napadení PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Hynek88
Návštěvník
Návštěvník
Příspěvky: 68
Registrován: 18 Ún 2012 06:47

napadení PC

#1 Příspěvek od Hynek88 »

Zdravím,

vypadá to, že se mně ňáký dobrodruzi dostali do pc, jde to nějak zjistit?

popřípadě vypnout nějáký funkce, služby?

děkuji za případné řešení.

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120145
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: napadení PC

#2 Příspěvek od Rudy »

Zdravím!
Nejprve dejte log FRST: http://forum.viry.cz/viewtopic.php?f=24&t=132509 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hynek88
Návštěvník
Návštěvník
Příspěvky: 68
Registrován: 18 Ún 2012 06:47

Re: napadení PC

#3 Příspěvek od Hynek88 »

frst--

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-10-2026
Ran by PC (administrator) on DESKTOP-3CTVH0E (04-10-2026 12:23:10)
Running from C:\Users\PC\Desktop\FRST64.exe
Loaded Profiles: PC
Platform: Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler64.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe
(DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atieclxx.exe
(explorer.exe ->) () [File not signed] C:\Windows\System\HsMgr64.exe
(explorer.exe ->) () [File not signed] C:\Windows\SysWOW64\HsMgr.exe
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(explorer.exe ->) (BitTorrent Inc -> BitTorrent, Inc.) C:\Program Files (x86)\uTorrent\uTorrent.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Learsy) [File not signed] C:\Program Files (x86)\MuralPix\MpAgent.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(services.exe ->) (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Malwarebytes Corporation -> Malwarebytes) C:\ProgramData\MB3Install\MBAMIService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2607.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (J's Future Corp. -> ) C:\Program Files (x86)\TabService\tabservicepack.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (SOKNO S.R.L. -> ) C:\Program Files (x86)\SpeedFan\speedfan.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ISCT Tray] => C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [5860656 2014-06-18] (Intel CASE -> Intel Corporation)
HKLM\...\Run: [Cmaudio8788] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd [13463552 2021-03-23] (C-Media Corporation) [File not signed]
HKLM\...\Run: [Cmaudio8788GX] => C:\Windows\syswow64\HsMgr.exe [200704 2021-03-23] () [File not signed]
HKLM\...\Run: [Cmaudio8788GX64] => C:\Windows\system\HsMgr64.exe [282112 2021-03-23] () [File not signed]
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech -> Logitech Inc.)
HKLM-x32\...\Run: [MuralPixAgent] => C:\Program Files (x86)\MuralPix\MpAgent.exe [102400 2006-12-30] (Learsy) [File not signed]
HKLM-x32\...\Run: [Fujitsu Mouse LX960] => C:\Program Files (x86)\Fujitsu Mouse LX960\DriverAP4.exe [1719808 2019-10-08] (Fujitsu) [File not signed]
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Run: [Steam] => D:\Steam\steam.exe [5767832 2026-03-13] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Run: [DualSenseX] => C:\Users\PC\AppData\Local\DualSenseX\DualSenseX.exe [328192 2025-01-04] () [File not signed]
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [45610456 2026-09-16] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\RunOnce: [Application Restart #0] => C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe [4425808 2026-10-02] (Brave Software, Inc. -> Brave Software, Inc.)
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\SysWOW64\MuralPix.scr [106496 2006-12-30] (Learsy) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" --first-run (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\154.1.96.61\Installer\chrmstp.exe [6493264 2026-10-02] (Brave Software, Inc. -> Brave Software, Inc.)
Startup: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Speedfan Startup.lnk [2021-03-28]
ShortcutTarget: Speedfan Startup.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Windows -> Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {6BBC76C6-B263-44AC-924F-C6F4E1BEB04D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1617408 2026-08-03] (Adobe Inc. -> Adobe Inc.)
Task: {EA8C714A-80F0-45C6-9DCF-179C4D8DDAE2} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore{096F4ABF-A5B5-4D33-BC04-5BBAA571C85F} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {6764ACC0-D2FF-4FC5-B863-AFD2E4ACC7C4} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {EADBEAA2-0E38-4DA7-B3DE-FB61D0722FEC} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {41E9C842-585E-468B-B09B-9E0DAE8AD059} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6140920 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "deaa1c9e-3d31-4138-b212-954468be02e8" --version "6.41.0.11567" --silent
Task: {1709A315-EB60-4417-B501-E05062D7AD4F} - System32\Tasks\CCleanerSkipUAC - PC => C:\Program Files\CCleaner\CCleaner.exe [39839224 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3D8C4218-B793-40AE-BC7F-346E307B6A95} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {46102E77-D26A-4201-9AB6-9481154C87F6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {64E2EC95-B9F5-48E7-8FEE-38816D521A6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0F43F7D2-D213-4A2B-BAA4-7558AC6BCA04} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {70DC0CDE-E0DF-45EF-A0A4-8C0BBBEC3A49} - System32\Tasks\Mozilla\Firefox Default Browser Agent 9388B6559483FD17 => C:\Mozilla Firefox\default-browser-agent.exe [44160 2026-09-29] (Mozilla Corporation -> Mozilla Foundation)
Task: {1D270147-DD55-4E70-9FBD-5177E19A1EE4} - System32\Tasks\Speedfan Startup => C:\Program Files (x86)\SpeedFan\speedfan.exe [8166536 2016-06-29] (SOKNO S.R.L. -> ) -> /c start "Speedfan Startup" "C:\Program Files (x86)\SpeedFan\speedfan.exe"
Task: {67321662-FA67-4707-B2E0-1B813C745DB6} - System32\Tasks\TabServiceScheduler => C:\Program Files (x86)\TabService\tabservicepack.exe [1385832 2026-06-11] (J's Future Corp. -> )

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.5.1 172.21.1.1 172.21.1.2
Tcpip\..\Interfaces\{154e81dd-97c9-424e-bd8c-4ca78f603f95}: [DhcpNameServer] 192.168.5.1 172.21.1.1 172.21.1.2
Tcpip\..\Interfaces\{154e81dd-97c9-424e-bd8c-4ca78f603f95}: [DhcpDomain] lan

FireFox:
========
FF TaskBarID: 9388B6559483FD17 -> C:\Mozilla Firefox
FF DefaultProfile: cmv64535.default-1617030860948 -> 9388B6559483FD17
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948 [2026-10-04]
FF Homepage: Mozilla\Firefox\Profiles\cmv64535.default-1617030860948 -> hxxps://www.templ.net/cesky/patrick_barta_a_kontakt.php
FF Session Restore: Mozilla\Firefox\Profiles\cmv64535.default-1617030860948 -> is enabled.
FF Extension: (Dark Reader) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\addon@darkreader.org.xpi [2026-09-25]
FF Extension: (uBlock Origin) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\uBlock0@raymondhill.net.xpi [2026-09-16]
FF Extension: (Dark space - The best dynamic theme) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{22b0eca1-8c02-4c0d-a5d7-6604ddd9836e}.xpi [2024-01-26]
FF Extension: (Galaxy Space Theme) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{5eae7880-dab2-4337-bc53-e4b58db7aec4}.xpi [2022-12-19]
FF Extension: (This is a sunrise) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{8295aeba-205d-4a8a-8155-c0f8f0f959a1}.xpi [2022-11-26]
FF Extension: (Fractal Senzune Alphacoder) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{ceefc8d7-d251-4762-bfcd-35cdeb3c52cd}.xpi [2023-03-08]
FF Extension: (Northern Lake FT by MaDonna) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{fcebb804-5eb9-43d9-a12a-30f6ca1b9b1b}.xpi [2021-06-02]
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\c5xkfvmc.default-1616169207305 [2026-10-04]
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\16rhk66j.default-1483610832811 [2026-10-04]
FF Plugin: @videolan.org/vlc,version=3.0.22 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-11-27] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-09-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
StartMenuInternet: Firefox-9388B6559483FD17 - C:\Mozilla Firefox\firefox.exe

Edge:
=======
Edge Profile: C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default [2026-10-04]

Chrome:
=======
CHR HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

Brave:
=======
BRA DefaultProfile: Default
BRA Profile: C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2026-10-04]
BRA DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}&t=brave
BRA DefaultSearchKeyword: Default -> :d
BRA DefaultSuggestURL: Default -> hxxps://ac.duckduckgo.com/ac/?q={searchTerms}&type=list
BRA Extension: (DuckDuckGo) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2026-09-03]
BRA Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-09-25]
BRA Extension: (Dark Reader) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2026-09-25]
BRA Profile: C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Guest Profile [2024-09-04]
BRA Profile: C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\System Profile [2025-10-05]
BRA Extension: (Brave Ad Block Updater (Brave First Party Adblock Filters (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2026-09-23]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2026-10-02]
BRA Extension: (Brave NTP background images) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2026-09-23]
BRA Extension: (Brave Ad Block Updater (Fanboy's Mobile Notifications (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2026-09-25]
BRA Extension: (Wallet Data Files Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2024-01-30]
BRA Extension: (Brave Ad Block Updater (EasyList Cookie (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2026-10-04]
BRA Extension: (Query Filter) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cemdlagocoimleflkfkjoihojfainiho [2026-10-04]
BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2023-08-04]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2025-08-16]
BRA Extension: (Brave NTP sponsored images) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\efkihffiamafhbhefjaljejgdpkelpal [2026-09-25]
BRA Extension: (Brave WebMCP Tool Scripts) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\eingdhelnaolbpcdkgddekhifcjfkalf [2026-09-15]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2026-09-09]
BRA Extension: (Brave Ads Resources) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\iejekkikpddbbockoldagmfcdbffomfc [2026-02-21]
BRA Extension: (Brave Ad Block Updater (Brave Ad Block Updater (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2026-10-04]
BRA Extension: (Brave SpeedReader Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2022-03-10]
BRA Extension: (Brave Ad Block Updater (Brave Default Privacy Filters (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\kihnoaefogbkmblfimmibknnmkllbhlf [2026-10-04]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2026-09-21]
BRA Extension: (Brave Ad Block Updater (Brave Twitch Adblock Rules (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\mhccgcegedfkhdbfbgllfkkcjhgkoinc [2024-09-19]
BRA Extension: (Brave User Agent) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\nlpaeekllejnmhoonlpcefpfnpbajbpe [2026-10-04]
BRA Extension: (Brave Ad Block Updater (Czech and Slovak website ad blocker (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\oegebjahecghlckbhkmojgnpcgdeajdi [2026-09-15]
BRA Extension: (Brave Ad Block Updater (CZE, SVK: EasyList Czech and Slovak)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\omkkefoeihpbpebhhbhmjekpnegokpbj [2023-04-15]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2023-10-26]
BRA Extension: (P3A Configuration) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\P3AConfig [2025-09-27]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [182776 2026-08-03] (Adobe Inc. -> Adobe Inc.)
S3 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 BraveElevationService; C:\Program Files\BraveSoftware\Brave-Browser\Application\154.1.96.61\elevation_service.exe [5151824 2026-10-02] (Brave Software, Inc. -> Brave Software, Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1080824 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
S3 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-06-18] (Intel CASE -> )
S3 LibreOfficeMaintenance; C:\Program Files\LibreOffice\program\update_service.exe [125352 2026-01-28] (The Document Foundation -> The Document Foundation)
R2 MBAMIService; C:\ProgramData\MB3Install\MBAMIService.exe [231120 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11420952 2026-03-27] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-03-27] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe [2307776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe [1275016 2025-03-15] (NVIDIA Corporation -> NVIDIA Corporation)
S3 PrintNotify; C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll [3596288 2021-03-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
S4 tmAInstall; C:\Program Files\Thrustmaster\Hotas Warthog\drivers\amd64\tmAInstall.exe [38408 2018-03-01] (Guillemot Recherche et Développement, Inc -> Thrustmaster®)
S4 TmWinService; C:\Program Files (x86)\Thrustmaster\TARGET\TmService.exe [320544 2024-07-02] (Guillemot Corporation S.A. -> Guillemot Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe [5311776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe [291360 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdfendrmgr; C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrmgr.sys [25672 2024-04-23] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\Windows\System32\DriverStore\FileRepository\amdsafd.inf_amd64_960126269e89c62e\amdsafd.sys [113880 2024-05-10] (Advanced Micro Devices -> Advanced Micro Devices)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\amdkmdag.sys [106596128 2024-09-04] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2021-09-15] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [154112 2021-10-13] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R3 cmudaxp; C:\Windows\system32\drivers\cmudaxp.sys [2735616 2021-03-23] (C-MEDIA ELECTRONICS INC. -> C-Media Inc)
S3 INETMON; \??\C:\Windows\System32\Drivers\INETMON.sys [25800 2014-05-27] (Intel CASE -> )
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [83008 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [245864 2026-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MZ_USBAUDIO; C:\Windows\system32\drivers\mz_usbaudio.sys [144896 2013-05-14] (DandM Holdings Inc. -> D&M Holdings Inc.)
R2 speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> )
R1 steamxbox; C:\Windows\System32\drivers\steamxbox.sys [278208 2023-02-21] (Valve Corp. -> Valve Corporation)
R3 TmBusEn; C:\Windows\System32\drivers\TmBusEn.sys [43088 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
R3 TmBusEn; C:\Windows\SysWOW64\drivers\TmBusEn.sys [43088 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmFilter; C:\Windows\System32\drivers\TmFilter.sys [70736 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmFilter; C:\Windows\SysWOW64\drivers\TmFilter.sys [70736 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmHid; C:\Windows\system32\DRIVERS\TmHid.sys [49040 2023-12-14] (WDKTestCert plukidis,131540205154897060 -> Guillemot Corporation)
S3 TmHid; C:\Windows\SysWOW64\DRIVERS\TmHid.sys [49040 2023-12-14] (WDKTestCert plukidis,131540205154897060 -> Guillemot Corporation)
S4 WdAiNisDrv; C:\Windows\System32\drivers\wd\WdAiNisDrv.sys [51264 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21632 2026-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [664592 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [137240 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 ysusb_w10_64; C:\Windows\System32\DriverStore\FileRepository\ysusb_w10.inf_amd64_0c08afcf04fddf00\ysusb_w10_64.sys [199160 2026-06-11] (WDKTestCert AF919676,134063601988638324 -> Yamaha Corporation)

==================== SvcHost (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-10-04 12:23 - 2026-10-04 12:24 - 000026228 _____ C:\Users\PC\Desktop\FRST.txt
2026-10-04 12:16 - 2026-10-04 12:16 - 002456064 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2026-10-04 06:42 - 2026-10-04 06:42 - 000021365 _____ C:\Users\PC\Downloads\Chosen Survivors (1974) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-10-04 06:31 - 2026-10-04 06:31 - 000021804 _____ C:\Users\PC\Downloads\Rose (2026) [1080p] [BluRay] [x265] [10bit] [5.1] [YTS.GG - YTS.BZ].torrent
2026-10-01 19:02 - 2026-10-01 19:02 - 000017803 _____ C:\Users\PC\Downloads\the-cursed-2025-1080p-korean-web-dl-hevc-x265-5-1-bone-mkv.torrent
2026-10-01 18:38 - 2026-10-01 18:38 - 000012923 _____ C:\Users\PC\Downloads\--the-cursed-2025-dsnp-web-dl-1080p-h-264-ddp5-1-ngp.torrent
2026-09-29 19:05 - 2026-09-29 19:05 - 000000000 ____D C:\Mozilla Firefox
2026-09-29 16:36 - 2026-10-03 04:45 - 000003716 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{221C60D5-F766-43A8-86A4-2138D1921CC5}
2026-09-29 16:36 - 2026-10-03 04:45 - 000003644 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{E1551A82-DA2D-4EBA-A531-C4132BC7A1C5}
2026-09-26 09:04 - 2026-09-26 09:04 - 000002521 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yamaha Steinberg USB Control Panel.lnk
2026-09-26 09:04 - 2026-09-26 09:04 - 000000000 ____D C:\Program Files (x86)\Yamaha
2026-09-26 09:03 - 2026-09-26 09:04 - 000000000 ____D C:\ProgramData\Yamaha_Uninstaller
2026-09-25 05:54 - 2026-09-25 05:54 - 000001159 _____ C:\Users\PC\Documents\Nový textový dokument.txt
2026-09-21 20:18 - 2026-09-21 20:18 - 000062720 _____ C:\Users\PC\Downloads\Dèmoni 2... l'incubo ritorna (1986) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 20:16 - 2026-09-21 20:16 - 000061116 _____ C:\Users\PC\Downloads\Dèmoni (1985) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 17:14 - 2026-09-21 17:14 - 000071608 _____ C:\Users\PC\Downloads\Muse (2017) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 17:12 - 2026-09-21 17:12 - 000076937 _____ C:\Users\PC\Downloads\Mientras duermes (2011) [1080p] [BluRay] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-21 15:22 - 2026-09-21 15:22 - 000068127 _____ C:\Users\PC\Downloads\Route Irish (2010) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 15:18 - 2026-09-21 15:18 - 000070414 _____ C:\Users\PC\Downloads\Los cronocrímenes (2007) [1080p] [BluRay] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-21 09:25 - 2026-09-21 09:25 - 000018236 _____ C:\Users\PC\Downloads\--resident-evil-2026-1080p-telesync-multi-x264-dks.torrent
2026-09-20 02:49 - 2026-09-20 02:49 - 000021420 _____ C:\Users\PC\Downloads\Los ojos de Julia (2010) [1080p] [BluRay] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-17 04:18 - 2026-09-17 04:18 - 000042582 _____ C:\Users\PC\Downloads\karupsow-13-10-07-louise-pearce-solo-2-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:18 - 2026-09-17 04:18 - 000040960 _____ C:\Users\PC\Downloads\karupsha-13-10-07-riley-grey-solo-5-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:17 - 2026-09-17 04:17 - 000057344 _____ C:\Users\PC\Downloads\brazzers-plib---skin-diamond-ultimate-sin-480p.torrent
2026-09-17 04:17 - 2026-09-17 04:17 - 000041381 _____ C:\Users\PC\Downloads\karupsha-13-10-07-mia-mea-solo-1-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:17 - 2026-09-17 04:17 - 000037461 _____ C:\Users\PC\Downloads\karupspc-13-10-07-serenity-reed-solo-2-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:16 - 2026-09-17 04:16 - 000315360 _____ C:\Users\PC\Downloads\pornstarslikeitbig-13-10-07-skin-diamond-ultimate-sin-xxx-1080p-mp4-sexors.torrent
2026-09-17 04:16 - 2026-09-17 04:16 - 000043870 _____ C:\Users\PC\Downloads\firstclasspov-skin-diamond-skin-diamond-glam-bj-mp4.torrent
2026-09-17 04:16 - 2026-09-17 04:16 - 000031074 _____ C:\Users\PC\Downloads\pornstarslikeitbig---skin-diamond---ultimate-sin-mp4.torrent
2026-09-17 04:15 - 2026-09-17 04:15 - 000194648 _____ C:\Users\PC\Downloads\ls-studios-collection---ls-dreams.torrent
2026-09-17 04:15 - 2026-09-17 04:15 - 000142361 _____ C:\Users\PC\Downloads\footworship-13-09-06-kristina-rose-and-skin-diamond-xxx-720p-mp4-ktrrarbg.torrent
2026-09-17 04:15 - 2026-09-17 04:15 - 000013662 _____ C:\Users\PC\Downloads\cherrypimpssoloskindiamond-mp4-1.torrent
2026-09-17 04:14 - 2026-09-17 04:14 - 000042236 _____ C:\Users\PC\Downloads\karupspc-15-05-12-skin-diamond-solo-1-xxx-720p-mp4-ktrmedm.torrent
2026-09-17 04:14 - 2026-09-17 04:14 - 000034654 _____ C:\Users\PC\Downloads\skin-diamond-solo-1080-mp4.torrent
2026-09-17 04:14 - 2026-09-17 04:14 - 000013662 _____ C:\Users\PC\Downloads\cherrypimpssoloskindiamond-mp4.torrent
2026-09-16 14:40 - 2026-09-16 14:40 - 000039212 _____ C:\Users\PC\Downloads\school-models-paula-custom-sheer-panties-topless-avi.torrent
2026-09-16 14:39 - 2026-09-16 14:39 - 000021504 _____ C:\Users\PC\Downloads\A Prize of Gold (1955) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-16 14:39 - 2026-09-16 14:39 - 000019191 _____ C:\Users\PC\Downloads\school-models-paula-vids.torrent
2026-09-16 14:38 - 2026-09-16 14:38 - 000023851 _____ C:\Users\PC\Downloads\The End of Oak Street (2026) [2160p] [WEBRip] [x265] [10bit] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-16 14:38 - 2026-09-16 14:38 - 000022721 _____ C:\Users\PC\Downloads\The End of Oak Street (2026) [1080p] [WEBRip] [x265] [10bit] [5.1] [YTS.GG - YTS.BZ].torrent

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-10-04 12:24 - 2021-03-24 21:19 - 000000000 ____D C:\Users\PC\AppData\Roaming\uTorrent
2026-10-04 12:23 - 2021-12-27 09:49 - 000000000 ____D C:\FRST
2026-10-04 12:22 - 2025-04-19 07:11 - 000000000 ____D C:\Program Files\CCleaner
2026-10-04 12:21 - 2021-03-24 21:23 - 000000000 ____D C:\Users\PC\AppData\Local\CrashDumps
2026-10-04 12:18 - 2025-03-29 17:13 - 000003386 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2026-10-04 12:18 - 2025-03-29 17:13 - 000000670 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2026-10-04 12:13 - 2020-09-27 07:50 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-10-04 12:01 - 2021-12-16 06:28 - 000000000 ____D C:\Windows\SystemTemp
2026-10-04 10:05 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-10-04 05:51 - 2021-03-23 16:56 - 001693820 _____ C:\Windows\system32\PerfStringBackup.INI
2026-10-04 05:51 - 2019-12-07 16:41 - 000716932 _____ C:\Windows\system32\perfh005.dat
2026-10-04 05:51 - 2019-12-07 16:41 - 000145110 _____ C:\Windows\system32\perfc005.dat
2026-10-04 05:51 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2026-10-04 05:48 - 2021-03-24 12:19 - 000000000 ____D C:\Program Files (x86)\SpeedFan
2026-10-04 05:47 - 2021-03-23 17:24 - 000000000 __SHD C:\Users\PC\IntelGraphicsProfiles
2026-10-04 05:47 - 2020-09-27 09:51 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-10-04 05:47 - 2020-09-27 07:50 - 000008192 ___SH C:\DumpStack.log.tmp
2026-10-04 05:12 - 2025-04-19 11:31 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2026-10-04 05:12 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2026-10-04 05:11 - 2025-12-31 19:04 - 000000000 ____D C:\Users\PC\AppData\Roaming\vlc
2026-10-03 22:46 - 2024-01-17 16:30 - 000000000 ____D C:\Users\PC\AppData\Roaming\foobar2000-v2
2026-10-03 10:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2026-10-03 06:08 - 2021-03-23 16:55 - 000000000 ____D C:\Users\PC
2026-10-02 23:54 - 2021-03-24 12:12 - 000002364 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2026-09-30 02:32 - 2026-08-19 01:31 - 000001714 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-09-29 16:36 - 2021-03-24 09:54 - 000000000 ____D C:\ProgramData\Adobe
2026-09-29 10:20 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2026-09-25 19:03 - 2021-03-23 16:55 - 000000000 ____D C:\Users\PC\AppData\Local\Packages
2026-09-25 13:13 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\WindowsApps
2026-09-23 06:08 - 2022-02-20 14:30 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-09-19 17:07 - 2026-06-04 22:50 - 000002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-09-19 17:07 - 2025-08-02 09:07 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2026-09-18 16:25 - 2020-09-27 09:51 - 000000000 ____D C:\Windows\system32\Drivers\wd
2026-09-09 11:11 - 2021-03-24 12:34 - 000000000 ____D C:\Users\PC\AppData\Local\D3DSCache
2026-09-09 07:13 - 2021-03-24 09:31 - 000000000 ____D C:\Windows\system32\MRT
2026-09-09 07:10 - 2021-03-24 09:31 - 230964456 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-09-09 07:09 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp

==================== Files in the root of some directories ========

2021-03-24 09:36 - 2026-04-28 12:10 - 000000600 _____ () C:\Users\PC\AppData\Roaming\winscp.rnd
2021-03-25 17:30 - 2021-03-25 17:31 - 000007597 _____ () C:\Users\PC\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


addition ---
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-10-2026
Ran by PC (04-10-2026 12:27:42)
Running from C:\Users\PC\Desktop
Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) (2021-03-23 14:52:24)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-1091510603-4126540304-2273175986-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-1091510603-4126540304-2273175986-503 - Limited - Disabled)
Guest (S-1-5-21-1091510603-4126540304-2273175986-501 - Limited - Disabled)
PC (S-1-5-21-1091510603-4126540304-2273175986-1001 - Administrators - Enabled) => C:\Users\PC
WDAGUtilityAccount (S-1-5-21-1091510603-4126540304-2273175986-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 26.002.21931 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601180}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Aegisub 3.0.0 (HKLM-x32\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.0.0 - Aegisub Team)
Aegisub 3.4.2 (HKLM\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.4.2 - Aegisub Team)
Altap Salamander 4.0 (x86) (HKLM-x32\...\Altap Salamander 4.0 (x86)) (Version: 4.0 - ALTAP)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 24.9.1 - Advanced Micro Devices, Inc.)
ASUS Xonar Essence ST Audio (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F392008788}) (Version: - ASUSTeK Computer Inc.)
Bandicut (HKLM-x32\...\Bandicut) (Version: 4.2.4.2552 - Bandicam.com)
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 154.1.96.61 - Autoři prohlížeče Brave)
CCleaner (HKLM\...\CCleaner) (Version: 6.41 - Piriform)
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1990.6 - Piriform Software) Hidden
CDisplayEx 1.10.33 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.)
DualSenseX (HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\DualSenseX) (Version: 1.4.9 - Paliverse)
Easy Audio Extractor v. 1.0 (HKLM-x32\...\Easy Audio Extractor_is1) (Version: - Video-Easy.com)
ffdshow x64 v1.3.4531 [2014-06-28] (HKLM\...\ffdshow64_is1) (Version: 1.3.4531.0 - )
foobar2000 v2.1.1 (x64) (HKLM\...\foobar2000 (x64)) (Version: 2.1.1 - Peter Pawlowski)
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.3.112.5382 - GOM & Company)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.101.0 - Google LLC) Hidden
HOTAS WARTHOG drivers (HKLM-x32\...\{C33F3C7C-F964-4919-97D3-0C4F2A538D87}) (Version: 1.TMHW.2018 - Thrustmaster)
Intel(R) Chipset Device Software (HKLM\...\{B685D0AD-42A8-4A39-9BFE-8C063FA9AF29}) (Version: 10.1.1.8 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1156 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{5D1BFBB8-4923-4388-9559-C86F5D9E2740}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{B434599E-E35F-4612-9803-A2FB7A8E066B}) (Version: 11.0.0.1156 - Intel Corporation) Hidden
Intel(R) ME UninstallLegacy (HKLM\...\{ECA145AF-55D0-42BA-870F-4213F0198A46}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel(R) Smart Connect Technology (HKLM\...\{F46EF80D-07F0-4E56-B9B3-8EDB759B52D8}) (Version: 5.0.10.2850 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00001100-0230-1029-84C8-B8D95FA3C8C3}) (Version: 23.100.1.1 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{c6cff78a-cccb-49d5-be68-ae0ec5f0d48a}) (Version: 10.1.1.8 - Intel(R) Corporation) Hidden
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{7D84E343-A23D-451C-B123-0195B2D903A6}) (Version: 1.42.17.0 - Intel Corporation) Hidden
LibreOffice 26.2.0.3 (HKLM\...\{5B9B7FC3-E7A6-4B71-922B-BDAB5FD55147}) (Version: 26.2.0.3 - The Document Foundation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Malwarebytes version 5.5.2.242 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.5.2.242 - Malwarebytes)
Microsoft .NET Host - 6.0.11 (x64) (HKLM\...\{B92B890A-04F2-4880-BA20-20D4364FB263}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.11 (x64) (HKLM\...\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.11 (x64) (HKLM\...\{C3DD1448-513A-4DB8-978D-6991562EA63D}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.53 - Microsoft Corporation) Hidden
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{659502b7-dea8-4adc-99c4-64f141a83c2d}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 (HKLM-x32\...\{b49c10dd-4d54-45f8-ad13-fa25704456a4}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34438 (HKLM-x32\...\{ba10fda9-f731-441f-a999-000bbb7ceec2}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438 (HKLM\...\{E528AD94-12D7-42C4-91A3-908BE28E9BD2}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438 (HKLM\...\{2E15F519-4FDA-4834-B4EE-7EFCE7D8D4EE}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34438 (HKLM-x32\...\{A5592FEF-F948-4BA6-A066-8BBFC2DC7EE1}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34438 (HKLM-x32\...\{5D0C4511-3CA1-4FF8-A4BA-C0E1957ABEEA}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM\...\{A39D4115-3A27-4245-AE92-3214B8B21932}) (Version: 48.47.50419 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM-x32\...\{c4846f79-a633-4ae4-92a3-92fdbeb33da2}) (Version: 6.0.11.31823 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Mozilla Firefox 157.0 (x64 cs)) (Version: 157.0 - Mozilla)
Mozilla Firefox 87.0 (x64 cs) (HKLM\...\Mozilla Firefox 87.0 (x64 cs)) (Version: 87.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 87.0 - Mozilla)
MuralPix 1.07 (HKLM-x32\...\MuralPix) (Version: - )
ocenaudio (HKLM-x32\...\ocenaudio) (Version: 3.14.10 - Rui Seara Junior)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Panzer Corps 2 (HKLM-x32\...\1698452155_is1) (Version: 1.11.01 - GOG.com)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Thrustmaster TARGET (HKLM-x32\...\{8036A569-CA02-4D33-A7E9-E9BC8A482E91}) (Version: 3.0.24.618 - Thrustmaster)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 10.52 - Ghisler Software GmbH)
UninstallFujitsu Mouse LX960 (HKLM-x32\...\{FE95C175-92E0-45E7-B771-6C82CD64B2AE}}_is1) (Version: - Fujitsu Mouse LX960)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
USB Audio (HKLM\...\{B500C5BD-165A-4F93-ADAB-BA9E3C071B6C}) (Version: 2.0.1 - Marantz)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.22 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.92.0 - Winamp SA)
WinArchiver (HKLM\...\WinArchiver) (Version: 5.7 - Power Software Ltd)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
Wooky 3.0.2.2 (HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Wooky) (Version: 3.0.2.2 - Mobilbonus, s.r.o.)
Yamaha Steinberg USB Driver (HKLM\...\{589D761D-6EBA-4BF4-90C7-0B2D7AEBAD8E}) (Version: 2.1.11 - Yamaha Corporation) Hidden
Yamaha Steinberg USB Driver (HKLM-x32\...\yUninstall_{2938B185-2D57-47B0-9FC8-C90A67BA9277}) (Version: 2.1.11 - Yamaha Corporation)
Youtube Downloader HD v. 5.9.9.10 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com)

Packages:
=========
7-Zip File Manager (Unofficial) -> C:\Program Files\WindowsApps\HaukeGtze.7-ZipFileManagerUnofficial_1.2201.1.0_x64__6bk20wvc8rfx2 [2025-04-19] (Hauke Hasselberg)
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2026-09-09] ()
RAR Opener -> C:\Program Files\WindowsApps\DeviceDoctor.RAROpener_1.3.48.0_x64__mkdtfchztkfbm [2026-07-27] (Tiny Opener)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{4F2B02E3-DC31-489F-9FC8-B87598E9BCFC}\InprocServer32 -> C:\Mozilla Firefox\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel(R) pGFX 2020 -> Intel Corporation)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{C78B614F-F3EA-11D2-94A1-00E0292A01E3}\InprocServer32 -> C:\Program Files (x86)\Altap Salamander\utils\salextx64.dll (Fine spol. s r.o. -> ALTAP)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-06-08] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2021-07-16] (Notepad++ -> )
ContextMenuHandlers1: [WinArchiver] -> {A6630968-27DC-8DB8-9BCE-E12B3198A9B1} => C:\Program Files\WinArchiver\WASHELL.DLL [2024-04-14] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-03-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [WinArchiver] -> {A6630968-27DC-8DB8-9BCE-E12B3198A9B1} => C:\Program Files\WinArchiver\WASHELL.DLL [2024-04-14] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2020-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvshext.dll [2025-03-15] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-03-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [WinArchiver] -> {A6630968-27DC-8DB8-9BCE-E12B3198A9B1} => C:\Program Files\WinArchiver\WASHELL.DLL [2024-04-14] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\system32\ff_vfw.dll [127488 2014-06-28] () [File not signed]
HKLM\...\Drivers32-x32: [VIDC.FFDS] => ff_vfw.dll
HKLM\...\Drivers32: [vidc.tscc] => C:\Program Files (x86)\MpcStar\Codecs\tscc\tsccvid.dll [102400 2008-07-08] (TechSmith Corporation) [File not signed]

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2026-09-14 01:16 - 2026-10-04 05:47 - 000192512 _____ () [File not signed] C:\Users\PC\AppData\Local\Temp\sfamcc00001.dll
2026-09-22 11:19 - 2026-10-04 05:47 - 000158720 _____ () [File not signed] C:\Users\PC\AppData\Local\Temp\sfareca00001.dll
2026-04-12 22:28 - 2026-04-12 22:28 - 000030720 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\Acrobat Elements\ContextMenuShim64.cze
2021-03-23 17:26 - 2021-03-23 17:26 - 000122880 ____N (C-Media Electronics Inc.) [File not signed] C:\Windows\System\HsSrv64.dll
2015-05-22 01:59 - 2015-05-22 01:59 - 001202688 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Intel\iCLS Client\LIBEAY32.dll
2015-05-22 01:59 - 2015-05-22 01:59 - 000306688 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Intel\iCLS Client\ssleay32.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2022-11-29 20:08 - 000000828 _____ C:\Windows\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.5.1 - 172.21.1.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Broadcom NetLink (TM) Gigabit Ethernet -> k57nd60a.sys

steamxboxndi: Steam Xbox Controller Enhanced Features Driver

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\dotnet\
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\Control Panel\Desktop\\Wallpaper -> c:\users\pc\appdata\roaming\mozilla\firefox\pozadí plochy.bmp
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "ISCT Tray"
HKLM\...\StartupApproved\Run: => "Cmaudio8788"
HKLM\...\StartupApproved\Run: => "Start WingMan Profiler"
HKLM\...\StartupApproved\Run32: => "Fujitsu Mouse LX960"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "ISCT Tray"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "DualSenseX"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "Application Restart #0"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{1B38B56F-40FA-445E-A85F-A19EDC28BC0D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7EFDB021-F8CA-4192-BB38-BAD2560F818F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FAB62E66-85BA-48F1-B647-9DA88CEAA711}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{EA034265-458D-4C38-B6FB-DEA5FD5CDEE8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E6AA9AA5-9D34-4A16-BB9A-CD7BCF591160}] => (Allow) D:\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{86C8FDBC-3C48-4227-A827-A3E40126E6D8}] => (Allow) D:\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{9BED10CE-BC62-4E7A-BA7F-31B3C26574C2}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{286814D8-B567-46CB-979C-F75E7CF505E1}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{344689AA-FCEF-4FDE-B2ED-91FBBB141AD4}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent, Inc.)
FirewallRules: [{6122EF37-CDFD-460A-95C2-CCA56BE1007B}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent, Inc.)
FirewallRules: [{41BA48C4-2FD8-4098-9313-5C1E761D4810}] => (Allow) C:\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{D3709EB1-28E6-4601-BB3B-D726507856E4}] => (Allow) C:\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{40642B31-D916-4F00-8157-9965E5D35737}] => (Allow) D:\Steam\steamapps\common\Xenonauts\Xenonauts.exe () [File not signed]
FirewallRules: [{CDB3D726-A12A-46C2-8152-A7286E671071}] => (Allow) D:\Steam\steamapps\common\Xenonauts\Xenonauts.exe () [File not signed]
FirewallRules: [{E974110C-73CB-47F8-A2B8-61400BB352A1}] => (Allow) D:\Steam\steamapps\common\Project CARS 2\pCARS2.exe (Slightly Mad Studios Ltd) [File not signed]
FirewallRules: [{295B1D99-D292-417A-BA5B-FEC52C9E18BB}] => (Allow) D:\Steam\steamapps\common\Project CARS 2\pCARS2.exe (Slightly Mad Studios Ltd) [File not signed]
FirewallRules: [TCP Query User{866C3C38-49B6-4EB7-8D7F-1926F0E2C9C1}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{16B0A46E-1501-481F-A303-C986C7B678D5}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{CD0617C8-D2C0-4CAE-8E1A-E32503F0A076}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Cliffs of Dover Blitz\Launcher64.exe (Team Fusion Simulations Ltd. -> 1C:SoftClub)
FirewallRules: [{761D1E59-EB82-4EA6-89BF-E5FF661AC0A2}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Cliffs of Dover Blitz\Launcher64.exe (Team Fusion Simulations Ltd. -> 1C:SoftClub)
FirewallRules: [{314D97EE-35A3-49F5-B05D-5594478B02A0}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Battle of Stalingrad\bin\game\Il-2.exe (LLC 1c Game Studios -> FOR-GAMES CR LTD)
FirewallRules: [{EABE4FDE-C836-4A17-890C-562F6A60C4E2}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Battle of Stalingrad\bin\game\Il-2.exe (LLC 1c Game Studios -> FOR-GAMES CR LTD)
FirewallRules: [{5304423E-EBD1-44C7-8C35-5C0C769A587B}] => (Allow) D:\Steam\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe (Larian Studios Games Ltd. -> LariLauncher)
FirewallRules: [{E20B44D5-D34B-4065-A77E-7026C3309554}] => (Allow) D:\Steam\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe (Larian Studios Games Ltd. -> LariLauncher)
FirewallRules: [{882B7A1F-ED70-40F1-B9E2-B6AF4FE7AD0E}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{CA9CD3CB-6215-47BC-8395-8C2B0CBB7248}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{DE145AB4-C63B-43C5-98E3-27A1325EC802}] => (Allow) D:\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F9ED3B27-21AC-4CA8-818C-C461F83D424A}] => (Allow) D:\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{9D9538FD-FE69-47CA-8828-4CA61C503497}] => (Allow) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)

==================== Restore Points =========================

17-09-2026 11:01:54 Naplánovaný kontrolní bod
26-09-2026 09:03:59 Installed Yamaha Steinberg USB Driver

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================

System errors:
=============
Error: (10/04/2026 05:52:16 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/04/2026 04:40:43 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/03/2026 06:46:14 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/02/2026 06:50:07 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/02/2026 06:45:06 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (18:41:21, ‎02.‎10.‎2026) bylo neočekávané.

Error: (10/01/2026 06:22:55 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/01/2026 12:00:00 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (09/30/2026 04:42:49 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0


Windows Defender:
================

TimeCreated : 29.09.2026 8:39:27
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
5E22D0EB-C689-40BF-B0CC-ED8990C40B7E}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 28.09.2026 8:42:36
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
C514D958-2B8E-4A04-8E43-119D390AD228}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 27.09.2026 10:09:25
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
9E93DA09-30AB-43F1-B469-ADBD1A298652}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 26.09.2026 11:29:53
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
C9E38731-A7BF-4197-9AFC-EA40EED93F27}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъҐРĈ ċōηʼnëстĭøи яúñðöŵй

TimeCreated : 21.09.2026 8:36:28
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
90B9B3F0-4660-4CAC-A862-AA4FF36C43E4}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 20.09.2026 8:43:56
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
CA459285-872E-49C1-8C6B-4E4CAE3FCE59}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 18.09.2026 9:12:36
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
9E65CC29-2DB6-409B-BFEA-1B1FD61E67B2}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅćђęđμĺēδ ѕčªη ωáŝ şĸΐррėď ьê¢āúşє ţнё ľãŝ
τ šūçсëśşƒüℓ şсāņ ωąş щĩţнïņ ŧђё ĺǻŝť 7 ðαỳş

TimeCreated : 17.09.2026 9:27:40
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
E6846E99-5376-42CD-8B25-C39FB06A06DA}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅćђęđμĺēδ ѕčªη ωáŝ şĸΐррėď ьê¢āúşє ţнё ľãŝ
τ šūçсëśşƒüℓ şсāņ ωąş щĩţнïņ ŧђё ĺǻŝť 7 ðαỳş


CodeIntegrity:
===============
Date: 2026-10-04 05:47:17
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

BIOS: American Megatrends Inc. P2.80 07/01/2013
Motherboard: ASRock Z77 Extreme6
Processor: Intel(R) Core(TM) i5-3450 CPU @ 3.10GHz
Percentage of memory in use: 28%
Total physical RAM: 16268.1 MB
Available physical RAM: 11665.15 MB
Total Virtual: 18700.1 MB
Available Virtual: 13024.37 MB

==================== Drives ================================

Disk 1 - Drive c: () (Fixed) (Total:232.28 GB) (Free:10.12 GB) (Model: WDC WD2500HHTZ-04N21V0) NTFS
Disk 0 - Drive d: (ROCOR GYM) (Fixed) (Total:931.5 GB) (Free:20.3 GB) (Model: WDC WD10EZEX-08WN4A0) NTFS
Disk 2 - Drive f: () (Removable) (Total:114.58 GB) (Free:2.14 GB) FAT32
Disk 3 - Drive h: () (Fixed) (Total:465.76 GB) (Free:4.76 GB) (Model: ST500LM0 12 HN-M500MB USB Device) NTFS

Disk 1 - \\?\Volume{de8f403c-78c6-4da3-98dd-7c65f59081c4}\ () (Fixed) (Total:498 MB) (Free:81.76 MB) NTFS
Disk 1 - \\?\Volume{f65d7f54-4dcf-4e60-95b6-df53b1a403eb}\ () (Fixed) (Total:96 MB) (Free:69 MB) FAT32

==================== MBR & Partition Table ====================

============================================================
Disk: 0 (Protective MBR) (Size: 931.51 GB)

Partitions:
===========
Partition Style : GPT
Partition Count : 2
Disk ID : {C76A7A3F-AFDD-463E-BB00-C678181B8D83}
Usable Offset : 0.02 MB
Usable Length : 931.51 GB
Max Partitions : 128

Partition 1
Type : Microsoft Reserved (MSR)
Size : 15.98 MB
Offset : 0.02 MB
Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
Partition GUID : {EEDF0ECA-5A80-4626-AA4A-35CB3E8CEC04}
GPT Name : Microsoft reserved partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 2
Type : Basic Data Partition
Size : 931.5 GB
Offset : 16 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {A1EFA991-AE62-4E96-81DC-A633628DE46F}
GPT Name : Basic data partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------


============================================================
Disk: 1 (Size: 232.89 GB) (Disk ID: 0BA592B7)

Partitions:
===========
Partition Style : GPT
Partition Count : 4
Disk ID : {AD3CA0E2-8C5D-43FA-A3E9-EDF9CF9A91D9}
Usable Offset : 0.02 MB
Usable Length : 232.89 GB
Max Partitions : 128

Partition 1
Type : EFI System Partition
Size : 100 MB
Offset : 1 MB
Type GUID : {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}
Partition GUID : {F65D7F54-4DCF-4E60-95B6-DF53B1A403EB}
GPT Name : EFI system partition
Attributes : 0x8000000000000000
Attribute Flags : No Default Drive Letter
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 2
Type : Microsoft Reserved (MSR)
Size : 16 MB
Offset : 101 MB
Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
Partition GUID : {F0C39394-B12D-490D-9EE9-3AEE25B12C2B}
GPT Name : Microsoft reserved partition
Attributes : 0x8000000000000000
Attribute Flags : No Default Drive Letter
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 3
Type : Basic Data Partition
Size : 232.28 GB
Offset : 117 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {FE5B68A7-CB6F-4673-800F-E01FAF2C4501}
GPT Name : Basic data partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------
Partition 4
Type : Windows Recovery
Size : 498 MB
Offset : 237976 MB
Type GUID : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}
Partition GUID : {DE8F403C-78C6-4DA3-98DD-7C65F59081C4}
Attributes : 0x8000000000000001
Attribute Flags : Platform Required, No Default Drive Letter
Hidden : Yes
Platform Required: Yes
------------------------------------------------------------


============================================================
Disk: 2 (Protective MBR) (Size: 114.61 GB)

Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0x00000000

Partition 1
Type : MBR 0x0C (FAT32 LBA)
Size : 114.61 GB
Offset : 0.02 MB
Partition GUID : {00000000-0000-0000-0040-000000000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 32
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 1


============================================================
Disk: 3 (Size: 465.76 GB) (Disk ID: A345F4C7)

Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0xA345F4C7

Partition 1
Type : MBR 0x07 (NTFS / exFAT / HPFS)
Size : 465.76 GB
Offset : 1 MB
Partition GUID : {A345F4C7-0000-0000-0000-100000000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 2048
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 1

============================================================

==================== End of Addition.txt =======================

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120145
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: napadení PC

#4 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
S3 PrintNotify; C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll [3596288 2021-03-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
C:\DumpStack.log.tmp
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hynek88
Návštěvník
Návštěvník
Příspěvky: 68
Registrován: 18 Ún 2012 06:47

Re: napadení PC

#5 Příspěvek od Hynek88 »

Fix result of Farbar Recovery Scan Tool (x64) Version: 01-10-2026
Ran by PC (04-10-2026 14:55:35) Run:8
Running from C:\Users\PC\Desktop
Loaded Profiles: PC
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
S3 PrintNotify; C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll [3596288 2021-03-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
C:\DumpStack.log.tmp
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\System\CurrentControlSet\Services\PrintNotify => removed successfully
PrintNotify => service removed successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.

HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5410572 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 412508853 B
Windows/system/drivers => 8848397 B
Edge => 147456 B
Brave => 157892799 B
Firefox => 116386020 B
Opera => 0 B

Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 5 B
ProgramData => 0 B
Public => 0 B
systemprofile => 501280 B
systemprofile32 => 159 B
LocalService => 5 B
NetworkService => 454949 B
PC => 17805543 B

RecycleBin => 0 B
EmptyTemp: => 687.85 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 04-10-2026 15:42:53)

C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 15:42:54 ====

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120145
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: napadení PC

#6 Příspěvek od Rudy »

Vše bylo smazáno.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hynek88
Návštěvník
Návštěvník
Příspěvky: 68
Registrován: 18 Ún 2012 06:47

Re: napadení PC

#7 Příspěvek od Hynek88 »

Díky!

no a vyplývá z toho něco?

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120145
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: napadení PC

#8 Příspěvek od Rudy »

Pokud jste v systému něco měl, pak to bylo uloženo v dočasných souborech. Tam mi log ukáže pouze to, že byly smazány, bez konkrétního výčtu (nejsou pro systém důležité). Ty jmenovité jsou nějaký print manager, dočasný adresář a záznsm v registry která zbyl po smazaném souboru. Jinak OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hynek88
Návštěvník
Návštěvník
Příspěvky: 68
Registrován: 18 Ún 2012 06:47

Re: napadení PC

#9 Příspěvek od Hynek88 »

ok,

tak zatím díky!

Avatar uživatele
Rudy
Site Admin
Site Admin
Příspěvky: 120145
Registrován: 30 Říj 2003 13:42
Místo/Bydliště: Plzeň
Kontaktovat uživatele:

Re: napadení PC

#10 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno