Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Prosím o kontrolu logu

#1 Příspěvek od Ecinazuz »

Dobrý den, před časem jsem ve dvou vláknech s vámi řešila problém zasekávání a restarování PC.
https://forum.viry.cz/viewtopic.php?t=159948
https://forum.viry.cz/viewtopic.php?t=160170

Od té doby do te´d vše klapalo bez problému. V posledním týdnu se mi opět z ničeho noc restartuje PC během práce nebo zamrzne obrazovka. Není to tak časté jako minule, ale objevuje se to.
Nejsem si vědoma, žádné chyby při stahování - pouze nějaké aktualizace, ale ty jsem dala při posledním restartu a výzvě systému odstranit...
Juknete na log?

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-10-2025
Ran by safro (administrator) on DESKTOP-B59IHMH (HP HP ProDesk 400 G6 MT) (05-10-2025 14:13:15)
Running from C:\Users\safro\Desktop\FRST64.exe
Loaded Profiles: safro & WsiAccount
Platform: Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bromium UK Limited -> ) C:\Program Files\HP\Sure Click\servers\BrHostHelper\BrHostHelper.exe <2>
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eServiceHost.exe <2>
(C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe ->) (DigitalPersona, Inc. -> Crossmatch, Inc.) C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpCardEngine.exe
(C:\Program Files\HP\Sure Click\servers\BrHostSvr.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\bin\Br-uxendm.exe
(C:\Program Files\HP\Sure Click\servers\BrService.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BrHostSvr.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\BrowserPrivacyAndSecurity.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Windows\CxSvc\CxAudioSvc.exe ->) (Synaptics Incorporated -> Conexant) C:\Windows\System32\MicTray64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxEM.exe
(DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\BridgeCommunication.exe
(DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HotKeyServiceUWP.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HPHotkeyNotification.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2507.26.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\CCleaner\CCleaner64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <41>
(services.exe ->) (Acronis International GmbH -> ) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(services.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Security Update Service\4.4.26.1391\SecurityUpdateService.exe
(services.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BemSvc.exe
(services.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BrService.exe
(services.exe ->) (DigitalPersona, Inc. -> Crossmatch, Inc.) C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Hewlett-Packard Company -> HP) C:\Windows\System32\HPSIsvc.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_d57a8c6bda0aacf4\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\HotkeyServiceDSU.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\LanWlanWwanSwitchingServiceDSU.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HotKeyServiceUWP.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\LanWlanWwanSwitchingServiceUWP.exe
(services.exe ->) (HP Inc. -> HP) C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
(services.exe ->) (HP) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(services.exe ->) (Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_1d1c7ad354f3422f\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c18e9c8eed547b01\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_fd156d877b034329\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_fd156d877b034329\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_2c17521ca0d3f79c\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe
(services.exe ->) (Synaptics Incorporated -> Conexant Systems LLC.) C:\Windows\CxSvc\CxAudioSvc.exe
(services.exe ->) (Wondershare Technology Group Co.,Ltd -> wondershare) C:\ProgramData\Wondershare\wsServices\WsidService.exe
(svchost.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BrConsole.exe
(svchost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPJumpStarts_1.10.1627.0_x64__v10z8vjag6ke6\HP.JumpStarts.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Client Security Manager\HP.ClientSecurityManager.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.140.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_22508.1401.7.0_x64__8wekyb3d8bbwe\WinStore.DesktopExtension\StoreDesktopExtension.exe
(svchost.exe ->) (Microsoft Windows -> ) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [644000 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285616 2025-09-10] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [PenTablet] => C:\Program Files\Pentablet\PenTablet.exe [1151608 2023-03-09] (Hanvon Ugee Technology Co., Ltd. -> XPPEN TECHNOLOGY CO.)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [6206360 2021-03-23] (Acronis International GmbH -> )
HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe [446392 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [BingSvc] => C:\Users\safro\AppData\Local\Microsoft\BingSvc\BingSvc.exe [6638496 2022-09-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [693376 2025-10-04] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42449880 2025-09-08] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [MicrosoftEdgeAutoLaunch_8B3575D364394B552A9C25D557FBDA68] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45988576 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\...\Windows x64\Print Processors\HPM1210PrintProc: C:\Windows\System32\spool\prtprocs\x64\HPM1210PP.dll [74240 2012-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\HP ad2a Status Monitor: C:\WINDOWS\system32\hpinkstsad2aLM.dll [476904 2022-03-14] (HP Inc -> HP Inc.)
HKLM\...\Print\Monitors\HPM1210LM: C:\WINDOWS\system32\HPM1210LM.DLL [409088 2012-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files (x86)\CCleaner Browser\Application\140.0.32151.209\Installer\chrmstp.exe [2025-09-30] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\140.0.7339.186\Installer\chrmstp.exe [2025-09-18] (Google LLC -> Google LLC)
AppInit_DLLs: C:\PROGRA~1\HP\SURECL~1\servers\BemHook.dll => No File
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\safro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CEWE služba na pozadí.lnk [2023-07-26]
ShortcutTarget: CEWE služba na pozadí.lnk -> C:\Program Files\Fotolab\CEWE fotosvet\AutoBookService.exe () [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {40399BFE-AFCC-4FA7-81EE-F5439097ADDF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1581568 2025-08-24] (Adobe Inc. -> Adobe Inc.)
Task: {AC50B660-A303-4FB3-B160-69652C9EEED0} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-3530282796-2492871232-3359154168-1008 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-09-30] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3EC33D0B-64CD-46FE-9BAA-CC43475BD936} - System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [3778728 2025-09-27] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9F3A6E60-E7D7-48A4-8CB8-2D5AC323C225} - System32\Tasks\CCleaner Browser Heartbeat Task (Logon) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [3778728 2025-09-27] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {D49D3034-CD76-48AC-8514-4CFE5105C456} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B5FEABBF-D588-439B-A99D-1A49ABAC39DA} - System32\Tasks\CCleanerBrowserProtectS-1-5-21-3530282796-2492871232-3359154168-1001 => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowserProtect.exe [1774816 2025-09-11] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {BDEFBA4A-C147-4474-8D61-53B9F0783EDC} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6140640 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "187ebab5-e5a6-410a-b62d-0b89cd8881b3" --version "6.39.0.11548" --silent
Task: {FD6935ED-99E5-4FB3-85B6-6A4CE583D372} - System32\Tasks\CCleanerSkipUAC - safro => C:\Program Files\CCleaner\CCleaner.exe [39822560 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {4919C92A-D5B9-4804-B247-AC2F4D880E13} - System32\Tasks\CCleanerUpdateTaskMachineCore => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
Task: {88567D73-D7CB-4EE6-B7F4-0BC61083A718} - System32\Tasks\CCleanerUpdateTaskMachineUA => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
Task: {81DFCA96-1C55-4642-AC07-66EE999CCF58} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem142.0.7416.0{23FE4B8C-3740-48D2-9171-3B6723519324} => C:\Program Files (x86)\Google\GoogleUpdater\142.0.7416.0\updater.exe [6863512 2025-09-15] (Google LLC -> Google LLC)
Task: {5B517483-DB6D-402E-80AD-BB80EA230FF8} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://ABO
Task: {74316B36-7D10-4F03-A92B-D6F22ABDE9B1} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BatteryStatusError
Task: {501CECD4-C31E-4E78-9696-E19F6E82D9D1} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BCF
Task: {3155A5EC-D6CD-4052-A480-FB652FA56E6F} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1 => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM1
Task: {7228309C-D29A-4A93-A7DC-AB9AE08CF761} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2 => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM2
Task: {EEDC1D84-D03A-4880-9827-37B4FA49CBC3} - System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://LaunchUI
Task: {97268EF1-ED16-468E-8A5F-C9DD07EDF538} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags:
Task: {1F862B8E-DB19-427F-A606-9CC6AC45D4CC} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckError
Task: {2D6BCF35-3111-459A-81CC-E1AA30AB298C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [1004040 2025-09-02] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {81F4C074-68D7-4840-99FB-F64AA5437684} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2025-09-02] (HP Inc. -> HP Inc.)
Task: {389EEA1C-6579-4DBF-B986-F95EDFA4E59F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [231944 2025-09-02] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {8D502118-8950-44B8-AD26-20FB1A0CB24C} - System32\Tasks\HP\Consent Manager Launcher => C:\WINDOWS\system32\sc.exe [102400 2025-07-09] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice
Task: {40D9150C-2145-482C-9B89-8A7347C045C3} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [91144 2025-08-29] (HP Inc. -> HP Inc.)
Task: {B10C3A40-57C3-4988-865F-8D4064DD427A} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [91144 2025-08-29] (HP Inc. -> HP Inc.)
Task: {822D2D2E-6580-492A-B170-D8210E237C2A} - System32\Tasks\HP\HP Wolf Security\Launch Console => C:\Program Files\HP\HP Client Security Manager\HP.ClientSecurityManager.exe [250888 2025-03-28] (HP Inc. -> HP Inc.)
Task: {40D437D2-BF06-4D40-A1C2-27F36DF44D3D} - System32\Tasks\HP\Sure Click\Sure Click 4.4.26.1391 => C:\Program Files\HP\Sure Click\servers\BrLauncher.exe [2784584 2025-07-23] (Bromium UK Limited -> HP)
Task: {BB9346D2-04E2-4D54-9791-109C7DE9D1DC} - System32\Tasks\HP\Sure Click\Sure Click UI 4.4.26.1391 => C:\Program Files\HP\Sure Click\servers\BrConsole.exe [186696 2025-07-23] (Bromium UK Limited -> HP)
Task: {8A59A006-099A-42F4-9040-46AA0067DDCD} - System32\Tasks\HPDataRetriever => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-application-info-collector_ver_4.675.11370\hp-data-retriever.exe (No File)
Task: {0CB26830-1288-4745-87BD-4E8F735AB774} - System32\Tasks\HPOneAgentRepairTask => C:\ProgramData\Package Cache\{7CF09040-C14A-4FAA-B61A-1A7F2BDE3719}\HPOneAgent.exe [1169744 2025-09-13] (HP Inc. -> HP Inc; HP Development Company, L.P.)
Task: {DB5845A0-A548-49BB-8035-A6B0CB2330CF} - System32\Tasks\HPSupportTool => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-iolo-collector_ver_4.675.11370\HPSupportAssistant1.exe (No File)
Task: {994BE5CF-6F3B-4609-A539-4268229737B3} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16954752 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {63DA5A32-A7F0-48CE-B47A-E864F4DCF4D3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29038432 2025-09-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {C1DA3AE4-266F-4DCE-95B0-2CC5486E4D37} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [70464 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {87FA8DFC-7AE8-4E58-A0B7-5B5E9377BA9A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29038432 2025-09-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {8B49989A-E2C9-421A-8EE9-65A4512EAB88} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [318720 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0036CCA-5FA7-4979-993B-403F47A0BF94} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [318720 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {87B8C786-9713-404F-9E30-89DC826CA5B7} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [1365304 2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {B9B2828E-EB6C-4DE6-BA9D-4ECD34C9970F} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [693376 2025-10-04] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {43833194-A1F1-4FB8-A67A-BAB9CF926176} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3530282796-2492871232-3359154168-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [693376 2025-10-04] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {09CF39A6-2EAE-49D9-991A-4E581B8BB323} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2025-10-04] (Mozilla Corporation -> Mozilla Foundation)
Task: {7BB9BC5B-E347-4EFA-A171-F03C69ACCAF3} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3530282796-2492871232-3359154168-1001 => C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDriveLauncher.exe [725880 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {4CC23C0D-3CAA-497C-B7FE-5B4763CC3AAB} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-3530282796-2492871232-3359154168-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-09-30] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {490A93EB-6AB1-47BC-B5B0-A87EBD7E50B2} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-3530282796-2492871232-3359154168-1008 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-09-30] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {CD1A8EDF-DBDA-4ED4-BA70-F0E7E2734D7A} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6243960 2025-09-30] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {6CDC37B4-AB81-4E23-B973-5522835964F2} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [8971064 2025-09-25] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 62.24.64.2 8.8.8.8 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{5d78b6c1-816b-4e77-8125-9f3ad7ca951c}: [DhcpNameServer] 62.24.64.2 8.8.8.8 8.8.8.8 192.168.1.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-01]
Edge Extension: (HP Wolf Security Extension) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aoganjpeihhkhippgnniaclfocnihgln [2025-07-28]
Edge Extension: (Google Docs Offline) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-10-01]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2025-09-11]
Edge Extension: (Edge relevant text changes) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (ESET Browser Privacy & Security) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2025-07-27]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]

FireFox:
========
FF DefaultProfile: dhpnfwib.default
FF ProfilePath: C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\dhpnfwib.default [2022-09-15]
FF ProfilePath: C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694 [2025-10-05]
FF Homepage: Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694 -> seznam.cz
FF Extension: (ESET Browser Privacy & Security) - C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694\Extensions\browserextension@eset.com.xpi [2025-05-09]
FF Extension: (HP Wolf Security Extension) - C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694\Extensions\firefoxhpwolfsecurityextension@bromium.com.xpi [2025-07-19] [UpdateUrl:hxxps://addons.bromium-online.com/updates.json]
FF Extension: (Tlačítko Uložit pro Pinterest) - C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694\Extensions\jid1-YcMV6ngYmQRA2w@jetpack.xpi [2024-12-15]
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-09-08] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-07-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1583.3\npCCleanerBrowserUpdate3.dll [2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1583.3\npCCleanerBrowserUpdate3.dll [2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2025-10-05]

Chrome:
=======
CHR Profile: C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default [2025-09-18]
CHR Notifications: Default -> hxxps://business.facebook.com; hxxps://victoriavette.com; hxxps://wp.aliexpress.com; hxxps://www.aliexpress.com; hxxps://www.eva.cz; hxxps://www.facebook.com; hxxps://www.penny.cz
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-05-10]
CHR Extension: (HP Wolf Security Extension) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpmlagmcbcnjhkdjiofoenkfbaclgjkk [2025-05-10]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2025-06-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-08-01]
CHR Extension: (ESET Browser Privacy & Security) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2025-06-09]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hkecabaloghleaicfhefejdijblljpco]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [oombnmpbbhbakfpfgdflaajkhicgfaam]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 aakore; C:\Program Files (x86)\Acronis\Agent\aakore.exe [9022120 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 AcronisActiveProtectionService; C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe [12952232 2021-03-23] (Acronis International GmbH -> )
S4 AcronisCyberProtectionService; C:\Program Files\Acronis\CyberProtect\cyber-protect-service.exe [1425256 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1052280 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174584 2025-08-24] (Adobe Inc. -> Adobe Inc.)
R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [6391536 2021-05-19] (Acronis International GmbH -> )
S4 BrAmSvc; C:\Program Files\HP\Sure Click\servers\BrAmSvc.exe [2054032 2025-07-23] (HP Inc -> HP)
R2 BrEndpointSvc; C:\Program Files\HP\Sure Click\servers\BemSvc.exe [4896072 2025-07-23] (Bromium UK Limited -> HP)
R2 BrService; C:\Program Files\HP\Sure Click\servers\BrService.exe [10941768 2025-07-23] (Bromium UK Limited -> HP)
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [28280440 2025-09-30] (Gen Digital Inc. -> Gen Digital Inc.)
S3 CCleanerBrowserElevationService; C:\Program Files (x86)\CCleaner Browser\Application\140.0.32151.209\elevation_service.exe [2611896 2025-09-27] (Gen Digital Inc. -> Gen Digital Inc.)
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1080544 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
S4 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13343584 2025-09-28] (Microsoft Corporation -> Microsoft Corporation)
R2 CxAudioSvc; C:\WINDOWS\CxSvc\CxAudioSvc.exe [86592 2022-11-14] (Synaptics Incorporated -> Conexant Systems LLC.)
S2 CxUIUSvc; C:\WINDOWS\System32\CxUIUSvc64.exe [191360 2022-11-14] (Synaptics Incorporated -> Conexant Systems, Inc.)
R2 DFWSIDService; C:\ProgramData\Wondershare\wsServices\WsidService.exe [3963120 2023-09-15] (Wondershare Technology Group Co.,Ltd -> wondershare)
R2 DpHost; C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe [530136 2020-04-30] (DigitalPersona, Inc. -> Crossmatch, Inc.)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5538224 2025-09-10] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4662320 2025-09-10] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4662320 2025-09-10] (ESET, spol. s r.o. -> ESET)
R2 HotKeyServiceDSU; C:\WINDOWS\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\HotKeyServiceDSU.exe [681544 2024-09-05] (HP Inc. -> HP Inc.)
R2 HotKeyServiceUWP; C:\WINDOWS\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HotKeyServiceUWP.exe [1526176 2020-08-18] (HP Inc. -> HP Inc.)
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136192 2009-10-15] (HP) [File not signed]
S4 hp-one-agent-service; C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe [2408032 2025-08-13] (HP Inc. -> HP Inc; HP Development Company, L.P.)
R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\AppHelperCap.exe [909496 2025-08-20] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\DiagsCap.exe [907960 2025-08-20] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\NetworkCap.exe [903840 2025-08-20] (HP Inc. -> HP Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243720 2025-08-29] (HP Inc. -> HP Inc.)
R3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1149448 2020-07-23] (HP Inc. -> HP)
R2 HPSIService; C:\windows\system32\HPSIsvc.exe [126856 2012-11-08] (Hewlett-Packard Company -> HP)
R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\SysInfoCap.exe [909496 2025-08-20] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_d57a8c6bda0aacf4\x64\TouchpointAnalyticsClientService.exe [639760 2025-07-14] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192320 2020-09-07] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S4 LanWlanSwitchingService; C:\Program Files (x86)\HP\HP Hotkey Support\LanWlanSwitchingService.exe [628776 2019-05-28] (HP Inc. -> HP)
R2 LanWlanWwanSwitchingServiceDSU; C:\WINDOWS\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\LanWlanWwanSwitchingServiceDSU.exe [587848 2024-09-05] (HP Inc. -> HP Inc.)
R2 LanWlanWwanSwitchingServiceUWP; C:\WINDOWS\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\LanWlanWwanSwitchingServiceUWP.exe [782744 2020-08-18] (HP Inc. -> HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9608720 2025-09-07] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2024-12-26] (Malwarebytes Inc. -> Malwarebytes)
S4 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4878840 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 mobile_backup_server; C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [3004128 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 mobile_backup_status_server; C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [2136488 2021-03-23] (Acronis International GmbH -> )
R2 SecurityUpdateService; C:\Program Files\HP\Security Update Service\4.4.26.1391\SecurityUpdateService.exe [5615432 2025-07-23] (Bromium UK Limited -> HP)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-08-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [7398360 2021-03-23] (Acronis International GmbH -> )
S4 Tib Mounter Service; C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe [5910328 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3174840 2024-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [133592 2024-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [7786032 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA)
S3 BdDci4; C:\WINDOWS\system32\DRIVERS\bddci4.sys [971312 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 BrCow_4_4_26_1391; C:\WINDOWS\System32\DRIVERS\BrCow_4_4_26_1391.sys [71208 2025-07-23] (Bromium UK Limited -> HP)
R2 BrFilter_4_4_26_1391; C:\WINDOWS\System32\DRIVERS\BrFilter_4_4_26_1391.sys [236552 2025-07-23] (Bromium UK Limited -> HP)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2025-01-30] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2025-01-30] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2025-01-30] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [232456 2025-08-15] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [139944 2025-08-15] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [16336 2025-01-30] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [270136 2025-08-15] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [57352 2025-08-15] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [86792 2025-08-15] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [126024 2025-08-15] (ESET, spol. s r.o. -> ESET)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2020-09-07] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R2 file_protector; C:\WINDOWS\System32\DRIVERS\file_protector.sys [720392 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [392840 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R0 fltsrv; C:\WINDOWS\System32\DRIVERS\fltsrv.sys [183944 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
S1 Gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [1791064 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> BitDefender S.R.L. Bucharest, ROMANIA)
R3 hanvonugeemfilter; C:\WINDOWS\System32\drivers\hanvonugeemfilter.sys [9728 2023-02-03] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-06] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-10-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-03-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [244800 2025-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [29168 2016-01-06] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
S0 ngelam; C:\WINDOWS\System32\drivers\ngelam.sys [15816 2021-03-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Acronis International GmbH)
R1 ngscan; C:\WINDOWS\System32\DRIVERS\ngscan.sys [179104 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_0ca603ee5d51e3b2\rt68cx21x64.sys [810328 2024-03-19] (Realtek Semiconductor Corp. -> Realtek)
S3 Ser2pl; C:\WINDOWS\System32\drivers\ser2pl64.sys [258544 2019-08-01] (WDKTestCert charles-yeh,131345514351795974 -> Prolific Technology Inc.)
S0 sselam_4_4_19_828; C:\WINDOWS\System32\DRIVERS\sselam_4_4_19_828.sys [19528 2025-07-23] (Microsoft Windows Early Launch Anti-malware Publisher -> HP)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 tib; C:\WINDOWS\system32\DRIVERS\tib.sys [887032 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [175648 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
S3 tnd; C:\WINDOWS\system32\DRIVERS\tnd.sys [694920 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R3 uxen; C:\Program Files\HP\Sure Click\bin\uxen.sys [2053080 2025-04-15] (Bromium UK Limited -> HP)
R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [334984 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R3 vlflt; C:\WINDOWS\System32\DRIVERS\vlflt.sys [1438768 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 volume_tracker; C:\WINDOWS\System32\DRIVERS\volume_tracker.sys [251016 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [55856 2024-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [594304 2024-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [105856 2024-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-01-30] (Microsoft Windows -> Microsoft Corporation)
S3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys [61440 2025-09-09] (Microsoft Windows -> Microsoft Corporation)
R3 XPPenTablet; C:\WINDOWS\System32\drivers\XPPenTablet.sys [10752 2023-02-03] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 ax_pvi; \??\C:\Program Files\HP\Sure Click\bin\ax_pvi.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-10-05 14:09 - 2025-10-05 14:09 - 002442752 _____ (Farbar) C:\Users\safro\Desktop\FRST64.exe
2025-10-05 08:54 - 2025-10-05 08:58 - 000000000 ____D C:\Program Files\CCleaner
2025-10-05 08:54 - 2025-10-05 08:57 - 000003386 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2025-10-05 08:54 - 2025-10-05 08:57 - 000000670 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2025-10-05 08:54 - 2025-10-05 08:54 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2025-10-05 08:54 - 2025-10-05 08:54 - 000002904 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - safro
2025-10-05 08:54 - 2025-10-05 08:54 - 000000871 _____ C:\Users\Public\Desktop\CCleaner.lnk
2025-10-05 08:54 - 2025-10-05 08:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2025-10-05 08:51 - 2025-10-05 08:52 - 088266800 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\ccsetup639(1).zmzo3B35.exe.part
2025-10-05 08:51 - 2025-10-05 08:51 - 000000000 _____ C:\Users\safro\Downloads\ccsetup639(1).exe
2025-10-05 08:50 - 2025-10-05 08:51 - 096538504 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\CCleanerBundle-639-Setup(2).exe
2025-10-05 08:50 - 2025-10-05 08:51 - 096538504 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\CCleanerBundle-639-Setup(1).exe
2025-10-05 08:50 - 2025-10-05 08:51 - 088268600 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\ccsetup639.KzYlaz1j.exe.part
2025-10-05 08:50 - 2025-10-05 08:50 - 000000000 _____ C:\Users\safro\Downloads\ccsetup639.exe
2025-10-05 08:38 - 2025-10-05 08:38 - 000711764 _____ C:\WINDOWS\system32\perfh005.dat
2025-10-05 08:38 - 2025-10-05 08:38 - 000152978 _____ C:\WINDOWS\system32\perfc005.dat
2025-10-04 19:23 - 2025-10-04 19:23 - 000077709 _____ C:\Users\safro\Downloads\vypis-28019713832010-2025-10-01-1.pdf
2025-10-04 19:23 - 2025-10-04 19:23 - 000077709 _____ C:\Users\safro\Downloads\vypis-28019713832010-2025-10-01.pdf
2025-10-04 19:22 - 2025-10-04 19:22 - 000085089 _____ C:\Users\safro\Downloads\vypis-28019713832010-2025-09-30.pdf
2025-10-04 13:48 - 2025-10-04 13:50 - 000071342 _____ C:\Users\safro\Downloads\kniha-jizd-2025-od-csob.xlsx
2025-10-04 09:44 - 2025-10-04 09:44 - 038574063 _____ C:\Users\safro\Downloads\NA ZAČÁTKU LISTOPADA, TEPLO SE ZIMOU SE HÁDÁ - flexibilní plán.pdf
2025-10-03 19:26 - 2025-10-03 19:26 - 042800762 _____ C:\Users\safro\Downloads\Carodejnicke_diplomy_cukrkava_PDF.pdf
2025-10-03 19:26 - 2025-10-03 19:26 - 012318922 _____ C:\Users\safro\Downloads\256-Halloweenska-plotovka-Hravy-Design.pdf
2025-10-03 19:26 - 2025-10-03 19:26 - 002849726 _____ C:\Users\safro\Downloads\dusickyxhalloween-lapbook-pro-ms.pdf
2025-10-03 19:25 - 2025-10-03 19:25 - 006740857 _____ C:\Users\safro\Downloads\Halloween.PDF
2025-10-02 16:14 - 2025-10-02 16:14 - 002690104 _____ C:\Users\safro\Downloads\Pisnicky-pro-deti-13-PDF.zip
2025-10-01 20:20 - 2025-10-01 20:20 - 000261292 _____ C:\Users\safro\Downloads\1208.webp
2025-09-30 16:58 - 2025-10-05 10:31 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-09-30 15:58 - 2025-09-30 15:58 - 022763518 _____ C:\Users\safro\Downloads\Podzimni-hra.pdf.zip
2025-09-29 15:33 - 2025-09-29 15:33 - 000000000 ____D C:\WINDOWS\LastGood
2025-09-27 15:27 - 2025-09-27 15:27 - 003165032 _____ C:\Users\safro\Downloads\bramborovy-tyden-flexibilni-plan-final-1.pdf
2025-09-27 15:25 - 2025-09-27 15:25 - 083104464 _____ C:\Users\safro\Downloads\bramborovy-tyden-flexibilni-plan-final.pdf
2025-09-27 15:12 - 2025-09-27 15:12 - 032449191 _____ C:\Users\safro\Downloads\znaky-a-symboly-podzimu-ok.pdf
2025-09-27 09:23 - 2025-09-27 09:23 - 026546031 _____ C:\Users\safro\Downloads\léto a podzim flexibilní plán-final.pdf
2025-09-27 09:23 - 2025-09-27 09:23 - 026546031 _____ C:\Users\safro\Downloads\léto a podzim flexibilní plán-1.pdf
2025-09-27 09:09 - 2025-09-27 09:09 - 014658143 _____ C:\Users\safro\Downloads\léto a podzim flexibilní plán.pdf
2025-09-25 20:16 - 2024-10-17 03:53 - 000175824 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus2.sys
2025-09-25 19:58 - 2025-09-25 19:58 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-09-23 17:42 - 2025-09-23 17:41 - 000047101 _____ C:\Users\safro\Desktop\Integrovaný blok TRADICE, ZVYKY, SVÁTKY, OSLAVY návrh ŠVP
2025-09-23 17:08 - 2025-09-23 17:08 - 005960599 _____ C:\Users\safro\Downloads\stezka-knihovna2(1).zip
2025-09-23 16:38 - 2025-09-23 15:33 - 005848948 _____ C:\Users\safro\Downloads\stezka-knihovna2.pdf
2025-09-23 16:38 - 2025-09-15 13:37 - 000359771 _____ C:\Users\safro\Downloads\stezka-knihovna-pruvodni-dopis.pdf
2025-09-23 16:37 - 2025-09-23 16:37 - 005960599 _____ C:\Users\safro\Downloads\stezka-knihovna2.zip
2025-09-23 16:20 - 2025-09-23 16:34 - 000000000 ____D C:\Users\safro\Downloads\Podzimni-hudebni-balicek_0
2025-09-23 16:20 - 2025-09-23 16:20 - 044944872 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek_0.zip
2025-09-22 19:55 - 2025-09-22 19:55 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek(3).zip
2025-09-22 19:52 - 2025-09-22 19:52 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek(2).zip
2025-09-22 19:49 - 2025-09-22 19:49 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek(1).zip
2025-09-22 19:49 - 2025-09-22 19:49 - 000000000 ____D C:\Users\safro\Downloads\Podzimni-hudebni-balicek
2025-09-22 19:47 - 2025-09-22 19:47 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek.zip
2025-09-22 18:45 - 2025-09-22 18:47 - 000000000 ____D C:\Users\safro\Desktop\PŘÍPRAVY TWIGSEE
2025-09-22 18:45 - 2025-09-22 18:46 - 011922963 _____ C:\Users\safro\Downloads\twigsee-ms-pripravy-zari-2024-1.pdf
2025-09-22 17:01 - 2025-09-22 17:01 - 011922963 _____ C:\Users\safro\Downloads\twigsee-ms-pripravy-zari-2024.pdf
2025-09-22 08:36 - 2025-09-22 08:36 - 026260662 _____ C:\Users\safro\Downloads\twigsee-ms-pripravy-rijen-2025.pdf
2025-09-21 20:58 - 2024-10-17 03:54 - 000174264 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2025-09-21 08:32 - 2025-09-21 08:32 - 014083209 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-1-kompr..pdf
2025-09-21 08:30 - 2025-09-21 08:30 - 155625773 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-1.pdf
2025-09-21 08:25 - 2025-09-21 08:25 - 029365822 _____ C:\Users\safro\Downloads\HALLOWEENSKÝ- DUŠIČKOVÝ flexifilní plán-1.pdf
2025-09-20 19:07 - 2025-09-27 14:31 - 000000000 ____D C:\Users\safro\Desktop\VLASTNÍ HODNOCENÍ ŠKOLY
2025-09-20 09:02 - 2025-09-20 09:02 - 014082726 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-final-1.pdf
2025-09-20 08:45 - 2025-09-20 08:46 - 155625163 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-final.pdf
2025-09-19 20:33 - 2025-09-19 20:33 - 036259127 _____ C:\Users\safro\Downloads\HALLOWEENSKÝ- DUŠIČKOVÝ flexifilní plán-final.pdf
2025-09-19 20:23 - 2025-09-19 20:23 - 000031712 _____ C:\Users\safro\Downloads\bezplamenne-cajove-svicky-na-baterie-nancia-realisticke-jasne-blikajici-elektricka-svickova-lampa.webp
2025-09-19 20:02 - 2025-09-19 20:02 - 010196144 _____ C:\Users\safro\Downloads\HALLOWEENSKÝ- DUŠIČKOVÝ flexifilní plán.pdf
2025-09-19 18:50 - 2025-10-05 08:49 - 000000000 ____D C:\Program Files\Recuva
2025-09-19 18:50 - 2025-09-19 18:50 - 000001707 _____ C:\Users\Public\Desktop\Recuva.lnk
2025-09-19 18:50 - 2025-09-19 18:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2025-09-19 18:46 - 2025-09-19 18:47 - 096538504 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe
2025-09-19 18:25 - 2025-09-19 18:25 - 071297301 _____ C:\Users\safro\Downloads\HUDEBNÍ HRÁTKY PODZIM UČITELÉ.zip
2025-09-19 18:23 - 2025-09-19 18:23 - 009616736 _____ (Malwarebytes) C:\Users\safro\Desktop\adwcleaner.exe
2025-09-18 20:10 - 2025-09-18 20:10 - 020830420 _____ C:\Users\safro\Downloads\Bingo-podzim.zip
2025-09-18 19:44 - 2025-09-18 19:44 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2025-09-17 21:43 - 2025-09-17 21:43 - 003721734 _____ C:\Users\safro\Downloads\Ja-mam-kdo-ma-Podzim(1).zip
2025-09-17 21:23 - 2025-09-17 21:23 - 011442877 _____ C:\Users\safro\Downloads\Podzimni-sklizen-1.pdf
2025-09-17 21:21 - 2025-09-17 21:21 - 057937341 _____ C:\Users\safro\Downloads\Podzimni-sklizen.pdf
2025-09-17 18:25 - 2025-09-17 18:25 - 012550345 _____ C:\Users\safro\Downloads\Podzimni-zavarovani.zip
2025-09-17 18:23 - 2025-09-17 18:23 - 001662887 _____ C:\Users\safro\Downloads\Podzimni-girlanda.zip
2025-09-17 18:22 - 2025-09-17 18:22 - 013002487 _____ C:\Users\safro\Downloads\Podzimni-aktivity.zip
2025-09-17 18:17 - 2025-09-17 18:17 - 003721734 _____ C:\Users\safro\Downloads\Ja-mam-kdo-ma-Podzim.zip
2025-09-17 17:14 - 2025-09-17 17:28 - 000000000 ____D C:\Users\safro\Desktop\seznamy 2025
2025-09-17 17:14 - 2025-09-17 17:14 - 000081528 _____ C:\Users\safro\Downloads\prilohy_78958.zip
2025-09-17 17:08 - 2025-09-17 17:08 - 000012677 _____ C:\Users\safro\Desktop\stav dovolených 8-2025.xlsx
2025-09-17 14:15 - 2025-09-17 14:15 - 035244911 _____ C:\Users\safro\Downloads\STRAŠIDELNÁ STEZKA.zip
2025-09-16 20:05 - 2025-09-16 20:05 - 023668825 _____ C:\Users\safro\Downloads\kompetencestrategieOVU-kompletnmaterily.pdf
2025-09-16 19:50 - 2025-09-16 19:50 - 028355751 _____ C:\Users\safro\Downloads\prilohy_1213715.zip
2025-09-16 19:46 - 2025-09-16 19:46 - 155622706 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim.pdf
2025-09-16 19:15 - 2025-09-16 19:15 - 003165032 _____ C:\Users\safro\Downloads\bramborový týden- flexibilní plán-final-kompr.pdf
2025-09-16 19:04 - 2025-09-16 19:04 - 083104464 _____ C:\Users\safro\Downloads\bramborový týden- flexibilní plán-final.pdf
2025-09-16 18:46 - 2025-09-16 18:46 - 083104464 _____ C:\Users\safro\Downloads\bramborový týden- flexibilní plán.pdf
2025-09-16 17:16 - 2025-09-16 17:16 - 000063452 _____ C:\Users\safro\Downloads\Bramb Notis-1.webp
2025-09-16 15:00 - 2025-09-16 15:00 - 000353588 _____ C:\Users\safro\Downloads\PTS-ZV5-004-SPLNENO-Co-je-domov.pdf
2025-09-16 14:58 - 2025-09-16 14:59 - 000291830 _____ C:\Users\safro\Downloads\PTS-ZV5-004-NA-CESTE-100-deti.pdf
2025-09-15 15:00 - 2025-09-15 15:00 - 005950714 _____ C:\Users\safro\Downloads\stezka-knihovna.zip
2025-09-14 21:17 - 2025-09-14 21:17 - 021740251 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-půlené obr. final.pdf
2025-09-14 20:04 - 2025-09-14 20:04 - 021740250 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-3.pdf
2025-09-14 17:42 - 2025-09-14 17:42 - 000497850 _____ C:\Users\safro\Downloads\upravený text zkrácený.pdf
2025-09-14 17:31 - 2025-09-14 17:31 - 016449069 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-2.pdf
2025-09-14 16:28 - 2025-09-14 16:28 - 009624053 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-1.pdf
2025-09-14 16:00 - 2025-09-14 16:00 - 000230760 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(4).jpeg
2025-09-14 16:00 - 2025-09-14 16:00 - 000200521 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(3).jpeg
2025-09-14 16:00 - 2025-09-14 16:00 - 000200521 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(2).jpeg
2025-09-14 15:59 - 2025-09-14 15:59 - 000231326 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena.jpeg
2025-09-14 15:59 - 2025-09-14 15:59 - 000231326 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(1).jpeg
2025-09-14 15:58 - 2025-09-14 15:58 - 000253711 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné(3).jpeg
2025-09-14 15:58 - 2025-09-14 15:58 - 000253711 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné(2).jpeg
2025-09-14 15:58 - 2025-09-14 15:58 - 000253711 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné(1).jpeg
2025-09-14 15:57 - 2025-09-14 15:57 - 000270362 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné.jpeg
2025-09-14 15:54 - 2025-09-14 15:54 - 000280400 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti si ubližují.jpeg
2025-09-14 15:54 - 2025-09-14 15:54 - 000269130 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti si ubližují(1).jpeg
2025-09-14 15:53 - 2025-09-14 15:53 - 000239254 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky(3).jpeg
2025-09-14 15:53 - 2025-09-14 15:53 - 000230233 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky(2).jpeg
2025-09-14 15:52 - 2025-09-14 15:52 - 000267929 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky.jpeg
2025-09-14 15:52 - 2025-09-14 15:52 - 000240288 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky(1).jpeg
2025-09-14 15:08 - 2025-09-14 15:08 - 009367476 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO.pdf
2025-09-13 19:46 - 2025-09-13 19:46 - 000633201 _____ C:\Users\safro\Downloads\EKOABECEDA pro klima_MS_2_scenar_Co se uci stromy.pdf
2025-09-13 15:02 - 2025-09-13 15:02 - 006024668 _____ C:\Users\safro\Downloads\JÁ MÁM, KDO MÁ OVOCE A ZELENINA.zip
2025-09-13 15:01 - 2025-09-13 15:01 - 062375839 _____ C:\Users\safro\Downloads\tp-jablicko.pdf
2025-09-13 14:12 - 2025-09-13 14:12 - 007285874 _____ C:\Users\safro\Downloads\_TŘÍDA SLUNÍČEK (2).pdf
2025-09-13 10:41 - 2025-09-13 10:41 - 000000000 _____ C:\WINDOWS\system32\enrollment.sto
2025-09-12 21:32 - 2025-09-12 21:32 - 036656553 _____ C:\Users\safro\Downloads\Pohadky-pro-hezke-sny-zimni-spaci-final.pdf
2025-09-12 19:26 - 2025-09-12 19:26 - 041035444 _____ C:\Users\safro\Downloads\Jablíčkový týden- flexibilní plán-final.pdf
2025-09-12 19:25 - 2025-09-12 19:25 - 041035442 _____ C:\Users\safro\Downloads\Jablíčkový týden- flexibilní plán.pdf
2025-09-12 19:23 - 2025-09-12 19:23 - 041034143 _____ C:\Users\safro\Downloads\JABLÍČKOVÝ TÝDEN-2.pdf
2025-09-12 16:28 - 2025-09-12 16:28 - 016859319 _____ C:\Users\safro\Downloads\Katalog+FC+2025-2026-1.pdf
2025-09-12 08:42 - 2025-09-12 08:42 - 013910549 _____ C:\Users\safro\Downloads\119-Hrajeme-si-s-kastany-Hravy-Design.pdf
2025-09-11 16:57 - 2025-09-11 16:57 - 000360662 _____ C:\Users\safro\Downloads\Revize_RVP_PV_Zasady_pro_zpracovani__vyhodnocovani_a_upravu_SVP-3951.pdf
2025-09-11 08:06 - 2025-09-11 08:06 - 000495926 _____ C:\Users\safro\Downloads\OznProCleny_2025_08_70340762.pdf
2025-09-10 20:01 - 2025-09-10 20:01 - 001646788 _____ C:\Users\safro\Downloads\RANNI-UKOLY-ZARI-OPRAVENO.pdf
2025-09-09 21:14 - 2025-09-09 21:14 - 000077233 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-09-09 21:14 - 2025-09-09 21:14 - 000077233 _____ C:\WINDOWS\system32\ctac.json
2025-09-09 21:14 - 2025-09-09 21:14 - 000001681 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-09-09 18:59 - 2025-09-09 18:59 - 000302219 _____ C:\Users\safro\Downloads\ŠVP 2020 Obsah vzděláváni- KK.pdf
2025-09-09 09:08 - 2025-09-09 09:09 - 000204447 _____ C:\Users\safro\Downloads\CZ0208000000000860948133_2000022773264106.pdf
2025-09-08 19:31 - 2025-09-08 19:31 - 000412055 _____ C:\Users\safro\Downloads\rvp-pv-manual-svp-tridni-planovani-a4.pdf
2025-09-08 19:31 - 2025-09-08 19:31 - 000406025 _____ C:\Users\safro\Downloads\kurikulum-manual-svp-pro-pv.pdf
2025-09-08 19:22 - 2025-09-08 19:22 - 000595604 _____ C:\Users\safro\Downloads\SVP-Slunicko-se-skolni-druzinou-2024-.pdf
2025-09-08 19:16 - 2025-09-08 19:16 - 003999814 _____ C:\Users\safro\Downloads\TOFLOVÁ - švp 1-aktualizovany-k-1-9-25.pdf
2025-09-08 17:02 - 2025-09-08 17:02 - 000406328 _____ C:\Users\safro\Downloads\rvp-pv-manual-svp-a4.pdf
2025-09-08 16:14 - 2025-09-08 16:14 - 001120027 _____ C:\Users\safro\Downloads\ŠVP 2020-25 2.pdf
2025-09-08 08:38 - 2025-09-08 08:38 - 000481414 _____ C:\Users\safro\Downloads\SVP-2025-novy.pdf
2025-09-08 08:36 - 2025-09-08 08:36 - 000263498 _____ C:\Users\safro\Downloads\opatreni_ministra_RVP_PV_MSMT-17147_2024-4.pdf
2025-09-08 08:35 - 2025-09-08 08:35 - 000709445 _____ C:\Users\safro\Downloads\vyhlaseni_PO_mSVP_ZS_MSMT_6537_2025_3.pdf
2025-09-08 08:29 - 2025-09-08 08:29 - 002266492 _____ C:\Users\safro\Downloads\RVP-PV-kveten-2025.pdf
2025-09-08 08:20 - 2025-09-08 08:22 - 000911144 _____ C:\Users\safro\Downloads\ŠVP MŠ.pdf
2025-09-08 08:18 - 2025-09-08 08:18 - 000312303 _____ C:\Users\safro\Downloads\2025-01-14-tematicky-zakladni-ramec-a-vecny-popis.pdf
2025-09-07 14:47 - 2025-09-07 14:47 - 040932988 _____ C:\Users\safro\Downloads\JABLÍČKOVÝ TÝDEN-1.pdf
2025-09-07 09:45 - 2025-09-07 09:45 - 010194152 _____ C:\Users\safro\Downloads\JABLÍČKOVÝ TÝDEN.pdf
2025-09-06 09:42 - 2025-09-06 09:42 - 036656553 _____ C:\Users\safro\Downloads\Pohádky pro hezké sny- zimní spáči-final.pdf
2025-09-06 09:28 - 2025-09-06 09:28 - 036656553 _____ C:\Users\safro\Downloads\Pohádky pro hezké sny- zimní spáči-1.pdf
2025-09-06 09:07 - 2025-09-06 09:07 - 017803918 _____ C:\Users\safro\Downloads\Pohádky pro hezké sny- zimní spáči.pdf
2025-09-05 17:15 - 2025-06-18 02:32 - 000725976 _____ (Intel) C:\WINDOWS\system32\libvpl.dll
2025-09-05 17:15 - 2025-06-18 02:32 - 000619672 _____ (Intel) C:\WINDOWS\SysWOW64\libvpl.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 027976568 _____ (Intel Corporation) C:\WINDOWS\system32\mfxplugin64_hw.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 020700552 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\mfxplugin32_hw.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 001982320 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-09-05 17:15 - 2025-06-18 02:31 - 001982320 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-09-05 17:15 - 2025-06-18 02:31 - 001538904 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-09-05 17:15 - 2025-06-18 02:31 - 001538904 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-09-05 17:15 - 2025-06-18 02:31 - 001446768 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 001160056 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 000963496 _____ (Intel Corporation) C:\WINDOWS\system32\libmfxhw64.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 000724344 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\libmfxhw32.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 000609224 _____ (Intel Corporation) C:\WINDOWS\system32\intel_gfx_api-x64.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 000505176 _____ C:\WINDOWS\system32\ze_tracing_layer.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 000469480 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\intel_gfx_api-x86.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 000410968 _____ C:\WINDOWS\system32\ze_loader.dll
2025-09-05 17:15 - 2025-06-18 02:31 - 000171888 _____ C:\WINDOWS\system32\ze_validation_layer.dll

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-10-05 14:16 - 2024-12-26 21:07 - 000000000 ____D C:\Users\safro\AppData\Local\Malwarebytes
2025-10-05 14:14 - 2024-12-03 20:24 - 000046306 _____ C:\Users\safro\Desktop\FRST.txt
2025-10-05 14:13 - 2022-09-14 19:09 - 000000000 ____D C:\FRST
2025-10-05 14:05 - 2022-02-08 20:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-10-05 14:03 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-05 14:03 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-05 14:03 - 2020-06-13 15:36 - 000000000 ____D C:\Users\safro\AppData\Local\Packages
2025-10-05 09:45 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-05 08:55 - 2022-05-12 15:36 - 000000000 ____D C:\ProgramData\Piriform
2025-10-05 08:46 - 2025-02-04 20:29 - 000000000 ____D C:\WINDOWS\Minidump
2025-10-05 08:38 - 2025-01-30 21:20 - 001692324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-10-05 08:38 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-10-05 08:32 - 2025-01-30 19:37 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2025-10-05 08:31 - 2025-01-30 21:15 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-05 08:31 - 2025-01-30 21:11 - 000011972 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-10-05 08:31 - 2025-01-30 21:11 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-05 08:31 - 2025-01-30 19:50 - 000000000 ____D C:\Users\safro
2025-10-05 08:31 - 2020-09-15 19:42 - 000012288 ___SH C:\DumpStack.log.tmp
2025-10-05 08:31 - 2020-06-13 15:36 - 000000000 __SHD C:\Users\safro\IntelGraphicsProfiles
2025-10-05 08:31 - 2020-03-13 07:10 - 000000000 ___HD C:\Intel
2025-10-04 21:08 - 2025-01-30 21:15 - 000003168 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3530282796-2492871232-3359154168-1001
2025-10-04 20:59 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-04 20:59 - 2020-03-13 07:20 - 000000000 ____D C:\Program Files\Microsoft Office
2025-10-04 18:36 - 2025-01-30 21:15 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3530282796-2492871232-3359154168-1001
2025-10-04 18:36 - 2025-01-30 21:15 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3530282796-2492871232-3359154168-1001
2025-10-04 18:36 - 2020-09-15 18:57 - 000002391 _____ C:\Users\safro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-10-04 17:11 - 2023-11-23 17:38 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-10-04 17:11 - 2020-06-13 15:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-10-04 17:00 - 2025-01-30 21:15 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-10-04 17:00 - 2020-06-13 15:45 - 000001081 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-10-04 13:50 - 2020-06-13 15:39 - 000000000 ____D C:\Users\safro\AppData\Roaming\Microsoft\Excel
2025-10-04 08:19 - 2020-06-13 15:48 - 000000000 ____D C:\Users\safro\AppData\Roaming\Microsoft\Word
2025-10-04 08:03 - 2020-07-16 19:49 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-10-04 08:03 - 2020-07-16 19:49 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-10-03 19:22 - 2023-07-24 17:26 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2025-10-03 19:21 - 2020-06-13 15:37 - 000000000 ____D C:\Users\safro\AppData\Roaming\hpqLog
2025-10-02 16:31 - 2025-05-12 15:06 - 000000000 ____D C:\Users\safro\Desktop\vtipné obrázky
2025-10-02 16:19 - 2025-01-30 21:15 - 000003542 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-10-01 19:51 - 2020-06-18 07:33 - 000000000 ____D C:\Users\safro\AppData\Local\D3DSCache
2025-09-30 18:44 - 2025-01-30 21:15 - 000002834 _____ C:\WINDOWS\system32\Tasks\HPOneAgentRepairTask
2025-09-30 14:53 - 2020-07-21 23:31 - 000002395 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2025-09-30 14:53 - 2020-07-21 23:30 - 000000000 ____D C:\Program Files (x86)\CCleaner Browser
2025-09-23 16:56 - 2024-04-17 14:32 - 000002081 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-09-23 16:56 - 2024-04-17 14:32 - 000002069 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2025-09-23 16:45 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-09-23 16:42 - 2020-06-13 16:22 - 000000000 ____D C:\Users\safro\AppData\Local\Adobe
2025-09-21 13:05 - 2025-02-12 20:39 - 000244800 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2025-09-20 19:23 - 2020-03-13 07:19 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2025-09-19 18:53 - 2020-06-17 07:02 - 000000000 ____D C:\Users\safro\AppData\Local\CrashDumps
2025-09-19 18:25 - 2019-04-19 20:34 - 000000000 ____D C:\ProgramData\HP
2025-09-18 19:38 - 2020-06-20 08:46 - 000002309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-09-18 19:38 - 2020-06-20 08:46 - 000002268 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-09-14 07:54 - 2025-01-30 21:15 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-09-14 07:54 - 2025-01-30 21:15 - 000003514 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-09-13 10:41 - 2020-03-13 07:14 - 000000000 ____D C:\ProgramData\Package Cache
2025-09-09 21:57 - 2025-01-30 21:10 - 000587608 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-09-09 21:56 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-09-09 21:56 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-09-09 21:55 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-09-09 21:55 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-09-09 21:27 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-09-09 21:27 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2025-09-09 21:14 - 2025-01-30 21:11 - 003270656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-09-05 17:10 - 2020-06-13 15:48 - 000000000 ____D C:\Users\safro\AppData\Roaming\Microsoft\Office

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by safro (05-10-2025 14:18:09)
Running from C:\Users\safro\Desktop
Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) (2025-01-30 19:15:40)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3530282796-2492871232-3359154168-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3530282796-2492871232-3359154168-503 - Limited - Disabled)
Guest (S-1-5-21-3530282796-2492871232-3359154168-501 - Limited - Disabled)
safro (S-1-5-21-3530282796-2492871232-3359154168-1001 - Administrator - Enabled) => C:\Users\safro
WDAGUtilityAccount (S-1-5-21-3530282796-2492871232-3359154168-504 - Limited - Disabled)
WsiAccount (S-1-5-21-3530282796-2492871232-3359154168-1008 - Limited - Disabled) => C:\Users\WsiAccount

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Security (Enabled - Up to date) {DF8BEACB-94C9-218A-73AD-A78362A8C516}
AV: ESET Security (Enabled - Up to date) {89B55CC4-3881-78B2-11E2-479AE0371896}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}
FW: ESET Firewall (Enabled) {E7B06BEE-DEA6-20D2-58F2-0EB69C7B826D}
FW: ESET Firewall (Enabled) {B18EDDE1-72EE-79EA-3ABD-EEAF1EE45FED}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acronis Drivers (HKLM\...\{7C36ADC0-5219-4D31-90D1-4211321481EF}) (Version: 25.8.39216 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}) (Version: 25.8.39216 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}Visible) (Version: 25.8.39216 - Acronis)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 25.001.20693 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601120}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
ApowerCompress V1.1.18 (HKLM-x32\...\{10998dc6-e8e2-48ef-9378-0db3d4c7f32a}_is1) (Version: 1.1.18 - Wangxu Technology Co.,Ltd.)
Audacity 3.7.5 (HKLM\...\Audacity_is1) (Version: 3.7.5 - Audacity Team)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 6.39 - Piriform)
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.0.967.1130 - Piriform)
CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 140.0.32151.209 - Autoři prohlížeče CCleaner Browser)
CCleaner Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1067.0 - Piriform Software) Hidden
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1583.3 - Piriform Software) Hidden
CEWE fotosvet (HKLM\...\CEWE fotosvet) (Version: 7.3.3 - CEWE Stiftung u Co. KGaA)
CPUID HWMonitor 1.54 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.54 - CPUID, Inc.)
CrystalDiskInfo 8.17.5 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.17.5 - Crystal Dew World)
Dynamic Application Loader Host Interface Service (HKLM\...\{9DE7A0A5-C13D-4FDD-B78B-53C744C82F1A}) (Version: 1.0.0.0 - Intel Corporation) Hidden
ESET Security (HKLM\...\{32DA3D18-091D-4B85-BFD4-C17C514674ED}) (Version: 18.2.18.0 - ESET, spol. s r.o.)
Express Burn Disc Burning Software (HKLM-x32\...\ExpressBurn) (Version: 10.30 - NCH Software)
Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 9.26 - NCH Software)
FastStone Photo Resizer 4.4 (HKLM-x32\...\FastStone Photo Resizer) (Version: 4.4 - FastStone Corporation)
Google Chrome (HKLM\...\{15971136-C56A-3015-AC9D-ED17B8F94952}) (Version: 140.0.7339.186 - Google LLC)
HappyFoto (HKLM\...\{621A70CA-32A5-4F50-A66C-C9C792580415}_is1) (Version: - Happy Foto CZ)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 11.0.0.320 - Huawei Technologies Co., Ltd.)
HP Client Security Manager (HKLM\...\{456CC699-FD29-4835-9CE6-BB3E63DC76E3}) (Version: 9.5.3.2908 - HP Inc.) Hidden
HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 9.5.3.2908 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP Hotkey Support (HKLM-x32\...\{6606696F-B31A-48B7-B05D-FB5DDFAD9FAB}) (Version: 6.2.52.1 - HP Inc.)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version: - )
HP Notifications (HKLM-x32\...\{84937F28-9CB4-49E7-A2CF-E32D97E6DAE6}) (Version: 1.1.28.1 - HP)
HP One Agent (HKLM\...\{7CF09040-C14A-4FAA-B61A-1A7F2BDE3719}) (Version: 1.1.973.9172 - HP Inc.)
HP One Agent (HKLM\...\{7EFF7A5C-E41B-4E5C-B075-08C00AA3F2EB}) (Version: 1.1.973.9172 - HP Inc.) Hidden
HP Security Update Service (HKLM\...\{74C6C478-7AD6-4923-AC3A-B5C837C7B517}) (Version: 4.4.26.1391 - HP Inc.)
HP System Default Settings (HKLM-x32\...\{0543AB37-B3F9-4948-A6D7-AB574271DEAC}) (Version: 1.4.9.2 - HP Inc.) Hidden
HP Wolf Security - Console (HKLM\...\{75B6E6CE-A9AC-4801-A4A8-B22098A8355C}) (Version: 11.1.4.895 - HP Inc.)
HP Wolf Security (HKLM\...\{8CD49D08-67F1-11F0-9844-000C29910851}) (Version: 4.4.26.1391 - HP Inc.)
HP Wolf Security Application Support for Chrome 138.0.7204.170 (HKLM\...\{6C174EDA-F80B-4926-B659-F08E5C7BBC59}) (Version: 4.4.26.1406 - HP Inc.) Hidden
HP Wolf Security Application Support for Sure Sense (HKLM\...\{0B429B75-9F00-490C-89C6-BF7A97FCE2F0}) (Version: 4.4.26.1391 - HP Inc.) Hidden
HPSSupply (HKLM-x32\...\{7902E313-FF0F-4493-ACB1-A8147B78DCD0}) (Version: 2.1.1.0000 - Hewlett Packard Development Company L.P.)
Intel(R) Chipset Device Software (HKLM\...\{00C43022-CFDA-4942-9D3F-04199C91C939}) (Version: 10.1.18121.8164 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{37942a92-9e3f-4d70-9b5c-5955cbc54505}) (Version: 10.1.18121.8164 - Intel(R) Corporation)
Intel(R) Icls (HKLM\...\{AE33809B-734E-4A79-BBDC-0DDE03950065}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) LMS (HKLM\...\{4479B4B8-D77B-474A-ABC5-1E5A4356F7DE}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1A9FE6B4-801A-4AF0-AEDB-EA49BD80C9F2}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2205.15.0.2623 - Intel Corporation)
Intel(R) Management Engine Driver (HKLM\...\{F0A3D842-E346-45C5-9546-90FEFD477F6E}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.7261 - Intel Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Malwarebytes version 5.4.0.213 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.4.0.213 - Malwarebytes)
Microsoft .NET Host - 7.0.20 (x64) (HKLM\...\{EE5EB03B-D65C-4991-848E-2C6E024326DB}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.20 (x64) (HKLM\...\{B0FC828F-678C-4868-9B5B-99639758E6F3}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 7.0.20 (x64) (HKLM\...\{221BB52A-B763-4C9D-AA62-4B0B6C9AAD62}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft 365 - cs-cz (HKLM\...\O365HomePremRetail - cs-cz) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 - sk-sk (HKLM\...\O365HomePremRetail - sk-sk) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 Apps pro firmy - cs-cz (HKLM\...\O365BusinessRetail - cs-cz) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft ASP.NET Core 7.0.20 - Shared Framework (x64) (HKLM-x32\...\{6c2f4b5b-86d2-4aff-bf79-d1e73cc20ab3}) (Version: 7.0.20.24269 - Microsoft Corporation)
Microsoft ASP.NET Core 7.0.20 Shared Framework (x64) (HKLM\...\{BD401329-F877-391C-9E5A-FEB423C5A196}) (Version: 7.0.20.24269 - Microsoft Corporation) Hidden
Microsoft Bing Service (HKLM-x32\...\{27990F25-A90A-4CE5-868E-1A1BB70A58EE}) (Version: 2.0.0.7 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\{871D86E3-8175-34F3-9C07-7679EC1CF1D1}) (Version: 141.0.3537.57 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 140.0.3485.94 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\OneDriveSetup.exe) (Version: 25.174.0907.0003 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Teams) (Version: 1.8.00.21151 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.31301 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{BACA8ED0-DB44-468A-9D76-7D4588B90D60}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{3FED85F2-4004-4F8A-B65B-DDC1F6013FAA}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM\...\{72C29BED-666F-4E5E-BC49-DF44C890742E}) (Version: 56.80.15245 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM-x32\...\{362ea044-f96f-45c7-b59f-0dbe5ca98ff4}) (Version: 7.0.20.33720 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 143.0.4 (x64 cs)) (Version: 143.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 132.0.2 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.19231.20072 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.19029.20156 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Pentablet (HKLM\...\{5DAB8C1A-6D8E-467D-BE62-AC13087AA950}_is1) (Version: 3.4.3.230310 - XPPen Technology)
PosteRazor (HKLM-x32\...\PosteRazor_is1) (Version: 1.5.2 - Alessandro Portale)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Skype 8.134 (HKLM-x32\...\{6F9453A2-F32E-4BB7-9E60-F4EAD9B799A9}) (Version: 8.134.0.202 - Skype Technologies S.A.)
Skype verze 8.134 (HKLM-x32\...\Skype_is1) (Version: 8.134 - Skype Technologies S.A.) Hidden
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.3.0.9267 - Microsoft Corporation)
Vcows 2.0.6 (HKLM\...\{E56AB601-3746-4243-BD26-09D63162C7AA}_is1) (Version: 2.0.6 - Vcows Software)
Windows Driver Package - HP Inc. BrCow_4_4_26_1391 ActivityMonitor (07/23/2025 4.4.26.1391) (HKLM\...\35EE803A85F6C575E85E83A231CEF99D88E1397A) (Version: 07/23/2025 4.4.26.1391 - HP Inc.) Hidden
Windows Driver Package - HP Inc. BrFilter_4_4_26_1391 ActivityMonitor (07/23/2025 4.4.26.1391) (HKLM\...\24DED937F1CF88463C61BCEEC433424A2E9175CB) (Version: 07/23/2025 4.4.26.1391 - HP Inc.) Hidden
Windows Driver Package - HP Inc. sselam_4_4_19_828 AntiVirus (08/09/2024 4.4.19.828) (HKLM\...\FB93285F183DE6985F684AEE5F637905935D05BF) (Version: 08/09/2024 4.4.19.828 - HP Inc.) Hidden

Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-11] ()
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2025-09-23] ()
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2024-12-11] (INTEL CORP) [Startup Task]
Audio Controls -> C:\Program Files\WindowsApps\22094SynapticsIncorporate.AudioControls_1.3.99.0_x64__qt57b6kdvhcfw [2024-12-11] (Synaptics Hong Kong Limited, Taiwan Branch (H.K.))
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation)
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2025-09-29] (Sparse Package)
HP Desktop Support Utilities -> C:\Program Files\WindowsApps\AD2F1837.HPDesktopSupportUtilities_7.0.8.0_x64__v10z8vjag6ke6 [2025-01-28] (HP Inc.)
HP JumpStarts -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStarts_1.10.1627.0_x64__v10z8vjag6ke6 [2025-01-08] (HP Inc.)
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_2.8.1.0_x64__v10z8vjag6ke6 [2025-09-20] (HP Inc.)
HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.4.17.0_x64__v10z8vjag6ke6 [2025-08-22] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_161.1.1087.0_x64__v10z8vjag6ke6 [2025-08-29] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.47.41.0_x64__v10z8vjag6ke6 [2025-09-12] (HP Inc.)
HP System Information -> C:\Program Files\WindowsApps\AD2F1837.HPSystemInformation_8.10.45.0_x64__v10z8vjag6ke6 [2025-05-20] (HP Inc.)
Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2024-12-11] (INTEL CORP)
Local Artificial Intelligence Manager -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2025-10-04] ()
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2025-10-02] ()
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation) [MS Ad]
Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2025-10-04] ()
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2025-10-04] ()
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0 [2025-09-25] (Spotify AB) [Startup Task]
WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-22] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8000.616.304.0_x64__8wekyb3d8bbwe [2025-09-10] (Microsoft Corp.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{82A6D7A6-FC2E-4DFD-AAEF-E3BBF9AD71AD}\localserver32 -> C:\Program Files\Fotolab\CEWE fotosvet\AutoBookService.exe () [File not signed]
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BromiumOverlay_4_4_26_1391] -> {6CDCC3E8-D8FF-46EF-B8BE-63A0593C7E4E} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ShellIconOverlayIdentifiers: [ AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers-x32: [ BromiumOverlay_4_4_26_1391] -> {6CDCC3E8-D8FF-46EF-B8BE-63A0593C7E4E} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2025-09-07] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-22] () [File not signed]
ContextMenuHandlers2: [Bromium TrustDrive Context Menu_4_4_26_1391] -> {5F4F5529-DD35-4B9F-812F-A5B0B3FF5492} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-02] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers3: [SureSense_ScanFile_4_4_26_1391] -> {1003406D-B16C-4A93-B2F0-13CCAAD250E2} => C:\Program Files\HP\Sure Click\ApplicationSupport\sure_sense\4.4.26.1391\SureSenseShellExt.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers3: [vSentry_TrustFile_4_4_26_1391] -> {833378FE-1986-46BA-9B4E-F8F1D9B29D00} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2024-05-22] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-22] () [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-02] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2024-05-22] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2009-10-15 12:13 - 2009-10-15 12:13 - 000061440 _____ () [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPTools.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000964096 _____ () [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\LEDMXMLObjects.dll
2022-06-22 19:41 - 2022-06-22 19:41 - 000105984 _____ () [File not signed] C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll
2025-08-15 02:15 - 2025-08-15 02:15 - 000030720 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\Acrobat Elements\ContextMenuShim64.cze
2020-04-30 13:40 - 2020-04-30 13:40 - 000382464 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPCPFelica.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000338432 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPDevice2.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000456192 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPDevice5.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000032768 _____ (HP) [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPHTTPProxy.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000031744 _____ (HP) [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPServiceCommunicator.dll
2023-10-05 16:35 - 2023-09-12 10:52 - 008382976 _____ (wondershare) [File not signed] C:\ProgramData\Wondershare\wsServices\WsidClient.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe:MBAM.Zone.Identifier [224]
AlternateDataStreams: C:\Users\safro\Downloads\dům 1.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\safro\Downloads\dům 2.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\sharepoint.com -> hxxps://zuzanasafrova-files.sharepoint.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2022-09-18 15:57 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 62.24.64.2 - 8.8.8.8
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt68cx21x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Pozadí plochy.bmp
HKU\S-1-5-21-3530282796-2492871232-3359154168-1008\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
HKLM\...\StartupApproved\Run: => "PenTablet"
HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\StartupFolder: => "CEWE služba na pozadí.lnk"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_8B3575D364394B552A9C25D557FBDA68"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "BingSvc"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "Mozilla-Firefox-308046B0AF4A39CB"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D0B184A7-6D52-4C48-897D-140BD7A6F353}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{DABFF653-A5E5-4521-B6AF-1B5F60D10FB5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{F8A4B796-F877-4E10-A712-8065DAF0DE52}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{4210D988-5DC2-44D2-80D6-4E9DC5386A6B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{F95611D3-953E-47B0-8523-AA5803A2BF78}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{E351475D-8610-4035-AAE2-F67051A27598}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{266E7165-18AD-41C6-B9A2-22F7C72DBB11}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{1EDA986E-46DE-4A4D-BC45-FF2B9C5D0FB7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{EA176052-6DF6-4AFD-B602-C61960B4F133}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{171D8BFC-D7DB-4D77-97B1-73DC2C3A61D3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{86B628A2-9658-417C-A3D7-13F163631063}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D8ABF27C-8370-4448-B670-3B70E3AA6537}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F8253C58-A590-4860-AEB3-9C439AAAE94C}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24295.402.3249.3850_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A8B45281-004B-46BD-96BC-0E002774730B}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24295.402.3249.3850_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9386FE13-9B9B-4085-B8D7-C7C9F8192F91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3B2A4243-1E39-4C08-B1D0-AC9FD6F43376}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{745668C2-1AEB-4D2E-945E-B1A7E74C15E6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5158859D-AE2A-4FA9-8CF7-A99A858BC518}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{0E6A422F-B807-440E-A9BA-8423B81DC310}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerCompress\ApowerCompress.exe (Apowersoft Ltd -> Wangxu Technology Co.,Ltd.)
FirewallRules: [{614A9769-FD95-46F3-A710-CC73E76EB958}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerCompress\ApowerCompress.exe (Apowersoft Ltd -> Wangxu Technology Co.,Ltd.)
FirewallRules: [{79588B28-F54B-4D3A-9055-F764571B0DC6}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{A7D7256C-5086-4E3C-AF56-7F861233E55E}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{9847D37C-418A-4F12-8172-542853480EDF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{4D441A47-E117-4CF7-82EF-3660804B0D0B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C7105644-92C7-4514-AA67-ED1F1C70800B}] => (Allow) C:\hp\Diagnostics\PSDR\HPDiagnosticCoreUI.exe (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{9FACFD9B-83E9-4BE6-BB12-0B62F0DDF13E}] => (Allow) C:\hp\Diagnostics\PSDR\HPDiagnosticCoreUI.exe (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{C96A3876-7F5F-452E-8C47-ACF4E1A33364}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{72D8F8DE-F138-40FC-86A0-71F6777ABB83}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E92455EB-3D07-4AF4-96F0-4824AFBC1A32}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FA8393A4-7A7A-499D-8DEC-522EB14D526D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{21B1D686-A71F-4EEC-BA63-908EB5DC0D86}] => (Allow) C:\Program Files\HP\Sure Click\4.4.26.1391\servers\manifests\chrome\brchromium\136.0.7103.179\BrChrome.exe (Bromium UK Limited -> HP)
FirewallRules: [{286AC0B9-7F5E-491A-8635-E349017E323A}] => (Allow) C:\Users\safro\Downloads\vcows-ppc(1).exe (SMARTSHARE CO., LIMITED -> Vcows)
FirewallRules: [{978412E6-E782-4B5F-9AA9-0BF162D6F457}] => (Allow) C:\Users\safro\Downloads\vcows-ppc(1).exe (SMARTSHARE CO., LIMITED -> Vcows)
FirewallRules: [{69569FA5-39A6-4140-B102-06707788119E}] => (Allow) C:\Program Files (x86)\Vcows\Vcows.exe (PixelVista Co., Limited -> Vcows Software)
FirewallRules: [{7E364A1D-53B4-4FAE-9FD6-4E07C885B1EE}] => (Allow) C:\Program Files (x86)\Vcows\Update.exe (PixelVista Co., Limited -> )
FirewallRules: [{08A5D1E5-CCD3-4250-834E-D820FBD42586}] => (Allow) C:\Program Files (x86)\Vcows\DownLoadProcess.exe => No File
FirewallRules: [{D26A2B5F-F9A3-400A-844E-E60297326AAD}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\AI-Center.exe => No File
FirewallRules: [{5865A713-1826-4322-986B-1BA39D99DF6A}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\video\face_track\face_track_server.exe => No File
FirewallRules: [{9D3D0A79-1351-4A65-9D78-3ADBA7D551E6}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\AI-Center.exe => No File
FirewallRules: [{70A58689-6C47-4819-ACB6-4C52EDBFE58F}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\ZNCJPackage\ZNCJ_Server.exe => No File
FirewallRules: [{F5DBF784-159F-4F4D-8B2E-6FFD3A46B252}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\VcowsPrimeVideo.exe => No File
FirewallRules: [{61F71D58-A0C3-49B8-8A09-09264C7993EB}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\data\bin\native\sheller.exe => No File
FirewallRules: [{4CCEB92C-CD82-43EA-81C8-2C4EBA99FDF0}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\VcowsNetflix.exe => No File
FirewallRules: [{3EA9590F-E33B-4BA2-AB86-97AE48DEDCC7}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\data\bin\native\sheller.exe => No File
FirewallRules: [{704A05C1-8F9E-47C4-8494-38365EA1181F}] => (Allow) C:\Program Files\HP\Sure Click\ApplicationSupport\chrome\4.4.26.1406\brchromium\138.0.7204.170\BrChrome.exe (Bromium UK Limited -> HP)
FirewallRules: [{BF5583F1-4416-4DFE-BC2D-61599D246CCB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{07B1FA18-81D1-4FE7-81E9-2D42697969B7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{5CA62EF5-D5C1-490E-853A-472BAF171317}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{DD2FDBA6-1AEF-4754-AD89-D1A5B81C4640}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A8817300-6708-484E-A5A8-9C7BAA362CC5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{E08CDCA7-7E6E-475D-96F6-56F45549B74A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{68090CF7-7D59-47DB-A621-671DD7DE0196}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{356E3558-F76C-4ED7-9B92-6040C83B667E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{0D52429E-7744-42AB-A880-260703BBF3A1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1E85FC00-C256-4296-88B7-946656CB5B02}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{82B4EB75-0E96-42A0-ADB7-DE8EEFB5794A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B23C634E-E005-4C05-8229-2F3DB9C71B6A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{C684FAE9-36AB-4B6E-8A8F-100276F02336}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{AE062DCB-BED0-4106-9F0A-094B5352BF2A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{DEC3A504-8C94-4865-A307-1EA149C062B7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7734E1AE-0046-41E3-B98F-931511C1E182}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)

==================== Restore Points =========================

03-10-2025 20:14:30 Windows Update
03-10-2025 20:14:32 Windows Update
03-10-2025 20:14:34 Windows Update
05-10-2025 08:24:37 Grab_MSIExecute
05-10-2025 08:29:26 Grab_MSIExecute
05-10-2025 08:31:21 Grab_MSIExecute
05-10-2025 09:10:30 Grab_MSIExecute
05-10-2025 09:23:47 Grab_MSIExecute

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (10/05/2025 02:03:39 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/05/2025 02:03:39 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: 204c4a65-bc6e-4acb-a28e-a31e09656f00 Correlation ID: ac4dce89-95be-40e6-9cac-156533b27d82 Timestamp: 2025-10-05 12:03:24Z

Error: (10/05/2025 02:03:35 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/05/2025 02:03:35 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: 204c4a65-bc6e-4acb-a28e-a31e09656f00 Correlation ID: ac4dce89-95be-40e6-9cac-156533b27d82 Timestamp: 2025-10-05 12:03:24Z

Error: (10/05/2025 02:03:31 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/05/2025 02:03:31 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: 204c4a65-bc6e-4acb-a28e-a31e09656f00 Correlation ID: ac4dce89-95be-40e6-9cac-156533b27d82 Timestamp: 2025-10-05 12:03:24Z

Error: (10/05/2025 02:03:27 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/05/2025 02:03:27 PM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: 204c4a65-bc6e-4acb-a28e-a31e09656f00 Correlation ID: ac4dce89-95be-40e6-9cac-156533b27d82 Timestamp: 2025-10-05 12:03:24Z


System errors:
=============
Error: (10/05/2025 08:36:13 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -1878589247. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (10/05/2025 08:33:19 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/05/2025 08:33:19 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (10/05/2025 08:31:14 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1096) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo. Systém Windows nemohl použít nastavení zásad týkající se registru pro objekt zásad skupiny LocalGPO. Nastavení zásad skupiny nebude vyřešeno, dokud nebude vyřešena tato událost. Další informace o názvu souboru a cestě, které jsou příčinou selhání, zobrazíte pomocí detailů událostí.

Error: (10/05/2025 08:31:13 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba CxUIUSvc neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/05/2025 08:31:13 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby CxUIUSvc bylo dosaženo časového limitu (45000 ms).

Error: (10/05/2025 08:31:09 AM) (Source: Microsoft-Windows-WER-SystemErrorReporting) (EventID: 1001) (User: NT AUTHORITY)
Description: 0x0000001a (0x0000000000041791, 0xffff9280063ef910, 0xffffca0198743db0, 0x0000000000020001)C:\WINDOWS\MEMORY.DMPc183d625-3b14-4a63-bf13-20b644c6d1ea

Error: (10/05/2025 08:30:50 AM) (Source: volmgr) (EventID: 162) (User: )
Description: Soubor se stavem systému byl úspěšně vygenerován.


CodeIntegrity:
===============
Date: 2025-10-05 14:03:35
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: HP R03 Ver. 02.22.00 12/30/2024
Motherboard: HP 8599
Processor: Intel(R) Core(TM) i5-9500 CPU @ 3.00GHz
Percentage of memory in use: 52%
Total physical RAM: 16222.29 MB
Available physical RAM: 7770.58 MB
Total Virtual: 32606.29 MB
Available Virtual: 22838.42 MB

==================== Drives ================================

Drive c: (Windows ) (Fixed) (Total:475.92 GB) (Free:130.74 GB) (Model: WDC PC SN520 SDAPNUW-512G-1006) (Protected) NTFS
Drive f: (2020 Elements) (Fixed) (Total:2794.49 GB) (Free:2716.13 GB) (Model: WD Elements 25A3 USB Device) NTFS
Drive g: (Elements) (Fixed) (Total:1862.98 GB) (Free:1558.24 GB) (Model: WD Elements 107C USB Device) NTFS

\\?\Volume{52f48983-432c-4b4e-a5ca-5a3c84de645a}\ () (Fixed) (Total:0.74 GB) (Free:0.11 GB) NTFS
\\?\Volume{f2dd5105-3d43-4ecb-9619-823b99375fc3}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.15 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 390A4304)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: D954268B)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==========================================================
Disk: 2 (Size: 2794.5 GB) (Disk ID: 16F2A91F)

Partition: GPT.

==================== End of Addition.txt =======================
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu

#2 Příspěvek od JaRon »

Ahoj,
spust prikazovy riadok ako spravca (cmd)
1. do cierneho okna napis
sfc /scannow
2. do cierneho okna napis
chkdsk /f

Daj odsuhlasenie pri dalsom starte arestartuj PC
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#3 Příspěvek od Ecinazuz »

nějak mi to nejde
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#4 Příspěvek od Ecinazuz »

nebo to neumím :(
scan příkaz.jpg
scan příkaz.jpg (44.47 KiB) Zobrazeno 1686 x
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu

#5 Příspěvek od JaRon »

cmd MUSIS spustit ako spravca :!:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#6 Příspěvek od Ecinazuz »

no- nevím proč to nešlo normálně, až přes powerschel,
podílám scan obr.
Přílohy
Snímek obrazovky 2025-10-05 181027.jpg
Snímek obrazovky 2025-10-05 181027.jpg (51.85 KiB) Zobrazeno 1673 x
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu

#7 Příspěvek od JaRon »

Super, po restarte bude skontrolovany disk
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#8 Příspěvek od Ecinazuz »

restart už proběhl, ale žádný report nemám
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu

#9 Příspěvek od JaRon »

Pokial si nevidel ziadne hlasky o vadnych sektoroch je to OK
Urob este podobne s prikazoveho riadku
mdsched
a postupuj podla pokynov
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#10 Příspěvek od Ecinazuz »

omlouvám se za prodlení.. udělal jsem dnes znovu přes powershel - žádné chyby nebyly zjištěny.
Přesto mi dnes asi 4 x pc spadl a restartoval
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu

#11 Příspěvek od JaRon »

Vloz oba aktualne logy FRST - zajtra docistime
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#12 Příspěvek od Ecinazuz »

ok
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-10-2025
Ran by safro (administrator) on DESKTOP-B59IHMH (HP HP ProDesk 400 G6 MT) (08-10-2025 08:27:17)
Running from C:\Users\safro\Desktop\FRST64.exe
Loaded Profiles: safro & WsiAccount & Administrator
Platform: Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eServiceHost.exe <2>
(C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe ->) (DigitalPersona, Inc. -> Crossmatch, Inc.) C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpCardEngine.exe
(C:\Program Files\HP\Sure Click\servers\BrHostSvr.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\bin\Br-uxendm.exe
(C:\Program Files\HP\Sure Click\servers\BrService.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BrHostSvr.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Bromium UK Limited -> ) C:\Program Files\HP\Sure Click\servers\BrHostHelper\BrHostHelper.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\BrowserPrivacyAndSecurity.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\wa_3rd_party_host_32.exe
(C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\wa_3rd_party_host_64.exe
(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.24401.50.0_x64__cw5n1h2txyewy\WidgetBoard.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\141.0.3537.57\msedgewebview2.exe <7>
(C:\Windows\CxSvc\CxAudioSvc.exe ->) (Synaptics Incorporated -> Conexant) C:\Windows\System32\MicTray64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxEM.exe
(DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\BridgeCommunication.exe
(DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HotKeyServiceUWP.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HPHotkeyNotification.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <14>
(services.exe ->) (Acronis International GmbH -> ) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(services.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Security Update Service\4.4.26.1391\SecurityUpdateService.exe
(services.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BemSvc.exe
(services.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BrService.exe
(services.exe ->) (DigitalPersona, Inc. -> Crossmatch, Inc.) C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Hewlett-Packard Company -> HP) C:\Windows\System32\HPSIsvc.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_d57a8c6bda0aacf4\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\HotkeyServiceDSU.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\LanWlanWwanSwitchingServiceDSU.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HotKeyServiceUWP.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\LanWlanWwanSwitchingServiceUWP.exe
(services.exe ->) (HP Inc. -> HP) C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
(services.exe ->) (HP) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(services.exe ->) (Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_c36cd6406677db45\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_1d1c7ad354f3422f\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c18e9c8eed547b01\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_fd156d877b034329\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_fd156d877b034329\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_2c17521ca0d3f79c\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe
(services.exe ->) (Synaptics Incorporated -> Conexant Systems LLC.) C:\Windows\CxSvc\CxAudioSvc.exe
(services.exe ->) (Wondershare Technology Group Co.,Ltd -> wondershare) C:\ProgramData\Wondershare\wsServices\WsidService.exe
(svchost.exe ->) (Bromium UK Limited -> HP) C:\Program Files\HP\Sure Click\servers\BrConsole.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Client Security Manager\HP.ClientSecurityManager.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.140.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> ) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <6>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [644000 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285616 2025-09-10] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [PenTablet] => C:\Program Files\Pentablet\PenTablet.exe [1151608 2023-03-09] (Hanvon Ugee Technology Co., Ltd. -> XPPEN TECHNOLOGY CO.)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [6206360 2021-03-23] (Acronis International GmbH -> )
HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe [446392 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
HKLM-x32\...\Run: [] => [X]
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\141.0.3537.57\Installer\setup.exe [7665208 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [BingSvc] => C:\Users\safro\AppData\Local\Microsoft\BingSvc\BingSvc.exe [6638496 2022-09-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [693376 2025-10-04] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42449880 2025-09-08] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Run: [MicrosoftEdgeAutoLaunch_8B3575D364394B552A9C25D557FBDA68] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3530282796-2492871232-3359154168-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\HPM1210PrintProc: C:\Windows\System32\spool\prtprocs\x64\HPM1210PP.dll [74240 2012-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\HP ad2a Status Monitor: C:\WINDOWS\system32\hpinkstsad2aLM.dll [476904 2022-03-14] (HP Inc -> HP Inc.)
HKLM\...\Print\Monitors\HPM1210LM: C:\WINDOWS\system32\HPM1210LM.DLL [409088 2012-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files (x86)\CCleaner Browser\Application\140.0.32231.210\Installer\chrmstp.exe [2025-10-06] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\140.0.7339.186\Installer\chrmstp.exe [2025-09-18] (Google LLC -> Google LLC)
AppInit_DLLs: C:\PROGRA~1\HP\SURECL~1\servers\BemHook.dll => No File
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\safro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CEWE služba na pozadí.lnk [2023-07-26]
ShortcutTarget: CEWE služba na pozadí.lnk -> C:\Program Files\Fotolab\CEWE fotosvet\AutoBookService.exe () [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {40399BFE-AFCC-4FA7-81EE-F5439097ADDF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1581568 2025-08-24] (Adobe Inc. -> Adobe Inc.)
Task: {AC50B660-A303-4FB3-B160-69652C9EEED0} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-3530282796-2492871232-3359154168-1008 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-10-06] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3EC33D0B-64CD-46FE-9BAA-CC43475BD936} - System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [3778728 2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9F3A6E60-E7D7-48A4-8CB8-2D5AC323C225} - System32\Tasks\CCleaner Browser Heartbeat Task (Logon) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [3778728 2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B5FEABBF-D588-439B-A99D-1A49ABAC39DA} - System32\Tasks\CCleanerBrowserProtectS-1-5-21-3530282796-2492871232-3359154168-1001 => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowserProtect.exe [1774816 2025-09-11] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {4919C92A-D5B9-4804-B247-AC2F4D880E13} - System32\Tasks\CCleanerUpdateTaskMachineCore => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
Task: {88567D73-D7CB-4EE6-B7F4-0BC61083A718} - System32\Tasks\CCleanerUpdateTaskMachineUA => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
Task: {81DFCA96-1C55-4642-AC07-66EE999CCF58} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem142.0.7416.0{23FE4B8C-3740-48D2-9171-3B6723519324} => C:\Program Files (x86)\Google\GoogleUpdater\142.0.7416.0\updater.exe [6863512 2025-09-15] (Google LLC -> Google LLC)
Task: {5B517483-DB6D-402E-80AD-BB80EA230FF8} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://ABO
Task: {74316B36-7D10-4F03-A92B-D6F22ABDE9B1} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BatteryStatusError
Task: {501CECD4-C31E-4E78-9696-E19F6E82D9D1} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BCF
Task: {3155A5EC-D6CD-4052-A480-FB652FA56E6F} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1 => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM1
Task: {7228309C-D29A-4A93-A7DC-AB9AE08CF761} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2 => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM2
Task: {EEDC1D84-D03A-4880-9827-37B4FA49CBC3} - System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://LaunchUI
Task: {97268EF1-ED16-468E-8A5F-C9DD07EDF538} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags:
Task: {1F862B8E-DB19-427F-A606-9CC6AC45D4CC} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError => C:\WINDOWS\system32\cmd.exe [344064 2025-09-09] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckError
Task: {2D6BCF35-3111-459A-81CC-E1AA30AB298C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [1004040 2025-09-02] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {81F4C074-68D7-4840-99FB-F64AA5437684} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2025-09-02] (HP Inc. -> HP Inc.)
Task: {389EEA1C-6579-4DBF-B986-F95EDFA4E59F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [231944 2025-09-02] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {8D502118-8950-44B8-AD26-20FB1A0CB24C} - System32\Tasks\HP\Consent Manager Launcher => C:\WINDOWS\system32\sc.exe [102400 2025-07-09] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice
Task: {40D9150C-2145-482C-9B89-8A7347C045C3} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [91144 2025-08-29] (HP Inc. -> HP Inc.)
Task: {B10C3A40-57C3-4988-865F-8D4064DD427A} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [91144 2025-08-29] (HP Inc. -> HP Inc.)
Task: {822D2D2E-6580-492A-B170-D8210E237C2A} - System32\Tasks\HP\HP Wolf Security\Launch Console => C:\Program Files\HP\HP Client Security Manager\HP.ClientSecurityManager.exe [250888 2025-03-28] (HP Inc. -> HP Inc.)
Task: {40D437D2-BF06-4D40-A1C2-27F36DF44D3D} - System32\Tasks\HP\Sure Click\Sure Click 4.4.26.1391 => C:\Program Files\HP\Sure Click\servers\BrLauncher.exe [2784584 2025-07-23] (Bromium UK Limited -> HP)
Task: {BB9346D2-04E2-4D54-9791-109C7DE9D1DC} - System32\Tasks\HP\Sure Click\Sure Click UI 4.4.26.1391 => C:\Program Files\HP\Sure Click\servers\BrConsole.exe [186696 2025-07-23] (Bromium UK Limited -> HP)
Task: {8A59A006-099A-42F4-9040-46AA0067DDCD} - System32\Tasks\HPDataRetriever => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-application-info-collector_ver_4.675.11370\hp-data-retriever.exe (No File)
Task: {0CB26830-1288-4745-87BD-4E8F735AB774} - System32\Tasks\HPOneAgentRepairTask => C:\ProgramData\Package Cache\{7CF09040-C14A-4FAA-B61A-1A7F2BDE3719}\HPOneAgent.exe [1169744 2025-09-13] (HP Inc. -> HP Inc; HP Development Company, L.P.)
Task: {DB5845A0-A548-49BB-8035-A6B0CB2330CF} - System32\Tasks\HPSupportTool => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-iolo-collector_ver_4.675.11370\HPSupportAssistant1.exe (No File)
Task: {994BE5CF-6F3B-4609-A539-4268229737B3} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16954752 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {63DA5A32-A7F0-48CE-B47A-E864F4DCF4D3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29038432 2025-09-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {C1DA3AE4-266F-4DCE-95B0-2CC5486E4D37} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [70464 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {87FA8DFC-7AE8-4E58-A0B7-5B5E9377BA9A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29038432 2025-09-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {8B49989A-E2C9-421A-8EE9-65A4512EAB88} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [318720 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0036CCA-5FA7-4979-993B-403F47A0BF94} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [318720 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {87B8C786-9713-404F-9E30-89DC826CA5B7} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [1365304 2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {B9B2828E-EB6C-4DE6-BA9D-4ECD34C9970F} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [693376 2025-10-04] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {43833194-A1F1-4FB8-A67A-BAB9CF926176} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3530282796-2492871232-3359154168-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [693376 2025-10-04] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {09CF39A6-2EAE-49D9-991A-4E581B8BB323} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2025-10-04] (Mozilla Corporation -> Mozilla Foundation)
Task: {7BB9BC5B-E347-4EFA-A171-F03C69ACCAF3} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3530282796-2492871232-3359154168-1001 => C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDriveLauncher.exe [725880 2025-10-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {79B658AB-84BE-4017-A33C-92543C838696} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3530282796-2492871232-3359154168-500 => C:\Users\Administrator\AppData\Local\Microsoft\OneDrive\25.087.0506.0001_1\OneDriveLauncher.exe [684880 2025-10-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {4CC23C0D-3CAA-497C-B7FE-5B4763CC3AAB} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-3530282796-2492871232-3359154168-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-10-06] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {490A93EB-6AB1-47BC-B5B0-A87EBD7E50B2} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-3530282796-2492871232-3359154168-1008 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-10-06] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {A37E58DD-B102-4B6B-97B2-227BA3DEFA20} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-3530282796-2492871232-3359154168-500 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4717688 2025-10-06] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {CD1A8EDF-DBDA-4ED4-BA70-F0E7E2734D7A} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6243960 2025-10-06] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {6CDC37B4-AB81-4E23-B973-5522835964F2} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [8971064 2025-10-02] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 62.24.64.2 8.8.8.8 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{5d78b6c1-816b-4e77-8125-9f3ad7ca951c}: [DhcpNameServer] 62.24.64.2 8.8.8.8 8.8.8.8 192.168.1.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-01]
Edge Extension: (HP Wolf Security Extension) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aoganjpeihhkhippgnniaclfocnihgln [2025-07-28]
Edge Extension: (Google Docs Offline) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-10-01]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2025-09-11]
Edge Extension: (Edge relevant text changes) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (ESET Browser Privacy & Security) - C:\Users\safro\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2025-07-27]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]

FireFox:
========
FF DefaultProfile: dhpnfwib.default
FF ProfilePath: C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\dhpnfwib.default [2022-09-15]
FF ProfilePath: C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694 [2025-10-08]
FF Homepage: Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694 -> seznam.cz
FF Extension: (ESET Browser Privacy & Security) - C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694\Extensions\browserextension@eset.com.xpi [2025-05-09]
FF Extension: (HP Wolf Security Extension) - C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694\Extensions\firefoxhpwolfsecurityextension@bromium.com.xpi [2025-07-19] [UpdateUrl:hxxps://addons.bromium-online.com/updates.json]
FF Extension: (Tlačítko Uložit pro Pinterest) - C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Profiles\wwh84cyh.default-release-1725711429694\Extensions\jid1-YcMV6ngYmQRA2w@jetpack.xpi [2024-12-15]
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-09-08] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-07-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1583.3\npCCleanerBrowserUpdate3.dll [2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1583.3\npCCleanerBrowserUpdate3.dll [2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2025-10-08]

Chrome:
=======
CHR Profile: C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default [2025-09-18]
CHR Notifications: Default -> hxxps://business.facebook.com; hxxps://victoriavette.com; hxxps://wp.aliexpress.com; hxxps://www.aliexpress.com; hxxps://www.eva.cz; hxxps://www.facebook.com; hxxps://www.penny.cz
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-05-10]
CHR Extension: (HP Wolf Security Extension) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpmlagmcbcnjhkdjiofoenkfbaclgjkk [2025-05-10]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2025-06-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-08-01]
CHR Extension: (ESET Browser Privacy & Security) - C:\Users\safro\AppData\Local\Google\Chrome\User Data\Default\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2025-06-09]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hkecabaloghleaicfhefejdijblljpco]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [oombnmpbbhbakfpfgdflaajkhicgfaam]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 aakore; C:\Program Files (x86)\Acronis\Agent\aakore.exe [9022120 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 AcronisActiveProtectionService; C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe [12952232 2021-03-23] (Acronis International GmbH -> )
S4 AcronisCyberProtectionService; C:\Program Files\Acronis\CyberProtect\cyber-protect-service.exe [1425256 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1052280 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174584 2025-08-24] (Adobe Inc. -> Adobe Inc.)
R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [6391536 2021-05-19] (Acronis International GmbH -> )
S4 BrAmSvc; C:\Program Files\HP\Sure Click\servers\BrAmSvc.exe [2054032 2025-07-23] (HP Inc -> HP)
R2 BrEndpointSvc; C:\Program Files\HP\Sure Click\servers\BemSvc.exe [4896072 2025-07-23] (Bromium UK Limited -> HP)
R2 BrService; C:\Program Files\HP\Sure Click\servers\BrService.exe [10941768 2025-07-23] (Bromium UK Limited -> HP)
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [28280440 2025-10-06] (Gen Digital Inc. -> Gen Digital Inc.)
S3 CCleanerBrowserElevationService; C:\Program Files (x86)\CCleaner Browser\Application\140.0.32231.210\elevation_service.exe [2611896 2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-13] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13343584 2025-09-28] (Microsoft Corporation -> Microsoft Corporation)
R2 CxAudioSvc; C:\WINDOWS\CxSvc\CxAudioSvc.exe [86592 2022-11-14] (Synaptics Incorporated -> Conexant Systems LLC.)
S2 CxUIUSvc; C:\WINDOWS\System32\CxUIUSvc64.exe [191360 2022-11-14] (Synaptics Incorporated -> Conexant Systems, Inc.)
R2 DFWSIDService; C:\ProgramData\Wondershare\wsServices\WsidService.exe [3963120 2023-09-15] (Wondershare Technology Group Co.,Ltd -> wondershare)
R2 DpHost; C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe [530136 2020-04-30] (DigitalPersona, Inc. -> Crossmatch, Inc.)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5538224 2025-09-10] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4662320 2025-09-10] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4662320 2025-09-10] (ESET, spol. s r.o. -> ESET)
R2 HotKeyServiceDSU; C:\WINDOWS\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\HotKeyServiceDSU.exe [681544 2024-09-05] (HP Inc. -> HP Inc.)
R2 HotKeyServiceUWP; C:\WINDOWS\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\HotKeyServiceUWP.exe [1526176 2020-08-18] (HP Inc. -> HP Inc.)
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136192 2009-10-15] (HP) [File not signed]
S4 hp-one-agent-service; C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe [2408032 2025-08-13] (HP Inc. -> HP Inc; HP Development Company, L.P.)
R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\AppHelperCap.exe [909496 2025-08-20] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\DiagsCap.exe [907960 2025-08-20] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\NetworkCap.exe [903840 2025-08-20] (HP Inc. -> HP Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243720 2025-08-29] (HP Inc. -> HP Inc.)
R3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1149448 2020-07-23] (HP Inc. -> HP)
R2 HPSIService; C:\windows\system32\HPSIsvc.exe [126856 2012-11-08] (Hewlett-Packard Company -> HP)
R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_435c166df33291ac\x64\SysInfoCap.exe [909496 2025-08-20] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_d57a8c6bda0aacf4\x64\TouchpointAnalyticsClientService.exe [639760 2025-07-14] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192320 2020-09-07] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S4 LanWlanSwitchingService; C:\Program Files (x86)\HP\HP Hotkey Support\LanWlanSwitchingService.exe [628776 2019-05-28] (HP Inc. -> HP)
R2 LanWlanWwanSwitchingServiceDSU; C:\WINDOWS\System32\DriverStore\FileRepository\hpdsusoftwarecomponent.inf_amd64_5416f6085e93e9fa\LanWlanWwanSwitchingServiceDSU.exe [587848 2024-09-05] (HP Inc. -> HP Inc.)
R2 LanWlanWwanSwitchingServiceUWP; C:\WINDOWS\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_42257e45eaa17009\LanWlanWwanSwitchingServiceUWP.exe [782744 2020-08-18] (HP Inc. -> HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9608720 2025-09-07] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2024-12-26] (Malwarebytes Inc. -> Malwarebytes)
S4 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4878840 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 mobile_backup_server; C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [3004128 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S4 mobile_backup_status_server; C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [2136488 2021-03-23] (Acronis International GmbH -> )
R2 SecurityUpdateService; C:\Program Files\HP\Security Update Service\4.4.26.1391\SecurityUpdateService.exe [5615432 2025-07-23] (Bromium UK Limited -> HP)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-08-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [7398360 2021-03-23] (Acronis International GmbH -> )
S4 Tib Mounter Service; C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe [5910328 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3174840 2024-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [133592 2024-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [7786032 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA)
S3 BdDci4; C:\WINDOWS\system32\DRIVERS\bddci4.sys [971312 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 BrCow_4_4_26_1391; C:\WINDOWS\System32\DRIVERS\BrCow_4_4_26_1391.sys [71208 2025-07-23] (Bromium UK Limited -> HP)
R2 BrFilter_4_4_26_1391; C:\WINDOWS\System32\DRIVERS\BrFilter_4_4_26_1391.sys [236552 2025-07-23] (Bromium UK Limited -> HP)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [232456 2025-08-15] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [139944 2025-08-15] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [16336 2025-01-30] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [270136 2025-08-15] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [57352 2025-08-15] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [86792 2025-08-15] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [126024 2025-08-15] (ESET, spol. s r.o. -> ESET)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2020-09-07] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R2 file_protector; C:\WINDOWS\System32\DRIVERS\file_protector.sys [720392 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [392840 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R0 fltsrv; C:\WINDOWS\System32\DRIVERS\fltsrv.sys [183944 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
S1 Gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [1791064 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> BitDefender S.R.L. Bucharest, ROMANIA)
R3 hanvonugeemfilter; C:\WINDOWS\System32\drivers\hanvonugeemfilter.sys [9728 2023-02-03] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-06] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-10-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-03-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [244800 2025-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [29168 2016-01-06] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
S0 ngelam; C:\WINDOWS\System32\drivers\ngelam.sys [15816 2021-03-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Acronis International GmbH)
R1 ngscan; C:\WINDOWS\System32\DRIVERS\ngscan.sys [179104 2021-03-23] (Acronis International GmbH -> Acronis International GmbH)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_0ca603ee5d51e3b2\rt68cx21x64.sys [810328 2024-03-19] (Realtek Semiconductor Corp. -> Realtek)
S3 Ser2pl; C:\WINDOWS\System32\drivers\ser2pl64.sys [258544 2019-08-01] (WDKTestCert charles-yeh,131345514351795974 -> Prolific Technology Inc.)
S0 sselam_4_4_19_828; C:\WINDOWS\System32\DRIVERS\sselam_4_4_19_828.sys [19528 2025-07-23] (Microsoft Windows Early Launch Anti-malware Publisher -> HP)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 tib; C:\WINDOWS\system32\DRIVERS\tib.sys [887032 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [175648 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
S3 tnd; C:\WINDOWS\system32\DRIVERS\tnd.sys [694920 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R3 uxen; C:\Program Files\HP\Sure Click\bin\uxen.sys [2053080 2025-04-15] (Bromium UK Limited -> HP)
R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [334984 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
R3 vlflt; C:\WINDOWS\System32\DRIVERS\vlflt.sys [1438768 2025-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 volume_tracker; C:\WINDOWS\System32\DRIVERS\volume_tracker.sys [251016 2021-05-19] (Acronis International GmbH -> Acronis International GmbH)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [55856 2024-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [594304 2024-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [105856 2024-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-01-30] (Microsoft Windows -> Microsoft Corporation)
R3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys [61440 2025-09-09] (Microsoft Windows -> Microsoft Corporation)
R3 XPPenTablet; C:\WINDOWS\System32\drivers\XPPenTablet.sys [10752 2023-02-03] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 ax_pvi; \??\C:\Program Files\HP\Sure Click\bin\ax_pvi.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-10-08 08:27 - 2025-10-08 08:27 - 000046134 _____ C:\Users\safro\Desktop\FRST.txt
2025-10-07 21:40 - 2025-10-07 21:40 - 000711764 _____ C:\WINDOWS\system32\perfh005.dat
2025-10-07 21:40 - 2025-10-07 21:40 - 000152978 _____ C:\WINDOWS\system32\perfc005.dat
2025-10-07 20:21 - 2025-10-07 20:22 - 061958138 _____ C:\Users\safro\Downloads\Ptáci (draci) na odletu – konec i babímu létu- flexibilní plán-final.pdf
2025-10-07 20:07 - 2025-10-07 20:08 - 061954130 _____ C:\Users\safro\Downloads\Ptáci (draci) na odletu – konec i babímu létu- flexibilní plán-1.pdf
2025-10-07 20:02 - 2025-10-07 20:02 - 057004226 _____ C:\Users\safro\Downloads\Ptáci (draci) na odletu – konec i babímu létu- flexibilní plán.pdf
2025-10-07 19:19 - 2025-10-07 19:19 - 000407363 _____ C:\Users\safro\Downloads\Návrh bez názvu-49.pdf
2025-10-07 19:16 - 2025-10-07 19:16 - 000407287 _____ C:\Users\safro\Downloads\Návrh bez názvu-48.pdf
2025-10-07 19:10 - 2025-10-07 19:10 - 000182997 _____ C:\Users\safro\Downloads\Návrh bez názvu-47.pdf
2025-10-07 16:45 - 2025-10-07 16:45 - 001534260 _____ C:\WINDOWS\Minidump\100725-17781-01.dmp
2025-10-07 16:41 - 2025-10-07 18:55 - 1585303618 _____ C:\WINDOWS\MEMORY.DMP
2025-10-07 16:41 - 2025-10-07 16:41 - 002004380 _____ C:\WINDOWS\Minidump\100725-13500-01.dmp
2025-10-06 16:50 - 2025-10-06 16:50 - 000002076 _____ C:\Users\Public\Desktop\CCleaner 7.lnk
2025-10-05 18:20 - 2025-10-05 18:20 - 000000000 ____D C:\Users\Administrator\AppData\Local\Comms
2025-10-05 18:18 - 2025-10-05 18:21 - 000003590 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3530282796-2492871232-3359154168-500
2025-10-05 18:18 - 2025-10-05 18:21 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3530282796-2492871232-3359154168-500
2025-10-05 18:18 - 2025-10-05 18:21 - 000002409 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-10-05 18:18 - 2025-10-05 18:21 - 000000000 ___RD C:\Users\Administrator\OneDrive
2025-10-05 18:17 - 2025-10-05 18:21 - 000000000 ____D C:\Users\Administrator\AppData\Local\Publishers
2025-10-05 18:17 - 2025-10-05 18:17 - 000081842 _____ C:\WINDOWS\system32\NOTICE_mod
2025-10-05 18:17 - 2025-10-05 18:17 - 000000000 ____D C:\Users\Administrator\AppData\Local\PlaceholderTileLogoFolder
2025-10-05 18:15 - 2025-10-05 19:04 - 000000000 ____D C:\Users\Administrator
2025-10-05 18:15 - 2025-10-05 18:30 - 000000000 ____D C:\Users\Administrator\AppData\Local\Malwarebytes
2025-10-05 18:15 - 2025-10-05 18:25 - 000000000 ____D C:\Users\Administrator\AppData\Local\Packages
2025-10-05 18:15 - 2025-10-05 18:20 - 000000000 __SHD C:\Users\Administrator\IntelGraphicsProfiles
2025-10-05 18:15 - 2025-10-05 18:17 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows
2025-10-05 18:15 - 2025-10-05 18:17 - 000000000 ____D C:\Users\Administrator\AppData\Local\D3DSCache
2025-10-05 18:15 - 2025-10-05 18:16 - 000000000 ____D C:\Users\Administrator\AppData\Local\HP
2025-10-05 18:15 - 2025-10-05 18:15 - 000002432 _____ C:\Users\Administrator\Desktop\CCleaner Browser.lnk
2025-10-05 18:15 - 2025-10-05 18:15 - 000000020 ___SH C:\Users\Administrator\ntuser.ini
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Šablony
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Soubory cookie
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Poslední
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Okolní tiskárny
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Okolní síť
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Nabídka Start
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Dokumenty
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Documents\Obrázky
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Documents\Hudba
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Documents\Filmy
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\Data aplikací
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 SHDJL C:\Users\Administrator\AppData\Local\Data aplikací
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Protect
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Crypto
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Vault
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Spelling
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\hpqLog
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Intel
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Bromium
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Local\Google
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Local\ESET
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Local\ConnectedDevicesPlatform
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Local\CCleaner Browser
2025-10-05 18:15 - 2025-10-05 18:15 - 000000000 ____D C:\Users\Administrator\AppData\Local\Bromium
2025-10-05 18:15 - 2025-01-30 21:14 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Network
2025-10-05 18:15 - 2020-09-03 16:00 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\HP
2025-10-05 17:55 - 2025-10-05 17:55 - 000000000 ____D C:\Users\safro\AppData\Local\Microsoft_Corporation
2025-10-05 17:38 - 2025-10-05 17:39 - 033639960 _____ (TeamViewer) C:\Users\safro\Desktop\TeamViewerQS_x64.exe
2025-10-05 14:32 - 2025-10-05 14:35 - 000000000 ____D C:\Users\safro\Desktop\UČITELKA ŠKOLKA
2025-10-05 14:29 - 2025-10-07 19:51 - 000000000 ____D C:\Users\safro\Desktop\VŠE DO ŠKOLKY
2025-10-05 14:27 - 2025-10-05 14:27 - 000054868 _____ C:\Users\safro\Desktop\nápady a texty.txt
2025-10-05 14:09 - 2025-10-05 14:09 - 002442752 _____ (Farbar) C:\Users\safro\Desktop\FRST64.exe
2025-10-05 08:51 - 2025-10-05 08:52 - 088266800 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\ccsetup639(1).zmzo3B35.exe.part
2025-10-05 08:51 - 2025-10-05 08:51 - 000000000 _____ C:\Users\safro\Downloads\ccsetup639(1).exe
2025-10-05 08:50 - 2025-10-05 08:51 - 096538504 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\CCleanerBundle-639-Setup(2).exe
2025-10-05 08:50 - 2025-10-05 08:51 - 096538504 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\CCleanerBundle-639-Setup(1).exe
2025-10-05 08:50 - 2025-10-05 08:51 - 088268600 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\ccsetup639.KzYlaz1j.exe.part
2025-10-05 08:50 - 2025-10-05 08:50 - 000000000 _____ C:\Users\safro\Downloads\ccsetup639.exe
2025-10-04 19:23 - 2025-10-04 19:23 - 000077709 _____ C:\Users\safro\Downloads\vypis-28019713832010-2025-10-01-1.pdf
2025-10-04 19:23 - 2025-10-04 19:23 - 000077709 _____ C:\Users\safro\Downloads\vypis-28019713832010-2025-10-01.pdf
2025-10-04 19:22 - 2025-10-04 19:22 - 000085089 _____ C:\Users\safro\Downloads\vypis-28019713832010-2025-09-30.pdf
2025-10-04 13:48 - 2025-10-04 13:50 - 000071342 _____ C:\Users\safro\Downloads\kniha-jizd-2025-od-csob.xlsx
2025-10-04 09:44 - 2025-10-04 09:44 - 038574063 _____ C:\Users\safro\Downloads\NA ZAČÁTKU LISTOPADA, TEPLO SE ZIMOU SE HÁDÁ - flexibilní plán.pdf
2025-10-03 19:26 - 2025-10-03 19:26 - 042800762 _____ C:\Users\safro\Downloads\Carodejnicke_diplomy_cukrkava_PDF.pdf
2025-10-03 19:26 - 2025-10-03 19:26 - 012318922 _____ C:\Users\safro\Downloads\256-Halloweenska-plotovka-Hravy-Design.pdf
2025-10-03 19:26 - 2025-10-03 19:26 - 002849726 _____ C:\Users\safro\Downloads\dusickyxhalloween-lapbook-pro-ms.pdf
2025-10-03 19:25 - 2025-10-03 19:25 - 006740857 _____ C:\Users\safro\Downloads\Halloween.PDF
2025-10-02 16:14 - 2025-10-02 16:14 - 002690104 _____ C:\Users\safro\Downloads\Pisnicky-pro-deti-13-PDF.zip
2025-10-01 20:20 - 2025-10-01 20:20 - 000261292 _____ C:\Users\safro\Downloads\1208.webp
2025-09-30 16:58 - 2025-10-07 21:44 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-09-30 15:58 - 2025-09-30 15:58 - 022763518 _____ C:\Users\safro\Downloads\Podzimni-hra.pdf.zip
2025-09-29 15:33 - 2025-09-29 15:33 - 000000000 ____D C:\WINDOWS\LastGood
2025-09-27 15:27 - 2025-09-27 15:27 - 003165032 _____ C:\Users\safro\Downloads\bramborovy-tyden-flexibilni-plan-final-1.pdf
2025-09-27 15:25 - 2025-09-27 15:25 - 083104464 _____ C:\Users\safro\Downloads\bramborovy-tyden-flexibilni-plan-final.pdf
2025-09-27 15:12 - 2025-09-27 15:12 - 032449191 _____ C:\Users\safro\Downloads\znaky-a-symboly-podzimu-ok.pdf
2025-09-27 09:23 - 2025-09-27 09:23 - 026546031 _____ C:\Users\safro\Downloads\léto a podzim flexibilní plán-final.pdf
2025-09-27 09:23 - 2025-09-27 09:23 - 026546031 _____ C:\Users\safro\Downloads\léto a podzim flexibilní plán-1.pdf
2025-09-27 09:09 - 2025-09-27 09:09 - 014658143 _____ C:\Users\safro\Downloads\léto a podzim flexibilní plán.pdf
2025-09-25 20:16 - 2024-10-17 03:53 - 000175824 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus2.sys
2025-09-25 19:58 - 2025-09-25 19:58 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-09-23 17:08 - 2025-09-23 17:08 - 005960599 _____ C:\Users\safro\Downloads\stezka-knihovna2(1).zip
2025-09-23 16:38 - 2025-09-23 15:33 - 005848948 _____ C:\Users\safro\Downloads\stezka-knihovna2.pdf
2025-09-23 16:38 - 2025-09-15 13:37 - 000359771 _____ C:\Users\safro\Downloads\stezka-knihovna-pruvodni-dopis.pdf
2025-09-23 16:37 - 2025-09-23 16:37 - 005960599 _____ C:\Users\safro\Downloads\stezka-knihovna2.zip
2025-09-23 16:20 - 2025-09-23 16:34 - 000000000 ____D C:\Users\safro\Downloads\Podzimni-hudebni-balicek_0
2025-09-23 16:20 - 2025-09-23 16:20 - 044944872 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek_0.zip
2025-09-22 19:55 - 2025-09-22 19:55 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek(3).zip
2025-09-22 19:52 - 2025-09-22 19:52 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek(2).zip
2025-09-22 19:49 - 2025-09-22 19:49 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek(1).zip
2025-09-22 19:49 - 2025-09-22 19:49 - 000000000 ____D C:\Users\safro\Downloads\Podzimni-hudebni-balicek
2025-09-22 19:47 - 2025-09-22 19:47 - 044944789 _____ C:\Users\safro\Downloads\Podzimni-hudebni-balicek.zip
2025-09-22 18:45 - 2025-09-22 18:46 - 011922963 _____ C:\Users\safro\Downloads\twigsee-ms-pripravy-zari-2024-1.pdf
2025-09-22 17:01 - 2025-09-22 17:01 - 011922963 _____ C:\Users\safro\Downloads\twigsee-ms-pripravy-zari-2024.pdf
2025-09-22 08:36 - 2025-09-22 08:36 - 026260662 _____ C:\Users\safro\Downloads\twigsee-ms-pripravy-rijen-2025.pdf
2025-09-21 20:58 - 2024-10-17 03:54 - 000174264 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2025-09-21 08:32 - 2025-09-21 08:32 - 014083209 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-1-kompr..pdf
2025-09-21 08:30 - 2025-09-21 08:30 - 155625773 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-1.pdf
2025-09-21 08:25 - 2025-09-21 08:25 - 029365822 _____ C:\Users\safro\Downloads\HALLOWEENSKÝ- DUŠIČKOVÝ flexifilní plán-1.pdf
2025-09-20 09:02 - 2025-09-20 09:02 - 014082726 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-final-1.pdf
2025-09-20 08:45 - 2025-09-20 08:46 - 155625163 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim-final.pdf
2025-09-19 20:33 - 2025-09-19 20:33 - 036259127 _____ C:\Users\safro\Downloads\HALLOWEENSKÝ- DUŠIČKOVÝ flexifilní plán-final.pdf
2025-09-19 20:23 - 2025-09-19 20:23 - 000031712 _____ C:\Users\safro\Downloads\bezplamenne-cajove-svicky-na-baterie-nancia-realisticke-jasne-blikajici-elektricka-svickova-lampa.webp
2025-09-19 20:02 - 2025-09-19 20:02 - 010196144 _____ C:\Users\safro\Downloads\HALLOWEENSKÝ- DUŠIČKOVÝ flexifilní plán.pdf
2025-09-19 18:50 - 2025-10-05 08:49 - 000000000 ____D C:\Program Files\Recuva
2025-09-19 18:50 - 2025-09-19 18:50 - 000001707 _____ C:\Users\Public\Desktop\Recuva.lnk
2025-09-19 18:50 - 2025-09-19 18:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2025-09-19 18:46 - 2025-09-19 18:47 - 096538504 _____ (Gen Digital Inc.) C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe
2025-09-19 18:25 - 2025-09-19 18:25 - 071297301 _____ C:\Users\safro\Downloads\HUDEBNÍ HRÁTKY PODZIM UČITELÉ.zip
2025-09-19 18:23 - 2025-09-19 18:23 - 009616736 _____ (Malwarebytes) C:\Users\safro\Desktop\adwcleaner.exe
2025-09-18 20:10 - 2025-09-18 20:10 - 020830420 _____ C:\Users\safro\Downloads\Bingo-podzim.zip
2025-09-18 19:44 - 2025-09-18 19:44 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2025-09-17 21:43 - 2025-09-17 21:43 - 003721734 _____ C:\Users\safro\Downloads\Ja-mam-kdo-ma-Podzim(1).zip
2025-09-17 21:23 - 2025-09-17 21:23 - 011442877 _____ C:\Users\safro\Downloads\Podzimni-sklizen-1.pdf
2025-09-17 21:21 - 2025-09-17 21:21 - 057937341 _____ C:\Users\safro\Downloads\Podzimni-sklizen.pdf
2025-09-17 18:25 - 2025-09-17 18:25 - 012550345 _____ C:\Users\safro\Downloads\Podzimni-zavarovani.zip
2025-09-17 18:23 - 2025-09-17 18:23 - 001662887 _____ C:\Users\safro\Downloads\Podzimni-girlanda.zip
2025-09-17 18:22 - 2025-09-17 18:22 - 013002487 _____ C:\Users\safro\Downloads\Podzimni-aktivity.zip
2025-09-17 18:17 - 2025-09-17 18:17 - 003721734 _____ C:\Users\safro\Downloads\Ja-mam-kdo-ma-Podzim.zip
2025-09-17 17:14 - 2025-09-17 17:28 - 000000000 ____D C:\Users\safro\Desktop\seznamy 2025
2025-09-17 17:14 - 2025-09-17 17:14 - 000081528 _____ C:\Users\safro\Downloads\prilohy_78958.zip
2025-09-17 14:15 - 2025-09-17 14:15 - 035244911 _____ C:\Users\safro\Downloads\STRAŠIDELNÁ STEZKA.zip
2025-09-16 20:05 - 2025-09-16 20:05 - 023668825 _____ C:\Users\safro\Downloads\kompetencestrategieOVU-kompletnmaterily.pdf
2025-09-16 19:50 - 2025-09-16 19:50 - 028355751 _____ C:\Users\safro\Downloads\prilohy_1213715.zip
2025-09-16 19:46 - 2025-09-16 19:46 - 155622706 _____ C:\Users\safro\Downloads\když jdou stromy spát - podzim.pdf
2025-09-16 19:15 - 2025-09-16 19:15 - 003165032 _____ C:\Users\safro\Downloads\bramborový týden- flexibilní plán-final-kompr.pdf
2025-09-16 19:04 - 2025-09-16 19:04 - 083104464 _____ C:\Users\safro\Downloads\bramborový týden- flexibilní plán-final.pdf
2025-09-16 18:46 - 2025-09-16 18:46 - 083104464 _____ C:\Users\safro\Downloads\bramborový týden- flexibilní plán.pdf
2025-09-16 17:16 - 2025-09-16 17:16 - 000063452 _____ C:\Users\safro\Downloads\Bramb Notis-1.webp
2025-09-16 15:00 - 2025-09-16 15:00 - 000353588 _____ C:\Users\safro\Downloads\PTS-ZV5-004-SPLNENO-Co-je-domov.pdf
2025-09-16 14:58 - 2025-09-16 14:59 - 000291830 _____ C:\Users\safro\Downloads\PTS-ZV5-004-NA-CESTE-100-deti.pdf
2025-09-15 15:00 - 2025-09-15 15:00 - 005950714 _____ C:\Users\safro\Downloads\stezka-knihovna.zip
2025-09-14 21:17 - 2025-09-14 21:17 - 021740251 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-půlené obr. final.pdf
2025-09-14 20:04 - 2025-09-14 20:04 - 021740250 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-3.pdf
2025-09-14 17:42 - 2025-09-14 17:42 - 000497850 _____ C:\Users\safro\Downloads\upravený text zkrácený.pdf
2025-09-14 17:31 - 2025-09-14 17:31 - 016449069 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-2.pdf
2025-09-14 16:28 - 2025-09-14 16:28 - 009624053 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO-1.pdf
2025-09-14 16:00 - 2025-09-14 16:00 - 000230760 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(4).jpeg
2025-09-14 16:00 - 2025-09-14 16:00 - 000200521 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(3).jpeg
2025-09-14 16:00 - 2025-09-14 16:00 - 000200521 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(2).jpeg
2025-09-14 15:59 - 2025-09-14 15:59 - 000231326 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena.jpeg
2025-09-14 15:59 - 2025-09-14 15:59 - 000231326 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. správné mytí rukou a hygiena(1).jpeg
2025-09-14 15:58 - 2025-09-14 15:58 - 000253711 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné(3).jpeg
2025-09-14 15:58 - 2025-09-14 15:58 - 000253711 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné(2).jpeg
2025-09-14 15:58 - 2025-09-14 15:58 - 000253711 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné(1).jpeg
2025-09-14 15:57 - 2025-09-14 15:57 - 000270362 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti jsou nepořádné.jpeg
2025-09-14 15:54 - 2025-09-14 15:54 - 000280400 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti si ubližují.jpeg
2025-09-14 15:54 - 2025-09-14 15:54 - 000269130 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. děti si ubližují(1).jpeg
2025-09-14 15:53 - 2025-09-14 15:53 - 000239254 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky(3).jpeg
2025-09-14 15:53 - 2025-09-14 15:53 - 000230233 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky(2).jpeg
2025-09-14 15:52 - 2025-09-14 15:52 - 000267929 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky.jpeg
2025-09-14 15:52 - 2025-09-14 15:52 - 000240288 _____ C:\Users\safro\Downloads\dětský barevný obrázek pro dodržování pravidel ve školce - např. půjčujeme si hračky(1).jpeg
2025-09-14 15:08 - 2025-09-14 15:08 - 009367476 _____ C:\Users\safro\Downloads\VÁNOČNÍ PEXESO.pdf
2025-09-13 19:46 - 2025-09-13 19:46 - 000633201 _____ C:\Users\safro\Downloads\EKOABECEDA pro klima_MS_2_scenar_Co se uci stromy.pdf
2025-09-13 15:02 - 2025-09-13 15:02 - 006024668 _____ C:\Users\safro\Downloads\JÁ MÁM, KDO MÁ OVOCE A ZELENINA.zip
2025-09-13 15:01 - 2025-09-13 15:01 - 062375839 _____ C:\Users\safro\Downloads\tp-jablicko.pdf
2025-09-13 14:12 - 2025-09-13 14:12 - 007285874 _____ C:\Users\safro\Downloads\_TŘÍDA SLUNÍČEK (2).pdf
2025-09-13 10:41 - 2025-09-13 10:41 - 000000000 _____ C:\WINDOWS\system32\enrollment.sto
2025-09-12 21:32 - 2025-09-12 21:32 - 036656553 _____ C:\Users\safro\Downloads\Pohadky-pro-hezke-sny-zimni-spaci-final.pdf
2025-09-12 19:26 - 2025-09-12 19:26 - 041035444 _____ C:\Users\safro\Downloads\Jablíčkový týden- flexibilní plán-final.pdf
2025-09-12 19:25 - 2025-09-12 19:25 - 041035442 _____ C:\Users\safro\Downloads\Jablíčkový týden- flexibilní plán.pdf
2025-09-12 19:23 - 2025-09-12 19:23 - 041034143 _____ C:\Users\safro\Downloads\JABLÍČKOVÝ TÝDEN-2.pdf
2025-09-12 16:28 - 2025-09-12 16:28 - 016859319 _____ C:\Users\safro\Downloads\Katalog+FC+2025-2026-1.pdf
2025-09-12 08:42 - 2025-09-12 08:42 - 013910549 _____ C:\Users\safro\Downloads\119-Hrajeme-si-s-kastany-Hravy-Design.pdf
2025-09-11 16:57 - 2025-09-11 16:57 - 000360662 _____ C:\Users\safro\Downloads\Revize_RVP_PV_Zasady_pro_zpracovani__vyhodnocovani_a_upravu_SVP-3951.pdf
2025-09-11 08:06 - 2025-09-11 08:06 - 000495926 _____ C:\Users\safro\Downloads\OznProCleny_2025_08_70340762.pdf
2025-09-10 20:01 - 2025-09-10 20:01 - 001646788 _____ C:\Users\safro\Downloads\RANNI-UKOLY-ZARI-OPRAVENO.pdf
2025-09-09 21:14 - 2025-09-09 21:14 - 000077233 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-09-09 21:14 - 2025-09-09 21:14 - 000077233 _____ C:\WINDOWS\system32\ctac.json
2025-09-09 21:14 - 2025-09-09 21:14 - 000001681 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-09-09 18:59 - 2025-09-09 18:59 - 000302219 _____ C:\Users\safro\Downloads\ŠVP 2020 Obsah vzděláváni- KK.pdf
2025-09-09 09:08 - 2025-09-09 09:09 - 000204447 _____ C:\Users\safro\Downloads\CZ0208000000000860948133_2000022773264106.pdf
2025-09-08 19:31 - 2025-09-08 19:31 - 000412055 _____ C:\Users\safro\Downloads\rvp-pv-manual-svp-tridni-planovani-a4.pdf
2025-09-08 19:31 - 2025-09-08 19:31 - 000406025 _____ C:\Users\safro\Downloads\kurikulum-manual-svp-pro-pv.pdf
2025-09-08 19:22 - 2025-09-08 19:22 - 000595604 _____ C:\Users\safro\Downloads\SVP-Slunicko-se-skolni-druzinou-2024-.pdf
2025-09-08 19:16 - 2025-09-08 19:16 - 003999814 _____ C:\Users\safro\Downloads\TOFLOVÁ - švp 1-aktualizovany-k-1-9-25.pdf
2025-09-08 17:02 - 2025-09-08 17:02 - 000406328 _____ C:\Users\safro\Downloads\rvp-pv-manual-svp-a4.pdf
2025-09-08 16:14 - 2025-09-08 16:14 - 001120027 _____ C:\Users\safro\Downloads\ŠVP 2020-25 2.pdf
2025-09-08 08:38 - 2025-09-08 08:38 - 000481414 _____ C:\Users\safro\Downloads\SVP-2025-novy.pdf
2025-09-08 08:36 - 2025-09-08 08:36 - 000263498 _____ C:\Users\safro\Downloads\opatreni_ministra_RVP_PV_MSMT-17147_2024-4.pdf
2025-09-08 08:35 - 2025-09-08 08:35 - 000709445 _____ C:\Users\safro\Downloads\vyhlaseni_PO_mSVP_ZS_MSMT_6537_2025_3.pdf
2025-09-08 08:29 - 2025-09-08 08:29 - 002266492 _____ C:\Users\safro\Downloads\RVP-PV-kveten-2025.pdf
2025-09-08 08:20 - 2025-09-08 08:22 - 000911144 _____ C:\Users\safro\Downloads\ŠVP MŠ.pdf
2025-09-08 08:18 - 2025-09-08 08:18 - 000312303 _____ C:\Users\safro\Downloads\2025-01-14-tematicky-zakladni-ramec-a-vecny-popis.pdf

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-10-08 08:27 - 2022-09-14 19:09 - 000000000 ____D C:\FRST
2025-10-08 08:26 - 2024-12-26 21:07 - 000000000 ____D C:\Users\safro\AppData\Local\Malwarebytes
2025-10-08 08:05 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-08 08:01 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-08 07:55 - 2022-02-08 20:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-10-08 07:54 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-08 07:54 - 2020-06-13 15:36 - 000000000 ____D C:\Users\safro\AppData\Local\Packages
2025-10-08 07:50 - 2020-06-18 07:33 - 000000000 ____D C:\Users\safro\AppData\Local\D3DSCache
2025-10-08 07:47 - 2025-01-30 19:37 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2025-10-08 07:46 - 2020-06-13 15:38 - 000000000 ___RD C:\Users\safro\OneDrive
2025-10-08 07:46 - 2020-06-13 15:36 - 000000000 __SHD C:\Users\safro\IntelGraphicsProfiles
2025-10-07 21:45 - 2025-01-30 21:11 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-07 21:40 - 2025-01-30 21:20 - 001692324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-10-07 21:40 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-10-07 21:34 - 2025-01-30 21:15 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-07 21:34 - 2025-01-30 21:11 - 000013286 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-10-07 21:34 - 2020-03-13 07:10 - 000000000 ___HD C:\Intel
2025-10-07 21:33 - 2020-09-15 19:42 - 000012288 ___SH C:\DumpStack.log.tmp
2025-10-07 21:01 - 2024-04-01 09:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2025-10-07 20:47 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-07 19:51 - 2020-06-13 15:48 - 000000000 ____D C:\Users\safro\AppData\Roaming\Microsoft\Word
2025-10-07 18:55 - 2025-02-04 20:29 - 000000000 ____D C:\WINDOWS\Minidump
2025-10-06 21:31 - 2020-07-21 23:31 - 000002395 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2025-10-06 21:31 - 2020-07-21 23:30 - 000000000 ____D C:\Program Files (x86)\CCleaner Browser
2025-10-06 16:50 - 2025-08-25 21:27 - 000000000 ____D C:\WINDOWS\system32\Tasks\Piriform
2025-10-06 16:50 - 2022-05-12 15:36 - 000000000 ____D C:\ProgramData\Piriform
2025-10-06 07:46 - 2025-01-30 21:15 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-10-06 07:46 - 2025-01-30 21:15 - 000003514 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-10-05 19:04 - 2025-01-30 19:50 - 000000000 ____D C:\Users\safro
2025-10-05 18:21 - 2025-01-30 21:15 - 000003394 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3530282796-2492871232-3359154168-500
2025-10-05 18:21 - 2019-04-19 20:32 - 000000000 ____D C:\ProgramData\Packages
2025-10-05 18:15 - 2019-04-19 20:29 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-10-05 17:39 - 2020-06-13 17:05 - 000000000 ____D C:\Users\safro\AppData\Local\TeamViewer
2025-10-05 14:27 - 2025-03-18 18:32 - 000088969 _____ C:\Users\safro\Desktop\1newsletter 1.txt
2025-10-05 14:27 - 2020-10-16 22:05 - 000055565 _____ C:\Users\safro\Desktop\finclub partnerský odkaz.txt
2025-10-05 14:26 - 2025-06-26 19:28 - 000009295 _____ C:\Users\safro\Downloads\DIAGNOSTICKE-PORTFOLIO-DITETE.txt
2025-10-04 21:08 - 2025-01-30 21:15 - 000003168 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3530282796-2492871232-3359154168-1001
2025-10-04 20:59 - 2020-03-13 07:20 - 000000000 ____D C:\Program Files\Microsoft Office
2025-10-04 18:36 - 2025-01-30 21:15 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3530282796-2492871232-3359154168-1001
2025-10-04 18:36 - 2025-01-30 21:15 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3530282796-2492871232-3359154168-1001
2025-10-04 18:36 - 2020-09-15 18:57 - 000002391 _____ C:\Users\safro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-10-04 17:11 - 2023-11-23 17:38 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-10-04 17:11 - 2020-06-13 15:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-10-04 17:00 - 2025-01-30 21:15 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-10-04 17:00 - 2020-06-13 15:45 - 000001081 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-10-04 13:50 - 2020-06-13 15:39 - 000000000 ____D C:\Users\safro\AppData\Roaming\Microsoft\Excel
2025-10-04 08:03 - 2020-07-16 19:49 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-10-04 08:03 - 2020-07-16 19:49 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-10-03 19:22 - 2023-07-24 17:26 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2025-10-03 19:21 - 2020-06-13 15:37 - 000000000 ____D C:\Users\safro\AppData\Roaming\hpqLog
2025-10-02 16:31 - 2025-05-12 15:06 - 000000000 ____D C:\Users\safro\Desktop\vtipné obrázky
2025-10-02 16:19 - 2025-01-30 21:15 - 000003542 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-09-30 18:44 - 2025-01-30 21:15 - 000002834 _____ C:\WINDOWS\system32\Tasks\HPOneAgentRepairTask
2025-09-23 16:56 - 2024-04-17 14:32 - 000002081 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-09-23 16:56 - 2024-04-17 14:32 - 000002069 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2025-09-23 16:42 - 2020-06-13 16:22 - 000000000 ____D C:\Users\safro\AppData\Local\Adobe
2025-09-21 13:05 - 2025-02-12 20:39 - 000244800 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2025-09-20 19:23 - 2020-03-13 07:19 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2025-09-19 18:53 - 2020-06-17 07:02 - 000000000 ____D C:\Users\safro\AppData\Local\CrashDumps
2025-09-19 18:25 - 2019-04-19 20:34 - 000000000 ____D C:\ProgramData\HP
2025-09-18 19:38 - 2020-06-20 08:46 - 000002309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-09-18 19:38 - 2020-06-20 08:46 - 000002268 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-09-13 10:41 - 2020-03-13 07:14 - 000000000 ____D C:\ProgramData\Package Cache
2025-09-09 21:57 - 2025-01-30 21:10 - 000587608 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-09-09 21:56 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-09-09 21:56 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-09-09 21:56 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-09-09 21:55 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-09-09 21:55 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-09-09 21:55 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-09-09 21:27 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-09-09 21:27 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2025-09-09 21:14 - 2025-01-30 21:11 - 003270656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================




Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by safro (08-10-2025 08:30:49)
Running from C:\Users\safro\Desktop
Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) (2025-01-30 19:15:40)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3530282796-2492871232-3359154168-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-3530282796-2492871232-3359154168-503 - Limited - Disabled)
Guest (S-1-5-21-3530282796-2492871232-3359154168-501 - Limited - Disabled)
safro (S-1-5-21-3530282796-2492871232-3359154168-1001 - Administrator - Enabled) => C:\Users\safro
WDAGUtilityAccount (S-1-5-21-3530282796-2492871232-3359154168-504 - Limited - Disabled)
WsiAccount (S-1-5-21-3530282796-2492871232-3359154168-1008 - Limited - Disabled) => C:\Users\WsiAccount

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Security (Enabled - Up to date) {DF8BEACB-94C9-218A-73AD-A78362A8C516}
AV: ESET Security (Enabled - Up to date) {89B55CC4-3881-78B2-11E2-479AE0371896}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}
FW: ESET Firewall (Enabled) {E7B06BEE-DEA6-20D2-58F2-0EB69C7B826D}
FW: ESET Firewall (Enabled) {B18EDDE1-72EE-79EA-3ABD-EEAF1EE45FED}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acronis Drivers (HKLM\...\{7C36ADC0-5219-4D31-90D1-4211321481EF}) (Version: 25.8.39216 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}) (Version: 25.8.39216 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}Visible) (Version: 25.8.39216 - Acronis)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 25.001.20693 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601120}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
ApowerCompress V1.1.18 (HKLM-x32\...\{10998dc6-e8e2-48ef-9378-0db3d4c7f32a}_is1) (Version: 1.1.18 - Wangxu Technology Co.,Ltd.)
Audacity 3.7.5 (HKLM\...\Audacity_is1) (Version: 3.7.5 - Audacity Team)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.0.984.1153 - Piriform)
CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 140.0.32231.210 - Autoři prohlížeče CCleaner Browser)
CCleaner Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1067.0 - Piriform Software) Hidden
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1583.3 - Piriform Software) Hidden
CEWE fotosvet (HKLM\...\CEWE fotosvet) (Version: 7.3.3 - CEWE Stiftung u Co. KGaA)
CPUID HWMonitor 1.54 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.54 - CPUID, Inc.)
CrystalDiskInfo 8.17.5 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.17.5 - Crystal Dew World)
Dynamic Application Loader Host Interface Service (HKLM\...\{9DE7A0A5-C13D-4FDD-B78B-53C744C82F1A}) (Version: 1.0.0.0 - Intel Corporation) Hidden
ESET Security (HKLM\...\{32DA3D18-091D-4B85-BFD4-C17C514674ED}) (Version: 18.2.18.0 - ESET, spol. s r.o.)
Express Burn Disc Burning Software (HKLM-x32\...\ExpressBurn) (Version: 10.30 - NCH Software)
Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 9.26 - NCH Software)
FastStone Photo Resizer 4.4 (HKLM-x32\...\FastStone Photo Resizer) (Version: 4.4 - FastStone Corporation)
Google Chrome (HKLM\...\{15971136-C56A-3015-AC9D-ED17B8F94952}) (Version: 140.0.7339.186 - Google LLC)
HappyFoto (HKLM\...\{621A70CA-32A5-4F50-A66C-C9C792580415}_is1) (Version: - Happy Foto CZ)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 11.0.0.320 - Huawei Technologies Co., Ltd.)
HP Client Security Manager (HKLM\...\{456CC699-FD29-4835-9CE6-BB3E63DC76E3}) (Version: 9.5.3.2908 - HP Inc.) Hidden
HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 9.5.3.2908 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP Hotkey Support (HKLM-x32\...\{6606696F-B31A-48B7-B05D-FB5DDFAD9FAB}) (Version: 6.2.52.1 - HP Inc.)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version: - )
HP Notifications (HKLM-x32\...\{84937F28-9CB4-49E7-A2CF-E32D97E6DAE6}) (Version: 1.1.28.1 - HP)
HP One Agent (HKLM\...\{7CF09040-C14A-4FAA-B61A-1A7F2BDE3719}) (Version: 1.1.973.9172 - HP Inc.)
HP One Agent (HKLM\...\{7EFF7A5C-E41B-4E5C-B075-08C00AA3F2EB}) (Version: 1.1.973.9172 - HP Inc.) Hidden
HP Security Update Service (HKLM\...\{74C6C478-7AD6-4923-AC3A-B5C837C7B517}) (Version: 4.4.26.1391 - HP Inc.)
HP System Default Settings (HKLM-x32\...\{0543AB37-B3F9-4948-A6D7-AB574271DEAC}) (Version: 1.4.9.2 - HP Inc.) Hidden
HP Wolf Security - Console (HKLM\...\{75B6E6CE-A9AC-4801-A4A8-B22098A8355C}) (Version: 11.1.4.895 - HP Inc.)
HP Wolf Security (HKLM\...\{8CD49D08-67F1-11F0-9844-000C29910851}) (Version: 4.4.26.1391 - HP Inc.)
HP Wolf Security Application Support for Chrome 138.0.7204.170 (HKLM\...\{6C174EDA-F80B-4926-B659-F08E5C7BBC59}) (Version: 4.4.26.1406 - HP Inc.) Hidden
HP Wolf Security Application Support for Sure Sense (HKLM\...\{0B429B75-9F00-490C-89C6-BF7A97FCE2F0}) (Version: 4.4.26.1391 - HP Inc.) Hidden
HPSSupply (HKLM-x32\...\{7902E313-FF0F-4493-ACB1-A8147B78DCD0}) (Version: 2.1.1.0000 - Hewlett Packard Development Company L.P.)
Intel(R) Chipset Device Software (HKLM\...\{00C43022-CFDA-4942-9D3F-04199C91C939}) (Version: 10.1.18121.8164 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{37942a92-9e3f-4d70-9b5c-5955cbc54505}) (Version: 10.1.18121.8164 - Intel(R) Corporation)
Intel(R) Icls (HKLM\...\{AE33809B-734E-4A79-BBDC-0DDE03950065}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) LMS (HKLM\...\{4479B4B8-D77B-474A-ABC5-1E5A4356F7DE}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1A9FE6B4-801A-4AF0-AEDB-EA49BD80C9F2}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2205.15.0.2623 - Intel Corporation)
Intel(R) Management Engine Driver (HKLM\...\{F0A3D842-E346-45C5-9546-90FEFD477F6E}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.7261 - Intel Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Malwarebytes version 5.4.0.213 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.4.0.213 - Malwarebytes)
Microsoft .NET Host - 7.0.20 (x64) (HKLM\...\{EE5EB03B-D65C-4991-848E-2C6E024326DB}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.20 (x64) (HKLM\...\{B0FC828F-678C-4868-9B5B-99639758E6F3}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 7.0.20 (x64) (HKLM\...\{221BB52A-B763-4C9D-AA62-4B0B6C9AAD62}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft 365 - cs-cz (HKLM\...\O365HomePremRetail - cs-cz) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 - sk-sk (HKLM\...\O365HomePremRetail - sk-sk) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 Apps pro firmy - cs-cz (HKLM\...\O365BusinessRetail - cs-cz) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft ASP.NET Core 7.0.20 - Shared Framework (x64) (HKLM-x32\...\{6c2f4b5b-86d2-4aff-bf79-d1e73cc20ab3}) (Version: 7.0.20.24269 - Microsoft Corporation)
Microsoft ASP.NET Core 7.0.20 Shared Framework (x64) (HKLM\...\{BD401329-F877-391C-9E5A-FEB423C5A196}) (Version: 7.0.20.24269 - Microsoft Corporation) Hidden
Microsoft Bing Service (HKLM-x32\...\{27990F25-A90A-4CE5-868E-1A1BB70A58EE}) (Version: 2.0.0.7 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\{871D86E3-8175-34F3-9C07-7679EC1CF1D1}) (Version: 141.0.3537.57 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 141.0.3537.57 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\OneDriveSetup.exe) (Version: 25.174.0907.0003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3530282796-2492871232-3359154168-500\...\OneDriveSetup.exe) (Version: 25.087.0506.0001 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Teams) (Version: 1.8.00.21151 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.31301 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{BACA8ED0-DB44-468A-9D76-7D4588B90D60}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{3FED85F2-4004-4F8A-B65B-DDC1F6013FAA}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM\...\{72C29BED-666F-4E5E-BC49-DF44C890742E}) (Version: 56.80.15245 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM-x32\...\{362ea044-f96f-45c7-b59f-0dbe5ca98ff4}) (Version: 7.0.20.33720 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 143.0.4 (x64 cs)) (Version: 143.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 132.0.2 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.19231.20072 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.19029.20156 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Pentablet (HKLM\...\{5DAB8C1A-6D8E-467D-BE62-AC13087AA950}_is1) (Version: 3.4.3.230310 - XPPen Technology)
PosteRazor (HKLM-x32\...\PosteRazor_is1) (Version: 1.5.2 - Alessandro Portale)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Skype 8.134 (HKLM-x32\...\{6F9453A2-F32E-4BB7-9E60-F4EAD9B799A9}) (Version: 8.134.0.202 - Skype Technologies S.A.)
Skype verze 8.134 (HKLM-x32\...\Skype_is1) (Version: 8.134 - Skype Technologies S.A.) Hidden
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.3.0.9267 - Microsoft Corporation)
Vcows 2.0.6 (HKLM\...\{E56AB601-3746-4243-BD26-09D63162C7AA}_is1) (Version: 2.0.6 - Vcows Software)
Windows Driver Package - HP Inc. BrCow_4_4_26_1391 ActivityMonitor (07/23/2025 4.4.26.1391) (HKLM\...\35EE803A85F6C575E85E83A231CEF99D88E1397A) (Version: 07/23/2025 4.4.26.1391 - HP Inc.) Hidden
Windows Driver Package - HP Inc. BrFilter_4_4_26_1391 ActivityMonitor (07/23/2025 4.4.26.1391) (HKLM\...\24DED937F1CF88463C61BCEEC433424A2E9175CB) (Version: 07/23/2025 4.4.26.1391 - HP Inc.) Hidden
Windows Driver Package - HP Inc. sselam_4_4_19_828 AntiVirus (08/09/2024 4.4.19.828) (HKLM\...\FB93285F183DE6985F684AEE5F637905935D05BF) (Version: 08/09/2024 4.4.19.828 - HP Inc.) Hidden

Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-11] ()
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2025-10-05] ()
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2024-12-11] (INTEL CORP) [Startup Task]
Audio Controls -> C:\Program Files\WindowsApps\22094SynapticsIncorporate.AudioControls_1.3.99.0_x64__qt57b6kdvhcfw [2024-12-11] (Synaptics Hong Kong Limited, Taiwan Branch (H.K.))
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation)
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2025-10-07] (Sparse Package)
HP Desktop Support Utilities -> C:\Program Files\WindowsApps\AD2F1837.HPDesktopSupportUtilities_7.0.8.0_x64__v10z8vjag6ke6 [2025-01-28] (HP Inc.)
HP JumpStarts -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStarts_1.10.1627.0_x64__v10z8vjag6ke6 [2025-01-08] (HP Inc.)
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_2.8.1.0_x64__v10z8vjag6ke6 [2025-09-20] (HP Inc.)
HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.4.17.0_x64__v10z8vjag6ke6 [2025-08-22] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_161.1.1087.0_x64__v10z8vjag6ke6 [2025-08-29] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.47.41.0_x64__v10z8vjag6ke6 [2025-09-12] (HP Inc.)
HP System Information -> C:\Program Files\WindowsApps\AD2F1837.HPSystemInformation_8.10.45.0_x64__v10z8vjag6ke6 [2025-05-20] (HP Inc.)
Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2024-12-11] (INTEL CORP)
Local Artificial Intelligence Manager -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2025-10-05] ()
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2025-10-05] ()
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation) [MS Ad]
Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2025-10-05] ()
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2025-10-05] ()
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0 [2025-09-25] (Spotify AB) [Startup Task]
WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-22] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8000.616.304.0_x64__8wekyb3d8bbwe [2025-09-10] (Microsoft Corp.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{82A6D7A6-FC2E-4DFD-AAEF-E3BBF9AD71AD}\localserver32 -> C:\Program Files\Fotolab\CEWE fotosvet\AutoBookService.exe () [File not signed]
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BromiumOverlay_4_4_26_1391] -> {6CDCC3E8-D8FF-46EF-B8BE-63A0593C7E4E} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ShellIconOverlayIdentifiers: [ AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers-x32: [ BromiumOverlay_4_4_26_1391] -> {6CDCC3E8-D8FF-46EF-B8BE-63A0593C7E4E} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2025-09-07] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-22] () [File not signed]
ContextMenuHandlers2: [Bromium TrustDrive Context Menu_4_4_26_1391] -> {5F4F5529-DD35-4B9F-812F-A5B0B3FF5492} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-02] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers3: [SureSense_ScanFile_4_4_26_1391] -> {1003406D-B16C-4A93-B2F0-13CCAAD250E2} => C:\Program Files\HP\Sure Click\ApplicationSupport\sure_sense\4.4.26.1391\SureSenseShellExt.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers3: [vSentry_TrustFile_4_4_26_1391] -> {833378FE-1986-46BA-9B4E-F8F1D9B29D00} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2024-05-22] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-22] () [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-02] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2024-05-22] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2009-10-15 12:13 - 2009-10-15 12:13 - 000061440 _____ () [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPTools.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000964096 _____ () [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\LEDMXMLObjects.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000382464 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPCPFelica.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000338432 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPDevice2.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000456192 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPDevice5.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000032768 _____ (HP) [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPHTTPProxy.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000031744 _____ (HP) [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPServiceCommunicator.dll
2023-10-05 16:35 - 2023-09-12 10:52 - 008382976 _____ (wondershare) [File not signed] C:\ProgramData\Wondershare\wsServices\WsidClient.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe:MBAM.Zone.Identifier [224]
AlternateDataStreams: C:\Users\safro\Downloads\dům 1.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\safro\Downloads\dům 2.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\sharepoint.com -> hxxps://zuzanasafrova-files.sharepoint.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2022-09-18 15:57 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 62.24.64.2 - 8.8.8.8
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt68cx21x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Pozadí plochy.bmp
HKU\S-1-5-21-3530282796-2492871232-3359154168-1008\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3530282796-2492871232-3359154168-500\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_0.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
HKLM\...\StartupApproved\Run: => "PenTablet"
HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\StartupFolder: => "CEWE služba na pozadí.lnk"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_8B3575D364394B552A9C25D557FBDA68"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "BingSvc"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "Mozilla-Firefox-308046B0AF4A39CB"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D0B184A7-6D52-4C48-897D-140BD7A6F353}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{DABFF653-A5E5-4521-B6AF-1B5F60D10FB5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{F8A4B796-F877-4E10-A712-8065DAF0DE52}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{4210D988-5DC2-44D2-80D6-4E9DC5386A6B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{F95611D3-953E-47B0-8523-AA5803A2BF78}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{E351475D-8610-4035-AAE2-F67051A27598}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{266E7165-18AD-41C6-B9A2-22F7C72DBB11}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{1EDA986E-46DE-4A4D-BC45-FF2B9C5D0FB7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{EA176052-6DF6-4AFD-B602-C61960B4F133}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{171D8BFC-D7DB-4D77-97B1-73DC2C3A61D3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{86B628A2-9658-417C-A3D7-13F163631063}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D8ABF27C-8370-4448-B670-3B70E3AA6537}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F8253C58-A590-4860-AEB3-9C439AAAE94C}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24295.402.3249.3850_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A8B45281-004B-46BD-96BC-0E002774730B}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24295.402.3249.3850_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9386FE13-9B9B-4085-B8D7-C7C9F8192F91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3B2A4243-1E39-4C08-B1D0-AC9FD6F43376}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{745668C2-1AEB-4D2E-945E-B1A7E74C15E6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5158859D-AE2A-4FA9-8CF7-A99A858BC518}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{0E6A422F-B807-440E-A9BA-8423B81DC310}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerCompress\ApowerCompress.exe (Apowersoft Ltd -> Wangxu Technology Co.,Ltd.)
FirewallRules: [{614A9769-FD95-46F3-A710-CC73E76EB958}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerCompress\ApowerCompress.exe (Apowersoft Ltd -> Wangxu Technology Co.,Ltd.)
FirewallRules: [{79588B28-F54B-4D3A-9055-F764571B0DC6}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{A7D7256C-5086-4E3C-AF56-7F861233E55E}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{9847D37C-418A-4F12-8172-542853480EDF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{4D441A47-E117-4CF7-82EF-3660804B0D0B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C7105644-92C7-4514-AA67-ED1F1C70800B}] => (Allow) C:\hp\Diagnostics\PSDR\HPDiagnosticCoreUI.exe (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{9FACFD9B-83E9-4BE6-BB12-0B62F0DDF13E}] => (Allow) C:\hp\Diagnostics\PSDR\HPDiagnosticCoreUI.exe (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{C96A3876-7F5F-452E-8C47-ACF4E1A33364}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{72D8F8DE-F138-40FC-86A0-71F6777ABB83}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E92455EB-3D07-4AF4-96F0-4824AFBC1A32}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FA8393A4-7A7A-499D-8DEC-522EB14D526D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{21B1D686-A71F-4EEC-BA63-908EB5DC0D86}] => (Allow) C:\Program Files\HP\Sure Click\4.4.26.1391\servers\manifests\chrome\brchromium\136.0.7103.179\BrChrome.exe (Bromium UK Limited -> HP)
FirewallRules: [{286AC0B9-7F5E-491A-8635-E349017E323A}] => (Allow) C:\Users\safro\Downloads\vcows-ppc(1).exe (SMARTSHARE CO., LIMITED -> Vcows)
FirewallRules: [{978412E6-E782-4B5F-9AA9-0BF162D6F457}] => (Allow) C:\Users\safro\Downloads\vcows-ppc(1).exe (SMARTSHARE CO., LIMITED -> Vcows)
FirewallRules: [{69569FA5-39A6-4140-B102-06707788119E}] => (Allow) C:\Program Files (x86)\Vcows\Vcows.exe (PixelVista Co., Limited -> Vcows Software)
FirewallRules: [{7E364A1D-53B4-4FAE-9FD6-4E07C885B1EE}] => (Allow) C:\Program Files (x86)\Vcows\Update.exe (PixelVista Co., Limited -> )
FirewallRules: [{08A5D1E5-CCD3-4250-834E-D820FBD42586}] => (Allow) C:\Program Files (x86)\Vcows\DownLoadProcess.exe => No File
FirewallRules: [{D26A2B5F-F9A3-400A-844E-E60297326AAD}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\AI-Center.exe => No File
FirewallRules: [{5865A713-1826-4322-986B-1BA39D99DF6A}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\video\face_track\face_track_server.exe => No File
FirewallRules: [{9D3D0A79-1351-4A65-9D78-3ADBA7D551E6}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\AI-Center.exe => No File
FirewallRules: [{70A58689-6C47-4819-ACB6-4C52EDBFE58F}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\ZNCJPackage\ZNCJ_Server.exe => No File
FirewallRules: [{F5DBF784-159F-4F4D-8B2E-6FFD3A46B252}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\VcowsPrimeVideo.exe => No File
FirewallRules: [{61F71D58-A0C3-49B8-8A09-09264C7993EB}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\data\bin\native\sheller.exe => No File
FirewallRules: [{4CCEB92C-CD82-43EA-81C8-2C4EBA99FDF0}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\VcowsNetflix.exe => No File
FirewallRules: [{3EA9590F-E33B-4BA2-AB86-97AE48DEDCC7}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\data\bin\native\sheller.exe => No File
FirewallRules: [{704A05C1-8F9E-47C4-8494-38365EA1181F}] => (Allow) C:\Program Files\HP\Sure Click\ApplicationSupport\chrome\4.4.26.1406\brchromium\138.0.7204.170\BrChrome.exe (Bromium UK Limited -> HP)
FirewallRules: [{BF5583F1-4416-4DFE-BC2D-61599D246CCB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{07B1FA18-81D1-4FE7-81E9-2D42697969B7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{5CA62EF5-D5C1-490E-853A-472BAF171317}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{DD2FDBA6-1AEF-4754-AD89-D1A5B81C4640}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A8817300-6708-484E-A5A8-9C7BAA362CC5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{E08CDCA7-7E6E-475D-96F6-56F45549B74A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{68090CF7-7D59-47DB-A621-671DD7DE0196}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{356E3558-F76C-4ED7-9B92-6040C83B667E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{0D52429E-7744-42AB-A880-260703BBF3A1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1E85FC00-C256-4296-88B7-946656CB5B02}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{82B4EB75-0E96-42A0-ADB7-DE8EEFB5794A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B23C634E-E005-4C05-8229-2F3DB9C71B6A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{C684FAE9-36AB-4B6E-8A8F-100276F02336}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{AE062DCB-BED0-4106-9F0A-094B5352BF2A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{DEC3A504-8C94-4865-A307-1EA149C062B7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4CB6DA0C-320A-43BA-BFD7-EB0AD8006F58}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7FCE310D-6DB1-4F36-B3B3-E42F4CC6E86B}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DB2ECD51-63DE-4ABB-B8B6-0D2BF82C1A6E}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{78287A8A-2BDA-42AF-89EE-39717FAF2297}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FC154809-8B7C-491B-8811-B43FA2CC07EC}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)

==================== Restore Points =========================

05-10-2025 09:23:47 Grab_MSIExecute

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (10/08/2025 08:24:24 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:24 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z

Error: (10/08/2025 08:24:20 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:20 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z

Error: (10/08/2025 08:24:16 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:16 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z

Error: (10/08/2025 08:24:12 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:12 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z


System errors:
=============
Error: (10/07/2025 09:39:11 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -1878589247. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (10/07/2025 09:36:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/07/2025 09:36:16 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (10/07/2025 09:34:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba CxUIUSvc neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/07/2025 09:34:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby CxUIUSvc bylo dosaženo časového limitu (45000 ms).

Error: (10/07/2025 09:34:11 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1096) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo. Systém Windows nemohl použít nastavení zásad týkající se registru pro objekt zásad skupiny LocalGPO. Nastavení zásad skupiny nebude vyřešeno, dokud nebude vyřešena tato událost. Další informace o názvu souboru a cestě, které jsou příčinou selhání, zobrazíte pomocí detailů událostí.

Error: (10/07/2025 09:01:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B59IHMH)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/07/2025 09:01:28 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B59IHMH)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.


CodeIntegrity:
===============
Date: 2025-10-08 07:48:41
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: HP R03 Ver. 02.22.00 12/30/2024
Motherboard: HP 8599
Processor: Intel(R) Core(TM) i5-9500 CPU @ 3.00GHz
Percentage of memory in use: 49%
Total physical RAM: 16222.29 MB
Available physical RAM: 8167.25 MB
Total Virtual: 32606.29 MB
Available Virtual: 23877 MB

==================== Drives ================================

Drive c: (Windows ) (Fixed) (Total:475.92 GB) (Free:121.65 GB) (Model: WDC PC SN520 SDAPNUW-512G-1006) (Protected) NTFS
Drive f: (2020 Elements) (Fixed) (Total:2794.49 GB) (Free:2716.13 GB) (Model: WD Elements 25A3 USB Device) NTFS
Drive g: (Elements) (Fixed) (Total:1862.98 GB) (Free:1558.24 GB) (Model: WD Elements 107C USB Device) NTFS

\\?\Volume{52f48983-432c-4b4e-a5ca-5a3c84de645a}\ () (Fixed) (Total:0.74 GB) (Free:0.11 GB) NTFS
\\?\Volume{f2dd5105-3d43-4ecb-9619-823b99375fc3}\ (SYSTEM) (Fixed) (Total:0.25 GB)
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#13 Příspěvek od Ecinazuz »

asi jsem ten druhý nezkopírovala selý, tak ještě jednou

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by safro (08-10-2025 08:30:49)
Running from C:\Users\safro\Desktop
Microsoft Windows 11 Pro Version 24H2 26100.6584 (X64) (2025-01-30 19:15:40)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3530282796-2492871232-3359154168-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-3530282796-2492871232-3359154168-503 - Limited - Disabled)
Guest (S-1-5-21-3530282796-2492871232-3359154168-501 - Limited - Disabled)
safro (S-1-5-21-3530282796-2492871232-3359154168-1001 - Administrator - Enabled) => C:\Users\safro
WDAGUtilityAccount (S-1-5-21-3530282796-2492871232-3359154168-504 - Limited - Disabled)
WsiAccount (S-1-5-21-3530282796-2492871232-3359154168-1008 - Limited - Disabled) => C:\Users\WsiAccount

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Security (Enabled - Up to date) {DF8BEACB-94C9-218A-73AD-A78362A8C516}
AV: ESET Security (Enabled - Up to date) {89B55CC4-3881-78B2-11E2-479AE0371896}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}
FW: ESET Firewall (Enabled) {E7B06BEE-DEA6-20D2-58F2-0EB69C7B826D}
FW: ESET Firewall (Enabled) {B18EDDE1-72EE-79EA-3ABD-EEAF1EE45FED}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acronis Drivers (HKLM\...\{7C36ADC0-5219-4D31-90D1-4211321481EF}) (Version: 25.8.39216 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}) (Version: 25.8.39216 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}Visible) (Version: 25.8.39216 - Acronis)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 25.001.20693 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601120}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
ApowerCompress V1.1.18 (HKLM-x32\...\{10998dc6-e8e2-48ef-9378-0db3d4c7f32a}_is1) (Version: 1.1.18 - Wangxu Technology Co.,Ltd.)
Audacity 3.7.5 (HKLM\...\Audacity_is1) (Version: 3.7.5 - Audacity Team)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.0.984.1153 - Piriform)
CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 140.0.32231.210 - Autoři prohlížeče CCleaner Browser)
CCleaner Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1067.0 - Piriform Software) Hidden
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1583.3 - Piriform Software) Hidden
CEWE fotosvet (HKLM\...\CEWE fotosvet) (Version: 7.3.3 - CEWE Stiftung u Co. KGaA)
CPUID HWMonitor 1.54 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.54 - CPUID, Inc.)
CrystalDiskInfo 8.17.5 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.17.5 - Crystal Dew World)
Dynamic Application Loader Host Interface Service (HKLM\...\{9DE7A0A5-C13D-4FDD-B78B-53C744C82F1A}) (Version: 1.0.0.0 - Intel Corporation) Hidden
ESET Security (HKLM\...\{32DA3D18-091D-4B85-BFD4-C17C514674ED}) (Version: 18.2.18.0 - ESET, spol. s r.o.)
Express Burn Disc Burning Software (HKLM-x32\...\ExpressBurn) (Version: 10.30 - NCH Software)
Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 9.26 - NCH Software)
FastStone Photo Resizer 4.4 (HKLM-x32\...\FastStone Photo Resizer) (Version: 4.4 - FastStone Corporation)
Google Chrome (HKLM\...\{15971136-C56A-3015-AC9D-ED17B8F94952}) (Version: 140.0.7339.186 - Google LLC)
HappyFoto (HKLM\...\{621A70CA-32A5-4F50-A66C-C9C792580415}_is1) (Version: - Happy Foto CZ)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 11.0.0.320 - Huawei Technologies Co., Ltd.)
HP Client Security Manager (HKLM\...\{456CC699-FD29-4835-9CE6-BB3E63DC76E3}) (Version: 9.5.3.2908 - HP Inc.) Hidden
HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 9.5.3.2908 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP Hotkey Support (HKLM-x32\...\{6606696F-B31A-48B7-B05D-FB5DDFAD9FAB}) (Version: 6.2.52.1 - HP Inc.)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version: - )
HP Notifications (HKLM-x32\...\{84937F28-9CB4-49E7-A2CF-E32D97E6DAE6}) (Version: 1.1.28.1 - HP)
HP One Agent (HKLM\...\{7CF09040-C14A-4FAA-B61A-1A7F2BDE3719}) (Version: 1.1.973.9172 - HP Inc.)
HP One Agent (HKLM\...\{7EFF7A5C-E41B-4E5C-B075-08C00AA3F2EB}) (Version: 1.1.973.9172 - HP Inc.) Hidden
HP Security Update Service (HKLM\...\{74C6C478-7AD6-4923-AC3A-B5C837C7B517}) (Version: 4.4.26.1391 - HP Inc.)
HP System Default Settings (HKLM-x32\...\{0543AB37-B3F9-4948-A6D7-AB574271DEAC}) (Version: 1.4.9.2 - HP Inc.) Hidden
HP Wolf Security - Console (HKLM\...\{75B6E6CE-A9AC-4801-A4A8-B22098A8355C}) (Version: 11.1.4.895 - HP Inc.)
HP Wolf Security (HKLM\...\{8CD49D08-67F1-11F0-9844-000C29910851}) (Version: 4.4.26.1391 - HP Inc.)
HP Wolf Security Application Support for Chrome 138.0.7204.170 (HKLM\...\{6C174EDA-F80B-4926-B659-F08E5C7BBC59}) (Version: 4.4.26.1406 - HP Inc.) Hidden
HP Wolf Security Application Support for Sure Sense (HKLM\...\{0B429B75-9F00-490C-89C6-BF7A97FCE2F0}) (Version: 4.4.26.1391 - HP Inc.) Hidden
HPSSupply (HKLM-x32\...\{7902E313-FF0F-4493-ACB1-A8147B78DCD0}) (Version: 2.1.1.0000 - Hewlett Packard Development Company L.P.)
Intel(R) Chipset Device Software (HKLM\...\{00C43022-CFDA-4942-9D3F-04199C91C939}) (Version: 10.1.18121.8164 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{37942a92-9e3f-4d70-9b5c-5955cbc54505}) (Version: 10.1.18121.8164 - Intel(R) Corporation)
Intel(R) Icls (HKLM\...\{AE33809B-734E-4A79-BBDC-0DDE03950065}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) LMS (HKLM\...\{4479B4B8-D77B-474A-ABC5-1E5A4356F7DE}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1A9FE6B4-801A-4AF0-AEDB-EA49BD80C9F2}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2205.15.0.2623 - Intel Corporation)
Intel(R) Management Engine Driver (HKLM\...\{F0A3D842-E346-45C5-9546-90FEFD477F6E}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.7261 - Intel Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Malwarebytes version 5.4.0.213 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.4.0.213 - Malwarebytes)
Microsoft .NET Host - 7.0.20 (x64) (HKLM\...\{EE5EB03B-D65C-4991-848E-2C6E024326DB}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.20 (x64) (HKLM\...\{B0FC828F-678C-4868-9B5B-99639758E6F3}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 7.0.20 (x64) (HKLM\...\{221BB52A-B763-4C9D-AA62-4B0B6C9AAD62}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft 365 - cs-cz (HKLM\...\O365HomePremRetail - cs-cz) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 - sk-sk (HKLM\...\O365HomePremRetail - sk-sk) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft 365 Apps pro firmy - cs-cz (HKLM\...\O365BusinessRetail - cs-cz) (Version: 16.0.19231.20156 - Microsoft Corporation)
Microsoft ASP.NET Core 7.0.20 - Shared Framework (x64) (HKLM-x32\...\{6c2f4b5b-86d2-4aff-bf79-d1e73cc20ab3}) (Version: 7.0.20.24269 - Microsoft Corporation)
Microsoft ASP.NET Core 7.0.20 Shared Framework (x64) (HKLM\...\{BD401329-F877-391C-9E5A-FEB423C5A196}) (Version: 7.0.20.24269 - Microsoft Corporation) Hidden
Microsoft Bing Service (HKLM-x32\...\{27990F25-A90A-4CE5-868E-1A1BB70A58EE}) (Version: 2.0.0.7 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\{871D86E3-8175-34F3-9C07-7679EC1CF1D1}) (Version: 141.0.3537.57 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 141.0.3537.57 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\OneDriveSetup.exe) (Version: 25.174.0907.0003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3530282796-2492871232-3359154168-500\...\OneDriveSetup.exe) (Version: 25.087.0506.0001 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\Teams) (Version: 1.8.00.21151 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.31301 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{BACA8ED0-DB44-468A-9D76-7D4588B90D60}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{3FED85F2-4004-4F8A-B65B-DDC1F6013FAA}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM\...\{72C29BED-666F-4E5E-BC49-DF44C890742E}) (Version: 56.80.15245 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM-x32\...\{362ea044-f96f-45c7-b59f-0dbe5ca98ff4}) (Version: 7.0.20.33720 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 143.0.4 (x64 cs)) (Version: 143.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 132.0.2 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.19231.20072 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.19029.20156 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Pentablet (HKLM\...\{5DAB8C1A-6D8E-467D-BE62-AC13087AA950}_is1) (Version: 3.4.3.230310 - XPPen Technology)
PosteRazor (HKLM-x32\...\PosteRazor_is1) (Version: 1.5.2 - Alessandro Portale)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Skype 8.134 (HKLM-x32\...\{6F9453A2-F32E-4BB7-9E60-F4EAD9B799A9}) (Version: 8.134.0.202 - Skype Technologies S.A.)
Skype verze 8.134 (HKLM-x32\...\Skype_is1) (Version: 8.134 - Skype Technologies S.A.) Hidden
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.3.0.9267 - Microsoft Corporation)
Vcows 2.0.6 (HKLM\...\{E56AB601-3746-4243-BD26-09D63162C7AA}_is1) (Version: 2.0.6 - Vcows Software)
Windows Driver Package - HP Inc. BrCow_4_4_26_1391 ActivityMonitor (07/23/2025 4.4.26.1391) (HKLM\...\35EE803A85F6C575E85E83A231CEF99D88E1397A) (Version: 07/23/2025 4.4.26.1391 - HP Inc.) Hidden
Windows Driver Package - HP Inc. BrFilter_4_4_26_1391 ActivityMonitor (07/23/2025 4.4.26.1391) (HKLM\...\24DED937F1CF88463C61BCEEC433424A2E9175CB) (Version: 07/23/2025 4.4.26.1391 - HP Inc.) Hidden
Windows Driver Package - HP Inc. sselam_4_4_19_828 AntiVirus (08/09/2024 4.4.19.828) (HKLM\...\FB93285F183DE6985F684AEE5F637905935D05BF) (Version: 08/09/2024 4.4.19.828 - HP Inc.) Hidden

Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-11] ()
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2025-10-05] ()
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2024-12-11] (INTEL CORP) [Startup Task]
Audio Controls -> C:\Program Files\WindowsApps\22094SynapticsIncorporate.AudioControls_1.3.99.0_x64__qt57b6kdvhcfw [2024-12-11] (Synaptics Hong Kong Limited, Taiwan Branch (H.K.))
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation)
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2025-10-07] (Sparse Package)
HP Desktop Support Utilities -> C:\Program Files\WindowsApps\AD2F1837.HPDesktopSupportUtilities_7.0.8.0_x64__v10z8vjag6ke6 [2025-01-28] (HP Inc.)
HP JumpStarts -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStarts_1.10.1627.0_x64__v10z8vjag6ke6 [2025-01-08] (HP Inc.)
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_2.8.1.0_x64__v10z8vjag6ke6 [2025-09-20] (HP Inc.)
HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.4.17.0_x64__v10z8vjag6ke6 [2025-08-22] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_161.1.1087.0_x64__v10z8vjag6ke6 [2025-08-29] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.47.41.0_x64__v10z8vjag6ke6 [2025-09-12] (HP Inc.)
HP System Information -> C:\Program Files\WindowsApps\AD2F1837.HPSystemInformation_8.10.45.0_x64__v10z8vjag6ke6 [2025-05-20] (HP Inc.)
Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2024-12-11] (INTEL CORP)
Local Artificial Intelligence Manager -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2025-10-05] ()
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2025-10-05] ()
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2024-12-11] (Microsoft Corporation) [MS Ad]
Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2025-10-05] ()
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2025-10-05] ()
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0 [2025-09-25] (Spotify AB) [Startup Task]
WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-22] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8000.616.304.0_x64__8wekyb3d8bbwe [2025-09-10] (Microsoft Corp.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{82A6D7A6-FC2E-4DFD-AAEF-E3BBF9AD71AD}\localserver32 -> C:\Program Files\Fotolab\CEWE fotosvet\AutoBookService.exe () [File not signed]
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\OneDrive\25.174.0907.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\safro\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BromiumOverlay_4_4_26_1391] -> {6CDCC3E8-D8FF-46EF-B8BE-63A0593C7E4E} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ShellIconOverlayIdentifiers: [ AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers: [ AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> )
ShellIconOverlayIdentifiers-x32: [ BromiumOverlay_4_4_26_1391] -> {6CDCC3E8-D8FF-46EF-B8BE-63A0593C7E4E} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2025-09-07] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-22] () [File not signed]
ContextMenuHandlers2: [Bromium TrustDrive Context Menu_4_4_26_1391] -> {5F4F5529-DD35-4B9F-812F-A5B0B3FF5492} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-02] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers3: [SureSense_ScanFile_4_4_26_1391] -> {1003406D-B16C-4A93-B2F0-13CCAAD250E2} => C:\Program Files\HP\Sure Click\ApplicationSupport\sure_sense\4.4.26.1391\SureSenseShellExt.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers3: [vSentry_TrustFile_4_4_26_1391] -> {833378FE-1986-46BA-9B4E-F8F1D9B29D00} => C:\Program Files\HP\Sure Click\4.4.26.1391\servers\HostShellExtension.dll [2025-07-23] (Bromium UK Limited -> HP)
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2024-05-22] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-09-10] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-22] () [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-10-02] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2024-05-22] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2009-10-15 12:13 - 2009-10-15 12:13 - 000061440 _____ () [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPTools.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000964096 _____ () [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\LEDMXMLObjects.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000382464 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPCPFelica.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000338432 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPDevice2.dll
2020-04-30 13:40 - 2020-04-30 13:40 - 000456192 _____ (Crossmatch, Inc.) [File not signed] C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DPDevice5.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000032768 _____ (HP) [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPHTTPProxy.dll
2009-10-15 12:13 - 2009-10-15 12:13 - 000031744 _____ (HP) [File not signed] [File is in use] C:\Program Files (x86)\HP\HPLaserJetService\HPServiceCommunicator.dll
2023-10-05 16:35 - 2023-09-12 10:52 - 008382976 _____ (wondershare) [File not signed] C:\ProgramData\Wondershare\wsServices\WsidClient.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe:MBAM.Zone.Identifier [224]
AlternateDataStreams: C:\Users\safro\Downloads\dům 1.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\safro\Downloads\dům 2.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-09-25] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\sharepoint.com -> hxxps://zuzanasafrova-files.sharepoint.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2022-09-18 15:57 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 62.24.64.2 - 8.8.8.8
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt68cx21x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\safro\AppData\Roaming\Mozilla\Firefox\Pozadí plochy.bmp
HKU\S-1-5-21-3530282796-2492871232-3359154168-1008\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3530282796-2492871232-3359154168-500\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_0.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
HKLM\...\StartupApproved\Run: => "PenTablet"
HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\StartupFolder: => "CEWE služba na pozadí.lnk"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_8B3575D364394B552A9C25D557FBDA68"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "BingSvc"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "Mozilla-Firefox-308046B0AF4A39CB"
HKU\S-1-5-21-3530282796-2492871232-3359154168-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D0B184A7-6D52-4C48-897D-140BD7A6F353}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{DABFF653-A5E5-4521-B6AF-1B5F60D10FB5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{F8A4B796-F877-4E10-A712-8065DAF0DE52}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{4210D988-5DC2-44D2-80D6-4E9DC5386A6B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{F95611D3-953E-47B0-8523-AA5803A2BF78}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{E351475D-8610-4035-AAE2-F67051A27598}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{266E7165-18AD-41C6-B9A2-22F7C72DBB11}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{1EDA986E-46DE-4A4D-BC45-FF2B9C5D0FB7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{EA176052-6DF6-4AFD-B602-C61960B4F133}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{171D8BFC-D7DB-4D77-97B1-73DC2C3A61D3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.255.235.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{86B628A2-9658-417C-A3D7-13F163631063}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D8ABF27C-8370-4448-B670-3B70E3AA6537}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F8253C58-A590-4860-AEB3-9C439AAAE94C}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24295.402.3249.3850_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A8B45281-004B-46BD-96BC-0E002774730B}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24295.402.3249.3850_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9386FE13-9B9B-4085-B8D7-C7C9F8192F91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3B2A4243-1E39-4C08-B1D0-AC9FD6F43376}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{745668C2-1AEB-4D2E-945E-B1A7E74C15E6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5158859D-AE2A-4FA9-8CF7-A99A858BC518}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{0E6A422F-B807-440E-A9BA-8423B81DC310}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerCompress\ApowerCompress.exe (Apowersoft Ltd -> Wangxu Technology Co.,Ltd.)
FirewallRules: [{614A9769-FD95-46F3-A710-CC73E76EB958}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerCompress\ApowerCompress.exe (Apowersoft Ltd -> Wangxu Technology Co.,Ltd.)
FirewallRules: [{79588B28-F54B-4D3A-9055-F764571B0DC6}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{A7D7256C-5086-4E3C-AF56-7F861233E55E}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{9847D37C-418A-4F12-8172-542853480EDF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{4D441A47-E117-4CF7-82EF-3660804B0D0B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C7105644-92C7-4514-AA67-ED1F1C70800B}] => (Allow) C:\hp\Diagnostics\PSDR\HPDiagnosticCoreUI.exe (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{9FACFD9B-83E9-4BE6-BB12-0B62F0DDF13E}] => (Allow) C:\hp\Diagnostics\PSDR\HPDiagnosticCoreUI.exe (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{C96A3876-7F5F-452E-8C47-ACF4E1A33364}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{72D8F8DE-F138-40FC-86A0-71F6777ABB83}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E92455EB-3D07-4AF4-96F0-4824AFBC1A32}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FA8393A4-7A7A-499D-8DEC-522EB14D526D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{21B1D686-A71F-4EEC-BA63-908EB5DC0D86}] => (Allow) C:\Program Files\HP\Sure Click\4.4.26.1391\servers\manifests\chrome\brchromium\136.0.7103.179\BrChrome.exe (Bromium UK Limited -> HP)
FirewallRules: [{286AC0B9-7F5E-491A-8635-E349017E323A}] => (Allow) C:\Users\safro\Downloads\vcows-ppc(1).exe (SMARTSHARE CO., LIMITED -> Vcows)
FirewallRules: [{978412E6-E782-4B5F-9AA9-0BF162D6F457}] => (Allow) C:\Users\safro\Downloads\vcows-ppc(1).exe (SMARTSHARE CO., LIMITED -> Vcows)
FirewallRules: [{69569FA5-39A6-4140-B102-06707788119E}] => (Allow) C:\Program Files (x86)\Vcows\Vcows.exe (PixelVista Co., Limited -> Vcows Software)
FirewallRules: [{7E364A1D-53B4-4FAE-9FD6-4E07C885B1EE}] => (Allow) C:\Program Files (x86)\Vcows\Update.exe (PixelVista Co., Limited -> )
FirewallRules: [{08A5D1E5-CCD3-4250-834E-D820FBD42586}] => (Allow) C:\Program Files (x86)\Vcows\DownLoadProcess.exe => No File
FirewallRules: [{D26A2B5F-F9A3-400A-844E-E60297326AAD}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\AI-Center.exe => No File
FirewallRules: [{5865A713-1826-4322-986B-1BA39D99DF6A}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\video\face_track\face_track_server.exe => No File
FirewallRules: [{9D3D0A79-1351-4A65-9D78-3ADBA7D551E6}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\AI-Center.exe => No File
FirewallRules: [{70A58689-6C47-4819-ACB6-4C52EDBFE58F}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\ZNCJPackage\ZNCJ_Server.exe => No File
FirewallRules: [{F5DBF784-159F-4F4D-8B2E-6FFD3A46B252}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\VcowsPrimeVideo.exe => No File
FirewallRules: [{61F71D58-A0C3-49B8-8A09-09264C7993EB}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\data\bin\native\sheller.exe => No File
FirewallRules: [{4CCEB92C-CD82-43EA-81C8-2C4EBA99FDF0}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\VcowsNetflix.exe => No File
FirewallRules: [{3EA9590F-E33B-4BA2-AB86-97AE48DEDCC7}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\data\bin\native\sheller.exe => No File
FirewallRules: [{704A05C1-8F9E-47C4-8494-38365EA1181F}] => (Allow) C:\Program Files\HP\Sure Click\ApplicationSupport\chrome\4.4.26.1406\brchromium\138.0.7204.170\BrChrome.exe (Bromium UK Limited -> HP)
FirewallRules: [{BF5583F1-4416-4DFE-BC2D-61599D246CCB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{07B1FA18-81D1-4FE7-81E9-2D42697969B7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{5CA62EF5-D5C1-490E-853A-472BAF171317}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{DD2FDBA6-1AEF-4754-AD89-D1A5B81C4640}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A8817300-6708-484E-A5A8-9C7BAA362CC5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{E08CDCA7-7E6E-475D-96F6-56F45549B74A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{68090CF7-7D59-47DB-A621-671DD7DE0196}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{356E3558-F76C-4ED7-9B92-6040C83B667E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{0D52429E-7744-42AB-A880-260703BBF3A1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1E85FC00-C256-4296-88B7-946656CB5B02}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{82B4EB75-0E96-42A0-ADB7-DE8EEFB5794A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B23C634E-E005-4C05-8229-2F3DB9C71B6A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{C684FAE9-36AB-4B6E-8A8F-100276F02336}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{AE062DCB-BED0-4106-9F0A-094B5352BF2A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.273.474.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{DEC3A504-8C94-4865-A307-1EA149C062B7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4CB6DA0C-320A-43BA-BFD7-EB0AD8006F58}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7FCE310D-6DB1-4F36-B3B3-E42F4CC6E86B}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DB2ECD51-63DE-4ABB-B8B6-0D2BF82C1A6E}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{78287A8A-2BDA-42AF-89EE-39717FAF2297}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25255.703.3978.7153_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FC154809-8B7C-491B-8811-B43FA2CC07EC}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)

==================== Restore Points =========================

05-10-2025 09:23:47 Grab_MSIExecute

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (10/08/2025 08:24:24 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:24 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z

Error: (10/08/2025 08:24:20 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:20 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z

Error: (10/08/2025 08:24:16 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:16 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z

Error: (10/08/2025 08:24:12 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: Failed to get auth header with 0x8086000c

Error: (10/08/2025 08:24:12 AM) (Source: Universal Print) (EventID: 1) (User: )
Description: User Interaction Required while trying to get a token silently. ErrorCode: 0xcaa20003, Error: AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2025-07-06T06:06:46.9663310Z and was inactive for 90.00:00:00. Trace ID: ffb1c33e-cc83-4b83-8b7f-12a87b2b5c00 Correlation ID: ae76ac28-9594-48ea-86f0-308b439a9994 Timestamp: 2025-10-08 06:23:24Z


System errors:
=============
Error: (10/07/2025 09:39:11 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error -1878589247. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Error: (10/07/2025 09:36:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/07/2025 09:36:16 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (10/07/2025 09:34:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba CxUIUSvc neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/07/2025 09:34:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby CxUIUSvc bylo dosaženo časového limitu (45000 ms).

Error: (10/07/2025 09:34:11 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1096) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo. Systém Windows nemohl použít nastavení zásad týkající se registru pro objekt zásad skupiny LocalGPO. Nastavení zásad skupiny nebude vyřešeno, dokud nebude vyřešena tato událost. Další informace o názvu souboru a cestě, které jsou příčinou selhání, zobrazíte pomocí detailů událostí.

Error: (10/07/2025 09:01:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B59IHMH)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/07/2025 09:01:28 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B59IHMH)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.


CodeIntegrity:
===============
Date: 2025-10-08 07:48:41
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: HP R03 Ver. 02.22.00 12/30/2024
Motherboard: HP 8599
Processor: Intel(R) Core(TM) i5-9500 CPU @ 3.00GHz
Percentage of memory in use: 49%
Total physical RAM: 16222.29 MB
Available physical RAM: 8167.25 MB
Total Virtual: 32606.29 MB
Available Virtual: 23877 MB

==================== Drives ================================

Drive c: (Windows ) (Fixed) (Total:475.92 GB) (Free:121.65 GB) (Model: WDC PC SN520 SDAPNUW-512G-1006) (Protected) NTFS
Drive f: (2020 Elements) (Fixed) (Total:2794.49 GB) (Free:2716.13 GB) (Model: WD Elements 25A3 USB Device) NTFS
Drive g: (Elements) (Fixed) (Total:1862.98 GB) (Free:1558.24 GB) (Model: WD Elements 107C USB Device) NTFS

\\?\Volume{52f48983-432c-4b4e-a5ca-5a3c84de645a}\ () (Fixed) (Total:0.74 GB) (Free:0.11 GB) NTFS
\\?\Volume{f2dd5105-3d43-4ecb-9619-823b99375fc3}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.15 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 390A4304)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: D954268B)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==========================================================
Disk: 2 (Size: 2794.5 GB) (Disk ID: 16F2A91F)

Partition: GPT.

==================== End of Addition.txt =======================
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15744
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu

#14 Příspěvek od JaRon »

ahoj,
citat:
Tvorba fixlistu pro FRST
•Spustte poznamkovy blok (Start-spustit-notepad)
•Zkopirujte skript >>

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
AppInit_DLLs: C:\PROGRA~1\HP\SURECL~1\servers\BemHook.dll => No File
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {8A59A006-099A-42F4-9040-46AA0067DDCD} - System32\Tasks\HPDataRetriever => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-application-info-collector_ver_4.675.11370\hp-data-retriever.exe (No File)
Task: {DB5845A0-A548-49BB-8035-A6B0CB2330CF} - System32\Tasks\HPSupportTool => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-iolo-collector_ver_4.675.11370\HPSupportAssistant1.exe (No File)
S3 ax_pvi; \??\C:\Program Files\HP\Sure Click\bin\ax_pvi.sys [X]

AlternateDataStreams: C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe:MBAM.Zone.Identifier [224]
AlternateDataStreams: C:\Users\safro\Downloads\dům 1.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\safro\Downloads\dům 2.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
FirewallRules: [{79588B28-F54B-4D3A-9055-F764571B0DC6}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{A7D7256C-5086-4E3C-AF56-7F861233E55E}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{08A5D1E5-CCD3-4250-834E-D820FBD42586}] => (Allow) C:\Program Files (x86)\Vcows\DownLoadProcess.exe => No File
FirewallRules: [{D26A2B5F-F9A3-400A-844E-E60297326AAD}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\AI-Center.exe => No File
FirewallRules: [{5865A713-1826-4322-986B-1BA39D99DF6A}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\video\face_track\face_track_server.exe => No File
FirewallRules: [{9D3D0A79-1351-4A65-9D78-3ADBA7D551E6}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\AI-Center.exe => No File
FirewallRules: [{70A58689-6C47-4819-ACB6-4C52EDBFE58F}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\ZNCJPackage\ZNCJ_Server.exe => No File
FirewallRules: [{F5DBF784-159F-4F4D-8B2E-6FFD3A46B252}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\VcowsPrimeVideo.exe => No File
FirewallRules: [{61F71D58-A0C3-49B8-8A09-09264C7993EB}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\data\bin\native\sheller.exe => No File
FirewallRules: [{4CCEB92C-CD82-43EA-81C8-2C4EBA99FDF0}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\VcowsNetflix.exe => No File
FirewallRules: [{3EA9590F-E33B-4BA2-AB86-97AE48DEDCC7}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\data\bin\native\sheller.exe => No File


EmptyTemp:
Reboot:
End
•Ulozte vytvoreny TXT jako fixlist.txt
•Presunte vytvoreny fixlist vedle FRST

:arrow: Spustte znovu FRST.exe
•Kliknete na Fix
•Probehne oprava a vytvori log Fixlog.txt

:arrow: Restart PC a dejte mi sem fixlog.txt
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Ecinazuz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 355
Registrován: 16 zář 2006 21:47

Re: Prosím o kontrolu logu

#15 Příspěvek od Ecinazuz »

ok

Fix result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by safro (08-10-2025 16:29:16) Run:6
Running from C:\Users\safro\Desktop
Loaded Profiles: safro & WsiAccount & Administrator
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
AppInit_DLLs: C:\PROGRA~1\HP\SURECL~1\servers\BemHook.dll => No File
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {8A59A006-099A-42F4-9040-46AA0067DDCD} - System32\Tasks\HPDataRetriever => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-application-info-collector_ver_4.675.11370\hp-data-retriever.exe (No File)
Task: {DB5845A0-A548-49BB-8035-A6B0CB2330CF} - System32\Tasks\HPSupportTool => C:\ProgramData\HP\Telemetry\collectors\hp-telemetry-iolo-collector_ver_4.675.11370\HPSupportAssistant1.exe (No File)
S3 ax_pvi; \??\C:\Program Files\HP\Sure Click\bin\ax_pvi.sys [X]

AlternateDataStreams: C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe:MBAM.Zone.Identifier [224]
AlternateDataStreams: C:\Users\safro\Downloads\dům 1.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\safro\Downloads\dům 2.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
FirewallRules: [{79588B28-F54B-4D3A-9055-F764571B0DC6}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{A7D7256C-5086-4E3C-AF56-7F861233E55E}] => (Allow) C:\Users\safro\Downloads\4ukey(1).exe => No File
FirewallRules: [{08A5D1E5-CCD3-4250-834E-D820FBD42586}] => (Allow) C:\Program Files (x86)\Vcows\DownLoadProcess.exe => No File
FirewallRules: [{D26A2B5F-F9A3-400A-844E-E60297326AAD}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\AI-Center.exe => No File
FirewallRules: [{5865A713-1826-4322-986B-1BA39D99DF6A}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_FaceBlurDownload\video\face_track\face_track_server.exe => No File
FirewallRules: [{9D3D0A79-1351-4A65-9D78-3ADBA7D551E6}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\AI-Center.exe => No File
FirewallRules: [{70A58689-6C47-4819-ACB6-4C52EDBFE58F}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_SmartCroppingDownload\ZNCJPackage\ZNCJ_Server.exe => No File
FirewallRules: [{F5DBF784-159F-4F4D-8B2E-6FFD3A46B252}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\VcowsPrimeVideo.exe => No File
FirewallRules: [{61F71D58-A0C3-49B8-8A09-09264C7993EB}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_PrimeVideo\data\bin\native\sheller.exe => No File
FirewallRules: [{4CCEB92C-CD82-43EA-81C8-2C4EBA99FDF0}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\VcowsNetflix.exe => No File
FirewallRules: [{3EA9590F-E33B-4BA2-AB86-97AE48DEDCC7}] => (Allow) C:\Users\safro\AppData\Local\HitPaw Software\Vcows\cache\OnlineLocal\HP_NetFilxDownload\data\bin\native\sheller.exe => No File


EmptyTemp:
Reboot:
End

*****************

Processes closed successfully.
Restore point was successfully created.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"C:\PROGRA~1\HP\SURECL~1\servers\BemHook.dll" => Value data removed successfully

"C:\WINDOWS\system32\GroupPolicy\Machine" Folder move:

C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully

"C:\WINDOWS\system32\GroupPolicy\User" Folder move:

C:\WINDOWS\system32\GroupPolicy\User => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A59A006-099A-42F4-9040-46AA0067DDCD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A59A006-099A-42F4-9040-46AA0067DDCD}" => removed successfully
C:\WINDOWS\System32\Tasks\HPDataRetriever => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPDataRetriever" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB5845A0-A548-49BB-8035-A6B0CB2330CF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB5845A0-A548-49BB-8035-A6B0CB2330CF}" => removed successfully
C:\WINDOWS\System32\Tasks\HPSupportTool => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPSupportTool" => removed successfully
HKLM\System\CurrentControlSet\Services\ax_pvi => removed successfully
ax_pvi => service removed successfully
C:\Users\safro\Downloads\CCleanerBundle-639-Setup.exe => ":MBAM.Zone.Identifier" ADS removed successfully
C:\Users\safro\Downloads\dům 1.jpeg => ":3or4kl4x13tuuug3Byamue2s4b" ADS could not remove.
C:\Users\safro\Downloads\dům 2.jpeg => ":3or4kl4x13tuuug3Byamue2s4b" ADS could not remove.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{79588B28-F54B-4D3A-9055-F764571B0DC6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A7D7256C-5086-4E3C-AF56-7F861233E55E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{08A5D1E5-CCD3-4250-834E-D820FBD42586}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D26A2B5F-F9A3-400A-844E-E60297326AAD}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5865A713-1826-4322-986B-1BA39D99DF6A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9D3D0A79-1351-4A65-9D78-3ADBA7D551E6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{70A58689-6C47-4819-ACB6-4C52EDBFE58F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F5DBF784-159F-4F4D-8B2E-6FFD3A46B252}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{61F71D58-A0C3-49B8-8A09-09264C7993EB}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4CCEB92C-CD82-43EA-81C8-2C4EBA99FDF0}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3EA9590F-E33B-4BA2-AB86-97AE48DEDCC7}" => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 44761753 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 14379402 B
Edge => 0 B
Chrome => 348160 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 12 B
systemprofile32 => 12 B
LocalService => 64819 B
NetworkService => 64819 B
safro => 306860976 B
WsiAccount => 346601897 B
Administrator => 439068066 B

RecycleBin => 0 B
EmptyTemp: => 1.1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 16:38:04 ====
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)

Zamčeno