Prosim o kontrolu Dekuji

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43454
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: Prosim o kontrolu Dekuji

Příspěvek od jaro3 »

Máš přitom vypnutý antivir a firewall?
Když to nepůjde, tak napiš co problémy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
ladislavhu1993
nováček
Příspěvky: 46
Registrován: 18 lis 2023 19:00

Re: Prosim o kontrolu Dekuji

Příspěvek od ladislavhu1993 »

nejde to vubec i kdyz to vypnu
jinak se zda ze je to o neco lepsi
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43454
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: Prosim o kontrolu Dekuji

Příspěvek od jaro3 »

Vypni antivir i firewall.
Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
další odkaz:
http://www.bleepingcomputer.com/downloa ... scan-tool/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
ladislavhu1993
nováček
Příspěvky: 46
Registrován: 18 lis 2023 19:00

Re: Prosim o kontrolu Dekuji

Příspěvek od ladislavhu1993 »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-01-2026
Ran by Asus (25-01-2026 11:59:26)
Running from C:\Users\Asus\Desktop\hudba
Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) (2020-09-14 12:05:10)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-804831582-2933453136-550661674-500 - Administrator - Disabled)
Asus (S-1-5-21-804831582-2933453136-550661674-1001 - Administrator - Enabled) => C:\Users\Asus
DefaultAccount (S-1-5-21-804831582-2933453136-550661674-503 - Limited - Disabled)
Guest (S-1-5-21-804831582-2933453136-550661674-501 - Limited - Disabled)
Lada (S-1-5-21-804831582-2933453136-550661674-1005 - Administrator - Enabled) => C:\Users\Lada
Mamka (S-1-5-21-804831582-2933453136-550661674-1004 - Limited - Enabled) => C:\Users\Mamka
WDAGUtilityAccount (S-1-5-21-804831582-2933453136-550661674-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
FW: Avast Antivirus (Disabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3uTools (HKLM-x32\...\3uToolsV3_x64) (Version: 3.29.009 - Shenzhen Aidapu Network Technology Co.,Ltd.)
4MeKey 4.2.12.2 (HKLM-x32\...\{Tenorshare 4MeKey}_is1) (Version: 4.2.12.2 - Tenorshare, Inc.)
Adlice Protect version 16.5.4.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 16.5.4.0 - Adlice Software)
Adobe Reader X - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
Apple Mobile Device Support (HKLM\...\{B9292776-A87E-404C-8569-72CEC689F6C6}) (Version: 19.0.1.27 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{B292D163-23D2-4523-A699-1ABEC1875609}) (Version: 2.7.0.3 - Apple Inc.)
AudioHUBWwwAccessConnector 1.0.0.2290 (HKLM-x32\...\AudioHUBWwwAccessConnector) (Version: 1.0.0.2290 - MEDIAN s.r.o.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 25.12.10659.3321 - Gen Digital Inc.)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 143.0.33371.147 - Autoři prohlížeče Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1697.6 - AVAST Software) Hidden
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\BE156A27AFEAEA39D6A7C9D25CFA8DAFAF91756B) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\D43FD4059F47ACA9539247D6CF690AAEA503AF2D) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (dg_ssudbus) USB (12/02/2015 2.12.1.0) (HKLM\...\85A33267F12961AF9ED9AE799DEDA5E62BEA236F) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (ssudmdm) Modem (12/02/2015 2.12.1.0) (HKLM\...\88ED314360B98E6E82E7CC3201FAEB4A9FD291B4) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd. (WinUSB) AndroidUsbDeviceClass (12/02/2015 2.12.1.0) (HKLM\...\701281E8283E9E3681220099A9DA5013A5A437AF) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
BFT TOOL verze 1.7 (HKLM\...\{3F833D5B-8FAC-47FA-80DA-864D6A73BAB8}_is1) (Version: 1.7 - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Catalyst Control Center - Branding (HKLM-x32\...\{11087D24-567D-7D88-69C6-D7A08B5F4C47}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 6.39 - Piriform)
CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 143.0.33371.147 - Autoři prohlížeče CCleaner Browser)
CCleaner Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1067.0 - Piriform Software) Hidden
CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1636.4 - Piriform Software) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 12.3.0.2358 - Disc Soft Ltd)
DroidKit (HKLM-x32\...\DroidKit) (Version: 1.0.1.1 - iMobie Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 9.26 - NCH Software)
F3arRa1n Tool v7.1.4.0 (HKLM-x32\...\F3arRa1n) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 143.0.7499.194 - Google LLC)
Checkm8.info Software (HKLM-x32\...\{E1E86DDF-EF9B-4CF4-B2EC-53A5ECAC36C4}) (Version: 5.4.7 - Checkm8.info)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.5126 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000040-0220-1029-84C8-B8D95FA3C8C3}) (Version: 22.40.0.2 - Intel Corporation)
Java 8 Update 411 (64-bit) (HKLM\...\{77924AE4-039E-4CA4-87B4-2F64180411F0}) (Version: 8.0.4110.9 - Oracle Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{4F81B8ED-D6B5-497F-AAEC-9DECD42CB03D}) (Version: 3.9.2402.14001 - Microsoft Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{D1F15F7A-707A-42BD-BE6B-3380616F796D}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LG Mobile Drivers (HKLM-x32\...\{C3C008A7-D4A5-4E19-B0D6-72043D6EFE34}) (Version: 4.2.0 - LG Electronics)
LightPDF Editor (HKLM-x32\...\{161C8BF4-DB06-49A7-B6AC-7CAB7DAF136F}_is1) (Version: 2.14.13.4 - Wangxu Technology Co., Ltd.)
Lightshot-5.5.0.7 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.7 - Skillbrains)
MagFone iPhone Activation Unlocker 2.5.1.17 (HKLM-x32\...\MagFone iPhone Activation Unlocker_is1) (Version: - MagFone, Inc.)
Malwarebytes version 5.4.5.226 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.4.5.226 - Malwarebytes)
MediaTek SP Driver version 5.23.07.02 (HKLM\...\MediaTek SP Driver_is1) (Version: 5.23.07.02 - MediaTek.Inc.)
Microsoft .NET Core Host - 3.1.32 (x86) (HKLM-x32\...\{3C73457A-1A33-4DE0-B6C2-6FBA877E1FCF}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x86) (HKLM-x32\...\{CE1A992F-4571-423D-9CAE-1184E8F29471}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x86) (HKLM-x32\...\{841FE4B1-2C3F-4304-A686-6DF41B4CC1A1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Host - 6.0.10 (x64) (HKLM\...\{0222FFF1-57A3-48A6-9AD2-0D6B5D0172B3}) (Version: 48.43.48869 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.10 (x64) (HKLM\...\{A93C4E12-1BAB-4CFB-ADBC-9CE0B93176FF}) (Version: 48.43.48869 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.10 (x64) (HKLM\...\{A2A39CB9-677D-4299-8537-C00B99F3D4A4}) (Version: 48.43.48869 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 144.0.3719.82 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 144.0.3719.93 - Microsoft Corporation) Hidden
Microsoft GameInput (HKLM\...\{ECB4BDD1-984C-9F25-299C-A9EF75C14197}) (Version: 10.1.26100.6879 - Microsoft Corporation)
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\OneDriveSetup.exe) (Version: 25.238.1204.0001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-804831582-2933453136-550661674-1004\...\OneDriveSetup.exe) (Version: 20.169.0823.0008 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-804831582-2933453136-550661674-1005\...\OneDriveSetup.exe) (Version: 21.220.1024.0005 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 x64 ENU (HKLM\...\{8424B163-D1E0-48B7-88A2-C7A61767B3D7}) (Version: 4.0.8482.1 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (HKLM\...\{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (HKLM\...\{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (HKLM-x32\...\{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (HKLM-x32\...\{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}) (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29334 (HKLM-x32\...\{a9cfe9c7-e54f-46cd-9c5c-542ff8e3e8c4}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29334 (HKLM\...\{2E11EF4E-901F-4B2D-B68E-3DB2A566C857}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29334 (HKLM\...\{8A3F7D5B-422D-49D9-84F7-8DC1B7782967}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 3.1.32 (x86) (HKLM-x32\...\{25D5B94A-E3CD-44E8-9C3A-FE320B7B38FC}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 3.1.32 (x86) (HKLM-x32\...\{4f894285-fd43-43ac-8669-33e8b7c0a97d}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 6.0.10 (x64) (HKLM\...\{3EC7701F-54F2-491D-AFD1-0395F465BC5A}) (Version: 48.43.48870 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.10 (x64) (HKLM-x32\...\{ff748137-9c9a-4056-be0a-48c7e465453c}) (Version: 6.0.10.31726 - Microsoft Corporation)
Minimal ADB and Fastboot version 1.3 (HKLM-x32\...\{FB7E6E10-9DAA-476F-9876-078D40F6D233}_is1) (Version: 1.3 - Sam Rodberg)
NVIDIA Ovladače grafiky 432.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 432.00 - NVIDIA Corporation)
OMT TOOL 2.1 (HKLM-x32\...\OMT TOOL 2.1) (Version: 2.1 - Adyah Mobile Traning Center)
PassFab iPhone Unlock 3.9.2.1 (HKLM-x32\...\{PassFab iPhone Unlock}_is1) (Version: 3.9.2.1 - TENORSHARE(HONGKONG)LIMITED)
Plarium Play (HKLM-x32\...\{1b16bdf4-f85f-4248-ae9c-6105e7beca99}) (Version: 9.4.0 - Plarium)
PlariumPlay (HKLM-x32\...\{B8E0E173-DE7E-46CD-8AC2-73F746632F0B}) (Version: 9.4.0 - Plarium) Hidden
Pomocník s aktualizací Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22807 - Microsoft Corporation)
Prohlížeč Seznam.cz (HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\Seznam Browser) (Version: 6.20.2 - Seznam.cz a.s.)
Python Launcher (HKLM-x32\...\{3C4935A5-B72E-4DA4-809E-0287A0BC046F}) (Version: 3.12.4150.0 - Python Software Foundation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8328 - Realtek Semiconductor Corp.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.7.61.0 - Samsung Electronics Co., Ltd.)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.9.0 - Sophos Limited)
ST MTK Tool version V1.0 (HKLM-x32\...\{261E0AD4-1222-45F5-A07E-4C31842E1D78}_is1) (Version: V1.0 - Shin Thant)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Tenorshare ReiBoot 9.6.5.1 (HKLM-x32\...\{Tenorshare ReiBoot}_is1) (Version: 9.6.5.1 - Tenorshare)
Universal Adb Driver (HKLM-x32\...\{C0E08D8D-6076-4117-B644-2AF34F35B757}) (Version: 1.0.4 - ClockworkMod)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
UsbDk Runtime Libraries (HKLM\...\{6D4A6ED0-CF41-4615-A4B3-BDA018C3C1CD}) (Version: 1.0.22 - Red Hat, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.10 - VideoLAN)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
WinUSB Drivers x64 (HKLM\...\{370C1839-B7D8-425E-8D3F-C79638E7D09C}) (Version: 2011.44.1.182 - Nokia)
Zemana AntiMalware verze 3.2.28 (HKLM-x32\...\{4E1F3677-C72E-4F7D-B66E-85467B1A289E}_is1) (Version: 3.2.28 - Zemana)

Packages:
=========
123 Fotky -> C:\Program Files\WindowsApps\38623ExtremeSleeper.123ImageViewerHD_2025.12.14.0_x64__2gsdpn732f8ba [2025-12-16] (mjmengji.com)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.310.400.0_x64__kgqvnymyfvs32 [2026-01-21] (king.com)
Craft Pocket Edition! -> C:\Program Files\WindowsApps\45719HeroCraftPvPGames.CraftPocketEdition_10.1.1.0_x86__t2awzc9bhj6z2 [2024-05-13] (Hero Craft PvP Games) [MS Ad]
Disney Speedstorm -> C:\Program Files\WindowsApps\A278AB0D.DisneySpeedstorm_1.90.638.0_x64__h6adky7gbf63m [2024-10-10] (Gameloft SE)
Document Editor Pro For Windows -> C:\Program Files\WindowsApps\38526MediaLife.WordEditorForWindows10_1.1.15.0_x64__1crh1k73ty8mg [2022-11-15] (Media Life)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-05-01] (Microsoft Corporation)
Extreme Off-road 4x4 Driving -> C:\Program Files\WindowsApps\12705GameStone.ExtremeOff-road4x4Driving_1.1.8.0_x86__xx7a0xg4kw6vg [2022-04-03] (Game Stone) [MS Ad]
Future Tanks: Armored War Machines Free Online Game -> C:\Program Files\WindowsApps\23866EXTREMEDEVELOPERS.FUTURETANKS3DONLINEBATTLE_3.60.7.0_x64__zxxvj7ezs5pcc [2025-08-24] (Extreme Developers)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-04-27] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-04-27] (Microsoft Corporation) [MS Ad]
Minecraft Launcher -> C:\Program Files\WindowsApps\Microsoft.4297127D64EC6_2.5.2.0_x64__8wekyb3d8bbwe [2025-12-10] (Microsoft Studios)
Modern Assault Tanks: War Tank Games -> C:\Program Files\WindowsApps\XDEVS.ModernAssaultTanksWarTankGames_3.74.4.0_x64__7yw2516a0mwqy [2025-08-22] (XDEVS LIMITED)
Nitro Nation -> C:\Program Files\WindowsApps\CreativeMobile.NitroNationbeta_7.9.4.0_x64__ewn699wwxwmvy [2024-07-02] (CM Games OÜ)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-11-06] (NVIDIA Corp.)
Roblox -> C:\Program Files\WindowsApps\ROBLOXCORPORATION.ROBLOX_2.699.877.0_x64__55nm5eh3cm0pr [2025-11-29] (Roblox Corporation)
Super Cario World - Jungle Runner -> C:\Program Files\WindowsApps\45188ClassicalFreeGames.SuperCarioWorld-JungleRunn_1.0.23.0_x64__ncpcy17kdq9fg [2022-04-03] (Classical Free Games)
Super Gary marlo adventure -> C:\Program Files\WindowsApps\34966AmgDevStudio.SuperGarymarloadventure_1.0.2.0_x86__q63fr4yfmg7x8 [2025-08-22] (AmgDev Studio)
World of Tanks Blitz -> C:\Program Files\WindowsApps\7458BE2C.WorldofTanksBlitz_11.15.155.0_x64__x4tje2y229k00 [2025-12-05] (Wargaming Group Limited)
World of Tanks Blitz Assistant -> C:\Program Files\WindowsApps\7458BE2C.WorldofTanksBlitzAssistant_1.9.0.0_x64__x4tje2y229k00 [2025-08-24] (Wargaming Group Limited)
Worldcraft -> C:\Program Files\WindowsApps\PlaylabsLLC.Worldcraft_3.8.26.0_x64__2919ryhc0tmbe [2025-10-17] (Playlabs)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-804831582-2933453136-550661674-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\Asus\AppData\Local\Microsoft\OneDrive\25.238.1204.0001\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-804831582-2933453136-550661674-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\Asus\AppData\Local\Microsoft\OneDrive\25.238.1204.0001\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-804831582-2933453136-550661674-1001_Classes\CLSID\{BEA218D2-6950-497B-9434-61683EC065FE}\InprocServer32 -> C:\Users\Asus\AppData\Local\Programs\Python\Launcher\pyshellext.amd64.dll (Python Software Foundation -> Python Software Foundation)
CustomCLSID: HKU\S-1-5-21-804831582-2933453136-550661674-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2210608 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2021-03-30] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-28] () [File not signed]
ContextMenuHandlers1: [Long-Term Docs Signer] -> {8B7B7594-9951-4D5A-BBCC-EB9AEE81CB12} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2025-09-17] (AVB Disc Soft, SIA -> Disc Soft Limited)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2025-09-17] (AVB Disc Soft, SIA -> Disc Soft Limited)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-01-07] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2020-06-01] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2021-03-30] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2022-06-28] () [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-01-07] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6_S-1-5-21-804831582-2933453136-550661674-1001: [UltraEdit] -> {b5eedee0-c06e-11cf-8c56-444553540000} => -> No File

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Asus\Desktop\Osoba 1 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Dokishop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=nncommfheogfbhilcclhhappdhglbhhg

==================== Loaded Modules (Whitelisted) =============

2026-01-07 15:41 - 2026-01-25 09:44 - 000104448 _____ () [File not signed] C:\Program Files (x86)\Median\WwwAccessConnector\AudioMarkerWin.dll
2026-01-07 15:41 - 2026-01-25 09:44 - 002391615 _____ () [File not signed] C:\Program Files (x86)\Median\WwwAccessConnector\libfftw3f-3.dll
2020-09-21 09:39 - 2020-09-07 07:55 - 001035264 _____ (Robert Simpson, et al.) [File not signed] [File is in use] C:\Program Files (x86)\Median\WwwAccessConnector\System.Data.SQLite.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Asus\Desktop\JRT.exe:MBAM.Zone.Identifier [186]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre-1.8\bin\ssv.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre-1.8\bin\jp2ssv.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\localhost -> localhost

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-30 08:24 - 2026-01-15 14:47 - 000000841 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.10.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet 2: Intel(R) Ethernet Connection I217-LM -> e1d65x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\java8path;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\dotnet\
HKU\S-1-5-21-804831582-2933453136-550661674-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Asus\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\14626697083204159005\134137382134291802.jpg
HKU\S-1-5-21-804831582-2933453136-550661674-1004\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-804831582-2933453136-550661674-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Lada\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\1685642650001532420\134029528366067651.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "Adobe Reader Speed Launcher"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\StartupApproved\Run: => "PlariumPlay"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\StartupApproved\Run: => "Bright VPN"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{9F3CCBB4-DDDA-4FD3-8815-3F772E9A2B24}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe => No File
FirewallRules: [{91A35D2F-F01F-4DE8-B055-B53BC32342A6}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe => No File
FirewallRules: [{8D5EB34E-607D-44C9-9040-2A8C7E0BCB62}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{2E2B7E30-5ED1-4E42-A2B3-13CC849A3F64}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{4F2C5D40-3E9A-4FD3-9D98-8E103109C66C}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{9E396163-58D1-45A1-A988-FA16FCD03AD1}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{7916077C-0E52-4EA9-8D17-115FB78EA1DB}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{9F99CB82-E2A8-4203-97B5-B11B6DE0710D}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{B44BBF30-E9FA-4EC5-B679-8E87DD26CEF1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{25E2E8BC-6B2C-4197-B928-AAEF64C6B6B4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{5D11745E-B886-42A2-8DBC-042EAD946F80}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{681E83B1-7220-4F9A-8B89-5B9F53288DB8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{3C9C54E3-A3EF-4330-83CB-7904FD92BB3E}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{7034B917-E098-4966-949F-7E1791855853}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{D4C30DB8-51B1-4C0F-A864-903EE0055F09}] => (Allow) D:\wondershare\drfone\drfonetoolkit.exe (Wondershare Technology Group Co.,Ltd -> Wondershare) [File not signed]
FirewallRules: [{676147CC-3421-4D4C-B74F-0BA4C7ED241C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{4E66189E-4734-48AB-8F77-CB04225E3A3F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9DE90DD7-70D9-41AB-84FC-1E27922D2129}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{057DE74A-3AD6-4833-ACCB-9F4D712B094F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D914AC95-9AFC-4CA3-A99B-E9F37BA3602F}] => (Allow) C:\program files (x86)\wondershare\dr.fone - data eraser (ios)\drfonetoolkit.exe => No File
FirewallRules: [{DD1C6705-652D-4805-9BBD-CEB4B5B32210}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc.)
FirewallRules: [{CDA0D51B-DBAB-4011-BFDC-496F2F1B9473}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Limited)
FirewallRules: [{9F8E9C9A-EF2C-4E8F-A2F3-9D61F2605BEB}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Limited)
FirewallRules: [{1A3FBE61-6095-4069-BFD1-33EDED427824}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B711E045-8B7F-4C40-B254-CA4807275EA3}] => (Allow) C:\Program Files\3uToolsV3\3uTools.exe (Shenzhen Aidapu Network Technology Co.,Ltd. -> Shenzhen Aidapu Network Technology Co.,Ltd.)
FirewallRules: [{BBA526E9-9EC0-4F41-86B7-66AC5EFC750B}] => (Allow) C:\Program Files\3uToolsV3\3uTools.exe (Shenzhen Aidapu Network Technology Co.,Ltd. -> Shenzhen Aidapu Network Technology Co.,Ltd.)
FirewallRules: [{FDD627EB-269D-4BE5-B63E-28823F2F0465}] => (Allow) LPort=80
FirewallRules: [{3C1C02E3-0E07-4E3A-A6F1-FACAC23BEBE8}] => (Allow) D:\Program Files (x86)\Tenorshare ReiBoot\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{11C4810A-03D6-4D65-AECD-C895243A11C7}] => (Allow) D:\Program Files (x86)\Tenorshare ReiBoot\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3A4D4A76-DF3A-4681-9006-D4C3F940EFCB}] => (Allow) D:\Program Files (x86)\Tenorshare ReiBoot\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{4C72058B-AC4A-494F-B9BF-861934AA70CA}] => (Allow) D:\Program Files (x86)\Tenorshare ReiBoot\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{AF2E092B-9625-4611-A20C-3E9BE2B782DF}] => (Allow) C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{4423DDE6-B98E-4A34-9C51-D9051FBA7C5C}] => (Allow) C:\Program Files\CCleaner Browser\Application\CCleanerBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [{3AED0163-B8FB-42B1-8146-D3B952A6A787}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

18-01-2026 14:47:32 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices ============
Name: Myš Microsoft PS/2
Description: Myš Microsoft PS/2
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Standardní klávesnice PS/2
Description: Standardní klávesnice PS/2
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardní klávesnice)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: ========================

Application errors:
==================
Error: (01/22/2026 08:38:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe, verze: 1.0.0.2310, časové razítko: 0x64198cc9
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.19041.6456, časové razítko: 0xbf208242
Kód výjimky: 0xe0434352
Posun chyby: 0x0013b702
ID chybujícího procesu: 0x6924
Čas spuštění chybující aplikace: 0x01dc8b75ac80cb5f
Cesta k chybující aplikaci: C:\Program Files (x86)\Median\WwwAccessConnector\AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: ca469315-5b34-4a97-ac2b-60510f519dea
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (01/22/2026 08:38:14 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.InvalidOperationException
na System.Diagnostics.Process.EnsureState(State)
na System.Diagnostics.Process.get_ProcessName()
na AudioHUB.Processing.WwwAccessConnector.ProcessSniffer.SelectedProcessWatcher.CheckNew(System.Diagnostics.Process)
na AudioHUB.Processing.WwwAccessConnector.ProcessSniffer.SelectedProcessWatcher.Check(AudioHUB.Processing.WwwAccessConnector.ProcessSniffer.ProcessEvent, System.Diagnostics.Process)
na AudioHUB.Processing.WwwAccessConnector.ProcessSniffer.SniffeSelectedProcess.OnTimer(System.Object)
na System.Threading.TimerQueueTimer.CallCallbackInContext(System.Object)
na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.TimerQueueTimer.CallCallback()
na System.Threading.TimerQueueTimer.Fire()
na System.Threading.TimerQueue.FireQueuedTimerCompletion(System.Object)
na System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
na System.Threading.ThreadPoolWorkQueue.Dispatch()
na System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (01/21/2026 11:17:33 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na Nový svazek (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (01/18/2026 02:47:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddWin32ServiceFiles: Unable to back up image of service Avast SecureLine VPN since QueryServiceConfig API failed

System Error:
Systém nemůže nalézt uvedený soubor..

Error: (01/18/2026 02:47:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddWin32ServiceFiles: Unable to back up image of service Brightdata Service (win_brightvpn.com) since QueryServiceConfig API failed

System Error:
Systém nemůže nalézt uvedený soubor..

Error: (01/18/2026 02:47:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddWin32ServiceFiles: Unable to back up image of service Kamo Service since QueryServiceConfig API failed

System Error:
Systém nemůže nalézt uvedený soubor..

Error: (01/17/2026 06:46:42 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program wotblitz.exe verze 0.0.0.0 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 28cc

Čas spuštění: 01dc87d8efd11b0e

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\7458BE2C.WorldofTanksBlitz_11.15.155.0_x64__x4tje2y229k00\wotblitz.exe

ID hlášení: cde698a9-55da-48c8-88c0-95f304c7f401

Úplný název balíčku s chybou: 7458BE2C.WorldofTanksBlitz_11.15.155.0_x64__x4tje2y229k00

ID aplikace relativní podle balíčku s chybou: App

Typ zablokování: Quiesce

Error: (01/15/2026 02:46:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: DaS_21.exe, verze: 2.1.0.4, časové razítko: 0x540c90b2
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.19041.6280, časové razítko: 0x56511854
Kód výjimky: 0xe0434352
Posun chyby: 0x0000000000025369
ID chybujícího procesu: 0x585c
Čas spuštění chybující aplikace: 0x01dc862551da5d9b
Cesta k chybující aplikaci: C:\Users\Asus\AppData\Local\Temp\DaS_21.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: b34eab50-accd-4804-ae28-70acfd573f85
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (01/25/2026 12:02:55 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GBIP3G3)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/19/2026 03:59:05 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby FDResPub bylo dosaženo časového limitu (30000 ms).

Error: (01/17/2026 10:10:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GBIP3G3)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/17/2026 10:10:58 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GBIP3G3)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/17/2026 06:47:01 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GBIP3G3)
Description: Server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/17/2026 06:44:32 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GBIP3G3)
Description: Server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/17/2026 06:43:18 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GBIP3G3)
Description: Server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/17/2026 10:28:07 AM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.


CodeIntegrity:
===============
Date: 2026-01-25 11:50:28
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements.

Date: 2026-01-25 11:34:57
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: Hewlett-Packard L01 v02.70 10/04/2016
Motherboard: Hewlett-Packard 18E7
Processor: Intel(R) Pentium(R) CPU G3220 @ 3.00GHz
Percentage of memory in use: 87%
Total physical RAM: 3986.31 MB
Available physical RAM: 513.85 MB
Total Virtual: 13250.53 MB
Available Virtual: 6121.75 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:446.15 GB) (Free:26.72 GB) (Model: Patriot Burst) NTFS
Drive d: (Nový svazek) (Fixed) (Total:465.76 GB) (Free:435.88 GB) (Model: WDC WD5000AAKX-60U6AA0) NTFS

\\?\Volume{bbf438af-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.49 GB) (Free:0.45 GB) NTFS
\\?\Volume{bbf438af-0000-0000-0000-10a96f000000}\ () (Fixed) (Total:0.49 GB) (Free:0.06 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 447.1 GB) (Disk ID: BBF438AF)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=446.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=499 MB) - (Type=27)

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 00BEAFF3)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================
ladislavhu1993
nováček
Příspěvky: 46
Registrován: 18 lis 2023 19:00

Re: Prosim o kontrolu Dekuji

Příspěvek od ladislavhu1993 »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2026
Ran by Asus (administrator) on DESKTOP-GBIP3G3 (Hewlett-Packard HP ProDesk 600 G1 TWR) (25-01-2026 11:57:34)
Running from C:\Users\Asus\Desktop\hudba\FRST64.exe
Loaded Profiles: Asus
Platform: Microsoft Windows 10 Home Version 22H2 19045.6466 (X64) Language: Čeština (Česko)
Default browser: "C:\Program Files\CCleaner Browser\Application\CCleanerBrowser.exe" --single-argument %1
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <18>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <14>
(explorer.exe ->) (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc.) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe <13>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <5>
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\CCleaner\CCleaner64.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Common Files\Avast Software\Icarus\avast-av-vps\icarus.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Limited) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(svchost.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
(svchost.exe ->) (MEDIAN s.r.o.) [File not signed] C:\Program Files (x86)\Median\WwwAccessConnector\AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
Failed to access process -> CCleanerBrowserProtect.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [869032 2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9240512 2017-12-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1492928 2017-12-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [369104 2025-10-04] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe (No File)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [750680 2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45988576 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\Run: [MicrosoftEdgeAutoLaunch_E27E50BD5633453D54C19716A813DFE6] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4314192 2026-01-16] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\Run: [PlariumPlay] => C:\Users\Asus\AppData\Local\PlariumPlay\PlariumPlay.exe [295240 2024-07-02] (Plarium Global LTD -> PlariumPlay)
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [486512 2025-09-17] (AVB Disc Soft, SIA -> Disc Soft Limited)
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {289a066e-6ca7-11f0-a650-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {391ba123-f766-11eb-a5a8-ecb1d73deff7} - "E:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {7e166aa0-49b0-11eb-a595-ecb1d73deff7} - "E:\AutoRun.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {ae6c0047-2bd2-11eb-a593-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {c74added-7617-11f0-a651-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {ca78114a-6c92-11f0-a64f-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {d12555bc-6217-11f0-a64c-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1004\...\Run: [CCleanerBrowserAutoLaunch_2FC9E7AA8C05809553C094036F5C4818] => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [3188472 2024-11-06] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc.)
HKU\S-1-5-21-804831582-2933453136-550661674-1005\...\Run: [MicrosoftEdgeAutoLaunch_1C971306302C20228138B8867279E9E1] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4314192 2026-01-16] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-804831582-2933453136-550661674-1005\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Lada\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [42164600 2025-09-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-804831582-2933453136-550661674-1005\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Lada\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\...\Print\Monitors\Software602 XPS port monitor: C:\WINDOWS\system32\602localmon.dll [47896 2021-09-23] (Software602 a.s. -> Windows (R) Win 7 DDK provider)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files\CCleaner Browser\Application\143.0.33371.147\Installer\chrmstp.exe [2025-12-22] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [2025-11-06] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\143.0.7499.194\Installer\chrmstp.exe [2026-01-20] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files\AVAST Software\Browser\Application\143.0.33371.147\Installer\chrmstp.exe [2025-12-19] (Gen Digital Inc. -> Gen Digital Inc.)
Startup: C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Url Monitor.lnk [2021-11-23]
ShortcutTarget: Url Monitor.lnk -> C:\Program Files (x86)\Median\WwwAccessConnector\AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe (MEDIAN s.r.o.) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SPDriverInstall.lnk [2025-07-18] <==== ATTENTION
ShortcutTarget: SPDriverInstall.lnk -> C:\Program Files\MediaTek\SP Driver\SPDriverInstall (No File) <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAndroidAppHelper.lnk [2020-08-15]
ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAndroidAppHelper.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAppHelper.lnk [2020-08-15]
ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAppHelper.exe (No File)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {BAEBC3E3-CB88-4253-BA50-0BBA6B3165E2} - System32\Tasks\AMHelper => C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe [682008 2021-03-30] (Zemana D.O.O. Sarajevo -> Zemana Ltd.)
Task: {74CA6534-6B48-40FD-9707-0E4684D4FD81} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [617096 2022-02-25] (Apple Inc. -> Apple Inc.)
Task: {2F207F4E-6866-40D6-A24D-B0E1B58B8921} - System32\Tasks\AudioHUB => C:\Program Files (x86)\Median\WwwAccessConnector\AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe [275968 2023-03-21] (MEDIAN s.r.o.) [File not signed]
Task: {4D18069D-3B88-44D4-BB3F-05880AEC5C3C} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [9212640 2025-12-03] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B5DE4824-2A7A-4EFC-A7A4-35C491D1D0A1} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5601960 2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {371CE74D-91E5-4838-83EB-F70D35370113} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2977504 2025-10-14] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {45A27334-F1BB-4727-A5CD-4AF6E5C5FB23} - System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) => C:\Program Files\CCleaner Browser\Application\CCleanerBrowser.exe [3749768 2025-12-17] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {BC2B36B3-38B9-49C9-A15C-42262B341A64} - System32\Tasks\CCleaner Browser Heartbeat Task (Logon) => C:\Program Files\CCleaner Browser\Application\CCleanerBrowser.exe [3749768 2025-12-17] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {E9F75206-F8B9-4F5E-A417-7493072D2767} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9B1DC81C-F337-4242-83D7-8307D59F2556} - System32\Tasks\CCleanerBrowserProtectS-1-5-21-804831582-2933453136-550661674-1001 => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowserProtect.exe [1717416 2024-04-23] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc.)
Task: {5C06A93B-ED51-4305-A0D1-B5A6E6D5C445} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6140640 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "2ec9177d-ea16-4a42-a3ad-1f903b6f8f8a" --version "6.39.0.11548" --silent
Task: {7CA8EE72-BA53-4F2B-8EAB-4937AB2CC11D} - System32\Tasks\CCleanerSkipUAC - Asus => C:\Program Files\CCleaner\CCleaner.exe [39822560 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {2149A7E2-526C-4341-9480-A8320F74FF08} - System32\Tasks\CCleanerUpdateTaskMachineCore => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208168 2024-12-30] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
Task: {A15C14B6-D416-4B3B-86AB-2387BB0B86F0} - System32\Tasks\CCleanerUpdateTaskMachineUA => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208168 2024-12-30] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
Task: {C949BAD0-83E2-414F-A534-BA5582B2BA93} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{9FE296AD-B050-47F2-BADE-CA165801DAC7} => C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe [7056536 2025-11-26] (Google LLC -> Google LLC)
Task: {9B28029C-B43C-4A15-8A99-9D583417AFF8} - System32\Tasks\NCH Software\ExpressZipDowngrade => C:\Program Files (x86)\NCH Software\ExpressZip\expresszip.exe [1847024 2022-06-17] (NCH Software, Inc. -> NCH Software)
Task: {3780096D-F749-475D-BF84-664864FBA9A0} - System32\Tasks\OneDrive Startup Task-S-1-5-21-804831582-2933453136-550661674-1001 => C:\Users\Asus\AppData\Local\Microsoft\OneDrive\25.238.1204.0001\OneDriveLauncher.exe [746856 2026-01-19] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{6af0e780-1171-4ca0-8990-daabf43f3253}: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{6af0e780-1171-4ca0-8990-daabf43f3253}: [DhcpDomain] lan
Tcpip\..\Interfaces\{d0b016a5-1620-48ea-9bc5-4ee63f672201}: [DhcpNameServer] 192.168.1.254 81.161.66.130 81.161.66.2 8.8.8.8

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.411.2 -> C:\Program Files\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.411.2 -> C:\Program Files\Java\jre-1.8\bin\plugin2\npjp2.dll [2024-03-13] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1697.6\npAvastBrowserUpdate3.dll [2024-07-05] (Avast Software s.r.o. -> Gen Digital Inc.)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1697.6\npAvastBrowserUpdate3.dll [2024-07-05] (Avast Software s.r.o. -> Gen Digital Inc.)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1636.4\npCCleanerBrowserUpdate3.dll [2024-12-30] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1636.4\npCCleanerBrowserUpdate3.dll [2024-12-30] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-04-23] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-04-23] (VideoLAN -> VideoLAN)

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Asus\AppData\Local\Microsoft\Edge\User Data\Default [2026-01-25]
Edge Notifications: Default -> hxxps://automix.denik.cz; hxxps://cs.top-home-tips.com; hxxps://fzone.cz; hxxps://slovacky.denik.cz; hxxps://tennis-infinity.com; hxxps://www.bejvavalo.cz; hxxps://www.ceskestavby.cz; hxxps://www.drevostavitel.cz; hxxps://www.idnes.cz; hxxps://www.kurzy.cz; hxxps://www.lidl.cz; hxxps://www.nespechej.cz; hxxps://www.techzpravy.cz; hxxps://www.veleton.cz
Edge Extension: (Dokumenty Google offline) - C:\Users\Asus\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-01-15]
Edge Extension: (Edge relevant text changes) - C:\Users\Asus\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-01-15]

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default [2026-01-25]
CHR Notifications: Default -> hxxps://cooky.cz; hxxps://cz.pinterest.com; hxxps://eshop.tescoma.cz; hxxps://inspirace.pepco.cz; hxxps://jimezdrave.cz; hxxps://ksporting.cz; hxxps://mail.google.com; hxxps://nabidkydnes.cz; hxxps://objevim.cz; hxxps://postovnezdarma.cz; hxxps://preppykitchen.com; hxxps://primainspirace.cz; hxxps://skrz.cz; hxxps://slovacky.denik.cz; hxxps://svetkreativity.cz; hxxps://www.apetitonline.cz; hxxps://www.badatel.net; hxxps://www.bonami.cz; hxxps://www.bratislavskenoviny.sk; hxxps://www.ceskapoliklinika.cz; hxxps://www.delimano.cz; hxxps://www.energiezivota.com; hxxps://www.facebook.com; hxxps://www.fitness4u.cz; hxxps://www.ireceptar.cz; hxxps://www.jenzeny.cz; hxxps://www.knizniklub.cz; hxxps://www.kupi.cz; hxxps://www.lightinthebox.com; hxxps://www.lyke.cz; hxxps://www.megaknihy.cz; hxxps://www.mesec.cz; hxxps://www.messenger.com; hxxps://www.naturesfinest.cz; hxxps://www.ozp.cz; hxxps://www.peta.org; hxxps://www.postazdarma.cz; hxxps://www.sousviderecepty.cz; hxxps://www.tescoma.cz; hxxps://www.tetadrogerie.cz; hxxps://www.tui.cz; hxxps://www.vivantis.cz; hxxps://www.youtube.com; hxxps://zkustosam.cz
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2026-01-16]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [117168 2015-08-07] (Andrea Electronics -> Andrea Electronics Corporation)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [103888 2025-10-07] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7830184 2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2024-07-05] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [1036968 2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2608296 2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1090216 2025-12-20] (Gen Digital Inc. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [192664 2024-07-05] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 AvastSecureBrowserElevationService; C:\Program Files\AVAST Software\Browser\Application\143.0.33371.147\elevation_service.exe [2656832 2025-12-17] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2021-06-01] (Avast Software s.r.o. -> AVAST Software)
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208168 2024-12-30] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
S3 CCleanerBrowserElevationService; C:\Program Files\CCleaner Browser\Application\143.0.33371.147\elevation_service.exe [2631528 2025-12-17] (Gen Digital Inc. -> Gen Digital Inc.)
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208168 2024-12-30] (PIRIFORM SOFTWARE LIMITED -> Piriform Software)
R3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1080544 2025-08-14] (Gen Digital Inc. -> Gen Digital Inc.)
S2 DFWSIDService; C:\ProgramData\Wondershare\wsServices\WsidService.exe [3963120 2024-07-03] (Wondershare Technology Group Co.,Ltd -> wondershare)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4954224 2025-09-17] (AVB Disc Soft, SIA -> Disc Soft Limited)
S3 GameInputRedistService; C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe [141680 2025-10-20] (Microsoft Corporation -> Microsoft Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11207664 2026-01-07] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-01-07] (Malwarebytes Inc. -> Malwarebytes)
S2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [16175680 2025-12-11] (ADLICE -> )
S2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2023-12-21] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [933432 2023-12-21] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-04-24] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-04-24] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 WirelessBackupService; C:\Program Files (x86)\Wondershare\Dr.Fone - Data Eraser (iOS)\Addins\Recovery\WirelessBackupService.exe [X]
S2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [X]
S2 WsDrvInst; C:\Program Files (x86)\Wondershare\drfone\Addins\Unlock\DriverInstall.exe [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 amsdk; C:\WINDOWS\system32\drivers\amsdk.sys [232792 2026-01-19] (Zemana D.O.O. Sarajevo -> Copyright 2018.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [21088 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [286816 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [435296 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [304736 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [88160 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [29144 2025-07-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [32856 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [289376 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [584800 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [97376 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [73312 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [898144 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1314912 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [219744 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [403552 2025-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2025-09-22] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [63696 2025-09-22] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [19200 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hn_usbdev; C:\Windows\System32\Drivers\hn_usbdev.sys [116864 2022-04-24] (Microsoft Windows Hardware Compatibility Publisher -> Honor Technologies Co., Ltd.)
S3 HWHandSetProLine; C:\WINDOWS\system32\DRIVERS\hw_quusbmdm.sys [226560 2016-04-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hw_ctrlfakedev; C:\WINDOWS\system32\DRIVERS\hw_ctrlfakedev.sys [115712 2015-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-23] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 libusbK; C:\WINDOWS\System32\drivers\libusbK.sys [47928 2022-04-19] (Travis Lee Robinson -> hxxp://libusb-win32.sourceforge.net)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-01-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [245336 2026-01-07] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50896 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2018-05-04] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
R3 UsbDk; C:\WINDOWS\System32\Drivers\UsbDk.sys [103128 2020-03-13] (Red Hat, Inc. -> Red Hat Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-04-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [391392 2020-04-24] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2016-08-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-04-24] (Microsoft Windows -> Microsoft Corporation)
S3 hwusb_cdcacm; \SystemRoot\system32\DRIVERS\hw_cdcacm.sys [X]
S1 netfilter2; system32\drivers\netfilter2.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-01-25 11:57 - 2026-01-25 11:58 - 000000000 ____D C:\FRST
2026-01-19 16:56 - 2026-01-25 11:58 - 002369823 _____ C:\WINDOWS\ZAM.krnl.trace
2026-01-19 16:56 - 2026-01-25 10:22 - 000002520 _____ C:\WINDOWS\system32\Tasks\AMHelper
2026-01-19 16:56 - 2026-01-22 17:41 - 000001329 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2026-01-19 16:56 - 2026-01-22 17:41 - 000000000 ____D C:\Users\Asus\AppData\Local\AMSDK
2026-01-19 16:56 - 2026-01-22 17:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2026-01-19 16:56 - 2026-01-19 16:56 - 000232792 _____ (Copyright 2018.) C:\WINDOWS\system32\Drivers\amsdk.sys
2026-01-19 16:56 - 2026-01-19 16:56 - 000000000 ____D C:\Users\Asus\AppData\Local\Zemana
2026-01-19 16:56 - 2026-01-19 16:56 - 000000000 ____D C:\Program Files (x86)\Zemana
2026-01-15 16:42 - 2014-02-13 23:59 - 000024064 _____ C:\WINDOWS\zoek-delete.exe
2026-01-15 16:09 - 2026-01-15 16:09 - 000003269 _____ C:\Users\Asus\Downloads\smime.p7s
2026-01-14 12:45 - 2026-01-15 16:32 - 000000000 ____D C:\zoek_backup
2026-01-12 13:19 - 2026-01-12 13:19 - 000001175 _____ C:\Users\Asus\Desktop\EVEREST Home Edition.lnk
2026-01-12 13:19 - 2026-01-12 13:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2026-01-12 13:19 - 2026-01-12 13:19 - 000000000 ____D C:\Program Files (x86)\Lavalys
2026-01-09 22:32 - 2026-01-09 22:32 - 000001187 _____ C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adlice Protect.lnk
2026-01-09 22:32 - 2026-01-09 22:32 - 000000899 _____ C:\Users\Public\Desktop\Adlice Protect.lnk
2026-01-09 22:32 - 2026-01-09 22:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2026-01-09 22:32 - 2026-01-09 22:32 - 000000000 ____D C:\Program Files\RogueKiller
2026-01-09 20:29 - 2026-01-09 20:29 - 000002775 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2026-01-09 20:29 - 2026-01-09 20:29 - 000000000 ____D C:\ProgramData\Sophos
2026-01-09 20:29 - 2026-01-09 20:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2026-01-09 20:29 - 2026-01-09 20:29 - 000000000 ____D C:\Program Files (x86)\Sophos
2026-01-08 18:30 - 2026-01-08 18:30 - 000000000 ____D C:\Users\Asus\AppData\Local\Apple
2026-01-08 12:44 - 2025-10-23 11:50 - 005689843 _____ (The OpenSSL Project, hxxps://www.openssl.org/) C:\WINDOWS\system32\libcrypto-3-x64.dll
2026-01-08 12:44 - 2025-10-23 11:50 - 003450648 _____ (The OpenSSL Project, hxxps://www.openssl.org/) C:\WINDOWS\system32\libcrypto-1_1.dll
2026-01-08 12:44 - 2025-10-23 11:50 - 001083646 _____ (libusb.info) C:\WINDOWS\system32\libusb-1.0.dll
2026-01-08 10:55 - 2026-01-08 10:55 - 000000943 _____ C:\Users\Asus\Desktop\JRT.txt
2026-01-07 15:52 - 2026-01-12 14:46 - 000000000 ____D C:\Users\Asus\AppData\Local\Malwarebytes
2026-01-07 15:52 - 2026-01-07 15:52 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-01-07 15:52 - 2026-01-07 15:52 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-01-07 15:51 - 2026-01-07 15:51 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-01-07 15:51 - 2026-01-07 15:51 - 000000000 ____D C:\Program Files\Malwarebytes
2026-01-06 21:02 - 2026-01-25 11:57 - 000000000 ____D C:\Users\Asus\Desktop\hudba
2025-12-31 20:05 - 2025-12-31 20:05 - 000000000 ____D C:\WINDOWS\LastGood.Tmp

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-01-25 11:58 - 2025-11-05 10:22 - 000000000 ____D C:\AAA
2026-01-25 11:58 - 2021-11-24 08:55 - 008584192 _____ C:\WINDOWS\SysWOW64\tempResults.db
2026-01-25 11:52 - 2020-09-14 12:57 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-01-25 11:23 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-01-25 10:22 - 2025-09-21 18:21 - 000003058 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-804831582-2933453136-550661674-1005
2026-01-25 10:22 - 2025-09-21 18:20 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-804831582-2933453136-550661674-1005
2026-01-25 10:22 - 2025-09-21 10:22 - 000002954 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2026-01-25 10:22 - 2025-09-21 10:22 - 000000670 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2026-01-25 10:22 - 2025-01-21 09:51 - 000003096 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-804831582-2933453136-550661674-1001
2026-01-25 10:22 - 2024-01-24 10:17 - 000002852 _____ C:\WINDOWS\system32\Tasks\CCleanerBrowserProtectS-1-5-21-804831582-2933453136-550661674-1001
2026-01-25 10:22 - 2022-06-06 08:56 - 000002248 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Asus
2026-01-25 10:22 - 2021-12-13 14:27 - 000003058 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-804831582-2933453136-550661674-1001
2026-01-25 10:22 - 2021-11-23 16:19 - 000002550 _____ C:\WINDOWS\system32\Tasks\AudioHUB
2026-01-25 10:22 - 2020-11-15 13:50 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-804831582-2933453136-550661674-1004
2026-01-25 10:22 - 2020-09-14 13:04 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-01-25 10:22 - 2020-09-14 13:04 - 000003456 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineUA
2026-01-25 10:22 - 2020-09-14 13:04 - 000003340 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-01-25 10:22 - 2020-09-14 13:04 - 000003232 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineCore
2026-01-25 10:22 - 2020-09-14 13:04 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2026-01-25 10:22 - 2020-09-14 13:04 - 000003092 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Hourly)
2026-01-25 10:22 - 2020-09-14 13:04 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-804831582-2933453136-550661674-1001
2026-01-25 10:22 - 2020-09-14 13:04 - 000002610 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Logon)
2026-01-25 10:19 - 2020-09-14 13:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2026-01-25 09:48 - 2021-12-17 23:51 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-01-25 09:44 - 2020-05-03 10:39 - 000000000 ____D C:\Program Files\CCleaner
2026-01-23 13:34 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-01-23 13:34 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-01-23 12:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2026-01-22 20:38 - 2020-04-27 13:15 - 000000000 ____D C:\Users\Asus\AppData\Local\CrashDumps
2026-01-20 19:12 - 2020-04-25 08:24 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-01-20 19:12 - 2020-04-25 08:24 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-01-19 20:41 - 2020-09-14 12:58 - 000002376 _____ C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-01-18 16:32 - 2020-06-11 13:52 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-01-18 16:32 - 2020-06-11 13:52 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-01-16 11:14 - 2025-01-17 12:57 - 000002430 _____ C:\Users\Asus\Desktop\Osoba 1 - Chrome.lnk
2026-01-16 09:34 - 2021-06-09 21:48 - 000000000 ____D C:\Users\Asus\AppData\Local\Avast Software
2026-01-15 16:26 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2026-01-15 16:26 - 2015-10-30 08:24 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2026-01-15 16:23 - 2025-09-21 18:16 - 000000000 ____D C:\Users\Lada\AppData\Local\AVAST Software
2026-01-15 16:23 - 2020-09-14 12:58 - 000000000 ____D C:\Users\Asus
2026-01-12 14:47 - 2020-04-24 10:07 - 000000000 ____D C:\Users\Asus\AppData\Local\VirtualStore
2026-01-09 23:19 - 2023-07-09 10:52 - 000000000 ____D C:\ProgramData\RogueKiller
2026-01-09 20:26 - 2025-09-22 17:32 - 000000000 ____D C:\Program Files (x86)\Bright VPN
2026-01-08 12:44 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2026-01-08 11:33 - 2024-07-12 16:54 - 000000000 ____D C:\Program Files (x86)\Chimera
2026-01-08 11:27 - 2025-07-28 20:11 - 000000000 ____D C:\ProgramData\Chimera
2026-01-08 11:26 - 2024-06-27 20:00 - 000000000 ____D C:\Users\Asus\AppData\Roaming\IDMComp
2026-01-08 11:24 - 2024-06-11 15:15 - 000000000 ____D C:\Program Files (x86)\Frp HiJacker by Hagard
2026-01-07 15:52 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-01-07 15:49 - 2021-01-06 21:38 - 000000000 ____D C:\Users\Asus\AppData\Roaming\Samsung
2026-01-07 15:49 - 2021-01-06 21:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2026-01-07 15:49 - 2021-01-06 21:38 - 000000000 ____D C:\Program Files (x86)\Samsung
2026-01-07 15:47 - 2020-09-14 13:08 - 001693820 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-01-07 15:47 - 2020-04-25 08:40 - 000000000 ____D C:\Program Files\Avast Software
2026-01-07 15:47 - 2020-04-25 08:29 - 000000000 ____D C:\ProgramData\AVAST Software
2026-01-07 15:47 - 2019-12-07 15:41 - 000716932 _____ C:\WINDOWS\system32\perfh005.dat
2026-01-07 15:47 - 2019-12-07 15:41 - 000145110 _____ C:\WINDOWS\system32\perfc005.dat
2026-01-07 15:41 - 2020-09-14 10:31 - 000000000 __SHD C:\Users\Asus\IntelGraphicsProfiles
2026-01-07 15:41 - 2020-09-14 10:30 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2026-01-07 15:40 - 2024-06-20 15:14 - 000008192 ___SH C:\DumpStack.log.tmp
2026-01-07 15:40 - 2020-09-14 13:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-01-07 15:40 - 2019-12-07 10:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2026-01-07 15:18 - 2024-06-13 17:36 - 000000000 ____D C:\Users\Asus\AppData\Local\ElevatedDiagnostics
2026-01-01 23:37 - 2025-10-21 19:20 - 000000000 ____D C:\Program Files\3uToolsV3

==================== Files in the root of some directories ========

2025-09-16 17:47 - 2025-09-16 17:47 - 000000128 _____ () C:\Users\Asus\AppData\Local\PUTTY.RND
2021-08-22 19:13 - 2021-08-22 19:13 - 000000424 _____ () C:\Users\Asus\AppData\Local\UserProducts.xml

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
ladislavhu1993
nováček
Příspěvky: 46
Registrován: 18 lis 2023 19:00

Re: Prosim o kontrolu Dekuji

Příspěvek od ladislavhu1993 »

ted uz nejde ani seznam :D
ladislavhu1993
nováček
Příspěvky: 46
Registrován: 18 lis 2023 19:00

Re: Prosim o kontrolu Dekuji

Příspěvek od ladislavhu1993 »

:D
Bez názvu.jpg
Nemáte oprávnění prohlížet přiložené soubory.
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43454
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: Prosim o kontrolu Dekuji

Příspěvek od jaro3 »

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CreateRestorePoint:
CloseProcesses:
ContextMenuHandlers1: [Long-Term Docs Signer] -> {8B7B7594-9951-4D5A-BBCC-EB9AEE81CB12} => -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6_S-1-5-21-804831582-2933453136-550661674-1001: [UltraEdit] -> {b5eedee0-c06e-11cf-8c56-444553540000} => -> No File
FirewallRules: [{9F3CCBB4-DDDA-4FD3-8815-3F772E9A2B24}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe => No File
FirewallRules: [{91A35D2F-F01F-4DE8-B055-B53BC32342A6}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe => No File
FirewallRules: [{8D5EB34E-607D-44C9-9040-2A8C7E0BCB62}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{2E2B7E30-5ED1-4E42-A2B3-13CC849A3F64}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{4F2C5D40-3E9A-4FD3-9D98-8E103109C66C}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{9E396163-58D1-45A1-A988-FA16FCD03AD1}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{7916077C-0E52-4EA9-8D17-115FB78EA1DB}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{9F99CB82-E2A8-4203-97B5-B11B6DE0710D}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{D914AC95-9AFC-4CA3-A99B-E9F37BA3602F}] => (Allow) C:\program files (x86)\wondershare\dr.fone - data eraser (ios)\drfonetoolkit.exe => No File
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {289a066e-6ca7-11f0-a650-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {391ba123-f766-11eb-a5a8-ecb1d73deff7} - "E:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {7e166aa0-49b0-11eb-a595-ecb1d73deff7} - "E:\AutoRun.exe" 
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {ae6c0047-2bd2-11eb-a593-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {c74added-7617-11f0-a651-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {ca78114a-6c92-11f0-a64f-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {d12555bc-6217-11f0-a64c-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1005\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Lada\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SPDriverInstall.lnk [2025-07-18] <==== ATTENTION
ShortcutTarget: SPDriverInstall.lnk -> C:\Program Files\MediaTek\SP Driver\SPDriverInstall (No File) <==== ATTENTION
ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAndroidAppHelper.exe (No File)
ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAppHelper.exe (No File)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

EmptyTemp:
End
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Drive c: () (Fixed) (Total:446.15 GB) (Free:26.72 GB) (Model: Patriot Burst) NTFS
Totální nedostatek volného místa na disku!! Něco odinstaluj , smaž. Máš mít nejméně 15-20% volného místa na syst. disku , pro zajištění bezproblémového chodu windows!!
Error: (01/22/2026 08:38:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe, verze: 1.0.0.2310, časové razítko: 0x64198cc9
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.19041.6456, časové razítko: 0xbf208242
Asi opravit ten program přeinstalací.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
ladislavhu1993
nováček
Příspěvky: 46
Registrován: 18 lis 2023 19:00

Re: Prosim o kontrolu Dekuji

Příspěvek od ladislavhu1993 »

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-01-2026
Ran by Asus (26-01-2026 16:30:37) Run:1
Running from C:\Users\Asus\Desktop\hudba
Loaded Profiles: Asus & Mamka & Lada
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
ContextMenuHandlers1: [Long-Term Docs Signer] -> {8B7B7594-9951-4D5A-BBCC-EB9AEE81CB12} => -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6_S-1-5-21-804831582-2933453136-550661674-1001: [UltraEdit] -> {b5eedee0-c06e-11cf-8c56-444553540000} => -> No File
FirewallRules: [{9F3CCBB4-DDDA-4FD3-8815-3F772E9A2B24}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe => No File
FirewallRules: [{91A35D2F-F01F-4DE8-B055-B53BC32342A6}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe => No File
FirewallRules: [{8D5EB34E-607D-44C9-9040-2A8C7E0BCB62}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{2E2B7E30-5ED1-4E42-A2B3-13CC849A3F64}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{4F2C5D40-3E9A-4FD3-9D98-8E103109C66C}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{9E396163-58D1-45A1-A988-FA16FCD03AD1}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{7916077C-0E52-4EA9-8D17-115FB78EA1DB}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{9F99CB82-E2A8-4203-97B5-B11B6DE0710D}] => (Allow) C:\Users\Asus\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{D914AC95-9AFC-4CA3-A99B-E9F37BA3602F}] => (Allow) C:\program files (x86)\wondershare\dr.fone - data eraser (ios)\drfonetoolkit.exe => No File
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {289a066e-6ca7-11f0-a650-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {391ba123-f766-11eb-a5a8-ecb1d73deff7} - "E:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {7e166aa0-49b0-11eb-a595-ecb1d73deff7} - "E:\AutoRun.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {ae6c0047-2bd2-11eb-a593-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {c74added-7617-11f0-a651-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {ca78114a-6c92-11f0-a64f-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1001\...\MountPoints2: {d12555bc-6217-11f0-a64c-ecb1d73deff7} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-804831582-2933453136-550661674-1005\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Lada\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SPDriverInstall.lnk [2025-07-18] <==== ATTENTION
ShortcutTarget: SPDriverInstall.lnk -> C:\Program Files\MediaTek\SP Driver\SPDriverInstall (No File) <==== ATTENTION
ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAndroidAppHelper.exe (No File)
ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAppHelper.exe (No File)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

EmptyTemp:
End
*****************

CreateRestorePoint: Error(1=6%) -> Failed to create a restore point.
Processes closed successfully.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Long-Term Docs Signer => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ACE => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UltraEdit => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Classes\CLSID\{b5eedee0-c06e-11cf-8c56-444553540000} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9F3CCBB4-DDDA-4FD3-8815-3F772E9A2B24}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{91A35D2F-F01F-4DE8-B055-B53BC32342A6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8D5EB34E-607D-44C9-9040-2A8C7E0BCB62}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2E2B7E30-5ED1-4E42-A2B3-13CC849A3F64}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4F2C5D40-3E9A-4FD3-9D98-8E103109C66C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9E396163-58D1-45A1-A988-FA16FCD03AD1}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7916077C-0E52-4EA9-8D17-115FB78EA1DB}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9F99CB82-E2A8-4203-97B5-B11B6DE0710D}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D914AC95-9AFC-4CA3-A99B-E9F37BA3602F}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{289a066e-6ca7-11f0-a650-ecb1d73deff7} => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{391ba123-f766-11eb-a5a8-ecb1d73deff7} => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7e166aa0-49b0-11eb-a595-ecb1d73deff7} => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ae6c0047-2bd2-11eb-a593-ecb1d73deff7} => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c74added-7617-11f0-a651-ecb1d73deff7} => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ca78114a-6c92-11f0-a64f-ecb1d73deff7} => removed successfully
HKU\S-1-5-21-804831582-2933453136-550661674-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d12555bc-6217-11f0-a64c-ecb1d73deff7} => removed successfully
"HKU\S-1-5-21-804831582-2933453136-550661674-1005\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SPDriverInstall.lnk => moved successfully
"C:\Program Files\MediaTek\SP Driver\SPDriverInstall" => not found
"C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAndroidAppHelper.exe" => not found
"C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAppHelper.exe" => not found
C:\ProgramData\NTUSER.pol => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1835008 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 121771149 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 136823505 B
Windows/system/drivers => 94975720 B
Edge => 898579346 B
Chrome => 504041765 B
Firefox => 0 B
Opera => 0 B

Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 6656 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 4308 B
NetworkService => 0 B
Asus => 649299489 B
Mamka => 55855 B
Lada => 17767 B

RecycleBin => 43681971 B
EmptyTemp: => 2.3 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 16:32:58 ====
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43454
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: Prosim o kontrolu Dekuji

Příspěvek od jaro3 »

Uvolnil sis místo nadisku? Napiš co problémy , zda jsou.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
ladislavhu1993
nováček
Příspěvky: 46
Registrován: 18 lis 2023 19:00

Re: Prosim o kontrolu Dekuji

Příspěvek od ladislavhu1993 »

hezky , den uz je to lepsi ale i tak je to pomale.
Jinak jsem mazal veci tak snad asi staci volneho mista ? 72,5
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43454
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: Prosim o kontrolu Dekuji

Příspěvek od jaro3 »

Stáhni si Memtest
http://www.stahuj.cz/utility_a_ostatni/ ... i/memtest/

Políčko , ve kterém je napsáno:
All unused RAM ponech.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.
poklepej na Memtest , pak znovu a znovu , do políček všech Memtestů napiš 2048 , pak dej u všech Memtestů "Start".

//
+

Stáhni si CrystalDiskInfo
https://www.stahuj.cz/utility_a_ostatni ... ldiskinfo/
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Zpět na „HiJackThis“