Pozůstatky malware ?
Napsal: 26 bře 2026 16:00
Dobrý den,
prosím o konntrolu logu, 18.03.2025 kolem p§l osmé ráno jsem při vstývání zjitil, že jsem se stal obětí hackerského útoku, kdy mi byly odcizeny ověřené účty na sociálních sítích bez upozornění, vyčistil jsem snad vše a zasílám log pro kointrolu, podíváte se mi na to prosím ?
can result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-03-2026
Ran by Jose Madeira (administrator) on JOSECKO (Dell Inc. Latitude 5510) (26-03-2026 15:41:16)
Running from C:\Users\Jose Madeira\Downloads\FRST64.exe
Loaded Profiles: Jose Madeira & WsiAccount
Platform: Microsoft Windows 11 Pro Version 24H2 26100.8039 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSATray.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1538.24328.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1538.24328.0_x64__nzyj5cx40ttqa\AppleMobileDeviceProcess.exe
(C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudCKKS.exe
(C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudDrive.exe
(C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudPhotos.exe
(C:\ProgramData\Dell\drivers\7e98c440-4a26-46d6-864d-50287d8955fe\DellOptimizer.exe ->) (Dell Technologies Inc. -> Dell Technologies, Inc.) C:\Windows\Temp\{0F53B847-F7AD-4001-850E-C0763C766A0D}\_is6E39.exe <2>
(C:\ProgramData\Dell\UpdateService\Downloads\FOLDER14235674M\4\Dell-Optimizer-Application_J9P2R_WIN64_6.3.2.0_A00.EXE ->) (Dell Technologies Inc. -> Dell Technologies, Inc.) C:\ProgramData\Dell\drivers\7e98c440-4a26-46d6-864d-50287d8955fe\DellOptimizer.exe
(C:\Windows\Temp\{0F53B847-F7AD-4001-850E-C0763C766A0D}\_is6E39.exe ->) (Dell Technologies Inc. -> Flexera) C:\Windows\Temp\{0F53B847-F7AD-4001-850E-C0763C766A0D}\{3858D95B}\setup64.exe
(Dell Technologies Inc. -> ) C:\Program Files\Dell\DellOptimizer\DellEnterpriseClientFrameworkSubAgent.exe
(Dell Technologies Inc. -> ) C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe
(Dell Technologies Inc. -> Dell Inc.) C:\ProgramData\Dell\UpdateService\Downloads\FOLDER14235674M\4\Dell-Optimizer-Application_J9P2R_WIN64_6.3.2.0_A00.EXE
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellOptimizer\Console\DellOptimizer.Systray.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellOptimizer\SubAgents\Dell.UUE.CoreSubAgent\Dell.UUE.CoreSubAgent.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellOptimizer\SubAgents\Dell.UUE.User.SubAgent\Dell.UUE.User.SubAgent.exe
(Dell Technologies Inc. -> Dell) C:\Program Files\Dell\DellDigitalDelivery\SubAgent\Dell.Digital.Delivery.Service.SubAgent.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_0e0cef3aab259dd1\igfxCUIService.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0e0cef3aab259dd1\igfxEM.exe
(DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\dptf_helper.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <12>
(explorer.exe ->) (Telegram FZ-LLC -> Telegram FZ-LLC) C:\Users\Jose Madeira\AppData\Roaming\Telegram Desktop\Telegram.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2603.48201.0_x64__8wekyb3d8bbwe\M365Copilot.exe
(msiexec.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(services.exe ->) ("STMicroelectronics Srl" -> ) C:\Windows\System32\drivers\DellFFDPWmiService.exe
(services.exe ->) (Avid Technology, Inc. -> M-Audio) C:\Program Files (x86)\M-Audio\Fast Track Pro\AudioDevMon.exe
(services.exe ->) (Broadcom Inc. -> ) C:\Windows\System32\bcmUshUpgradeService.exe
(services.exe ->) (Broadcom Inc. -> Broadcom Corporation) C:\Windows\System32\bcmHostControlService.exe
(services.exe ->) (Broadcom Inc. -> Broadcom Corporation) C:\Windows\System32\bcmHostStorageService.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files (x86)\Dell\CommandIntelvProOutOfBand\DellAWESvc.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\EndpointConfigure\Dell.EndpointConfigure.WinServiceAgent.exe
(services.exe ->) (Dell Technologies Inc. -> Dell INC.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(services.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TrustedDevice\Dell.TrustedDevice.Service.exe
(services.exe ->) (Fibocom Wireless Inc. -> Fibocom Wireless Inc.) C:\Windows\Firmware\FwSwitchbin\FwSwitchService.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_99f6bd58bfe82726\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d7a222f6ce13d429\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_581d7e91d349facc\AS\IAS\IntelAudioService.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0e0cef3aab259dd1\igfxCUIService.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_bcf814bde8c7d262\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d5820df0105f0e9\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d5820df0105f0e9\IntelCpHeciSvc.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe <2>
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm\Bluetooth Suite\AdminService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe
(services.exe ->) (MuseCY SM Ltd -> Muse Group) C:\Program Files\MuseHub\current\MuseAuthService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_04ff63d068f8c626\RtkAudUService64.exe <3>
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_9cf66a75b9c50ded\WavesSysSvc64.exe
(sihost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> WhatsApp.Root) C:\Program Files\WindowsApps\5319275A.51895FA4EA97F_2.2611.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(sihost.exe ->) (50BDFD77-8903-4850-9FFE-6E8522F64D5B -> OpenAI) C:\Program Files\WindowsApps\OpenAI.ChatGPT-Desktop_1.2026.43.0_x64__2p2nqsd0c76g0\app\ChatGPT.exe <5>
(sihost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1538.24328.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe
(sihost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe
(sihost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(svchost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\ApplePhotoStreams.exe
(svchost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\APSDaemon.exe
(svchost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple, Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\secd.exe
(svchost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.ScreenSketch_11.2601.2.0_x64__8wekyb3d8bbwe\SnippingTool\SnippingTool.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.241.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\UtcDecoderHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_04ff63d068f8c626\RtkAudUService64.exe [1961360 2023-11-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\WINDOWS\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_9cf66a75b9c50ded\WavesSvc64.exe [5542112 2024-03-08] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [MuseHub] => C:\Program Files\MuseHub\current\MuseHub.exe [59699760 2026-01-15] (MuseCY SM Ltd -> MuseHub)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-196143437-2400517662-190078704-1002\...\Run: [org.whispersystems.signal-desktop] => C:\Users\Jose Madeira\AppData\Local\Programs\signal-desktop\Signal.exe [213754288 2026-02-25] (Signal Messenger, LLC -> Signal Messenger, LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\146.0.7680.165\Installer\chrmstp.exe [2026-03-26] (Google LLC -> Google LLC)
Startup: C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk [2026-03-17]
ShortcutTarget: Telegram.lnk -> C:\Users\Jose Madeira\AppData\Roaming\Telegram Desktop\Telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ableton USB Audio Control Panel Autostart.lnk [2025-12-11]
ShortcutTarget: Ableton USB Audio Control Panel Autostart.lnk -> C:\Program Files\Ableton\USB Audio Driver\x64\AbletonAudioCpl.exe (Thesycon Software Solutions GmbH & Co. KG -> )
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {ECA0AB4E-E54E-4804-A96A-B004F16FB6E8} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-196143437-2400517662-190078704-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {2170452D-DCF4-4DB9-ADE5-114C6DED8287} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [1308312 2026-02-27] (Dell Technologies Inc. -> Dell Inc.) -> C:\Program Files\Dell\SupportAssistAgent\bin\AutoUpdate
Task: {1A0A632B-1BAB-4D19-ADFF-5F197AACDE10} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{6BBFD062-BC30-4841-A3F4-E0D77EE0D9CA} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [6517400 2026-03-12] (Google LLC -> Google LLC)
Task: {43D76A25-682E-4F6E-9E32-EE3B2A2D3112} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [6466256 2026-01-16] (Intel Corporation -> Intel Corporation)
Task: {78FBE537-0B95-4261-95BD-5E82B5422479} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [6466256 2026-01-16] (Intel Corporation -> Intel Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {D4867D41-B900-49EC-9726-967D0865C165} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {190FC5EF-3D50-4208-A483-5B8B4B106A8D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D6A1AAB0-8D6C-4D61-941B-A684532F7A70} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CDE98D87-3A36-469B-A7A0-509DC9591E75} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9AA6FEB3-EFD5-4437-854A-7EEEFFEA1426} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-196143437-2400517662-190078704-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {2CC11382-FC30-4A59-8D71-708174423A8B} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-196143437-2400517662-190078704-1003 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {EE263844-040D-4103-ACFF-44BEA51F7FD5} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-196143437-2400517662-190078704-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {DBE9539C-7117-4B64-8BE2-3A1C19CB26D0} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6461560 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {9C428FDC-8851-47E1-A838-93C85E6309FD} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9274080 2026-02-26] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {C48797BD-B567-4358-9FEE-0C6FC1888DA5} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe [454656 2025-11-07] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\-Command "Start-Process -WindowStyle Hidden task.bat"
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 06 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 06 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0ac08c43-85cc-49e2-97c5-8b314b5e5f80}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{d46ca9e9-995c-47a4-94a0-0b34a7790ba2}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default [2026-03-26]
Edge Notifications: Default -> hxxps://www.snapchat.com
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-03-25]
Edge Extension: (Dokumenty Google offline) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-04]
Edge Extension: (Edge relevant text changes) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-12-10]
Edge Profile: C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2026-03-04]
Edge Extension: (Dokumenty Google offline) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-09]
Edge Extension: (Edge relevant text changes) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-12-09]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default [2026-03-26]
CHR Notifications: Default -> hxxps://business.facebook.com; hxxps://webmail.forpsi.com; hxxps://www.facebook.com; hxxps://www.youtube.com
CHR Extension: (Překladač Google) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2025-11-24]
CHR Extension: (Authenticator) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhghoamapcdpbohphigoooaddinpkbai [2025-12-11]
CHR Extension: (Word Online) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2025-11-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-11-24]
CHR Extension: (Hesla na iCloudu) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pejdijmoenmkgeppbflobdenhhabjlaj [2025-12-19]
CHR Profile: C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\System Profile [2026-03-20]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm\Bluetooth Suite\adminservice.exe [404384 2022-01-23] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [29465352 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
R2 DCECMISvc; C:\Program Files\Dell\EndpointConfigure\Dell.EndpointConfigure.WinServiceAgent.exe [168216 2025-04-15] (Dell Technologies Inc. -> Dell Inc.)
R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [20240 2025-12-02] (Dell Technologies Inc. -> Dell INC.)
R2 DellAweSvc; C:\Program Files (x86)\Dell\CommandIntelvProOutOfBand\DellAWESvc.exe [73968 2025-04-04] (Dell Technologies Inc. -> Dell Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [49952 2026-02-02] (Dell Technologies Inc. -> )
R2 DellFFDPWmiService; C:\WINDOWS\System32\drivers\DellFFDPWmiService.exe [33368 2022-01-26] ("STMicroelectronics Srl" -> )
R2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [149704 2025-11-30] (Dell Technologies Inc. -> Dell)
R2 DellTrustedDevice; C:\Program Files\Dell\TrustedDevice\Dell.TrustedDevice.Service.exe [154752 2025-11-07] (Dell Technologies Inc. -> Dell)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [133736 2025-08-27] (Intel Corporation -> Intel)
R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [133224 2025-08-27] (Intel Corporation -> Intel)
R2 FastTrackProAudioDevMon; C:\Program Files (x86)\M-Audio\Fast Track Pro\AudioDevMon.exe [1688296 2015-06-10] (Avid Technology, Inc. -> M-Audio)
R2 hostcontrolsvc; C:\WINDOWS\System32\bcmHostControlService.exe [846512 2025-06-16] (Broadcom Inc. -> Broadcom Corporation)
R2 hoststoragesvc; C:\WINDOWS\System32\bcmHostStorageService.exe [209136 2025-10-21] (Broadcom Inc. -> Broadcom Corporation)
R2 IntelAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_581d7e91d349facc\AS\IAS\IntelAudioService.exe [412128 2022-10-27] (Intel Corporation -> Intel)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11420952 2026-03-20] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-01-10] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe [2088128 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MuseAuthService; C:\Program Files\MuseHub\current\MuseAuthService.exe [9957424 2026-01-15] (MuseCY SM Ltd -> Muse Group)
S3 MuseHubUpdaterService; C:\Program Files\MuseHub\current\MuseHub.Updater.exe [8250416 2026-01-15] (MuseCY SM Ltd -> MuseHub.Updater)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [811360 2026-02-24] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [149656 2026-02-27] (Dell Technologies Inc. -> Dell Inc.)
R2 ushupgradesvc; C:\WINDOWS\System32\bcmUshUpgradeService.exe [360752 2025-10-21] (Broadcom Inc. -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe [4451664 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe [290704 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
S3 AppShellElevationService; "C:\Program Files\TikTok LIVE Studio\1.12.0\elevation_service.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 cxwmbclass; C:\WINDOWS\System32\DriverStore\FileRepository\netwmbclass.inf_amd64_7e33f06b13d0c370\cxwmbclass.sys [167936 2026-02-24] (Microsoft Windows -> Microsoft Corporation)
S3 DellBV; C:\WINDOWS\system32\DRIVERS\DellBV.sys [161072 2025-11-07] (Dell Technologies Inc. -> Dell)
S3 DellInstrumentation; C:\WINDOWS\System32\drivers\DellInstrumentation.sys [33336 2025-11-20] (Microsoft Windows Hardware Compatibility Publisher -> Dell)
S3 DPMDriver; C:\WINDOWS\System32\drivers\DPMDriver.sys [142272 2024-10-30] (IndiLogic LLC -> Dell Inc.)
R1 dtdsel; C:\WINDOWS\System32\DRIVERS\dtdsel.sys [139576 2025-11-07] (Dell Technologies Inc. -> Dell)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_0a58c9ba33b1dc0f\e1d.sys [625368 2025-09-01] (Intel Corporation -> Intel Corporation)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82352 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 MAUSBFASTTRACKPRO; C:\WINDOWS\System32\drivers\MAudioFastTrackPro.sys [184552 2015-06-10] (Avid Technology, Inc. -> M-Audio)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234600 2026-03-25] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [245864 2026-03-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MoisesVAD; C:\WINDOWS\System32\DriverStore\FileRepository\moisesvad.inf_amd64_69572c0db43b9e35\MoisesVAD.sys [80872 2026-02-02] (Moises Systems, Inc. -> Windows (R) Win 7 DDK provider)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [32352 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
S3 RtkUsbAD_2370; C:\WINDOWS\System32\DriverStore\FileRepository\rtdusbad_dell.inf_amd64_fcf8a1ae51151778\RtUsbA64.sys [504168 2023-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 RtkUsbAD_2422; C:\WINDOWS\System32\DriverStore\FileRepository\rtdusbad_dell.inf_amd64_07ee7a18aaea6155\RtUsbA64.sys [524288 2025-08-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 rtu53cx22x64; C:\WINDOWS\System32\DriverStore\FileRepository\rtu53cx22x64sta.inf_amd64_96b55918d02d83c6\rtu53cx22x64.sys [1168896 2025-12-03] (Realtek Semiconductor Corp. -> Realtek Corporation)
S3 rtucx21x64; C:\WINDOWS\System32\DriverStore\FileRepository\rtucx21x64.inf_amd64_286645bc82b2f9fb\rtucx21x64.sys [1359360 2024-04-01] (Microsoft Windows -> Realtek Corporation)
R3 UDE; C:\WINDOWS\System32\drivers\UDE.sys [337384 2021-09-27] (Fibocom Wireless Inc. -> Intel Corporation)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [File not signed]
S3 UsbNcm; C:\WINDOWS\System32\DriverStore\FileRepository\usbncm.inf_amd64_989230fcb4a5468f\UsbNcm.sys [208896 2026-02-24] (Microsoft Windows -> )
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21888 2026-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [641416 2026-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [103816 2026-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WiManH; C:\WINDOWS\System32\DriverStore\FileRepository\wiman.inf_amd64_1d81bc4f31bf65c7\WiManH\WiManH.sys [184224 2025-10-28] (Intel Corporation -> Intel Corporation)
S3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-03-26 15:41 - 2026-03-26 15:43 - 000030444 _____ C:\Users\Jose Madeira\Downloads\FRST.txt
2026-03-26 15:41 - 2026-03-26 15:42 - 000000000 ____D C:\FRST
2026-03-26 15:40 - 2026-03-26 15:40 - 002445824 _____ (Farbar) C:\Users\Jose Madeira\Downloads\FRST64.exe
2026-03-26 14:12 - 2026-03-26 14:12 - 006416248 _____ C:\Users\Jose Madeira\Downloads\IMG_3A56896E-1DAA-4365-BC77-BB9767BDCCF9.JPEG
2026-03-26 14:11 - 2026-03-26 14:11 - 000105699 _____ C:\Users\Jose Madeira\Downloads\71987a73-dc0a-4c41-a338-a45519ebec4e.JPEG
2026-03-26 14:09 - 2026-03-26 14:09 - 002930270 _____ C:\Users\Jose Madeira\Downloads\IMG_4FB31948-405D-4F8C-A467-30FA29FDCD0A.JPEG
2026-03-26 13:55 - 2026-03-26 13:55 - 000089263 _____ C:\Users\Jose Madeira\OneDrive\Plocha\WhatsApp Image 2026-03-26 at 02.25.46.jpeg
2026-03-26 13:55 - 2026-03-26 13:55 - 000066589 _____ C:\Users\Jose Madeira\OneDrive\Plocha\WhatsApp Image 2026-03-26 at 02.27.56.jpeg
2026-03-26 13:33 - 2026-03-26 13:33 - 000002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-03-26 13:33 - 2026-03-26 13:33 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2026-03-26 13:32 - 2026-03-26 13:32 - 011487160 _____ (Google LLC) C:\Users\Jose Madeira\Downloads\ChromeSetup.exe
2026-03-26 11:40 - 2026-03-26 11:40 - 000679834 _____ C:\WINDOWS\system32\perfh005.dat
2026-03-26 11:40 - 2026-03-26 11:40 - 000145634 _____ C:\WINDOWS\system32\perfc005.dat
2026-03-25 21:57 - 2026-03-25 21:57 - 000000000 ____D C:\Program Files\Google
2026-03-25 18:27 - 2026-03-26 11:52 - 000000000 ____D C:\ProgramData\RogueKiller
2026-03-25 18:12 - 2026-03-25 18:12 - 000000000 ____D C:\AdwCleaner
2026-03-24 10:29 - 2026-03-26 13:33 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-03-21 01:33 - 2026-03-21 01:33 - 000000765 _____ C:\Users\Jose Madeira\OneDrive\Plocha\rekordbox 7.lnk
2026-03-20 20:49 - 2026-03-20 20:49 - 000000000 ____D C:\Users\Jose Madeira\Downloads\Telegram Desktop
2026-03-17 17:10 - 2026-03-17 20:01 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\tor
2026-03-17 08:13 - 2026-03-26 12:42 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\FOTKY NA SC
2026-03-17 05:12 - 2026-03-17 05:12 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\AdvinstAnalytics
2026-03-17 05:11 - 2026-03-17 05:11 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Opera Software
2026-03-13 18:09 - 2026-03-26 12:44 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\MUJ TRACK
2026-03-13 02:02 - 2026-03-13 02:02 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Xfer
2026-03-13 01:59 - 2026-03-13 01:59 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Xfer
2026-03-13 01:58 - 2026-03-13 01:58 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Documents\Xfer
2026-03-10 07:04 - 2026-03-10 07:07 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Moises
2026-03-10 07:04 - 2026-03-10 07:04 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\moises-desktop-updater
2026-03-10 06:41 - 2026-03-10 19:39 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Moises Live
2026-03-10 06:41 - 2026-03-10 06:41 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\moises-live-windows-updater
2026-03-06 20:44 - 2026-03-06 20:44 - 005255624 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\Netwtw10.sys
2026-03-06 20:44 - 2026-03-06 20:44 - 001627080 _____ (Intel Corporation) C:\WINDOWS\system32\IntelIHVRouter10.dll
2026-03-05 12:58 - 2026-03-05 12:58 - 000001133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton Live 12 Suite.lnk
2026-03-05 12:58 - 2026-03-05 12:58 - 000000410 __RSH C:\ProgramData\ntuser.pol
2026-03-05 12:37 - 2026-03-05 12:37 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-03-04 20:19 - 2026-03-11 07:02 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Avast Software
2026-03-04 20:14 - 2026-03-04 20:14 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\CEF
2026-03-04 20:12 - 2026-03-11 07:31 - 000000000 ____D C:\ProgramData\Avast Software
2026-03-04 20:12 - 2026-03-10 19:23 - 000002398 _____ C:\WINDOWS\system32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-196143437-2400517662-190078704-1002
2026-03-04 20:12 - 2026-03-04 20:12 - 000056128 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2026-03-04 20:12 - 2026-03-04 20:12 - 000002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 7.lnk
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\WINDOWS\system32\Tasks\Piriform
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\CCleaner
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\ProgramData\Piriform
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\Program Files\Piriform
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\Program Files\Common Files\Piriform
2026-03-03 12:14 - 2026-03-10 19:23 - 000002608 _____ C:\WINDOWS\system32\Tasks\USER_ESRV_SVC_QUEENCREEK
2026-03-03 12:14 - 2026-01-27 11:24 - 000049872 _____ (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\semav6msr64.sys
2026-02-26 10:30 - 2026-02-26 10:30 - 000000000 ____D C:\Users\Jose Madeira\0
2026-02-24 19:43 - 2026-02-24 19:43 - 000083946 _____ C:\WINDOWS\SysWOW64\ctac.json
2026-02-24 19:43 - 2026-02-24 19:43 - 000083946 _____ C:\WINDOWS\system32\ctac.json
2026-02-24 19:43 - 2026-02-24 19:43 - 000036382 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-02-24 19:43 - 2026-02-24 19:43 - 000036382 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-03-26 15:44 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-03-26 15:43 - 2026-01-10 08:54 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Malwarebytes
2026-03-26 15:40 - 2025-11-07 08:05 - 000000000 ____D C:\Program Files (x86)\Dell
2026-03-26 14:33 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-03-26 13:34 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-03-26 13:33 - 2025-11-24 09:34 - 000000000 ____D C:\Program Files (x86)\Google
2026-03-26 13:31 - 2026-02-18 02:12 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Telegram Desktop
2026-03-26 12:44 - 2026-02-23 22:37 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\HLAS BEZ TVÁŘE - PROJEKT
2026-03-26 12:43 - 2026-01-06 13:16 - 000000000 ___RD C:\Users\Jose Madeira\OneDrive\Plocha\HUDBA
2026-03-26 12:12 - 2025-11-07 07:56 - 000000000 ___DC C:\WINDOWS\Panther
2026-03-26 12:08 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ServiceState
2026-03-26 12:06 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-03-26 11:40 - 2025-11-07 08:07 - 001603854 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-03-26 11:40 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF
2026-03-26 11:39 - 2025-11-07 07:58 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-03-26 11:35 - 2025-12-10 13:57 - 000000000 ___RD C:\Users\Jose Madeira\iCloudDrive
2026-03-26 11:35 - 2025-12-10 04:34 - 000000000 ___RD C:\Users\Jose Madeira\iCloudPhotos
2026-03-26 11:33 - 2025-11-14 10:57 - 000000000 __SHD C:\Users\Jose Madeira\IntelGraphicsProfiles
2026-03-26 11:33 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\Registration
2026-03-26 11:32 - 2025-12-11 02:44 - 000000000 ____D C:\ProgramData\boost_interprocess
2026-03-26 11:32 - 2025-11-07 08:09 - 000000000 ____D C:\Intel
2026-03-26 11:32 - 2025-11-07 08:07 - 000450668 _____ C:\WINDOWS\system32\CVFirmwareUpgradeLog.txt
2026-03-26 11:32 - 2025-11-07 08:04 - 000020878 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-03-26 11:32 - 2025-11-07 07:58 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-03-26 11:32 - 2025-11-07 07:57 - 000012288 ___SH C:\DumpStack.log.tmp
2026-03-26 11:32 - 2024-04-01 08:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-03-26 09:59 - 2025-11-24 19:23 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH
2026-03-26 09:56 - 2025-11-07 07:57 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2026-03-26 08:05 - 2025-11-07 07:57 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-03-26 08:04 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\D3DSCache
2026-03-25 21:46 - 2026-01-15 19:49 - 000000000 ____D C:\WINDOWS\Minidump
2026-03-25 21:46 - 2026-01-11 07:08 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\CrashDumps
2026-03-25 21:18 - 2025-11-07 07:58 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-03-25 21:06 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira
2026-03-25 18:15 - 2025-11-24 07:55 - 000000000 ____D C:\Users\WsiAccount
2026-03-25 18:03 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Packages
2026-03-25 17:53 - 2025-11-07 08:48 - 000000000 ____D C:\Program Files (x86)\Intel
2026-03-25 17:46 - 2025-11-07 08:42 - 000000000 ____D C:\ProgramData\Package Cache
2026-03-25 17:46 - 2025-11-07 08:42 - 000000000 ____D C:\Program Files\Intel
2026-03-25 11:43 - 2025-11-24 07:07 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Comms
2026-03-22 11:51 - 2024-04-01 08:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2026-03-22 11:51 - 2024-04-01 08:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2026-03-21 21:20 - 2025-12-10 05:25 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\audacity
2026-03-21 03:07 - 2025-11-24 06:58 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\rekordboxAgent
2026-03-21 01:35 - 2025-11-25 05:26 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\rekordbox
2026-03-21 01:35 - 2025-11-24 06:58 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\PioneerLog
2026-03-21 01:35 - 2025-11-24 06:52 - 000000000 ____D C:\Program Files\rekordbox
2026-03-19 23:45 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2026-03-17 17:28 - 2020-08-13 06:00 - 000056520 _____ (Microsoft Corporation) C:\WINDOWS\cryptdll.dll
2026-03-17 17:28 - 2019-12-09 10:06 - 000001368 _____ C:\WINDOWS\system32\README.txt
2026-03-17 17:08 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows
2026-03-17 16:53 - 2025-11-25 04:01 - 000003030 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132
2026-03-17 16:53 - 2025-11-25 04:01 - 000002664 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon
2026-03-17 15:54 - 2025-12-10 05:01 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\APPKY
2026-03-17 15:09 - 2026-01-26 06:06 - 000002611 _____ C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Signal.lnk
2026-03-17 14:45 - 2025-11-07 08:00 - 000000000 ____D C:\ProgramData\Packages
2026-03-17 05:01 - 2025-12-31 19:01 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\honza fa
2026-03-15 18:23 - 2026-01-10 08:54 - 000002053 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-03-15 18:22 - 2026-01-10 08:53 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-03-15 18:22 - 2026-01-10 08:53 - 000000000 ____D C:\Program Files\Malwarebytes
2026-03-13 01:58 - 2025-12-11 02:47 - 000000000 ____D C:\Program Files\Common Files\VST3
2026-03-11 13:57 - 2025-12-11 08:19 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Documents\Audacity
2026-03-11 12:18 - 2026-01-10 09:38 - 000003942 _____ C:\WINDOWS\system32\Tasks\Dell SupportAssistAgent AutoUpdate
2026-03-11 12:18 - 2025-11-07 08:04 - 000000000 ____D C:\ProgramData\Dell
2026-03-11 06:54 - 2025-12-20 19:48 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Bytedance
2026-03-11 03:56 - 2024-04-01 17:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-03-11 03:45 - 2025-11-07 08:02 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-03-10 23:41 - 2025-11-25 04:01 - 000000000 ____D C:\Program Files\dotnet
2026-03-10 23:40 - 2025-11-25 04:00 - 000000000 ____D C:\Program Files (x86)\dotnet
2026-03-10 19:23 - 2025-11-07 07:58 - 000003642 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{6753DEC1-A261-4A01-94F7-175AF372A4FF}
2026-03-10 19:23 - 2025-11-07 07:58 - 000003416 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{8A9FE38D-73D2-48B8-AEC7-62EF82D81B0D}
2026-03-10 16:28 - 2025-12-11 08:47 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Documents\Max 9
2026-03-10 13:13 - 2026-02-17 15:19 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\ABLETON - PROJEKTY
2026-03-08 17:46 - 2025-11-24 14:26 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\CapCut
2026-03-08 17:40 - 2025-12-10 03:50 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000000-000000.txt
2026-03-05 13:02 - 2025-12-11 08:46 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Ableton
2026-03-04 21:27 - 2026-02-01 22:38 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\veci na AKAI & ABLETON
2026-03-04 20:29 - 2026-01-26 06:06 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Signal
2026-03-04 20:29 - 2025-12-11 02:44 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Muse Hub
2026-03-04 20:21 - 2026-01-10 08:54 - 000245864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2026-03-04 20:13 - 2024-04-01 08:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-03-03 19:21 - 2025-12-11 02:44 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\MuseSampler
2026-02-28 10:43 - 2026-01-14 12:36 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\VirtualDJ
2026-02-28 10:43 - 2026-01-14 12:36 - 000000000 ____D C:\Program Files\VirtualDJ
2026-02-26 10:44 - 2025-11-24 10:26 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Microsoft\MMC
2026-02-25 17:12 - 2026-01-10 10:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\UUS
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-02-24 20:41 - 2024-04-01 17:31 - 000000000 ____D C:\WINDOWS\InboxApps
2026-02-24 20:41 - 2024-04-01 17:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\appcompat
2026-02-24 20:41 - 2024-04-01 08:21 - 000000000 ____D C:\WINDOWS\servicing
==================== Files in the root of some directories ========
2024-02-22 12:40 - 2024-02-22 12:40 - 000181440 _____ (Dell Inc.) C:\Users\Jose Madeira\DellInstaller_x64.exe
2025-12-11 02:47 - 2025-12-11 02:47 - 000450785 _____ () C:\Program Files\Common Files\Place_it_Uninstall.exe
2025-12-11 02:48 - 2025-12-11 02:48 - 000060131 _____ () C:\Program Files\Common Files\Shape_it_Uninstall.exe
2026-01-17 19:07 - 2026-01-17 19:07 - 000000017 _____ () C:\Users\Jose Madeira\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
prosím o konntrolu logu, 18.03.2025 kolem p§l osmé ráno jsem při vstývání zjitil, že jsem se stal obětí hackerského útoku, kdy mi byly odcizeny ověřené účty na sociálních sítích bez upozornění, vyčistil jsem snad vše a zasílám log pro kointrolu, podíváte se mi na to prosím ?
can result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-03-2026
Ran by Jose Madeira (administrator) on JOSECKO (Dell Inc. Latitude 5510) (26-03-2026 15:41:16)
Running from C:\Users\Jose Madeira\Downloads\FRST64.exe
Loaded Profiles: Jose Madeira & WsiAccount
Platform: Microsoft Windows 11 Pro Version 24H2 26100.8039 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSATray.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1538.24328.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1538.24328.0_x64__nzyj5cx40ttqa\AppleMobileDeviceProcess.exe
(C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudCKKS.exe
(C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudDrive.exe
(C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudPhotos.exe
(C:\ProgramData\Dell\drivers\7e98c440-4a26-46d6-864d-50287d8955fe\DellOptimizer.exe ->) (Dell Technologies Inc. -> Dell Technologies, Inc.) C:\Windows\Temp\{0F53B847-F7AD-4001-850E-C0763C766A0D}\_is6E39.exe <2>
(C:\ProgramData\Dell\UpdateService\Downloads\FOLDER14235674M\4\Dell-Optimizer-Application_J9P2R_WIN64_6.3.2.0_A00.EXE ->) (Dell Technologies Inc. -> Dell Technologies, Inc.) C:\ProgramData\Dell\drivers\7e98c440-4a26-46d6-864d-50287d8955fe\DellOptimizer.exe
(C:\Windows\Temp\{0F53B847-F7AD-4001-850E-C0763C766A0D}\_is6E39.exe ->) (Dell Technologies Inc. -> Flexera) C:\Windows\Temp\{0F53B847-F7AD-4001-850E-C0763C766A0D}\{3858D95B}\setup64.exe
(Dell Technologies Inc. -> ) C:\Program Files\Dell\DellOptimizer\DellEnterpriseClientFrameworkSubAgent.exe
(Dell Technologies Inc. -> ) C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe
(Dell Technologies Inc. -> Dell Inc.) C:\ProgramData\Dell\UpdateService\Downloads\FOLDER14235674M\4\Dell-Optimizer-Application_J9P2R_WIN64_6.3.2.0_A00.EXE
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellOptimizer\Console\DellOptimizer.Systray.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellOptimizer\SubAgents\Dell.UUE.CoreSubAgent\Dell.UUE.CoreSubAgent.exe
(Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellOptimizer\SubAgents\Dell.UUE.User.SubAgent\Dell.UUE.User.SubAgent.exe
(Dell Technologies Inc. -> Dell) C:\Program Files\Dell\DellDigitalDelivery\SubAgent\Dell.Digital.Delivery.Service.SubAgent.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_0e0cef3aab259dd1\igfxCUIService.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0e0cef3aab259dd1\igfxEM.exe
(DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\dptf_helper.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <12>
(explorer.exe ->) (Telegram FZ-LLC -> Telegram FZ-LLC) C:\Users\Jose Madeira\AppData\Roaming\Telegram Desktop\Telegram.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2603.48201.0_x64__8wekyb3d8bbwe\M365Copilot.exe
(msiexec.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(services.exe ->) ("STMicroelectronics Srl" -> ) C:\Windows\System32\drivers\DellFFDPWmiService.exe
(services.exe ->) (Avid Technology, Inc. -> M-Audio) C:\Program Files (x86)\M-Audio\Fast Track Pro\AudioDevMon.exe
(services.exe ->) (Broadcom Inc. -> ) C:\Windows\System32\bcmUshUpgradeService.exe
(services.exe ->) (Broadcom Inc. -> Broadcom Corporation) C:\Windows\System32\bcmHostControlService.exe
(services.exe ->) (Broadcom Inc. -> Broadcom Corporation) C:\Windows\System32\bcmHostStorageService.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files (x86)\Dell\CommandIntelvProOutOfBand\DellAWESvc.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\EndpointConfigure\Dell.EndpointConfigure.WinServiceAgent.exe
(services.exe ->) (Dell Technologies Inc. -> Dell INC.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(services.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TrustedDevice\Dell.TrustedDevice.Service.exe
(services.exe ->) (Fibocom Wireless Inc. -> Fibocom Wireless Inc.) C:\Windows\Firmware\FwSwitchbin\FwSwitchService.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_99f6bd58bfe82726\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d7a222f6ce13d429\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_581d7e91d349facc\AS\IAS\IntelAudioService.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0e0cef3aab259dd1\igfxCUIService.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_bcf814bde8c7d262\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d5820df0105f0e9\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Graphics Internal 2023 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6d5820df0105f0e9\IntelCpHeciSvc.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe <2>
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm\Bluetooth Suite\AdminService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe
(services.exe ->) (MuseCY SM Ltd -> Muse Group) C:\Program Files\MuseHub\current\MuseAuthService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_04ff63d068f8c626\RtkAudUService64.exe <3>
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_9cf66a75b9c50ded\WavesSysSvc64.exe
(sihost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> WhatsApp.Root) C:\Program Files\WindowsApps\5319275A.51895FA4EA97F_2.2611.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(sihost.exe ->) (50BDFD77-8903-4850-9FFE-6E8522F64D5B -> OpenAI) C:\Program Files\WindowsApps\OpenAI.ChatGPT-Desktop_1.2026.43.0_x64__2p2nqsd0c76g0\app\ChatGPT.exe <5>
(sihost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1538.24328.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe
(sihost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\iCloudHome.exe
(sihost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(svchost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\ApplePhotoStreams.exe
(svchost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\APSDaemon.exe
(svchost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple, Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_15.7.56.0_x64__nzyj5cx40ttqa\iCloud\secd.exe
(svchost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.ScreenSketch_11.2601.2.0_x64__8wekyb3d8bbwe\SnippingTool\SnippingTool.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.241.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\UtcDecoderHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_04ff63d068f8c626\RtkAudUService64.exe [1961360 2023-11-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\WINDOWS\System32\DriverStore\FileRepository\wavesapo9de.inf_amd64_9cf66a75b9c50ded\WavesSvc64.exe [5542112 2024-03-08] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [MuseHub] => C:\Program Files\MuseHub\current\MuseHub.exe [59699760 2026-01-15] (MuseCY SM Ltd -> MuseHub)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-196143437-2400517662-190078704-1002\...\Run: [org.whispersystems.signal-desktop] => C:\Users\Jose Madeira\AppData\Local\Programs\signal-desktop\Signal.exe [213754288 2026-02-25] (Signal Messenger, LLC -> Signal Messenger, LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\146.0.7680.165\Installer\chrmstp.exe [2026-03-26] (Google LLC -> Google LLC)
Startup: C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk [2026-03-17]
ShortcutTarget: Telegram.lnk -> C:\Users\Jose Madeira\AppData\Roaming\Telegram Desktop\Telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ableton USB Audio Control Panel Autostart.lnk [2025-12-11]
ShortcutTarget: Ableton USB Audio Control Panel Autostart.lnk -> C:\Program Files\Ableton\USB Audio Driver\x64\AbletonAudioCpl.exe (Thesycon Software Solutions GmbH & Co. KG -> )
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {ECA0AB4E-E54E-4804-A96A-B004F16FB6E8} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-196143437-2400517662-190078704-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {2170452D-DCF4-4DB9-ADE5-114C6DED8287} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [1308312 2026-02-27] (Dell Technologies Inc. -> Dell Inc.) -> C:\Program Files\Dell\SupportAssistAgent\bin\AutoUpdate
Task: {1A0A632B-1BAB-4D19-ADFF-5F197AACDE10} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{6BBFD062-BC30-4841-A3F4-E0D77EE0D9CA} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [6517400 2026-03-12] (Google LLC -> Google LLC)
Task: {43D76A25-682E-4F6E-9E32-EE3B2A2D3112} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [6466256 2026-01-16] (Intel Corporation -> Intel Corporation)
Task: {78FBE537-0B95-4261-95BD-5E82B5422479} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [6466256 2026-01-16] (Intel Corporation -> Intel Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {D4867D41-B900-49EC-9726-967D0865C165} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {190FC5EF-3D50-4208-A483-5B8B4B106A8D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D6A1AAB0-8D6C-4D61-941B-A684532F7A70} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CDE98D87-3A36-469B-A7A0-509DC9591E75} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9AA6FEB3-EFD5-4437-854A-7EEEFFEA1426} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-196143437-2400517662-190078704-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {2CC11382-FC30-4A59-8D71-708174423A8B} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-196143437-2400517662-190078704-1003 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {EE263844-040D-4103-ACFF-44BEA51F7FD5} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-196143437-2400517662-190078704-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {DBE9539C-7117-4B64-8BE2-3A1C19CB26D0} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6461560 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {9C428FDC-8851-47E1-A838-93C85E6309FD} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9274080 2026-02-26] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {C48797BD-B567-4358-9FEE-0C6FC1888DA5} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe [454656 2025-11-07] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\-Command "Start-Process -WindowStyle Hidden task.bat"
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 06 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 06 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0ac08c43-85cc-49e2-97c5-8b314b5e5f80}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{d46ca9e9-995c-47a4-94a0-0b34a7790ba2}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default [2026-03-26]
Edge Notifications: Default -> hxxps://www.snapchat.com
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-03-25]
Edge Extension: (Dokumenty Google offline) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-04]
Edge Extension: (Edge relevant text changes) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-12-10]
Edge Profile: C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2026-03-04]
Edge Extension: (Dokumenty Google offline) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-09]
Edge Extension: (Edge relevant text changes) - C:\Users\Jose Madeira\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-12-09]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default [2026-03-26]
CHR Notifications: Default -> hxxps://business.facebook.com; hxxps://webmail.forpsi.com; hxxps://www.facebook.com; hxxps://www.youtube.com
CHR Extension: (Překladač Google) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2025-11-24]
CHR Extension: (Authenticator) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhghoamapcdpbohphigoooaddinpkbai [2025-12-11]
CHR Extension: (Word Online) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2025-11-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-11-24]
CHR Extension: (Hesla na iCloudu) - C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pejdijmoenmkgeppbflobdenhhabjlaj [2025-12-19]
CHR Profile: C:\Users\Jose Madeira\AppData\Local\Google\Chrome\User Data\System Profile [2026-03-20]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm\Bluetooth Suite\adminservice.exe [404384 2022-01-23] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [29465352 2026-03-04] (Gen Digital Inc. -> Gen Digital Inc.)
R2 DCECMISvc; C:\Program Files\Dell\EndpointConfigure\Dell.EndpointConfigure.WinServiceAgent.exe [168216 2025-04-15] (Dell Technologies Inc. -> Dell Inc.)
R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [20240 2025-12-02] (Dell Technologies Inc. -> Dell INC.)
R2 DellAweSvc; C:\Program Files (x86)\Dell\CommandIntelvProOutOfBand\DellAWESvc.exe [73968 2025-04-04] (Dell Technologies Inc. -> Dell Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [49952 2026-02-02] (Dell Technologies Inc. -> )
R2 DellFFDPWmiService; C:\WINDOWS\System32\drivers\DellFFDPWmiService.exe [33368 2022-01-26] ("STMicroelectronics Srl" -> )
R2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [149704 2025-11-30] (Dell Technologies Inc. -> Dell)
R2 DellTrustedDevice; C:\Program Files\Dell\TrustedDevice\Dell.TrustedDevice.Service.exe [154752 2025-11-07] (Dell Technologies Inc. -> Dell)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [133736 2025-08-27] (Intel Corporation -> Intel)
R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [133224 2025-08-27] (Intel Corporation -> Intel)
R2 FastTrackProAudioDevMon; C:\Program Files (x86)\M-Audio\Fast Track Pro\AudioDevMon.exe [1688296 2015-06-10] (Avid Technology, Inc. -> M-Audio)
R2 hostcontrolsvc; C:\WINDOWS\System32\bcmHostControlService.exe [846512 2025-06-16] (Broadcom Inc. -> Broadcom Corporation)
R2 hoststoragesvc; C:\WINDOWS\System32\bcmHostStorageService.exe [209136 2025-10-21] (Broadcom Inc. -> Broadcom Corporation)
R2 IntelAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_581d7e91d349facc\AS\IAS\IntelAudioService.exe [412128 2022-10-27] (Intel Corporation -> Intel)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11420952 2026-03-20] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-01-10] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe [2088128 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MuseAuthService; C:\Program Files\MuseHub\current\MuseAuthService.exe [9957424 2026-01-15] (MuseCY SM Ltd -> Muse Group)
S3 MuseHubUpdaterService; C:\Program Files\MuseHub\current\MuseHub.Updater.exe [8250416 2026-01-15] (MuseCY SM Ltd -> MuseHub.Updater)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [811360 2026-02-24] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [149656 2026-02-27] (Dell Technologies Inc. -> Dell Inc.)
R2 ushupgradesvc; C:\WINDOWS\System32\bcmUshUpgradeService.exe [360752 2025-10-21] (Broadcom Inc. -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe [4451664 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe [290704 2026-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
S3 AppShellElevationService; "C:\Program Files\TikTok LIVE Studio\1.12.0\elevation_service.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 cxwmbclass; C:\WINDOWS\System32\DriverStore\FileRepository\netwmbclass.inf_amd64_7e33f06b13d0c370\cxwmbclass.sys [167936 2026-02-24] (Microsoft Windows -> Microsoft Corporation)
S3 DellBV; C:\WINDOWS\system32\DRIVERS\DellBV.sys [161072 2025-11-07] (Dell Technologies Inc. -> Dell)
S3 DellInstrumentation; C:\WINDOWS\System32\drivers\DellInstrumentation.sys [33336 2025-11-20] (Microsoft Windows Hardware Compatibility Publisher -> Dell)
S3 DPMDriver; C:\WINDOWS\System32\drivers\DPMDriver.sys [142272 2024-10-30] (IndiLogic LLC -> Dell Inc.)
R1 dtdsel; C:\WINDOWS\System32\DRIVERS\dtdsel.sys [139576 2025-11-07] (Dell Technologies Inc. -> Dell)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_0a58c9ba33b1dc0f\e1d.sys [625368 2025-09-01] (Intel Corporation -> Intel Corporation)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82352 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 MAUSBFASTTRACKPRO; C:\WINDOWS\System32\drivers\MAudioFastTrackPro.sys [184552 2015-06-10] (Avid Technology, Inc. -> M-Audio)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234600 2026-03-25] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [245864 2026-03-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MoisesVAD; C:\WINDOWS\System32\DriverStore\FileRepository\moisesvad.inf_amd64_69572c0db43b9e35\MoisesVAD.sys [80872 2026-02-02] (Moises Systems, Inc. -> Windows (R) Win 7 DDK provider)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [32352 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
S3 RtkUsbAD_2370; C:\WINDOWS\System32\DriverStore\FileRepository\rtdusbad_dell.inf_amd64_fcf8a1ae51151778\RtUsbA64.sys [504168 2023-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 RtkUsbAD_2422; C:\WINDOWS\System32\DriverStore\FileRepository\rtdusbad_dell.inf_amd64_07ee7a18aaea6155\RtUsbA64.sys [524288 2025-08-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 rtu53cx22x64; C:\WINDOWS\System32\DriverStore\FileRepository\rtu53cx22x64sta.inf_amd64_96b55918d02d83c6\rtu53cx22x64.sys [1168896 2025-12-03] (Realtek Semiconductor Corp. -> Realtek Corporation)
S3 rtucx21x64; C:\WINDOWS\System32\DriverStore\FileRepository\rtucx21x64.inf_amd64_286645bc82b2f9fb\rtucx21x64.sys [1359360 2024-04-01] (Microsoft Windows -> Realtek Corporation)
R3 UDE; C:\WINDOWS\System32\drivers\UDE.sys [337384 2021-09-27] (Fibocom Wireless Inc. -> Intel Corporation)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [File not signed]
S3 UsbNcm; C:\WINDOWS\System32\DriverStore\FileRepository\usbncm.inf_amd64_989230fcb4a5468f\UsbNcm.sys [208896 2026-02-24] (Microsoft Windows -> )
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21888 2026-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [641416 2026-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [103816 2026-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WiManH; C:\WINDOWS\System32\DriverStore\FileRepository\wiman.inf_amd64_1d81bc4f31bf65c7\WiManH\WiManH.sys [184224 2025-10-28] (Intel Corporation -> Intel Corporation)
S3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-03-26 15:41 - 2026-03-26 15:43 - 000030444 _____ C:\Users\Jose Madeira\Downloads\FRST.txt
2026-03-26 15:41 - 2026-03-26 15:42 - 000000000 ____D C:\FRST
2026-03-26 15:40 - 2026-03-26 15:40 - 002445824 _____ (Farbar) C:\Users\Jose Madeira\Downloads\FRST64.exe
2026-03-26 14:12 - 2026-03-26 14:12 - 006416248 _____ C:\Users\Jose Madeira\Downloads\IMG_3A56896E-1DAA-4365-BC77-BB9767BDCCF9.JPEG
2026-03-26 14:11 - 2026-03-26 14:11 - 000105699 _____ C:\Users\Jose Madeira\Downloads\71987a73-dc0a-4c41-a338-a45519ebec4e.JPEG
2026-03-26 14:09 - 2026-03-26 14:09 - 002930270 _____ C:\Users\Jose Madeira\Downloads\IMG_4FB31948-405D-4F8C-A467-30FA29FDCD0A.JPEG
2026-03-26 13:55 - 2026-03-26 13:55 - 000089263 _____ C:\Users\Jose Madeira\OneDrive\Plocha\WhatsApp Image 2026-03-26 at 02.25.46.jpeg
2026-03-26 13:55 - 2026-03-26 13:55 - 000066589 _____ C:\Users\Jose Madeira\OneDrive\Plocha\WhatsApp Image 2026-03-26 at 02.27.56.jpeg
2026-03-26 13:33 - 2026-03-26 13:33 - 000002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-03-26 13:33 - 2026-03-26 13:33 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2026-03-26 13:32 - 2026-03-26 13:32 - 011487160 _____ (Google LLC) C:\Users\Jose Madeira\Downloads\ChromeSetup.exe
2026-03-26 11:40 - 2026-03-26 11:40 - 000679834 _____ C:\WINDOWS\system32\perfh005.dat
2026-03-26 11:40 - 2026-03-26 11:40 - 000145634 _____ C:\WINDOWS\system32\perfc005.dat
2026-03-25 21:57 - 2026-03-25 21:57 - 000000000 ____D C:\Program Files\Google
2026-03-25 18:27 - 2026-03-26 11:52 - 000000000 ____D C:\ProgramData\RogueKiller
2026-03-25 18:12 - 2026-03-25 18:12 - 000000000 ____D C:\AdwCleaner
2026-03-24 10:29 - 2026-03-26 13:33 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-03-21 01:33 - 2026-03-21 01:33 - 000000765 _____ C:\Users\Jose Madeira\OneDrive\Plocha\rekordbox 7.lnk
2026-03-20 20:49 - 2026-03-20 20:49 - 000000000 ____D C:\Users\Jose Madeira\Downloads\Telegram Desktop
2026-03-17 17:10 - 2026-03-17 20:01 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\tor
2026-03-17 08:13 - 2026-03-26 12:42 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\FOTKY NA SC
2026-03-17 05:12 - 2026-03-17 05:12 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\AdvinstAnalytics
2026-03-17 05:11 - 2026-03-17 05:11 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Opera Software
2026-03-13 18:09 - 2026-03-26 12:44 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\MUJ TRACK
2026-03-13 02:02 - 2026-03-13 02:02 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Xfer
2026-03-13 01:59 - 2026-03-13 01:59 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Xfer
2026-03-13 01:58 - 2026-03-13 01:58 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Documents\Xfer
2026-03-10 07:04 - 2026-03-10 07:07 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Moises
2026-03-10 07:04 - 2026-03-10 07:04 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\moises-desktop-updater
2026-03-10 06:41 - 2026-03-10 19:39 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Moises Live
2026-03-10 06:41 - 2026-03-10 06:41 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\moises-live-windows-updater
2026-03-06 20:44 - 2026-03-06 20:44 - 005255624 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\Netwtw10.sys
2026-03-06 20:44 - 2026-03-06 20:44 - 001627080 _____ (Intel Corporation) C:\WINDOWS\system32\IntelIHVRouter10.dll
2026-03-05 12:58 - 2026-03-05 12:58 - 000001133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton Live 12 Suite.lnk
2026-03-05 12:58 - 2026-03-05 12:58 - 000000410 __RSH C:\ProgramData\ntuser.pol
2026-03-05 12:37 - 2026-03-05 12:37 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-03-04 20:19 - 2026-03-11 07:02 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Avast Software
2026-03-04 20:14 - 2026-03-04 20:14 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\CEF
2026-03-04 20:12 - 2026-03-11 07:31 - 000000000 ____D C:\ProgramData\Avast Software
2026-03-04 20:12 - 2026-03-10 19:23 - 000002398 _____ C:\WINDOWS\system32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-196143437-2400517662-190078704-1002
2026-03-04 20:12 - 2026-03-04 20:12 - 000056128 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2026-03-04 20:12 - 2026-03-04 20:12 - 000002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 7.lnk
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\WINDOWS\system32\Tasks\Piriform
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\CCleaner
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\ProgramData\Piriform
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\Program Files\Piriform
2026-03-04 20:12 - 2026-03-04 20:12 - 000000000 ____D C:\Program Files\Common Files\Piriform
2026-03-03 12:14 - 2026-03-10 19:23 - 000002608 _____ C:\WINDOWS\system32\Tasks\USER_ESRV_SVC_QUEENCREEK
2026-03-03 12:14 - 2026-01-27 11:24 - 000049872 _____ (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\semav6msr64.sys
2026-02-26 10:30 - 2026-02-26 10:30 - 000000000 ____D C:\Users\Jose Madeira\0
2026-02-24 19:43 - 2026-02-24 19:43 - 000083946 _____ C:\WINDOWS\SysWOW64\ctac.json
2026-02-24 19:43 - 2026-02-24 19:43 - 000083946 _____ C:\WINDOWS\system32\ctac.json
2026-02-24 19:43 - 2026-02-24 19:43 - 000036382 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-02-24 19:43 - 2026-02-24 19:43 - 000036382 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-03-26 15:44 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-03-26 15:43 - 2026-01-10 08:54 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Malwarebytes
2026-03-26 15:40 - 2025-11-07 08:05 - 000000000 ____D C:\Program Files (x86)\Dell
2026-03-26 14:33 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-03-26 13:34 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-03-26 13:33 - 2025-11-24 09:34 - 000000000 ____D C:\Program Files (x86)\Google
2026-03-26 13:31 - 2026-02-18 02:12 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Telegram Desktop
2026-03-26 12:44 - 2026-02-23 22:37 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\HLAS BEZ TVÁŘE - PROJEKT
2026-03-26 12:43 - 2026-01-06 13:16 - 000000000 ___RD C:\Users\Jose Madeira\OneDrive\Plocha\HUDBA
2026-03-26 12:12 - 2025-11-07 07:56 - 000000000 ___DC C:\WINDOWS\Panther
2026-03-26 12:08 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ServiceState
2026-03-26 12:06 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-03-26 11:40 - 2025-11-07 08:07 - 001603854 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-03-26 11:40 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF
2026-03-26 11:39 - 2025-11-07 07:58 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-03-26 11:35 - 2025-12-10 13:57 - 000000000 ___RD C:\Users\Jose Madeira\iCloudDrive
2026-03-26 11:35 - 2025-12-10 04:34 - 000000000 ___RD C:\Users\Jose Madeira\iCloudPhotos
2026-03-26 11:33 - 2025-11-14 10:57 - 000000000 __SHD C:\Users\Jose Madeira\IntelGraphicsProfiles
2026-03-26 11:33 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\Registration
2026-03-26 11:32 - 2025-12-11 02:44 - 000000000 ____D C:\ProgramData\boost_interprocess
2026-03-26 11:32 - 2025-11-07 08:09 - 000000000 ____D C:\Intel
2026-03-26 11:32 - 2025-11-07 08:07 - 000450668 _____ C:\WINDOWS\system32\CVFirmwareUpgradeLog.txt
2026-03-26 11:32 - 2025-11-07 08:04 - 000020878 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-03-26 11:32 - 2025-11-07 07:58 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-03-26 11:32 - 2025-11-07 07:57 - 000012288 ___SH C:\DumpStack.log.tmp
2026-03-26 11:32 - 2024-04-01 08:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-03-26 09:59 - 2025-11-24 19:23 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH
2026-03-26 09:56 - 2025-11-07 07:57 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2026-03-26 08:05 - 2025-11-07 07:57 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-03-26 08:04 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\D3DSCache
2026-03-25 21:46 - 2026-01-15 19:49 - 000000000 ____D C:\WINDOWS\Minidump
2026-03-25 21:46 - 2026-01-11 07:08 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\CrashDumps
2026-03-25 21:18 - 2025-11-07 07:58 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-03-25 21:06 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira
2026-03-25 18:15 - 2025-11-24 07:55 - 000000000 ____D C:\Users\WsiAccount
2026-03-25 18:03 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Packages
2026-03-25 17:53 - 2025-11-07 08:48 - 000000000 ____D C:\Program Files (x86)\Intel
2026-03-25 17:46 - 2025-11-07 08:42 - 000000000 ____D C:\ProgramData\Package Cache
2026-03-25 17:46 - 2025-11-07 08:42 - 000000000 ____D C:\Program Files\Intel
2026-03-25 11:43 - 2025-11-24 07:07 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Comms
2026-03-22 11:51 - 2024-04-01 08:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2026-03-22 11:51 - 2024-04-01 08:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2026-03-21 21:20 - 2025-12-10 05:25 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\audacity
2026-03-21 03:07 - 2025-11-24 06:58 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\rekordboxAgent
2026-03-21 01:35 - 2025-11-25 05:26 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\rekordbox
2026-03-21 01:35 - 2025-11-24 06:58 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\PioneerLog
2026-03-21 01:35 - 2025-11-24 06:52 - 000000000 ____D C:\Program Files\rekordbox
2026-03-19 23:45 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2026-03-17 17:28 - 2020-08-13 06:00 - 000056520 _____ (Microsoft Corporation) C:\WINDOWS\cryptdll.dll
2026-03-17 17:28 - 2019-12-09 10:06 - 000001368 _____ C:\WINDOWS\system32\README.txt
2026-03-17 17:08 - 2025-11-14 10:57 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows
2026-03-17 16:53 - 2025-11-25 04:01 - 000003030 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132
2026-03-17 16:53 - 2025-11-25 04:01 - 000002664 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon
2026-03-17 15:54 - 2025-12-10 05:01 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\APPKY
2026-03-17 15:09 - 2026-01-26 06:06 - 000002611 _____ C:\Users\Jose Madeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Signal.lnk
2026-03-17 14:45 - 2025-11-07 08:00 - 000000000 ____D C:\ProgramData\Packages
2026-03-17 05:01 - 2025-12-31 19:01 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\honza fa
2026-03-15 18:23 - 2026-01-10 08:54 - 000002053 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-03-15 18:22 - 2026-01-10 08:53 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-03-15 18:22 - 2026-01-10 08:53 - 000000000 ____D C:\Program Files\Malwarebytes
2026-03-13 01:58 - 2025-12-11 02:47 - 000000000 ____D C:\Program Files\Common Files\VST3
2026-03-11 13:57 - 2025-12-11 08:19 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Documents\Audacity
2026-03-11 12:18 - 2026-01-10 09:38 - 000003942 _____ C:\WINDOWS\system32\Tasks\Dell SupportAssistAgent AutoUpdate
2026-03-11 12:18 - 2025-11-07 08:04 - 000000000 ____D C:\ProgramData\Dell
2026-03-11 06:54 - 2025-12-20 19:48 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Bytedance
2026-03-11 03:56 - 2024-04-01 17:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-03-11 03:56 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-03-11 03:45 - 2025-11-07 08:02 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-03-10 23:41 - 2025-11-25 04:01 - 000000000 ____D C:\Program Files\dotnet
2026-03-10 23:40 - 2025-11-25 04:00 - 000000000 ____D C:\Program Files (x86)\dotnet
2026-03-10 19:23 - 2025-11-07 07:58 - 000003642 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{6753DEC1-A261-4A01-94F7-175AF372A4FF}
2026-03-10 19:23 - 2025-11-07 07:58 - 000003416 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{8A9FE38D-73D2-48B8-AEC7-62EF82D81B0D}
2026-03-10 16:28 - 2025-12-11 08:47 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Documents\Max 9
2026-03-10 13:13 - 2026-02-17 15:19 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\ABLETON - PROJEKTY
2026-03-08 17:46 - 2025-11-24 14:26 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\CapCut
2026-03-08 17:40 - 2025-12-10 03:50 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000000-000000.txt
2026-03-05 13:02 - 2025-12-11 08:46 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Ableton
2026-03-04 21:27 - 2026-02-01 22:38 - 000000000 ____D C:\Users\Jose Madeira\OneDrive\Plocha\veci na AKAI & ABLETON
2026-03-04 20:29 - 2026-01-26 06:06 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Signal
2026-03-04 20:29 - 2025-12-11 02:44 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\Muse Hub
2026-03-04 20:21 - 2026-01-10 08:54 - 000245864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2026-03-04 20:13 - 2024-04-01 08:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-03-03 19:21 - 2025-12-11 02:44 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\MuseSampler
2026-02-28 10:43 - 2026-01-14 12:36 - 000000000 ____D C:\Users\Jose Madeira\AppData\Local\VirtualDJ
2026-02-28 10:43 - 2026-01-14 12:36 - 000000000 ____D C:\Program Files\VirtualDJ
2026-02-26 10:44 - 2025-11-24 10:26 - 000000000 ____D C:\Users\Jose Madeira\AppData\Roaming\Microsoft\MMC
2026-02-25 17:12 - 2026-01-10 10:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\UUS
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-02-24 20:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-02-24 20:41 - 2024-04-01 17:31 - 000000000 ____D C:\WINDOWS\InboxApps
2026-02-24 20:41 - 2024-04-01 17:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-02-24 20:41 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\appcompat
2026-02-24 20:41 - 2024-04-01 08:21 - 000000000 ____D C:\WINDOWS\servicing
==================== Files in the root of some directories ========
2024-02-22 12:40 - 2024-02-22 12:40 - 000181440 _____ (Dell Inc.) C:\Users\Jose Madeira\DellInstaller_x64.exe
2025-12-11 02:47 - 2025-12-11 02:47 - 000450785 _____ () C:\Program Files\Common Files\Place_it_Uninstall.exe
2025-12-11 02:48 - 2025-12-11 02:48 - 000060131 _____ () C:\Program Files\Common Files\Shape_it_Uninstall.exe
2026-01-17 19:07 - 2026-01-17 19:07 - 000000017 _____ () C:\Users\Jose Madeira\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================