE-VT Wireless LAN WiFi 6 PCI-E NIC -> rtwlane613.sys
Wi-Fi 2: Realtek 8852BE-VT Wireless LAN WiFi 6 PCI-E NIC -> rtwlane613.sys
Wi-Fi: Realtek 8852BE-VT Wireless LAN WiFi 6 PCI-E NIC -> rtwlane613.sys
vms_vsf: Hyper-V Virtual Switch Extension Filter
ms_l1vhlwf: Nested Network Virtualization
vms_vsp: Hyper-V Virtual Switch Extension Protocol
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1877878918-3685700731-2616821082-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\keram\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\9710132291668702418\134329192986114012.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\windows\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0D076BC1-04AD-4862-8153-FD55B88AE66A}] => (Allow) C:\Program Files (x86)\ Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{20B07498-4B9B-4404-8EE3-EEEFDD01C59D}] => (Allow) C:\Program Files (x86)\ Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E805A317-8EDD-4124-8E35-A88DA28E7757}] => (Allow) C:\Program Files (x86)\ Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{23C55F0A-2D8D-4581-9DA4-EE1D9402248F}] => (Allow) C:\Program Files (x86)\ Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B73E39BE-FE4C-4964-ABC5-4A7DF6F918A8}] => (Allow) C:\Program Files (x86)\ Steam\steamapps\common\Hollow Knight\hollow_knight.exe () [File not signed]
FirewallRules: [{62CEE14F-7F95-4FFE-AC42-953AFB038D64}] => (Allow) C:\Program Files (x86)\ Steam\steamapps\common\Hollow Knight\hollow_knight.exe () [File not signed]
FirewallRules: [{1BD805B1-3BD9-4015-9DCF-531D3A4146C2}] => (Allow) C:\Program Files (x86)\ Steam\steamapps\common\Tinykin\Tinykin.exe () [File not signed]
FirewallRules: [{4578D2E7-F800-478E-A8C9-F568E9EF7207}] => (Allow) C:\Program Files (x86)\ Steam\steamapps\common\Tinykin\Tinykin.exe () [File not signed]
FirewallRules: [{D78DC237-B814-4ACA-B648-764AAAC809AB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0A66DF58-949B-4AAB-89D9-B04EAFA4C377}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0C20D746-6BB3-4753-B449-62ABE0F7E1E7}] => (Allow) C:\Users\Public\AppData\Roaming\Flixmate\flixmate.service.exe (Zinlab Technologies -> )
FirewallRules: [{7F2FA5D7-A5D2-4A70-ABFB-CC97580DCB0C}] => (Allow) C:\Users\Public\AppData\Roaming\Flixmate\update\Flixmate.UpdateService.exe (Zinlab Technologies -> )
FirewallRules: [{9883FF5E-B8B4-434D-A3B7-3FDDC35D7FA9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MixedRealityLink_26.8200.8060.0_x64__8wekyb3d8bbwe\Platform\MrBackgroundHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DB497F2B-5054-45AF-BCBC-D602E98876DB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MixedRealityLink_26.8200.8060.0_x64__8wekyb3d8bbwe\Platform\MrBackgroundHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E5E6CE80-A2C1-4105-8B30-54B92B329BC2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MixedRealityLink_26.8200.8060.0_x64__8wekyb3d8bbwe\Platform\MrBackgroundHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{ADE5AC13-88E0-4B4C-8EDF-C49B929371FC}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{25170726-0227-40C0-BFC1-DF60A9ABB487}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{9B1B86DA-CF61-49C4-BCF8-6C9547199F9A}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{9022FF87-A2FF-4307-B0E4-8A090EEC92EB}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{7514C73F-A9BF-47DD-AF5C-150CA836DE83}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{6119040C-9881-4889-910B-28B023658197}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{178879C2-E6E2-4EC2-9606-65B30D90378C}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{ED8A7997-33A8-4CE7-889F-FDED038F1B63}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{29A7C5C6-AB43-47C9-961C-6DD37326B019}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{71DDA59C-D744-4BB0-8DCD-FFE441CE463D}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{16B5FF89-4301-4265-A66E-8F31C7392F71}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{07E8A561-51A1-4396-B16C-80310BF504C7}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{0F63E66D-EF92-4DA7-B91D-4C50BA5841EA}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{31B96FDF-A138-4DB8-8D5D-110ACD6C2479}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{95D57A8A-46BA-4D09-BF0F-1CE32697EDEB}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.)
FirewallRules: [{AD76EA20-B114-42B2-920F-56734AA1F4EC}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2608.3.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.)
FirewallRules: [{10AE4046-E75C-4B64-BE06-C8DC6D57EC42}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D1366E88-3894-4C75-A9C3-7688659E33D7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2FE3F9C4-0E41-4F22-84AE-2403E915D8B0}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2825AC02-8F08-4892-8E91-A059CE32ECB5}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E68EDD22-78AB-45E3-9380-C4D25069C466}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
05-09-2026 13:51:32 Instalační služba modulů systému Windows
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (08/24/2026 07:19:42 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C020
ID SKU=84e442c0-87a0-49b5-bcd1-b161b0b35e4b
Error: (08/24/2026 07:19:42 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C020
Error: (08/24/2026 07:16:51 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C020
ID SKU=84e442c0-87a0-49b5-bcd1-b161b0b35e4b
Error: (08/24/2026 07:16:51 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C020
Error: (08/12/2026 08:00:29 PM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://AMD-KeyId-9cb359a22a91df22045f5 ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Wed, 12 Aug 2026 18:00:29 GMT
Content-Length: 148
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: d10cbcbb-4b3b-46e1-bfd4-0ebfb50e6f20
Metoda: POST(4579ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (08/12/2026 07:58:51 PM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://AMD-KeyId-9cb359a22a91df22045f5 ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Wed, 12 Aug 2026 17:58:52 GMT
Content-Length: 148
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 2dc8bd81-0ce6-441d-ba36-26df625a0482
Metoda: POST(4047ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (08/08/2026 05:28:46 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C020
ID SKU=84e442c0-87a0-49b5-bcd1-b161b0b35e4b
Error: (08/08/2026 05:28:46 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C020
System errors:
=============
Error: (09/05/2026 02:35:47 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Updated Secure Boot certificates are available on this device but have not yet been applied to the firmware. Review the published guidance to complete the update and maintain full protection. This device signature information is included here.
DeviceAttributes: FirmwareManufacturer:AMI;FirmwareVersion:F.25;OEMModelBaseBoard:8DC7;OEMManufacturerName:HP;OSArchitecture:amd64;
BucketId: 9c3b8692adea5d332d38b2d180df68dc101c86dc7f5b7ad8fa548dcef9b874ac
BucketConfidenceLevel: Under Observation - More Data Needed
UpdateType:
For more information, please see https://go.microsoft.com/fwlink/?linkid=2301018.
Error: (09/05/2026 02:35:47 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update SBAT with error -1878589247. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
Error: (09/05/2026 02:30:29 PM) (Source: Microsoft-Windows-BitLocker-Driver) (EventID: 24641) (User: NT AUTHORITY)
Description: Při pokusu o načtení hlavního klíče svazku nástroje BitLocker během restartování došlo k neočekávané chybě.
Error: (09/05/2026 02:30:29 PM) (Source: Microsoft-Windows-BitLocker-Driver) (EventID: 24641) (User: NT AUTHORITY)
Description: Při pokusu o načtení hlavního klíče svazku nástroje BitLocker během restartování došlo k neočekávané chybě.
Error: (09/05/2026 02:30:08 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Aktualizovat službu Orchestrator byla ukončena s následující chybou:
%%2149884192
Error: (09/05/2026 02:29:43 PM) (Source: Microsoft-Windows-BitLocker-Driver) (EventID: 24641) (User: NT AUTHORITY)
Description: Při pokusu o načtení hlavního klíče svazku nástroje BitLocker během restartování došlo k neočekávané chybě.
Error: (09/05/2026 02:29:43 PM) (Source: Microsoft-Windows-BitLocker-Driver) (EventID: 24641) (User: NT AUTHORITY)
Description: Při pokusu o načtení hlavního klíče svazku nástroje BitLocker během restartování došlo k neočekávané chybě.
Error: (09/05/2026 02:28:58 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Aktualizovat službu Orchestrator byla ukončena s následující chybou:
%%2149884192
Error: (08/25/2026 06:03:40 PM) (Source: disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR4.
Error: (08/24/2026 08:14:47 PM) (Source: disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR2.
Error: (08/20/2026 10:08:21 AM) (Source: disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.
Windows Defender:
================
TimeCreated : 30.08.2026 17:07:54
Message : Antivirová ochrana v programu Microsoft Defender šćаň ђăѕ ьё℮ň śŧőφφĕď взƒοгè čőmрŀ℮ţîŏñ.%π %τŜčдň ΊĐ:%в{
969ADE30-616D-414A-BCBD-73C069DEE560}%л %ţŠ¢ăň Тýρэ:%ьAntimalwarový program%ŋ %ťŞсàπ Ράгамέŧęŗŝ:%ъRychlé
prohledávání%ņ %ŧŪŝėř:%ьNT AUTHORITY\SYSTEM%ñ %тŞτõρ Ґėâšóй:%вŠçнëðūĺεđ ѕčäπ щâš śķîρφєδ ьέčаũѕé ťĥє ℓâš
ŧ śúςćęşşƒύł ѕ¢аи ẅäš ẅîťĥίπ ŧђэ ŀäѕŧ 7 ďäŷş
TimeCreated : 27.08.2026 18:06:33
Message : Antivirová ochrana v programu Microsoft Defender šćаň ђăѕ ьё℮ň śŧőφφĕď взƒοгè čőmрŀ℮ţîŏñ.%π %τŜčдň ΊĐ:%в{
379D0EE9-DD5E-4EA7-9966-F4AA14EE20B2}%л %ţŠ¢ăň Тýρэ:%ьAntimalwarový program%ŋ %ťŞсàπ Ράгамέŧęŗŝ:%ъRychlé
prohledávání%ņ %ŧŪŝėř:%ьNT AUTHORITY\SYSTEM%ñ %тŞτõρ Ґėâšóй:%вŠçнëðūĺεđ ѕčäπ щâš śķîρφєδ ьέčаũѕé ťĥє ℓâš
ŧ śúςćęşşƒύł ѕ¢аи ẅäš ẅîťĥίπ ŧђэ ŀäѕŧ 7 ďäŷş
TimeCreated : 27.08.2026 12:22:22
Message : Antivirová ochrana v programu Microsoft Defender šćаň ђăѕ ьё℮ň śŧőφφĕď взƒοгè čőmрŀ℮ţîŏñ.%π %τŜčдň ΊĐ:%в{
9750DEC9-0FAC-4D0E-902D-5A9D1C41C470}%л %ţŠ¢ăň Тýρэ:%ьAntimalwarový program%ŋ %ťŞсàπ Ράгамέŧęŗŝ:%ъRychlé
prohledávání%ņ %ŧŪŝėř:%ьNT AUTHORITY\SYSTEM%ñ %тŞτõρ Ґėâšóй:%вŠçнëðūĺεđ ѕčäπ щâš śķîρφєδ ьέčаũѕé ťĥє ℓâš
ŧ śúςćęşşƒύł ѕ¢аи ẅäš ẅîťĥίπ ŧђэ ŀäѕŧ 7 ďäŷş
TimeCreated : 25.08.2026 20:52:57
Message : Antivirová ochrana v programu Microsoft Defender šćаň ђăѕ ьё℮ň śŧőφφĕď взƒοгè čőmрŀ℮ţîŏñ.%π %τŜčдň ΊĐ:%в{
D0F1F784-ABC0-450C-93F6-9CA1410BBE3A}%л %ţŠ¢ăň Тýρэ:%ьAntimalwarový program%ŋ %ťŞсàπ Ράгамέŧęŗŝ:%ъRychlé
prohledávání%ņ %ŧŪŝėř:%ьNT AUTHORITY\SYSTEM%ñ %тŞτõρ Ґėâšóй:%вŠçнëðūĺεđ ѕčäπ щâš śķîρφєδ ьέčаũѕé ťĥє ℓâš
ŧ śúςćęşşƒύł ѕ¢аи ẅäš ẅîťĥίπ ŧђэ ŀäѕŧ 7 ďäŷş
TimeCreated : 17.08.2026 19:35:54
Message : Antivirová ochrana v programu Microsoft Defender šćаň ђăѕ ьё℮ň śŧőφφĕď взƒοгè čőmрŀ℮ţîŏñ.%π %τŜčдň ΊĐ:%в{
60F6C5CA-2084-4D81-A407-877FFCCE4DA8}%л %ţŠ¢ăň Тýρэ:%ьAntimalwarový program%ŋ %ťŞсàπ Ράгамέŧęŗŝ:%ъRychlé
prohledávání%ņ %ŧŪŝėř:%ьNT AUTHORITY\SYSTEM%ñ %тŞτõρ Ґėâšóй:%вŠçнëðūĺεđ ѕčäπ щâš śķîρφєδ ьέčаũѕé ťĥє ℓâš
ŧ śúςćęşşƒύł ѕ¢аи ẅäš ẅîťĥίπ ŧђэ ŀäѕŧ 7 ďäŷş
CodeIntegrity:
===============
Date: 2026-09-05 14:33:47
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Microsoft signing level requirements.
Date: 2026-09-05 14:32:48
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: AMI F.25 04/20/2026
Motherboard: HP 8DC7
Processor: AMD Ryzen 7 7730U with Radeon Graphics
Percentage of memory in use: 27%
Total physical RAM: 32095.32 MB
Available physical RAM: 23383.26 MB
Total Virtual: 34143.32 MB
Available Virtual: 23901.35 MB
==================== Drives ================================
Disk 0 - Drive c: (Windows) (Fixed) (Total:561.83 GB) (Free:465.92 GB) (Model: SAMSUNG MZVMX1T0HCLD-00BH1) (Protected) NTFS
Disk 0 - Drive d: (Data) (Fixed) (Total:390.62 GB) (Free:390.51 GB) (Model: SAMSUNG MZVMX1T0HCLD-00BH1) (Protected) NTFS
Disk 0 - \\?\Volume{7dc92c86-c2da-48e8-b70b-413a7cd534a1}\ (Windows RE tools) (Fixed) (Total:0.89 GB) (Free:0.08 GB) NTFS
Disk 0 - \\?\Volume{245bf89e-2992-4fb4-b8fa-dae5d976aa24}\ (SYSTEM) (Fixed) (Total:0.5 GB) (Free:0.41 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 953.9 GB) (Disk ID: B0444A2E)
Partition: GPT.
==================== End of Addition.txt =======================
Infird.com
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.

Přispějete na provoz fóra?