Stránka 1 z 1

napadení PC

Odeslal: 04 Říj 2026 08:20
od Hynek88
Zdravím,

vypadá to, že se mně ňáký dobrodruzi dostali do pc, jde to nějak zjistit?

popřípadě vypnout nějáký funkce, služby?

děkuji za případné řešení.

Re: napadení PC

Odeslal: 04 Říj 2026 10:20
od Rudy
Zdravím!
Nejprve dejte log FRST: http://forum.viry.cz/viewtopic.php?f=24&t=132509 .

Re: napadení PC

Odeslal: 04 Říj 2026 11:31
od Hynek88
frst--

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-10-2026
Ran by PC (administrator) on DESKTOP-3CTVH0E (04-10-2026 12:23:10)
Running from C:\Users\PC\Desktop\FRST64.exe
Loaded Profiles: PC
Platform: Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler64.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe
(DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atieclxx.exe
(explorer.exe ->) () [File not signed] C:\Windows\System\HsMgr64.exe
(explorer.exe ->) () [File not signed] C:\Windows\SysWOW64\HsMgr.exe
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
(explorer.exe ->) (BitTorrent Inc -> BitTorrent, Inc.) C:\Program Files (x86)\uTorrent\uTorrent.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Learsy) [File not signed] C:\Program Files (x86)\MuralPix\MpAgent.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\atiesrxx.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(services.exe ->) (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Malwarebytes Corporation -> Malwarebytes) C:\ProgramData\MB3Install\MBAMIService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2607.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (J's Future Corp. -> ) C:\Program Files (x86)\TabService\tabservicepack.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (SOKNO S.R.L. -> ) C:\Program Files (x86)\SpeedFan\speedfan.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ISCT Tray] => C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [5860656 2014-06-18] (Intel CASE -> Intel Corporation)
HKLM\...\Run: [Cmaudio8788] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd [13463552 2021-03-23] (C-Media Corporation) [File not signed]
HKLM\...\Run: [Cmaudio8788GX] => C:\Windows\syswow64\HsMgr.exe [200704 2021-03-23] () [File not signed]
HKLM\...\Run: [Cmaudio8788GX64] => C:\Windows\system\HsMgr64.exe [282112 2021-03-23] () [File not signed]
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech -> Logitech Inc.)
HKLM-x32\...\Run: [MuralPixAgent] => C:\Program Files (x86)\MuralPix\MpAgent.exe [102400 2006-12-30] (Learsy) [File not signed]
HKLM-x32\...\Run: [Fujitsu Mouse LX960] => C:\Program Files (x86)\Fujitsu Mouse LX960\DriverAP4.exe [1719808 2019-10-08] (Fujitsu) [File not signed]
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Run: [Steam] => D:\Steam\steam.exe [5767832 2026-03-13] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Run: [DualSenseX] => C:\Users\PC\AppData\Local\DualSenseX\DualSenseX.exe [328192 2025-01-04] () [File not signed]
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [45610456 2026-09-16] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\RunOnce: [Application Restart #0] => C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe [4425808 2026-10-02] (Brave Software, Inc. -> Brave Software, Inc.)
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\SysWOW64\MuralPix.scr [106496 2006-12-30] (Learsy) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" --first-run (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\154.1.96.61\Installer\chrmstp.exe [6493264 2026-10-02] (Brave Software, Inc. -> Brave Software, Inc.)
Startup: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Speedfan Startup.lnk [2021-03-28]
ShortcutTarget: Speedfan Startup.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Windows -> Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {6BBC76C6-B263-44AC-924F-C6F4E1BEB04D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1617408 2026-08-03] (Adobe Inc. -> Adobe Inc.)
Task: {EA8C714A-80F0-45C6-9DCF-179C4D8DDAE2} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore{096F4ABF-A5B5-4D33-BC04-5BBAA571C85F} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {6764ACC0-D2FF-4FC5-B863-AFD2E4ACC7C4} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {EADBEAA2-0E38-4DA7-B3DE-FB61D0722FEC} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {41E9C842-585E-468B-B09B-9E0DAE8AD059} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6140920 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "deaa1c9e-3d31-4138-b212-954468be02e8" --version "6.41.0.11567" --silent
Task: {1709A315-EB60-4417-B501-E05062D7AD4F} - System32\Tasks\CCleanerSkipUAC - PC => C:\Program Files\CCleaner\CCleaner.exe [39839224 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3D8C4218-B793-40AE-BC7F-346E307B6A95} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {46102E77-D26A-4201-9AB6-9481154C87F6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {64E2EC95-B9F5-48E7-8FEE-38816D521A6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0F43F7D2-D213-4A2B-BAA4-7558AC6BCA04} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpCmdRun.exe [1902880 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {70DC0CDE-E0DF-45EF-A0A4-8C0BBBEC3A49} - System32\Tasks\Mozilla\Firefox Default Browser Agent 9388B6559483FD17 => C:\Mozilla Firefox\default-browser-agent.exe [44160 2026-09-29] (Mozilla Corporation -> Mozilla Foundation)
Task: {1D270147-DD55-4E70-9FBD-5177E19A1EE4} - System32\Tasks\Speedfan Startup => C:\Program Files (x86)\SpeedFan\speedfan.exe [8166536 2016-06-29] (SOKNO S.R.L. -> ) -> /c start "Speedfan Startup" "C:\Program Files (x86)\SpeedFan\speedfan.exe"
Task: {67321662-FA67-4707-B2E0-1B813C745DB6} - System32\Tasks\TabServiceScheduler => C:\Program Files (x86)\TabService\tabservicepack.exe [1385832 2026-06-11] (J's Future Corp. -> )

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.5.1 172.21.1.1 172.21.1.2
Tcpip\..\Interfaces\{154e81dd-97c9-424e-bd8c-4ca78f603f95}: [DhcpNameServer] 192.168.5.1 172.21.1.1 172.21.1.2
Tcpip\..\Interfaces\{154e81dd-97c9-424e-bd8c-4ca78f603f95}: [DhcpDomain] lan

FireFox:
========
FF TaskBarID: 9388B6559483FD17 -> C:\Mozilla Firefox
FF DefaultProfile: cmv64535.default-1617030860948 -> 9388B6559483FD17
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948 [2026-10-04]
FF Homepage: Mozilla\Firefox\Profiles\cmv64535.default-1617030860948 -> hxxps://www.templ.net/cesky/patrick_barta_a_kontakt.php
FF Session Restore: Mozilla\Firefox\Profiles\cmv64535.default-1617030860948 -> is enabled.
FF Extension: (Dark Reader) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\addon@darkreader.org.xpi [2026-09-25]
FF Extension: (uBlock Origin) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\uBlock0@raymondhill.net.xpi [2026-09-16]
FF Extension: (Dark space - The best dynamic theme) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{22b0eca1-8c02-4c0d-a5d7-6604ddd9836e}.xpi [2024-01-26]
FF Extension: (Galaxy Space Theme) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{5eae7880-dab2-4337-bc53-e4b58db7aec4}.xpi [2022-12-19]
FF Extension: (This is a sunrise) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{8295aeba-205d-4a8a-8155-c0f8f0f959a1}.xpi [2022-11-26]
FF Extension: (Fractal Senzune Alphacoder) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{ceefc8d7-d251-4762-bfcd-35cdeb3c52cd}.xpi [2023-03-08]
FF Extension: (Northern Lake FT by MaDonna) - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\cmv64535.default-1617030860948\Extensions\{fcebb804-5eb9-43d9-a12a-30f6ca1b9b1b}.xpi [2021-06-02]
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\c5xkfvmc.default-1616169207305 [2026-10-04]
FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\16rhk66j.default-1483610832811 [2026-10-04]
FF Plugin: @videolan.org/vlc,version=3.0.22 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-11-27] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-09-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
StartMenuInternet: Firefox-9388B6559483FD17 - C:\Mozilla Firefox\firefox.exe

Edge:
=======
Edge Profile: C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default [2026-10-04]

Chrome:
=======
CHR HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

Brave:
=======
BRA DefaultProfile: Default
BRA Profile: C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2026-10-04]
BRA DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}&t=brave
BRA DefaultSearchKeyword: Default -> :d
BRA DefaultSuggestURL: Default -> hxxps://ac.duckduckgo.com/ac/?q={searchTerms}&type=list
BRA Extension: (DuckDuckGo) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2026-09-03]
BRA Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-09-25]
BRA Extension: (Dark Reader) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2026-09-25]
BRA Profile: C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Guest Profile [2024-09-04]
BRA Profile: C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\System Profile [2025-10-05]
BRA Extension: (Brave Ad Block Updater (Brave First Party Adblock Filters (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2026-09-23]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2026-10-02]
BRA Extension: (Brave NTP background images) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2026-09-23]
BRA Extension: (Brave Ad Block Updater (Fanboy's Mobile Notifications (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2026-09-25]
BRA Extension: (Wallet Data Files Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2024-01-30]
BRA Extension: (Brave Ad Block Updater (EasyList Cookie (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2026-10-04]
BRA Extension: (Query Filter) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cemdlagocoimleflkfkjoihojfainiho [2026-10-04]
BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2023-08-04]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2025-08-16]
BRA Extension: (Brave NTP sponsored images) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\efkihffiamafhbhefjaljejgdpkelpal [2026-09-25]
BRA Extension: (Brave WebMCP Tool Scripts) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\eingdhelnaolbpcdkgddekhifcjfkalf [2026-09-15]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2026-09-09]
BRA Extension: (Brave Ads Resources) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\iejekkikpddbbockoldagmfcdbffomfc [2026-02-21]
BRA Extension: (Brave Ad Block Updater (Brave Ad Block Updater (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2026-10-04]
BRA Extension: (Brave SpeedReader Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2022-03-10]
BRA Extension: (Brave Ad Block Updater (Brave Default Privacy Filters (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\kihnoaefogbkmblfimmibknnmkllbhlf [2026-10-04]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2026-09-21]
BRA Extension: (Brave Ad Block Updater (Brave Twitch Adblock Rules (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\mhccgcegedfkhdbfbgllfkkcjhgkoinc [2024-09-19]
BRA Extension: (Brave User Agent) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\nlpaeekllejnmhoonlpcefpfnpbajbpe [2026-10-04]
BRA Extension: (Brave Ad Block Updater (Czech and Slovak website ad blocker (plaintext))) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\oegebjahecghlckbhkmojgnpcgdeajdi [2026-09-15]
BRA Extension: (Brave Ad Block Updater (CZE, SVK: EasyList Czech and Slovak)) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\omkkefoeihpbpebhhbhmjekpnegokpbj [2023-04-15]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2023-10-26]
BRA Extension: (P3A Configuration) - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\P3AConfig [2025-09-27]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [182776 2026-08-03] (Adobe Inc. -> Adobe Inc.)
S3 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 BraveElevationService; C:\Program Files\BraveSoftware\Brave-Browser\Application\154.1.96.61\elevation_service.exe [5151824 2026-10-02] (Brave Software, Inc. -> Brave Software, Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-03-24] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1080824 2026-06-19] (Gen Digital Inc. -> Gen Digital Inc.)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
S3 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-06-18] (Intel CASE -> )
S3 LibreOfficeMaintenance; C:\Program Files\LibreOffice\program\update_service.exe [125352 2026-01-28] (The Document Foundation -> The Document Foundation)
R2 MBAMIService; C:\ProgramData\MB3Install\MBAMIService.exe [231120 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11420952 2026-03-27] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-03-27] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe [2307776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\Display.NvContainer\NVDisplay.Container.exe [1275016 2025-03-15] (NVIDIA Corporation -> NVIDIA Corporation)
S3 PrintNotify; C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll [3596288 2021-03-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
S4 tmAInstall; C:\Program Files\Thrustmaster\Hotas Warthog\drivers\amd64\tmAInstall.exe [38408 2018-03-01] (Guillemot Recherche et Développement, Inc -> Thrustmaster®)
S4 TmWinService; C:\Program Files (x86)\Thrustmaster\TARGET\TmService.exe [320544 2024-07-02] (Guillemot Corporation S.A. -> Guillemot Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe [5311776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe [291360 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdfendrmgr; C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_5f2cd636dbc40dd2\amdfendrmgr.sys [25672 2024-04-23] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\Windows\System32\DriverStore\FileRepository\amdsafd.inf_amd64_960126269e89c62e\amdsafd.sys [113880 2024-05-10] (Advanced Micro Devices -> Advanced Micro Devices)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0407052.inf_amd64_84d15514ad17ffa0\B406619\amdkmdag.sys [106596128 2024-09-04] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2021-09-15] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [154112 2021-10-13] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R3 cmudaxp; C:\Windows\system32\drivers\cmudaxp.sys [2735616 2021-03-23] (C-MEDIA ELECTRONICS INC. -> C-Media Inc)
S3 INETMON; \??\C:\Windows\System32\Drivers\INETMON.sys [25800 2014-05-27] (Intel CASE -> )
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [83008 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [245864 2026-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MZ_USBAUDIO; C:\Windows\system32\drivers\mz_usbaudio.sys [144896 2013-05-14] (DandM Holdings Inc. -> D&M Holdings Inc.)
R2 speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> )
R1 steamxbox; C:\Windows\System32\drivers\steamxbox.sys [278208 2023-02-21] (Valve Corp. -> Valve Corporation)
R3 TmBusEn; C:\Windows\System32\drivers\TmBusEn.sys [43088 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
R3 TmBusEn; C:\Windows\SysWOW64\drivers\TmBusEn.sys [43088 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmFilter; C:\Windows\System32\drivers\TmFilter.sys [70736 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmFilter; C:\Windows\SysWOW64\drivers\TmFilter.sys [70736 2023-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Guillemot Corporation)
S3 TmHid; C:\Windows\system32\DRIVERS\TmHid.sys [49040 2023-12-14] (WDKTestCert plukidis,131540205154897060 -> Guillemot Corporation)
S3 TmHid; C:\Windows\SysWOW64\DRIVERS\TmHid.sys [49040 2023-12-14] (WDKTestCert plukidis,131540205154897060 -> Guillemot Corporation)
S4 WdAiNisDrv; C:\Windows\System32\drivers\wd\WdAiNisDrv.sys [51264 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21632 2026-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [664592 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [137240 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 ysusb_w10_64; C:\Windows\System32\DriverStore\FileRepository\ysusb_w10.inf_amd64_0c08afcf04fddf00\ysusb_w10_64.sys [199160 2026-06-11] (WDKTestCert AF919676,134063601988638324 -> Yamaha Corporation)

==================== SvcHost (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-10-04 12:23 - 2026-10-04 12:24 - 000026228 _____ C:\Users\PC\Desktop\FRST.txt
2026-10-04 12:16 - 2026-10-04 12:16 - 002456064 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2026-10-04 06:42 - 2026-10-04 06:42 - 000021365 _____ C:\Users\PC\Downloads\Chosen Survivors (1974) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-10-04 06:31 - 2026-10-04 06:31 - 000021804 _____ C:\Users\PC\Downloads\Rose (2026) [1080p] [BluRay] [x265] [10bit] [5.1] [YTS.GG - YTS.BZ].torrent
2026-10-01 19:02 - 2026-10-01 19:02 - 000017803 _____ C:\Users\PC\Downloads\the-cursed-2025-1080p-korean-web-dl-hevc-x265-5-1-bone-mkv.torrent
2026-10-01 18:38 - 2026-10-01 18:38 - 000012923 _____ C:\Users\PC\Downloads\--the-cursed-2025-dsnp-web-dl-1080p-h-264-ddp5-1-ngp.torrent
2026-09-29 19:05 - 2026-09-29 19:05 - 000000000 ____D C:\Mozilla Firefox
2026-09-29 16:36 - 2026-10-03 04:45 - 000003716 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{221C60D5-F766-43A8-86A4-2138D1921CC5}
2026-09-29 16:36 - 2026-10-03 04:45 - 000003644 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{E1551A82-DA2D-4EBA-A531-C4132BC7A1C5}
2026-09-26 09:04 - 2026-09-26 09:04 - 000002521 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yamaha Steinberg USB Control Panel.lnk
2026-09-26 09:04 - 2026-09-26 09:04 - 000000000 ____D C:\Program Files (x86)\Yamaha
2026-09-26 09:03 - 2026-09-26 09:04 - 000000000 ____D C:\ProgramData\Yamaha_Uninstaller
2026-09-25 05:54 - 2026-09-25 05:54 - 000001159 _____ C:\Users\PC\Documents\Nový textový dokument.txt
2026-09-21 20:18 - 2026-09-21 20:18 - 000062720 _____ C:\Users\PC\Downloads\Dèmoni 2... l'incubo ritorna (1986) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 20:16 - 2026-09-21 20:16 - 000061116 _____ C:\Users\PC\Downloads\Dèmoni (1985) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 17:14 - 2026-09-21 17:14 - 000071608 _____ C:\Users\PC\Downloads\Muse (2017) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 17:12 - 2026-09-21 17:12 - 000076937 _____ C:\Users\PC\Downloads\Mientras duermes (2011) [1080p] [BluRay] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-21 15:22 - 2026-09-21 15:22 - 000068127 _____ C:\Users\PC\Downloads\Route Irish (2010) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-21 15:18 - 2026-09-21 15:18 - 000070414 _____ C:\Users\PC\Downloads\Los cronocrímenes (2007) [1080p] [BluRay] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-21 09:25 - 2026-09-21 09:25 - 000018236 _____ C:\Users\PC\Downloads\--resident-evil-2026-1080p-telesync-multi-x264-dks.torrent
2026-09-20 02:49 - 2026-09-20 02:49 - 000021420 _____ C:\Users\PC\Downloads\Los ojos de Julia (2010) [1080p] [BluRay] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-17 04:18 - 2026-09-17 04:18 - 000042582 _____ C:\Users\PC\Downloads\karupsow-13-10-07-louise-pearce-solo-2-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:18 - 2026-09-17 04:18 - 000040960 _____ C:\Users\PC\Downloads\karupsha-13-10-07-riley-grey-solo-5-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:17 - 2026-09-17 04:17 - 000057344 _____ C:\Users\PC\Downloads\brazzers-plib---skin-diamond-ultimate-sin-480p.torrent
2026-09-17 04:17 - 2026-09-17 04:17 - 000041381 _____ C:\Users\PC\Downloads\karupsha-13-10-07-mia-mea-solo-1-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:17 - 2026-09-17 04:17 - 000037461 _____ C:\Users\PC\Downloads\karupspc-13-10-07-serenity-reed-solo-2-xxx-720p-mp4-sexorsrarbg.torrent
2026-09-17 04:16 - 2026-09-17 04:16 - 000315360 _____ C:\Users\PC\Downloads\pornstarslikeitbig-13-10-07-skin-diamond-ultimate-sin-xxx-1080p-mp4-sexors.torrent
2026-09-17 04:16 - 2026-09-17 04:16 - 000043870 _____ C:\Users\PC\Downloads\firstclasspov-skin-diamond-skin-diamond-glam-bj-mp4.torrent
2026-09-17 04:16 - 2026-09-17 04:16 - 000031074 _____ C:\Users\PC\Downloads\pornstarslikeitbig---skin-diamond---ultimate-sin-mp4.torrent
2026-09-17 04:15 - 2026-09-17 04:15 - 000194648 _____ C:\Users\PC\Downloads\ls-studios-collection---ls-dreams.torrent
2026-09-17 04:15 - 2026-09-17 04:15 - 000142361 _____ C:\Users\PC\Downloads\footworship-13-09-06-kristina-rose-and-skin-diamond-xxx-720p-mp4-ktrrarbg.torrent
2026-09-17 04:15 - 2026-09-17 04:15 - 000013662 _____ C:\Users\PC\Downloads\cherrypimpssoloskindiamond-mp4-1.torrent
2026-09-17 04:14 - 2026-09-17 04:14 - 000042236 _____ C:\Users\PC\Downloads\karupspc-15-05-12-skin-diamond-solo-1-xxx-720p-mp4-ktrmedm.torrent
2026-09-17 04:14 - 2026-09-17 04:14 - 000034654 _____ C:\Users\PC\Downloads\skin-diamond-solo-1080-mp4.torrent
2026-09-17 04:14 - 2026-09-17 04:14 - 000013662 _____ C:\Users\PC\Downloads\cherrypimpssoloskindiamond-mp4.torrent
2026-09-16 14:40 - 2026-09-16 14:40 - 000039212 _____ C:\Users\PC\Downloads\school-models-paula-custom-sheer-panties-topless-avi.torrent
2026-09-16 14:39 - 2026-09-16 14:39 - 000021504 _____ C:\Users\PC\Downloads\A Prize of Gold (1955) [1080p] [BluRay] [YTS.GG - YTS.BZ].torrent
2026-09-16 14:39 - 2026-09-16 14:39 - 000019191 _____ C:\Users\PC\Downloads\school-models-paula-vids.torrent
2026-09-16 14:38 - 2026-09-16 14:38 - 000023851 _____ C:\Users\PC\Downloads\The End of Oak Street (2026) [2160p] [WEBRip] [x265] [10bit] [5.1] [YTS.GG - YTS.BZ].torrent
2026-09-16 14:38 - 2026-09-16 14:38 - 000022721 _____ C:\Users\PC\Downloads\The End of Oak Street (2026) [1080p] [WEBRip] [x265] [10bit] [5.1] [YTS.GG - YTS.BZ].torrent

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-10-04 12:24 - 2021-03-24 21:19 - 000000000 ____D C:\Users\PC\AppData\Roaming\uTorrent
2026-10-04 12:23 - 2021-12-27 09:49 - 000000000 ____D C:\FRST
2026-10-04 12:22 - 2025-04-19 07:11 - 000000000 ____D C:\Program Files\CCleaner
2026-10-04 12:21 - 2021-03-24 21:23 - 000000000 ____D C:\Users\PC\AppData\Local\CrashDumps
2026-10-04 12:18 - 2025-03-29 17:13 - 000003386 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2026-10-04 12:18 - 2025-03-29 17:13 - 000000670 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2026-10-04 12:13 - 2020-09-27 07:50 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-10-04 12:01 - 2021-12-16 06:28 - 000000000 ____D C:\Windows\SystemTemp
2026-10-04 10:05 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-10-04 05:51 - 2021-03-23 16:56 - 001693820 _____ C:\Windows\system32\PerfStringBackup.INI
2026-10-04 05:51 - 2019-12-07 16:41 - 000716932 _____ C:\Windows\system32\perfh005.dat
2026-10-04 05:51 - 2019-12-07 16:41 - 000145110 _____ C:\Windows\system32\perfc005.dat
2026-10-04 05:51 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2026-10-04 05:48 - 2021-03-24 12:19 - 000000000 ____D C:\Program Files (x86)\SpeedFan
2026-10-04 05:47 - 2021-03-23 17:24 - 000000000 __SHD C:\Users\PC\IntelGraphicsProfiles
2026-10-04 05:47 - 2020-09-27 09:51 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-10-04 05:47 - 2020-09-27 07:50 - 000008192 ___SH C:\DumpStack.log.tmp
2026-10-04 05:12 - 2025-04-19 11:31 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2026-10-04 05:12 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2026-10-04 05:11 - 2025-12-31 19:04 - 000000000 ____D C:\Users\PC\AppData\Roaming\vlc
2026-10-03 22:46 - 2024-01-17 16:30 - 000000000 ____D C:\Users\PC\AppData\Roaming\foobar2000-v2
2026-10-03 10:59 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2026-10-03 06:08 - 2021-03-23 16:55 - 000000000 ____D C:\Users\PC
2026-10-02 23:54 - 2021-03-24 12:12 - 000002364 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2026-09-30 02:32 - 2026-08-19 01:31 - 000001714 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-09-29 16:36 - 2021-03-24 09:54 - 000000000 ____D C:\ProgramData\Adobe
2026-09-29 10:20 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2026-09-25 19:03 - 2021-03-23 16:55 - 000000000 ____D C:\Users\PC\AppData\Local\Packages
2026-09-25 13:13 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\WindowsApps
2026-09-23 06:08 - 2022-02-20 14:30 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-09-19 17:07 - 2026-06-04 22:50 - 000002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-09-19 17:07 - 2025-08-02 09:07 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2026-09-18 16:25 - 2020-09-27 09:51 - 000000000 ____D C:\Windows\system32\Drivers\wd
2026-09-09 11:11 - 2021-03-24 12:34 - 000000000 ____D C:\Users\PC\AppData\Local\D3DSCache
2026-09-09 07:13 - 2021-03-24 09:31 - 000000000 ____D C:\Windows\system32\MRT
2026-09-09 07:10 - 2021-03-24 09:31 - 230964456 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-09-09 07:09 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp

==================== Files in the root of some directories ========

2021-03-24 09:36 - 2026-04-28 12:10 - 000000600 _____ () C:\Users\PC\AppData\Roaming\winscp.rnd
2021-03-25 17:30 - 2021-03-25 17:31 - 000007597 _____ () C:\Users\PC\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


addition ---
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-10-2026
Ran by PC (04-10-2026 12:27:42)
Running from C:\Users\PC\Desktop
Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) (2021-03-23 14:52:24)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-1091510603-4126540304-2273175986-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-1091510603-4126540304-2273175986-503 - Limited - Disabled)
Guest (S-1-5-21-1091510603-4126540304-2273175986-501 - Limited - Disabled)
PC (S-1-5-21-1091510603-4126540304-2273175986-1001 - Administrators - Enabled) => C:\Users\PC
WDAGUtilityAccount (S-1-5-21-1091510603-4126540304-2273175986-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 26.002.21931 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601180}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Aegisub 3.0.0 (HKLM-x32\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.0.0 - Aegisub Team)
Aegisub 3.4.2 (HKLM\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.4.2 - Aegisub Team)
Altap Salamander 4.0 (x86) (HKLM-x32\...\Altap Salamander 4.0 (x86)) (Version: 4.0 - ALTAP)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 24.9.1 - Advanced Micro Devices, Inc.)
ASUS Xonar Essence ST Audio (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F392008788}) (Version: - ASUSTeK Computer Inc.)
Bandicut (HKLM-x32\...\Bandicut) (Version: 4.2.4.2552 - Bandicam.com)
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 154.1.96.61 - Autoři prohlížeče Brave)
CCleaner (HKLM\...\CCleaner) (Version: 6.41 - Piriform)
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1990.6 - Piriform Software) Hidden
CDisplayEx 1.10.33 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.)
DualSenseX (HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\DualSenseX) (Version: 1.4.9 - Paliverse)
Easy Audio Extractor v. 1.0 (HKLM-x32\...\Easy Audio Extractor_is1) (Version: - Video-Easy.com)
ffdshow x64 v1.3.4531 [2014-06-28] (HKLM\...\ffdshow64_is1) (Version: 1.3.4531.0 - )
foobar2000 v2.1.1 (x64) (HKLM\...\foobar2000 (x64)) (Version: 2.1.1 - Peter Pawlowski)
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.3.112.5382 - GOM & Company)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.101.0 - Google LLC) Hidden
HOTAS WARTHOG drivers (HKLM-x32\...\{C33F3C7C-F964-4919-97D3-0C4F2A538D87}) (Version: 1.TMHW.2018 - Thrustmaster)
Intel(R) Chipset Device Software (HKLM\...\{B685D0AD-42A8-4A39-9BFE-8C063FA9AF29}) (Version: 10.1.1.8 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1156 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{5D1BFBB8-4923-4388-9559-C86F5D9E2740}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{B434599E-E35F-4612-9803-A2FB7A8E066B}) (Version: 11.0.0.1156 - Intel Corporation) Hidden
Intel(R) ME UninstallLegacy (HKLM\...\{ECA145AF-55D0-42BA-870F-4213F0198A46}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel(R) Smart Connect Technology (HKLM\...\{F46EF80D-07F0-4E56-B9B3-8EDB759B52D8}) (Version: 5.0.10.2850 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00001100-0230-1029-84C8-B8D95FA3C8C3}) (Version: 23.100.1.1 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{c6cff78a-cccb-49d5-be68-ae0ec5f0d48a}) (Version: 10.1.1.8 - Intel(R) Corporation) Hidden
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{7D84E343-A23D-451C-B123-0195B2D903A6}) (Version: 1.42.17.0 - Intel Corporation) Hidden
LibreOffice 26.2.0.3 (HKLM\...\{5B9B7FC3-E7A6-4B71-922B-BDAB5FD55147}) (Version: 26.2.0.3 - The Document Foundation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Malwarebytes version 5.5.2.242 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.5.2.242 - Malwarebytes)
Microsoft .NET Host - 6.0.11 (x64) (HKLM\...\{B92B890A-04F2-4880-BA20-20D4364FB263}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.11 (x64) (HKLM\...\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.11 (x64) (HKLM\...\{C3DD1448-513A-4DB8-978D-6991562EA63D}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.53 - Microsoft Corporation) Hidden
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{659502b7-dea8-4adc-99c4-64f141a83c2d}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 (HKLM-x32\...\{b49c10dd-4d54-45f8-ad13-fa25704456a4}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34438 (HKLM-x32\...\{ba10fda9-f731-441f-a999-000bbb7ceec2}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438 (HKLM\...\{E528AD94-12D7-42C4-91A3-908BE28E9BD2}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438 (HKLM\...\{2E15F519-4FDA-4834-B4EE-7EFCE7D8D4EE}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34438 (HKLM-x32\...\{A5592FEF-F948-4BA6-A066-8BBFC2DC7EE1}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34438 (HKLM-x32\...\{5D0C4511-3CA1-4FF8-A4BA-C0E1957ABEEA}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM\...\{A39D4115-3A27-4245-AE92-3214B8B21932}) (Version: 48.47.50419 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM-x32\...\{c4846f79-a633-4ae4-92a3-92fdbeb33da2}) (Version: 6.0.11.31823 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Mozilla Firefox 157.0 (x64 cs)) (Version: 157.0 - Mozilla)
Mozilla Firefox 87.0 (x64 cs) (HKLM\...\Mozilla Firefox 87.0 (x64 cs)) (Version: 87.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 87.0 - Mozilla)
MuralPix 1.07 (HKLM-x32\...\MuralPix) (Version: - )
ocenaudio (HKLM-x32\...\ocenaudio) (Version: 3.14.10 - Rui Seara Junior)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Panzer Corps 2 (HKLM-x32\...\1698452155_is1) (Version: 1.11.01 - GOG.com)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Thrustmaster TARGET (HKLM-x32\...\{8036A569-CA02-4D33-A7E9-E9BC8A482E91}) (Version: 3.0.24.618 - Thrustmaster)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 10.52 - Ghisler Software GmbH)
UninstallFujitsu Mouse LX960 (HKLM-x32\...\{FE95C175-92E0-45E7-B771-6C82CD64B2AE}}_is1) (Version: - Fujitsu Mouse LX960)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
USB Audio (HKLM\...\{B500C5BD-165A-4F93-ADAB-BA9E3C071B6C}) (Version: 2.0.1 - Marantz)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.22 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.92.0 - Winamp SA)
WinArchiver (HKLM\...\WinArchiver) (Version: 5.7 - Power Software Ltd)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
Wooky 3.0.2.2 (HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\Wooky) (Version: 3.0.2.2 - Mobilbonus, s.r.o.)
Yamaha Steinberg USB Driver (HKLM\...\{589D761D-6EBA-4BF4-90C7-0B2D7AEBAD8E}) (Version: 2.1.11 - Yamaha Corporation) Hidden
Yamaha Steinberg USB Driver (HKLM-x32\...\yUninstall_{2938B185-2D57-47B0-9FC8-C90A67BA9277}) (Version: 2.1.11 - Yamaha Corporation)
Youtube Downloader HD v. 5.9.9.10 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com)

Packages:
=========
7-Zip File Manager (Unofficial) -> C:\Program Files\WindowsApps\HaukeGtze.7-ZipFileManagerUnofficial_1.2201.1.0_x64__6bk20wvc8rfx2 [2025-04-19] (Hauke Hasselberg)
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2026-09-09] ()
RAR Opener -> C:\Program Files\WindowsApps\DeviceDoctor.RAROpener_1.3.48.0_x64__mkdtfchztkfbm [2026-07-27] (Tiny Opener)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{4F2B02E3-DC31-489F-9FC8-B87598E9BCFC}\InprocServer32 -> C:\Mozilla Firefox\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel(R) pGFX 2020 -> Intel Corporation)
CustomCLSID: HKU\S-1-5-21-1091510603-4126540304-2273175986-1001_Classes\CLSID\{C78B614F-F3EA-11D2-94A1-00E0292A01E3}\InprocServer32 -> C:\Program Files (x86)\Altap Salamander\utils\salextx64.dll (Fine spol. s r.o. -> ALTAP)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-06-08] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2021-07-16] (Notepad++ -> )
ContextMenuHandlers1: [WinArchiver] -> {A6630968-27DC-8DB8-9BCE-E12B3198A9B1} => C:\Program Files\WinArchiver\WASHELL.DLL [2024-04-14] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-03-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [WinArchiver] -> {A6630968-27DC-8DB8-9BCE-E12B3198A9B1} => C:\Program Files\WinArchiver\WASHELL.DLL [2024-04-14] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2020-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9d15b9aa9e1c885b\nvshext.dll [2025-03-15] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-03-27] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [WinArchiver] -> {A6630968-27DC-8DB8-9BCE-E12B3198A9B1} => C:\Program Files\WinArchiver\WASHELL.DLL [2024-04-14] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\system32\ff_vfw.dll [127488 2014-06-28] () [File not signed]
HKLM\...\Drivers32-x32: [VIDC.FFDS] => ff_vfw.dll
HKLM\...\Drivers32: [vidc.tscc] => C:\Program Files (x86)\MpcStar\Codecs\tscc\tsccvid.dll [102400 2008-07-08] (TechSmith Corporation) [File not signed]

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2026-09-14 01:16 - 2026-10-04 05:47 - 000192512 _____ () [File not signed] C:\Users\PC\AppData\Local\Temp\sfamcc00001.dll
2026-09-22 11:19 - 2026-10-04 05:47 - 000158720 _____ () [File not signed] C:\Users\PC\AppData\Local\Temp\sfareca00001.dll
2026-04-12 22:28 - 2026-04-12 22:28 - 000030720 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\cs_cz\Acrobat Elements\ContextMenuShim64.cze
2021-03-23 17:26 - 2021-03-23 17:26 - 000122880 ____N (C-Media Electronics Inc.) [File not signed] C:\Windows\System\HsSrv64.dll
2015-05-22 01:59 - 2015-05-22 01:59 - 001202688 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Intel\iCLS Client\LIBEAY32.dll
2015-05-22 01:59 - 2015-05-22 01:59 - 000306688 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Intel\iCLS Client\ssleay32.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2022-11-29 20:08 - 000000828 _____ C:\Windows\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.5.1 - 172.21.1.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Broadcom NetLink (TM) Gigabit Ethernet -> k57nd60a.sys

steamxboxndi: Steam Xbox Controller Enhanced Features Driver

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\dotnet\
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\Control Panel\Desktop\\Wallpaper -> c:\users\pc\appdata\roaming\mozilla\firefox\pozadí plochy.bmp
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "ISCT Tray"
HKLM\...\StartupApproved\Run: => "Cmaudio8788"
HKLM\...\StartupApproved\Run: => "Start WingMan Profiler"
HKLM\...\StartupApproved\Run32: => "Fujitsu Mouse LX960"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "ISCT Tray"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "DualSenseX"
HKU\S-1-5-21-1091510603-4126540304-2273175986-1001\...\StartupApproved\Run: => "Application Restart #0"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{1B38B56F-40FA-445E-A85F-A19EDC28BC0D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7EFDB021-F8CA-4192-BB38-BAD2560F818F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FAB62E66-85BA-48F1-B647-9DA88CEAA711}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{EA034265-458D-4C38-B6FB-DEA5FD5CDEE8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E6AA9AA5-9D34-4A16-BB9A-CD7BCF591160}] => (Allow) D:\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{86C8FDBC-3C48-4227-A827-A3E40126E6D8}] => (Allow) D:\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{9BED10CE-BC62-4E7A-BA7F-31B3C26574C2}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{286814D8-B567-46CB-979C-F75E7CF505E1}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{344689AA-FCEF-4FDE-B2ED-91FBBB141AD4}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent, Inc.)
FirewallRules: [{6122EF37-CDFD-460A-95C2-CCA56BE1007B}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent, Inc.)
FirewallRules: [{41BA48C4-2FD8-4098-9313-5C1E761D4810}] => (Allow) C:\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{D3709EB1-28E6-4601-BB3B-D726507856E4}] => (Allow) C:\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{40642B31-D916-4F00-8157-9965E5D35737}] => (Allow) D:\Steam\steamapps\common\Xenonauts\Xenonauts.exe () [File not signed]
FirewallRules: [{CDB3D726-A12A-46C2-8152-A7286E671071}] => (Allow) D:\Steam\steamapps\common\Xenonauts\Xenonauts.exe () [File not signed]
FirewallRules: [{E974110C-73CB-47F8-A2B8-61400BB352A1}] => (Allow) D:\Steam\steamapps\common\Project CARS 2\pCARS2.exe (Slightly Mad Studios Ltd) [File not signed]
FirewallRules: [{295B1D99-D292-417A-BA5B-FEC52C9E18BB}] => (Allow) D:\Steam\steamapps\common\Project CARS 2\pCARS2.exe (Slightly Mad Studios Ltd) [File not signed]
FirewallRules: [TCP Query User{866C3C38-49B6-4EB7-8D7F-1926F0E2C9C1}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{16B0A46E-1501-481F-A303-C986C7B678D5}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{CD0617C8-D2C0-4CAE-8E1A-E32503F0A076}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Cliffs of Dover Blitz\Launcher64.exe (Team Fusion Simulations Ltd. -> 1C:SoftClub)
FirewallRules: [{761D1E59-EB82-4EA6-89BF-E5FF661AC0A2}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Cliffs of Dover Blitz\Launcher64.exe (Team Fusion Simulations Ltd. -> 1C:SoftClub)
FirewallRules: [{314D97EE-35A3-49F5-B05D-5594478B02A0}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Battle of Stalingrad\bin\game\Il-2.exe (LLC 1c Game Studios -> FOR-GAMES CR LTD)
FirewallRules: [{EABE4FDE-C836-4A17-890C-562F6A60C4E2}] => (Allow) D:\Steam\steamapps\common\IL-2 Sturmovik Battle of Stalingrad\bin\game\Il-2.exe (LLC 1c Game Studios -> FOR-GAMES CR LTD)
FirewallRules: [{5304423E-EBD1-44C7-8C35-5C0C769A587B}] => (Allow) D:\Steam\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe (Larian Studios Games Ltd. -> LariLauncher)
FirewallRules: [{E20B44D5-D34B-4065-A77E-7026C3309554}] => (Allow) D:\Steam\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe (Larian Studios Games Ltd. -> LariLauncher)
FirewallRules: [{882B7A1F-ED70-40F1-B9E2-B6AF4FE7AD0E}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{CA9CD3CB-6215-47BC-8395-8C2B0CBB7248}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{DE145AB4-C63B-43C5-98E3-27A1325EC802}] => (Allow) D:\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F9ED3B27-21AC-4CA8-818C-C461F83D424A}] => (Allow) D:\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{9D9538FD-FE69-47CA-8828-4CA61C503497}] => (Allow) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)

==================== Restore Points =========================

17-09-2026 11:01:54 Naplánovaný kontrolní bod
26-09-2026 09:03:59 Installed Yamaha Steinberg USB Driver

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================

System errors:
=============
Error: (10/04/2026 05:52:16 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/04/2026 04:40:43 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/03/2026 06:46:14 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/02/2026 06:50:07 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/02/2026 06:45:06 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (18:41:21, ‎02.‎10.‎2026) bylo neočekávané.

Error: (10/01/2026 06:22:55 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (10/01/2026 12:00:00 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0

Error: (09/30/2026 04:42:49 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Secure Boot CA/keys need to be updated. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P2.80;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:Z77 Extreme6;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: 2c442d7376e014787b9eb219ec04dff97a9f938f24378a74f9c7035f252491d8
BucketConfidenceLevel:
UpdateType: 0
HResult: 0


Windows Defender:
================

TimeCreated : 29.09.2026 8:39:27
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
5E22D0EB-C689-40BF-B0CC-ED8990C40B7E}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 28.09.2026 8:42:36
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
C514D958-2B8E-4A04-8E43-119D390AD228}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 27.09.2026 10:09:25
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
9E93DA09-30AB-43F1-B469-ADBD1A298652}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 26.09.2026 11:29:53
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
C9E38731-A7BF-4197-9AFC-EA40EED93F27}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъҐРĈ ċōηʼnëстĭøи яúñðöŵй

TimeCreated : 21.09.2026 8:36:28
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
90B9B3F0-4660-4CAC-A862-AA4FF36C43E4}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 20.09.2026 8:43:56
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
CA459285-872E-49C1-8C6B-4E4CAE3FCE59}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅςнέďύłеđ śςåп ẃªѕ śķĩρрĕð ъ℮ςάųşє тħē ĺªš
ť šùčсéѕѕƒµĺ ŝĉäŋ ŵаѕ ŵīтћιή ţĥĕ łãşť 7 ðάýş

TimeCreated : 18.09.2026 9:12:36
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
9E65CC29-2DB6-409B-BFEA-1B1FD61E67B2}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅćђęđμĺēδ ѕčªη ωáŝ şĸΐррėď ьê¢āúşє ţнё ľãŝ
τ šūçсëśşƒüℓ şсāņ ωąş щĩţнïņ ŧђё ĺǻŝť 7 ðαỳş

TimeCreated : 17.09.2026 9:27:40
Message : Antivirová ochrana v programu Microsoft Defender ş¢αⁿ ĥąş вêėη śţóрφёđ ьέƒóяе ¢òmφŀéтīбñ.%η %τŜ¢аή ĬĐ:%ъ{
E6846E99-5376-42CD-8B25-C39FB06A06DA}%и %ťŚĉάñ Ťуρё:%ьAntimalwarový program%ñ %ŧЅçâл Ρãѓªмêţêѓŝ:%ъRychlé
prohledávání%ņ %тЏśèŗ:%ьNT AUTHORITY\SYSTEM%π %тŞŧôφ Ŗëąşòй:%ъЅćђęđμĺēδ ѕčªη ωáŝ şĸΐррėď ьê¢āúşє ţнё ľãŝ
τ šūçсëśşƒüℓ şсāņ ωąş щĩţнïņ ŧђё ĺǻŝť 7 ðαỳş


CodeIntegrity:
===============
Date: 2026-10-04 05:47:17
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

BIOS: American Megatrends Inc. P2.80 07/01/2013
Motherboard: ASRock Z77 Extreme6
Processor: Intel(R) Core(TM) i5-3450 CPU @ 3.10GHz
Percentage of memory in use: 28%
Total physical RAM: 16268.1 MB
Available physical RAM: 11665.15 MB
Total Virtual: 18700.1 MB
Available Virtual: 13024.37 MB

==================== Drives ================================

Disk 1 - Drive c: () (Fixed) (Total:232.28 GB) (Free:10.12 GB) (Model: WDC WD2500HHTZ-04N21V0) NTFS
Disk 0 - Drive d: (ROCOR GYM) (Fixed) (Total:931.5 GB) (Free:20.3 GB) (Model: WDC WD10EZEX-08WN4A0) NTFS
Disk 2 - Drive f: () (Removable) (Total:114.58 GB) (Free:2.14 GB) FAT32
Disk 3 - Drive h: () (Fixed) (Total:465.76 GB) (Free:4.76 GB) (Model: ST500LM0 12 HN-M500MB USB Device) NTFS

Disk 1 - \\?\Volume{de8f403c-78c6-4da3-98dd-7c65f59081c4}\ () (Fixed) (Total:498 MB) (Free:81.76 MB) NTFS
Disk 1 - \\?\Volume{f65d7f54-4dcf-4e60-95b6-df53b1a403eb}\ () (Fixed) (Total:96 MB) (Free:69 MB) FAT32

==================== MBR & Partition Table ====================

============================================================
Disk: 0 (Protective MBR) (Size: 931.51 GB)

Partitions:
===========
Partition Style : GPT
Partition Count : 2
Disk ID : {C76A7A3F-AFDD-463E-BB00-C678181B8D83}
Usable Offset : 0.02 MB
Usable Length : 931.51 GB
Max Partitions : 128

Partition 1
Type : Microsoft Reserved (MSR)
Size : 15.98 MB
Offset : 0.02 MB
Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
Partition GUID : {EEDF0ECA-5A80-4626-AA4A-35CB3E8CEC04}
GPT Name : Microsoft reserved partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 2
Type : Basic Data Partition
Size : 931.5 GB
Offset : 16 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {A1EFA991-AE62-4E96-81DC-A633628DE46F}
GPT Name : Basic data partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------


============================================================
Disk: 1 (Size: 232.89 GB) (Disk ID: 0BA592B7)

Partitions:
===========
Partition Style : GPT
Partition Count : 4
Disk ID : {AD3CA0E2-8C5D-43FA-A3E9-EDF9CF9A91D9}
Usable Offset : 0.02 MB
Usable Length : 232.89 GB
Max Partitions : 128

Partition 1
Type : EFI System Partition
Size : 100 MB
Offset : 1 MB
Type GUID : {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}
Partition GUID : {F65D7F54-4DCF-4E60-95B6-DF53B1A403EB}
GPT Name : EFI system partition
Attributes : 0x8000000000000000
Attribute Flags : No Default Drive Letter
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 2
Type : Microsoft Reserved (MSR)
Size : 16 MB
Offset : 101 MB
Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
Partition GUID : {F0C39394-B12D-490D-9EE9-3AEE25B12C2B}
GPT Name : Microsoft reserved partition
Attributes : 0x8000000000000000
Attribute Flags : No Default Drive Letter
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 3
Type : Basic Data Partition
Size : 232.28 GB
Offset : 117 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {FE5B68A7-CB6F-4673-800F-E01FAF2C4501}
GPT Name : Basic data partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------
Partition 4
Type : Windows Recovery
Size : 498 MB
Offset : 237976 MB
Type GUID : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}
Partition GUID : {DE8F403C-78C6-4DA3-98DD-7C65F59081C4}
Attributes : 0x8000000000000001
Attribute Flags : Platform Required, No Default Drive Letter
Hidden : Yes
Platform Required: Yes
------------------------------------------------------------


============================================================
Disk: 2 (Protective MBR) (Size: 114.61 GB)

Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0x00000000

Partition 1
Type : MBR 0x0C (FAT32 LBA)
Size : 114.61 GB
Offset : 0.02 MB
Partition GUID : {00000000-0000-0000-0040-000000000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 32
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 1


============================================================
Disk: 3 (Size: 465.76 GB) (Disk ID: A345F4C7)

Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0xA345F4C7

Partition 1
Type : MBR 0x07 (NTFS / exFAT / HPFS)
Size : 465.76 GB
Offset : 1 MB
Partition GUID : {A345F4C7-0000-0000-0000-100000000000}
Bootable : No
Recognized : Yes
Hidden Sectors : 2048
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 1

============================================================

==================== End of Addition.txt =======================

Re: napadení PC

Odeslal: 04 Říj 2026 13:23
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
S3 PrintNotify; C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll [3596288 2021-03-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
C:\DumpStack.log.tmp
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: napadení PC

Odeslal: 04 Říj 2026 14:43
od Hynek88
Fix result of Farbar Recovery Scan Tool (x64) Version: 01-10-2026
Ran by PC (04-10-2026 14:55:35) Run:8
Running from C:\Users\PC\Desktop
Loaded Profiles: PC
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
S3 PrintNotify; C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll [3596288 2021-03-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
C:\DumpStack.log.tmp
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\System\CurrentControlSet\Services\PrintNotify => removed successfully
PrintNotify => service removed successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.

HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5410572 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 412508853 B
Windows/system/drivers => 8848397 B
Edge => 147456 B
Brave => 157892799 B
Firefox => 116386020 B
Opera => 0 B

Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 5 B
ProgramData => 0 B
Public => 0 B
systemprofile => 501280 B
systemprofile32 => 159 B
LocalService => 5 B
NetworkService => 454949 B
PC => 17805543 B

RecycleBin => 0 B
EmptyTemp: => 687.85 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 04-10-2026 15:42:53)

C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 15:42:54 ====

Re: napadení PC

Odeslal: 04 Říj 2026 14:49
od Rudy
Vše bylo smazáno.

Re: napadení PC

Odeslal: 04 Říj 2026 15:12
od Hynek88
Díky!

no a vyplývá z toho něco?

Re: napadení PC

Odeslal: 04 Říj 2026 15:51
od Rudy
Pokud jste v systému něco měl, pak to bylo uloženo v dočasných souborech. Tam mi log ukáže pouze to, že byly smazány, bez konkrétního výčtu (nejsou pro systém důležité). Ty jmenovité jsou nějaký print manager, dočasný adresář a záznsm v registry která zbyl po smazaném souboru. Jinak OK.

Re: napadení PC

Odeslal: 04 Říj 2026 16:20
od Hynek88
ok,

tak zatím díky!

Re: napadení PC

Odeslal: 04 Říj 2026 17:45
od Rudy
Nemáte zač! :)