Prosím o kontrolu. Děkuji
Napsal: 11 kvě 2026 16:51
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-04-2026
Ran by Jiri (administrator) on HOME (MSI MS-7817) (11-05-2026 17:41:50)
Running from C:\download\FRST64.exe
Loaded Profiles: Jiri
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\KEMailKb.EXE
(explorer.exe ->) () [File not signed] C:\Program Files (x86)\Capture\HoverSnap.exe
(explorer.exe ->) () [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(explorer.exe ->) (AVerMedia TECHNOLOGIES, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <24>
(explorer.exe ->) (hxxp://www.SteveMiller.net) [File not signed] C:\Program Files (x86)\PureText\PureText.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(explorer.exe ->) (OpenVPN Technologies, Inc. -> ) C:\Program Files\OpenVPN\bin\openvpn-gui.exe
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (VIA Technologies, Inc.) [File not signed] C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe
(Hagel Technologies) [File not signed] C:\Program Files (x86)\DU Meter\DUMeter.exe
(Intel Corporation - pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (AVerMedia TECHNOLOGIES, Inc.) [File not signed] C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe
(services.exe ->) (AVerMedia) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
(services.exe ->) (Intel CASE -> ) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (OpenVPN Technologies, Inc. -> The OpenVPN Project) C:\Program Files\OpenVPN\bin\openvpnserv.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (Wondershare Technology Group Co.,Ltd -> wondershare) C:\ProgramData\wondershare\wsServices\WsidService.exe
(services.exe ->) (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe
(services.exe ->) (北京海誉动想科技股份有限公司 -> ) C:\Program Files (x86)\Droid4X\Droid4XService.exe
(taskeng.exe ->) (Speed-Bit LTD -> Speedbit Ltd.) C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.) [File not signed]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7659736 2014-11-26] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-06-27] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [DU Meter] => C:\Program Files (x86)\DU Meter\DUMeter.exe [1469952 2005-02-01] (Hagel Technologies) [File not signed]
HKLM-x32\...\Run: [KEMailKb] => C:\Program Files (x86)\KEMailKb\KEMailKb.EXE [401667 2004-07-26] (Dritek System Inc.) [File not signed]
HKLM-x32\...\Run: [WheelMouse] => C:\Program Files (x86)\A4Tech\Mouse\Amoumain.exe [159744 2005-09-21] (A4Tech Co.,Ltd.) [File not signed]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [748624 2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [DU Meter] => C:\Program Files (x86)\DU Meter\DUMeter.exe [1469952 2005-02-01] (Hagel Technologies) [File not signed]
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [PureText] => C:\Program Files (x86)\PureText\PureText.exe [33792 2013-01-04] (hxxp://www.SteveMiller.net) [File not signed]
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [638592 2017-07-14] (OpenVPN Technologies, Inc. -> )
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [com.squirrel.WhatsApp.WhatsApp] => C:\Users\Jiri\AppData\Local\WhatsApp\Update.exe [2412768 2023-06-15] (WhatsApp LLC -> )
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\MountPoints2: {1e1f76b3-4c7f-11ee-81ea-448a5bcb771c} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\MountPoints2: {a07e04a8-4528-11e6-a432-448a5bcb771c} - G:\CallSetup.exe
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\MountPoints2: {ef68f20e-c508-11e4-a73c-448a5bcb771c} - E:\CallSetup.exe
HKLM\...\Windows x64\Print Processors\HP1020PrintProc: C:\Windows\System32\spool\prtprocs\x64\pphp1020.dll [65024 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Windows x64\Print Processors\LMUD1O4C: C:\Windows\System32\spool\prtprocs\x64\LMUD1O4C.DLL [283152 2016-10-17] (Microsoft Windows Hardware Compatibility Publisher -> Lexmark International Inc.)
HKLM\...\Windows x64\Print Processors\MIMFPR_Y: C:\Windows\System32\spool\prtprocs\x64\MIMFPR_Y.DLL [56320 2006-03-09] (Microsoft Windows Hardware Compatibility Publisher -> KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
HKLM\...\Print\Monitors\HPLJ1020LM: C:\Windows\system32\zlhp1020.dll [192512 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\MLMON__Y: C:\Windows\system32\MLMON__Y.DLL [144384 2006-03-09] (Microsoft Windows Hardware Compatibility Publisher -> KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
HKLM\...\Print\Monitors\pdfcmon: C:\Windows\system32\pdfcmon.dll [116224 2017-06-21] (pdfforge GmbH) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [OpenVPN_UserSetup] -> reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /t REG_SZ /d "C:\Program Files\OpenVPN\bin\openvpn-gui.exe" /f
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.120\Installer\chrmstp.exe [4956952 2023-01-27] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google Chrome.lnk [2015-03-09]
ShortcutTarget: Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
Startup: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HoverSnap – zástupce.lnk [2015-03-09]
ShortcutTarget: HoverSnap – zástupce.lnk -> C:\Program Files (x86)\Capture\HoverSnap.exe () [File not signed]
Startup: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TOTALCMD64.lnk [2015-03-07]
ShortcutTarget: TOTALCMD64.lnk -> C:\Program Files\totalcmd\TOTALCMD64.EXE (Ghisler Software GmbH -> Ghisler Software GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVer HID Receiver.lnk [2019-07-18]
ShortcutTarget: AVer HID Receiver.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe () [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVerQuick.lnk [2019-07-18]
ShortcutTarget: AVerQuick.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\KDE Connect.lnk [2023-05-23]
ShortcutTarget: KDE Connect.lnk -> C:\Program Files\KDE Connect\bin\kdeconnect-indicator.exe (K Desktop Environment e.V. -> )
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {B12C58C2-AEEF-41E2-B38B-7617A133354E} - System32\Tasks\{0A4B1322-A08A-4CC4-B8DF-5D362026AA1C} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\Jiri\AppData\Local\Temp\jre-8u381-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
Task: {B59530A6-3312-4585-9D90-1380DF987F58} - System32\Tasks\{2B2FBF63-1173-49F7-B056-41C1497A5C02} => F:\Opera_PortableSetup.exe (No File)
Task: {91B27F21-055D-4136-9F23-EAEE657A34A9} - System32\Tasks\{6FB5E648-6FB3-44BC-AB04-CB7DC4B72CB2} => F:\Opera_PortableSetup.exe (No File)
Task: {F9BD04AA-1C44-4664-9D39-9E96B74230FC} - System32\Tasks\{81488D6F-1EA5-4A77-8AB5-B4DF4B4DE94E} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\Jiri\AppData\Local\Temp\jre-8u371-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
Task: {476085AF-A1AE-438C-88CC-1024305B4215} - System32\Tasks\{885BADA0-4B2B-4EBC-9482-8E4B04FBF8ED} => c:\program files (x86)\google\chrome\application\chrome.exe [3151128 2023-01-23] (Google LLC -> Google LLC) -> hxxp://ui.skype.com/ui/0/7.10.64.101/cs/abandoninstall?page=tsPlugin
Task: {FCADA655-D08E-41CF-9514-91ABBAAAB741} - System32\Tasks\{99F5C876-B9AF-4034-A921-C0BEDA35F132} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\aa\A4 Tech - myš\Setup.exe" -d "c:\aa\A4 Tech - myš\"
Task: {FC092BF6-42CE-4FF3-B08F-08BA9EE40455} - System32\Tasks\{F4741BFD-31C8-4AF7-B980-54329950A649} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a C:\download\OperaSetup.exe -d C:\download
Task: {C9C4B352-B6A9-4560-A341-7876C96550BC} - System32\Tasks\{F8CA36F3-DA22-4D02-AFE3-0F212024B5A1} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\aa\email kb driver\Setup.exe" -d "c:\aa\email kb driver\"
Task: {2F820978-A16E-487E-853C-733808B8996F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {79AE72AA-1734-4B37-8A17-9061213F0C6B} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\download\esetonlinescanner.exe LOGON (No File)
Task: {EE83280C-AD75-418C-88F4-EF427E536470} - System32\Tasks\EOSv3 Scheduler onTime => C:\download\esetonlinescanner.exe SCHED (No File)
Task: {1BAE5261-BA52-4107-A480-E025C783B4F0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
Task: {B8A922D7-122C-4044-91C9-BB1BEAF0C807} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
Task: {8E02EDAB-768F-4984-92FC-9C5C9F47DAF0} - System32\Tasks\Opera scheduled Autoupdate 1663184996 => C:\Users\Jiri\AppData\Local\Programs\Opera\launcher.exe [42724048 2021-09-13] (Opera Software AS -> Opera Software)
Task: {41FC091F-B865-4F14-AE90-46F1A41F80E5} - System32\Tasks\SBWUpdateTask_Logon_4e925d94-00FF542154E9 => C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe [92320 2012-02-08] (Speed-Bit LTD -> Speedbit Ltd.) <==== ATTENTION
Task: {870D3EDD-D2B8-4083-B448-A48DF79B44E1} - System32\Tasks\SBWUpdateTask_Time_4e925d94-00FF542154E9 => C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe [92320 2012-02-08] (Speed-Bit LTD -> Speedbit Ltd.) <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-2007933777-2661868901-2044359937-1000] => 45.77.103.193:3128
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 81.200.55.222 81.200.55.223
Tcpip\..\Interfaces\{0E1C7303-F805-4545-AFA2-66B7D70D2B2B}: [NameServer] 1.1.1.1,1.0.0.1
Tcpip\..\Interfaces\{0E1C7303-F805-4545-AFA2-66B7D70D2B2B}: [DhcpNameServer] 81.200.55.222 81.200.55.223
Tcpip\..\Interfaces\{0E1C7303-F805-4545-AFA2-66B7D70D2B2B}: [DhcpDomain] nej.cz
FireFox:
========
FF DefaultProfile: qkw5swb8.default-1630436187493 -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493 [2026-05-09]
FF Homepage: Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493 -> hxxp://search.speedbit.com/?aff=dap10_vlc
FF Notifications: Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493 -> hxxps://web.whatsapp.com
FF Extension: (Hoxx VPN Proxy) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\@hoxx-vpn.xpi [2025-06-20]
FF Extension: (Český slovník pro kontrolu pravopisu) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\cs@dictionaries.addons.mozilla.org.xpi [2024-12-28]
FF Extension: (Language: Čeština (Czech)) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\langpack-cs@firefox.mozilla.org.xpi [2024-12-28]
FF Extension: (uBlock Origin) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\uBlock0@raymondhill.net.xpi [2026-03-22]
FF Extension: (Video DownloadHelper) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2025-07-01]
FF SearchPlugin: C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\searchplugins\speedbit.xml [2022-04-16]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1218158.dll [2015-05-07] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-11-10] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-11-10] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.391.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.391.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-03-17] (VideoLAN) [File not signed]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Jiri\AppData\Local\Microsoft\Edge\User Data\Default [2026-04-29]
Edge Notifications: Default -> hxxps://web.whatsapp.com
Edge HomePage: Default -> hxxps://email.seznam.cz/
Edge StartupUrls: Default -> "hxxps://email.seznam.cz/","hxxps://www.bazos.cz/hodnoceni.php?idmail=69740 ... 3&jmeno=EL"
Edge Extension: (Translator) - C:\Users\Jiri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cdkmohnpfdennnemmjekmmiibgfddako [2024-10-21]
Edge Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Jiri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2026-04-08]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default [2026-05-11]
CHR DownloadDir: C:\download
CHR Notifications: Default -> hxxps://app.zoom.us; hxxps://messages.google.com; hxxps://teams.microsoft.com; hxxps://web.whatsapp.com; hxxps://www.edarling.cz; hxxps://www.facebook.com; hxxps://www.lidl.cz; hxxps://www.slevomat.cz
CHR HomePage: Default -> hxxps://email.seznam.cz/www.benefity-veterani.cz
CHR StartupUrls: Default -> "hxxps://email.seznam.cz/#inbox/564674","hxxps://tvprogram.idnes.cz/?k=1&k=2&k=3&k=4&k=78&k=92&k=89&k=226&k=302&k=330&k=332&k=331&k=24&k=18&k=19&k=94&k=95"
CHR Extension: (Překladač Google) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-25]
CHR Extension: (Right Click Enable - Pravým tlačítkem povolit) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegpaehcnpbhdmnghlnbnngogbfelnno [2026-03-12]
CHR Extension: (Data Compression Proxy) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajfiodhbiellfpcjjedhmmmpeeaebmep [2017-08-08]
CHR Extension: (Browser Boost - Extra Nástroje) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\akknpgblpchaoebdoiojonnahhnfgnem [2025-02-27]
CHR Extension: (IP Address & My IP Address Geo-Location) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\allbgfamnneoaccefakgmikbjlhndkff [2018-02-10]
CHR Extension: (SPOI Options (Please remove me)) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn [2015-03-07]
CHR Extension: (JavaScript Toggle On and Off) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdcgbgnfhhdmdkallfmlachogpghifgf [2026-02-03]
CHR Extension: (Pricecut) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\cefdmiohfoihglgojcjlgfefkbphoaoj [2015-03-07]
CHR Extension: (OneTab) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2026-03-23]
CHR Extension: (Aliexpress SuperStar česky, Historie cen) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciclollkolafellcaolgccmfjldgpolo [2025-10-24]
CHR Extension: (uBlock Origin) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2026-03-12]
CHR Extension: (Video Viewer) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\dejgnnjohnpljeijfendiiafgpaenbip [2015-03-07]
CHR Extension: (HTML5 video for YouTube™) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\dolajcekhnohkpncmhgledbmndjpblei [2015-03-07]
CHR Extension: (Proxy SwitchySharp) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpplabbmogkhghncfbfdeeokoefdjegm [2020-03-15]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-08]
CHR Extension: (Youtube-to-MP3 GOLD) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejcmlonfegmnhinnopgjhibfghbgpeoc [2015-03-28]
CHR Extension: (Video Downloader Professional) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2026-03-13]
CHR Extension: (YoWindow Počasí Zdarma) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef [2017-03-15]
CHR Extension: (MonkeyECHO - GearBest Price Tracker) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmdnnfdofijijgcbhdbnlohaabnmdkb [2020-06-03]
CHR Extension: (I don't care about cookies) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2024-06-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-24]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-04-11]
CHR Extension: (Hola VPN - Your Website Unblocker) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2026-05-07]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2024-11-23]
CHR Extension: (Read Aloud: A Text to Speech Voice Reader) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdhinadidafjejdhmfkjgnolgimiaplp [2025-12-13]
CHR Extension: (Video Downloader Plus) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkdmdpdhfaamhgaojpelccmeehpfljgf [2026-04-22]
CHR Extension: (Perplexity - AI Companion) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlgbcneanomplepojfcnclggenpcoldo [2023-10-20]
CHR Extension: (Windscribe - Free Proxy and Ad Blocker) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpcagpplmpfojmgmnngilcnanddlhb [2024-12-10]
CHR Extension: (Bardeen: Automate Browser Apps with AI) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihhkmalpkhkoedlmcnilbbhhbhnicjga [2026-03-25]
CHR Extension: (Distill Web Monitor) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\inlikjemeeknofckkjolnjbpehgadgge [2024-05-15]
CHR Extension: (Unpaywall) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplffkdpngmdjhlpjmppncnlhomiipha [2025-01-09]
CHR Extension: (Extensity) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjmflmamggggndanpgfnpelongoepncg [2024-09-02]
CHR Extension: (Price.com: Cash Back, Coupons & Price Comparison) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmmpkhpajpecmpdmmbpjmkmcmfdahkcj [2026-04-15]
CHR Extension: (BugMeNot Lite) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lackfehpdclhclidcbbfcemcpolgdgnb [2015-03-07]
CHR Extension: (Reader Mode) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\llimhhconnjiflfimocjggfjdlmlhblm [2025-11-30]
CHR Extension: (Rozšíření Google Keep pro Chrome) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2026-05-05]
CHR Extension: (BLACKBOX.AI) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcgbeeipkmelnpldkobichboakdfaeon [2025-05-21]
CHR Extension: (Reload All Tabs) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\midkcinmplflbiflboepnahkboeonkam [2026-04-26]
CHR Extension: (Pocket) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2017-07-15]
CHR Extension: (Hodiny) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjocghlclkpgheifflemilcnblodjohg [2015-03-07]
CHR Extension: (YouTube Překladač & Dabing Videa) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndbhldoclidahhoogmgklimmomnnepjg [2026-01-23]
CHR Extension: (GearBest Coupons) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhhofjfofhkgeofpjkemonejjflnjnid [2019-04-23]
CHR Extension: (Save to Pocket) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2023-06-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
CHR Extension: (GearBest Star, Price history, coupons ) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\obahoaepjklfhghnafdcganehbokgffh [2020-10-01]
CHR Extension: (Readlang Web Reader) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\odpdkefpnfejbfnmdilmfhephfffmfoh [2026-04-16]
CHR Extension: (Povolit kliknutí pravým tlačítkem pro Google Chrome ™) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofgdcdohlhjfdhbnfkikfeakhpojhpgm [2024-04-15]
CHR Extension: (hide.me Proxy) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjocgmpmlfahafbipehkhbaacoemojp [2026-03-28]
CHR Extension: (PrintFriendly: Print Clean Pages, Save as PDF & Screenshot, AI Tools) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2026-04-26]
CHR Extension: (rádio) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\plaapjbgohfgkalmmjpakodbpomahebn [2017-01-20]
CHR Extension: (Hlídač Shopů) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlonggbfebcjelncogcnclagkmkikk [2025-02-07]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
Opera:
=======
OPR Profile: C:\Users\Jiri\AppData\Roaming\Opera Software\Opera Stable [2025-08-15]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=o ... utEncoding}
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [360448 2011-08-19] (AVerMedia) [File not signed]
R2 AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [403456 2011-04-01] () [File not signed]
R2 AVerUpdateServer; C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe [167936 2011-10-31] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 DFWSIDService; C:\ProgramData\Wondershare\wsServices\WsidService.exe [4231408 2023-05-29] (Wondershare Technology Group Co.,Ltd -> wondershare)
R2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [285616 2017-08-14] (北京海誉动想科技股份有限公司 -> )
S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
R2 HFGService; C:\Windows\System32\HFGService.dll [535552 2009-12-21] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-08-25] (Intel CASE -> )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv2.exe [15872 2016-11-25] () [File not signed]
R2 OpenVPNServiceInteractive; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72832 2017-07-14] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 OpenVPNServiceLegacy; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72832 2017-07-14] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13172752 2020-01-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe [388608 2016-01-28] (Wondershare) [File not signed]
S2 ElevationService; C:\ProgramData\Wondershare\wsServices\ElevationService.exe (No File)
S2 WirelessBackupService; C:\Program Files (x86)\Wondershare\drfone\Addins\Recovery\WirelessBackupService.exe (No File)
S2 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe (No File)
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe" (No File)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [312064 2009-12-04] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
S3 BthAudioHF; C:\Windows\System32\DRIVERS\BthAudioHF.sys [52224 2009-12-21] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [29184 2009-08-13] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [22568 2016-09-10] (IVT CORPORATION -> IVT Corporation.)
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csr_a2dp; C:\Windows\System32\drivers\bthav.sys [78848 2009-12-21] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 diagswitchdrv; C:\Windows\System32\DRIVERS\diagswitchdrv.sys [117888 2014-08-16] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 DKbFltr; C:\Windows\SysWOW64\Drivers\DKbFltr.sys [17071 2004-07-26] (Dritek System Inc.) [File not signed]
R3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [31576 2020-04-24] (DEV47 APPS -> Dev47Apps)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [19200 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 HWHandSetProLine; C:\Windows\System32\DRIVERS\hw_quusbmdm.sys [226560 2016-04-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hw_ctrlfakedev; C:\Windows\System32\DRIVERS\hw_ctrlfakedev.sys [115712 2015-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-22] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 IvtAudioBusSrv; C:\Windows\System32\Drivers\IvtBtBus.sys [27256 2016-09-10] (IVT CORPORATION -> IVT Corporation.)
S3 IvtPanBusSrv; C:\Windows\System32\Drivers\btnetBus.sys [31480 2016-09-10] (IVT CORPORATION -> IVT Corporation.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation -> Microsoft Corporation)
S3 MpKsl46be9343; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FF811A98-E18D-4A0E-9092-59314F5CF33F}\MpKslDrv.sys [51632 2025-09-30] (Microsoft Windows -> Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation -> Microsoft Corporation)
S3 nmwcd; C:\Windows\System32\drivers\ccdcmbx64.sys [19968 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\Windows\System32\drivers\ccdcmbox64.sys [27136 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 qcusbser; C:\Windows\System32\DRIVERS\qu_usb_serial.sys [245248 2015-07-08] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [168968 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [9216 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys [9216 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [159936 2016-08-16] (NGO -> MBB)
S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys (No File)
S3 BT; system32\DRIVERS\btnetdrv.sys (No File)
S3 BTCOM; system32\DRIVERS\btcomport.sys (No File)
S3 Btcsrusb; System32\Drivers\btcusb.sys (No File)
S3 csravrcp; system32\DRIVERS\csravrcp.sys (No File)
S3 CsrBtPort; system32\DRIVERS\CsrBtPort.sys (No File)
S3 csrhfgcc; system32\DRIVERS\csrhfgcc.sys (No File)
S3 csrpan; system32\DRIVERS\csrpan.sys (No File)
S3 csrserial; system32\DRIVERS\csrserial.sys (No File)
S3 csrusb; System32\Drivers\csrusb.sys (No File)
S3 csr_bthav; system32\drivers\csrbthav.sys (No File)
S3 DUMeterDrv; \??\C:\Program Files (x86)\DU Meter\DUMETR64.SYS (No File)
S3 IvtComBusSrv; System32\Drivers\btcombus.sys (No File)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
Error Reading file: "C:\ProgramData\Desktop\VLC media player.lnk"
Error Reading file: "C:\ProgramData\Desktop\Total Commander 64 bit.lnk"
Error Reading file: "C:\ProgramData\Desktop\TeamViewer.lnk"
Error Reading file: "C:\ProgramData\Desktop\Smart Switch.lnk"
Error Reading file: "C:\ProgramData\Desktop\Sejda PDF Desktop.lnk"
Error Reading file: "C:\ProgramData\Desktop\PDFCreator.lnk"
Error Reading file: "C:\ProgramData\Desktop\OpenVPN GUI.lnk"
Error Reading file: "C:\ProgramData\Desktop\Nokia PC Suite.lnk"
Error Reading file: "C:\ProgramData\Desktop\MyPhoneExplorer.lnk"
Error Reading file: "C:\ProgramData\Desktop\MPC-HC x64.lnk"
Error Reading file: "C:\ProgramData\Desktop\Microsoft Edge.lnk"
Error Reading file: "C:\ProgramData\Desktop\KDE Connect.lnk"
Error Reading file: "C:\ProgramData\Desktop\Intel(R) HD Graphics Control Panel.lnk"
Error Reading file: "C:\ProgramData\Desktop\Google Chrome.lnk"
Error Reading file: "C:\ProgramData\Desktop\Firefox.lnk"
Error Reading file: "C:\ProgramData\Desktop\Droid4X.lnk"
Error Reading file: "C:\ProgramData\Desktop\Droid4X Multi Manager.lnk"
Error Reading file: "C:\ProgramData\Desktop\desktop.ini"
Error Reading file: "C:\ProgramData\Desktop\CPUID CPU-Z.lnk"
Error Reading file: "C:\ProgramData\Desktop\AVerTV 3D.lnk"
Error Reading file: "C:\ProgramData\Desktop\ApowerPDF.lnk"
Error Reading file: "C:\ProgramData\Desktop\Acrobat Reader.lnk"
Error Reading file: "C:\ProgramData\Desktop\4uKey for Android.lnk"
2026-05-11 17:40 - 2026-05-11 17:42 - 000000000 ____D C:\FRST
2026-05-08 10:43 - 2026-05-10 08:21 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-05-08 01:13 - 2026-05-08 01:13 - 000000050 _____ C:\EC-INVIA 20za14,75.txt
2026-04-29 19:14 - 2026-05-02 14:35 - 000009778 _____ C:\SLEVOMAT - ENERGYLANDIA.xlsx
2026-04-25 08:57 - 2026-04-25 12:39 - 000000211 _____ C:\co zadat jako FILTR u INVIA na emailu SEZNAM.txt
2026-04-16 08:35 - 2026-04-16 13:47 - 000000412 _____ C:\INVIA 16.4.2026.txt
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-05-11 17:41 - 2015-03-07 15:20 - 000000000 ____D C:\download
2026-05-11 17:38 - 2015-07-02 23:51 - 000000000 ____D C:\AAA-poukázky
2026-05-11 17:36 - 2018-05-13 20:43 - 000000000 ____D C:\__pomocne
2026-05-11 17:35 - 2023-06-04 20:05 - 000000000 ____D C:\_____VYRIDT
2026-05-11 17:28 - 2015-06-29 22:17 - 000000000 ____D C:\Smazat
2026-05-11 17:20 - 2015-03-07 15:07 - 000000000 ____D C:\Program Files (x86)\Google
2026-05-11 17:05 - 2010-11-21 11:27 - 000668542 _____ C:\Windows\system32\perfh005.dat
2026-05-11 17:05 - 2010-11-21 11:27 - 000141202 _____ C:\Windows\system32\perfc005.dat
2026-05-11 17:05 - 2009-07-14 07:13 - 001583290 _____ C:\Windows\system32\PerfStringBackup.INI
2026-05-11 17:05 - 2009-07-14 06:45 - 000030960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2026-05-11 17:05 - 2009-07-14 06:45 - 000030960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2026-05-11 17:05 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2026-05-11 17:00 - 2022-03-06 09:19 - 000000000 _____ C:\hsrv.txt
2026-05-11 17:00 - 2015-03-28 21:59 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2026-05-11 17:00 - 2015-03-07 14:51 - 000000000 __SHD C:\Users\Jiri\IntelGraphicsProfiles
2026-05-11 17:00 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-05-11 16:57 - 2021-03-13 12:16 - 000003950 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{4EAC9B19-D03F-4901-8EFD-291C9946C3F0}
2026-05-10 23:46 - 2015-04-20 18:19 - 000000000 ____D C:\Mix
2026-05-10 08:41 - 2015-03-08 21:04 - 000000000 ____D C:\Users\Jiri\AppData\Roaming\Microsoft\Excel
2026-05-09 13:49 - 2024-12-28 11:08 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-05-09 13:48 - 2018-01-25 00:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-05-05 17:18 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2026-05-02 08:16 - 2024-11-22 22:51 - 000002059 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2026-04-14 21:06 - 2024-11-22 22:51 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2026-04-11 14:01 - 2017-03-22 23:14 - 000000000 _____ C:\libSRTP_log.txt
2026-04-11 12:47 - 2015-03-10 19:40 - 000000000 ____D C:\Users\Jiri\AppData\Local\ElevatedDiagnostics
2026-04-11 08:06 - 2021-12-22 11:05 - 000003538 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-04-11 08:06 - 2021-12-22 11:05 - 000003408 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
==================== Files in the root of some directories ========
2023-02-26 23:21 - 2023-02-26 23:21 - 059548552 _____ (Microsoft Corporation) C:\Program Files (x86)\OneDriveSetup.exe
2017-12-17 00:34 - 2017-12-17 00:36 - 000002697 _____ () C:\Users\Jiri\AppData\Roaming\droid4xinstaller.log
2020-12-09 12:01 - 2026-01-22 19:35 - 000000027 _____ () C:\Users\Jiri\AppData\Local\.sdpl-system-config4
2015-10-18 14:27 - 2015-11-15 20:28 - 000004096 ____H () C:\Users\Jiri\AppData\Local\keyfile3.drm
2024-08-06 19:50 - 2026-03-02 18:46 - 000007605 _____ () C:\Users\Jiri\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2026-05-08 19:02
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-04-2026
Ran by Jiri (11-05-2026 17:44:08)
Running from C:\download
Microsoft Windows 7 Home Premium Service Pack 1 (X64) (2015-03-07 12:37:38)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2007933777-2661868901-2044359937-500 - Administrators - Disabled)
Guest (S-1-5-21-2007933777-2661868901-2044359937-501 - Limited - Disabled)
Jiri (S-1-5-21-2007933777-2661868901-2044359937-1000 - Administrators - Enabled) => C:\Users\Jiri
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4uKey for Android (HKLM-x32\...\{4uKeyforAndroid}_is1) (Version: 2.8.6.3 - Tenorshare)
A4Tech iWheelWorks 7.66 (HKLM-x32\...\WheelMouse) (Version: - )
ACDSee Trial Version (HKLM-x32\...\ACDSee Trial Version) (Version: - )
Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{36381D51-CC5E-4698-A0CC-E939C75EC9D8}) (Version: 1.5 - Eyeo GmbH)
Adobe Acrobat Reader - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 26.001.21529 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.8.158 - Adobe Systems, Inc.)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
ApowerPDF V3.1.6 (HKLM-x32\...\{99A1CF84-3154-433D-9F73-0A4D4DACBA1A}_is1) (Version: 3.1.6 - Apowersoft LIMITED)
ApowerPDF V4.2.0.418 (HKLM-x32\...\{8691C793-7B2C-46C5-9AB2-AB80D129A5EC}_is1) (Version: 4.2.0.418 - Apowersoft LIMITED)
AVerMedia A815 USB DVB-T 1.0.64.63 (HKLM-x32\...\AVerMedia A815 USB DVB-T) (Version: 1.0.64.63 - AVerMedia TECHNOLOGIES, Inc.)
AVerTV 3D (HKLM-x32\...\InstallShield_{5016185F-05AF-455F-AA70-6B6E5D6D4E70}) (Version: 6.5.2.12 - AVerMedia Technologies, Inc.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\70EE67FB13B2F2BE1F5A57AB193643AEFBA8D39C) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\BE156A27AFEAEA39D6A7C9D25CFA8DAFAF91756B) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (dg_ssudbus) USB (12/02/2015 2.12.1.0) (HKLM\...\85A33267F12961AF9ED9AE799DEDA5E62BEA236F) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (ssudmdm) Modem (12/02/2015 2.12.1.0) (HKLM\...\88ED314360B98E6E82E7CC3201FAEB4A9FD291B4) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (WinUSB) AndroidUsbDeviceClass (12/02/2015 2.12.1.0) (HKLM\...\701281E8283E9E3681220099A9DA5013A5A437AF) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CPUID CPU-Z 2.08 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.08 - CPUID, Inc.)
CrystalDiskInfo 8.0.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 8.0.0 - Crystal Dew World)
Droid4X (HKLM-x32\...\Droid4X) (Version: 0.10.6 - Haiyu Dongxiang Co.,Ltd.)
DroidCam Client (HKLM-x32\...\DroidCam) (Version: 6.5.2 - DEV47APPS)
DU Meter (HKLM-x32\...\dumeter3_is1) (Version: - Hagel Technologies)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 109.0.5414.120 - Google LLC)
Intel(R) Chipset Device Software (HKLM\...\{98841A35-1CBE-4EA3-BFF5-F3E3AD894666}) (Version: 10.0.20 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.31.1000 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{8C791A9C-B26E-4E09-8D87-3348AAE61B4A}) (Version: 10.0.31.1000 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{9F75A0EC-6773-4116-9D07-ABC427273606}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) ME UninstallLegacy (HKLM\...\{DBC3205C-2A41-490A-8EE4-BE4993FC2EC6}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4264 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\...\{20F70BB1-9240-43D2-985C-A8F5C6AAA1C7}) (Version: 5.0.10.2907 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.34 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{d370215a-d003-43ae-a3b6-1028af64d5a1}) (Version: 10.0.20 - Intel(R) Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{1B444AF9-1DBE-4884-8F35-969BEFCF69A8}) (Version: 1.35.133.1 - Intel Corporation) Hidden
Java 8 Update 391 (HKLM-x32\...\{71324AE4-039E-4CA4-87B4-2F32180391F0}) (Version: 8.0.3910.13 - Oracle Corporation)
JDownloader 2 (HKLM-x32\...\jdownloader2) (Version: 2.0.1 - AppWork GmbH)
JPEG ReSizer (remove only) (HKLM-x32\...\JPEG ReSizer) (Version: - )
KDE Connect (HKLM-x32\...\KDE Connect) (Version: 23.04.0 - KDE e.V.)
KEMailKb (HKLM-x32\...\KEMailKb) (Version: - )
KONICA MINOLTA PagePro 1400W (HKLM\...\KONICA MINOLTA PagePro 1400W) (Version: - )
Microsoft .NET Framework 4.7.2 (CSY) (HKLM\...\{F4C44834-E4FA-3DA9-B999-A30EC54E95B0}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{09CCBE8E-B964-30EF-AE84-6537AB4197F9}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 109.0.1518.140 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0405-1000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}) (Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (HKLM\...\{3061DCA5-2D0B-48F9-800F-9D7C1FEB5E78}) (Version: 4.9.0218.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026 (HKLM-x32\...\{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026 (HKLM-x32\...\{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Mozilla Firefox ESR (x64 en-US) (HKLM\...\Mozilla Firefox 115.35.2 ESR (x64 en-US)) (Version: 115.35.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 115.18.0 - Mozilla)
MPC-HC 1.7.8 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.8 - MPC-HC Team)
MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.14 - F.J. Wechselberger)
Nokia Connectivity Cable Driver (HKLM-x32\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM-x32\...\{866C4563-ED53-43F3-A29D-8BEE2BD1BA3C}) (Version: 7.1.180.94 - Nokia) Hidden
Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
OpenVPN 2.4.3-I602 (HKLM\...\OpenVPN) (Version: 2.4.3-I602 - OpenVPN Technologies, Inc.)
Opera Stable 79.0.4143.22 (HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Opera 79.0.4143.22) (Version: 79.0.4143.22 - Opera Software)
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.5.2 - pdfforge GmbH)
PDFsam Basic (HKLM-x32\...\{0314BB4C-2B68-491C-B4FB-40F1EC6CA881}) (Version: 3.30.5.0 - Andrea Vacondio)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.90.826.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7399 - Realtek Semiconductor Corp.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.7.43.0 - Samsung Electronics Co., Ltd.)
Sejda PDF Desktop (HKLM\...\{0C82176E-0356-4FA0-B7A8-E210A068BE9E}) (Version: 7.1.3 - Sejda BV)
Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.22083.3 - Samsung Electronics Co., Ltd.) Hidden
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.22083.3 - Samsung Electronics Co., Ltd.)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.2.2756 - TeamViewer)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51 - Ghisler Software GmbH)
TrackChecker version 1.0.15.481 (HKLM-x32\...\{73C4CE23-8D4C-4B67-B1DC-30533208DC3F}_is1) (Version: 1.0.15.481 - )
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VdhCoApp 1.2.4 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper)
VIA Platforma Ovladače zařízení (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.)
VLC media player 2.0.1 (HKLM-x32\...\VLC media player) (Version: 2.0.1 - VideoLAN)
X-Lite 3.0 (HKLM-x32\...\X-Lite 3.0_is1) (Version: - CounterPath Solutions Inc.)
Zoom (HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\ZoomUMX) (Version: 5.17.7 (31859) - Zoom Video Communications, Inc.)
Chrome apps:
============
WhatsApp Web (HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\56ad8c9975e42fcc459efbb7377529d1) (Version: 1.0 - Google\Chrome)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Acrobat Elements\ContextMenuShim64.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Program Files (x86)\MyPhoneExplorer\DLL\ShellMgr.dll [2010-03-30] (F.J. Wechselberger) [File not signed]
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => -> No File
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-08-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
ShortcutWithArgument: C:\Users\Jiri\Desktop\Rekola.cz.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gnncbodkhiiofienjhmnjoececnpkgil
ShortcutWithArgument: C:\Users\Jiri\Desktop\WhatsApp Web.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hnpfjngllnobngcgfapefoaidbinmjnm
ShortcutWithArgument: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Pocket.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=mjcnijlhddpbdemagnpefmlkjdagkogk
ShortcutWithArgument: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Rekola.cz.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gnncbodkhiiofienjhmnjoececnpkgil
ShortcutWithArgument: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\WhatsApp Web.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hnpfjngllnobngcgfapefoaidbinmjnm
==================== Loaded Modules (Whitelisted) =============
2015-03-08 21:26 - 2003-07-06 17:10 - 000011264 _____ () [File not signed] C:\Program Files (x86)\Capture\HoverKHook.dll
2022-04-16 22:46 - 2011-04-15 15:59 - 000102912 _____ () [File not signed] C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\EasyHook64.dll
2020-09-12 22:02 - 2020-09-12 22:02 - 000160768 _____ () [File not signed] C:\Program Files (x86)\DroidCam\lib\DroidCamFilter64.ax
2020-05-28 16:41 - 2012-08-31 23:07 - 000110592 _____ (AVerMedia Technologies, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\dll\CardID.dll
2020-05-28 16:41 - 2011-07-21 18:40 - 000368640 _____ (AVerMedia Technologies, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\dll\GraphMaster.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000049152 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\CDRomUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000053248 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\ComFnUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000053248 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\DialCnt.Dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000073728 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\LgKCUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000061440 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\MixerUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000122880 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\OSDUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000049152 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\RgnMaker.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000061440 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\SzUPFUtl.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000061440 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\TkBarUtl.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000049152 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\USBKBKC.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000053248 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\Wnd2File.dll
2005-02-01 20:28 - 2005-02-01 20:28 - 000073728 _____ (Hagel Technologies) [File not signed] C:\Program Files (x86)\DU Meter\DUData.dll
2015-03-07 14:56 - 2014-06-27 12:30 - 000074240 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.dll
2017-12-12 18:57 - 2016-01-19 18:18 - 000489984 _____ (Newtonsoft) [File not signed] [File is in use] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\Newtonsoft.Json.dll
2012-06-26 13:08 - 2012-06-26 13:08 - 000026624 _____ (Nokia) [File not signed] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
2012-06-26 11:58 - 2012-06-26 11:58 - 001262592 _____ (Nokia) [File not signed] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\NGSCM64.DLL
2012-06-26 13:08 - 2012-06-26 13:08 - 000572928 _____ (Nokia) [File not signed] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
2017-06-21 23:49 - 2017-06-21 23:49 - 000116224 _____ (pdfforge GmbH) [File not signed] C:\Windows\System32\pdfcmon.dll
2017-12-12 18:57 - 2016-01-28 18:11 - 000072704 _____ (Wondershare) [File not signed] [File is in use] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppCollect.dll
2017-12-12 18:57 - 2016-01-28 18:11 - 000316416 _____ (Wondershare) [File not signed] [File is in use] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppCommon.dll
2023-06-08 12:49 - 2023-05-29 21:40 - 008684032 _____ (wondershare) [File not signed] C:\ProgramData\Wondershare\wsServices\WsidClient.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [135]
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Version 11) (Whitelisted) =============
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.speedbit.com/?aff=dap10_vlc
SearchScopes: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000 -> DefaultScope {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = hxxp://search.speedbit.com/search.aspx?aff=dap10_vlc&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000 -> {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = hxxp://search.speedbit.com/search.aspx?aff=dap10_vlc&q={searchTerms}
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH -> Eyeo GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre-1.8\bin\ssv.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre-1.8\bin\jp2ssv.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH -> Eyeo GmbH)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2017-01-16 01:37 - 000000826 _____ C:\Windows\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 1.1.1.1 - 1.0.0.1
Windows Firewall is enabled.
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\PC Connectivity Solution\;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\OpenVPN\bin
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\ACD Wallpaper.bmp
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{2C93F763-D753-4CEF-B1E2-5A7DBD2C8B3B}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe => No File
FirewallRules: [UDP Query User{916379AD-13EC-422C-AB4C-261A255C68E4}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe => No File
FirewallRules: [TCP Query User{B3711565-CF8E-4B30-8A9E-DCFE6E4F155C}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe => No File
FirewallRules: [UDP Query User{24663761-CBB9-4A10-B40F-1B236872B15F}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe => No File
FirewallRules: [TCP Query User{891F5987-D666-4010-B5E7-65CA15A3F001}C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{E508B613-1E71-4DB1-A612-1863F5F02C1A}C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [TCP Query User{A54D03D3-6478-44EA-A72D-119092ED639E}C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{1D527C97-FA9E-43E8-A2EC-F331DF90766D}C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [TCP Query User{87ECE67F-49AE-4B0F-8CEE-02319B73D617}C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{0133A6E0-E23C-47C2-90A4-2F0A8C9DAA7F}C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{5CB2D195-63F9-4BEF-86A5-F4F4CF396933}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [UDP Query User{98837934-6D03-4DF9-80B0-A5A6E6964330}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [TCP Query User{AAB77AE4-5569-4DED-8C69-2E36B090F51D}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [UDP Query User{7D430B11-FA81-4A4F-A0A9-9E94FB6019F3}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [TCP Query User{6CAF0716-5438-4B6B-BAB0-174F3E4D303A}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [UDP Query User{0FA9A6CF-8467-4E18-88B8-2C87047D2664}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [TCP Query User{34318E61-236A-4AF3-A13F-C320CA1900DE}C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe] => (Allow) C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe => No File
FirewallRules: [UDP Query User{AD9EA34F-C620-4CD3-9EE2-A7BAB3B80122}C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe] => (Allow) C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe => No File
FirewallRules: [TCP Query User{0D1009DF-0141-4D79-B662-AEC7D11F5986}C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{52A905C9-3742-49A1-89B3-F718CEDB7A1B}C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{8C7EFB65-5309-4EC7-96AF-591BE5074459}C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{43854F11-11B3-4D87-A9AB-43D2C064F3B4}C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{CDAA3B61-7FD7-4782-8493-80B1B5377F46}C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{5CF0285F-A24F-44D4-B71A-85A960B90841}C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{9C6A49E8-CED1-4072-ABBC-A134EE9AE734}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [UDP Query User{36FCEB94-AFB8-40C4-9AFD-9DA6ECAF27B9}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [{8F186614-565B-42EF-BECE-BF6703BCAE88}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{D8584DE3-E45A-4B36-B2E9-EC40697F9143}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{2AFC6A47-F05F-4FAC-9368-0CE048FDD60C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{2443D2F0-68EB-4411-8055-318EE248E539}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{19BB08C4-C448-4871-A1B6-C8BF0F229BBB}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [UDP Query User{BC35AE64-47BE-40C0-B609-39134F8CAC1E}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [TCP Query User{264C4E18-E083-455D-84F4-450AD78A28C8}C:\users\jiri\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\jiri\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe (ShenZhen Thunder Networking Technologies Ltd. -> 深圳市迅雷网络技术有限公司)
FirewallRules: [{3ABD33A1-7BC9-49AC-9114-7404EC7EE323}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe (北京海誉动想科技股份有限公司 -> )
FirewallRules: [{105A224C-B9F7-435E-BEEC-C132C1B7537E}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe (北京海誉动想科技股份有限公司 -> 深圳市迅雷网络技术有限公司)
FirewallRules: [{C1041802-A366-4DB6-A9E4-8EEA06E6297B}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe (北京海誉动想科技股份有限公司 -> 深圳市迅雷网络技术有限公司)
FirewallRules: [{E1914EDF-CB8A-45F5-AA43-0E3B88F7E4F2}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe (Oracle Corporation -> )
FirewallRules: [TCP Query User{F15D6B69-5303-4452-9247-B28985E5AD34}C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{07FE7E39-ED13-4153-9B7D-4660545D9BD4}C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe => No File
FirewallRules: [{66822E0D-4ED7-46A7-9D8F-AD728AEFF4EA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F68E8E38-FFBF-45A0-B053-F722AB103762}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{89C88373-4901-4623-BED7-CDF7BB5D4866}C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{7592A735-E666-400B-9484-EFA7A3D659F9}C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{A13D7054-15D0-430F-BB43-6F29299569FF}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [UDP Query User{909781C3-FB4C-48A1-9C5C-E4D3C90D665E}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [{4523FD65-0A35-42D9-8280-B3926732E584}] => (Allow) C:\Users\Jiri\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe => No File
FirewallRules: [{D3148B9A-5730-4C8E-AD83-5C2D75526BF0}] => (Allow) C:\Users\Jiri\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe => No File
FirewallRules: [TCP Query User{BAA1B0BA-6054-47C0-9FC8-20C06C702A89}C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{89E3AB94-E0FF-4495-9E12-944EE1568105}C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe => No File
FirewallRules: [{C2A54D01-2DA6-4DB8-9452-673C35BEDAC4}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File
FirewallRules: [TCP Query User{FEA1866E-582B-4897-ACC6-B376CB8CC194}C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{F71C02E5-4737-48DA-9DCA-AD1134FBFF7E}C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{5F50EB04-B166-4CC4-9808-CCBE4A55DAF2}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [UDP Query User{A30D9A0E-BE95-4814-9E14-70A162B99EBB}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{7C679329-F4E7-4372-A56C-3BEA1FF49469}] => (Block) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{85AD6805-402E-426D-8FF0-6471E53F1BC9}] => (Block) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [TCP Query User{5288C46A-E1BE-4299-80F1-B42D12DEE0F7}C:\users\jiri\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jiri\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [UDP Query User{DF6E2E7D-4B80-401F-9111-7A8EC28D30CD}C:\users\jiri\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jiri\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [TCP Query User{E37D0F96-2DCF-4443-8971-BC54A76D93A3}C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{E219A0B2-E808-48FF-B120-8CF493B60159}C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe => No File
FirewallRules: [{81016E7F-69D4-4065-813C-838C86960C17}] => (Allow) C:\Users\Jiri\AppData\Local\Programs\Opera\79.0.4143.22\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{36D46ED6-CE11-4A45-B35D-8D2E6700BED5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{A19D449C-F873-4D93-B601-2157315670A6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{4FA42D9F-4353-477F-91D6-BBC8425524EF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{8B17D4B0-1936-49B3-A908-4A96B87D068A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{10356C70-255D-4EF8-BBAF-64F51ED963BE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{5B368D71-11A9-4E36-9EA2-6197E98727D5}C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{EA1D36CE-A939-453A-AB94-2E5D80B4B48A}C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{DE0DCC93-41A3-4715-9DB6-054070B2D6BC}C:\program files\kde connect\bin\kdeconnectd.exe] => (Allow) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [UDP Query User{243F32BE-336D-4F03-B185-19BED5629CD0}C:\program files\kde connect\bin\kdeconnectd.exe] => (Allow) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [TCP Query User{3A4CB460-756C-4D5B-8D75-B7B957595C05}C:\program files\kde connect\bin\kdeconnectd.exe] => (Block) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [UDP Query User{5AD75EB9-0191-4A80-A5BD-4494A71094CD}C:\program files\kde connect\bin\kdeconnectd.exe] => (Block) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [{ABA6C096-4C6E-4DF9-B2A3-FF0115C7455F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{03DF3778-435B-4FB3-A8D7-9FC6ACBA5E3E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{CCC99412-69C8-4AFC-B3D6-E3956D513B7F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D2969A1C-8624-4D29-8113-0A8AA743CA78}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8AB2EB85-DE7E-438D-A241-DCF01E2555B8}] => (Allow) C:\program files (x86)\wondershare\drfone\drfonetoolkit.exe => No File
FirewallRules: [{06A3B7CD-7CE3-4A50-90EE-CF28E0E38E4C}] => (Allow) C:\download\4ukey-for-android.exe (Tenorshare Co., Ltd. -> Tenorshare Co., Ltd.)
FirewallRules: [{504262CD-D67D-42ED-9918-92DA4388BB51}] => (Allow) C:\download\4ukey-for-android.exe (Tenorshare Co., Ltd. -> Tenorshare Co., Ltd.)
FirewallRules: [TCP Query User{9B5D2413-FC8C-4F8F-95EB-03392CD2B529}C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{0A7004D4-A707-4E8C-948B-16E56F87B745}C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [{1DECEA78-E2A8-41C9-B35E-D9E5188575CE}] => (Allow) C:\Users\Jiri\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{66E5DE99-FB76-40CD-B660-59DF4E3CC30C}] => (Allow) C:\Users\Jiri\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{B094926C-1A12-4AA8-888E-875B7020C885}] => (Allow) C:\Users\Jiri\AppData\Roaming\Zoom\bin\airhost.exe => No File
==================== Restore Points =========================
04-05-2026 19:29:34 Naplánovaný kontrolní bod
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (05/11/2026 05:00:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/11/2026 04:54:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/11/2026 05:46:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CompatTelRunner.exe, verze: 10.0.14275.1000, časové razítko: 0x56e8dec4
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.23539, časové razítko: 0x57c99bd4
Kód výjimky: 0xc06d007e
Posun chyby: 0x000000000001a06d
ID chybujícího procesu: 0x1150
Čas spuštění chybující aplikace: 0x01dce0f8ca49189a
Cesta k chybující aplikaci: C:\Windows\system32\CompatTelRunner.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: 0f82a421-4cec-11f1-9af3-448a5bcb771c
Error: (05/11/2026 05:43:50 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/10/2026 08:24:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CompatTelRunner.exe, verze: 10.0.14275.1000, časové razítko: 0x56e8dec4
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.23539, časové razítko: 0x57c99bd4
Kód výjimky: 0xc06d007e
Posun chyby: 0x000000000001a06d
ID chybujícího procesu: 0x11d8
Čas spuštění chybující aplikace: 0x01dce045a344e506
Cesta k chybující aplikaci: C:\Windows\system32\CompatTelRunner.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: e9e2e295-4c38-11f1-96fa-448a5bcb771c
Error: (05/10/2026 08:21:23 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/09/2026 08:31:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CompatTelRunner.exe, verze: 10.0.14275.1000, časové razítko: 0x56e8dec4
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.23539, časové razítko: 0x57c99bd4
Kód výjimky: 0xc06d007e
Posun chyby: 0x000000000001a06d
ID chybujícího procesu: 0xf54
Čas spuštění chybující aplikace: 0x01dcdf7d4fb1dc82
Cesta k chybující aplikaci: C:\Windows\system32\CompatTelRunner.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: c80a5aff-4b70-11f1-96c1-448a5bcb771c
Error: (05/09/2026 08:27:21 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
System errors:
=============
Error: (05/11/2026 05:47:09 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {BB6DF56B-CACE-11DC-9992-0019B93A3A84} se v daném časovém limitu neregistroval u služby DCOM.
Error: (05/11/2026 05:45:31 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
Error: (05/11/2026 05:45:31 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.
Error: (05/11/2026 05:45:09 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.
Error: (05/11/2026 05:45:09 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
Error: (05/11/2026 05:44:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
Error: (05/11/2026 05:44:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.
Error: (05/11/2026 05:44:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
==================== Memory info ===========================
BIOS: American Megatrends Inc. V17.3 07/01/2014
Motherboard: MSI H81M-E34 (MS-7817)
Processor: Intel(R) Celeron(R) CPU G1840 @ 2.80GHz
Percentage of memory in use: 94%
Total physical RAM: 3972.53 MB
Available physical RAM: 220.65 MB
Total Virtual: 7943.25 MB
Available Virtual: 1616.39 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:119.14 GB) (Free:2.26 GB) (Model: Crucial_CT128M550SSD1 ATA Device) NTFS
Drive e: () (Fixed) (Total:39.06 GB) (Free:20.48 GB) (Model: WDC WD1600JS-00MHB0 ATA Device) NTFS
Drive f: () (Fixed) (Total:109.98 GB) (Free:17.85 GB) (Model: WDC WD1600JS-00MHB0 ATA Device) NTFS
\\?\Volume{f02c6443-c4c5-11e4-8d6b-806e6f6e6963}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 119.2 GB) (Disk ID: CD98BD4A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS)
==========================================================
Disk: 1 (Size: 149 GB) (Disk ID: D967D967)
Partition 1: (Active) - (Size=39.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=110 GB) - (Type=0F Extended)
==================== End of Addition.txt =======================
Ran by Jiri (administrator) on HOME (MSI MS-7817) (11-05-2026 17:41:50)
Running from C:\download\FRST64.exe
Loaded Profiles: Jiri
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\KEMailKb.EXE
(explorer.exe ->) () [File not signed] C:\Program Files (x86)\Capture\HoverSnap.exe
(explorer.exe ->) () [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(explorer.exe ->) (AVerMedia TECHNOLOGIES, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <24>
(explorer.exe ->) (hxxp://www.SteveMiller.net) [File not signed] C:\Program Files (x86)\PureText\PureText.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(explorer.exe ->) (OpenVPN Technologies, Inc. -> ) C:\Program Files\OpenVPN\bin\openvpn-gui.exe
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (VIA Technologies, Inc.) [File not signed] C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe
(Hagel Technologies) [File not signed] C:\Program Files (x86)\DU Meter\DUMeter.exe
(Intel Corporation - pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (AVerMedia TECHNOLOGIES, Inc.) [File not signed] C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe
(services.exe ->) (AVerMedia) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
(services.exe ->) (Intel CASE -> ) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (OpenVPN Technologies, Inc. -> The OpenVPN Project) C:\Program Files\OpenVPN\bin\openvpnserv.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (Wondershare Technology Group Co.,Ltd -> wondershare) C:\ProgramData\wondershare\wsServices\WsidService.exe
(services.exe ->) (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe
(services.exe ->) (北京海誉动想科技股份有限公司 -> ) C:\Program Files (x86)\Droid4X\Droid4XService.exe
(taskeng.exe ->) (Speed-Bit LTD -> Speedbit Ltd.) C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.) [File not signed]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7659736 2014-11-26] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-06-27] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [DU Meter] => C:\Program Files (x86)\DU Meter\DUMeter.exe [1469952 2005-02-01] (Hagel Technologies) [File not signed]
HKLM-x32\...\Run: [KEMailKb] => C:\Program Files (x86)\KEMailKb\KEMailKb.EXE [401667 2004-07-26] (Dritek System Inc.) [File not signed]
HKLM-x32\...\Run: [WheelMouse] => C:\Program Files (x86)\A4Tech\Mouse\Amoumain.exe [159744 2005-09-21] (A4Tech Co.,Ltd.) [File not signed]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [748624 2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [DU Meter] => C:\Program Files (x86)\DU Meter\DUMeter.exe [1469952 2005-02-01] (Hagel Technologies) [File not signed]
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [PureText] => C:\Program Files (x86)\PureText\PureText.exe [33792 2013-01-04] (hxxp://www.SteveMiller.net) [File not signed]
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [638592 2017-07-14] (OpenVPN Technologies, Inc. -> )
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Run: [com.squirrel.WhatsApp.WhatsApp] => C:\Users\Jiri\AppData\Local\WhatsApp\Update.exe [2412768 2023-06-15] (WhatsApp LLC -> )
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\MountPoints2: {1e1f76b3-4c7f-11ee-81ea-448a5bcb771c} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\MountPoints2: {a07e04a8-4528-11e6-a432-448a5bcb771c} - G:\CallSetup.exe
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\MountPoints2: {ef68f20e-c508-11e4-a73c-448a5bcb771c} - E:\CallSetup.exe
HKLM\...\Windows x64\Print Processors\HP1020PrintProc: C:\Windows\System32\spool\prtprocs\x64\pphp1020.dll [65024 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Windows x64\Print Processors\LMUD1O4C: C:\Windows\System32\spool\prtprocs\x64\LMUD1O4C.DLL [283152 2016-10-17] (Microsoft Windows Hardware Compatibility Publisher -> Lexmark International Inc.)
HKLM\...\Windows x64\Print Processors\MIMFPR_Y: C:\Windows\System32\spool\prtprocs\x64\MIMFPR_Y.DLL [56320 2006-03-09] (Microsoft Windows Hardware Compatibility Publisher -> KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
HKLM\...\Print\Monitors\HPLJ1020LM: C:\Windows\system32\zlhp1020.dll [192512 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\MLMON__Y: C:\Windows\system32\MLMON__Y.DLL [144384 2006-03-09] (Microsoft Windows Hardware Compatibility Publisher -> KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
HKLM\...\Print\Monitors\pdfcmon: C:\Windows\system32\pdfcmon.dll [116224 2017-06-21] (pdfforge GmbH) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [OpenVPN_UserSetup] -> reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /t REG_SZ /d "C:\Program Files\OpenVPN\bin\openvpn-gui.exe" /f
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.120\Installer\chrmstp.exe [4956952 2023-01-27] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google Chrome.lnk [2015-03-09]
ShortcutTarget: Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
Startup: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HoverSnap – zástupce.lnk [2015-03-09]
ShortcutTarget: HoverSnap – zástupce.lnk -> C:\Program Files (x86)\Capture\HoverSnap.exe () [File not signed]
Startup: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TOTALCMD64.lnk [2015-03-07]
ShortcutTarget: TOTALCMD64.lnk -> C:\Program Files\totalcmd\TOTALCMD64.EXE (Ghisler Software GmbH -> Ghisler Software GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVer HID Receiver.lnk [2019-07-18]
ShortcutTarget: AVer HID Receiver.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe () [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVerQuick.lnk [2019-07-18]
ShortcutTarget: AVerQuick.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\KDE Connect.lnk [2023-05-23]
ShortcutTarget: KDE Connect.lnk -> C:\Program Files\KDE Connect\bin\kdeconnect-indicator.exe (K Desktop Environment e.V. -> )
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {B12C58C2-AEEF-41E2-B38B-7617A133354E} - System32\Tasks\{0A4B1322-A08A-4CC4-B8DF-5D362026AA1C} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\Jiri\AppData\Local\Temp\jre-8u381-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
Task: {B59530A6-3312-4585-9D90-1380DF987F58} - System32\Tasks\{2B2FBF63-1173-49F7-B056-41C1497A5C02} => F:\Opera_PortableSetup.exe (No File)
Task: {91B27F21-055D-4136-9F23-EAEE657A34A9} - System32\Tasks\{6FB5E648-6FB3-44BC-AB04-CB7DC4B72CB2} => F:\Opera_PortableSetup.exe (No File)
Task: {F9BD04AA-1C44-4664-9D39-9E96B74230FC} - System32\Tasks\{81488D6F-1EA5-4A77-8AB5-B4DF4B4DE94E} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\Jiri\AppData\Local\Temp\jre-8u371-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
Task: {476085AF-A1AE-438C-88CC-1024305B4215} - System32\Tasks\{885BADA0-4B2B-4EBC-9482-8E4B04FBF8ED} => c:\program files (x86)\google\chrome\application\chrome.exe [3151128 2023-01-23] (Google LLC -> Google LLC) -> hxxp://ui.skype.com/ui/0/7.10.64.101/cs/abandoninstall?page=tsPlugin
Task: {FCADA655-D08E-41CF-9514-91ABBAAAB741} - System32\Tasks\{99F5C876-B9AF-4034-A921-C0BEDA35F132} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\aa\A4 Tech - myš\Setup.exe" -d "c:\aa\A4 Tech - myš\"
Task: {FC092BF6-42CE-4FF3-B08F-08BA9EE40455} - System32\Tasks\{F4741BFD-31C8-4AF7-B980-54329950A649} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a C:\download\OperaSetup.exe -d C:\download
Task: {C9C4B352-B6A9-4560-A341-7876C96550BC} - System32\Tasks\{F8CA36F3-DA22-4D02-AFE3-0F212024B5A1} => C:\Windows\System32\pcalua.exe [9728 2015-02-03] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\aa\email kb driver\Setup.exe" -d "c:\aa\email kb driver\"
Task: {2F820978-A16E-487E-853C-733808B8996F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {79AE72AA-1734-4B37-8A17-9061213F0C6B} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\download\esetonlinescanner.exe LOGON (No File)
Task: {EE83280C-AD75-418C-88F4-EF427E536470} - System32\Tasks\EOSv3 Scheduler onTime => C:\download\esetonlinescanner.exe SCHED (No File)
Task: {1BAE5261-BA52-4107-A480-E025C783B4F0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
Task: {B8A922D7-122C-4044-91C9-BB1BEAF0C807} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
Task: {8E02EDAB-768F-4984-92FC-9C5C9F47DAF0} - System32\Tasks\Opera scheduled Autoupdate 1663184996 => C:\Users\Jiri\AppData\Local\Programs\Opera\launcher.exe [42724048 2021-09-13] (Opera Software AS -> Opera Software)
Task: {41FC091F-B865-4F14-AE90-46F1A41F80E5} - System32\Tasks\SBWUpdateTask_Logon_4e925d94-00FF542154E9 => C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe [92320 2012-02-08] (Speed-Bit LTD -> Speedbit Ltd.) <==== ATTENTION
Task: {870D3EDD-D2B8-4083-B448-A48DF79B44E1} - System32\Tasks\SBWUpdateTask_Time_4e925d94-00FF542154E9 => C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe [92320 2012-02-08] (Speed-Bit LTD -> Speedbit Ltd.) <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-2007933777-2661868901-2044359937-1000] => 45.77.103.193:3128
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 81.200.55.222 81.200.55.223
Tcpip\..\Interfaces\{0E1C7303-F805-4545-AFA2-66B7D70D2B2B}: [NameServer] 1.1.1.1,1.0.0.1
Tcpip\..\Interfaces\{0E1C7303-F805-4545-AFA2-66B7D70D2B2B}: [DhcpNameServer] 81.200.55.222 81.200.55.223
Tcpip\..\Interfaces\{0E1C7303-F805-4545-AFA2-66B7D70D2B2B}: [DhcpDomain] nej.cz
FireFox:
========
FF DefaultProfile: qkw5swb8.default-1630436187493 -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493 [2026-05-09]
FF Homepage: Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493 -> hxxp://search.speedbit.com/?aff=dap10_vlc
FF Notifications: Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493 -> hxxps://web.whatsapp.com
FF Extension: (Hoxx VPN Proxy) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\@hoxx-vpn.xpi [2025-06-20]
FF Extension: (Český slovník pro kontrolu pravopisu) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\cs@dictionaries.addons.mozilla.org.xpi [2024-12-28]
FF Extension: (Language: Čeština (Czech)) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\langpack-cs@firefox.mozilla.org.xpi [2024-12-28]
FF Extension: (uBlock Origin) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\uBlock0@raymondhill.net.xpi [2026-03-22]
FF Extension: (Video DownloadHelper) - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2025-07-01]
FF SearchPlugin: C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\qkw5swb8.default-1630436187493\searchplugins\speedbit.xml [2022-04-16]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1218158.dll [2015-05-07] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-11-10] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-11-10] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.391.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.391.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-03-17] (VideoLAN) [File not signed]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Jiri\AppData\Local\Microsoft\Edge\User Data\Default [2026-04-29]
Edge Notifications: Default -> hxxps://web.whatsapp.com
Edge HomePage: Default -> hxxps://email.seznam.cz/
Edge StartupUrls: Default -> "hxxps://email.seznam.cz/","hxxps://www.bazos.cz/hodnoceni.php?idmail=69740 ... 3&jmeno=EL"
Edge Extension: (Translator) - C:\Users\Jiri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cdkmohnpfdennnemmjekmmiibgfddako [2024-10-21]
Edge Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Jiri\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2026-04-08]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default [2026-05-11]
CHR DownloadDir: C:\download
CHR Notifications: Default -> hxxps://app.zoom.us; hxxps://messages.google.com; hxxps://teams.microsoft.com; hxxps://web.whatsapp.com; hxxps://www.edarling.cz; hxxps://www.facebook.com; hxxps://www.lidl.cz; hxxps://www.slevomat.cz
CHR HomePage: Default -> hxxps://email.seznam.cz/www.benefity-veterani.cz
CHR StartupUrls: Default -> "hxxps://email.seznam.cz/#inbox/564674","hxxps://tvprogram.idnes.cz/?k=1&k=2&k=3&k=4&k=78&k=92&k=89&k=226&k=302&k=330&k=332&k=331&k=24&k=18&k=19&k=94&k=95"
CHR Extension: (Překladač Google) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-25]
CHR Extension: (Right Click Enable - Pravým tlačítkem povolit) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegpaehcnpbhdmnghlnbnngogbfelnno [2026-03-12]
CHR Extension: (Data Compression Proxy) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajfiodhbiellfpcjjedhmmmpeeaebmep [2017-08-08]
CHR Extension: (Browser Boost - Extra Nástroje) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\akknpgblpchaoebdoiojonnahhnfgnem [2025-02-27]
CHR Extension: (IP Address & My IP Address Geo-Location) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\allbgfamnneoaccefakgmikbjlhndkff [2018-02-10]
CHR Extension: (SPOI Options (Please remove me)) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn [2015-03-07]
CHR Extension: (JavaScript Toggle On and Off) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdcgbgnfhhdmdkallfmlachogpghifgf [2026-02-03]
CHR Extension: (Pricecut) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\cefdmiohfoihglgojcjlgfefkbphoaoj [2015-03-07]
CHR Extension: (OneTab) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2026-03-23]
CHR Extension: (Aliexpress SuperStar česky, Historie cen) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciclollkolafellcaolgccmfjldgpolo [2025-10-24]
CHR Extension: (uBlock Origin) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2026-03-12]
CHR Extension: (Video Viewer) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\dejgnnjohnpljeijfendiiafgpaenbip [2015-03-07]
CHR Extension: (HTML5 video for YouTube™) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\dolajcekhnohkpncmhgledbmndjpblei [2015-03-07]
CHR Extension: (Proxy SwitchySharp) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpplabbmogkhghncfbfdeeokoefdjegm [2020-03-15]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-08]
CHR Extension: (Youtube-to-MP3 GOLD) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejcmlonfegmnhinnopgjhibfghbgpeoc [2015-03-28]
CHR Extension: (Video Downloader Professional) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2026-03-13]
CHR Extension: (YoWindow Počasí Zdarma) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef [2017-03-15]
CHR Extension: (MonkeyECHO - GearBest Price Tracker) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmdnnfdofijijgcbhdbnlohaabnmdkb [2020-06-03]
CHR Extension: (I don't care about cookies) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2024-06-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-24]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-04-11]
CHR Extension: (Hola VPN - Your Website Unblocker) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2026-05-07]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2024-11-23]
CHR Extension: (Read Aloud: A Text to Speech Voice Reader) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdhinadidafjejdhmfkjgnolgimiaplp [2025-12-13]
CHR Extension: (Video Downloader Plus) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkdmdpdhfaamhgaojpelccmeehpfljgf [2026-04-22]
CHR Extension: (Perplexity - AI Companion) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlgbcneanomplepojfcnclggenpcoldo [2023-10-20]
CHR Extension: (Windscribe - Free Proxy and Ad Blocker) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpcagpplmpfojmgmnngilcnanddlhb [2024-12-10]
CHR Extension: (Bardeen: Automate Browser Apps with AI) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihhkmalpkhkoedlmcnilbbhhbhnicjga [2026-03-25]
CHR Extension: (Distill Web Monitor) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\inlikjemeeknofckkjolnjbpehgadgge [2024-05-15]
CHR Extension: (Unpaywall) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplffkdpngmdjhlpjmppncnlhomiipha [2025-01-09]
CHR Extension: (Extensity) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjmflmamggggndanpgfnpelongoepncg [2024-09-02]
CHR Extension: (Price.com: Cash Back, Coupons & Price Comparison) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmmpkhpajpecmpdmmbpjmkmcmfdahkcj [2026-04-15]
CHR Extension: (BugMeNot Lite) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lackfehpdclhclidcbbfcemcpolgdgnb [2015-03-07]
CHR Extension: (Reader Mode) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\llimhhconnjiflfimocjggfjdlmlhblm [2025-11-30]
CHR Extension: (Rozšíření Google Keep pro Chrome) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2026-05-05]
CHR Extension: (BLACKBOX.AI) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcgbeeipkmelnpldkobichboakdfaeon [2025-05-21]
CHR Extension: (Reload All Tabs) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\midkcinmplflbiflboepnahkboeonkam [2026-04-26]
CHR Extension: (Pocket) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2017-07-15]
CHR Extension: (Hodiny) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjocghlclkpgheifflemilcnblodjohg [2015-03-07]
CHR Extension: (YouTube Překladač & Dabing Videa) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndbhldoclidahhoogmgklimmomnnepjg [2026-01-23]
CHR Extension: (GearBest Coupons) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhhofjfofhkgeofpjkemonejjflnjnid [2019-04-23]
CHR Extension: (Save to Pocket) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2023-06-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
CHR Extension: (GearBest Star, Price history, coupons ) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\obahoaepjklfhghnafdcganehbokgffh [2020-10-01]
CHR Extension: (Readlang Web Reader) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\odpdkefpnfejbfnmdilmfhephfffmfoh [2026-04-16]
CHR Extension: (Povolit kliknutí pravým tlačítkem pro Google Chrome ™) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofgdcdohlhjfdhbnfkikfeakhpojhpgm [2024-04-15]
CHR Extension: (hide.me Proxy) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjocgmpmlfahafbipehkhbaacoemojp [2026-03-28]
CHR Extension: (PrintFriendly: Print Clean Pages, Save as PDF & Screenshot, AI Tools) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2026-04-26]
CHR Extension: (rádio) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\plaapjbgohfgkalmmjpakodbpomahebn [2017-01-20]
CHR Extension: (Hlídač Shopů) - C:\Users\Jiri\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlonggbfebcjelncogcnclagkmkikk [2025-02-07]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
Opera:
=======
OPR Profile: C:\Users\Jiri\AppData\Roaming\Opera Software\Opera Stable [2025-08-15]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=o ... utEncoding}
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [360448 2011-08-19] (AVerMedia) [File not signed]
R2 AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [403456 2011-04-01] () [File not signed]
R2 AVerUpdateServer; C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe [167936 2011-10-31] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 DFWSIDService; C:\ProgramData\Wondershare\wsServices\WsidService.exe [4231408 2023-05-29] (Wondershare Technology Group Co.,Ltd -> wondershare)
R2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [285616 2017-08-14] (北京海誉动想科技股份有限公司 -> )
S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-03-07] (Google Inc -> Google Inc.)
R2 HFGService; C:\Windows\System32\HFGService.dll [535552 2009-12-21] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-08-25] (Intel CASE -> )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv2.exe [15872 2016-11-25] () [File not signed]
R2 OpenVPNServiceInteractive; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72832 2017-07-14] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 OpenVPNServiceLegacy; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72832 2017-07-14] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13172752 2020-01-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe [388608 2016-01-28] (Wondershare) [File not signed]
S2 ElevationService; C:\ProgramData\Wondershare\wsServices\ElevationService.exe (No File)
S2 WirelessBackupService; C:\Program Files (x86)\Wondershare\drfone\Addins\Recovery\WirelessBackupService.exe (No File)
S2 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe (No File)
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe" (No File)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [312064 2009-12-04] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
S3 BthAudioHF; C:\Windows\System32\DRIVERS\BthAudioHF.sys [52224 2009-12-21] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [29184 2009-08-13] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [22568 2016-09-10] (IVT CORPORATION -> IVT Corporation.)
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csr_a2dp; C:\Windows\System32\drivers\bthav.sys [78848 2009-12-21] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 diagswitchdrv; C:\Windows\System32\DRIVERS\diagswitchdrv.sys [117888 2014-08-16] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 DKbFltr; C:\Windows\SysWOW64\Drivers\DKbFltr.sys [17071 2004-07-26] (Dritek System Inc.) [File not signed]
R3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [31576 2020-04-24] (DEV47 APPS -> Dev47Apps)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [19200 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 HWHandSetProLine; C:\Windows\System32\DRIVERS\hw_quusbmdm.sys [226560 2016-04-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hw_ctrlfakedev; C:\Windows\System32\DRIVERS\hw_ctrlfakedev.sys [115712 2015-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-22] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 IvtAudioBusSrv; C:\Windows\System32\Drivers\IvtBtBus.sys [27256 2016-09-10] (IVT CORPORATION -> IVT Corporation.)
S3 IvtPanBusSrv; C:\Windows\System32\Drivers\btnetBus.sys [31480 2016-09-10] (IVT CORPORATION -> IVT Corporation.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation -> Microsoft Corporation)
S3 MpKsl46be9343; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FF811A98-E18D-4A0E-9092-59314F5CF33F}\MpKslDrv.sys [51632 2025-09-30] (Microsoft Windows -> Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation -> Microsoft Corporation)
S3 nmwcd; C:\Windows\System32\drivers\ccdcmbx64.sys [19968 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\Windows\System32\drivers\ccdcmbox64.sys [27136 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 qcusbser; C:\Windows\System32\DRIVERS\qu_usb_serial.sys [245248 2015-07-08] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [168968 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [9216 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys [9216 2012-11-16] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [159936 2016-08-16] (NGO -> MBB)
S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys (No File)
S3 BT; system32\DRIVERS\btnetdrv.sys (No File)
S3 BTCOM; system32\DRIVERS\btcomport.sys (No File)
S3 Btcsrusb; System32\Drivers\btcusb.sys (No File)
S3 csravrcp; system32\DRIVERS\csravrcp.sys (No File)
S3 CsrBtPort; system32\DRIVERS\CsrBtPort.sys (No File)
S3 csrhfgcc; system32\DRIVERS\csrhfgcc.sys (No File)
S3 csrpan; system32\DRIVERS\csrpan.sys (No File)
S3 csrserial; system32\DRIVERS\csrserial.sys (No File)
S3 csrusb; System32\Drivers\csrusb.sys (No File)
S3 csr_bthav; system32\drivers\csrbthav.sys (No File)
S3 DUMeterDrv; \??\C:\Program Files (x86)\DU Meter\DUMETR64.SYS (No File)
S3 IvtComBusSrv; System32\Drivers\btcombus.sys (No File)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
Error Reading file: "C:\ProgramData\Desktop\VLC media player.lnk"
Error Reading file: "C:\ProgramData\Desktop\Total Commander 64 bit.lnk"
Error Reading file: "C:\ProgramData\Desktop\TeamViewer.lnk"
Error Reading file: "C:\ProgramData\Desktop\Smart Switch.lnk"
Error Reading file: "C:\ProgramData\Desktop\Sejda PDF Desktop.lnk"
Error Reading file: "C:\ProgramData\Desktop\PDFCreator.lnk"
Error Reading file: "C:\ProgramData\Desktop\OpenVPN GUI.lnk"
Error Reading file: "C:\ProgramData\Desktop\Nokia PC Suite.lnk"
Error Reading file: "C:\ProgramData\Desktop\MyPhoneExplorer.lnk"
Error Reading file: "C:\ProgramData\Desktop\MPC-HC x64.lnk"
Error Reading file: "C:\ProgramData\Desktop\Microsoft Edge.lnk"
Error Reading file: "C:\ProgramData\Desktop\KDE Connect.lnk"
Error Reading file: "C:\ProgramData\Desktop\Intel(R) HD Graphics Control Panel.lnk"
Error Reading file: "C:\ProgramData\Desktop\Google Chrome.lnk"
Error Reading file: "C:\ProgramData\Desktop\Firefox.lnk"
Error Reading file: "C:\ProgramData\Desktop\Droid4X.lnk"
Error Reading file: "C:\ProgramData\Desktop\Droid4X Multi Manager.lnk"
Error Reading file: "C:\ProgramData\Desktop\desktop.ini"
Error Reading file: "C:\ProgramData\Desktop\CPUID CPU-Z.lnk"
Error Reading file: "C:\ProgramData\Desktop\AVerTV 3D.lnk"
Error Reading file: "C:\ProgramData\Desktop\ApowerPDF.lnk"
Error Reading file: "C:\ProgramData\Desktop\Acrobat Reader.lnk"
Error Reading file: "C:\ProgramData\Desktop\4uKey for Android.lnk"
2026-05-11 17:40 - 2026-05-11 17:42 - 000000000 ____D C:\FRST
2026-05-08 10:43 - 2026-05-10 08:21 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-05-08 01:13 - 2026-05-08 01:13 - 000000050 _____ C:\EC-INVIA 20za14,75.txt
2026-04-29 19:14 - 2026-05-02 14:35 - 000009778 _____ C:\SLEVOMAT - ENERGYLANDIA.xlsx
2026-04-25 08:57 - 2026-04-25 12:39 - 000000211 _____ C:\co zadat jako FILTR u INVIA na emailu SEZNAM.txt
2026-04-16 08:35 - 2026-04-16 13:47 - 000000412 _____ C:\INVIA 16.4.2026.txt
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-05-11 17:41 - 2015-03-07 15:20 - 000000000 ____D C:\download
2026-05-11 17:38 - 2015-07-02 23:51 - 000000000 ____D C:\AAA-poukázky
2026-05-11 17:36 - 2018-05-13 20:43 - 000000000 ____D C:\__pomocne
2026-05-11 17:35 - 2023-06-04 20:05 - 000000000 ____D C:\_____VYRIDT
2026-05-11 17:28 - 2015-06-29 22:17 - 000000000 ____D C:\Smazat
2026-05-11 17:20 - 2015-03-07 15:07 - 000000000 ____D C:\Program Files (x86)\Google
2026-05-11 17:05 - 2010-11-21 11:27 - 000668542 _____ C:\Windows\system32\perfh005.dat
2026-05-11 17:05 - 2010-11-21 11:27 - 000141202 _____ C:\Windows\system32\perfc005.dat
2026-05-11 17:05 - 2009-07-14 07:13 - 001583290 _____ C:\Windows\system32\PerfStringBackup.INI
2026-05-11 17:05 - 2009-07-14 06:45 - 000030960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2026-05-11 17:05 - 2009-07-14 06:45 - 000030960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2026-05-11 17:05 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2026-05-11 17:00 - 2022-03-06 09:19 - 000000000 _____ C:\hsrv.txt
2026-05-11 17:00 - 2015-03-28 21:59 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2026-05-11 17:00 - 2015-03-07 14:51 - 000000000 __SHD C:\Users\Jiri\IntelGraphicsProfiles
2026-05-11 17:00 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-05-11 16:57 - 2021-03-13 12:16 - 000003950 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{4EAC9B19-D03F-4901-8EFD-291C9946C3F0}
2026-05-10 23:46 - 2015-04-20 18:19 - 000000000 ____D C:\Mix
2026-05-10 08:41 - 2015-03-08 21:04 - 000000000 ____D C:\Users\Jiri\AppData\Roaming\Microsoft\Excel
2026-05-09 13:49 - 2024-12-28 11:08 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-05-09 13:48 - 2018-01-25 00:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-05-05 17:18 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2026-05-02 08:16 - 2024-11-22 22:51 - 000002059 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2026-04-14 21:06 - 2024-11-22 22:51 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2026-04-11 14:01 - 2017-03-22 23:14 - 000000000 _____ C:\libSRTP_log.txt
2026-04-11 12:47 - 2015-03-10 19:40 - 000000000 ____D C:\Users\Jiri\AppData\Local\ElevatedDiagnostics
2026-04-11 08:06 - 2021-12-22 11:05 - 000003538 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-04-11 08:06 - 2021-12-22 11:05 - 000003408 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
==================== Files in the root of some directories ========
2023-02-26 23:21 - 2023-02-26 23:21 - 059548552 _____ (Microsoft Corporation) C:\Program Files (x86)\OneDriveSetup.exe
2017-12-17 00:34 - 2017-12-17 00:36 - 000002697 _____ () C:\Users\Jiri\AppData\Roaming\droid4xinstaller.log
2020-12-09 12:01 - 2026-01-22 19:35 - 000000027 _____ () C:\Users\Jiri\AppData\Local\.sdpl-system-config4
2015-10-18 14:27 - 2015-11-15 20:28 - 000004096 ____H () C:\Users\Jiri\AppData\Local\keyfile3.drm
2024-08-06 19:50 - 2026-03-02 18:46 - 000007605 _____ () C:\Users\Jiri\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2026-05-08 19:02
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-04-2026
Ran by Jiri (11-05-2026 17:44:08)
Running from C:\download
Microsoft Windows 7 Home Premium Service Pack 1 (X64) (2015-03-07 12:37:38)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2007933777-2661868901-2044359937-500 - Administrators - Disabled)
Guest (S-1-5-21-2007933777-2661868901-2044359937-501 - Limited - Disabled)
Jiri (S-1-5-21-2007933777-2661868901-2044359937-1000 - Administrators - Enabled) => C:\Users\Jiri
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4uKey for Android (HKLM-x32\...\{4uKeyforAndroid}_is1) (Version: 2.8.6.3 - Tenorshare)
A4Tech iWheelWorks 7.66 (HKLM-x32\...\WheelMouse) (Version: - )
ACDSee Trial Version (HKLM-x32\...\ACDSee Trial Version) (Version: - )
Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{36381D51-CC5E-4698-A0CC-E939C75EC9D8}) (Version: 1.5 - Eyeo GmbH)
Adobe Acrobat Reader - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 26.001.21529 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.8.158 - Adobe Systems, Inc.)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
ApowerPDF V3.1.6 (HKLM-x32\...\{99A1CF84-3154-433D-9F73-0A4D4DACBA1A}_is1) (Version: 3.1.6 - Apowersoft LIMITED)
ApowerPDF V4.2.0.418 (HKLM-x32\...\{8691C793-7B2C-46C5-9AB2-AB80D129A5EC}_is1) (Version: 4.2.0.418 - Apowersoft LIMITED)
AVerMedia A815 USB DVB-T 1.0.64.63 (HKLM-x32\...\AVerMedia A815 USB DVB-T) (Version: 1.0.64.63 - AVerMedia TECHNOLOGIES, Inc.)
AVerTV 3D (HKLM-x32\...\InstallShield_{5016185F-05AF-455F-AA70-6B6E5D6D4E70}) (Version: 6.5.2.12 - AVerMedia Technologies, Inc.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\70EE67FB13B2F2BE1F5A57AB193643AEFBA8D39C) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\BE156A27AFEAEA39D6A7C9D25CFA8DAFAF91756B) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (dg_ssudbus) USB (12/02/2015 2.12.1.0) (HKLM\...\85A33267F12961AF9ED9AE799DEDA5E62BEA236F) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (ssudmdm) Modem (12/02/2015 2.12.1.0) (HKLM\...\88ED314360B98E6E82E7CC3201FAEB4A9FD291B4) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (WinUSB) AndroidUsbDeviceClass (12/02/2015 2.12.1.0) (HKLM\...\701281E8283E9E3681220099A9DA5013A5A437AF) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CPUID CPU-Z 2.08 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.08 - CPUID, Inc.)
CrystalDiskInfo 8.0.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 8.0.0 - Crystal Dew World)
Droid4X (HKLM-x32\...\Droid4X) (Version: 0.10.6 - Haiyu Dongxiang Co.,Ltd.)
DroidCam Client (HKLM-x32\...\DroidCam) (Version: 6.5.2 - DEV47APPS)
DU Meter (HKLM-x32\...\dumeter3_is1) (Version: - Hagel Technologies)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 109.0.5414.120 - Google LLC)
Intel(R) Chipset Device Software (HKLM\...\{98841A35-1CBE-4EA3-BFF5-F3E3AD894666}) (Version: 10.0.20 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.31.1000 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{8C791A9C-B26E-4E09-8D87-3348AAE61B4A}) (Version: 10.0.31.1000 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{9F75A0EC-6773-4116-9D07-ABC427273606}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) ME UninstallLegacy (HKLM\...\{DBC3205C-2A41-490A-8EE4-BE4993FC2EC6}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4264 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\...\{20F70BB1-9240-43D2-985C-A8F5C6AAA1C7}) (Version: 5.0.10.2907 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.34 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{d370215a-d003-43ae-a3b6-1028af64d5a1}) (Version: 10.0.20 - Intel(R) Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{1B444AF9-1DBE-4884-8F35-969BEFCF69A8}) (Version: 1.35.133.1 - Intel Corporation) Hidden
Java 8 Update 391 (HKLM-x32\...\{71324AE4-039E-4CA4-87B4-2F32180391F0}) (Version: 8.0.3910.13 - Oracle Corporation)
JDownloader 2 (HKLM-x32\...\jdownloader2) (Version: 2.0.1 - AppWork GmbH)
JPEG ReSizer (remove only) (HKLM-x32\...\JPEG ReSizer) (Version: - )
KDE Connect (HKLM-x32\...\KDE Connect) (Version: 23.04.0 - KDE e.V.)
KEMailKb (HKLM-x32\...\KEMailKb) (Version: - )
KONICA MINOLTA PagePro 1400W (HKLM\...\KONICA MINOLTA PagePro 1400W) (Version: - )
Microsoft .NET Framework 4.7.2 (CSY) (HKLM\...\{F4C44834-E4FA-3DA9-B999-A30EC54E95B0}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{09CCBE8E-B964-30EF-AE84-6537AB4197F9}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 109.0.1518.140 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0405-1000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}) (Version: - Microsoft) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}) (Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (HKLM\...\{3061DCA5-2D0B-48F9-800F-9D7C1FEB5E78}) (Version: 4.9.0218.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026 (HKLM-x32\...\{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026 (HKLM-x32\...\{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Mozilla Firefox ESR (x64 en-US) (HKLM\...\Mozilla Firefox 115.35.2 ESR (x64 en-US)) (Version: 115.35.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 115.18.0 - Mozilla)
MPC-HC 1.7.8 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.8 - MPC-HC Team)
MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.14 - F.J. Wechselberger)
Nokia Connectivity Cable Driver (HKLM-x32\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM-x32\...\{866C4563-ED53-43F3-A29D-8BEE2BD1BA3C}) (Version: 7.1.180.94 - Nokia) Hidden
Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
OpenVPN 2.4.3-I602 (HKLM\...\OpenVPN) (Version: 2.4.3-I602 - OpenVPN Technologies, Inc.)
Opera Stable 79.0.4143.22 (HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\Opera 79.0.4143.22) (Version: 79.0.4143.22 - Opera Software)
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.5.2 - pdfforge GmbH)
PDFsam Basic (HKLM-x32\...\{0314BB4C-2B68-491C-B4FB-40F1EC6CA881}) (Version: 3.30.5.0 - Andrea Vacondio)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.90.826.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7399 - Realtek Semiconductor Corp.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.7.43.0 - Samsung Electronics Co., Ltd.)
Sejda PDF Desktop (HKLM\...\{0C82176E-0356-4FA0-B7A8-E210A068BE9E}) (Version: 7.1.3 - Sejda BV)
Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.22083.3 - Samsung Electronics Co., Ltd.) Hidden
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.22083.3 - Samsung Electronics Co., Ltd.)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.2.2756 - TeamViewer)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51 - Ghisler Software GmbH)
TrackChecker version 1.0.15.481 (HKLM-x32\...\{73C4CE23-8D4C-4B67-B1DC-30533208DC3F}_is1) (Version: 1.0.15.481 - )
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VdhCoApp 1.2.4 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper)
VIA Platforma Ovladače zařízení (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.)
VLC media player 2.0.1 (HKLM-x32\...\VLC media player) (Version: 2.0.1 - VideoLAN)
X-Lite 3.0 (HKLM-x32\...\X-Lite 3.0_is1) (Version: - CounterPath Solutions Inc.)
Zoom (HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\ZoomUMX) (Version: 5.17.7 (31859) - Zoom Video Communications, Inc.)
Chrome apps:
============
WhatsApp Web (HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\...\56ad8c9975e42fcc459efbb7377529d1) (Version: 1.0 - Google\Chrome)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Acrobat Elements\ContextMenuShim64.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Program Files (x86)\MyPhoneExplorer\DLL\ShellMgr.dll [2010-03-30] (F.J. Wechselberger) [File not signed]
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => -> No File
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-01-29] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-08-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
ShortcutWithArgument: C:\Users\Jiri\Desktop\Rekola.cz.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gnncbodkhiiofienjhmnjoececnpkgil
ShortcutWithArgument: C:\Users\Jiri\Desktop\WhatsApp Web.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hnpfjngllnobngcgfapefoaidbinmjnm
ShortcutWithArgument: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Pocket.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=mjcnijlhddpbdemagnpefmlkjdagkogk
ShortcutWithArgument: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Rekola.cz.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gnncbodkhiiofienjhmnjoececnpkgil
ShortcutWithArgument: C:\Users\Jiri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\WhatsApp Web.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hnpfjngllnobngcgfapefoaidbinmjnm
==================== Loaded Modules (Whitelisted) =============
2015-03-08 21:26 - 2003-07-06 17:10 - 000011264 _____ () [File not signed] C:\Program Files (x86)\Capture\HoverKHook.dll
2022-04-16 22:46 - 2011-04-15 15:59 - 000102912 _____ () [File not signed] C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\EasyHook64.dll
2020-09-12 22:02 - 2020-09-12 22:02 - 000160768 _____ () [File not signed] C:\Program Files (x86)\DroidCam\lib\DroidCamFilter64.ax
2020-05-28 16:41 - 2012-08-31 23:07 - 000110592 _____ (AVerMedia Technologies, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\dll\CardID.dll
2020-05-28 16:41 - 2011-07-21 18:40 - 000368640 _____ (AVerMedia Technologies, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\dll\GraphMaster.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000049152 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\CDRomUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000053248 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\ComFnUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000053248 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\DialCnt.Dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000073728 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\LgKCUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000061440 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\MixerUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000122880 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\OSDUtl.dll
2015-03-08 21:38 - 2004-07-26 08:50 - 000049152 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\RgnMaker.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000061440 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\SzUPFUtl.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000061440 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\TkBarUtl.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000049152 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\USBKBKC.dll
2015-03-08 21:38 - 2004-07-26 08:51 - 000053248 _____ (Dritek System Inc.) [File not signed] C:\Program Files (x86)\KEMailKb\Wnd2File.dll
2005-02-01 20:28 - 2005-02-01 20:28 - 000073728 _____ (Hagel Technologies) [File not signed] C:\Program Files (x86)\DU Meter\DUData.dll
2015-03-07 14:56 - 2014-06-27 12:30 - 000074240 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.dll
2017-12-12 18:57 - 2016-01-19 18:18 - 000489984 _____ (Newtonsoft) [File not signed] [File is in use] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\Newtonsoft.Json.dll
2012-06-26 13:08 - 2012-06-26 13:08 - 000026624 _____ (Nokia) [File not signed] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
2012-06-26 11:58 - 2012-06-26 11:58 - 001262592 _____ (Nokia) [File not signed] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\NGSCM64.DLL
2012-06-26 13:08 - 2012-06-26 13:08 - 000572928 _____ (Nokia) [File not signed] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
2017-06-21 23:49 - 2017-06-21 23:49 - 000116224 _____ (pdfforge GmbH) [File not signed] C:\Windows\System32\pdfcmon.dll
2017-12-12 18:57 - 2016-01-28 18:11 - 000072704 _____ (Wondershare) [File not signed] [File is in use] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppCollect.dll
2017-12-12 18:57 - 2016-01-28 18:11 - 000316416 _____ (Wondershare) [File not signed] [File is in use] C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppCommon.dll
2023-06-08 12:49 - 2023-05-29 21:40 - 008684032 _____ (wondershare) [File not signed] C:\ProgramData\Wondershare\wsServices\WsidClient.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [135]
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Version 11) (Whitelisted) =============
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.speedbit.com/?aff=dap10_vlc
SearchScopes: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000 -> DefaultScope {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = hxxp://search.speedbit.com/search.aspx?aff=dap10_vlc&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2007933777-2661868901-2044359937-1000 -> {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = hxxp://search.speedbit.com/search.aspx?aff=dap10_vlc&q={searchTerms}
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH -> Eyeo GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre-1.8\bin\ssv.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre-1.8\bin\jp2ssv.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH -> Eyeo GmbH)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2017-01-16 01:37 - 000000826 _____ C:\Windows\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 1.1.1.1 - 1.0.0.1
Windows Firewall is enabled.
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\PC Connectivity Solution\;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\OpenVPN\bin
HKU\S-1-5-21-2007933777-2661868901-2044359937-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\ACD Wallpaper.bmp
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{2C93F763-D753-4CEF-B1E2-5A7DBD2C8B3B}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe => No File
FirewallRules: [UDP Query User{916379AD-13EC-422C-AB4C-261A255C68E4}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe => No File
FirewallRules: [TCP Query User{B3711565-CF8E-4B30-8A9E-DCFE6E4F155C}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe => No File
FirewallRules: [UDP Query User{24663761-CBB9-4A10-B40F-1B236872B15F}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe => No File
FirewallRules: [TCP Query User{891F5987-D666-4010-B5E7-65CA15A3F001}C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{E508B613-1E71-4DB1-A612-1863F5F02C1A}C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [TCP Query User{A54D03D3-6478-44EA-A72D-119092ED639E}C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{1D527C97-FA9E-43E8-A2EC-F331DF90766D}C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [TCP Query User{87ECE67F-49AE-4B0F-8CEE-02319B73D617}C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{0133A6E0-E23C-47C2-90A4-2F0A8C9DAA7F}C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{5CB2D195-63F9-4BEF-86A5-F4F4CF396933}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [UDP Query User{98837934-6D03-4DF9-80B0-A5A6E6964330}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [TCP Query User{AAB77AE4-5569-4DED-8C69-2E36B090F51D}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [UDP Query User{7D430B11-FA81-4A4F-A0A9-9E94FB6019F3}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [TCP Query User{6CAF0716-5438-4B6B-BAB0-174F3E4D303A}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [UDP Query User{0FA9A6CF-8467-4E18-88B8-2C87047D2664}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe => No File
FirewallRules: [TCP Query User{34318E61-236A-4AF3-A13F-C320CA1900DE}C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe] => (Allow) C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe => No File
FirewallRules: [UDP Query User{AD9EA34F-C620-4CD3-9EE2-A7BAB3B80122}C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe] => (Allow) C:\users\jiri\appdata\local\skypeplugin\7.13.0.71\pluginhost.exe => No File
FirewallRules: [TCP Query User{0D1009DF-0141-4D79-B662-AEC7D11F5986}C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{52A905C9-3742-49A1-89B3-F718CEDB7A1B}C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{8C7EFB65-5309-4EC7-96AF-591BE5074459}C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{43854F11-11B3-4D87-A9AB-43D2C064F3B4}C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{CDAA3B61-7FD7-4782-8493-80B1B5377F46}C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{5CF0285F-A24F-44D4-B71A-85A960B90841}C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_111\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{9C6A49E8-CED1-4072-ABBC-A134EE9AE734}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [UDP Query User{36FCEB94-AFB8-40C4-9AFD-9DA6ECAF27B9}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [{8F186614-565B-42EF-BECE-BF6703BCAE88}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{D8584DE3-E45A-4B36-B2E9-EC40697F9143}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{2AFC6A47-F05F-4FAC-9368-0CE048FDD60C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{2443D2F0-68EB-4411-8055-318EE248E539}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{19BB08C4-C448-4871-A1B6-C8BF0F229BBB}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [UDP Query User{BC35AE64-47BE-40C0-B609-39134F8CAC1E}C:\program files (x86)\x-lite\x-lite.exe] => (Allow) C:\program files (x86)\x-lite\x-lite.exe () [File not signed]
FirewallRules: [TCP Query User{264C4E18-E083-455D-84F4-450AD78A28C8}C:\users\jiri\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\jiri\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe (ShenZhen Thunder Networking Technologies Ltd. -> 深圳市迅雷网络技术有限公司)
FirewallRules: [{3ABD33A1-7BC9-49AC-9114-7404EC7EE323}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe (北京海誉动想科技股份有限公司 -> )
FirewallRules: [{105A224C-B9F7-435E-BEEC-C132C1B7537E}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe (北京海誉动想科技股份有限公司 -> 深圳市迅雷网络技术有限公司)
FirewallRules: [{C1041802-A366-4DB6-A9E4-8EEA06E6297B}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe (北京海誉动想科技股份有限公司 -> 深圳市迅雷网络技术有限公司)
FirewallRules: [{E1914EDF-CB8A-45F5-AA43-0E3B88F7E4F2}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe (Oracle Corporation -> )
FirewallRules: [TCP Query User{F15D6B69-5303-4452-9247-B28985E5AD34}C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{07FE7E39-ED13-4153-9B7D-4660545D9BD4}C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\launch4j-tmp\frd.exe => No File
FirewallRules: [{66822E0D-4ED7-46A7-9D8F-AD728AEFF4EA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F68E8E38-FFBF-45A0-B053-F722AB103762}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{89C88373-4901-4623-BED7-CDF7BB5D4866}C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{7592A735-E666-400B-9484-EFA7A3D659F9}C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_161\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{A13D7054-15D0-430F-BB43-6F29299569FF}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [UDP Query User{909781C3-FB4C-48A1-9C5C-E4D3C90D665E}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Block) C:\program files (x86)\wondershare\mobilego\mobilego.exe => No File
FirewallRules: [{4523FD65-0A35-42D9-8280-B3926732E584}] => (Allow) C:\Users\Jiri\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe => No File
FirewallRules: [{D3148B9A-5730-4C8E-AD83-5C2D75526BF0}] => (Allow) C:\Users\Jiri\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe => No File
FirewallRules: [TCP Query User{BAA1B0BA-6054-47C0-9FC8-20C06C702A89}C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{89E3AB94-E0FF-4495-9E12-944EE1568105}C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_221\launch4j-tmp\frd.exe => No File
FirewallRules: [{C2A54D01-2DA6-4DB8-9452-673C35BEDAC4}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File
FirewallRules: [TCP Query User{FEA1866E-582B-4897-ACC6-B376CB8CC194}C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{F71C02E5-4737-48DA-9DCA-AD1134FBFF7E}C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_251\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{5F50EB04-B166-4CC4-9808-CCBE4A55DAF2}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [UDP Query User{A30D9A0E-BE95-4814-9E14-70A162B99EBB}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{7C679329-F4E7-4372-A56C-3BEA1FF49469}] => (Block) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{85AD6805-402E-426D-8FF0-6471E53F1BC9}] => (Block) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [TCP Query User{5288C46A-E1BE-4299-80F1-B42D12DEE0F7}C:\users\jiri\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jiri\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [UDP Query User{DF6E2E7D-4B80-401F-9111-7A8EC28D30CD}C:\users\jiri\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jiri\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [TCP Query User{E37D0F96-2DCF-4443-8971-BC54A76D93A3}C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{E219A0B2-E808-48FF-B120-8CF493B60159}C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_261\launch4j-tmp\frd.exe => No File
FirewallRules: [{81016E7F-69D4-4065-813C-838C86960C17}] => (Allow) C:\Users\Jiri\AppData\Local\Programs\Opera\79.0.4143.22\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{36D46ED6-CE11-4A45-B35D-8D2E6700BED5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{A19D449C-F873-4D93-B601-2157315670A6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{4FA42D9F-4353-477F-91D6-BBC8425524EF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{8B17D4B0-1936-49B3-A908-4A96B87D068A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{10356C70-255D-4EF8-BBAF-64F51ED963BE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{5B368D71-11A9-4E36-9EA2-6197E98727D5}C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe => No File
FirewallRules: [UDP Query User{EA1D36CE-A939-453A-AB94-2E5D80B4B48A}C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_351\launch4j-tmp\frd.exe => No File
FirewallRules: [TCP Query User{DE0DCC93-41A3-4715-9DB6-054070B2D6BC}C:\program files\kde connect\bin\kdeconnectd.exe] => (Allow) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [UDP Query User{243F32BE-336D-4F03-B185-19BED5629CD0}C:\program files\kde connect\bin\kdeconnectd.exe] => (Allow) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [TCP Query User{3A4CB460-756C-4D5B-8D75-B7B957595C05}C:\program files\kde connect\bin\kdeconnectd.exe] => (Block) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [UDP Query User{5AD75EB9-0191-4A80-A5BD-4494A71094CD}C:\program files\kde connect\bin\kdeconnectd.exe] => (Block) C:\program files\kde connect\bin\kdeconnectd.exe (K Desktop Environment e.V. -> )
FirewallRules: [{ABA6C096-4C6E-4DF9-B2A3-FF0115C7455F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{03DF3778-435B-4FB3-A8D7-9FC6ACBA5E3E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{CCC99412-69C8-4AFC-B3D6-E3956D513B7F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D2969A1C-8624-4D29-8113-0A8AA743CA78}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8AB2EB85-DE7E-438D-A241-DCF01E2555B8}] => (Allow) C:\program files (x86)\wondershare\drfone\drfonetoolkit.exe => No File
FirewallRules: [{06A3B7CD-7CE3-4A50-90EE-CF28E0E38E4C}] => (Allow) C:\download\4ukey-for-android.exe (Tenorshare Co., Ltd. -> Tenorshare Co., Ltd.)
FirewallRules: [{504262CD-D67D-42ED-9918-92DA4388BB51}] => (Allow) C:\download\4ukey-for-android.exe (Tenorshare Co., Ltd. -> Tenorshare Co., Ltd.)
FirewallRules: [TCP Query User{9B5D2413-FC8C-4F8F-95EB-03392CD2B529}C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{0A7004D4-A707-4E8C-948B-16E56F87B745}C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre-1.8\launch4j-tmp\frd.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [{1DECEA78-E2A8-41C9-B35E-D9E5188575CE}] => (Allow) C:\Users\Jiri\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{66E5DE99-FB76-40CD-B660-59DF4E3CC30C}] => (Allow) C:\Users\Jiri\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{B094926C-1A12-4AA8-888E-875B7020C885}] => (Allow) C:\Users\Jiri\AppData\Roaming\Zoom\bin\airhost.exe => No File
==================== Restore Points =========================
04-05-2026 19:29:34 Naplánovaný kontrolní bod
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (05/11/2026 05:00:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/11/2026 04:54:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/11/2026 05:46:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CompatTelRunner.exe, verze: 10.0.14275.1000, časové razítko: 0x56e8dec4
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.23539, časové razítko: 0x57c99bd4
Kód výjimky: 0xc06d007e
Posun chyby: 0x000000000001a06d
ID chybujícího procesu: 0x1150
Čas spuštění chybující aplikace: 0x01dce0f8ca49189a
Cesta k chybující aplikaci: C:\Windows\system32\CompatTelRunner.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: 0f82a421-4cec-11f1-9af3-448a5bcb771c
Error: (05/11/2026 05:43:50 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/10/2026 08:24:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CompatTelRunner.exe, verze: 10.0.14275.1000, časové razítko: 0x56e8dec4
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.23539, časové razítko: 0x57c99bd4
Kód výjimky: 0xc06d007e
Posun chyby: 0x000000000001a06d
ID chybujícího procesu: 0x11d8
Čas spuštění chybující aplikace: 0x01dce045a344e506
Cesta k chybující aplikaci: C:\Windows\system32\CompatTelRunner.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: e9e2e295-4c38-11f1-96fa-448a5bcb771c
Error: (05/10/2026 08:21:23 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/09/2026 08:31:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CompatTelRunner.exe, verze: 10.0.14275.1000, časové razítko: 0x56e8dec4
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.23539, časové razítko: 0x57c99bd4
Kód výjimky: 0xc06d007e
Posun chyby: 0x000000000001a06d
ID chybujícího procesu: 0xf54
Čas spuštění chybující aplikace: 0x01dcdf7d4fb1dc82
Cesta k chybující aplikaci: C:\Windows\system32\CompatTelRunner.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: c80a5aff-4b70-11f1-96c1-448a5bcb771c
Error: (05/09/2026 08:27:21 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
System errors:
=============
Error: (05/11/2026 05:47:09 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {BB6DF56B-CACE-11DC-9992-0019B93A3A84} se v daném časovém limitu neregistroval u služby DCOM.
Error: (05/11/2026 05:45:31 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
Error: (05/11/2026 05:45:31 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.
Error: (05/11/2026 05:45:09 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.
Error: (05/11/2026 05:45:09 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
Error: (05/11/2026 05:44:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
Error: (05/11/2026 05:44:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.
Error: (05/11/2026 05:44:52 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.
==================== Memory info ===========================
BIOS: American Megatrends Inc. V17.3 07/01/2014
Motherboard: MSI H81M-E34 (MS-7817)
Processor: Intel(R) Celeron(R) CPU G1840 @ 2.80GHz
Percentage of memory in use: 94%
Total physical RAM: 3972.53 MB
Available physical RAM: 220.65 MB
Total Virtual: 7943.25 MB
Available Virtual: 1616.39 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:119.14 GB) (Free:2.26 GB) (Model: Crucial_CT128M550SSD1 ATA Device) NTFS
Drive e: () (Fixed) (Total:39.06 GB) (Free:20.48 GB) (Model: WDC WD1600JS-00MHB0 ATA Device) NTFS
Drive f: () (Fixed) (Total:109.98 GB) (Free:17.85 GB) (Model: WDC WD1600JS-00MHB0 ATA Device) NTFS
\\?\Volume{f02c6443-c4c5-11e4-8d6b-806e6f6e6963}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 119.2 GB) (Disk ID: CD98BD4A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS)
==========================================================
Disk: 1 (Size: 149 GB) (Disk ID: D967D967)
Partition 1: (Active) - (Size=39.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=110 GB) - (Type=0F Extended)
==================== End of Addition.txt =======================