Stránka 1 z 1

Mohu poprosit prosím o preventivku :)

Napsal: 18 pro 2025 19:50
od Blazacz
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2025
Ran by marti (administrator) on MARTIN (ASRock Z790 Steel Legend WiFi) (19-12-2025 17:09:06)
Running from C:\Users\marti\OneDrive\Plocha\Nová složka\FRST64.exe
Loaded Profiles: marti
Platform: Microsoft Windows 11 Pro Version 25H2 26200.7462 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(A-Volute SAS -> A-Volute) C:\Users\marti\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe
(C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\ATuning.exe ->) (ASROCK INC. -> ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\AsrSvc.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(drivers\RivetNetworks\Killer\KAPSService.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\System32\drivers\RivetNetworks\Killer\KAPS.exe
(drivers\RivetNetworks\Killer\KNDBWMService.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\System32\drivers\RivetNetworks\Killer\KNDBWM.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <13>
(explorer.exe ->) (Navigraph Kommanditbolag -> Navigraph) C:\Program Files\Navigraph\Simlink\NavigraphSimlink.exe
(explorer.exe ->) (Navigraph Kommanditbolag -> Navigraph) C:\Users\marti\AppData\Local\Programs\navigraph-hub\Navigraph Hub.exe <4>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\143.0.3650.96\Installer\setup.exe <2>
(services.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Guillemot Corporation S.A. -> Guillemot Corporation) C:\Program Files (x86)\Thrustmaster\TARGET\TmService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\drivers\RivetNetworks\Killer\KillerAnalyticsService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\drivers\RivetNetworks\Killer\KillerNetworkService.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\System32\drivers\RivetNetworks\Killer\KAPSService.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\System32\drivers\RivetNetworks\Killer\KNDBWMService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Thrustmaster®) C:\Program Files\Thrustmaster\TM Flight Series\drivers\amd64\tmHInstall.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_6d8eaa80a18aada4\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_09eece2033f5a691\RtkAudUService64.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2512.1001.34.0_x64__8wekyb3d8bbwe\XboxPcTray.exe
(svchost.exe ->) (ASROCK INC. -> ) C:\Program Files (x86)\ASRock Utility\APP Shop\AsrAPPShop.exe
(svchost.exe ->) (ASROCK INC. -> ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\ATuning.exe
(svchost.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicSvc64.exe
(svchost.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\SysWOW64\NahimicSvc32.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2512.1001.34.0_x64__8wekyb3d8bbwe\XboxPcApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2512.1001.34.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.195.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\marti\AppData\Local\Microsoft\OneDrive\25.222.1112.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\marti\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <5>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.7295_none_a53f7c7777395343\TiWorker.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_09eece2033f5a691\RtkAudUService64.exe [1862040 2024-08-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [SimAppPro] => C:\Program Files (x86)\SimAppPro\SimAppPro.exe [90632704 2025-12-08] (WINWING) [File not signed]
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\Run: [MicrosoftEdgeAutoLaunch_4A886EB596DDE810C696BFE47BAAC943] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4228688 2025-12-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4700824 2025-11-22] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\Run: [Navigraph Hub] => C:\Users\marti\AppData\Local\Programs\navigraph-hub\Navigraph Hub.exe [176372304 2025-11-21] (Navigraph Kommanditbolag -> Navigraph)
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\Run: [Navigraph Simlink] => C:\Program Files\Navigraph\Simlink\NavigraphSimlink.exe [1795296 2025-10-14] (Navigraph Kommanditbolag -> Navigraph)
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\Run: [Teams] => C:\Users\marti\AppData\Local\Microsoft\WindowsApps\MSTeams_8wekyb3d8bbwe\ms-teams.exe [0 0] () [symlink -> ]
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\Run: [ASRock A-Tuning] => [X]
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\Run: [SimAppPro] => [X]
HKLM\...\Print\Monitors\HP D811 Status Monitor: C:\WINDOWS\system32\hpinkstsD811LM.dll [393352 2017-04-05] (Hewlett Packard -> HP Inc.)
Startup: C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SimAppPro – zástupce.lnk [2025-12-15]
ShortcutTarget: SimAppPro – zástupce.lnk -> C:\Program Files (x86)\SimAppPro\SimAppPro.exe (WINWING) [File not signed]

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {B8351AAD-57EF-4666-B274-61A6249DD9C3} - System32\Tasks\AsrAPPShop => C:\Program Files (x86)\ASRock Utility\APP Shop\AsrAPPShop.exe [6745544 2024-07-30] (ASROCK INC. -> )
Task: {CD51D756-82B6-4843-BA46-F5D8E432D272} - System32\Tasks\ATuning => C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\ATuning.exe [10455016 2024-08-09] (ASROCK INC. -> ASRock Incorporation)
Task: {F9D9D5C0-0A24-4BD2-A573-85783BAEA290} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-3429602048-725292175-2964145443-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4856440 2025-12-08] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9C7D1EFF-7C88-491E-81D2-893FA86C2A6A} - System32\Tasks\Microsoft\Windows\Setup\PITRTask => {093cb270-c282-4c22-b2ea-7d2bf1c30bbf} C:\WINDOWS\system32\oobe\PITRTask.dll [118784 2025-12-06] (Microsoft Windows -> Microsoft Corporation)
Task: {0F7625E6-5091-477B-8B40-19DB20E8A6A0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {74B343F4-9459-45CA-B46A-CF49CA7A8B43} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4BE743E0-CC77-4731-A06F-D1064C7F70D5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C46B263B-FBAF-4639-A590-4DB4BA933F4E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A42A3B05-10CA-4C11-9D90-FD2D8FADBE87} - System32\Tasks\NahimicTask32 => C:\Windows\System32\..\SysWOW64\NahimicSvc32.exe [1117352 0] (A-Volute SAS -> Nahimic)
Task: {4A04C468-F8E5-495D-BFC2-858AD3CD8E68} - System32\Tasks\NahimicTask64 => C:\Windows\System32\.\NahimicSvc64.exe [1437352 0] (A-Volute SAS -> Nahimic)
Task: {DD4F62AF-8FD2-4F39-B06B-91EC190533B3} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3429602048-725292175-2964145443-1001 => C:\Users\marti\AppData\Local\Microsoft\OneDrive\25.222.1112.0002\OneDriveLauncher.exe [745832 2025-12-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {F0842294-F19F-497A-9280-A761D4E9BA73} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-3429602048-725292175-2964145443-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4856440 2025-12-08] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {548D64EC-E6B7-4D8F-8CBB-07BC5428289B} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3429602048-725292175-2964145443-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4856440 2025-12-08] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {FE823439-432A-4271-B560-1B66A8A7BA6F} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6274680 2025-12-08] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {0CAE8208-3F60-4922-886F-5F8CEFC5CB63} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9239776 2025-11-25] (Gen Digital Inc. -> Gen Digital Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b8d9ed00-1987-41df-9510-461c6ad73bdb}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{ee1a321e-2873-4950-8725-cc3e6a03f061}: [DhcpNameServer] 192.168.1.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default [2025-12-19]
Edge Notifications: Default -> hxxps://www.facebook.com
Edge HomePage: Default -> hxxp://www.google.com/
Edge Extension: (Dokumenty Google offline) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-18]
Edge Extension: (Adblock Plus - free ad blocker) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2025-12-17]
Edge Extension: (Edge relevant text changes) - C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-31]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [28341880 2025-12-08] (Gen Digital Inc. -> Gen Digital Inc.)
R3 GameInputRedistService; C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe [141680 2025-10-20] (Microsoft Corporation -> Microsoft Corporation)
S2 Intel(R) Platform License Manager Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\PlatformLicenseManagerService.exe [741488 2023-12-14] (Intel Corporation -> Intel(R) Corporation)
R3 KAPSService; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KAPSService.exe [76576 2022-07-27] (Intel Corporation -> Intel® Corporation)
R2 Killer Analytics Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerAnalyticsService.exe [2454304 2022-07-27] (Intel Corporation -> Intel)
R2 Killer Network Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerNetworkService.exe [2898744 2022-07-27] (Intel Corporation -> Intel)
R3 KNDBWM; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KNDBWMService.exe [76600 2022-07-27] (Intel Corporation -> Intel® Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11172008 2025-12-06] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-02-01] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpDefenderCoreService.exe [2063376 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1909528 2023-10-02] (A-Volute SAS -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_6d8eaa80a18aada4\Display.NvContainer\NVDisplay.Container.exe [1275624 2025-12-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803088 2025-10-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 tmHInstall; C:\Program Files\Thrustmaster\TM Flight Series\drivers\amd64\tmHInstall.exe [139456 2025-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Thrustmaster®)
R2 TmWinService; C:\Program Files (x86)\Thrustmaster\TARGET\TmService.exe [320536 2024-11-30] (Guillemot Corporation S.A. -> Guillemot Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\NisSrv.exe [4426832 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe [290704 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AppShopDrv103; C:\WINDOWS\SysWOW64\Drivers\AppShopDrv103.sys [34568 2025-02-01] (ASROCK Incorporation -> ASRock Incorporation) [File not signed]
R3 AsrDrv202; C:\WINDOWS\SysWOW64\Drivers\AsrDrv202.sys [68208 2025-03-02] (ASROCK INC. -> ASRock Incorporation)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [602112 2025-08-16] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2025-08-16] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2025-08-16] (Microsoft Corporation) [File not signed]
R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [34920 2025-10-04] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
S3 GuiHidUsbDevLowerTFH; C:\WINDOWS\System32\drivers\GuiHidUsbDevLowerTFH.sys [256704 2025-06-02] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2020. All rights reserved.)
R3 KfeCoSvc; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KfeCo11X64.sys [188072 2022-07-27] (Intel Corporation -> Rivet Networks, LLC.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333192 2025-11-18] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234088 2025-12-17] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [245336 2025-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MSIO; C:\Program Files (x86)\ASRock Utility\ASRRGBLED\Bin\msio64.sys [19672 2023-12-10] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 TmBusEn; C:\WINDOWS\System32\drivers\TmBusEn.sys [43088 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
R3 TmBusEn; C:\Windows\SysWOW64\drivers\TmBusEn.sys [43088 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmFilter; C:\WINDOWS\System32\drivers\TmFilter.sys [70736 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmFilter; C:\Windows\SysWOW64\drivers\TmFilter.sys [70736 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmHid; C:\WINDOWS\system32\DRIVERS\TmHid.sys [49040 2023-12-14] (WDKTestCert plukidis,131540205154897060 -> Guillemot Corporation)
S3 TmHid; C:\Windows\SysWOW64\DRIVERS\TmHid.sys [49040 2023-12-14] (WDKTestCert plukidis,131540205154897060 -> Guillemot Corporation)
S3 TmHidFsimBus; C:\WINDOWS\System32\drivers\tmHidFsimBus.sys [202440 2025-06-02] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2021. All rights reserved.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2025-12-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [635272 2025-12-18] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102792 2025-12-18] (Microsoft Windows -> Microsoft Corporation)
S3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-08-16] (Microsoft Windows -> Microsoft Corporation)
S3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys [61440 2025-09-01] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-12-19 17:06 - 2025-12-19 17:09 - 000000000 ___RD C:\Users\marti\OneDrive\Plocha\Nová složka
2025-12-18 19:48 - 2025-12-18 19:48 - 000047540 _____ C:\Users\marti\Downloads\Addition.txt
2025-12-18 19:46 - 2025-12-18 19:48 - 000039553 _____ C:\Users\marti\Downloads\FRST.txt
2025-12-18 18:54 - 2025-12-18 19:30 - 000000000 ____D C:\Users\marti\AppData\Roaming\pmdg-oc3
2025-12-18 18:54 - 2025-12-18 18:54 - 000002291 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PMDG OC3.lnk
2025-12-18 18:54 - 2025-12-18 18:54 - 000002289 _____ C:\Users\marti\OneDrive\Plocha\PMDG OC3.lnk
2025-12-18 18:54 - 2025-12-18 18:54 - 000000000 ____D C:\Users\marti\AppData\Local\pmdg-oc3-updater
2025-12-18 18:53 - 2025-12-18 18:54 - 201613656 _____ (PMDG Simulations, LLC.) C:\Users\marti\Downloads\oc3_setup_3.0.259.exe
2025-12-18 17:52 - 2025-12-18 17:52 - 000677108 _____ C:\WINDOWS\system32\perfh005.dat
2025-12-18 17:52 - 2025-12-18 17:52 - 000144960 _____ C:\WINDOWS\system32\perfc005.dat
2025-12-17 19:02 - 2025-12-17 19:02 - 000000223 _____ C:\Users\marti\OneDrive\Plocha\Microsoft Flight Simulator 2024.url
2025-12-15 21:14 - 2025-12-15 21:14 - 000000000 ____D C:\MSFS 2024 SDK
2025-12-15 18:25 - 2025-12-15 18:25 - 000002055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimAppPro.lnk
2025-12-15 18:21 - 2025-12-15 18:21 - 000000000 ____D C:\Program Files\FenixSim A320
2025-12-15 18:20 - 2025-12-15 18:20 - 000002250 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fenix Installer.lnk
2025-12-15 18:20 - 2025-12-15 18:20 - 000002248 _____ C:\Users\marti\OneDrive\Plocha\Fenix Installer.lnk
2025-12-15 18:20 - 2025-12-15 18:20 - 000000000 ____D C:\Users\marti\AppData\Local\FenixApp
2025-12-14 13:06 - 2025-12-18 19:46 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-12-14 11:31 - 2025-12-14 11:35 - 2402943259 _____ C:\Users\marti\OneDrive\Plocha\inibuilds-airport-egcc-manchester-v1-0-2-msfs-2024.rar
2025-12-08 19:57 - 2025-12-08 19:57 - 000000437 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2025-12-08 19:36 - 2025-12-08 19:36 - 000000000 ____D C:\WINDOWS\ASRock
2025-12-07 10:03 - 2025-12-07 10:03 - 000000000 ____D C:\Users\marti\AppData\Roaming\NVIDIA
2025-12-06 19:06 - 2025-12-06 19:06 - 000000000 ____D C:\WINDOWS\system32\NarratorMCAT
2025-12-06 18:59 - 2025-12-06 18:59 - 000035602 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-12-06 18:59 - 2025-12-06 18:59 - 000035602 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-12-06 18:40 - 2025-12-18 20:43 - 000000000 ____D C:\ProgramData\NVIDIA
2025-12-06 18:40 - 2025-12-18 19:01 - 000000000 ____D C:\Users\marti\AppData\Local\D3DSCache
2025-12-06 18:40 - 2025-12-07 11:56 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-12-06 18:40 - 2025-12-06 18:43 - 000000000 ____D C:\Users\marti\AppData\Local\NVIDIA
2025-12-06 18:40 - 2025-12-06 18:40 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-12-06 18:40 - 2025-12-06 18:40 - 000000000 ____D C:\Users\marti\AppData\LocalLow\NVIDIA
2025-12-06 18:38 - 2025-12-03 09:51 - 002421296 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-12-06 18:38 - 2025-12-03 09:51 - 002421296 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-12-06 18:38 - 2025-12-03 09:51 - 001923120 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-12-06 18:38 - 2025-12-03 09:51 - 001923120 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-12-06 18:38 - 2025-12-03 09:51 - 001625648 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-12-06 18:38 - 2025-12-03 09:51 - 001625648 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-12-06 18:38 - 2025-12-03 09:51 - 001434672 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-12-06 18:38 - 2025-12-03 09:51 - 001434672 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-12-06 18:38 - 2025-12-03 09:51 - 000478952 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-12-06 18:38 - 2025-12-03 09:51 - 000375016 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-12-06 18:38 - 2025-12-03 09:47 - 001344744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-12-06 18:38 - 2025-12-03 09:47 - 000675048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-12-06 18:38 - 2025-12-03 09:47 - 000509160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-12-06 18:38 - 2025-12-03 09:46 - 027559144 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-12-06 18:38 - 2025-12-03 09:46 - 002319080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-12-06 18:38 - 2025-12-03 09:46 - 001716968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-12-06 18:38 - 2025-12-03 09:46 - 001616104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-12-06 18:38 - 2025-12-03 09:46 - 001574632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-12-06 18:38 - 2025-12-03 09:46 - 001224936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-12-06 18:38 - 2025-12-03 09:46 - 001055976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-12-06 18:38 - 2025-12-03 09:46 - 000812264 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-12-06 18:38 - 2025-12-03 09:45 - 022613224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-12-06 18:38 - 2025-12-03 09:45 - 018277608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-12-06 18:38 - 2025-12-03 09:45 - 007908072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-12-06 18:38 - 2025-12-03 09:45 - 005586664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-12-06 18:38 - 2025-12-03 09:45 - 004288232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-12-06 18:38 - 2025-12-03 09:45 - 000469224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-12-06 18:38 - 2025-12-03 09:44 - 005923048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-12-06 18:38 - 2025-12-03 09:44 - 000853736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-12-06 18:38 - 2025-12-03 09:43 - 005692632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-12-06 18:38 - 2025-12-03 09:43 - 004979216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-12-06 18:38 - 2025-12-02 16:55 - 000153488 _____ C:\WINDOWS\system32\nvinfo.pb
2025-12-06 18:38 - 2025-12-02 16:55 - 000126696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2025-11-30 02:27 - 2025-11-30 02:27 - 000000000 ____D C:\WINDOWS\Panther
2025-11-21 21:31 - 2025-11-21 21:31 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigraph Hub
2025-11-20 19:05 - 2025-11-28 20:16 - 000001466 _____ C:\Users\marti\OneDrive\Plocha\MSFS24.lnk
2025-11-20 16:56 - 2025-11-20 16:56 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS-ATC-Chatter
2025-11-20 16:53 - 2025-11-20 16:55 - 000000000 ____D C:\FS-ATC-Chatter

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-12-19 17:09 - 2025-10-23 18:37 - 000000000 ____D C:\FRST
2025-12-19 17:05 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-12-19 17:04 - 2025-02-01 13:16 - 000000000 ____D C:\Users\marti\AppData\Roaming\navigraph-hub
2025-12-19 17:04 - 2025-02-01 00:49 - 000000000 ____D C:\Program Files (x86)\Steam
2025-12-19 17:03 - 2025-02-01 00:00 - 000000000 ___RD C:\Users\marti\OneDrive
2025-12-19 17:03 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-12-19 17:02 - 2025-08-16 23:25 - 000003020 _____ C:\WINDOWS\system32\Tasks\AsrAPPShop
2025-12-18 20:43 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-12-18 20:36 - 2025-02-01 14:14 - 000000000 ____D C:\Users\marti\AppData\Local\Malwarebytes
2025-12-18 19:48 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF
2025-12-18 18:44 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-12-18 18:21 - 2025-02-01 13:11 - 000000000 ____D C:\Users\marti\AppData\Roaming\FlyByWire Installer
2025-12-18 18:14 - 2025-02-01 12:56 - 000001281 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\PMDG Operations Center v2.lnk
2025-12-18 18:02 - 2025-01-31 23:47 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-12-18 17:55 - 2025-02-01 13:25 - 000000000 ____D C:\Users\marti\AppData\Roaming\Aerosoft One
2025-12-18 17:52 - 2025-08-16 23:28 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-12-17 21:14 - 2025-05-20 19:39 - 000000000 ____D C:\Users\marti\AppData\Roaming\SimAppPro
2025-12-17 21:08 - 2025-08-16 23:25 - 000003016 _____ C:\WINDOWS\system32\Tasks\ATuning
2025-12-17 21:06 - 2025-02-01 13:19 - 000000000 ____D C:\Users\marti\AppData\Roaming\iniManager
2025-12-17 21:06 - 2025-02-01 13:11 - 000000000 ____D C:\Users\marti\AppData\Roaming\Virtuali
2025-12-17 21:06 - 2025-02-01 13:11 - 000000000 ____D C:\ProgramData\Virtuali
2025-12-17 21:05 - 2025-08-07 16:22 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft Flight Simulator 2024
2025-12-17 19:38 - 2025-02-01 13:28 - 000000000 ____D C:\FSUIPC7
2025-12-17 19:02 - 2025-02-03 19:03 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-12-17 19:01 - 2025-08-16 23:25 - 000011096 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-12-17 19:01 - 2025-08-16 23:25 - 000003108 _____ C:\WINDOWS\system32\Tasks\NahimicTask32
2025-12-17 19:01 - 2025-08-16 23:25 - 000003088 _____ C:\WINDOWS\system32\Tasks\NahimicTask64
2025-12-17 19:01 - 2025-08-16 23:25 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-12-17 19:01 - 2025-01-31 23:47 - 000012288 ___SH C:\DumpStack.log.tmp
2025-12-17 19:01 - 2024-04-01 08:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-12-16 18:50 - 2025-02-01 04:34 - 000000000 ____D C:\Users\marti\AppData\Local\CrashDumps
2025-12-16 15:48 - 2025-08-16 23:25 - 000003714 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{67CC9047-C3AD-4539-B2A6-99C3DD181152}
2025-12-16 15:48 - 2025-08-16 23:25 - 000003588 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{99CA179B-4625-40F9-81A8-B9FBE1F9501A}
2025-12-15 19:54 - 2025-08-16 23:25 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3429602048-725292175-2964145443-1001
2025-12-15 19:54 - 2025-08-16 23:25 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3429602048-725292175-2964145443-1001
2025-12-15 19:54 - 2025-08-16 23:25 - 000003360 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3429602048-725292175-2964145443-1001
2025-12-15 19:54 - 2025-02-01 00:00 - 000002379 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-12-15 18:27 - 2025-10-14 12:59 - 000000000 ____D C:\ProgramData\Fenix
2025-12-15 18:27 - 2025-02-01 13:30 - 000000000 ____D C:\Users\marti\OneDrive\Plocha\FS2024
2025-12-15 18:25 - 2025-08-20 15:27 - 000000000 ____D C:\Program Files (x86)\SimAppPro
2025-12-15 18:24 - 2025-02-01 14:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FenixSim A320
2025-12-14 11:30 - 2025-01-31 23:47 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-12-11 18:48 - 2025-08-16 23:23 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2025-12-11 18:47 - 2024-04-01 17:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-12-11 18:47 - 2024-04-01 08:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-12-11 18:47 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-12-11 18:47 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-12-11 18:47 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-12-11 18:47 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2025-12-11 18:47 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-12-11 18:33 - 2025-02-01 00:11 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-12-11 18:32 - 2025-02-01 00:11 - 218369424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-12-10 18:07 - 2025-08-16 23:26 - 003276800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-12-09 17:32 - 2025-01-31 23:57 - 000000000 ____D C:\Users\marti\AppData\Local\Nahimic
2025-12-08 19:39 - 2025-02-02 00:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
2025-12-08 19:39 - 2025-02-02 00:38 - 000000000 ____D C:\Program Files (x86)\ASRock Utility
2025-12-08 18:58 - 2025-10-10 14:43 - 000000000 ____D C:\WINDOWS\system32\Tasks\Piriform
2025-12-08 17:57 - 2025-01-31 23:49 - 000000000 ____D C:\ProgramData\Nahimic
2025-12-08 17:41 - 2025-02-01 13:26 - 000000000 ____D C:\Users\marti\Aerosoft One Library
2025-12-06 19:07 - 2025-08-16 23:23 - 000297264 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-12-06 19:06 - 2025-08-16 23:10 - 000000000 ____D C:\WINDOWS\system32\ruxim
2025-12-06 19:06 - 2024-04-01 17:31 - 000000000 ____D C:\WINDOWS\InboxApps
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ___RD C:\Program Files (x86)\Windows Defender
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\WUModels
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\UUS
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\DDFs
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\DiagTrack
2025-12-06 19:06 - 2024-04-01 08:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-12-06 19:06 - 2024-04-01 08:21 - 000000000 ____D C:\WINDOWS\servicing
2025-12-06 18:40 - 2025-01-31 23:57 - 000000000 ____D C:\Users\marti\AppData\Local\Packages
2025-12-06 18:40 - 2025-01-31 23:49 - 000000000 ____D C:\ProgramData\Packages
2025-12-06 18:36 - 2025-07-28 18:06 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-11-25 15:35 - 2025-11-01 21:53 - 000000000 ____D C:\ProgramData\Whesvc
2025-11-24 18:57 - 2025-05-11 18:29 - 000000000 ____D C:\Users\marti\AppData\Roaming\pesim-central-v2-client
2025-11-24 18:57 - 2025-05-11 18:29 - 000000000 ____D C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc
2025-11-20 18:55 - 2025-09-23 17:54 - 000436592 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_b.dll
2025-11-20 18:55 - 2025-02-01 00:22 - 004581752 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2025-11-20 18:55 - 2025-02-01 00:22 - 000878968 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2025-11-20 18:55 - 2025-02-01 00:22 - 000285040 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2025-11-20 18:55 - 2025-02-01 00:22 - 000244088 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2025-11-20 18:55 - 2025-02-01 00:22 - 000166264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2025-11-20 18:55 - 2025-02-01 00:22 - 000153976 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2025-11-20 18:55 - 2025-02-01 00:22 - 000076152 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2025-11-20 16:48 - 2025-08-29 15:53 - 000000000 ____D C:\REX Atmos Core

==================== Files in the root of some directories ========

2025-02-09 16:36 - 2025-02-09 16:40 - 000024576 _____ () C:\Users\marti\AppData\Roaming\EFB.db
2025-11-03 19:27 - 2025-11-03 19:27 - 000007603 _____ () C:\Users\marti\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-11-2025
Ran by marti (19-12-2025 17:10:03)
Running from C:\Users\marti\OneDrive\Plocha\Nová složka
Microsoft Windows 11 Pro Version 25H2 26200.7462 (X64) (2025-08-16 22:26:01)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3429602048-725292175-2964145443-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3429602048-725292175-2964145443-503 - Limited - Disabled)
Guest (S-1-5-21-3429602048-725292175-2964145443-501 - Limited - Disabled)
marti (S-1-5-21-3429602048-725292175-2964145443-1001 - Administrator - Enabled) => C:\Users\marti
WDAGUtilityAccount (S-1-5-21-3429602048-725292175-2964145443-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Aerosoft One 0.16.12 (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\6cfbc6f2-d82c-56dd-8cbb-177a5d4b5b90) (Version: 0.16.12 - Aerosoft GmbH)
APP Shop v2.0.0.6 (HKLM-x32\...\{3B9B2DDC-07B8-4F28-82D9-4092C4LE5B67}_is1) (Version: 2.0.0.6 - ASRock Inc.)
ASRock Restart to UEFI v1.0.15 (HKLM-x32\...\ASRock Restart to UEFI_is1) (Version: 1.0.15 - ASRock Inc.)
ASRRGBLED v2.0.190 (HKLM-x32\...\ASRock RGB LED_is1) (Version: 2.0.190 - ASRock Inc.)
A-Tuning v4.1.11 (HKLM-x32\...\A-Tuning_is1) (Version: 4.1.11 - ASRock Inc.)
BleachBit (HKLM-x32\...\BleachBit) (Version: 5.0.2.3065 - BleachBit)
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.2.1080.1295 - Piriform)
CPUID HWMonitor 1.60 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.60 - CPUID, Inc.)
Display Driver Uninstaller (HKLM-x32\...\Display Driver Uninstaller) (Version: 18.1.3.8 - Wagnardsoft)
Dynamic Application Loader Host Interface Service (HKLM\...\{12EF5653-F4C0-4B29-A4EE-E2C7A527E668}) (Version: 1.0.0.0 - Intel Corporation) Hidden
ENE Video Capture Box HAL (HKLM\...\{A096611D-BA11-4A1A-8D09-0A0462D7C8F2}) (Version: 1.0.5.15 - Ene Tech.) Hidden
ENE Video Capture Box HAL (HKLM-x32\...\{974259bf-3ed1-4cd6-9ed1-40c7f601a786}) (Version: 1.0.5.15 - Ene Tech.) Hidden
ENE_DRAM_RGB_AIO (HKLM\...\{93C7E355-7193-4F5F-938B-C519251D472B}) (Version: 1.0.13.0 - Ene Tech.) Hidden
ENE_DRAM_RGB_AIO (HKLM-x32\...\{b3481593-508d-41a9-b09f-4b10414b371d}) (Version: 1.0.13.0 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{c1d017c2-8846-4000-9254-5689eccd462e}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
ENE_External_Device_HAL (HKLM\...\{2B8E611F-0B51-4FAC-87BB-AF50D82E7DDA}) (Version: 1.0.12.7 - ENE Tech) Hidden
ENE_External_Device_HAL (HKLM-x32\...\{a7b1cf47-d8f0-423d-9494-568195f1c864}) (Version: 1.0.12.7 - ENE Tech) Hidden
ENE_MousePad_HAL (HKLM\...\{9E97178A-ADB8-4778-BE60-7E28E2A72721}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden
ENE_MousePad_HAL (HKLM-x32\...\{c2c794a4-7986-4c45-884d-d4ca43b88df9}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden
ENE_QSI_Loki_HAL (HKLM\...\{BDE43F26-5917-44F8-B86A-F1D9A6B80B32}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
ENE_QSI_Loki_HAL (HKLM-x32\...\{205ef3a8-937b-43cb-90fc-2f58f71408d8}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
ENE_X_AIC_HAL (HKLM\...\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.6.3 - ENE TECHNOLOGY INC.) Hidden
ENE_X_AIC_HAL (HKLM-x32\...\{c662a481-d76a-4188-95d2-6eb4ffd55542}) (Version: 1.0.6.3 - ENE TECHNOLOGY INC.) Hidden
Fenix Installer (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\FenixApp) (Version: 1.0.243 - FenixSim Ltd.)
FenixSim A320 (HKLM\...\{49120c8f-c92c-47c4-ba07-e99057c45d3d}) (Version: 2.4.0.2913 - FenixSim Ltd.)
FlyByWire Installer 3.5.0 (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\80b9efbf-2017-5d38-8868-3afd67a5a47d) (Version: 3.5.0 - FlyByWire Simulations)
FS-ATC-Chatter (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\FS-ATC-Chatter) (Version: 1.2.4 - Stick And Rudder Studios)
FSDreamTeam Universal Installer version 1.2.0 (HKLM-x32\...\FSDreamTeam Universal Installer_is1) (Version: 1.2.0 - VIRTUALI Sagl)
FSHud - Air Traffic Control (HKLM\...\{C119E5B9-BE5E-4785-A257-519F816FD88F}) (Version: 2.0.323.0 - FSHud)
FSUIPC7 v7.5.5 (HKLM-x32\...\FSUIPC72024) (Version: v7.5.5 - John L. Dowson)
iFly Manager (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\iFly Manager) (Version: - )
iniManager (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\iniManager) (Version: 2.4.8 - iniBuilds Ltd.)
Intel(R) Chipset Device Software (HKLM\...\{2B96B7E3-FA08-4749-9D23-CDC64F1B835B}) (Version: 10.1.19600.8418 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{404581d0-19c1-47ba-bcd3-10178793c239}) (Version: 10.1.19600.8418 - Intel(R) Corporation)
Intel(R) Icls (HKLM\...\{39C50D87-BFD1-43DD-8A18-676086E328C9}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2340.5.36.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{BA97A47F-9B59-4B07-BC82-FF3F6CE6E597}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Driver (HKLM\...\{C8EEBC98-5759-4B1D-9834-E5F897161475}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) ME WMI Provider (HKLM\...\{8105FECC-2670-4EA1-A98B-FA803A30AEEB}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Killer Performance Driver Suite UWD (HKLM\...\{FFC31014-7FD6-4720-8C5D-7B16E9E6F73E}) (Version: 3.1222.750 - Rivet Networks)
Malwarebytes version 5.4.4.225 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.4.4.225 - Malwarebytes)
Microsoft .NET Host - 6.0.36 (x64) (HKLM\...\{D6932D97-36F1-40B8-9CDC-CA8365B21000}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host - 7.0.17 (x64) (HKLM\...\{089B0F2C-87D9-4470-B6E6-154DD6961C56}) (Version: 56.68.10360 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.12 (x64) (HKLM\...\{C4C6E39D-48AE-426C-960C-46ED3447DDEB}) (Version: 64.48.26165 - Microsoft Corporation) Hidden
Microsoft .NET Host - 9.0.10 (x64) (HKLM\...\{EB00D346-1FB5-46E0-89C0-93F056F5ACF4}) (Version: 72.40.40927 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.36 (x64) (HKLM\...\{A9E32B25-994B-4856-A12B-0EBED3050410}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.17 (x64) (HKLM\...\{6B4D3428-4800-446B-971F-62A7377F06F6}) (Version: 56.68.10360 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.12 (x64) (HKLM\...\{C9C872D5-3CA9-4E0E-AF90-1B85325F9243}) (Version: 64.48.26165 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 9.0.10 (x64) (HKLM\...\{FDC862D8-5CDD-4FC6-8E9A-873A689600BC}) (Version: 72.40.40927 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.36 (x64) (HKLM\...\{C912E33F-956A-4921-9F55-CC11AE8F09AF}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.36 (x64) (HKLM-x32\...\{9d3fc73f-1cf4-412c-a1c9-d2ad28ccbd62}) (Version: 6.0.36.34214 - Microsoft Corporation)
Microsoft .NET Runtime - 7.0.17 (x64) (HKLM\...\{A638EFAE-5229-46A8-9A18-D0FF9D9827D2}) (Version: 56.68.10360 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.12 (x64) (HKLM\...\{1E606649-7E56-452F-8AC4-495C70D1E341}) (Version: 64.48.26165 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 9.0.10 (x64) (HKLM\...\{05987870-6EDD-4352-ADEA-4A8694040F3E}) (Version: 72.40.40927 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 143.0.3650.80 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 143.0.3650.96 - Microsoft Corporation) Hidden
Microsoft Flight Simulator 2024 SDK 1.5.6 (Core) (HKLM\...\{253EA388-D7C3-455F-9B65-56F733A3AA4B}) (Version: 1.5.6 - Microsoft)
Microsoft Flight Simulator SDK 0.24.4 (Core) (HKLM\...\{3D42EBFC-1EBC-4468-9B77-388C2A3290FE}) (Version: 0.24.4 - Microsoft)
Microsoft GameInput (HKLM\...\{ECB4BDD1-984C-9F25-299C-A9EF75C14197}) (Version: 10.1.26100.6879 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\OneDriveSetup.exe) (Version: 25.222.1112.0002 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.25.18302 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM\...\{61D4736B-3325-4D4A-BD41-8BD206C6A86E}) (Version: 48.144.23186 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM-x32\...\{0532b8f2-12d7-43de-95fc-7b87006758a8}) (Version: 6.0.36.34217 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 7.0.17 (x64) (HKLM\...\{93812F65-BAA9-42E0-AF19-F15F39A92E3C}) (Version: 56.68.10379 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.17 (x64) (HKLM-x32\...\{24a68a65-6ac6-4276-9d7d-2c3939d8474e}) (Version: 7.0.17.33416 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.12 (x64) (HKLM\...\{71CD19D6-C448-4B5D-9A38-018741753290}) (Version: 64.48.26178 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.12 (x64) (HKLM-x32\...\{aafaa0cc-b975-4ffa-ba33-8690e64683c4}) (Version: 8.0.12.34404 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 9.0.10 (x64) (HKLM\...\{8466C2EB-71A6-4529-A615-0E8FE0CCCBED}) (Version: 72.40.40921 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 9.0.10 (x64) (HKLM-x32\...\{877aacfd-984e-464a-ba89-9fc575eb79ed}) (Version: 9.0.10.35325 - Microsoft Corporation)
Navigraph Hub 1.2.24 (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\55f042a9-1285-5a7a-abcd-4e2044c5b51b) (Version: 1.2.24 - Navigraph)
Navigraph Simlink 1.1.40.1707 (HKLM\...\{E5431A0D-8735-4E89-9E41-D820334B2909}}_is1) (Version: 1.1.40.1707 - Navigraph)
NVIDIA Ovladač HD audia 1.4.5.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.6 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 591.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 591.44 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
Orbx Central 4.5.7 (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\7cf15176-b7c3-5704-8319-ddca84b92c9a) (Version: 4.5.7 - Orbx Simulation Systems Pty Ltd)
Pilot Experience Sim Central V2 (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\pesim-central-v2-client) (Version: 2.1.8 - Pilot Experience Sim)
PMDG OC3 3.0.259 (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\e64f4b9a-948d-5251-9b57-0bd6f3fbb888) (Version: 3.0.259 - PMDG Simulations, LLC.)
REX Atmos Core (HKLM\...\{525601AC-690F-4B81-A037-9F46BB5AA798}) (Version: 8.0.2025.0825 - REX Game Studios, LLC.)
SimAppPro 1.16.75 (HKLM-x32\...\2873a9d6-0e65-5078-b232-daee9dce2239) (Version: 1.16.75 - WINWING)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
T.Flight Hotas drivers (HKLM-x32\...\{E08E6F77-E66C-47FC-8565-0AA3389D48C8}) (Version: 4.TFHT.2025 - Thrustmaster)
Thrustmaster TARGET (HKLM-x32\...\{8036A569-CA02-4D33-A7E9-E9BC8A482E91}) (Version: 3.0.25.127 - Thrustmaster)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 159.0.11374 - Ubisoft)
vAMSYS Pegasus (HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\vAMSYS-Pegasus) (Version: 2.0.3 - vAMSYS LTD)
Verbatim_SureFireGaming_Product (HKLM\...\{35CB65C6-A7E3-4EE7-AD40-738D70A72164}) (Version: 1.0.3.11 - Verbatim) Hidden
Verbatim_SureFireGaming_Product (HKLM-x32\...\{d601832a-0d94-46ce-9b19-78e8a5887313}) (Version: 1.0.3.11 - Verbatim) Hidden
WinRAR 7.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 7.01.0 - win.rar GmbH)

Packages:
=========
@{MicrosoftWindows.57242383.Tasbar_1000.26100.7309.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.57242383.Tasbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57242383.Tasbar_cw5n1h2txyewy [2025-12-11] (Microsoft Windows)
@{MicrosoftWindows.58683691.InpApp_1000.26100.6725.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.58683691.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.58683691.InpApp_cw5n1h2txyewy [2025-12-06] ()
@{MicrosoftWindows.58683691.InpApp_1000.26100.6899.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.58683691.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.58683691.InpApp_cw5n1h2txyewy [2025-12-06] ()
@{MicrosoftWindows.58683691.InpApp_1000.26100.6901.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.58683691.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.58683691.InpApp_cw5n1h2txyewy [2025-12-06] ()
@{MicrosoftWindows.58683691.InpApp_1000.26100.7019.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.58683691.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.58683691.InpApp_cw5n1h2txyewy [2025-12-06] ()
@{MicrosoftWindows.59379618.InpApp_1000.26100.7019.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.59379618.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.59379618.InpApp_cw5n1h2txyewy [2025-12-11] (Microsoft Windows)
@{MicrosoftWindows.59379618.InpApp_1000.26100.7171.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.59379618.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.59379618.InpApp_cw5n1h2txyewy [2025-12-11] (Microsoft Windows)
@{MicrosoftWindows.59379618.InpApp_1000.26100.7309.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.59379618.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.59379618.InpApp_cw5n1h2txyewy [2025-12-11] (Microsoft Windows)
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57242383.Tasbar_cw5n1h2txyewy [2025-12-11] (Microsoft Windows)
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.59379618.InpApp_cw5n1h2txyewy [2025-12-11] (Microsoft Windows)
Edit Docx PLUS -> C:\Program Files\WindowsApps\24091FileFormatApps.WordEditorBasic_2.1.12.0_x64__8t2vtv4rwtrk0 [2025-05-18] (File Format Apps)
HyperX NGENUITY -> C:\Program Files\WindowsApps\33C30B79.HyperXNGenuity_5.35.0.0_x64__0a78dr3hq0pvt [2025-11-18] (HP Inc.) [Startup Task]
Killer Intelligence Center -> C:\Program Files\WindowsApps\rivetnetworks.killercontrolcenter_3.1222.726.0_x64__rh07ty8m5nkag [2025-05-18] (Rivet Networks LLC) [Startup Task]
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2025-12-06] ()
Microsoft Jenny (Natural) - English (United States) -> C:\Program Files\WindowsApps\MicrosoftWindows.Voice.en-US.Jenny.1_1.0.8.0_x64__cw5n1h2txyewy [2025-05-18] (Microsoft Windows)
Nahimic -> C:\Program Files\WindowsApps\A-Volute.Nahimic_1.10.7.0_x64__w2gh52qy24etm [2025-08-12] (A-Volute)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-12-06] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.43.296.0_x64__dt26b99r8h8gj [2025-08-09] (Realtek Semiconductor Corp)
Speech Pack - English (United States) -> C:\Program Files\WindowsApps\MicrosoftWindows.Speech.en-US.1_1.0.24.0_x64__cw5n1h2txyewy [2025-08-16] (Microsoft Windows)
WinRAR -> C:\Program Files\WinRAR [2025-03-16] (win.rar GmbH)
XboxInsiderHub -> C:\Program Files\WindowsApps\Microsoft.XboxInsider_1.2508.26001.0_x64__8wekyb3d8bbwe [2025-09-17] (Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3429602048-725292175-2964145443-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\marti\AppData\Local\Microsoft\OneDrive\25.222.1112.0002\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3429602048-725292175-2964145443-1001_Classes\CLSID\{80172dde-4e20-4df0-81a2-0a48553e80bb}\localserver32 -> C:\Users\marti\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe (A-Volute SAS -> A-Volute)
CustomCLSID: HKU\S-1-5-21-3429602048-725292175-2964145443-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\marti\AppData\Local\Microsoft\OneDrive\25.222.1112.0002\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3429602048-725292175-2964145443-1001_Classes\CLSID\{EABAE40C-B27C-455A-B672-F234DD780948}\InprocServer32 -> C:\Users\marti\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.25.18302\x64\Microsoft.Teams.MeetingAddin.DLL (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-12-06] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_6d8eaa80a18aada4\nvshext.dll [2025-12-03] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-12-06] (Malwarebytes Inc -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [MidisrvTransferComplete] => 0

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2025-02-01 13:16 - 2025-11-21 12:31 - 002866176 _____ () [File not signed] C:\Users\marti\AppData\Local\Programs\navigraph-hub\ffmpeg.dll
2025-02-01 13:16 - 2025-11-21 12:31 - 000479232 _____ () [File not signed] C:\Users\marti\AppData\Local\Programs\navigraph-hub\libegl.dll
2025-02-01 13:16 - 2025-11-21 12:31 - 007672320 _____ () [File not signed] C:\Users\marti\AppData\Local\Programs\navigraph-hub\libglesv2.dll
2025-02-01 13:16 - 2025-11-21 12:31 - 005312000 _____ () [File not signed] C:\Users\marti\AppData\Local\Programs\navigraph-hub\vk_swiftshader.dll
2025-05-25 15:55 - 2020-04-01 05:46 - 000037376 _____ (Guillemot Corporation) [File not signed] C:\Program Files (x86)\Thrustmaster\TARGET\cint.dll
2025-05-25 15:55 - 2016-04-14 03:46 - 001036800 _____ (Guillemot Corporation) [File not signed] C:\Program Files (x86)\Thrustmaster\TARGET\TmCommon.dll
2025-05-25 15:55 - 2024-09-09 20:09 - 000192000 _____ (Guillemot Corporation) [File not signed] C:\Program Files (x86)\Thrustmaster\TARGET\TmHidControl.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 002293248 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Navigraph\Simlink\LIBEAY32.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000386560 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Navigraph\Simlink\ssleay32.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000047616 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\bearer\qgenericbearer.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000031744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qgif.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000040960 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qicns.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000032256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qico.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000397312 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qjpeg.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000025600 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qsvg.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000025088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qtga.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000374272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qtiff.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000023552 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qwbmp.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000491520 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\imageformats\qwebp.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 001453568 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\platforms\qwindows.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 006130176 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\Qt5Core.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 006470656 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\Qt5Gui.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 001314816 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\Qt5Network.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000332288 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\Qt5Svg.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 005580800 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\Qt5Widgets.dll
2025-02-01 13:18 - 2024-04-18 13:27 - 000137216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Navigraph\Simlink\styles\qwindowsvistastyle.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2025-01-31 23:42 - 2025-01-31 23:42 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2025-12-08 19:57 - 2025-12-08 19:57 - 000000437 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.1.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek Gaming 2.5GbE Family Controller -> rt640x64.sys
Wi-Fi: Killer(R) Wi-Fi 6E AX1675x 160MHz Wireless Network Adapter (210NGW) -> Netwtw14.sys
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3429602048-725292175-2964145443-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\marti\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\17630007791790648602\134105530360579597.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 5) (TamperProtectionSource: 2)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Program Files (x86)\Addon Manager
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Program Files\FenixSim A320
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|C:\Program Files\FenixSim A320\Fenix.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|C:\Program Files\FenixSim A320\deps\FenixBootstrapper.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|C:\Program Files\FenixSim A320\deps\FenixCDU.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|C:\Program Files\FenixSim A320\deps\FenixDisplay.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|C:\Program Files\FenixSim A320\deps\FenixSystem.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|C:\Program Files\FenixSim A320\deps\GqlGateway\Fenix.GqlGateway.exe


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "SimAppPro"
HKU\S-1-5-21-3429602048-725292175-2964145443-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_4A886EB596DDE810C696BFE47BAAC943"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{4DB20927-AB65-476B-86A9-FAA3185BA230}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stronghold Crusader Definitive Edition\Stronghold Crusader Definitive Edition.exe () [File not signed]
FirewallRules: [{6DEA4A50-4212-4C94-A751-475E55D6B3AF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stronghold Crusader Definitive Edition\Stronghold Crusader Definitive Edition.exe () [File not signed]
FirewallRules: [UDP Query User{85C1CEF4-E338-432C-A2B4-D4EFA3C6D5D4}C:\users\marti\appdata\roaming\microsoft flight simulator 2024\packages\community\fsltl-traffic-injector\fsltl-trafficinjector.exe] => (Allow) C:\users\marti\appdata\roaming\microsoft flight simulator 2024\packages\community\fsltl-traffic-injector\fsltl-trafficinjector.exe (Node.js) [File not signed]
FirewallRules: [TCP Query User{D2C14152-CC5F-41D7-8E71-BF18B4382A16}C:\users\marti\appdata\roaming\microsoft flight simulator 2024\packages\community\fsltl-traffic-injector\fsltl-trafficinjector.exe] => (Allow) C:\users\marti\appdata\roaming\microsoft flight simulator 2024\packages\community\fsltl-traffic-injector\fsltl-trafficinjector.exe (Node.js) [File not signed]
FirewallRules: [UDP Query User{03823B6E-D220-4505-880B-A2A419C55560}C:\program files\fenixsim a320\deps\gqlgateway\fenix.gqlgateway.exe] => (Allow) C:\program files\fenixsim a320\deps\gqlgateway\fenix.gqlgateway.exe (FenixSim Limited -> FenixSim Ltd.)
FirewallRules: [TCP Query User{4A59D9D8-093E-4293-BB1B-2B9AC0DFEA50}C:\program files\fenixsim a320\deps\gqlgateway\fenix.gqlgateway.exe] => (Allow) C:\program files\fenixsim a320\deps\gqlgateway\fenix.gqlgateway.exe (FenixSim Limited -> FenixSim Ltd.)
FirewallRules: [UDP Query User{C627BBA9-8E18-477B-8F94-B33C89EE7DA4}C:\program files\fenixsim a320\deps\fenixsystem.exe] => (Allow) C:\program files\fenixsim a320\deps\fenixsystem.exe (FenixSim Limited -> FenixSim Ltd.)
FirewallRules: [TCP Query User{44FC857C-1A87-4A94-B2D1-B6825823E407}C:\program files\fenixsim a320\deps\fenixsystem.exe] => (Allow) C:\program files\fenixsim a320\deps\fenixsystem.exe (FenixSim Limited -> FenixSim Ltd.)
FirewallRules: [{3DB3E66F-10AF-4AEB-A46F-5EEE913A285C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\KingdomComeDeliverance2\Bin\Win64MasterMasterSteamPGO\KingdomCome.exe (Warhorse Studios sro) [File not signed]
FirewallRules: [{81AF212D-8C22-4885-9625-4F4CF2417AFE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\KingdomComeDeliverance2\Bin\Win64MasterMasterSteamPGO\KingdomCome.exe (Warhorse Studios sro) [File not signed]
FirewallRules: [{4F6E9194-A501-49C4-A3A1-505147589759}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B4FBB25F-296F-4931-B1FC-A33FB3A3FA0A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{FE7793A9-39CF-43E9-888A-A3D0F00B5BFE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{D6C9F1FF-425A-44A9-8C31-9B6D935ABAE3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [TCP Query User{113B68B2-EDC0-4914-A02C-2012AC8F7740}C:\program files (x86)\simapppro\simapppro.exe] => (Allow) C:\program files (x86)\simapppro\simapppro.exe (WINWING) [File not signed]
FirewallRules: [UDP Query User{884759EC-8ED9-4C6D-9937-6AB86754CA26}C:\program files (x86)\simapppro\simapppro.exe] => (Allow) C:\program files (x86)\simapppro\simapppro.exe (WINWING) [File not signed]
FirewallRules: [{E12F0322-7D7B-4121-9D46-D6C660DDC024}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25212.2101.3846.4105_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{51B8DDEF-2C2B-48B2-AC35-6441862DABBB}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25212.2101.3846.4105_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D2FDC3A0-64F8-4993-8D60-C20EFDC6206F}] => (Allow) LPort=8736
FirewallRules: [{6A6A2D7A-D287-4E0D-A8C7-0D07C16DFFBB}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25306.804.4102.7193_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3B285710-3BA1-452C-9B46-764CE37DF376}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25306.804.4102.7193_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3BA96D45-C684-4DD9-82A1-5EF5D9CB3891}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25306.804.4102.7193_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1FB48323-20B5-4332-8966-ED41EF429746}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25306.804.4102.7193_x64__8wekyb3d8bbwe\ms-teams_modulehost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6BD3D8FC-AACA-4F0D-991D-273BC13BCA17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MSFS2024\FlightSimulator2024.exe (Asobo Studio) [File not signed]
FirewallRules: [{87B3C153-D1BE-4493-83A1-04307CC3DC8E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MSFS2024\FlightSimulator2024.exe (Asobo Studio) [File not signed]
FirewallRules: [TCP Query User{C2F847EB-0FF2-4A7B-97FF-45B4B0BA3DAC}C:\users\marti\appdata\local\programs\pmdg-oc3\pmdg oc3.exe] => (Allow) C:\users\marti\appdata\local\programs\pmdg-oc3\pmdg oc3.exe (Gotaclue Robert Miroszewski -> PMDG Simulations, LLC.)
FirewallRules: [UDP Query User{A1793A8B-4146-4494-99A1-BF50A8D97388}C:\users\marti\appdata\local\programs\pmdg-oc3\pmdg oc3.exe] => (Allow) C:\users\marti\appdata\local\programs\pmdg-oc3\pmdg oc3.exe (Gotaclue Robert Miroszewski -> PMDG Simulations, LLC.)

==================== Restore Points =========================

15-12-2025 21:14:08 Installed Microsoft Flight Simulator 2024 SDK 1.5.6 (Core)

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (12/16/2025 06:51:32 PM) (Source: Application Hang) (EventID: 1002) (User: NT AUTHORITY)
Description: Verze 0.0.0.0 programu StoreDesktopExtension.exe ukončila interakci se systémem Windows a byla ukončena. Pokud chcete zjistit, zda jsou k dispozici další informace o problému, zkontrolujte historii problémů v ovládacím panelu Zabezpečení a údržba.

Error: (12/16/2025 04:32:52 PM) (Source: Application Error) (EventID: 1000) (User: MARTIN)
Description: Název chybující aplikace: couatl64_MSFS2024.exe, verze: 5.0.0.6195, časové razítko: 0x6915c8fa
Název chybujícího modulu: clr.dll, verze: 4.8.9221.0, časové razítko: 0x68531fc6
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000000657c
ID chybujícího procesu: 0x5ef0
Čas spuštění chybující aplikace: 0x1dc6e9ce8ee8533
Cesta k chybující aplikaci: C:\Program Files (x86)\Addon Manager\couatl64\couatl64_MSFS2024.exe
Cesta k chybujícímu modulu: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
ID sestavy: 12c89a3d-69ec-4f0f-85a5-686e5021cb50
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (12/16/2025 04:32:52 PM) (Source: .NET Runtime) (EventID: 1023) (User: )
Description: Aplikace: couatl64_MSFS2024.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu vnitřní chyby v modulu .NET Runtime na IP adrese 00007FFD362B657C (00007FFD362B0000) s ukončovacím kódem 80131506.

Error: (12/15/2025 07:09:56 PM) (Source: Application Error) (EventID: 1000) (User: MARTIN)
Description: Název chybující aplikace: couatl64_MSFS2024.exe, verze: 5.0.0.6195, časové razítko: 0x6915c8fa
Název chybujícího modulu: clr.dll, verze: 4.8.9221.0, časové razítko: 0x68531fc6
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000003bd10
ID chybujícího procesu: 0x5ec8
Čas spuštění chybující aplikace: 0x1dc6dee006df6ab
Cesta k chybující aplikaci: C:\Program Files (x86)\Addon Manager\couatl64\couatl64_MSFS2024.exe
Cesta k chybujícímu modulu: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
ID sestavy: fe611636-2c04-4b06-b79c-d38763a83feb
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (12/15/2025 07:09:56 PM) (Source: .NET Runtime) (EventID: 1023) (User: )
Description: Aplikace: couatl64_MSFS2024.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu vnitřní chyby v modulu .NET Runtime na IP adrese 00007FFD362EBD10 (00007FFD362B0000) s ukončovacím kódem 80131506.

Error: (12/15/2025 07:09:40 PM) (Source: Application Error) (EventID: 1000) (User: MARTIN)
Description: Název chybující aplikace: couatl64_MSFS2024.exe, verze: 5.0.0.6195, časové razítko: 0x6915c8fa
Název chybujícího modulu: clr.dll, verze: 4.8.9221.0, časové razítko: 0x68531fc6
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000000657c
ID chybujícího procesu: 0x5ef4
Čas spuštění chybující aplikace: 0x1dc6dea0fb7b98f
Cesta k chybující aplikaci: C:\Program Files (x86)\Addon Manager\couatl64\couatl64_MSFS2024.exe
Cesta k chybujícímu modulu: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
ID sestavy: 90bc1e1e-f1e4-4fb4-a62b-567e925eac7b
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (12/15/2025 07:09:39 PM) (Source: .NET Runtime) (EventID: 1023) (User: )
Description: Aplikace: couatl64_MSFS2024.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu vnitřní chyby v modulu .NET Runtime na IP adrese 00007FFD362B657C (00007FFD362B0000) s ukončovacím kódem 80131506.

Error: (12/14/2025 06:27:48 PM) (Source: Application Error) (EventID: 1000) (User: MARTIN)
Description: Název chybující aplikace: couatl64_MSFS2024.exe, verze: 5.0.0.6195, časové razítko: 0x6915c8fa
Název chybujícího modulu: clr.dll, verze: 4.8.9221.0, časové razítko: 0x68531fc6
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000000657c
ID chybujícího procesu: 0x2578
Čas spuštění chybující aplikace: 0x1dc6d1add06208e
Cesta k chybující aplikaci: C:\Program Files (x86)\Addon Manager\couatl64\couatl64_MSFS2024.exe
Cesta k chybujícímu modulu: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
ID sestavy: b41488f0-79b4-4a14-abc0-77a79b44579e
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:


System errors:
=============
Error: (12/19/2025 05:02:21 PM) (Source: GuiHidUsbDevLowerTFH) (EventID: 2) (User: )
Description: Event-ID 2

Error: (12/19/2025 05:02:21 PM) (Source: GuiHidUsbDevLowerTFH) (EventID: 2) (User: )
Description: Event-ID 2

Error: (12/18/2025 08:43:08 PM) (Source: DCOM) (EventID: 10010) (User: MARTIN)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (12/18/2025 08:43:08 PM) (Source: DCOM) (EventID: 10010) (User: MARTIN)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (12/17/2025 09:14:16 PM) (Source: DCOM) (EventID: 10010) (User: MARTIN)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (12/17/2025 09:14:12 PM) (Source: DCOM) (EventID: 10010) (User: MARTIN)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (12/17/2025 09:14:12 PM) (Source: DCOM) (EventID: 10010) (User: MARTIN)
Description: Server {3E11DF0F-42EB-4747-9A35-802D98B5BCF0} se v daném časovém limitu neregistroval u služby DCOM.

Error: (12/17/2025 07:06:49 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot certificates have been updated but are not yet applied to the device firmware. Review the published guidance to complete the update and ensure full protection. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends International, LLC.;FirmwareVersion:21.02;OEMModelNumber:Z790 Steel Legend WiFi;OEMModelBaseBoard:Z790 Steel Legend WiFi;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:ASRock;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 7041d25e0e6cf63d4d83891eca90a055898f64ce98de0862c1cf7bdb7ad788d2
BucketConfidenceLevel:
UpdateType:
For more information, please see https://go.microsoft.com/fwlink/?linkid=2301018.


Windows Defender:
================
Date: 2025-12-18 18:34:35
Description:
Antivirová ochrana v programu Microsoft Defender śсǻη ħдѕ ъэεή šтőρρéδ ьëƒόѓë ςσмрļєťíőň.%л %τŞčąη ĮÐ:%в{5700943E-743A-4165-9102-F408BE9C4756}%й %ŧŚčâń Τỳφε:%вAntimalwarový program%ń %ŧŜċăņ Ρдѓámĕťëяš:%ъRychlé prohledávání%π %ţÚѕêґ:%ьNT AUTHORITY\SYSTEM%ń %тŠŧõρ Ŕéāşôň:%ьΓΡ€ çоňиέčťíбʼn ŗúⁿδόώй

Date: 2025-12-18 18:09:43
Description:
Antivirová ochrana v programu Microsoft Defender śсǻη ħдѕ ъэεή šтőρρéδ ьëƒόѓë ςσмрļєťíőň.%л %τŞčąη ĮÐ:%в{E93DA442-5FF8-4DB8-80F5-3EA8ED4F1BD1}%й %ŧŚčâń Τỳφε:%вAntimalwarový program%ń %ŧŜċăņ Ρдѓámĕťëяš:%ъRychlé prohledávání%π %ţÚѕêґ:%ьNT AUTHORITY\SYSTEM%ń %тŠŧõρ Ŕéāşôň:%ьΓΡ€ çоňиέčťíбʼn ŗúⁿδόώй

Date: 2025-12-18 18:02:08
Description:
Antivirová ochrana v programu Microsoft Defender śсǻη ħдѕ ъэεή šтőρρéδ ьëƒόѓë ςσмрļєťíőň.%л %τŞčąη ĮÐ:%в{DD8507DB-42A8-4C01-AE02-51E59D5876AC}%й %ŧŚčâń Τỳφε:%вAntimalwarový program%ń %ŧŜċăņ Ρдѓámĕťëяš:%ъRychlé prohledávání%π %ţÚѕêґ:%ьNT AUTHORITY\SYSTEM%ń %тŠŧõρ Ŕéāşôň:%ьŔРÇ ĉǿⁿиèćţìóп яũňďōŵŋ

Date: 2025-12-16 18:57:05
Description:
Antivirová ochrana v programu Microsoft Defender śсǻη ħдѕ ъэεή šтőρρéδ ьëƒόѓë ςσмрļєťíőň.%л %τŞčąη ĮÐ:%в{1C422D81-9D9A-4DED-9692-3527143CC001}%й %ŧŚčâń Τỳφε:%вAntimalwarový program%ń %ŧŜċăņ Ρдѓámĕťëяš:%ъRychlé prohledávání%π %ţÚѕêґ:%ьNT AUTHORITY\SYSTEM%ń %тŠŧõρ Ŕéāşôň:%ьŜċħēđџĺèδ şçάл ŵάś śķίрρēð ьéċäůŝз ŧће ľāşť ѕΰςçэśšƒüℓ ŝčâņ ώαŝ ώìŧћîл τћё ℓαşţ 7 δăÿѕ

Date: 2025-12-14 12:57:42
Description:
Antivirová ochrana v programu Microsoft Defender śсǻη ħдѕ ъэεή šтőρρéδ ьëƒόѓë ςσмрļєťíőň.%л %τŞčąη ĮÐ:%в{BDD58D67-090A-44F7-BFFD-7E57E58760F9}%й %ŧŚčâń Τỳφε:%вAntimalwarový program%ń %ŧŜċăņ Ρдѓámĕťëяš:%ъRychlé prohledávání%π %ţÚѕêґ:%ьNT AUTHORITY\SYSTEM%ń %тŠŧõρ Ŕéāşôň:%ьŜċħēđџĺèδ şçάл ŵάś śķίрρēð ьéċäůŝз ŧће ľāşť ѕΰςçэśšƒüℓ ŝčâņ ώαŝ ώìŧћîл τћё ℓαşţ 7 δăÿѕ
Event[0]

Date: 2025-12-06 18:36:00
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-11-04 19:49:55
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-08-24 15:53:15
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-08-18 19:10:53
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-08-18 19:09:38
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

CodeIntegrity:
===============
Date: 2025-12-17 20:09:11
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\AudioDevProps2.dll that did not meet the Microsoft signing level requirements.

Date: 2025-12-14 11:53:48
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeWebView\Application\142.0.3595.94\msedgewebview2.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\AudioDevProps2.dll that did not meet the Microsoft signing level requirements.

Date: 2025-11-18 17:50:46
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeWebView\Application\142.0.3595.80\msedgewebview2.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\AudioDevProps2.dll that did not meet the Microsoft signing level requirements.

Date: 2025-11-03 19:21:15
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeWebView\Application\141.0.3537.99\msedgewebview2.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\AudioDevProps2.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends International, LLC. 21.02 10/08/2025
Motherboard: ASRock Z790 Steel Legend WiFi
Processor: Intel(R) Core(TM) i7-14700K
Percentage of memory in use: 16%
Total physical RAM: 65295.25 MB
Available physical RAM: 54581.67 MB
Total Virtual: 69391.25 MB
Available Virtual: 57734.23 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:1862.12 GB) (Free:1160.56 GB) (Model: WD_BLACK SN770 2TB) NTFS

\\?\Volume{15f8162a-6101-4482-a6d7-c7d0ee34c194}\ () (Fixed) (Total:0.78 GB) (Free:0.09 GB) NTFS
\\?\Volume{a3314b53-6b5b-465c-97cc-70ba011d202f}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Re: Mohu poprosit prosím o preventivku :)

Napsal: 19 pro 2025 11:46
od JaRon
Ahoj,
poslal si 2x log add, chyba frst.txt
Su aj nejake problemy, alebo len preventivka?

Re: Mohu poprosit prosím o preventivku :)

Napsal: 19 pro 2025 17:17
od Blazacz
Ahoj poslal jsem znovu předchozí sem smazal tak snad už je to dobře.Problém žádný jen preventivku. Díky

Re: Mohu poprosit prosím o preventivku :)

Napsal: 19 pro 2025 17:28
od JaRon
Nevidim tam zavaznejsi problem, preventivne prescanuj s NPE https://support.norton.com/sp/static/ex ... s/npe.html