Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
ed
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 14 led 2005 18:27

PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#1 Příspěvek od ed »

Ahoj,

prosím o kontrolu logu, zdali nemám v PC nějaké zpomalovače :-) Díky moc!

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-08-2025
Ran by admin (administrator) on DESKTOP-I28IM4U (20-08-2025 22:32:01)
Running from C:\Users\admin\Desktop\FRST64.exe
Loaded Profiles: admin
Platform: Microsoft Windows 10 Home Version 22H2 19045.6216 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Adobe Crash Processor.exe
(ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe <6>
(ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud Helper.exe
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.Service.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.UserSessionHelper.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Portrait Displays\Display Pilot\DisplayPilotService.exe ->) (Portrait Displays, Inc. -> Portrait Displays, Inc.) C:\Program Files\Portrait Displays\Display Pilot\CTHelper.exe
(C:\Program Files\WindowsApps\Microsoft.GamingServices_29.103.2001.0_x64__8wekyb3d8bbwe\gamingservices.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\xgamehelper.exe
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\dlls\wgc_renderer_host.exe <5>
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming.net Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wargamingerrormonitor.exe
(C:\Users\admin\AppData\Roaming\Seznam.cz\bin\szndesktop.exe ->) (Seznam.cz, a.s. -> ) C:\Users\admin\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <18>
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(explorer.exe ->) (Moonsworth, LLC -> Moonsworth LLC) C:\Users\admin\AppData\Local\Programs\Lunar Client\Lunar Client.exe <5>
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(explorer.exe ->) (Portrait Displays, Inc. -> Portrait Displays, Inc.) C:\Program Files\Portrait Displays\Display Pilot\DisplayPilot.exe
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E1YATIBXE.EXE
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wgc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.) C:\Program Files (x86)\ASUS\AsusCertService\1.2.36\AsusCertService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.03.12\atkexComSvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.Service.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Portrait Displays, Inc. -> Portrait Displays, Inc.) C:\Program Files\Portrait Displays\Display Pilot\DisplayPilotService.exe
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S11RPB.EXE
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(services.exe ->) (SeriousBit Srl -> SeriousBit) C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Service.exe
(services.exe ->) (Sophos BV -> Sophos B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(Seznam.cz, a.s. -> ) C:\Users\admin\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(svchost.exe ->) (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ) C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_6.2.11.0_x64__qmba6cd70vzyy\ArmouryCrate.exe
(svchost.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\WindowsApps\AdobeNotificationClient_6.0.0.1_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x64.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Compputer Inc.) C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2508.1001.27.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8838400 2016-06-07] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [9523624 2025-05-24] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [455968 2023-05-26] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Run: [DisplayPilot.exe] => C:\Program Files\Portrait Displays\Display Pilot\DisplayPilot.exe [5236544 2023-08-31] (Portrait Displays, Inc. -> Portrait Displays, Inc.)
HKLM\...\Run: [Display Pilot] => C:\Program Files\Portrait Displays\Display Pilot\DisplayPilot.exe [5236544 2023-08-31] (Portrait Displays, Inc. -> Portrait Displays, Inc.)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [11859680 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [133128 2025-05-27] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1069296 2018-03-27] (Seznam.cz, a.s. -> )
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2511784 2025-06-05] (Adobe Inc. -> Adobe Inc.)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [194112 2025-08-20] (Adobe Inc. -> Adobe Inc.)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [31190360 2021-09-29] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42073048 2025-07-15] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [NetBalancer] => C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Tray.exe [1919208 2023-02-08] (SeriousBit Srl -> SeriousBit)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [MicrosoftEdgeAutoLaunch_29EBC4579851B72EE312C449CF839B1A] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4117544 2025-08-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45741280 2025-07-18] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [Lunar Client] => C:\Users\admin\AppData\Local\Programs\Lunar Client\Lunar Client.exe [192024176 2025-08-17] (Moonsworth, LLC -> Moonsworth LLC)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2136016 2025-07-10] (Wargaming Group Limited -> Wargaming.net)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\admin\AppData\Roaming\Seznam.cz\szninstall.exe [1069296 2018-03-27] (Seznam.cz, a.s. -> )
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [109808 2018-03-27] (Seznam.cz, a.s. -> )
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4698720 2025-06-28] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E1YATIBXE.EXE [485736 2021-12-02] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 18\Program32\ZPSTRAY.EXE [680520 2017-01-09] (ZONER software, a.s. -> ZONER software)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\MountPoints2: {febef221-f2d8-11eb-ab01-a85e45536675} - "E:\HiSuiteDownLoader.exe"
HKLM\...\Windows x64\Print Processors\Canon MP980 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD9B.DLL [27648 2008-06-26] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP980 series: C:\WINDOWS\system32\CNMLM9B.DLL [279040 2008-06-26] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\EPSON L3560 Series 64MonitorBE: C:\WINDOWS\system32\E1YLMBBXE.DLL [237568 2021-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\WINDOWS\system32\enppmon.dll [3167256 2024-08-30] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\139.0.7258.129\Installer\chrmstp.exe [2025-08-19] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {E09DF36D-BA20-412F-8930-30C190C74A7F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {EE6B30F4-BB0C-41E7-9AFE-7F414A0902A2} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [9523624 2025-05-24] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {3D675532-8B8D-475A-8745-5395A0E0E105} - System32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [9838504 2025-05-24] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {5D5CD2A8-51A9-472A-B552-32E55023AE57} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [398688 2025-05-27] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {A3E58076-16AA-4469-A1C3-28E7A3DE6F40} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\TaskSchedulerTool_ArmourySocketServer.exe [120672 2025-05-27] (ASUSTeK COMPUTER INC. -> TODO: <公司名稱>)
Task: {D828E853-5BDB-497C-83C5-7EC5DE67FF0B} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2110000 2019-04-22] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {E6ACBABD-B51D-49EF-A495-E0A8C20BCBC0} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [253272 2025-07-21] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {231DD338-6947-4E0A-A78E-FE2D24F2159B} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [253272 2025-07-21] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {730E6F3B-CB82-4395-89BA-C3F9581A58E2} - System32\Tasks\ASUS\Ez Update => C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe [1509424 2019-07-18] (ASUSTeK Computer Inc. -> )
Task: {4323882C-0CE3-4323-8FFC-597F19BCEFB3} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\TaskSchedulerTool_asus_framework.exe [120664 2025-06-27] (ASUSTeK COMPUTER INC. -> TODO: <公司名稱>)
Task: {1735F037-028F-4AE9-A9F8-C0BFC97B064E} - System32\Tasks\ASUS\NoiseCancelingEngine => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe [1261928 2024-04-09] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {21FC4001-AA86-431E-AB08-5D3D476BAF5A} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {976FC833-75DB-4408-8F99-CF563852FAD6} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-07-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {995814D6-BD15-4D26-8BA6-F694342DCF42} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6140640 2025-07-18] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "ab94f503-8e42-49e5-9dec-3dcd410e6d75" --version "6.38.0.11537" --silent
Task: {60B0271A-B09B-4E69-B33E-DE395678CE93} - System32\Tasks\CCleanerSkipUAC - admin => C:\Program Files\CCleaner\CCleaner.exe [39575776 2025-07-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9D2ACF0D-DB0F-4D97-AC12-350E6AE85FFC} - System32\Tasks\EPSON L3560 Series Update {8AF816F6-7513-42B7-B4AA-8C41FA9C27B3} => C:\Windows\System32\spool\drivers\x64\3\E1YTSBXE.EXE [680440 2017-06-07] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {D034A8EC-DA74-4CCD-858E-31B0C66588B8} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [26968 2021-09-29] (Garmin International, Inc. -> )
Task: {2602FF4D-07F3-4180-8C82-27728EF5B5BE} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem141.0.7340.0{542A226C-6FEC-4673-B102-5EB67E5B102A} => C:\Program Files (x86)\Google\GoogleUpdater\141.0.7340.0\updater.exe [6813336 2025-08-06] (Google LLC -> Google LLC)
Task: {D6561256-A2B4-449A-8E0C-186787A38887} - System32\Tasks\Launch Adobe CCXProcess => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [194112 2025-08-20] (Adobe Inc. -> Adobe Inc.)
Task: {83BE996E-5780-4698-B901-85C7DDEDDC59} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D11BB94C-90D5-4AEC-AE32-CC8B9DA11190} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {07E3FDA7-0154-4DA5-BE97-C005EC69E123} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A89E7F16-5A90-4B63-B983-D9B31052BB1E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C0EB13D9-A27D-4226-BCFB-69A595804D43} - System32\Tasks\OneDrive Startup Task-S-1-5-21-502460867-2142398443-4065067644-1001 => C:\Users\admin\AppData\Local\Microsoft\OneDrive\25.140.0720.0001\OneDriveLauncher.exe [723816 2025-08-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {5F4899FA-3477-44D7-81A9-787E3A241AEE} - System32\Tasks\Opera scheduled assistant Autoupdate 1627586689 => C:\Users\admin\AppData\Local\Programs\Opera\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\admin\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {ECF9B003-985B-4DA0-AEEE-C1AEB81AE131} - System32\Tasks\Opera scheduled Autoupdate 1627586682 => C:\Users\admin\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {82F33472-B1EE-451B-B3CA-EF7D7EFA0ADF} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2398016 2025-07-21] (Overwolf Ltd -> Overwolf LTD) -> C:\Program Files (x86)\Overwolf\/RunningFrom Schedule

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\EPSON L3560 Series Update {8AF816F6-7513-42B7-B4AA-8C41FA9C27B3}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E1YTSBXE.EXE:/EXE:{8AF816F6-7513-42B7-B4AA-8C41FA9C27B3} /F:UpdateWORKGROUP\DESKTOP-I28IM4U$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.20
Tcpip\..\Interfaces\{842026ae-853e-40ec-a1d1-b4c1af9cfd6a}: [DhcpNameServer] 192.168.1.20

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default [2025-08-20]
Edge Notifications: Default -> hxxps://ct9v90500fes73b1b7j0.firewallon.co.in
Edge Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-08-05]
Edge Extension: (Edge relevant text changes) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]

FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-07-15] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2025-06-05] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.451.0 -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\dtplugin\npDeployJava1.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.451.0 -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\plugin2\npjp2.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2025-06-05] (Adobe Inc. -> Adobe Systems)

Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2025-08-19]
CHR Notifications: Default -> hxxps://meet.google.com; hxxps://www.mall.tv; hxxps://www.netflix.com
CHR Extension: (Seznam Doplněk – Email) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2025-04-19]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-08-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-08-05]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Seznam.cz) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2025-04-19]
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Guest Profile [2025-06-02]
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1 [2025-08-20]
CHR Notifications: Profile 1 -> hxxps://www.netflix.com
CHR Extension: (Seznam Doplněk – Email) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2025-04-19]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-08-20]
CHR Extension: (ChatGPT) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ejcfepkfckglbgocfkanmcdngdijcgld [2025-03-10]
CHR Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-07-15]
CHR Extension: (Docusign PKI) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hcclkhcbkkdkaedoogloknhdbkjjgdem [2025-03-14]
CHR Extension: (BizMachine Prospector Go) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdannaddgiklheglbfhoobggpdnhkdda [2024-08-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-02]
CHR Extension: (Seznam.cz) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2025-04-19]
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 2 [2025-08-20]
CHR Notifications: Profile 2 -> hxxps://aternos.org; hxxps://meet.google.com
CHR Extension: (Seznam Doplněk – Email) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2025-04-21]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-08-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-07-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-04]
CHR Extension: (Seznam.cz) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2025-04-21]
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 6 [2025-08-20]
CHR Extension: (Seznam Doplněk – Email) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2025-04-24]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-08-20]
CHR Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-08-05]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-02-11]
CHR Extension: (Seznam.cz) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2025-04-24]
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\System Profile [2025-08-20]
CHR HKU\S-1-5-21-502460867-2142398443-4065067644-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bgjpfhpjcgdppjbgnpnjllokbmcdllig]
CHR HKU\S-1-5-21-502460867-2142398443-4065067644-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-502460867-2142398443-4065067644-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olfeabkoenfaoljndfecamgilllcpiak]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

Opera:
=======
OPR Profile: C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable [2021-07-29]
OPR Extension: (Rich Hints Agent) - C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-07-29]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [944040 2025-06-05] (Adobe Inc. -> Adobe Inc.)
R2 ArmouryCrateService; C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.Service.exe [431144 2025-07-21] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.03.12\atkexComSvc.exe [908648 2025-03-13] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [253272 2025-07-21] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\1.2.36\AsusCertService.exe [485720 2025-04-17] (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [253272 2025-07-21] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S2 AsusROGLSLService; C:\Program Files (x86)\ASUS\AsusROGLSLService\AsusROGLSLService.exe [682840 2025-07-21] (ASUSTeK COMPUTER INC. -> ASUS)
R2 BQ2Service; C:\Program Files\Portrait Displays\Display Pilot\DisplayPilotService.exe [210752 2023-08-31] (Portrait Displays, Inc. -> Portrait Displays, Inc.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1080544 2025-07-18] (Gen Digital Inc. -> Gen Digital Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [1604112 2025-04-20] (Epic Games Inc. -> Epic Games, Inc.)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [206304 2022-10-21] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_11; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S11RPB.EXE [171096 2020-04-01] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [154920 2025-03-21] (Sophos BV -> Sophos B.V.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [13004248 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9591104 2025-08-05] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-01-14] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpDefenderCoreService.exe [2050952 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NetBalancerService; C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Service.exe [197864 2023-02-08] (SeriousBit Srl -> SeriousBit)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe [1275000 2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2398016 2025-07-21] (Overwolf Ltd -> Overwolf LTD)
R2 ROG Live Service; C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe [2347048 2025-06-24] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\NisSrv.exe [4517784 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MsMpEng.exe [282464 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [34112 2020-05-18] (ASUSTeK Computer Inc. -> )
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [33832 2020-05-18] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\WINDOWS\system32\drivers\AsIO3.sys [59936 2025-04-16] (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.)
S3 cpuz159; C:\WINDOWS\temp\cpuz159\cpuz159_x64.sys [44680 2025-07-21] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) <==== ATTENTION
R1 CTIAIO; C:\WINDOWS\system32\drivers\CtiAIo64.sys [34920 2025-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
S3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [55416 2024-12-01] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [332184 2025-08-07] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-06-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-03-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [242752 2025-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 nbdrv; C:\WINDOWS\system32\DRIVERS\nbdrv.sys [42128 2021-07-15] (SeriousBit Srl -> SeriousBit)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20888 2025-08-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [627120 2025-08-07] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [101792 2025-08-07] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-08-20 22:32 - 2025-08-20 22:32 - 000036442 _____ C:\Users\admin\Desktop\FRST.txt
2025-08-20 22:31 - 2025-08-20 22:32 - 000000000 ____D C:\FRST
2025-08-20 22:30 - 2025-08-20 22:30 - 002409472 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2025-08-18 18:31 - 2025-08-18 18:31 - 000023734 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-08-18 18:31 - 2025-08-18 18:31 - 000023734 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-08-16 17:58 - 2025-08-16 17:58 - 000001391 _____ C:\Users\admin\Desktop\Roblox Studio.lnk
2025-08-16 17:56 - 2025-08-20 09:25 - 000001391 _____ C:\Users\admin\Desktop\Roblox Player.lnk
2025-08-16 17:55 - 2025-08-20 10:38 - 000000000 ____D C:\Users\admin\AppData\Local\Roblox
2025-08-16 17:55 - 2025-08-20 09:25 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2025-08-16 17:55 - 2025-08-16 17:56 - 000000000 ____D C:\Users\admin\Desktop\Nová složka
2025-08-16 17:55 - 2025-08-16 17:55 - 007958992 _____ (Roblox Corporation) C:\Users\admin\Downloads\RobloxPlayerInstaller-DR7KX3HR6X.exe
2025-08-07 18:02 - 2025-08-07 18:02 - 000129326 _____ C:\Users\admin\Downloads\Lumíci.pdf
2025-08-07 11:36 - 2025-08-07 11:36 - 000047583 _____ C:\Users\admin\Downloads\rada-4.jfif
2025-08-07 11:35 - 2025-08-07 11:35 - 000112436 _____ C:\Users\admin\Downloads\iCjbXSHNjfVOKUs6OiuaqukjS7N.webp
2025-08-05 10:04 - 2025-08-05 10:06 - 000000000 ____D C:\Users\admin\Downloads\SPRAVNA PETKA jede taborit
2025-07-26 08:35 - 2025-07-26 08:35 - 000003526 _____ C:\Users\admin\Downloads\world.zip
2025-07-21 23:29 - 2025-07-21 23:38 - 000000000 ____D C:\Program Files (x86)\FanControl
2025-07-21 23:29 - 2025-07-21 23:29 - 000001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FanControl.lnk
2025-07-21 23:29 - 2025-07-21 23:29 - 000000000 ____D C:\Users\admin\AppData\Local\ToastNotificationManagerCompat
2025-07-21 23:28 - 2025-07-21 23:28 - 008715361 _____ (Remi Mercier Software Inc ) C:\Users\admin\Downloads\FanControl_228_net_4_8_Installer.exe
2025-07-21 23:11 - 2025-07-21 23:11 - 000000000 ____D C:\Program Files\Patriot
2025-07-21 23:11 - 2025-07-21 23:11 - 000000000 ____D C:\Program Files\ENE
2025-07-21 23:05 - 2025-08-20 11:48 - 000000000 ____D C:\Users\admin\AppData\Roaming\asus_framework
2025-07-21 23:02 - 2025-07-21 23:10 - 000000000 ____D C:\Users\admin\AppData\Local\AcSdkInsLog
2025-07-21 23:02 - 2025-07-21 23:02 - 000000000 ____D C:\Users\admin\AppData\Local\ASUS
2025-07-21 23:02 - 2025-07-21 23:02 - 000000000 ____D C:\Program Files\dotnet
2025-07-21 23:01 - 2025-07-21 23:25 - 000000000 ____D C:\Program Files\ASUS
2025-07-21 23:01 - 2025-04-17 15:01 - 000507232 _____ (Asustek Computer Inc.) C:\WINDOWS\system32\AsIO3.dll
2025-07-21 23:01 - 2025-04-17 15:01 - 000434008 _____ (Asustek Computer Inc.) C:\WINDOWS\SysWOW64\AsIO3.dll
2025-07-21 23:01 - 2025-04-17 00:21 - 000059936 _____ (Asustek Computer Inc.) C:\WINDOWS\system32\Drivers\AsIO3.sys
2025-07-21 23:01 - 2024-12-02 01:07 - 000055416 ____N (ASUSTeK Computer Inc.) C:\WINDOWS\system32\Drivers\IOMap64.sys
2025-07-21 22:57 - 2025-07-21 22:57 - 002165022 _____ C:\Users\admin\Downloads\ArmouryCrateInstallTool.zip
2025-07-21 22:57 - 2025-07-21 22:57 - 000000000 ____D C:\Users\admin\Downloads\ArmouryCrateInstallTool
2025-07-21 22:46 - 2025-07-21 22:46 - 000000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2025-07-21 22:46 - 2025-07-21 22:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2025-07-21 22:46 - 2025-07-21 22:46 - 000000000 ____D C:\Program Files\Speccy
2025-07-21 22:45 - 2025-07-21 22:45 - 018824928 _____ (Piriform Software Ltd) C:\Users\admin\Downloads\spsetup133.exe

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-08-20 22:32 - 2025-04-20 13:37 - 000000000 ____D C:\Program Files (x86)\Steam
2025-08-20 22:23 - 2024-11-19 18:20 - 000000000 ____D C:\Users\admin\AppData\Local\Malwarebytes
2025-08-20 22:07 - 2020-05-31 20:20 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2025-08-20 21:56 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-08-20 21:56 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2025-08-20 21:55 - 2021-12-16 07:57 - 000000000 ___HD C:\adobeTemp
2025-08-20 21:55 - 2020-05-31 20:17 - 000000000 ____D C:\Program Files\Adobe
2025-08-20 21:55 - 2020-05-18 21:17 - 000000000 ____D C:\Users\admin\AppData\Local\D3DSCache
2025-08-20 21:54 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-08-20 21:47 - 2025-07-04 08:46 - 000003326 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2025-08-20 21:47 - 2024-04-29 21:08 - 000000670 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2025-08-20 21:13 - 2021-02-27 21:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-08-20 11:53 - 2025-04-19 09:30 - 000000000 ____D C:\Users\admin\AppData\Roaming\Seznam.cz
2025-08-20 11:48 - 2024-11-05 18:18 - 000000000 ____D C:\Users\admin\AppData\Roaming\lunarclient
2025-08-20 11:48 - 2020-05-18 21:24 - 000000000 ____D C:\ProgramData\ASUS
2025-08-20 10:39 - 2020-05-26 20:59 - 000000000 ____D C:\ProgramData\NVIDIA
2025-08-20 09:27 - 2021-12-15 21:38 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-08-20 09:25 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-08-20 09:25 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-08-20 00:58 - 2020-06-10 22:25 - 000000000 ____D C:\Users\admin\AppData\Local\CrashDumps
2025-08-19 23:04 - 2025-02-09 21:38 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-502460867-2142398443-4065067644-1001
2025-08-19 23:04 - 2022-01-15 11:16 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-502460867-2142398443-4065067644-1001
2025-08-19 23:04 - 2021-02-27 21:04 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-502460867-2142398443-4065067644-1001
2025-08-19 23:04 - 2021-02-27 21:01 - 000002377 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-08-19 23:00 - 2021-02-27 21:09 - 001693820 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-08-19 23:00 - 2019-12-07 16:41 - 000716932 _____ C:\WINDOWS\system32\perfh005.dat
2025-08-19 23:00 - 2019-12-07 16:41 - 000145110 _____ C:\WINDOWS\system32\perfc005.dat
2025-08-19 22:56 - 2021-02-27 21:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-08-19 22:56 - 2021-02-27 21:00 - 000008192 ___SH C:\DumpStack.log.tmp
2025-08-19 22:56 - 2020-05-18 21:18 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-08-19 22:56 - 2020-05-18 21:18 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-08-19 22:56 - 2020-05-18 21:10 - 000000000 ____D C:\Users\admin\AppData\Local\Packages
2025-08-18 19:31 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2025-08-18 19:30 - 2021-02-27 21:00 - 000269520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-08-18 19:29 - 2024-07-19 22:23 - 000000000 ____D C:\WINDOWS\system32\compatrel
2025-08-18 19:29 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-08-18 19:29 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-08-18 19:29 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-08-18 19:29 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-08-18 19:29 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-08-18 19:29 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-08-18 18:35 - 2020-05-18 21:59 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-08-18 18:34 - 2020-05-18 21:59 - 223939376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-08-18 18:33 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-08-18 18:31 - 2021-07-29 23:25 - 000000000 ____D C:\Users\admin\AppData\Roaming\.minecraft
2025-08-18 18:31 - 2021-02-27 21:04 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-08-18 10:07 - 2024-03-03 17:39 - 000002317 _____ C:\Users\admin\Desktop\CurseForge.lnk
2025-08-18 10:07 - 2024-03-03 17:36 - 000000000 ____D C:\Users\admin\AppData\Local\Overwolf
2025-08-17 09:06 - 2020-07-15 00:46 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-08-17 09:06 - 2020-07-15 00:46 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-08-09 08:33 - 2024-03-03 17:39 - 000000000 ____D C:\Program Files (x86)\Overwolf
2025-08-07 17:36 - 2020-05-19 02:09 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-08-06 08:54 - 2021-02-27 21:01 - 000000000 ____D C:\Users\admin
2025-08-06 08:29 - 2024-04-29 21:08 - 000000000 ____D C:\Program Files\CCleaner
2025-08-05 09:47 - 2024-04-29 21:08 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2025-08-05 07:56 - 2021-02-27 21:04 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-08-05 07:56 - 2021-02-27 21:04 - 000003514 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-08-05 07:54 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2025-07-25 18:56 - 2022-02-16 22:48 - 000000000 ____D C:\Program Files\RUXIM
2025-07-21 23:25 - 2020-05-18 21:24 - 000000000 ____D C:\ProgramData\Package Cache
2025-07-21 23:25 - 2020-05-18 21:24 - 000000000 ____D C:\Program Files (x86)\ASUS
2025-07-21 23:10 - 2020-05-18 21:24 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2025-07-21 23:09 - 2021-02-27 21:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\ASUS
2025-07-21 23:00 - 2020-05-18 21:17 - 000000000 ____D C:\ProgramData\Packages
2025-07-21 22:52 - 2020-05-18 21:26 - 000012032 _____ C:\WINDOWS\PE_Rom.dll
2025-07-21 19:44 - 2025-05-08 12:19 - 000000000 ____D C:\foto_pracovni

==================== Files in the root of some directories ========

2020-06-25 22:49 - 2025-06-19 01:24 - 000001456 _____ () C:\Users\admin\AppData\Local\Adobe Save for Web 13.0 Prefs
2020-05-31 20:17 - 2020-05-31 20:17 - 000000410 _____ () C:\Users\admin\AppData\Local\oobelibMkey.log

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-08-2025
Ran by admin (20-08-2025 22:33:17)
Running from C:\Users\admin\Desktop
Microsoft Windows 10 Home Version 22H2 19045.6216 (X64) (2021-02-27 19:04:15)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

admin (S-1-5-21-502460867-2142398443-4065067644-1001 - Administrator - Enabled) => C:\Users\admin
Administrator (S-1-5-21-502460867-2142398443-4065067644-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-502460867-2142398443-4065067644-503 - Limited - Disabled)
Guest (S-1-5-21-502460867-2142398443-4065067644-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-502460867-2142398443-4065067644-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 24.08 (x64) (HKLM\...\7-Zip) (Version: 24.08 - Igor Pavlov)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 25.001.20577 - Adobe)
Adobe Bridge 2025 (HKLM-x32\...\KBRG_15_1_0) (Version: 15.1.0 - Adobe Inc.)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 6.7.0.278 - Adobe Inc.)
Adobe Genuine Service (HKLM-x32\...\AdobeGenuineService) (Version: 9.0.0.29 - Adobe Inc.)
Adobe Lightroom Classic (HKLM-x32\...\LTRM_14_4) (Version: 14.4 - Adobe Inc.)
Adobe Photoshop 2025 (HKLM-x32\...\PHSP_26_8_1) (Version: 26.8.1.8 - Adobe Inc.)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601110}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AI Suite 3 (HKLM-x32\...\{CD36E28B-6023-469A-91E7-049A2874EC13}) (Version: 3.00.52 - ASUSTeK Computer Inc.)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 19.30.28 - Advanced Micro Devices, Inc.)
AniMeVisionFont_MB (HKLM\...\{93E38BA3-9745-4D67-91BC-F65F81523D0A}) (Version: 1.0.1 - ASUSTek Computer Inc.) Hidden
ANT Drivers Installer x64 (HKLM\...\{71A1AEB1-EF84-4531-8A6B-B36F104C9F1D}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Armoury Crate Service (HKLM\...\Armoury Crate Service) (Version: 6.2.11 - ASUSTeK COMPUTER INC.)
ASUS AIOFan HAL (HKLM\...\{EAE80DED-1A39-41C5-9F60-87CC947F6454}) (Version: 1.5.2.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS AIOFan HAL (HKLM-x32\...\{4726e749-b1f1-43ce-95e4-2972f1911f8c}) (Version: 1.5.2.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM\...\{237E1CAC-1708-4940-AC34-DF15C079AB70}) (Version: 1.1.0.20 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM-x32\...\{49c4358d-054e-4cf1-9ec1-dca3487f304a}) (Version: 1.1.0.20 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM\...\{359B9A9D-A289-4962-BCE2-13EBFD50D532}) (Version: 1.6.1.2 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM-x32\...\{40dadfa2-acc5-4f75-9138-52616f20c493}) (Version: 1.6.1.2 - ASUSTeK COMPUTER INC.) Hidden
ASUS Framework Service (HKLM-x32\...\{339A6383-7862-46DA-8A9D-E84180EF9424}) (Version: 4.2.4.4 - ASUSTeK Computer Inc.)
ASUS Motherboard (HKLM-x32\...\{93795eb8-bd86-4d4d-ab27-ff80f9467b37}) (Version: 4.08.04 - ASUSTek Computer Inc.)
ASUS Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.107.139 - ASUSTeK Computer Inc.) Hidden
AURA DRAM Component (HKLM\...\{86D4C8A2-DB22-4948-950D-28DD5145F91C}) (Version: 1.1.29 - ASUS) Hidden
AURA DRAM Component (HKLM-x32\...\{f70a8a88-540d-485d-9aa8-001486fb050e}) (Version: 1.1.29 - ASUS) Hidden
Balanced (HKLM-x32\...\{24819F88-1B0B-4808-9982-5DC9C4AC7FA6}) (Version: 5.00.0000 - Advanced Micro Devices, Inc.) Hidden
Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Balíček ovladače systému Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
CCleaner (HKLM\...\CCleaner) (Version: 6.38 - Piriform)
CurseForge (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj) (Version: 1.286.0.7968 - Overwolf app)
CurseForge 1.262.1-20597 (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\ca0e291c-abd4-5fc3-b6a0-3d4333eccbd7) (Version: 1.262.1-20597 - Overwolf)
Display Pilot (HKLM\...\{E2736B8A-0125-4427-BC82-5E4906AED62C}) (Version: 2.4.2.0 - Portrait Displays, Inc.)
Elevated Installer (HKLM-x32\...\{3D0CEA2A-AAD6-428D-967B-C88F0E958AE2}) (Version: 7.9.0.0 - Garmin Ltd or its subsidiaries) Hidden
ENE RGB HAL (HKLM\...\{E050E98C-5524-4AFB-9E53-97700BEF2C02}) (Version: 1.1.57.0 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{aed74e04-f110-4d4d-bcfc-e8e9ad5fc0aa}) (Version: 1.1.57.0 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{c1d017c2-8846-4000-9254-5689eccd462e}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
Epic Online Services (HKLM-x32\...\{57A956AB-4BCC-45C6-9B40-957E4E125568}) (Version: 2.0.44.0 - Epic Games, Inc.)
EPSON L3560 Series Printer Uninstall (HKLM\...\EPSON L3560 Series) (Version: - Seiko Epson Corporation)
Epson Printer Connection Checker (HKLM-x32\...\{DE32F90E-1A29-4D74-BCF1-E7DDB25D713A}) (Version: 3.4.0.0 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version: - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\...\{711E8536-AB71-4455-A6C4-357FDBBEBF91}) (Version: 4.6.7 - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{92DCE546-2A73-4BCF-ADA5-0E6BD95E6B61}) (Version: 3.2.0.0 - Seiko Epson Corporation)
FanControl (HKLM-x32\...\{141A88F8-31AC-49EA-B428-2BE8C19DED83}_is1) (Version: 228 - Remi Mercier Software Inc)
Garmin Express (HKLM-x32\...\{580B8950-94E4-43F4-B4AA-E300A87E82B9}) (Version: 7.9.0.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{dc3a797a-2ec2-46c3-aa02-2de93fa270c6}) (Version: 7.9.0.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM\...\{825DE266-F7F9-3C28-BC5C-1DAED26C249C}) (Version: 139.0.7258.129 - Google LLC)
HitmanPro 3.8 (HKLM\...\HitmanPro38) (Version: 3.8.44.340 - SurfRight B.V.)
Java 8 Update 451 (HKLM-x32\...\{71024AE4-039E-4CA4-87B4-2F32180451F0}) (Version: 8.0.4510.10 - Oracle Corporation)
Kingston AURA DRAM Component (HKLM\...\{965CDF5F-901C-476F-B3A8-7396701B1129}) (Version: 1.1.40 - KINGSTON COMPONENTS INC.) Hidden
Kingston AURA DRAM Component (HKLM-x32\...\{2dcabc26-feae-4bc3-afc0-fba6e9f32af4}) (Version: 1.1.40 - KINGSTON COMPONENTS INC.) Hidden
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Macrium Reflect Free (HKLM\...\{A302C59F-C733-4DA0-9611-1286A9051D15}) (Version: 8.0.7783 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7783 - Paramount Software (UK) Ltd.)
Macrium Reflect FREE Edition verze 1.5 (HKLM-x32\...\Macrium Reflect FREE Edition_is1) (Version: 1.5 - )
Malwarebytes version 5.3.5.204 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.3.5.204 - Malwarebytes)
Medal of Honor - Allied Assault War Chest (HKLM-x32\...\1207659126_is1) (Version: 2.1.0.22 - GOG.com)
Microsoft .NET Host - 8.0.13 (x64) (HKLM\...\{6CD2C0A9-55E7-4133-BC19-205CCF2B64C9}) (Version: 64.52.27977 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.13 (x64) (HKLM\...\{BB5AC4BC-A263-43DA-A530-9CB56342D6B8}) (Version: 64.52.27977 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.13 (x64) (HKLM\...\{C7FB4EEE-D481-4AC1-B113-120A9124FE50}) (Version: 64.52.27977 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.13 (x64) (HKLM-x32\...\{8def024a-2c3c-4c48-a40d-05682ee1ec65}) (Version: 8.0.13.34516 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 139.0.3405.102 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 139.0.3405.102 - Microsoft Corporation) Hidden
Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\OneDriveSetup.exe) (Version: 25.140.0720.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 (HKLM-x32\...\{b49c10dd-4d54-45f8-ad13-fa25704456a4}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34438 (HKLM-x32\...\{ba10fda9-f731-441f-a999-000bbb7ceec2}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438 (HKLM\...\{E528AD94-12D7-42C4-91A3-908BE28E9BD2}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438 (HKLM\...\{2E15F519-4FDA-4834-B4EE-7EFCE7D8D4EE}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34438 (HKLM-x32\...\{A5592FEF-F948-4BA6-A066-8BBFC2DC7EE1}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34438 (HKLM-x32\...\{5D0C4511-3CA1-4FF8-A4BA-C0E1957ABEEA}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Mp3tag v2.99 (HKLM-x32\...\Mp3tag) (Version: 2.99 - Florian Heidenreich)
NetBalancer (HKLM\...\NetBalancer_is1) (Version: - SeriousBit)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.18 - DxO)
Nikon Transfer 2 (HKLM-x32\...\{3FC564E4-C8EA-4887-AEF3-268962172514}) (Version: 2.20.1 - Nikon Corporation)
NVIDIA Ovladače grafiky 560.94 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 560.94 - NVIDIA Corporation)
NX Studio (HKLM\...\{2857A646-0456-40E7-ABE7-99787C915705}) (Version: 1.9.0 - Nikon Corporation)
OEM Application Profile (HKLM-x32\...\{84AD2AF7-10C8-0395-66F9-FFAEB4C5DBF1}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OpenTTD (HKLM-x32\...\OpenTTD) (Version: 13.4 - OpenTTD)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.280.2.1 - Overwolf Ltd.)
Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.3 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM-x32\...\{6e0eff60-c502-43bb-8f56-360ca07e73d9}) (Version: 1.1.0.3 - Patriot Memory) Hidden
PlayStation(R) PC SDK Runtime (HKLM\...\{97E9FE56-6EE7-49EE-868C-F3AE86280073}) (Version: 3.00.0013 - Sony Interactive Entertainment Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7841 - Realtek Semiconductor Corp.)
Roblox Player for admin (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\roblox-player) (Version: - Roblox Corporation)
Roblox Studio for admin (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\roblox-studio) (Version: - Roblox Corporation)
ROG Live Service (HKLM\...\{2D87BFB6-C184-4A59-9BBE-3E20CE797631}) (Version: 3.1.15.0 - ASUSTek COMPUTER INC.)
Seznam Software (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\SeznamInstall) (Version: 2.1.35 - Seznam.cz)
SIGMA Optimization Pro (HKLM-x32\...\{A75A7BEA-7A33-46FF-A2CD-3B0AF8023903}) (Version: 1.7.0.1 - SIGMA CORPORATION)
Speccy (HKLM\...\Speccy) (Version: 1.33 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TechPowerUp GPU-Z (HKLM-x32\...\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1) (Version: - TechPowerUp)
Topaz Sharpen AI (HKLM\...\Topaz Sharpen AI 2.1.8) (Version: 3.2.2 - Topaz Labs LLC)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 11.03 - Ghisler Software GmbH)
UE4 Prerequisites (x64) (HKLM\...\{F9EC45F9-074A-48BF-92E9-A8CADD56F693}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{4e242cc8-5e3c-4b08-9d55-dbc62ddd1208}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
Uninstall Lunar Client (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\1fcec38f-e773-5444-8669-32b8eb41524b) (Version: 3.4.9-ow - Moonsworth LLC)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
UXP WebView Support (HKLM-x32\...\UXPW_1_3_0) (Version: 1.3.0 - Adobe Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
Wargaming.net Game Center (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Wargaming.net Game Center) (Version: 25.3.0.9647 - Wargaming.net)
WD_BLACK AN1500 (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
WD_BLACK AN1500 (HKLM-x32\...\{e42c5874-37b0-4977-9e8d-70bf006e1f76}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.92.0 - Winamp SA)
Zoner Photo Studio 18 (HKLM\...\ZonerPhotoStudio18_CZ_is1) (Version: 18.0.1.10 - ZONER software)

Chrome apps:
============
Disk Google (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\1b4b3acb34569556e963c5be9c5f66ca) (Version: 1.0 - Google\Chrome)
Disk Google (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\f802ca1ebdfffe2561f774d0af40d936) (Version: 1.0 - Google\Chrome)
Dokumenty (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\c2298ff0600f6d0a9e5e694b89d125fe) (Version: 1.0 - Google\Chrome)
Dokumenty (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\e312ea0bcd5a539356392fe6a2ccef36) (Version: 1.0 - Google\Chrome)
Gmail (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\1677f967f7498eba7fa0170357d2e2f7) (Version: 1.0 - Google\Chrome)
Gmail (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\af4493368aaef81d86c4775a5b625363) (Version: 1.0 - Google\Chrome)
LEGO.com (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\def80795df5189b47346449aa2d4ff6c) (Version: 1.0 - Google\Chrome)
Prezentace (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\32a9acda1cae9992272be94d1a1e1875) (Version: 1.0 - Google\Chrome)
Prezentace (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\f271b3d4ea52542e408b8163b9d25db1) (Version: 1.0 - Google\Chrome)
Tabulky (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\97bdea63382a0abe9cc05ad74c61bacd) (Version: 1.0 - Google\Chrome)
Tabulky (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\e6ce904702f85c52099b6d81283da6dd) (Version: 1.0 - Google\Chrome)
YouTube (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\2be86c87714923a68cb2151c092f841e) (Version: 1.0 - Google\Chrome)
YouTube (HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\74593adf70606ceb3f30ce7025bbe56f) (Version: 1.0 - Google\Chrome)

Packages:
=========
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2025-07-20] ()
Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_6.0.0.1_x86__enpm4xejd91yc [2024-05-22] (Adobe Systems Incorporated)
Armoury Crate -> C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_6.2.11.0_x64__qmba6cd70vzyy [2025-07-21] (ASUSTeK COMPUTER INC.)
AURA Creator -> C:\Program Files\WindowsApps\B9ECED6F.AURACreator_4.2.7.0_x64__qmba6cd70vzyy [2025-07-21] (ASUSTeK COMPUTER INC.)
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_4.14.3.0_x64__kgqvnymyfvs32 [2025-08-06] (king.com)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-03-04] (Microsoft Corporation)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa [2025-04-02] (Apple Inc.) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-02-27] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-02-27] (Microsoft Corporation) [MS Ad]
Minecraft Dungeons -> C:\Program Files\WindowsApps\Microsoft.Lovika_1.17.0.0_x64__8wekyb3d8bbwe [2024-04-07] (Microsoft Studios)
Minecraft for Windows -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.21.10101.0_x64__8wekyb3d8bbwe [2025-08-18] (Microsoft Studios)
Minecraft Launcher -> C:\Program Files\WindowsApps\Microsoft.4297127D64EC6_2.2.2.0_x64__8wekyb3d8bbwe [2025-02-19] (Microsoft Studios)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_7.0.8.0_neutral__mcm4njqhnhss8 [2024-07-23] (Netflix, Inc.)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.968.0_x64__56jybvy8sckqj [2025-06-14] (NVIDIA Corp.)
Zip Extractor Pro -> C:\Program Files\WindowsApps\38526MediaLife.ZipPlus_2.0.4.0_x86__1crh1k73ty8mg [2020-07-31] (Media Life)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-502460867-2142398443-4065067644-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-502460867-2142398443-4065067644-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
CustomCLSID: HKU\S-1-5-21-502460867-2142398443-4065067644-1001_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.)
CustomCLSID: HKU\S-1-5-21-502460867-2142398443-4065067644-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-502460867-2142398443-4065067644-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2025-08-20] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2025-08-20] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2025-08-20] (Adobe Inc. -> )
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-08-11] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2025-08-20] (Adobe Inc. -> )
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2025-07-15] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2019-10-18] (Florian Heidenreich) [File not signed]
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers2: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2019-10-18] (Florian Heidenreich) [File not signed]
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-06-15] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-08-11] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2019-10-18] (Florian Heidenreich) [File not signed]
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\nvshext.dll [2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-08-11] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2025-08-20] (Adobe Inc. -> )
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-06-15] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\admin\Desktop\Alena - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\admin\Desktop\LEGO.com.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=nmnjmgkpkfocpgkgopfmicanghkbckhd
ShortcutWithArgument: C:\Users\admin\Desktop\YouTube Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=cinhimbnkkaeohfgghhklpknlkffjgod
ShortcutWithArgument: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Profile 2\Web Applications\_crx_nmnjmgkpkfocpgkgopfmicanghkbckhd\LEGO.com.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=nmnjmgkpkfocpgkgopfmicanghkbckhd
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Disk Google (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=aghbiahbpaijignceidepookljebhfak
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Disk Google.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=aghbiahbpaijignceidepookljebhfak
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Dokumenty (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=mpnpojknpmmopombnjdcgaaiekajbnjb
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Dokumenty.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=mpnpojknpmmopombnjdcgaaiekajbnjb
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Gmail (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Gmail.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\LEGO.com.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=nmnjmgkpkfocpgkgopfmicanghkbckhd
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Prezentace (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=kefjledonklijopmnomlcbpllchaibag
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Prezentace.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=kefjledonklijopmnomlcbpllchaibag
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Tabulky (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=fhihpiojkbmbpdjeoajapmgkhlnakfjf
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Tabulky.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=fhihpiojkbmbpdjeoajapmgkhlnakfjf
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\YouTube (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=agimnkijcaahngcdmfeangaknmldooml
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\YouTube Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=cinhimbnkkaeohfgghhklpknlkffjgod
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=agimnkijcaahngcdmfeangaknmldooml
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\LEGO.com.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 2" --app-id=nmnjmgkpkfocpgkgopfmicanghkbckhd
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Vladimir (Osoba 1) - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\b4459b1d68d26673\YouTube Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=cinhimbnkkaeohfgghhklpknlkffjgod
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Antonin (zsradostna.cz) - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Vladimir - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"

==================== Loaded Modules (Whitelisted) =============

2025-07-21 23:02 - 2025-02-03 17:17 - 000349184 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\resources\app.asar.unpacked\node_modules\@img\sharp-win32-ia32\lib\sharp-win32-ia32.node
2024-11-30 17:29 - 2025-08-17 09:07 - 000276992 _____ () [File not signed] \\?\C:\Users\admin\AppData\Local\Programs\Lunar Client\resources\app.asar.unpacked\node_modules\@lunarclient\bsdiff-node\build\Release\bsdiff.node
2024-11-30 17:29 - 2025-08-17 09:07 - 000109056 _____ () [File not signed] \\?\C:\Users\admin\AppData\Local\Programs\Lunar Client\resources\app.asar.unpacked\node_modules\native-is-elevated\build\Release\iselevated.node
2020-05-18 21:24 - 2019-03-22 22:45 - 000147456 _____ () [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\AssistFunc.dll
2020-05-18 21:24 - 2019-07-18 18:02 - 001163776 _____ () [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EasyUpdt.dll
2020-05-18 21:24 - 2019-05-13 16:44 - 005843732 _____ () [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzULIB.dll
2020-05-18 21:24 - 2019-05-13 16:44 - 000208896 _____ () [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ImageHelper.dll
2020-05-18 21:24 - 2019-05-13 16:44 - 000681984 _____ () [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\UIImprovmentHelper.dll
2023-03-20 20:58 - 2021-09-09 09:10 - 000463360 _____ () [File not signed] C:\Program Files\NetBalancer\nDPI.dll
2024-11-05 18:18 - 2025-08-17 09:07 - 002976768 _____ () [File not signed] C:\Users\admin\AppData\Local\Programs\Lunar Client\ffmpeg.dll
2024-11-05 18:18 - 2025-08-17 09:07 - 000491008 _____ () [File not signed] C:\Users\admin\AppData\Local\Programs\Lunar Client\libegl.dll
2024-11-05 18:18 - 2025-08-17 09:07 - 008110592 _____ () [File not signed] C:\Users\admin\AppData\Local\Programs\Lunar Client\libglesv2.dll
2024-11-05 18:18 - 2025-08-17 09:07 - 005506560 _____ () [File not signed] C:\Users\admin\AppData\Local\Programs\Lunar Client\vk_swiftshader.dll
2025-07-16 00:44 - 2025-07-16 00:44 - 000030720 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\Acrobat Elements\ContextMenuShim64.cze
2020-05-18 21:24 - 2019-03-22 22:45 - 000108544 _____ (ASUS) [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\AsAcpi.dll
2025-07-21 23:08 - 2025-08-19 22:56 - 000033536 _____ (ASUSTeK Computer Inc. -> ) [File not signed] C:\Program Files (x86)\ASUS\AXSP\4.03.12\PEbiosinterface32.dll
2020-05-18 21:24 - 2019-03-22 22:45 - 000676864 _____ (ASUSTeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\asacpiEx.dll
2020-05-18 21:24 - 2019-03-22 22:45 - 000221184 _____ (ASUSTeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll
2019-10-18 18:32 - 2019-10-18 18:32 - 000424448 _____ (Florian Heidenreich) [File not signed] C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll
2023-06-07 22:24 - 2024-08-11 15:00 - 000101376 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2023-03-20 20:58 - 2021-07-15 09:49 - 000091648 _____ (NT Kernel Resources) [File not signed] C:\Program Files\NetBalancer\ndisapi.dll
2023-03-20 20:58 - 2020-04-05 21:14 - 001662976 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\NetBalancer\SQLite.Interop.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\admin\Downloads\ModrinthMalwareScanner.exe:MBAM.Zone.Identifier [599]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\jp2ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.1.20
Windows Firewall is enabled.

Network Binding:
=============
Síťové připojení Bluetooth 2: Bluetooth Device (Personal Area Network) #2 -> bthpan.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys

nt_nbdrv: NetBalancer Filter

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\java8path;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\dotnet\
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\admin\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\5551715845347201212\134001609993590903.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "OnrymSpeedup"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "CCXProcess"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "Zoner Photo Studio Autoupdate"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "GarminExpress"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "NetBalancer"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_29EBC4579851B72EE312C449CF839B1A"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\StartupApproved\Run: => "electron.app.BlueStacks Services"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{7590B502-D15E-4A2A-847C-504E378A6798}C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe] => (Block) C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe
FirewallRules: [UDP Query User{9BB9C6AD-50D7-44CB-AFAA-A1774B3D2D23}C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe] => (Block) C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe
FirewallRules: [TCP Query User{6D3BF9B9-B0EE-406D-9D86-AA8D4E41E183}C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [UDP Query User{E1B7EFD4-BC46-40DC-BF74-4B2B1FB25A23}C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [TCP Query User{E4929A1F-B69D-4DAB-84E0-01468A1F65AE}C:\program files (x86)\gog galaxy\games\medal of honor - allied assault war chest\mohaa.exe] => (Allow) C:\program files (x86)\gog galaxy\games\medal of honor - allied assault war chest\mohaa.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [UDP Query User{A22C1AC2-A3C5-42F6-8907-A6D753FD89A2}C:\program files (x86)\gog galaxy\games\medal of honor - allied assault war chest\mohaa.exe] => (Allow) C:\program files (x86)\gog galaxy\games\medal of honor - allied assault war chest\mohaa.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{2D66C2A8-DA59-4122-A057-AB720954B84A}] => (Block) C:\program files (x86)\gog galaxy\games\medal of honor - allied assault war chest\mohaa.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{20D19EF2-D5BE-43B5-B95A-7E30A34834CD}] => (Block) C:\program files (x86)\gog galaxy\games\medal of honor - allied assault war chest\mohaa.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{CD71A00B-260D-4FB6-8336-67FFABFE8221}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{2B1E4FED-6462-464A-8980-0FB8C20578F2}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [TCP Query User{2FD9325B-1362-4C7D-9CF9-F8385B86C668}C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [UDP Query User{5AA3B767-4B0C-4209-8E1F-E9544E9BC508}C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [TCP Query User{A0ABC63D-B323-4522-B8A6-2795A72DA673}C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe] => (Block) C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe
FirewallRules: [UDP Query User{713AA67B-3FC3-4B5E-8AEB-D5CEF12B716E}C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe] => (Block) C:\users\admin\curseforge\minecraft\install\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe
FirewallRules: [TCP Query User{6EC24F81-FA93-43FA-B7BF-ADDE1C832096}C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe] => (Block) C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe
FirewallRules: [UDP Query User{57C72252-7C58-4A15-B43D-14A87C3AB4DC}C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe] => (Block) C:\users\admin\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-delta\windows-x64\java-runtime-delta\bin\javaw.exe
FirewallRules: [TCP Query User{5E371D9F-AE25-4DDF-8057-3AFF65D7C15A}C:\users\admin\appdata\roaming\modrinthapp\meta\java_versions\zulu21.36.17-ca-jre21.0.4-win_x64\bin\javaw.exe] => (Block) C:\users\admin\appdata\roaming\modrinthapp\meta\java_versions\zulu21.36.17-ca-jre21.0.4-win_x64\bin\javaw.exe
FirewallRules: [UDP Query User{5D8BD396-E1BB-4DC4-920D-05EF3AFD69D5}C:\users\admin\appdata\roaming\modrinthapp\meta\java_versions\zulu21.36.17-ca-jre21.0.4-win_x64\bin\javaw.exe] => (Block) C:\users\admin\appdata\roaming\modrinthapp\meta\java_versions\zulu21.36.17-ca-jre21.0.4-win_x64\bin\javaw.exe
FirewallRules: [TCP Query User{AD8BC3EB-9320-4522-8F0F-DAFEAE27FDC6}C:\users\admin\appdata\local\programs\lunar client\lunar client.exe] => (Block) C:\users\admin\appdata\local\programs\lunar client\lunar client.exe (Moonsworth, LLC -> Moonsworth LLC)
FirewallRules: [UDP Query User{F16EAE1E-0316-46AA-B1D3-2220761A2C32}C:\users\admin\appdata\local\programs\lunar client\lunar client.exe] => (Block) C:\users\admin\appdata\local\programs\lunar client\lunar client.exe (Moonsworth, LLC -> Moonsworth LLC)
FirewallRules: [TCP Query User{C2EE5362-14C6-4475-B832-94D34ADD931F}C:\users\admin\appdata\local\programs\lunar client\lunar client.exe] => (Block) C:\users\admin\appdata\local\programs\lunar client\lunar client.exe (Moonsworth, LLC -> Moonsworth LLC)
FirewallRules: [UDP Query User{4C71072A-87C9-49C5-8A05-E12F407FAEE7}C:\users\admin\appdata\local\programs\lunar client\lunar client.exe] => (Block) C:\users\admin\appdata\local\programs\lunar client\lunar client.exe (Moonsworth, LLC -> Moonsworth LLC)
FirewallRules: [TCP Query User{4A994FCB-6BCF-4ABF-B1C8-3CE0FA087873}C:\users\admin\curseforge\minecraft\install\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe] => (Block) C:\users\admin\curseforge\minecraft\install\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe
FirewallRules: [UDP Query User{1AAC6523-9409-4DFD-B303-A875DF7ED39A}C:\users\admin\curseforge\minecraft\install\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe] => (Block) C:\users\admin\curseforge\minecraft\install\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe
FirewallRules: [TCP Query User{0DC89A44-BF3A-4577-A9F5-031F56652685}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{942DA470-FD9D-4C93-9DBD-257A63E4A8FD}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [{64139BE3-1298-4C42-BEFA-730557B7E972}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{599135C7-A8F3-4A2A-A42C-C8D24F861A59}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{3C174063-1347-44F2-AA20-AEBC83504E72}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{818F66B6-E916-4C7F-9AAD-5B556C0B82ED}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{ED631AB4-20DF-4A27-979F-694F889D0772}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{D19BFBB3-FC2D-4456-AFB4-8664BF59BE6A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{254120E7-2FBD-4C6F-8388-A48451E79E83}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{D3D60547-0A5C-473F-8680-1A6FB99AA56B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12137.1.3025.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{C0B158C2-3BF7-4AAD-AF7E-4A79602DD7BE}] => (Allow) C:\Program Files\Portrait Displays\Display Pilot\DisplayPilot.exe (Portrait Displays, Inc. -> Portrait Displays, Inc.)
FirewallRules: [{497A60E3-2149-470E-BBF8-C86F19B24CB2}] => (Allow) C:\Program Files\Portrait Displays\Display Pilot\DisplayPilot.exe (Portrait Displays, Inc. -> Portrait Displays, Inc.)
FirewallRules: [{33BEA81D-54C7-4A6D-9B78-735E7A7FC970}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{7DFB8BFB-8D6E-42D7-B4AB-29D8533552FB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E1017EB1-D4D5-4040-9E88-D747464DD0EF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E1291B9B-4BC8-434D-89AB-7F77768825CE}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{D1112F32-A610-4733-804A-952CFF652BEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Horizon Adventures\LegoHorizonAdventures.exe (Sony Interactive Entertainment LLC -> Sony Interactive Entertainment)
FirewallRules: [{7812D74B-9173-488F-9CC3-3149FDA3D15F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Horizon Adventures\LegoHorizonAdventures.exe (Sony Interactive Entertainment LLC -> Sony Interactive Entertainment)
FirewallRules: [TCP Query User{073EF3BF-4E39-488E-9A96-05D40071E860}C:\program files (x86)\steam\steamapps\common\lego horizon adventures\glow\binaries\win64\legohorizonadventures-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\lego horizon adventures\glow\binaries\win64\legohorizonadventures-win64-shipping.exe (Sony Interactive Entertainment LLC -> Sony Interactive Entertainment)
FirewallRules: [UDP Query User{3293D953-C647-4A78-B064-9EFE4A1DB919}C:\program files (x86)\steam\steamapps\common\lego horizon adventures\glow\binaries\win64\legohorizonadventures-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\lego horizon adventures\glow\binaries\win64\legohorizonadventures-win64-shipping.exe (Sony Interactive Entertainment LLC -> Sony Interactive Entertainment)
FirewallRules: [TCP Query User{E57CCD61-A299-4AC4-A03A-EB328DCDE69E}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [UDP Query User{83332904-3682-4B30-B219-AFB64A6F629A}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [{91BF592B-7EA8-4ABC-82A0-432688C0C14A}] => (Allow) C:\Users\admin\AppData\Local\Temp\ACFL20250721230111\ACSetup\ACSetup.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{34726386-9EFA-4064-A55A-9D75BD1988BE}] => (Allow) C:\Users\admin\AppData\Local\Temp\ACFL20250721230111\ACSetup\ACSetup.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{425C9708-D57F-4A41-A315-A78FEF22472F}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{D8EF385F-E596-45A7-8E87-3B426EEB1061}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{5E7AF017-1241-4F55-89A5-04E8078346D4}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{6DB4B182-046D-40D3-9AEC-7AC9E4E4CFD3}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{5286EF47-CF81-41A1-BCE9-EED685CB9F02}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmouryHtmlDebugServer.exe (ASUSTeK COMPUTER INC. -> ASUS)
FirewallRules: [{AEE25769-80D9-4718-BB29-A41CD2EE859C}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{BDF09D62-A352-4AA9-96A1-F0168C61E7F8}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{1C0F0B76-9CF3-4793-8E0E-576D56C36DC7}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{452B17E7-8902-471D-AEDF-7E3880ECAF4A}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{F40D0650-A61A-4E84-ACE3-CEC023FD4031}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.2.1\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{4D845943-041D-47D7-A3C3-65146871B52B}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.2.1\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{7BED2708-4BCD-45B9-9955-33B0DBF08C52}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (08/20/2025 10:25:00 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program NXStudio.exe verze 1.9.0.3004 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 1ee8

Čas spuštění: 01dc1209257290e6

Čas ukončení: 111

Cesta k aplikaci: C:\Program Files\Nikon\NXStudio\NXStudio.exe

ID hlášení: fd2b7a5e-f8db-4fe8-afd6-144d27db2833

Úplný název balíčku s chybou:

ID aplikace relativní podle balíčku s chybou:

Typ zablokování: Unknown

Error: (08/20/2025 01:02:16 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program NXStudio.exe verze 1.9.0.3004 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 4e9c

Čas spuštění: 01dc115cc2df2fcd

Čas ukončení: 55

Cesta k aplikaci: C:\Program Files\Nikon\NXStudio\NXStudio.exe

ID hlášení: 4beb8b92-b936-433e-8d91-09371b4bce6a

Úplný název balíčku s chybou:

ID aplikace relativní podle balíčku s chybou:

Typ zablokování: Unknown

Error: (08/20/2025 12:58:45 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Zps.exe, verze: 18.0.1.10, časové razítko: 0x5873831b
Název chybujícího modulu: Zps.exe, verze: 18.0.1.10, časové razítko: 0x5873831b
Kód výjimky: 0xc000041d
Posun chyby: 0x00000000002e17e9
ID chybujícího procesu: 0x249c
Čas spuštění chybující aplikace: 0x01dc11577d7c547f
Cesta k chybující aplikaci: C:\Program Files\Zoner\Photo Studio 18\Program64\Zps.exe
Cesta k chybujícímu modulu: C:\Program Files\Zoner\Photo Studio 18\Program64\Zps.exe
ID zprávy: 08e3319e-498f-4e4b-b9c9-6ec3e2642e73
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/20/2025 12:58:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Zps.exe, verze: 18.0.1.10, časové razítko: 0x5873831b
Název chybujícího modulu: Zps.exe, verze: 18.0.1.10, časové razítko: 0x5873831b
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000002e17e9
ID chybujícího procesu: 0x249c
Čas spuštění chybující aplikace: 0x01dc11577d7c547f
Cesta k chybující aplikaci: C:\Program Files\Zoner\Photo Studio 18\Program64\Zps.exe
Cesta k chybujícímu modulu: C:\Program Files\Zoner\Photo Studio 18\Program64\Zps.exe
ID zprávy: 313e350d-812c-4983-ab3e-147cb5142bd0
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/20/2025 12:58:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NXStudio.exe, verze: 1.9.0.3004, časové razítko: 0x67f38dca
Název chybujícího modulu: NXStudio.exe, verze: 1.9.0.3004, časové razítko: 0x67f38dca
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000024c4ec
ID chybujícího procesu: 0x4918
Čas spuštění chybující aplikace: 0x01dc114bd353c006
Cesta k chybující aplikaci: C:\Program Files\Nikon\NXStudio\NXStudio.exe
Cesta k chybujícímu modulu: C:\Program Files\Nikon\NXStudio\NXStudio.exe
ID zprávy: 452af68b-6db2-48a0-a92a-1e1f148d153b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/19/2025 11:41:19 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení se nezdařilo (Proces = C:\WINDOWS\system32\srtasks.exe ExecuteScheduledSPPCreation; Popis = Naplánovaný kontrolní bod; Chyba = 0x80070422).

Error: (08/19/2025 11:38:21 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Data (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (08/18/2025 07:29:54 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..


System errors:
=============
Error: (08/20/2025 09:56:28 PM) (Source: nvlddmkm) (EventID: 153) (User: )
Description: Event-ID 153

Error: (08/19/2025 11:06:25 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80073d02): 9NMPJ99VJBWV-Microsoft.YourPhone.

Error: (08/19/2025 10:58:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (08/19/2025 10:58:14 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (08/19/2025 10:56:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba GameInput Service byla neočekávaně ukončena. Tento stav nastal již 6krát.

Error: (08/19/2025 10:56:18 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba GameInput Service byla ukončena s následující chybou:
Složený soubor GameInput Service byl vytvořen s novější verzi úložného prostoru.

Error: (08/19/2025 10:56:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba GameInput Service byla nečekaně ukončena. Stalo se to 5 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (08/19/2025 10:56:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba GameInput Service byla ukončena s následující chybou:
Složený soubor GameInput Service byl vytvořen s novější verzi úložného prostoru.


Windows Defender:
================
Date: 2025-08-20 18:56:39
Description:
Antivirová ochrana v programu Microsoft Defender ŝĉàʼn нåš ъè℮η śţőррзð веƒσге ćóмрľ℮ŧĭσň.%и %ťŚĉăй ĪÐ:%в{40CB8F33-757E-4298-A3EB-C266EA24E675}%ʼn %тŜċàή Τỳφέ:%ьAntimalwarový program%ň %ŧЅĉăп Рàřáméŧėяѕ:%ъRychlé prohledávání%ή %ŧЦŝèя:%ъNT AUTHORITY\SYSTEM%ʼn %тŞтøр Ŕęаśòή:%ьŞςħеδΰĺэδ ŝćąń ŵάŝ şķïρρĕđ ьěċäύśé ţħė łªśт şΰćčêѕŝƒŭℓ śčàņ ŵαš ώîťђîп ťħз łáśť 7 δªỳş

Date: 2025-08-16 19:30:38
Description:
Antivirová ochrana v programu Microsoft Defender ŝĉàʼn нåš ъè℮η śţőррзð веƒσге ćóмрľ℮ŧĭσň.%и %ťŚĉăй ĪÐ:%в{CE4CB501-EA94-4A22-BB2C-5AFC798989DC}%ʼn %тŜċàή Τỳφέ:%ьAntimalwarový program%ň %ŧЅĉăп Рàřáméŧėяѕ:%ъRychlé prohledávání%ή %ŧЦŝèя:%ъNT AUTHORITY\SYSTEM%ʼn %тŞтøр Ŕęаśòή:%ьŔΡÇ ċбňйεčтìσй ѓŭлðóщʼn

Date: 2025-08-07 18:16:54
Description:
Antivirová ochrana v programu Microsoft Defender ŝĉàʼn нåš ъè℮η śţőррзð веƒσге ćóмрľ℮ŧĭσň.%и %ťŚĉăй ĪÐ:%в{9DE74D07-8AA6-4D36-B2E2-99E763A1575F}%ʼn %тŜċàή Τỳφέ:%ьAntimalwarový program%ň %ŧЅĉăп Рàřáméŧėяѕ:%ъRychlé prohledávání%ή %ŧЦŝèя:%ъNT AUTHORITY\SYSTEM%ʼn %тŞтøр Ŕęаśòή:%ьŔΡÇ ċбňйεčтìσй ѓŭлðóщʼn

Date: 2025-08-07 08:39:59
Description:
Antivirová ochrana v programu Microsoft Defender ŝĉàʼn нåš ъè℮η śţőррзð веƒσге ćóмрľ℮ŧĭσň.%и %ťŚĉăй ĪÐ:%в{34E0F1C1-6E3A-408D-A130-366870AF5D31}%ʼn %тŜċàή Τỳφέ:%ьAntimalwarový program%ň %ŧЅĉăп Рàřáméŧėяѕ:%ъRychlé prohledávání%ή %ŧЦŝèя:%ъNT AUTHORITY\SYSTEM%ʼn %тŞтøр Ŕęаśòή:%ьЅ¢ĥёðűľēđ şςãп щдş šκìφрéđ ьěςǻŭѕê ŧће ŀªşт ѕϋčсęѕşƒùľ şćâň ẅâŝ ẅϊŧћïй τђέ ŀàŝτ 7 đăγş

Date: 2025-07-21 18:26:20
Description:
Antivirová ochrana v programu Microsoft Defender ŝĉàʼn нåš ъè℮η śţőррзð веƒσге ćóмрľ℮ŧĭσň.%и %ťŚĉăй ĪÐ:%в{A77E9B57-7528-4157-AF13-0CB35C55B136}%ʼn %тŜċàή Τỳφέ:%ьAntimalwarový program%ň %ŧЅĉăп Рàřáméŧėяѕ:%ъRychlé prohledávání%ή %ŧЦŝèя:%ъNT AUTHORITY\SYSTEM%ʼn %тŞтøр Ŕęаśòή:%ьŚ¢ћ℮ďϋℓзđ śĉăπ ẅāš şĸíррēδ вєĉąűŝє ţĥэ ľǻѕŧ šυсćεşŝƒůŀ şċäй ŵâš ώϊţнìŋ ţне łªşŧ 7 ðãỳŝ
Event[0]:

Date: 2025-04-03 13:16:48
Description:
Microsoft Defender Antivirus narazil na chybu při pokusu o aktualizaci bezpečnostních informací a pokusí se o obnovení na předchozí verzi.
Bezpečnostní informace, které se měly načíst: Current
Kód chyby: 0x80501102
Popis chyby: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Verze bezpečnostních informací: 1.427.31.0;1.427.31.0
Verze modulu: 1.1.25030.1

Date: 2024-12-01 13:40:38
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací a pokusí se o obnovení na předchozí verzi.
Bezpečnostní informace, které se měly načíst: Aktuální
Kód chyby: 0x80501102
Popis chyby: Došlo k neočekávaným potížím. Nainstalujte všechny dostupné aktualizace a potom opakujte spuštění programu. Informace o instalaci aktualizací naleznete v nápovědě a podpoře.
Verze bezpečnostních informací: 1.421.363.0;1.421.363.0
Verze modulu: 1.1.24090.11

Date: 2024-08-24 10:00:15
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.417.217.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24070.3
Kód chyby: 0x80070102
Popis chyby: Vypršel časový limit operace čekání.

Date: 2024-08-24 10:00:15
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.417.217.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24070.3
Kód chyby: 0x80070102
Popis chyby: Vypršel časový limit operace čekání.

Date: 2024-07-19 14:42:28
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.415.103.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24060.5
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

CodeIntegrity:
===============
Date: 2025-08-20 11:48:47
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Users\admin\AppData\Local\Programs\Lunar Client\Lunar Client.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.280.2.1\OWClient.dll that did not meet the Microsoft signing level requirements.

Date: 2025-08-20 11:48:47
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Users\admin\AppData\Local\Programs\Lunar Client\Lunar Client.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Overwolf\0.280.2.1\ow-graphics-vulkan.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. 2006 11/13/2019
Motherboard: ASUSTeK COMPUTER INC. PRIME B450M-A
Processor: AMD Ryzen 7 3700X 8-Core Processor
Percentage of memory in use: 15%
Total physical RAM: 65472.38 MB
Available physical RAM: 55559.27 MB
Total Virtual: 75200.38 MB
Available Virtual: 61415.71 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:930.94 GB) (Free:86.42 GB) (Model: Samsung SSD 980 1TB) NTFS
Drive d: (Data) (Fixed) (Total:5589.01 GB) (Free:880.24 GB) (Model: ST6000DM003-2CY186) NTFS
Drive e: (Elements) (Fixed) (Total:1397.23 GB) (Free:856.18 GB) (Model: WD Elements 2620 USB Device) NTFS
Drive g: (NIKON Z 8 ) (Fixed) (Total:119.21 GB) (Free:91.46 GB) (Model: Lexar Lexar RW520 SCSI Disk Device) exFAT

\\?\Volume{032b61af-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.57 GB) (Free:0.12 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 5589 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 032B61AF)
Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=930.9 GB) - (Type=07 NTFS)

==========================================================
Disk: 2 (Size: 1397.2 GB) (Disk ID: 16F2A91F)

Partition: GPT.

==========================================================
Disk: 5 (Size: 119.2 GB) (Disk ID: B0562E19)
Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119486
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#2 Příspěvek od Rudy »

Zdravím!
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\MountPoints2: {febef221-f2d8-11eb-ab01-a85e45536675} - "E:\HiSuiteDownLoader.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {ECF9B003-985B-4DA0-AEEE-C1AEB81AE131} - System32\Tasks\Opera scheduled Autoupdate 1627586682 => C:\Users\admin\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
S3 cpuz159; C:\WINDOWS\temp\cpuz159\cpuz159_x64.sys [44680 2025-07-21] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) <==== ATTENTION
C:\DumpStack.log.tmp
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
AlternateDataStreams: C:\Users\admin\Downloads\ModrinthMalwareScanner.exe:MBAM.Zone.Identifier [599]
FirewallRules: [TCP Query User{E57CCD61-A299-4AC4-A03A-EB328DCDE69E}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [UDP Query User{83332904-3682-4B30-B219-AFB64A6F629A}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [{AEE25769-80D9-4718-BB29-A41CD2EE859C}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{BDF09D62-A352-4AA9-96A1-F0168C61E7F8}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{1C0F0B76-9CF3-4793-8E0E-576D56C36DC7}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{452B17E7-8902-471D-AEDF-7E3880ECAF4A}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ed
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 14 led 2005 18:27

Re: PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#3 Příspěvek od ed »

Ahoj,

tak tady výpis

Fix result of Farbar Recovery Scan Tool (x64) Version: 21-08-2025
Ran by admin (21-08-2025 17:59:13) Run:1
Running from C:\Users\admin\Desktop
Loaded Profiles: admin
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\MountPoints2: {febef221-f2d8-11eb-ab01-a85e45536675} - "E:\HiSuiteDownLoader.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {ECF9B003-985B-4DA0-AEEE-C1AEB81AE131} - System32\Tasks\Opera scheduled Autoupdate 1627586682 => C:\Users\admin\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
S3 cpuz159; C:\WINDOWS\temp\cpuz159\cpuz159_x64.sys [44680 2025-07-21] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) <==== ATTENTION
C:\DumpStack.log.tmp
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
AlternateDataStreams: C:\Users\admin\Downloads\ModrinthMalwareScanner.exe:MBAM.Zone.Identifier [599]
FirewallRules: [TCP Query User{E57CCD61-A299-4AC4-A03A-EB328DCDE69E}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [UDP Query User{83332904-3682-4B30-B219-AFB64A6F629A}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [{AEE25769-80D9-4718-BB29-A41CD2EE859C}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{BDF09D62-A352-4AA9-96A1-F0168C61E7F8}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{1C0F0B76-9CF3-4793-8E0E-576D56C36DC7}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{452B17E7-8902-471D-AEDF-7E3880ECAF4A}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File

EmptyTemop:
End
*****************

Processes closed successfully.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
"HKU\S-1-5-21-502460867-2142398443-4065067644-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => removed successfully
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{febef221-f2d8-11eb-ab01-a85e45536675} => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ECF9B003-985B-4DA0-AEEE-C1AEB81AE131}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECF9B003-985B-4DA0-AEEE-C1AEB81AE131}" => removed successfully
C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1627586682 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1627586682" => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz159 => removed successfully
cpuz159 => service removed successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PowerISO => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PowerISO => removed successfully
C:\Users\admin\Downloads\ModrinthMalwareScanner.exe => ":MBAM.Zone.Identifier" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E57CCD61-A299-4AC4-A03A-EB328DCDE69E}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{83332904-3682-4B30-B219-AFB64A6F629A}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AEE25769-80D9-4718-BB29-A41CD2EE859C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BDF09D62-A352-4AA9-96A1-F0168C61E7F8}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1C0F0B76-9CF3-4793-8E0E-576D56C36DC7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{452B17E7-8902-471D-AEDF-7E3880ECAF4A}" => removed successfully
EmptyTemop: => Error: No automatic fix found for this entry.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 21-08-2025 18:00:19)

C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 18:00:19 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119486
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#4 Příspěvek od Rudy »

Omlouvám se za překlep. Budete to muset spustit ještě jednou. Skript je opraven.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ed
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 14 led 2005 18:27

Re: PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#5 Příspěvek od ed »

Druhý pokus :-)

Fix result of Farbar Recovery Scan Tool (x64) Version: 21-08-2025
Ran by admin (21-08-2025 20:25:32) Run:2
Running from C:\Users\admin\Desktop
Loaded Profiles: admin
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\...\MountPoints2: {febef221-f2d8-11eb-ab01-a85e45536675} - "E:\HiSuiteDownLoader.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {ECF9B003-985B-4DA0-AEEE-C1AEB81AE131} - System32\Tasks\Opera scheduled Autoupdate 1627586682 => C:\Users\admin\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
S3 cpuz159; C:\WINDOWS\temp\cpuz159\cpuz159_x64.sys [44680 2025-07-21] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) <==== ATTENTION
C:\DumpStack.log.tmp
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
AlternateDataStreams: C:\Users\admin\Downloads\ModrinthMalwareScanner.exe:MBAM.Zone.Identifier [599]
FirewallRules: [TCP Query User{E57CCD61-A299-4AC4-A03A-EB328DCDE69E}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [UDP Query User{83332904-3682-4B30-B219-AFB64A6F629A}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [{AEE25769-80D9-4718-BB29-A41CD2EE859C}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{BDF09D62-A352-4AA9-96A1-F0168C61E7F8}] => (Allow) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{1C0F0B76-9CF3-4793-8E0E-576D56C36DC7}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File
FirewallRules: [{452B17E7-8902-471D-AEDF-7E3880ECAF4A}] => (Block) C:\Program Files (x86)\Overwolf\0.280.1.4\OverwolfBrowser.exe => No File

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => not found
"HKU\S-1-5-21-502460867-2142398443-4065067644-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => not found
HKU\S-1-5-21-502460867-2142398443-4065067644-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{febef221-f2d8-11eb-ab01-a85e45536675} => not found
HKLM\SOFTWARE\Policies\Mozilla => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECF9B003-985B-4DA0-AEEE-C1AEB81AE131}" => not found
"C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1627586682" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1627586682" => not found
cpuz159 => service not found.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PowerISO => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PowerISO => not found
"C:\Users\admin\Downloads\ModrinthMalwareScanner.exe" => ":MBAM.Zone.Identifier" ADS not found.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E57CCD61-A299-4AC4-A03A-EB328DCDE69E}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{83332904-3682-4B30-B219-AFB64A6F629A}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\3.00.00.13\webview2runtime\msedgewebview2.exe" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AEE25769-80D9-4718-BB29-A41CD2EE859C}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BDF09D62-A352-4AA9-96A1-F0168C61E7F8}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1C0F0B76-9CF3-4793-8E0E-576D56C36DC7}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{452B17E7-8902-471D-AEDF-7E3880ECAF4A}" => not found

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 457589451 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 193639425 B
Windows/system/drivers => 127351519 B
Edge => 0 B
Chrome => 7854640229 B
Firefox => 0 B
Opera => 13549436 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 411 B
systemprofile32 => 411 B
LocalService => 74601 B
NetworkService => 2602463 B

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 21-08-2025 21:06:38)

C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 21:06:38 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119486
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#6 Příspěvek od Rudy »

OK, děkuji, vše bylo smazáno. Zlepšila se odezva?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ed
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 14 led 2005 18:27

Re: PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#7 Příspěvek od ed »

Vypadá to, že ano :-) Větrák se pořád ještě na můj vkus spouští zbytečně často, ale to už bude asi spíš HW problém. Takže díky moc za pomoc :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119486
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PRosím o kontrolu logu - pomalá odezva, časté spouštění větráku

#8 Příspěvek od Rudy »

Chladič může být zaprášený a tím se toto může stát. Pokud je jinak vše v pořádku, jsem rád, že se problém zlepšil. Nemáte zač! V případě potřeby s ozvěte. :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno