Stránka 1 z 1

kontrola logu

Napsal: 27 kvě 2026 19:31
od Trejsi91
Dobrý den, prosím o kontrolu logu. Google psal, že část uložených hesel uniklo na web, ať si je změním. Dnes se někdo pokoušel přihlásit na můj facebook.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2026
Ran by i7 6700 es (administrator) on JF (27-05-2026 20:23:16)
Running from C:\Users\i7 6700 es\Desktop\FRST64.exe
Loaded Profiles: i7 6700 es
Platform: Microsoft Windows 11 Pro Version 25H2 26200.8457 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\Bitdefender Agent\ProductAgentService.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\27.1.1.38\DiscoverySrv.exe
(C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdntwrk.exe
(C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe ->) (S.C. BITDEFENDER S.R.L. -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\wsccommunicator.exe
(C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\downloader.exe
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> ) C:\Program Files\TeamViewer\crashpad_handler.exe
(C:\Program Files\WindowsApps\Microsoft.BingWallpaper_1.1.452.0_x86__8wekyb3d8bbwe\BingWallpaper.exe ->) (Microsoft Corporation -> Microsoft Corp.) C:\Users\i7 6700 es\AppData\Local\Temp\bwpf17d98de-0178-4372-9e38-4ce0ef2349c6\UnInstDaemon.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\i7 6700 es\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\redline\bdredline.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security App\Safepay\bdservicehost.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe <3>
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(services.exe ->) (Flexera Software LLC -> Flexera) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (HP Inc.) [File not signed] C:\nazev\Intel_i7_speed.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_f4c7a2fd13e0f763\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.BingWallpaper_1.1.452.0_x86__8wekyb3d8bbwe\BingWallpaper.exe
(svchost.exe ->) (Environmental Systems Research Institute Inc. -> Esri) C:\Program Files\ArcGIS\Pro\bin\ArcGISIndexingServer.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.264.3.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SoftLandingTask\SoftLandingTask.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BdagentApp] => C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe [1091400 2026-05-26] (Bitdefender SRL -> Bitdefender)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe [1091400 2026-05-26] (Bitdefender SRL -> Bitdefender)
HKLM-x32\...\Run: [Family Tree Builder Update] => C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe [18623680 2023-10-05] (MyHeritage (USA) Inc. -> MyHeritage)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37460384 2025-08-16] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [Discord] => C:\Users\i7 6700 es\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\Office16\lync.exe [27141264 2024-05-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [Wargaming.net Game Center] => E:\Game\Wargaming.net\GameCenter\wgc.exe [2581240 2026-05-09] (Wargaming Group Limited -> Wargaming.net)
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [BingWallpaperDaemon] => C:\Users\i7 6700 es\AppData\Local\Temp\bwpf17d98de-0178-4372-9e38-4ce0ef2349c6\UnInstDaemon.exe [69432 2026-05-21] (Microsoft Corporation -> Microsoft Corp.) <==== ATTENTION
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [BingSvc] => C:\Users\i7 6700 es\AppData\Local\Microsoft\BingSvc\BingSvc.exe [3279408 2025-05-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [MicrosoftEdgeAutoLaunch_3004125DB9EAF8C14B3AA649BEF00AAF] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5168488 2026-05-21] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\HP E111 Status Monitor: C:\Windows\system32\hpinkstsE111LM.dll [393352 2017-04-14] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3971224 2026-04-18] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\148.0.7778.216\Installer\chrmstp.exe [7617688 2026-05-27] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {38024ED7-B5B0-481E-A01D-F86D232E19C2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {380F6D75-D3B0-415E-BBB5-C7E90923A295} - System32\Tasks\ArcGIS Pro Indexing (DESKTOP-62BVS3B_i7 6700 es) => C:\Program Files\ArcGIS\Pro\bin\ArcGISIndexingServer.exe [1095048 2020-07-09] (Environmental Systems Research Institute Inc. -> Esri)
Task: {D37C1D87-6A3E-425B-865A-403AC0929CD4} - System32\Tasks\avfree.migration => C:\Program Files\Bitdefender Antivirus Free\migration_tool\avfree.migration.exe /run (No File)
Task: {F5938EE0-8785-4478-A7F8-C63AFC004E61} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\27.1.1.38\WatchDog.exe [1191048 2026-04-24] (Bitdefender SRL -> Bitdefender) -> C:\Program Files\Bitdefender Agent\27.1.1.38\repair
Task: {9E706C7E-D9D8-401A-9AC4-4FFDDA39D6AD} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (No File)
Task: {7B531F5E-3758-4D51-89CD-FC432DC8010A} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{A2D70FD1-4DE9-4EA6-A1B1-E7795D19C13A} => C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe [8770200 2026-04-28] (Google LLC -> Google LLC)
Task: {05DE85E3-1F46-4A31-ACC7-60C652ECCC1E} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95240 2026-04-27] (HP Inc. -> HP Inc.)
Task: {6AF3D4BE-8C5D-4B5F-8FC9-F3B00439E3B6} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95240 2026-04-27] (HP Inc. -> HP Inc.)
Task: {6A56AEE1-56BC-4C4E-A0FD-6F976138969B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [336104 2024-11-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {C06B46FA-BEB2-4E44-BD2C-B006968BEA30} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {722F4B6B-859F-4D8C-A6C3-2B0A374CD50E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {4A339509-D6E8-4337-9B59-F361D5467B8E} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => %SystemRoot%\system32\clipesu.exe (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {5EDBFB5E-0460-4689-94FF-D69DBF5FC7F9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\Windows\System32\MRT.exe [220340424 2026-05-13] (Microsoft Windows -> Microsoft Corporation) -> C:\WINDOWS\system32\/EHB /HeartbeatFailure "SubmitHeartbeatReportData" /HeartbeatError "0x80072ee7"
Task: {A4A930F1-A627-401D-AE95-34BF330DBE89} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe RebootDialog (No File)
Task: {A0E9926A-A2B0-4D32-A64D-4427D1E51EAA} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC EngagedRebootReminder (No File)
Task: {F393C700-BDA8-4C93-B5B4-733E910C0F20} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery EngagedRebootReminder (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {DA1C1047-C058-41A9-9613-75B9AD3333D5} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9CFA7D83-B202-42FC-A859-81227C49B149} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {50C87A89-78A3-4A14-A901-8293A0872C17} - System32\Tasks\Ubisoft\Ubisoft Connect Background Update => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe [17246392 2025-12-22] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
Task: {5618B5E7-5914-4D45-AA6C-564BD9DFE389} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2238547156-67230461-3934341949-1001 => C:\Users\i7 6700 es\AppData\Roaming\Zoom\bin\Zoom.exe [507784 2026-03-16] (Zoom Communications, Inc. -> Zoom Communications, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1147a319-b0c4-438b-882b-cc0f19485cc1}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1147a319-b0c4-438b-882b-cc0f19485cc1}: [DhcpDomain] home
Tcpip\..\Interfaces\{5b040860-0ec2-4306-bbe3-a18fdb0ff94b}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6ae8cab2-d547-4564-b4ed-41f00695f75d}: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2024-05-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\i7 6700 es\AppData\Local\Microsoft\Edge\User Data\Default [2026-05-16]
Edge Extension: (Dokumenty Google offline) - C:\Users\i7 6700 es\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-26]
Edge Extension: (TinEye Reverse Image Search) - C:\Users\i7 6700 es\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2025-02-15]
Edge Extension: (Edge relevant text changes) - C:\Users\i7 6700 es\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-25]
Edge Extension: (AVG Online Security) - C:\Users\i7 6700 es\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nbmoafcmbajniiapeidgficgifbfmjfo [2025-11-14]
Edge Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\i7 6700 es\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2026-05-16]

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\i7 6700 es\AppData\Local\Google\Chrome\User Data\Default [2026-05-27]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://captcharesolver.com; hxxps://cs.gov-civil-setubal.pt; hxxps://eobuv.cz; hxxps://fastshare.cz; hxxps://fera24.cz; hxxps://keepvid.digital; hxxps://mp3download.to; hxxps://re-captha-version-3-51.top; hxxps://recepty.tvojekucharka.cz; hxxps://teams.microsoft.com; hxxps://web.skype.com; hxxps://worldwide-incoming-news.com; hxxps://www.ador.com; hxxps://www.aliexpress.com; hxxps://www.astratex.cz; hxxps://www.beler.cz; hxxps://www.bezvasport.cz; hxxps://www.chess.com; hxxps://www.eurosport.com; hxxps://www.facebook.com; hxxps://www.gfinityesports.com; hxxps://www.idnes.cz; hxxps://www.izlato24.cz; hxxps://www.letour.fr; hxxps://www.megaknihy.cz; hxxps://www.netflix.com; hxxps://www.pinterest.co.uk; hxxps://www.proficyklodresy.cz; hxxps://www.reddit.com; hxxps://www.slevomat.cz; hxxps://www.studentagency.cz; hxxps://www.superzoo.cz; hxxps://www.ticketmaster.cz; hxxps://www.whats-on-netflix.com; hxxps://www.wish.com; hxxps://www.youtube.com; hxxps://www22.davisonbarker.pro; hxxps://yt1s.com
CHR Extension: (change-language) - C:\Users\i7 6700 es\AppData\Local\Google\Chrome\User Data\Default\Extensions\cofdbpoegempjloogbagkncekinflcnj [2026-05-26]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\i7 6700 es\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-15]
CHR Extension: (Dokumenty Google offline) - C:\Users\i7 6700 es\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-05-27]
CHR Extension: (AdBlock - nejlepší blokátor reklam) - C:\Users\i7 6700 es\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2026-05-26]
CHR Extension: (AVG Online Security) - C:\Users\i7 6700 es\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbmoafcmbajniiapeidgficgifbfmjfo [2025-11-13]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\i7 6700 es\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR HKU\S-1-5-21-2238547156-67230461-3934341949-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 BDAppSrv; C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe [858432 2026-05-26] (Bitdefender SRL -> Bitdefender)
R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858944 2026-05-26] (Bitdefender SRL -> Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858944 2026-05-26] (Bitdefender SRL -> Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2966176 2023-07-20] (Bitdefender SRL -> Bitdefender)
R2 bdredline_agent; C:\Program Files\Bitdefender Agent\redline\bdredline.exe [2426992 2025-07-03] (Bitdefender SRL -> Bitdefender)
R2 BDSafepaySrv; C:\Program Files\Bitdefender\Bitdefender Security App\Safepay\bdservicehost.exe [858944 2026-05-26] (Bitdefender SRL -> Bitdefender)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [18663720 2024-08-04] (BattlEye Innovations e.K. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2020-02-29] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 EpicGamesUpdater; C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3071904 2025-08-16] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2022-11-16] (Epic Games Inc. -> Epic Games, Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [244232 2026-04-27] (HP Inc. -> HP Inc.)
R2 Intel_rules; C:\nazev\Intel_i7_speed.exe [12288 2019-05-28] (HP Inc.) [File not signed]
S4 Intel_speed_steps; C:\nazev\Intel_i7_speed.exe [12288 2019-05-28] (HP Inc.) [File not signed]
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2025-02-28] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_f4c7a2fd13e0f763\Display.NvContainer\NVDisplay.Container.exe [1275624 2026-02-17] (NVIDIA Corporation -> NVIDIA Corporation)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [770536 2026-04-24] (Bitdefender SRL -> Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [811360 2026-02-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [24710448 2025-05-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 UpcElevationService; C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher Core\UpcElevationService.exe [351928 2025-12-22] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [321784 2026-05-26] (Bitdefender SRL -> Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [858944 2026-05-26] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2025-02-28] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2025-02-28] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 atc; C:\WINDOWS\System32\drivers\atc.sys [9168984 2026-05-26] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA)
R3 AtcExt; C:\WINDOWS\System32\drivers\AtcExt.sys [85592 2026-05-26] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA)
R2 BdDci4; C:\WINDOWS\System32\drivers\bddci4.sys [1387096 2026-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [26064 2026-04-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
S3 bdprivmon; C:\WINDOWS\System32\drivers\bdprivmon.sys [49208 2025-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 bduefiscan; C:\WINDOWS\System32\drivers\bduefiscan.sys [53808 2025-10-27] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [577536 2025-05-18] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2025-05-18] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2025-05-18] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 Gemma; C:\WINDOWS\System32\drivers\gemma.sys [1793072 2025-10-27] (Microsoft Windows Hardware Compatibility Publisher -> BitDefender S.R.L. Bucharest, ROMANIA)
S3 Ignisv2; C:\WINDOWS\System32\drivers\ignisv2.sys [848456 2025-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 Trufos; C:\WINDOWS\System32\drivers\Trufos.sys [636504 2026-05-18] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 vlflt; C:\WINDOWS\System32\drivers\vlflt.sys [1447000 2026-05-26] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [22104 2025-02-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [606624 2025-02-28] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105888 2025-02-28] (Microsoft Windows -> Microsoft Corporation)
S2 mbamchameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys (No File)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

Error Reading file: "C:\WINDOWS\system32\tmp000001d5"
2026-05-27 20:23 - 2026-05-27 20:23 - 000711764 _____ C:\WINDOWS\system32\perfh005.dat
2026-05-27 20:23 - 2026-05-27 20:23 - 000152978 _____ C:\WINDOWS\system32\perfc005.dat
2026-05-27 20:23 - 2026-05-27 20:23 - 000025261 _____ C:\Users\i7 6700 es\Desktop\FRST.txt
2026-05-27 20:21 - 2026-05-27 20:21 - 002449408 _____ (Farbar) C:\Users\i7 6700 es\Desktop\FRST64.exe
2026-05-25 18:56 - 2026-05-25 18:56 - 000155659 _____ C:\Users\i7 6700 es\Downloads\Kreditka - nova zadost - FOS IB.pdf
2026-05-21 18:19 - 2026-05-26 21:15 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-05-16 17:33 - 2026-05-16 17:33 - 000752010 _____ C:\Users\i7 6700 es\Downloads\Agrowald 2.pdf
2026-05-16 17:16 - 2026-05-16 17:16 - 001604263 _____ C:\Users\i7 6700 es\Desktop\Agrowald 2.pdf
2026-05-16 17:15 - 2026-05-16 17:15 - 001243819 _____ C:\Users\i7 6700 es\Desktop\Agrowald 1.pdf
2026-05-13 11:38 - 2026-05-13 11:38 - 000000000 ____D C:\WINDOWS\SecureBoot
2026-05-09 20:33 - 2026-05-09 20:33 - 000431385 _____ C:\Users\i7 6700 es\Downloads\Tundra_Sae-.zip
2026-05-09 20:33 - 2026-05-09 20:33 - 000000000 ____D C:\Users\i7 6700 es\Downloads\Tundra_Sae-
2026-05-09 20:33 - 2026-05-09 20:33 - 000000000 ____D C:\Users\i7 6700 es\Documents\Aslain_Modpack_Presets
2026-05-09 20:32 - 2026-05-09 20:32 - 058111526 _____ (Aslain ) C:\Users\i7 6700 es\Downloads\Aslains_WoT_Modpack_Installer_v.2.2.1.2_09.exe
2026-05-01 08:19 - 2026-05-01 08:19 - 000085913 _____ C:\WINDOWS\SysWOW64\ctac.json
2026-05-01 08:19 - 2026-05-01 08:19 - 000085913 _____ C:\WINDOWS\system32\ctac.json
2026-05-01 08:19 - 2026-05-01 08:19 - 000003872 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2026-04-30 17:00 - 2026-04-30 17:00 - 000154604 _____ C:\ProgramData\agent.update.1777561211.bdinstall.v2.bin

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-05-27 20:23 - 2025-05-18 17:36 - 001692324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-05-27 20:23 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-05-27 20:23 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-05-27 20:23 - 2021-10-11 12:05 - 000000000 ____D C:\FRST
2026-05-27 20:22 - 2026-02-12 18:18 - 000000000 ____D C:\Users\i7 6700 es\AppData\Local\Ubisoft Game Launcher
2026-05-27 20:21 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-05-27 20:21 - 2019-05-28 14:29 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-05-27 20:21 - 2019-05-28 14:29 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-05-27 20:18 - 2025-06-02 19:23 - 000000000 ____D C:\Program Files\TeamViewer
2026-05-27 20:18 - 2025-05-18 17:36 - 000086724 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-05-27 20:18 - 2025-05-18 17:36 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-05-27 20:18 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-05-27 20:18 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-05-27 20:18 - 2019-07-26 12:39 - 000000000 ____D C:\ProgramData\NVIDIA
2026-05-27 20:17 - 2020-10-31 22:19 - 000012288 ___SH C:\DumpStack.log.tmp
2026-05-26 21:35 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-05-26 21:35 - 2021-07-25 13:56 - 000000000 ____D C:\Users\i7 6700 es\AppData\Roaming\upjers-playground2
2026-05-26 19:32 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-05-26 19:31 - 2025-03-02 18:42 - 001447000 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\vlflt.sys
2026-05-26 19:30 - 2025-03-03 19:40 - 000085592 _____ (Bitdefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\AtcExt.sys
2026-05-26 19:30 - 2025-03-02 18:42 - 009168984 _____ (Bitdefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2026-05-26 19:21 - 2025-05-18 17:36 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2238547156-67230461-3934341949-1001
2026-05-26 19:21 - 2025-05-18 17:36 - 000003574 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2238547156-67230461-3934341949-1001
2026-05-26 19:21 - 2025-05-18 17:36 - 000003360 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2238547156-67230461-3934341949-1001
2026-05-26 19:21 - 2020-10-31 12:04 - 000002394 _____ C:\Users\i7 6700 es\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-05-25 20:39 - 2019-05-28 09:14 - 000000000 ____D C:\Users\i7 6700 es\AppData\Local\D3DSCache
2026-05-25 18:58 - 2020-10-20 19:14 - 000000000 ____D C:\Users\i7 6700 es\AppData\Roaming\Microsoft\Excel
2026-05-23 20:32 - 2020-09-30 16:55 - 000000000 ____D C:\Users\i7 6700 es\AppData\Local\Steam
2026-05-23 18:56 - 2024-04-01 09:21 - 000065536 _____ C:\WINDOWS\system32\config\ELAM
2026-05-23 08:32 - 2020-09-28 12:36 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-05-18 19:46 - 2025-03-02 18:42 - 000636504 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\Trufos.sys
2026-05-16 16:17 - 2022-10-13 20:16 - 000002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-05-15 19:19 - 2025-10-04 14:34 - 000000000 ____D C:\ProgramData\Whesvc
2026-05-13 11:39 - 2025-05-18 17:33 - 000501944 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-05-13 11:38 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-05-13 11:38 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\SysWOW64\cs
2026-05-13 11:38 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\system32\cs
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-plocm
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-ploc
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\et-EE
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\am-ET
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-05-13 11:38 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-05-13 10:54 - 2025-05-18 17:34 - 003268096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-05-13 10:52 - 2019-05-28 17:05 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-05-13 10:50 - 2019-05-28 17:04 - 220340424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-05-03 08:14 - 2025-05-18 17:33 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-05-01 15:41 - 2025-06-27 13:48 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-05-01 15:41 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-05-01 15:41 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-05-01 15:41 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-05-01 08:26 - 2025-05-18 17:36 - 000003638 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-05-01 08:26 - 2025-05-18 17:36 - 000003512 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-04-30 17:00 - 2025-05-18 17:36 - 000003842 _____ C:\WINDOWS\system32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2026-04-30 17:00 - 2025-03-02 18:41 - 000000000 ____D C:\Program Files\Bitdefender Agent
2026-04-29 18:36 - 2019-08-21 10:30 - 000000000 ____D C:\Users\i7 6700 es\AppData\Roaming\Microsoft\Word
2026-04-27 18:46 - 2025-05-18 17:36 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2026-04-27 18:46 - 2021-05-11 16:28 - 000000000 ____D C:\Program Files\HPPrintScanDoctor

==================== Files in the root of some directories ========

2017-01-14 13:37 - 2017-01-14 13:37 - 002174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2023-11-27 20:21 - 2023-11-27 20:21 - 000000012 _____ () C:\Users\i7 6700 es\AppData\Roaming\2457fe3357cbf1220231e8917326f70f
2021-07-29 17:24 - 2021-09-28 08:06 - 000000615 _____ () C:\Users\i7 6700 es\AppData\Local\oobelibMkey.log

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-05-2026
Ran by i7 6700 es (27-05-2026 20:24:27)
Running from C:\Users\i7 6700 es\Desktop
Microsoft Windows 11 Pro Version 25H2 26200.8457 (X64) (2025-05-18 15:36:45)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-2238547156-67230461-3934341949-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-2238547156-67230461-3934341949-503 - Limited - Disabled)
Guest (S-1-5-21-2238547156-67230461-3934341949-501 - Limited - Disabled)
i7 6700 es (S-1-5-21-2238547156-67230461-3934341949-1001 - Administrators - Enabled) => C:\Users\i7 6700 es
WDAGUtilityAccount (S-1-5-21-2238547156-67230461-3934341949-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AV: Bitdefender Antivirus (Enabled - Up to date) {57FC340E-A75D-133C-CE37-7EC3762140D5}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\uTorrent) (Version: 3.5.5.45798 - BitTorrent Inc.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 26.001.21563 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
ArcGIS Pro - jazyková sada pro češtinu (HKLM\...\{B9A2CA2E-601B-43C0-B322-85927268CC29}) (Version: 2.6.24783 - Environmental Systems Research Institute, Inc.) Hidden
ArcGIS Pro - jazyková sada pro češtinu (HKLM\...\ArcGIS Pro - jazyková sada pro češtinu) (Version: 2.6.24783 - Environmental Systems Research Institute, Inc.)
ArcGIS Pro (HKLM\...\{612674FE-4B64-4254-A9AD-C31568C89EA4}) (Version: 2.6.24783 - Environmental Systems Research Institute, Inc.) Hidden
ArcGIS Pro (HKLM\...\ArcGISPro) (Version: 2.6.24783 - Environmental Systems Research Institute, Inc.)
ArcGIS Pro 2.6 Patch 2 (2.6.2) (HKLM\...\ArcGISPro Update262) (Version: ArcGIS Pro 2.6 Patch 2 (2.6.2) - Environmental Systems Research Institute, Inc.)
Aslain's WoT Modpack verze 2.2.1.2.09 (HKLM-x32\...\Aslains_WoT_Modpack_Installer_is1) (Version: 2.2.1.2.09 - Aslain)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1653.5 - AVAST Software) Hidden
Avatar: FoP CZ v3.1 (HKLM-x32\...\Avatar: FoP CZ) (Version: 3.1 - Squiee)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 27.1.1.38 - Bitdefender)
Bitdefender Antivirus Free (HKLM\...\Bitdefender) (Version: 27.0.47.239 - Bitdefender)
Discord (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Discord) (Version: 1.0.9234 - Discord Inc.)
Elden Ring čeština (HKLM-x32\...\Elden Ring čeština) (Version: 1.00 - FARFLAMOVY ČEŠTINY)
Epic Games Launcher (HKLM-x32\...\{DCE27B29-200D-491A-BBC5-98ECEFEC0843}) (Version: 1.1.257.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{A1EB595F-651D-4A04-99B0-A7065538B33C}) (Version: 2.0.38.0 - Epic Games, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 148.0.7778.216 - Google LLC)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Microsoft .NET 8.0 Templates 8.0.319 (x64) (HKLM\...\{F004CC72-FE79-45B1-A6F6-A75C493C67A0}) (Version: 32.13.62977 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.22 (x64) (HKLM\...\{E8F8575D-45CF-4FEA-A117-75B94AE853E0}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.22 (x64_arm64) (HKLM\...\{FFC716C3-545B-4D70-BF6C-3D0728470438}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.22 (x64_x86) (HKLM\...\{2A4FD089-B7E6-42F7-B11F-9F5EC7B2AD54}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.22 (x64) (HKLM\...\{872CDB4B-5DDE-4297-BD19-C93B6C93E386}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.22 (x64) (HKLM\...\{7A046DD7-9D61-4C5D-8F5E-24EE192B1B6A}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.22 (x64) (HKLM\...\{C43A1A89-0CA5-43FD-BDC4-3B85DAD06A41}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft .NET SDK 8.0.319 (x64) (HKLM-x32\...\{0f5b2e32-3589-49ee-bfa6-5bf2a30369f4}) (Version: 8.3.1925.52801 - Microsoft Corporation)
Microsoft .NET Standard Targeting Pack - 2.1.0 (x64) (HKLM\...\{A7036CFB-B403-4598-85FF-D397ABB88173}) (Version: 24.0.28113 - Microsoft Corporation) Hidden
Microsoft .NET Targeting Pack - 8.0.22 (x64) (HKLM\...\{D9CC2C55-F8FE-4613-911D-634167065E3B}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft .NET Toolset 8.0.319 (x64) (HKLM\...\{B05C9779-6E32-49DC-B838-48A7F8EC3DAC}) (Version: 32.13.62977 - Microsoft Corporation) Hidden
Microsoft Access MUI (Czech) 2016 (HKLM\...\{90160000-0015-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.22 Shared Framework (x64) (HKLM\...\{4675A82C-4BC0-3E41-99B1-25CFCEE2114D}) (Version: 8.0.22.25528 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.22 Targeting Pack (x64) (HKLM\...\{A6F1F643-F412-36F2-9565-7A6920DC1FB3}) (Version: 8.0.22.25528 - Microsoft Corporation) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Bing Service (HKLM-x32\...\{2227F026-F64E-4D72-A2DD-376E29A97EF1}) (Version: 2.0.0.12 - Microsoft Corporation)
Microsoft DCF MUI (Czech) 2016 (HKLM\...\{90160000-0090-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 148.0.3967.83 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 148.0.3967.83 - Microsoft Corporation) Hidden
Microsoft Excel MUI (Czech) 2016 (HKLM\...\{90160000-0016-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Groove MUI (Czech) 2016 (HKLM\...\{90160000-00BA-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft InfoPath MUI (Czech) 2016 (HKLM\...\{90160000-0044-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office 32-bit Components 2016 (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Korrekturhilfen 2016 – Deutsch (HKLM\...\{90160000-001F-0407-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (Czech) 2016 (HKLM\...\{90160000-00E1-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (Czech) 2016 (HKLM\...\{90160000-00E2-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2016 (HKLM\...\{90160000-0011-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft Office Proofing (Czech) 2016 (HKLM\...\{90160000-002C-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2016 - English (HKLM\...\{90160000-001F-0409-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (Czech) 2016 (HKLM\...\{90160000-00C1-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2016 (HKLM\...\{90160000-006E-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\OneDriveSetup.exe) (Version: 26.078.0426.0002 - Microsoft Corporation)
Microsoft OneNote MUI (Czech) 2016 (HKLM\...\{90160000-00A1-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (Czech) 2016 (HKLM\...\{90160000-001A-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (Czech) 2016 (HKLM\...\{90160000-0018-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (Czech) 2016 (HKLM\...\{90160000-0019-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Skype for Business MUI (Czech) 2016 (HKLM\...\{90160000-012B-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{C931A1C6-A7BF-3737-874A-818881A37E1B}) (Version: 10.0.60915 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60910 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.22 (x64) (HKLM\...\{4CCC1CCD-6FA3-4DD5-A06B-E94EA90094CF}) (Version: 64.88.42561 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Targeting Pack - 8.0.22 (x64) (HKLM\...\{019B5E05-8AF0-401A-9E49-9ADA9A21C9DF}) (Version: 64.88.42561 - Microsoft Corporation) Hidden
Microsoft Word MUI (Czech) 2016 (HKLM\...\{90160000-001B-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Android.Manifest-8.0.100 (x64) (HKLM\...\{B5A57BF9-FC7A-4FA6-BAEB-46E173986DF3}) (Version: 34.0.43 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Aspire.Manifest-8.0.100 (x64) (HKLM\...\{F3AEB036-4B8A-4C25-B4D2-850944E909C4}) (Version: 64.0.5426 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.iOS.Manifest-8.0.100 (x64) (HKLM\...\{6BF59E75-BE05-4C69-9C48-3532B6DE0EC5}) (Version: 17.0.8478 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.MacCatalyst.Manifest-8.0.100 (x64) (HKLM\...\{8B5384CA-D189-4CFE-8DF0-2D05B4EA8499}) (Version: 17.0.8478 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.macOS.Manifest-8.0.100 (x64) (HKLM\...\{98927287-8779-447A-919E-73028D53F719}) (Version: 14.0.8478 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Maui.Manifest-8.0.100 (x64) (HKLM\...\{116EF6D0-AE8E-4E6D-B0D8-EFF145CD45DA}) (Version: 8.0.3 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.tvOS.Manifest-8.0.100 (x64) (HKLM\...\{568F99E8-9F2D-48D7-A05D-D64C512B3AFD}) (Version: 17.0.8478 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.Current.Manifest (x64) (HKLM\...\{0EA5BD4D-ABBC-49A9-A514-E9E1BC8F86BA}) (Version: 64.88.42371 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net6.Manifest (x64) (HKLM\...\{00C0E483-9F0D-484D-99E0-CE8770A3EFC8}) (Version: 64.88.42371 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net7.Manifest (x64) (HKLM\...\{3819CE33-6420-43A5-B771-233A61E79978}) (Version: 64.88.42371 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest (x64) (HKLM\...\{56B1202A-22AD-4C92-86BF-DD5431D2DC6D}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest (x64) (HKLM\...\{2AF56535-DB65-488A-8B6A-9EDD96854B38}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest (x64) (HKLM\...\{112A15AD-F200-4575-9759-C4FAFF0A4612}) (Version: 64.88.42551 - Microsoft Corporation) Hidden
MSI Kombustor v4 0.6.3.3 (64-bit) (HKLM-x32\...\{F3D3CC6B-9AD7-4F43-8C69-40D5902FDC5C}}_is1) (Version: - MSI / Geeks3D)
MyHeritage Family Tree Builder (HKLM-x32\...\Family Tree Builder) (Version: 8.0.0.8642 - MyHeritage.com)
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština (HKLM\...\{90160000-001F-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina (HKLM\...\{90160000-001F-041B-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 591.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 591.86 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
Sid Meiers Civilization VI (HKLM-x32\...\Sid Meiers Civilization VI_is1) (Version: 0.0.0 - DODI-Repacks)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.66.5 - TeamViewer)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 2.6.3.0 - Zenimax Online Studios)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 169.5.13021 - Ubisoft)
Update for Skype for Business 2016 (KB5002567) 64-Bit Edition (HKLM\...\{90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{AC7565EF-E108-49D4-9F46-5A1AEC72B27B}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB5002567) 64-Bit Edition (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{AC7565EF-E108-49D4-9F46-5A1AEC72B27B}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB5002567) 64-Bit Edition (HKLM\...\{90160000-012B-0405-1000-0000000FF1CE}_Office16.PROPLUS_{AC7565EF-E108-49D4-9F46-5A1AEC72B27B}) (Version: - Microsoft)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{DA80A019-4C3B-4DAA-ACA1-6937D7CAAF9E}) (Version: 8.94.0.0 - Microsoft Corporation)
upjers Home 2.1.112 (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\e2446448-09eb-5b1b-84b1-6746557362e3) (Version: 2.1.112 - upjers GmbH)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Wand (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\WeMod) (Version: 12.17.0 - WeMod)
Wargaming.net Game Center (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Wargaming.net Game Center) (Version: 26.2.0.2387 - Wargaming.net)
WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 19.21 - NCH Software)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
World of Tanks EU (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\511405571) (Version: - Wargaming.net)
Zoom Workplace (HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\ZoomUMX) (Version: 6.7.8 (32670) - Zoom Communications, Inc.)

Packages:
=========
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2026-05-16] ()
Bing Wallpaper -> C:\Program Files\WindowsApps\Microsoft.BingWallpaper_1.1.452.0_x86__8wekyb3d8bbwe [2026-05-21] (Microsoft Corporation) [Startup Task]
Bitdefender CL Contextual Menu -> C:\Program Files\Bitdefender\Bitdefender Security App [2026-05-27] (Bitdefender)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_164.1.1128.0_x64__v10z8vjag6ke6 [2026-04-27] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-05-28] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-05-28] (Microsoft Corporation) [MS Ad]
Microsoft.AIFabric.CBS.1.6 -> C:\WINDOWS\SystemApps\Microsoft.AIFabric.CBS.1.6_8wekyb3d8bbwe [2026-05-01] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-11-07] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.5.190.0_x64__dt26b99r8h8gj [2019-10-07] (Realtek Semiconductor Corp)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2238547156-67230461-3934341949-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-2238547156-67230461-3934341949-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-2238547156-67230461-3934341949-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_f4c7a2fd13e0f763\nvshext.dll [2026-02-17] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2024-05-14] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2018-07-20] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2024-05-14] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2018-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2021-08-18] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2021-08-18] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2021-08-18] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2021-08-18] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\localhost -> localhost

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-09-15 09:31 - 2023-02-22 19:17 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.1.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet 14: Realtek PCIe GbE Family Controller #6 -> rtcx21x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2238547156-67230461-3934341949-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\i7 6700 es\AppData\Local\Packages\Microsoft.BingWallpaper_8wekyb3d8bbwe\LocalState\images\bing\20260527_OHR.OtterDay_ROW8950256578_UHD_bing.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 4) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|F:\KMSAuto Lite 1.5.6 Portable\KMSAuto x64.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|F:\KMSAuto Lite 1.5.6 Portable\KMSAuto_Files
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\WINDOWS\System32\SppExtComObjPatcher.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\WINDOWS\System32\SppExtComObjHook.dll


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "RTHDVCPL"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Family Tree Builder Update"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "Wargaming.net Game Center"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "GarminExpress"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_3004125DB9EAF8C14B3AA649BEF00AAF"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "YouTubeToMP3"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\StartupApproved\Run: => "BingWallpaperDaemon"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{84F318D2-622D-44BE-A831-E99C9BAC7200}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25108.501.3586.7144_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B8A679AF-C686-4A21-BABE-734AAB84FE94}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25108.501.3586.7144_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3711D41A-4DCE-4A47-87A0-96C6355C92E9}] => (Allow) D:\Games\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{E65FDC1E-1BE7-46D3-A849-33AAEEE32E66}] => (Allow) D:\Games\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{B521B6BF-676E-48CA-B572-BCADB8265516}] => (Allow) D:\Games\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{0CC31262-AB36-44FD-B512-BEB4F02A250D}] => (Allow) D:\Games\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E9E828EB-D648-4F17-AF24-8039B922C47D}] => (Allow) C:\Users\i7 6700 es\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{52DEDD4C-2F09-449E-8BDC-1384E7C2A1FC}] => (Allow) C:\Users\i7 6700 es\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{519E8056-5B50-4633-B66A-5A88C15FE056}C:\users\i7 6700 es\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\i7 6700 es\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{CEC3A5F1-D1CA-46E2-9F92-CF414F9316BE}C:\users\i7 6700 es\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\i7 6700 es\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{1087318D-3933-4420-B876-DDF820B478CF}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{506AD946-071A-4D49-A915-42F1FAF9422D}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E2056642-5E13-4B46-B302-F85828504EC0}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4131871A-406D-4FD2-9DE3-89245329B8F4}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{7A013283-66AD-497C-B1F4-46AECD78A620}D:\games\wargaming.net\gamecenter\wgc.exe] => (Allow) D:\games\wargaming.net\gamecenter\wgc.exe => No File
FirewallRules: [UDP Query User{B49111DF-B281-4E68-A5CF-9A859144CFB1}D:\games\wargaming.net\gamecenter\wgc.exe] => (Allow) D:\games\wargaming.net\gamecenter\wgc.exe => No File
FirewallRules: [TCP Query User{86098444-92E2-49DA-9DB4-5DA59DDBD951}D:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\win64\worldoftanks.exe => No File
FirewallRules: [UDP Query User{74F5809A-59A5-453F-9C10-7972BF20C77E}D:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) D:\games\world_of_tanks_eu\win64\worldoftanks.exe => No File
FirewallRules: [TCP Query User{CBCB5F84-F92A-41D5-A2D7-3F3A15FED57E}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{EB68E251-DA91-4D3E-96B2-7183C79C0775}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{2747F46F-39E6-4281-AAAF-BA184E94BF11}D:\games\sid meiers civilization vi new frontier pass portugal\base\binaries\win64steam\civilizationvi.exe] => (Allow) D:\games\sid meiers civilization vi new frontier pass portugal\base\binaries\win64steam\civilizationvi.exe => No File
FirewallRules: [UDP Query User{55733FFF-12F0-4C4D-BA58-BFE2F309E183}D:\games\sid meiers civilization vi new frontier pass portugal\base\binaries\win64steam\civilizationvi.exe] => (Allow) D:\games\sid meiers civilization vi new frontier pass portugal\base\binaries\win64steam\civilizationvi.exe => No File
FirewallRules: [{097A8AB9-7E38-407E-9409-C40AC58A2CEE}] => (Allow) D:\Games\steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [{F902230B-18CB-4660-BAC0-10C6CB861DA6}] => (Allow) D:\Games\steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [{FB7BCB81-3821-4E0E-9BFA-61AA95DF5A72}] => (Allow) D:\Games\steam\steamapps\common\Farming Simulator 22\x64\FarmingSimulator2022Game.exe => No File
FirewallRules: [{8F159595-06A1-4D32-934C-E59EFF3500F5}] => (Allow) D:\Games\steam\steamapps\common\Farming Simulator 22\x64\FarmingSimulator2022Game.exe => No File
FirewallRules: [TCP Query User{FBCDF5FE-6DA5-41EC-8696-EC0904B1E62D}C:\program files\streamfab\streamfab\youtubedl\youtubetomp3service.exe] => (Allow) C:\program files\streamfab\streamfab\youtubedl\youtubetomp3service.exe => No File
FirewallRules: [UDP Query User{7D897946-6ED9-429A-94A6-CFF0DA7706D0}C:\program files\streamfab\streamfab\youtubedl\youtubetomp3service.exe] => (Allow) C:\program files\streamfab\streamfab\youtubedl\youtubetomp3service.exe => No File
FirewallRules: [TCP Query User{8C6A701E-8CEB-4C01-B349-82D3F6EF0974}D:\games\steam\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe] => (Allow) D:\games\steam\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe => No File
FirewallRules: [UDP Query User{21C3AB71-866E-44C9-9F48-4083411201C9}D:\games\steam\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe] => (Allow) D:\games\steam\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe => No File
FirewallRules: [{DAEA4221-C72D-4A92-BA4C-D48B421F8D15}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6888F529-3172-4297-8708-F69EDC2ADBC4}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9943E0D2-D91C-42BE-AF23-0251A60127B0}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{05C5FCA8-E82F-4EAA-BE2A-A3E11BFB9EFA}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{F8FFAFB1-B838-49C5-BB1E-11ED63D872B2}D:\games\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe] => (Allow) D:\games\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe => No File
FirewallRules: [UDP Query User{85763402-1747-4E1C-9427-FD9DCC7307E9}D:\games\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe] => (Allow) D:\games\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe => No File
FirewallRules: [{2FB6D288-9E59-470B-82B1-17C536B11670}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [{FC633820-79C8-4EFD-80DF-7FCBDF03B92B}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [TCP Query User{24390DB0-E114-4F3C-A886-2D7F26EAA509}E:\game\wargaming.net\gamecenter\wgc.exe] => (Allow) E:\game\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{7C341D80-110B-4DF5-AD15-40F53F7E6369}E:\game\wargaming.net\gamecenter\wgc.exe] => (Allow) E:\game\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [{1129506D-5C46-46F3-881F-CEBCC2B3FC17}] => (Allow) E:\SteamLibrary\steamapps\common\Manor Lords\ManorLords.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{0BC6766A-6AE0-47CC-BD75-D8883E26486F}] => (Allow) E:\SteamLibrary\steamapps\common\Manor Lords\ManorLords.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [TCP Query User{D2FDD191-A58F-47C4-8386-AF0DCC7767AF}E:\game\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) E:\game\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{E8734419-08CB-454A-9ADC-8957DA810FF8}E:\game\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) E:\game\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [{286B4605-A1C3-4885-97A9-ABD6581001B0}] => (Allow) E:\SteamLibrary\steamapps\common\AFOP\afop.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{A28A89F0-82E5-43B0-9134-593F6B8B87BD}] => (Allow) E:\SteamLibrary\steamapps\common\AFOP\afop.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{06B67FED-6FB2-4D1E-A6B0-14BF685E149A}] => (Allow) C:\Program Files\Bitdefender\Bitdefender Security\bdntwrk.exe (Bitdefender SRL -> Bitdefender)
FirewallRules: [{F7702FB9-9588-464A-80C5-8D23F7671680}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25108.501.3586.7144_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{783D0F36-4A9B-4AEB-A7A4-D087BF751EC1}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25108.501.3586.7144_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7CC84504-D2C9-4BCE-B1A4-D5F07CA8589E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{62AB4BFE-69E8-4843-9809-6C53FBE22F2A}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{695BA6DD-4FE3-45DC-ADAC-15B996184D98}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0D87FAB8-CAB5-4B30-927B-B9D56268C2C8}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{80CC78E0-696D-4887-89C1-2EB014F13BB3}E:\steamlibrary\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe (Render Cube, Toplitz Productions) [File not signed]
FirewallRules: [UDP Query User{37C43A93-A150-4F50-8393-390C08AC794E}E:\steamlibrary\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\medieval dynasty\medieval_dynasty\binaries\win64\medieval_dynasty-win64-shipping.exe (Render Cube, Toplitz Productions) [File not signed]
FirewallRules: [{11C794B4-B41D-4445-BE90-055862C55D8A}] => (Allow) E:\SteamLibrary\steamapps\common\Sengoku Dynasty\SengokuDynasty.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{B74AA594-1908-4091-9DB4-3EF21917A8F5}] => (Allow) E:\SteamLibrary\steamapps\common\Sengoku Dynasty\SengokuDynasty.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [TCP Query User{174EB249-7207-474C-BE16-462454FD43E4}E:\steamlibrary\steamapps\common\sengoku dynasty\sengokudynasty\binaries\win64\sengokudynasty-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\sengoku dynasty\sengokudynasty\binaries\win64\sengokudynasty-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [UDP Query User{EFB17C33-2725-431E-8796-63BF58681D54}E:\steamlibrary\steamapps\common\sengoku dynasty\sengokudynasty\binaries\win64\sengokudynasty-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\sengoku dynasty\sengokudynasty\binaries\win64\sengokudynasty-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [TCP Query User{80C293BE-C1BD-4E23-A755-0A7926DAA627}E:\game\civilization 6\sidmeierscivilizationvi\base\binaries\win64eos\civilizationvi.exe] => (Allow) E:\game\civilization 6\sidmeierscivilizationvi\base\binaries\win64eos\civilizationvi.exe => No File
FirewallRules: [UDP Query User{A0929511-9DDB-42B5-83FF-1221CF722F59}E:\game\civilization 6\sidmeierscivilizationvi\base\binaries\win64eos\civilizationvi.exe] => (Allow) E:\game\civilization 6\sidmeierscivilizationvi\base\binaries\win64eos\civilizationvi.exe => No File
FirewallRules: [TCP Query User{B551E4F6-4965-4B73-B8E9-B5998845BDB6}E:\game\civilization 6\game\base\binaries\win64steam\civilizationvi_dx12.exe] => (Allow) E:\game\civilization 6\game\base\binaries\win64steam\civilizationvi_dx12.exe => No File
FirewallRules: [UDP Query User{03D8D30B-CB71-42D5-809F-2D88C112F468}E:\game\civilization 6\game\base\binaries\win64steam\civilizationvi_dx12.exe] => (Allow) E:\game\civilization 6\game\base\binaries\win64steam\civilizationvi_dx12.exe => No File
FirewallRules: [TCP Query User{7E7A13A4-F233-46DA-AE60-FA4D4EFA6F91}E:\game\sid meiers civilization vi\base\binaries\win64steam\civilizationvi.exe] => (Allow) E:\game\sid meiers civilization vi\base\binaries\win64steam\civilizationvi.exe (Firaxis Games) [File not signed]
FirewallRules: [UDP Query User{F8292BDD-E508-439E-994B-48A46DDAAFA8}E:\game\sid meiers civilization vi\base\binaries\win64steam\civilizationvi.exe] => (Allow) E:\game\sid meiers civilization vi\base\binaries\win64steam\civilizationvi.exe (Firaxis Games) [File not signed]
FirewallRules: [TCP Query User{DB661709-3B5F-460F-839E-1F600A48BD2C}C:\users\i7 6700 es\downloads\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe] => (Allow) C:\users\i7 6700 es\downloads\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe => No File
FirewallRules: [UDP Query User{15736A8D-A098-421F-9778-5541C0112116}C:\users\i7 6700 es\downloads\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe] => (Allow) C:\users\i7 6700 es\downloads\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe => No File
FirewallRules: [TCP Query User{8BD4659B-B8C1-45FB-A535-60B10E82FF2B}E:\game\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe] => (Allow) E:\game\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe => No File
FirewallRules: [UDP Query User{878679CE-A07D-437F-8248-03F789E79A10}E:\game\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe] => (Allow) E:\game\tribe.primitive.builder.v1.1.10\tribe.primitive.builder.v1.1.10\tribe\binaries\win64\tribe-win64-shipping.exe => No File
FirewallRules: [TCP Query User{6660F95E-7E54-433C-B9DA-38C51C76D79E}C:\users\i7 6700 es\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\i7 6700 es\appdata\roaming\zoom\bin\zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
FirewallRules: [UDP Query User{42EA5FE0-165A-463C-8C2D-5AAEB845D170}C:\users\i7 6700 es\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\i7 6700 es\appdata\roaming\zoom\bin\zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
FirewallRules: [{57BBF3EB-4CA1-439D-A627-001EB30709FD}] => (Allow) E:\SteamLibrary\steamapps\common\Planet Coaster 2\PlanetCoaster2.exe (Frontier Developments) [File not signed]
FirewallRules: [{6B04FBC3-3095-4252-8358-ED6D95E1D35F}] => (Allow) E:\SteamLibrary\steamapps\common\Planet Coaster 2\PlanetCoaster2.exe (Frontier Developments) [File not signed]
FirewallRules: [{716A8AD3-9BDD-4284-B3A4-1C548D6DA86E}] => (Allow) D:\Games\steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{86F7657D-65B1-40C7-84FF-A72846C93C91}] => (Allow) D:\Games\steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DEE7551F-5B5F-4014-8365-B379E9B534E9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

20-05-2026 20:26:28 Windows Update
20-05-2026 20:26:29 Windows Update
20-05-2026 20:26:34 Windows Update

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (05/27/2026 08:22:47 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (05/26/2026 07:21:06 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (05/25/2026 06:44:35 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (05/24/2026 08:04:26 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (05/23/2026 09:02:55 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..

Error: (05/23/2026 09:02:55 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]

Error: (05/23/2026 09:02:55 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému..

Error: (05/23/2026 09:02:55 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.]


System errors:
=============
Error: (05/27/2026 08:20:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (05/27/2026 08:20:03 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (05/27/2026 08:18:00 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 22) (User: NT AUTHORITY)
Description: Služba protokolování událostí zjistila při inicializaci publikačních prostředků chybu v kanálu Microsoft-RMS-MSIPC/Debug. V případě analytického nebo ladicího typu kanálu to může znamenat, že došlo také k chybě při inicializaci přihlašovacích prostředků.

Error: (05/27/2026 08:18:00 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 22) (User: NT AUTHORITY)
Description: Služba protokolování událostí zjistila při inicializaci publikačních prostředků chybu v kanálu DebugChannel. V případě analytického nebo ladicího typu kanálu to může znamenat, že došlo také k chybě při inicializaci přihlašovacích prostředků.

Error: (05/27/2026 08:18:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba mbamchameleon neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (05/26/2026 07:17:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (05/26/2026 07:17:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (05/26/2026 07:15:04 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 22) (User: NT AUTHORITY)
Description: Služba protokolování událostí zjistila při inicializaci publikačních prostředků chybu v kanálu Microsoft-RMS-MSIPC/Debug. V případě analytického nebo ladicího typu kanálu to může znamenat, že došlo také k chybě při inicializaci přihlašovacích prostředků.


CodeIntegrity:
===============
Date: 2026-05-27 20:23:07
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender Security\bdamsi\dlls_268485804182457648\antimalware_provider64.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. 4622 09/29/2024
Motherboard: ASUSTeK COMPUTER INC. PRIME B450M-K
Processor: AMD Ryzen 5 5600 6-Core Processor
Percentage of memory in use: 19%
Total physical RAM: 32678.61 MB
Available physical RAM: 26175.71 MB
Total Virtual: 34726.61 MB
Available Virtual: 27793.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:475.43 GB) (Free:315.88 GB) (Model: SAMSUNG MZVLW512HMJP-00000) NTFS
Drive d: (Nový svazek) (Fixed) (Total:1863 GB) (Free:1749.85 GB) (Model: WDC WD20EZRZ-00Z5HB0) NTFS
Drive e: (Disk SSD) (Fixed) (Total:894.24 GB) (Free:591.6 GB) (Model: KINGSTON SA400S37960G) NTFS

\\?\Volume{e982de3d-69dc-4451-bb7f-c425d0275b02}\ () (Fixed) (Total:0.77 GB) (Free:0.09 GB) NTFS
\\?\Volume{ba5fbc33-b5dd-4468-b9fb-349269ef43b8}\ (Bitdefender Virtual Disk) (Fixed) (Total:0.03 GB) (Free:0.02 GB) NTFS
\\?\Volume{1c1942a8-3eb8-416b-9975-23a7d27775f0}\ () (Fixed) (Total:0.1 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 894.3 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: 98C3C70A)

Partition: GPT.

==========================================================
Disk: 3 (Protective MBR) (Size: 32 MB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Re: kontrola logu

Napsal: 27 kvě 2026 21:28
od JaRon
Ahoj,
hesla je potrebne zmenit
+
prescanuj PC s Adwcleanerom - log sem

Re: kontrola logu

Napsal: 28 kvě 2026 14:31
od Trejsi91
# -------------------------------
# Malwarebytes AdwCleaner 8.8.1.639
# -------------------------------
# Build: 05-13-2026
# Database: 2026-05-07.3 (Cloud)
# Support: https://help.malwarebytes.com/
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 05-28-2026
# Duration: 00:00:06
# OS: Windows 11 (Build 26200.8524)
# Scanned: 32079
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.


AdwCleaner[S00].txt - [2909 octets] - [28/09/2021 07:52:52]
AdwCleaner[C00].txt - [2861 octets] - [28/09/2021 07:53:23]
AdwCleaner[S01].txt - [1527 octets] - [14/10/2021 18:20:57]
AdwCleaner[C01].txt - [1717 octets] - [14/10/2021 18:21:43]
AdwCleaner[S02].txt - [1664 octets] - [16/07/2024 19:07:00]
AdwCleaner[C02].txt - [1854 octets] - [16/07/2024 19:07:44]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S03].txt ##########

Re: kontrola logu

Napsal: 28 kvě 2026 16:11
od JaRon
Pouzi fixlist.txt s obsahom:

Start

CloseProcesses:

HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION

HKU\S-1-5-21-2238547156-67230461-3934341949-1001\...\Run: [BingWallpaperDaemon] => C:\Users\i7 6700 es\AppData\Local\Temp\bwpf17d98de-0178-4372-9e38-4ce0ef2349c6\UnInstDaemon.exe [69432 2026-05-21] (Microsoft Corporation -> Microsoft Corp.) <==== ATTENTION

Task: {9E706C7E-D9D8-401A-9AC4-4FFDDA39D6AD} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (No File)
Task: {7B531F5E-3758-4D51-89CD-FC432DC8010A} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{A2D70FD1-4DE9-4EA6-A1B1-E7795D19C13A} => C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe [8770200 2026-04-28] (Google LLC -> Google LLC)

Task: {4A339509-D6E8-4337-9B59-F361D5467B8E} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => %SystemRoot%\system32\clipesu.exe (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {A4A930F1-A627-401D-AE95-34BF330DBE89} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe RebootDialog (No File)
Task: {A0E9926A-A2B0-4D32-A64D-4427D1E51EAA} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC EngagedRebootReminder (No File)
Task: {F393C700-BDA8-4C93-B5B4-733E910C0F20} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery EngagedRebootReminder (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)

S2 mbamchameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys (No File)

AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}


EmptyTemp:

End