Zdravím, prosím o kontrolu logu. Díky
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-10-2026
Ran by sadro (administrator) on DESKTOP-4E77SLT (LENOVO 6475AG9) (08-10-2026 12:33:41)
Running from C:\Users\sadro\OneDrive\Plocha\Čištení\FRST64.exe
Loaded Profiles: sadro
Platform: Microsoft Windows 10 Home Version 22H2 19045.7725 (X64) Language: Čeština (Česko)
Default browser: "C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\DefenderAiPlatformHost.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\DefenderSessionHelper.exe
(C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\sadro\AppData\Local\Programs\Opera\136.0.6008.80\opera_crashreporter.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe
(Opera Norway AS -> Opera Software) C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe <14>
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\NisSrv.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.7714_none_7dea5cb47ca89937\TiWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [TrackPointSrv] => C:\Program Files\Lenovo\TrackPoint\tp4serv.exe [138784 2011-11-01] (Lenovo (Japan) Ltd. -> Lenovo Group Limited)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2539320 2024-01-09] (Malwarebytes Inc. -> Malwarebytes Corporation)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Run: [ut] => C:\Users\sadro\AppData\Roaming\uTorrent\uTorrent.exe [2071560 2025-08-14] (BitTorrent Inc -> BitTorrent Limited)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [46775800 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Run: [MicrosoftEdgeAutoLaunch_2F877205FC610259C551AA55F379B2D4] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5403976 2026-10-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {84f22e1e-039d-11f0-af6d-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {84f23ec3-039d-11f0-af6d-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {d7530b63-3f8c-11f0-af75-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Windows\System32\osk.exe [684544 2026-08-13] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\PDF-XChange5-ABBYY-FR15: C:\WINDOWS\system32\pxc50pmaf15.dll [57328 2018-12-04] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\147.0.7727.138\Installer\chrmstp.exe [7428248 2026-05-01] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {6BDBB040-4E5E-4835-B1CE-E30B01793D82} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {BD6013EE-B70A-433C-8BAA-F1B2DF3D5D1A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9624CC7B-E024-4253-95A4-633BDAB7A770} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6140920 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "bb0d7bde-416d-4286-b352-424eb73e6649" --version "6.41.0.11567" --silent
Task: {BD9136EF-67D2-4416-BBF9-441262B15920} - System32\Tasks\CCleanerSkipUAC - sadro => C:\Program Files\CCleaner\CCleaner.exe [39839224 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {827FEEBC-04C8-4DAC-865A-5A829EF98D11} - System32\Tasks\Driver Booster SkipUAC (sadro) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [8946688 2023-06-09] (IObit) [File not signed] <==== ATTENTION
Task: {C5FE9906-B104-44A5-BEE3-0984AF674071} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{0882C11F-A16E-46F7-B6D9-C7F305DB9A93} => C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe [7056536 2025-11-26] (Google LLC -> Google LLC)
Task: {B5D9926D-E6BD-424D-BFC9-1F457F98639E} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{15BFC5EE-74CD-49F3-81A8-BF07DC61B75E} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [6517400 2026-04-15] (Google LLC -> Google LLC)
Task: {C5022AF4-9706-412A-B55E-E8AB5AE63881} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => C:\WINDOWS\system32\sc.exe [72192 2019-12-07] (Microsoft Windows -> Microsoft Corporation) -> start LenovoVantageService
Task: {30F95CC3-079E-4452-AD72-048ADA5676D9} - System32\Tasks\Lenovo\Vantage\Schedule\BatteryGaugeAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {ECAB5733-C40D-4B95-909A-C233E7D2EE50} - System32\Tasks\Lenovo\Vantage\Schedule\DailyTelemetryTransmission => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {EC28FE73-70A9-4FCA-A91B-E29FDE4E524C} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {285E97C1-AD05-46C9-BBFA-BFF1BD54BCB8} - System32\Tasks\Lenovo\Vantage\Schedule\HeartbeatAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {4132853B-99B9-4F06-83C4-0F36F7CD2468} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {5ABFD021-A741-4D36-BDF1-4112E7079540} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoBatteryPartSalesMonthlyToast => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {7CEF24CF-BE5C-432D-80BD-E70545AB122F} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {9C800CB1-5F0C-4B7E-A1B4-55953965F22E} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {100522FD-579C-4BA5-854A-BC376D1A342B} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {FCA466FD-1A63-4418-86A7-4F83544407EB} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinIdleScheduleTask => C:\ProgramData\Lenovo\Vantage\Addins\VantageCoreAddin\1.0.0.181\x64\IdleScheduleEventAction.exe [143768 2024-11-01] (Lenovo -> )
Task: {68674784-1D49-457E-B081-12EDCBB86A8E} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinWeekScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {D78BD745-32B3-4F82-95BD-24DC208A4159} - System32\Tasks\Lenovo\Vantage\StartupFixPlan => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\uninstall.exe [340968 2024-09-12] (Lenovo -> Lenovo)
Task: {05ABA0F5-C616-4C30-93C6-F671B5C84244} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B5ABD661-0049-4360-8907-9A3547BF5143} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FC373213-CA37-45BE-B6BB-71CCFA116C23} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {47D0D973-17DB-4796-88DF-D01A2741B5FE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BC532278-CF10-441B-8FBF-D9570E1081B9} - System32\Tasks\Opera scheduled assistant Autoupdate 1729013942 => C:\Users\sadro\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [7762888 2026-09-29] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --installdir="C:\Users\sadro\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {C2566133-FE21-4233-8D4D-3D7DF89302E9} - System32\Tasks\Opera scheduled Autoupdate 1729013909 => C:\Users\sadro\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [7762888 2026-09-29] (Opera Norway AS -> Opera Software)
Task: {F17A929C-66D8-4975-921D-D873E9125C0D} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-978282830-4128747045-4181034530-1001 => {201600D8-6EFF-48CE-B842-E14D37A0682D} C:\WINDOWS\System32\wpninprc.dll [24064 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {BD0E2CD4-19A3-4D8D-8616-9E2A1B72E30B} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-978282830-4128747045-4181034530-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe /bg /scheduledHC (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{03ff6323-85d8-4241-9413-9622f5e73dc7}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{03ff6323-85d8-4241-9413-9622f5e73dc7}\255646D69602933402E46434: [DhcpNameServer] 192.168.43.1
FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-31] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-31] (VideoLAN -> VideoLAN)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\sadro\AppData\Local\Microsoft\Edge\User Data\Default [2026-10-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\sadro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-10]
Edge Extension: (Edge relevant text changes) - C:\Users\sadro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-11-20]
Chrome:
=======
CHR Profile: C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default [2026-10-05]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-07-22]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2025-07-22]
CHR Extension: (Dokumenty Google offline) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-07-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-07-22]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKU\S-1-5-21-978282830-4128747045-4181034530-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1080824 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [236864 2022-06-24] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S4 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\LenovoVantageService.exe [34256 2024-09-12] (Lenovo -> Lenovo)
S3 LPlatSvc; C:\WINDOWS\System32\LPlatSvc.exe [892288 2019-12-11] (Lenovo -> Lenovo.)
S3 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [169344 2024-01-09] (Malwarebytes Inc. -> Malwarebytes Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpDefenderCoreService.exe [2398680 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\NisSrv.exe [5555528 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe [378168 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 atmeltpm; C:\WINDOWS\System32\drivers\atmeltpm64.sys [19456 2011-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Atmel, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R3 CnxtHdAudService; C:\WINDOWS\system32\drivers\CHDRT64.sys [649216 2009-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems Inc.)
R3 cykbfltrService; C:\WINDOWS\System32\drivers\cykbfltr.sys [16896 2012-06-15] (Cypress Semiconductor -> Cypress Semiconductor, Inc.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-12-02] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-12-02] (Disc Soft Ltd -> Disc Soft Ltd)
S3 ecnssndis; C:\WINDOWS\System32\Drivers\wwuss64.sys [26664 2010-02-23] (Ericsson AB -> Ericsson AB)
S3 ecnssndisfltr; C:\WINDOWS\System32\Drivers\wwussf64.sys [30248 2010-02-23] (Ericsson AB -> Ericsson AB)
R1 ESProtectionDriver; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [158640 2024-01-09] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2022-06-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 GeneStor; C:\WINDOWS\System32\drivers\GeneStor.sys [159496 2026-04-25] (GENESYS LOGIC, INC. -> Genesys Logic)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2022-06-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82968 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S3 l36wgps; C:\WINDOWS\System32\drivers\l36wgps64.sys [101416 2011-02-28] (Ericsson AB -> Ericsson AB)
S3 Mbm3CBus; C:\WINDOWS\System32\drivers\Mbm3CBus.sys [419400 2011-04-13] (MCCI Corporation -> MCCI Corporation)
S3 Mbm3DevMt; C:\WINDOWS\System32\drivers\Mbm3DevMt.sys [430664 2011-04-13] (MCCI Corporation -> MCCI Corporation)
R0 PMDRVS; C:\WINDOWS\System32\drivers\pmdrvs.sys [38160 2019-12-11] (Lenovo -> Lenovo.)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 Tp4Track; C:\WINDOWS\System32\drivers\tp4track.sys [29992 2011-11-01] (Lenovo (Japan) Ltd. -> Lenovo Group Limited)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [51224 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21632 2026-10-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [669712 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [163048 2022-07-24] (MEDIATEK INC. -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [138264 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S2 mbamchameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys (No File)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 09:05 - 2026-10-08 09:05 - 000003326 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2026-10-08 09:05 - 2026-10-08 09:05 - 000000670 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2026-10-05 19:25 - 2026-10-05 19:25 - 000041544 _____ (ELAN Microelectronic Corp.) C:\WINDOWS\system32\Drivers\ETDSMBus.sys
2026-10-05 10:43 - 2026-10-05 10:43 - 000333141 _____ C:\Users\sadro\Downloads\cestne-prohlaseni-dite Adela.pdf
2026-10-05 10:37 - 2026-10-05 10:37 - 000043154 _____ C:\Users\sadro\Downloads\cestne-prohlaseni-dite.pdf
2026-10-05 10:11 - 2026-10-05 10:11 - 000391920 _____ C:\Users\sadro\Downloads\adela prohlaseni.pdf
2026-10-05 09:59 - 2026-10-05 09:59 - 000099686 _____ C:\Users\sadro\Downloads\180120_estne-prohlaseni-sleva-na-dite-vzor-cz-a-en.pdf
2026-10-05 09:58 - 2026-10-05 09:58 - 000001380 _____ C:\Users\sadro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 12:37 - 2022-12-04 20:05 - 000000000 ___RD C:\Users\sadro\OneDrive\Plocha\Čištení
2026-10-08 12:35 - 2025-02-20 06:43 - 000000000 ____D C:\FRST
2026-10-08 12:28 - 2023-06-07 09:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-10-08 11:34 - 2024-10-15 19:36 - 000000000 ____D C:\Users\sadro\AppData\Local\Programs\Opera
2026-10-08 11:25 - 2023-06-14 12:26 - 000000000 ____D C:\Users\sadro\AppData\Local\D3DSCache
2026-10-08 10:50 - 2023-06-07 11:32 - 000003714 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{98687D48-9E16-45DA-B4EE-CB04A689F559}
2026-10-08 10:50 - 2023-06-07 11:32 - 000003642 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{A97436AD-3E62-4163-9B81-28EEEFBEF18B}
2026-10-08 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-10-08 10:48 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-10-08 10:48 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-10-08 10:34 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2026-10-08 07:33 - 2023-06-07 09:53 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-10-07 16:04 - 2023-06-07 10:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-10-07 13:43 - 2022-12-03 12:08 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-10-05 19:32 - 2023-06-07 10:26 - 000858306 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-10-05 19:32 - 2019-12-07 16:41 - 000718024 _____ C:\WINDOWS\system32\perfh005.dat
2026-10-05 19:32 - 2019-12-07 16:41 - 000145166 _____ C:\WINDOWS\system32\perfc005.dat
2026-10-05 19:28 - 2023-06-07 10:27 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-10-05 19:27 - 2025-01-12 05:18 - 000008192 ___SH C:\DumpStack.log.tmp
2026-10-05 19:27 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-10-05 19:26 - 2023-06-07 10:01 - 000000000 ____D C:\Users\sadro
2026-10-05 19:21 - 2025-10-08 10:49 - 000002312 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - sadro
2026-10-05 19:20 - 2024-12-05 04:55 - 000000000 ____D C:\Users\sadro\AppData\Roaming\Telegram Desktop
2026-10-05 19:20 - 2024-11-10 05:33 - 000000000 ____D C:\Users\sadro\AppData\Roaming\uTorrent
2026-10-05 19:17 - 2025-10-08 10:49 - 000000000 ____D C:\Program Files\CCleaner
2026-10-05 18:58 - 2022-12-04 19:59 - 000000000 ___RD C:\Users\sadro\OneDrive\Plocha\Filmy
2026-10-05 18:57 - 2022-12-04 19:59 - 000000000 ____D C:\Users\sadro\OneDrive\Plocha\Torrent
2026-09-29 14:14 - 2023-06-07 11:34 - 000000000 ____D C:\Users\sadro\AppData\Local\Packages
2026-09-28 08:53 - 2023-06-07 11:35 - 000000000 ____D C:\ProgramData\Packages
2026-09-28 08:52 - 2023-06-07 11:40 - 000000000 ____D C:\Users\sadro\AppData\Local\PlaceholderTileLogoFolder
2026-09-27 09:14 - 2024-11-10 17:00 - 000000000 ____D C:\Users\sadro\AppData\Roaming\vlc
2026-09-15 01:07 - 2023-06-07 09:30 - 000322880 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-09-15 01:01 - 2024-08-04 10:38 - 000000000 ____D C:\WINDOWS\system32\compatrel
2026-09-15 01:01 - 2019-12-07 16:42 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\PerfLogs
2026-09-15 01:01 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2026-09-15 00:31 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-09-14 23:39 - 2023-06-07 09:49 - 003017728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-09-11 07:52 - 2023-06-13 22:12 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-09-11 07:41 - 2023-06-13 22:11 - 230964456 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2025-10-08 10:48 - 2025-10-08 10:48 - 084074272 _____ (Gen Digital Inc.) C:\Users\sadro\AppData\Roaming\ccsetup638_pro.exe
2025-07-29 19:52 - 2025-07-29 20:31 - 000080333 _____ () C:\Users\sadro\AppData\Local\dxdiag.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-10-2026
Ran by sadro (administrator) on DESKTOP-4E77SLT (LENOVO 6475AG9) (08-10-2026 12:33:41)
Running from C:\Users\sadro\OneDrive\Plocha\Čištení\FRST64.exe
Loaded Profiles: sadro
Platform: Microsoft Windows 10 Home Version 22H2 19045.7725 (X64) Language: Čeština (Česko)
Default browser: "C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\DefenderAiPlatformHost.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\DefenderSessionHelper.exe
(C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\sadro\AppData\Local\Programs\Opera\136.0.6008.80\opera_crashreporter.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe
(Opera Norway AS -> Opera Software) C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe <14>
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\NisSrv.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.7714_none_7dea5cb47ca89937\TiWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [TrackPointSrv] => C:\Program Files\Lenovo\TrackPoint\tp4serv.exe [138784 2011-11-01] (Lenovo (Japan) Ltd. -> Lenovo Group Limited)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2539320 2024-01-09] (Malwarebytes Inc. -> Malwarebytes Corporation)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Run: [ut] => C:\Users\sadro\AppData\Roaming\uTorrent\uTorrent.exe [2071560 2025-08-14] (BitTorrent Inc -> BitTorrent Limited)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [46775800 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Run: [MicrosoftEdgeAutoLaunch_2F877205FC610259C551AA55F379B2D4] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5403976 2026-10-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {84f22e1e-039d-11f0-af6d-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {84f23ec3-039d-11f0-af6d-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {d7530b63-3f8c-11f0-af75-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Windows\System32\osk.exe [684544 2026-08-13] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\PDF-XChange5-ABBYY-FR15: C:\WINDOWS\system32\pxc50pmaf15.dll [57328 2018-12-04] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\147.0.7727.138\Installer\chrmstp.exe [7428248 2026-05-01] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {6BDBB040-4E5E-4835-B1CE-E30B01793D82} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {BD6013EE-B70A-433C-8BAA-F1B2DF3D5D1A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9624CC7B-E024-4253-95A4-633BDAB7A770} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6140920 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "bb0d7bde-416d-4286-b352-424eb73e6649" --version "6.41.0.11567" --silent
Task: {BD9136EF-67D2-4416-BBF9-441262B15920} - System32\Tasks\CCleanerSkipUAC - sadro => C:\Program Files\CCleaner\CCleaner.exe [39839224 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {827FEEBC-04C8-4DAC-865A-5A829EF98D11} - System32\Tasks\Driver Booster SkipUAC (sadro) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [8946688 2023-06-09] (IObit) [File not signed] <==== ATTENTION
Task: {C5FE9906-B104-44A5-BEE3-0984AF674071} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{0882C11F-A16E-46F7-B6D9-C7F305DB9A93} => C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe [7056536 2025-11-26] (Google LLC -> Google LLC)
Task: {B5D9926D-E6BD-424D-BFC9-1F457F98639E} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{15BFC5EE-74CD-49F3-81A8-BF07DC61B75E} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [6517400 2026-04-15] (Google LLC -> Google LLC)
Task: {C5022AF4-9706-412A-B55E-E8AB5AE63881} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => C:\WINDOWS\system32\sc.exe [72192 2019-12-07] (Microsoft Windows -> Microsoft Corporation) -> start LenovoVantageService
Task: {30F95CC3-079E-4452-AD72-048ADA5676D9} - System32\Tasks\Lenovo\Vantage\Schedule\BatteryGaugeAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {ECAB5733-C40D-4B95-909A-C233E7D2EE50} - System32\Tasks\Lenovo\Vantage\Schedule\DailyTelemetryTransmission => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {EC28FE73-70A9-4FCA-A91B-E29FDE4E524C} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {285E97C1-AD05-46C9-BBFA-BFF1BD54BCB8} - System32\Tasks\Lenovo\Vantage\Schedule\HeartbeatAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {4132853B-99B9-4F06-83C4-0F36F7CD2468} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {5ABFD021-A741-4D36-BDF1-4112E7079540} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoBatteryPartSalesMonthlyToast => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {7CEF24CF-BE5C-432D-80BD-E70545AB122F} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {9C800CB1-5F0C-4B7E-A1B4-55953965F22E} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {100522FD-579C-4BA5-854A-BC376D1A342B} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {FCA466FD-1A63-4418-86A7-4F83544407EB} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinIdleScheduleTask => C:\ProgramData\Lenovo\Vantage\Addins\VantageCoreAddin\1.0.0.181\x64\IdleScheduleEventAction.exe [143768 2024-11-01] (Lenovo -> )
Task: {68674784-1D49-457E-B081-12EDCBB86A8E} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinWeekScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\ScheduleEventAction.exe [30056 2024-09-12] (Lenovo -> Lenovo)
Task: {D78BD745-32B3-4F82-95BD-24DC208A4159} - System32\Tasks\Lenovo\Vantage\StartupFixPlan => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\uninstall.exe [340968 2024-09-12] (Lenovo -> Lenovo)
Task: {05ABA0F5-C616-4C30-93C6-F671B5C84244} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B5ABD661-0049-4360-8907-9A3547BF5143} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FC373213-CA37-45BE-B6BB-71CCFA116C23} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {47D0D973-17DB-4796-88DF-D01A2741B5FE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpCmdRun.exe [1952424 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BC532278-CF10-441B-8FBF-D9570E1081B9} - System32\Tasks\Opera scheduled assistant Autoupdate 1729013942 => C:\Users\sadro\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [7762888 2026-09-29] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --installdir="C:\Users\sadro\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {C2566133-FE21-4233-8D4D-3D7DF89302E9} - System32\Tasks\Opera scheduled Autoupdate 1729013909 => C:\Users\sadro\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [7762888 2026-09-29] (Opera Norway AS -> Opera Software)
Task: {F17A929C-66D8-4975-921D-D873E9125C0D} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-978282830-4128747045-4181034530-1001 => {201600D8-6EFF-48CE-B842-E14D37A0682D} C:\WINDOWS\System32\wpninprc.dll [24064 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {BD0E2CD4-19A3-4D8D-8616-9E2A1B72E30B} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-978282830-4128747045-4181034530-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe /bg /scheduledHC (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{03ff6323-85d8-4241-9413-9622f5e73dc7}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{03ff6323-85d8-4241-9413-9622f5e73dc7}\255646D69602933402E46434: [DhcpNameServer] 192.168.43.1
FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-31] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-31] (VideoLAN -> VideoLAN)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\sadro\AppData\Local\Microsoft\Edge\User Data\Default [2026-10-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\sadro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-10]
Edge Extension: (Edge relevant text changes) - C:\Users\sadro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-11-20]
Chrome:
=======
CHR Profile: C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default [2026-10-05]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-07-22]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2025-07-22]
CHR Extension: (Dokumenty Google offline) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-07-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\sadro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-07-22]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKU\S-1-5-21-978282830-4128747045-4181034530-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1080824 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [236864 2022-06-24] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S4 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\LenovoVantageService.exe [34256 2024-09-12] (Lenovo -> Lenovo)
S3 LPlatSvc; C:\WINDOWS\System32\LPlatSvc.exe [892288 2019-12-11] (Lenovo -> Lenovo.)
S3 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [169344 2024-01-09] (Malwarebytes Inc. -> Malwarebytes Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MpDefenderCoreService.exe [2398680 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\NisSrv.exe [5555528 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26090.9-0\MsMpEng.exe [378168 2026-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 atmeltpm; C:\WINDOWS\System32\drivers\atmeltpm64.sys [19456 2011-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Atmel, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R3 CnxtHdAudService; C:\WINDOWS\system32\drivers\CHDRT64.sys [649216 2009-10-05] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems Inc.)
R3 cykbfltrService; C:\WINDOWS\System32\drivers\cykbfltr.sys [16896 2012-06-15] (Cypress Semiconductor -> Cypress Semiconductor, Inc.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-12-02] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-12-02] (Disc Soft Ltd -> Disc Soft Ltd)
S3 ecnssndis; C:\WINDOWS\System32\Drivers\wwuss64.sys [26664 2010-02-23] (Ericsson AB -> Ericsson AB)
S3 ecnssndisfltr; C:\WINDOWS\System32\Drivers\wwussf64.sys [30248 2010-02-23] (Ericsson AB -> Ericsson AB)
R1 ESProtectionDriver; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [158640 2024-01-09] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2022-06-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 GeneStor; C:\WINDOWS\System32\drivers\GeneStor.sys [159496 2026-04-25] (GENESYS LOGIC, INC. -> Genesys Logic)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2022-06-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82968 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S3 l36wgps; C:\WINDOWS\System32\drivers\l36wgps64.sys [101416 2011-02-28] (Ericsson AB -> Ericsson AB)
S3 Mbm3CBus; C:\WINDOWS\System32\drivers\Mbm3CBus.sys [419400 2011-04-13] (MCCI Corporation -> MCCI Corporation)
S3 Mbm3DevMt; C:\WINDOWS\System32\drivers\Mbm3DevMt.sys [430664 2011-04-13] (MCCI Corporation -> MCCI Corporation)
R0 PMDRVS; C:\WINDOWS\System32\drivers\pmdrvs.sys [38160 2019-12-11] (Lenovo -> Lenovo.)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 Tp4Track; C:\WINDOWS\System32\drivers\tp4track.sys [29992 2011-11-01] (Lenovo (Japan) Ltd. -> Lenovo Group Limited)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [51224 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21632 2026-10-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [669712 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [163048 2022-07-24] (MEDIATEK INC. -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [138264 2026-10-07] (Microsoft Windows -> Microsoft Corporation)
S2 mbamchameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys (No File)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 09:05 - 2026-10-08 09:05 - 000003326 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2026-10-08 09:05 - 2026-10-08 09:05 - 000000670 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2026-10-05 19:25 - 2026-10-05 19:25 - 000041544 _____ (ELAN Microelectronic Corp.) C:\WINDOWS\system32\Drivers\ETDSMBus.sys
2026-10-05 10:43 - 2026-10-05 10:43 - 000333141 _____ C:\Users\sadro\Downloads\cestne-prohlaseni-dite Adela.pdf
2026-10-05 10:37 - 2026-10-05 10:37 - 000043154 _____ C:\Users\sadro\Downloads\cestne-prohlaseni-dite.pdf
2026-10-05 10:11 - 2026-10-05 10:11 - 000391920 _____ C:\Users\sadro\Downloads\adela prohlaseni.pdf
2026-10-05 09:59 - 2026-10-05 09:59 - 000099686 _____ C:\Users\sadro\Downloads\180120_estne-prohlaseni-sleva-na-dite-vzor-cz-a-en.pdf
2026-10-05 09:58 - 2026-10-05 09:58 - 000001380 _____ C:\Users\sadro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 12:37 - 2022-12-04 20:05 - 000000000 ___RD C:\Users\sadro\OneDrive\Plocha\Čištení
2026-10-08 12:35 - 2025-02-20 06:43 - 000000000 ____D C:\FRST
2026-10-08 12:28 - 2023-06-07 09:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-10-08 11:34 - 2024-10-15 19:36 - 000000000 ____D C:\Users\sadro\AppData\Local\Programs\Opera
2026-10-08 11:25 - 2023-06-14 12:26 - 000000000 ____D C:\Users\sadro\AppData\Local\D3DSCache
2026-10-08 10:50 - 2023-06-07 11:32 - 000003714 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{98687D48-9E16-45DA-B4EE-CB04A689F559}
2026-10-08 10:50 - 2023-06-07 11:32 - 000003642 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{A97436AD-3E62-4163-9B81-28EEEFBEF18B}
2026-10-08 10:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-10-08 10:48 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-10-08 10:48 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-10-08 10:34 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2026-10-08 07:33 - 2023-06-07 09:53 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-10-07 16:04 - 2023-06-07 10:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-10-07 13:43 - 2022-12-03 12:08 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-10-05 19:32 - 2023-06-07 10:26 - 000858306 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-10-05 19:32 - 2019-12-07 16:41 - 000718024 _____ C:\WINDOWS\system32\perfh005.dat
2026-10-05 19:32 - 2019-12-07 16:41 - 000145166 _____ C:\WINDOWS\system32\perfc005.dat
2026-10-05 19:28 - 2023-06-07 10:27 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-10-05 19:27 - 2025-01-12 05:18 - 000008192 ___SH C:\DumpStack.log.tmp
2026-10-05 19:27 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-10-05 19:26 - 2023-06-07 10:01 - 000000000 ____D C:\Users\sadro
2026-10-05 19:21 - 2025-10-08 10:49 - 000002312 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - sadro
2026-10-05 19:20 - 2024-12-05 04:55 - 000000000 ____D C:\Users\sadro\AppData\Roaming\Telegram Desktop
2026-10-05 19:20 - 2024-11-10 05:33 - 000000000 ____D C:\Users\sadro\AppData\Roaming\uTorrent
2026-10-05 19:17 - 2025-10-08 10:49 - 000000000 ____D C:\Program Files\CCleaner
2026-10-05 18:58 - 2022-12-04 19:59 - 000000000 ___RD C:\Users\sadro\OneDrive\Plocha\Filmy
2026-10-05 18:57 - 2022-12-04 19:59 - 000000000 ____D C:\Users\sadro\OneDrive\Plocha\Torrent
2026-09-29 14:14 - 2023-06-07 11:34 - 000000000 ____D C:\Users\sadro\AppData\Local\Packages
2026-09-28 08:53 - 2023-06-07 11:35 - 000000000 ____D C:\ProgramData\Packages
2026-09-28 08:52 - 2023-06-07 11:40 - 000000000 ____D C:\Users\sadro\AppData\Local\PlaceholderTileLogoFolder
2026-09-27 09:14 - 2024-11-10 17:00 - 000000000 ____D C:\Users\sadro\AppData\Roaming\vlc
2026-09-15 01:07 - 2023-06-07 09:30 - 000322880 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-09-15 01:01 - 2024-08-04 10:38 - 000000000 ____D C:\WINDOWS\system32\compatrel
2026-09-15 01:01 - 2019-12-07 16:42 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-09-15 01:01 - 2019-12-07 11:14 - 000000000 ____D C:\PerfLogs
2026-09-15 01:01 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2026-09-15 00:31 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-09-14 23:39 - 2023-06-07 09:49 - 003017728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-09-11 07:52 - 2023-06-13 22:12 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-09-11 07:41 - 2023-06-13 22:11 - 230964456 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2025-10-08 10:48 - 2025-10-08 10:48 - 084074272 _____ (Gen Digital Inc.) C:\Users\sadro\AppData\Roaming\ccsetup638_pro.exe
2025-07-29 19:52 - 2025-07-29 20:31 - 000080333 _____ () C:\Users\sadro\AppData\Local\dxdiag.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Prosím o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin

- Příspěvky: 120150
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu
Zdravím!
Abych mohl provést kompletní kontrolu, potřebuji ještě vidět log Addition. Najudete ho v souboru addition.txt v C:\Users\sadro\OneDrive\Plocha\Čištení . Děkuji.
Abych mohl provést kompletní kontrolu, potřebuji ještě vidět log Addition. Najudete ho v souboru addition.txt v C:\Users\sadro\OneDrive\Plocha\Čištení . Děkuji.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
zdenek72
- 3. Stupeň Varování
- Příspěvky: 109
- Registrován: 09 Ún 2010 15:18
- Místo/Bydliště: Plzen, Czech Republic
- Kontaktovat uživatele:
Re: Prosím o kontrolu
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-10-2026
Ran by sadro (08-10-2026 12:41:15)
Running from C:\Users\sadro\OneDrive\Plocha\Čištení
Microsoft Windows 10 Home Version 22H2 19045.7725 (X64) (2023-06-07 08:51:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-978282830-4128747045-4181034530-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-978282830-4128747045-4181034530-503 - Limited - Disabled)
Guest (S-1-5-21-978282830-4128747045-4181034530-501 - Limited - Disabled)
sadro (S-1-5-21-978282830-4128747045-4181034530-1001 - Administrators - Enabled) => C:\Users\sadro
WDAGUtilityAccount (S-1-5-21-978282830-4128747045-4181034530-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\uTorrent) (Version: 3.6.0.47178 - BitTorrent Limited)
ABBYY FineReader PDF 15 (HKLM\...\{F15000FE-0001-6400-0000-074957833700}) (Version: 15.0.3887 - ABBYY Production LLC)
AdmWin 3.50 (HKLM-x32\...\AdmWin_is1) (Version: - AdmWin)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 6.41 - Piriform)
Conexant 20561 SmartAudio HD (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.92.12.0 - Conexant)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 154.0.4258.62 - Microsoft Corporation)
CrystalDiskInfo 8.8.5 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.8.5 - Crystal Dew World)
FastStone Image Viewer 8.1 (HKLM-x32\...\FastStone Image Viewer) (Version: 8.1 - FastStone Corporation)
Google Chrome (HKLM\...\{D1528E30-D992-3AB9-8128-7DC535E41601}) (Version: 147.0.7727.138 - Google LLC)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 11.0.0.650 - Huawei Technologies Co., Ltd.)
IObit Driver Booster 10.5.0.139 (HKLM-x32\...\IObit Driver Booster_is1) (Version: 10.5.0.139 - LR)
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 4.2.24.0 - Lenovo Group Ltd.)
Malwarebytes Anti-Exploit version 1.13.1.585 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.13.1.585 - Malwarebytes)
MediaHuman YouTube Downloader 3.9.16 (HKLM-x32\...\MediaHuman YouTube Downloader_is1) (Version: 3.9.16 - MediaHuman)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 154.0.4258.62 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.62 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\OneDriveSetup.exe) (Version: 26.113.0614.0004 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenOffice 4.1.16 (HKLM-x32\...\{99DC5A6B-0EF2-4D81-9EAC-35AC6F1E8DB2}) (Version: 4.116.9816 - Apache Software Foundation)
Opera Stable 124.0.5705.42 (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Opera 124.0.5705.42) (Version: 124.0.5705.42 - Opera Software)
Opera Stable 136.0.6008.80 (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Opera 136.0.6008.80) (Version: 136.0.6008.80 - Opera Software)
PDFgear 2.1.16 (HKLM\...\{7DACF63A-4EE4-4837-9AF9-C65D4509FFB4}_is1) (Version: 2.1.16 - PDFgear)
PROFIT 2026.04 (HKLM-x32\...\{670A9A20-E29D-40C3-9937-2AFF89C3AC82}_is1) (Version: - LPsoft)
Revo Uninstaller Pro 5.3.0 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.3.0 - VS Revo Group, Ltd.)
Telegram Desktop (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 6.7.6 - Telegram FZ-LLC)
ThinkPad Modem Adapter (HKLM\...\CNXT_MODEM_HDA_HSF) (Version: 7.80.8.50 - Conexant Systems)
ThinkPad TrackPoint Driver (HKLM\...\TrackPoint) (Version: 4.73.1.0 - Lenovo)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
WinRAR 7.13 (64-bit) (HKLM\...\WinRAR archiver) (Version: 7.13.0 - win.rar GmbH)
Packages:
=========
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2606.12.0_x64__k1h2ywk1493x8 [2026-08-09] (LENOVO INC.)
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2638.102.0_x64__cv1g1gvanyjgm [2026-10-01] (WhatsApp Inc.) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-978282830-4128747045-4181034530-1001_Classes\CLSID\{AF8998A0-AD09-7A81-67AE-4164797544C4}\InprocServer32 -> C:\Program Files (x86)\Common Files\System\ole32.dll => No File
ContextMenuHandlers1: [FineReader15ContextMenu] -> [CC]{53339754-4DD1-438B-8D24-0D0730F1A591} => -> No File
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [FineReader15ContextMenu] -> [CC]{53339754-4DD1-438B-8D24-0D0730F1A591} => -> No File
ContextMenuHandlers6: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2025-02-21 11:14 - 2025-10-08 10:53 - 000000890 __RSH C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 alpha-crap.ff.avast.com
127.0.0.1 analytics.ff.avast.com
127.0.0.1 license.piriform.com
127.0.0.1 ncc.avast.com
127.0.0.1 ncc.avast.com.edgesuite.net
127.0.0.1 shepherd.ff.avast.com
127.0.0.1 www.ccleaner.com
127.0.0.1 www.license.piriform.com
127.0.0.1 speccy.piriform.com
127.0.0.1 recuva.piriform.com
127.0.0.1 www.recuva.piriform.com
127.0.0.1 defraggler.piriform.com
127.0.0.1 www.defraggler.piriform.com
127.0.0.1 ccleaner.piriform.com
127.0.0.1 www.ccleaner.piriform.com
127.0.0.1 license-api.ccleaner.com
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Intel(R) 82567LM Gigabit Network Connection -> e1y62x64.sys
Wi-Fi: Intel(R) WiFi Link 5100 AGN -> NETwNs64.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "TrackPointSrv"
HKLM\...\StartupApproved\Run32: => "TrackPointSrv"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "Malwarebytes Anti-Exploit"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "ut"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_2F877205FC610259C551AA55F379B2D4"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Delete Cached Update Binary"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "RMDIR"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Uninstall 23.199.0924.0001"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Delete Cached Standalone Update Binary"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Uninstall 25.005.0112.0003"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Uninstall 26.088.0510.0004"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{E1E09391-DE3A-4BEE-BB02-084F544328BC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{272C5339-1F12-414F-94A9-B7264FD2AD5A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{51BEE53C-3CE9-49C9-88A8-3D209CBC3DFA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{86EB1890-F9AE-4130-940C-ECE3DD2F37B1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C0A43161-28EC-4678-A6B1-CD262144D86E}] => (Allow) C:\Users\sadro\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{69E2A26B-2019-422C-BA0D-F37CA31554BD}] => (Allow) C:\Users\sadro\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{4593587C-3363-4970-87CF-6AFB87807738}] => (Block) C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-FFFF-7760-BC15014EA700}\setup.exe => No File
FirewallRules: [{02B62D11-B2BC-44F0-AD4F-AC38ECF07B43}] => (Block) C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-FFFF-7760-BC15014EA700}\setup.exe => No File
FirewallRules: [{E975547B-617A-4D37-A8E3-B0AC3059183A}] => (Block) C:\Program Files (x86)\Common Files\Adobe\AdobeApplicationManager\AAMSetup\Set-up.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
FirewallRules: [{CBCB588C-B4F9-4B3D-BA12-44021E539A83}] => (Block) C:\Program Files (x86)\Common Files\Adobe\AdobeApplicationManager\AAMSetup\Set-up.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
FirewallRules: [{B3184661-5501-40A8-A900-BDA076091C20}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{94B3AEC8-1739-4225-BA63-EC8A5E0A2E0C}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{9DC5F9ED-7715-47EA-81F8-E3929DF03FCE}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{3D4DEC83-AB57-4650-9D2B-78B66B56CB0C}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{5589315B-E6B1-4013-9872-89096807EE82}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{2DA3A715-47DF-44C9-A86D-08F46A94C98F}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{8238C7F9-0820-41B9-ABC0-8219B07FD1AC}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{8F12EE3F-E096-4AD6-9ABB-358D8ABDC209}] => (Allow) C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{6B709E02-E570-444B-863B-55818BA0E182}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\copilotapp.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
14-09-2026 22:36:49 Instalační služba modulů systému Windows
25-09-2026 19:49:35 Naplánovaný kontrolní bod
05-10-2026 11:04:20 Naplánovaný kontrolní bod
05-10-2026 19:23:44 Driver Booster : ELAN SMBus Driver
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]
Error: (10/02/2026 06:17:18 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na (C:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
Error: (10/02/2026 05:50:48 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na System Reserved, protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
Error: (09/25/2026 07:49:15 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na (C:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
Error: (09/25/2026 07:16:10 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na System Reserved, protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
System errors:
=============
Error: (10/05/2026 07:28:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba mbamchameleon neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.
Error: (10/05/2026 07:27:51 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:50 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:50 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:49 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:49 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:48 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:48 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Windows Defender:
================
TimeCreated : 07.10.2026 6:23:38
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{AA9A1165-AF4D-4162-99AC-A0A567A645F6}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 03.10.2026 7:50:50
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{B31B5270-133E-4D95-9221-166FCEEF014D}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 02.10.2026 7:50:47
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{08B65947-5B28-491C-B86E-FC5535533030}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 01.10.2026 6:26:40
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{B685AD5B-A02C-4EE9-908D-8448736E6BD1}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 30.09.2026 7:50:42
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{974EE4F8-DFC7-4C7E-9C35-4D4768DF6888}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 28.09.2026 6:20:15
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{00E7E714-4E9A-4555-BDAE-7E9875F3AA42}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 27.09.2026 6:19:48
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{2A94D414-96B4-4A51-82EA-72F045B414F3}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 26.09.2026 6:19:48
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{C21DBCB6-B0A4-45E5-8989-AFF09B8FA00C}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
CodeIntegrity:
===============
Date: 2026-10-05 09:52:39
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2026-09-18 10:04:09
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\DefenderSessionHelper.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
BIOS: LENOVO 7UET48WW (1.18 ) 10/09/2008
Motherboard: LENOVO 6475AG9
Processor: Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz
Percentage of memory in use: 76%
Total physical RAM: 3992.02 MB
Available physical RAM: 955.58 MB
Total Virtual: 4696.02 MB
Available Virtual: 1422.18 MB
==================== Drives ================================
Disk 0 - Drive c: () (Fixed) (Total:147.79 GB) (Free:43.92 GB) (Model: WDC WD1600BEVS-08VAT2) NTFS
Disk 0 - \\?\Volume{db7274c8-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:350 MB) (Free:313.55 MB) NTFS
Disk 0 - \\?\Volume{db7274c8-0000-0000-0000-900825000000}\ () (Fixed) (Total:936 MB) (Free:162.56 MB) NTFS
==================== MBR & Partition Table ====================
============================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 149.05 GB) (Disk ID: DB7274C8)
Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0xDB7274C8
Partition 1
Type : MBR 0x07 (NTFS / exFAT / HPFS)
Size : 350 MB
Offset : 1 MB
Partition GUID : {DB7274C8-0000-0000-0000-100000000000}
Bootable : Yes
Recognized : Yes
Hidden Sectors : 2048
------------------------------------------------------------
Partition 2
Type : MBR 0x07 (NTFS / exFAT / HPFS)
Size : 147.79 GB
Offset : 351 MB
Partition GUID : {DB7274C8-0000-0000-0000-F01500000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 718848
------------------------------------------------------------
Partition 3
Type : MBR 0x27 (Windows Recovery)
Size : 936 MB
Offset : 151689 MB
Partition GUID : {DB7274C8-0000-0000-0000-900825000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 310659072
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 3
============================================================
==================== End of Addition.txt =======================
Ran by sadro (08-10-2026 12:41:15)
Running from C:\Users\sadro\OneDrive\Plocha\Čištení
Microsoft Windows 10 Home Version 22H2 19045.7725 (X64) (2023-06-07 08:51:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-978282830-4128747045-4181034530-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-978282830-4128747045-4181034530-503 - Limited - Disabled)
Guest (S-1-5-21-978282830-4128747045-4181034530-501 - Limited - Disabled)
sadro (S-1-5-21-978282830-4128747045-4181034530-1001 - Administrators - Enabled) => C:\Users\sadro
WDAGUtilityAccount (S-1-5-21-978282830-4128747045-4181034530-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\uTorrent) (Version: 3.6.0.47178 - BitTorrent Limited)
ABBYY FineReader PDF 15 (HKLM\...\{F15000FE-0001-6400-0000-074957833700}) (Version: 15.0.3887 - ABBYY Production LLC)
AdmWin 3.50 (HKLM-x32\...\AdmWin_is1) (Version: - AdmWin)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 6.41 - Piriform)
Conexant 20561 SmartAudio HD (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.92.12.0 - Conexant)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 154.0.4258.62 - Microsoft Corporation)
CrystalDiskInfo 8.8.5 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.8.5 - Crystal Dew World)
FastStone Image Viewer 8.1 (HKLM-x32\...\FastStone Image Viewer) (Version: 8.1 - FastStone Corporation)
Google Chrome (HKLM\...\{D1528E30-D992-3AB9-8128-7DC535E41601}) (Version: 147.0.7727.138 - Google LLC)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 11.0.0.650 - Huawei Technologies Co., Ltd.)
IObit Driver Booster 10.5.0.139 (HKLM-x32\...\IObit Driver Booster_is1) (Version: 10.5.0.139 - LR)
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 4.2.24.0 - Lenovo Group Ltd.)
Malwarebytes Anti-Exploit version 1.13.1.585 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.13.1.585 - Malwarebytes)
MediaHuman YouTube Downloader 3.9.16 (HKLM-x32\...\MediaHuman YouTube Downloader_is1) (Version: 3.9.16 - MediaHuman)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 154.0.4258.62 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.62 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\OneDriveSetup.exe) (Version: 26.113.0614.0004 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenOffice 4.1.16 (HKLM-x32\...\{99DC5A6B-0EF2-4D81-9EAC-35AC6F1E8DB2}) (Version: 4.116.9816 - Apache Software Foundation)
Opera Stable 124.0.5705.42 (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Opera 124.0.5705.42) (Version: 124.0.5705.42 - Opera Software)
Opera Stable 136.0.6008.80 (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\Opera 136.0.6008.80) (Version: 136.0.6008.80 - Opera Software)
PDFgear 2.1.16 (HKLM\...\{7DACF63A-4EE4-4837-9AF9-C65D4509FFB4}_is1) (Version: 2.1.16 - PDFgear)
PROFIT 2026.04 (HKLM-x32\...\{670A9A20-E29D-40C3-9937-2AFF89C3AC82}_is1) (Version: - LPsoft)
Revo Uninstaller Pro 5.3.0 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.3.0 - VS Revo Group, Ltd.)
Telegram Desktop (HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 6.7.6 - Telegram FZ-LLC)
ThinkPad Modem Adapter (HKLM\...\CNXT_MODEM_HDA_HSF) (Version: 7.80.8.50 - Conexant Systems)
ThinkPad TrackPoint Driver (HKLM\...\TrackPoint) (Version: 4.73.1.0 - Lenovo)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
WinRAR 7.13 (64-bit) (HKLM\...\WinRAR archiver) (Version: 7.13.0 - win.rar GmbH)
Packages:
=========
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2606.12.0_x64__k1h2ywk1493x8 [2026-08-09] (LENOVO INC.)
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2638.102.0_x64__cv1g1gvanyjgm [2026-10-01] (WhatsApp Inc.) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-978282830-4128747045-4181034530-1001_Classes\CLSID\{AF8998A0-AD09-7A81-67AE-4164797544C4}\InprocServer32 -> C:\Program Files (x86)\Common Files\System\ole32.dll => No File
ContextMenuHandlers1: [FineReader15ContextMenu] -> [CC]{53339754-4DD1-438B-8D24-0D0730F1A591} => -> No File
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [FineReader15ContextMenu] -> [CC]{53339754-4DD1-438B-8D24-0D0730F1A591} => -> No File
ContextMenuHandlers6: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2025-02-21 11:14 - 2025-10-08 10:53 - 000000890 __RSH C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 alpha-crap.ff.avast.com
127.0.0.1 analytics.ff.avast.com
127.0.0.1 license.piriform.com
127.0.0.1 ncc.avast.com
127.0.0.1 ncc.avast.com.edgesuite.net
127.0.0.1 shepherd.ff.avast.com
127.0.0.1 www.ccleaner.com
127.0.0.1 www.license.piriform.com
127.0.0.1 speccy.piriform.com
127.0.0.1 recuva.piriform.com
127.0.0.1 www.recuva.piriform.com
127.0.0.1 defraggler.piriform.com
127.0.0.1 www.defraggler.piriform.com
127.0.0.1 ccleaner.piriform.com
127.0.0.1 www.ccleaner.piriform.com
127.0.0.1 license-api.ccleaner.com
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Intel(R) 82567LM Gigabit Network Connection -> e1y62x64.sys
Wi-Fi: Intel(R) WiFi Link 5100 AGN -> NETwNs64.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "TrackPointSrv"
HKLM\...\StartupApproved\Run32: => "TrackPointSrv"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "Malwarebytes Anti-Exploit"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "ut"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_2F877205FC610259C551AA55F379B2D4"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Delete Cached Update Binary"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "RMDIR"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Uninstall 23.199.0924.0001"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Delete Cached Standalone Update Binary"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Uninstall 25.005.0112.0003"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\StartupApproved\Run: => "Uninstall 26.088.0510.0004"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{E1E09391-DE3A-4BEE-BB02-084F544328BC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{272C5339-1F12-414F-94A9-B7264FD2AD5A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{51BEE53C-3CE9-49C9-88A8-3D209CBC3DFA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{86EB1890-F9AE-4130-940C-ECE3DD2F37B1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C0A43161-28EC-4678-A6B1-CD262144D86E}] => (Allow) C:\Users\sadro\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{69E2A26B-2019-422C-BA0D-F37CA31554BD}] => (Allow) C:\Users\sadro\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{4593587C-3363-4970-87CF-6AFB87807738}] => (Block) C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-FFFF-7760-BC15014EA700}\setup.exe => No File
FirewallRules: [{02B62D11-B2BC-44F0-AD4F-AC38ECF07B43}] => (Block) C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-FFFF-7760-BC15014EA700}\setup.exe => No File
FirewallRules: [{E975547B-617A-4D37-A8E3-B0AC3059183A}] => (Block) C:\Program Files (x86)\Common Files\Adobe\AdobeApplicationManager\AAMSetup\Set-up.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
FirewallRules: [{CBCB588C-B4F9-4B3D-BA12-44021E539A83}] => (Block) C:\Program Files (x86)\Common Files\Adobe\AdobeApplicationManager\AAMSetup\Set-up.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
FirewallRules: [{B3184661-5501-40A8-A900-BDA076091C20}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{94B3AEC8-1739-4225-BA63-EC8A5E0A2E0C}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{9DC5F9ED-7715-47EA-81F8-E3929DF03FCE}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{3D4DEC83-AB57-4650-9D2B-78B66B56CB0C}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{5589315B-E6B1-4013-9872-89096807EE82}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{2DA3A715-47DF-44C9-A86D-08F46A94C98F}] => (Block) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Inc.)
FirewallRules: [{8238C7F9-0820-41B9-ABC0-8219B07FD1AC}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{8F12EE3F-E096-4AD6-9ABB-358D8ABDC209}] => (Allow) C:\Users\sadro\AppData\Local\Programs\Opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{6B709E02-E570-444B-863B-55818BA0E182}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\copilotapp.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
14-09-2026 22:36:49 Instalační služba modulů systému Windows
25-09-2026 19:49:35 Naplánovaný kontrolní bod
05-10-2026 11:04:20 Naplánovaný kontrolní bod
05-10-2026 19:23:44 Driver Booster : ELAN SMBus Driver
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..
Error: (10/05/2026 07:26:32 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]
Error: (10/02/2026 06:17:18 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na (C:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
Error: (10/02/2026 05:50:48 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na System Reserved, protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
Error: (09/25/2026 07:49:15 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na (C:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
Error: (09/25/2026 07:16:10 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na System Reserved, protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)
System errors:
=============
Error: (10/05/2026 07:28:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba mbamchameleon neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.
Error: (10/05/2026 07:27:51 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:50 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:50 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:49 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:49 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:48 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Error: (10/05/2026 07:27:48 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: V hardwaru čipu TPM (Trusted Platform Module) došlo k neobnovitelné chybě ovladače zařízení, která brání používání služeb TPM (například šifrování dat). Budete-li potřebovat další pomoc, obraťte se na výrobce počítače.
Windows Defender:
================
TimeCreated : 07.10.2026 6:23:38
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{AA9A1165-AF4D-4162-99AC-A0A567A645F6}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 03.10.2026 7:50:50
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{B31B5270-133E-4D95-9221-166FCEEF014D}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 02.10.2026 7:50:47
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{08B65947-5B28-491C-B86E-FC5535533030}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 01.10.2026 6:26:40
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{B685AD5B-A02C-4EE9-908D-8448736E6BD1}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 30.09.2026 7:50:42
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{974EE4F8-DFC7-4C7E-9C35-4D4768DF6888}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 28.09.2026 6:20:15
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{00E7E714-4E9A-4555-BDAE-7E9875F3AA42}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 27.09.2026 6:19:48
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{2A94D414-96B4-4A51-82EA-72F045B414F3}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
TimeCreated : 26.09.2026 6:19:48
Message : Antivirová ochrana v programu Microsoft Defender şсάń нαš ъέĕŋ šŧōρρёď вέƒŏѓē ćθmφłěтïòń
.%и %τŞĉàη ĨĎ:%в{C21DBCB6-B0A4-45E5-8989-AFF09B8FA00C}%η %тŜĉаή Ţýрэ:%ьAntimalwarový pro
gram%ⁿ %ţŜĉâη Ρąŗªmεт℮řš:%вRychlé prohledávání%п %ţŬŝèŗ:%ъNT AUTHORITY\SYSTEM%π %тŞŧǿр
Яéãѕøи:%ьЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªšť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť
7 ðάýş
CodeIntegrity:
===============
Date: 2026-10-05 09:52:39
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2026-09-18 10:04:09
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\DefenderSessionHelper.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
BIOS: LENOVO 7UET48WW (1.18 ) 10/09/2008
Motherboard: LENOVO 6475AG9
Processor: Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz
Percentage of memory in use: 76%
Total physical RAM: 3992.02 MB
Available physical RAM: 955.58 MB
Total Virtual: 4696.02 MB
Available Virtual: 1422.18 MB
==================== Drives ================================
Disk 0 - Drive c: () (Fixed) (Total:147.79 GB) (Free:43.92 GB) (Model: WDC WD1600BEVS-08VAT2) NTFS
Disk 0 - \\?\Volume{db7274c8-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:350 MB) (Free:313.55 MB) NTFS
Disk 0 - \\?\Volume{db7274c8-0000-0000-0000-900825000000}\ () (Fixed) (Total:936 MB) (Free:162.56 MB) NTFS
==================== MBR & Partition Table ====================
============================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 149.05 GB) (Disk ID: DB7274C8)
Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0xDB7274C8
Partition 1
Type : MBR 0x07 (NTFS / exFAT / HPFS)
Size : 350 MB
Offset : 1 MB
Partition GUID : {DB7274C8-0000-0000-0000-100000000000}
Bootable : Yes
Recognized : Yes
Hidden Sectors : 2048
------------------------------------------------------------
Partition 2
Type : MBR 0x07 (NTFS / exFAT / HPFS)
Size : 147.79 GB
Offset : 351 MB
Partition GUID : {DB7274C8-0000-0000-0000-F01500000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 718848
------------------------------------------------------------
Partition 3
Type : MBR 0x27 (Windows Recovery)
Size : 936 MB
Offset : 151689 MB
Partition GUID : {DB7274C8-0000-0000-0000-900825000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 310659072
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 3
============================================================
==================== End of Addition.txt =======================
- Rudy
- Site Admin

- Příspěvky: 120150
- Registrován: 30 Říj 2003 13:42
- Místo/Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu
Otevřte poznámkový blok a zkopírujte do něj:
Uložte do C:\Users\sadro\OneDrive\Plocha\Čištení jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
CustomCLSID: HKU\S-1-5-21-978282830-4128747045-4181034530-1001_Classes\CLSID\{AF8998A0-AD09-7A81-67AE-4164797544C4}\InprocServer32 -> C:\Program Files (x86)\Common Files\System\ole32.dll => No File
ContextMenuHandlers1: [FineReader15ContextMenu] -> [CC]{53339754-4DD1-438B-8D24-0D0730F1A591} => -> No File
ContextMenuHandlers1: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers1: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [FineReader15ContextMenu] -> [CC]{53339754-4DD1-438B-8D24-0D0730F1A591} => -> No File
ContextMenuHandlers6: [WinRAR] -> [CC]{B41DB860-64E4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers6: [WinRAR32] -> [CC]{B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
FirewallRules: [{4593587C-3363-4970-87CF-6AFB87807738}] => (Block) C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-FFFF-7760-BC15014EA700}\setup.exe => No File
FirewallRules: [{02B62D11-B2BC-44F0-AD4F-AC38ECF07B43}] => (Block) C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-FFFF-7760-BC15014EA700}\setup.exe => No File
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {84f22e1e-039d-11f0-af6d-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {84f23ec3-039d-11f0-af6d-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-978282830-4128747045-4181034530-1001\...\MountPoints2: {d7530b63-3f8c-11f0-af75-0021869ffec9} - "E:\HiSuiteDownLoader.exe"
Task: {827FEEBC-04C8-4DAC-865A-5A829EF98D11} - System32\Tasks\Driver Booster SkipUAC (sadro) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [8946688 2023-06-09] (IObit) [File not signed] <==== ATTENTION
Task: {BD0E2CD4-19A3-4D8D-8616-9E2A1B72E30B} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-978282830-4128747045-4181034530-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe /bg /scheduledHC (No File)
S2 mbamchameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys (No File)
C:\DumpStack.log.tmp
EmptyTemp:
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Přispějete na provoz fóra?