Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-05-2026
Ran by David Hynek (administrator) on DESKTOP-KR0LJ7U (Gigabyte Technology Co., Ltd. Z390 GAMING X) (17-05-2026 21:26:11)
Running from C:\Users\David Hynek\Desktop\FRST64.exe
Loaded Profiles: David Hynek
Platform: Microsoft Windows 10 Home Version 22H2 19045.7291 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSATray.exe
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(D:\overwolf\Overwolf.exe ->) (Overwolf Ltd -> Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.300.0.11\OverwolfHelper.exe
(D:\overwolf\Overwolf.exe ->) (Overwolf Ltd -> Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.300.0.11\OverwolfHelper64.exe
(D:\overwolf\Overwolf.exe ->) (Overwolf Ltd -> Overwolf LTD) D:\overwolf\0.300.0.11\OverwolfBrowser.exe <4>
(D:\Riot Games\Riot Client\RiotClientServices.exe ->) () [File not signed] D:\Riot Games\Riot Client\RiotClientCrashHandler.exe
(Discord Inc. -> Discord Inc.) C:\Users\David Hynek\AppData\Local\Discord\app-1.0.9237\Discord.exe <6>
(discord-code-sign-windows-admin -> Discord Inc.) C:\Users\David Hynek\AppData\Local\Discord\app-1.0.9237\modules\discord_utils-1\discord_utils\DiscordSystemHelper.exe <2>
(explorer.exe ->) (A FOUR TECH CO., LTD. -> ) C:\Program Files (x86)\Bloody7\Bloody7\Bloody7.exe
(explorer.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <32>
(explorer.exe ->) (Open Source Developer, Phillip Gibbons -> Highresolution Enterprises) C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) D:\Riot Games\Riot Client\RiotClientServices.exe
(explorer.exe ->) (Spotify AB -> Spotify Ltd) C:\Users\David Hynek\AppData\Roaming\Spotify\Spotify.exe <7>
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Overwolf Ltd -> Overwolf LTD) D:\overwolf\Overwolf.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\2.00.06\atkexComSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvDump.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft) C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logitech\LogiCapture\bin\Service\LogiFacecamService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\GameInputSvc.exe <2>
(services.exe ->) (Microsoft Corporation -> Windows (R) Win 7 DDK provider) C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe <2>
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_f088ae99b5a2f5fd\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2508.4.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [1061544 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1738088 2023-06-24] (Open Source Developer, Phillip Gibbons -> Highresolution Enterprises)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [4148120 2026-05-01] (Riot Games, Inc. -> Riot Games, Inc.)
HKLM-x32\...\Run: [Arc] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [751240 2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe [14632 2016-02-26] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\...\Run: [Discord] => C:\Users\David Hynek\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\...\Run: [Bloody2] => C:\Program Files (x86)\Bloody7\Bloody7\Bloody7.exe [19841264 2020-02-13] (A FOUR TECH CO., LTD. -> )
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\...\Run: [Microsoft Edge Update] => C:\Users\David Hynek\AppData\Local\Microsoft\EdgeUpdate\1.3.233.3\MicrosoftEdgeUpdateCore.exe [278912 2026-05-01] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\...\Run: [RiotClient] => D:\Riot Games\Riot Client\RiotClientServices.exe [75632248 2026-05-04] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\...\Run: [Overwolf] => D:\overwolf\OverwolfLauncher.exe [1987904 2026-05-07] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42087896 2026-04-29] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\...\Run: [MicrosoftEdgeAutoLaunch_1B7C220DB7067EC483E4B449B3CC6ADE] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5168456 2026-05-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-994775172-3552113607-2548991599-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [39936 2024-05-17] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3971224 2026-04-18] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\148.0.7778.168\Installer\chrmstp.exe [7605912 2026-05-15] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {D8816A71-4C4C-48EF-A253-A99040F87834} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {58EDBE0A-BF3B-4883-B209-21318A9BB484} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [9607904 2026-04-21] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {F8CAE712-D81C-4187-9879-CEF6B2E08151} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5783720 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {F16E0F1C-4A1E-47C0-827B-7F293103BADC} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2977504 2025-10-14] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9F651957-99E9-4C5A-9FBC-D9D86DF07956} - System32\Tasks\GBTECService => C:\Program Files (x86)\GIGABYTE\GBTECService\LiquidSensord.exe [253312 2021-06-23] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
Task: {1D081D10-327D-4B1F-9F01-A984104453D0} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{031462DA-4CD8-48D7-AEDA-2A5BA20396B3} => C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe [8770200 2026-04-28] (Google LLC -> Google LLC)
Task: {C27DD72E-8C31-4589-A4B8-6E5E65E802C4} - System32\Tasks\GraphicsCardEngine => C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngineStarter.exe [234880 2021-04-13] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
Task: {043FBF82-A55C-4787-B5C9-C144AB2EC3A6} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3077448 2021-12-13] (Intel Corporation -> Intel Corporation)
Task: {3DE5EE79-6D2F-4F19-BD9F-B31BF1A73CB2} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3077448 2021-12-13] (Intel Corporation -> Intel Corporation)
Task: {6DF47DF3-D03B-426C-9AF0-487C0421DA1D} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [11419480 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {C17EBEBE-E59B-458B-91E8-23A30AC4A5AA} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {228546EB-B6F4-43F6-9494-C1859BD3C340} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\opushutil.exe [61280 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {00C7872C-A684-42C2-B6D5-B3B48D57A466} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0207CB6-3843-48F8-8775-783C1440CBFE} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {77654474-67D6-4419-9261-9E55B115EF90} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {45D4FC9C-6234-4358-BE24-11423F47BBD7} - System32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-994775172-3552113607-2548991599-1001Core => C:\Users\David Hynek\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [206944 2026-03-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {22F00E39-3601-4FE6-92E6-C6392A0686D3} - System32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-994775172-3552113607-2548991599-1001UA => C:\Users\David Hynek\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [206944 2026-03-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {0C45EDA6-CF75-47E0-80B7-A49170137D25} - System32\Tasks\MSIAfterburner => D:\MSI Afterburner\MSIAfterburner.exe [804408 2021-12-03] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {839A12B1-0668-47BE-86DB-DE842D95A0AD} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3346544 2026-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A9C348A8-EBD9-4935-84D9-4D9F1E821877} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2400584 2026-05-07] (Overwolf Ltd -> Overwolf LTD) -> D:\overwolf\/RunningFrom Schedule

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{013838db-2b9b-489b-adc2-b1af1a53491a}: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.11 -> D:\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> D:\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> D:\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> D:\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-04-29] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.491.2 -> C:\Program Files (x86)\Java\jre1.8.0_491\bin\dtplugin\npDeployJava1.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.491.2 -> C:\Program Files (x86)\Java\jre1.8.0_491\bin\plugin2\npjp2.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-07-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-08-28] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.21 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\David Hynek\AppData\Local\Microsoft\Edge\User Data\Default [2026-05-17]
Edge DownloadDir: D:\ChromeDownloads
Edge StartupUrls: Default -> "hxxp://tipsport.cz/"
Edge Session Restore: Default -> is enabled.
Edge Extension: (Dokumenty Google offline) - C:\Users\David Hynek\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-15]
Edge Extension: (Edge relevant text changes) - C:\Users\David Hynek\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge DownloadDir: Default -> D:\ChromeDownloads

Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default [2026-05-17]
CHR DownloadDir: D:\ChromeDownloads
CHR Notifications: Default -> hxxps://badoo.com; hxxps://cz19.the-west.cz; hxxps://fr1.badoo.com; hxxps://lostmerchants.com; hxxps://www.escapefromtarkov.com; hxxps://www.facebook.com; hxxps://www.faceit.com; hxxps://www.pathofexile.com; hxxps://www.reddit.com
CHR Session Restore: Default -> is enabled.
CHR Extension: (BetterTTV) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2026-05-13]
CHR Extension: (Blokátor reklam AdGuard) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2026-05-16]
CHR Extension: (PoE Trade Extension) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikeebdigkompjnpcljicocidefgbhgl [2026-04-09]
CHR Extension: (uBlock Origin Lite) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddkjiahejlhfcafbddmgiahcphecmpfh [2026-05-09]
CHR Extension: (Tampermonkey) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2025-11-25]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-14]
CHR Extension: (Better PathOfExile Trading) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhlinfpmdlijegjlpgedcmglkakaghnk [2025-10-14]
CHR Extension: (Return YouTube Dislike) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebbhagfogifgggkldgodflihgfeippi [2026-05-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-15]
CHR Extension: (Path of Exile Trade - Fuzzy Search) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkbkmkampdnnbehdldipgjhbablkmfba [2023-10-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\Guest Profile [2026-05-17]
CHR Profile: C:\Users\David Hynek\AppData\Local\Google\Chrome\User Data\System Profile [2025-05-13]
CHR HKU\S-1-5-21-994775172-3552113607-2548991599-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
S3 AntiCheatExpert Service; C:\Program Files\AntiCheatExpert\SGuard\x64\SGuardSvc64.exe [2106368 2024-06-21] (PROXIMA BETA PTE. LIMITED -> ANTICHEATEXPERT.COM)
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [177944 2025-09-18] (Arc Games Inc. -> Arc Games Publishing)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\2.00.06\atkexComSvc.exe [411456 2019-04-30] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7984296 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [1038504 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1091752 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
R2 avastAvDumper64; C:\Program Files\Avast Software\Avast\AvDump.exe [4053672 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2025-03-13] (Avast Software s.r.o. -> AVAST Software)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3386064 2026-04-14] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [18991400 2025-10-27] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13288288 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
S3 DiscordSystemHelper; C:\Program Files\Common Files\Discord\Discord\DiscordSystemHelper.exe [2247552 2026-04-21] (discord-code-sign-windows-admin -> Discord Inc.)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [133736 2026-03-24] (Intel Corporation -> Intel)
R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [133224 2026-03-24] (Intel Corporation -> Intel)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [19068000 2024-12-16] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2024-04-25] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [985896 2026-05-04] (EasyAntiCheat Oy -> Epic Games, Inc.)
R2 EasyTuneEngineService; C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\EasyTuneEngineService.exe [147840 2022-01-25] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 EpicGamesUpdater; D:\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3407800 2026-05-12] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [2607032 2026-04-30] (Epic Games Inc. -> Epic Games, Inc.)
S3 GalaxyClientService; D:\GOG Galaxy\GalaxyClientService.exe [1959776 2022-04-04] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6484832 2022-04-04] (GOG Sp. z o.o. -> GOG.com)
R2 GameInputRedistService; C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe [400768 2026-03-31] (Microsoft Corporation -> Windows (R) Win 7 DDK provider)
S2 GBTECService; C:\Program Files (x86)\Gigabyte\GBTECService\OLEDDisplayService.exe [16768 2021-06-23] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R2 Gservice; C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe [19888 2016-12-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft)
R2 LMS; C:\Intel(R) Management Engine Components\LMS\LMS.exe [625240 2018-11-16] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 LogiFacecamService; C:\Program Files\Logitech\LogiCapture\bin\Service\LogiFacecamService.exe [497568 2021-10-25] (Logitech Inc -> Logitech)
R2 MyService1; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [17920 2015-06-25] () [File not signed]
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_f088ae99b5a2f5fd\Display.NvContainer\NVDisplay.Container.exe [1275584 2025-10-10] (NVIDIA Corporation -> NVIDIA Corporation)
S2 OCButtonService; C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\OcButtonService.exe [127360 2021-04-13] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2400584 2026-05-07] (Overwolf Ltd -> Overwolf LTD)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [6020336 2022-07-11] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2019-11-12] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [66393768 2026-05-01] (Riot Games, Inc. -> Riot Games, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [26193816 2025-10-27] (KRAFTON, Inc. -> KRAFTON, Inc.)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACE-BASE; C:\WINDOWS\system32\drivers\ACE-BASE.sys [2182128 2024-06-22] (Microsoft Windows Hardware Compatibility Publisher -> ANTICHEATEXPERT.COM)
S3 ACE-GAME; C:\WINDOWS\system32\drivers\ACE-GAME.sys [914760 2022-07-12] (PUBG CORPORATION -> ANTICHEATEXPERT.COM)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2019-04-30] (ASUSTeK Computer Inc. -> )
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [21088 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [259168 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [451168 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [315488 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [87136 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [29144 2025-07-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [32864 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [289376 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [633440 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [96864 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [71776 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [911456 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1292896 2026-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [250464 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [466016 2026-05-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
S3 DroidCam; C:\WINDOWS\System32\drivers\droidcam.sys [32240 2020-04-10] (Microsoft Windows Hardware Compatibility Publisher -> Dev47Apps)
S3 DroidCamVideo; C:\WINDOWS\System32\DriverStore\FileRepository\droidcamvideo.inf_amd64_47e18363cbf3dfe0\droidcamvideo.sys [33784 2021-04-10] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_e64afe811c7e4662\e1d.sys [607400 2022-02-22] (Intel Corporation -> Intel Corporation)
S3 gdrv; C:\Windows\gdrv.sys [26792 2019-04-28] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R3 gdrv2; C:\WINDOWS\gdrv2.sys [32600 2026-05-17] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R3 gdrv3; C:\WINDOWS\System32\drivers\gdrv3.sys [41480 2022-06-21] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [19392 2018-04-23] (ASUSTeK Computer Inc. -> )
S3 RTCore64; D:\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 VBAudioVMAUXVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmauxvaio64_win10.sys [71920 2023-04-07] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2023-04-07] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [53793336 2026-05-01] (Riot Games, Inc. -> Riot Games, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Users\David Hynek\AppData\Local\Temp\7z5F60B2E0\WinRing0x64.sys [33176 2019-01-02] (NetEase(Hangzhou) Network Co. Ltd. -> ) <==== ATTENTION
S3 xhunter1; C:\WINDOWS\xhunter1.sys [1431256 2022-07-26] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (No File)
S3 semav6msr64; \??\C:\WINDOWS\system32\drivers\semav6msr64.sys (No File)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

Error Reading file: "C:\ProgramData\Desktop\Urban Rivals.lnk"
Error Reading file: "C:\ProgramData\Desktop\TeamSpeak 3 Client.lnk"
Error Reading file: "C:\ProgramData\Desktop\StreamElements SE.Live.lnk"
Error Reading file: "C:\ProgramData\Desktop\Steam.lnk"
Error Reading file: "C:\ProgramData\Desktop\Path of Exile.lnk"
Error Reading file: "C:\ProgramData\Desktop\Path of Exile 2.lnk"
Error Reading file: "C:\ProgramData\Desktop\OBS Studio.lnk"
Error Reading file: "C:\ProgramData\Desktop\Microsoft Edge.lnk"
Error Reading file: "C:\ProgramData\Desktop\Legacy Games Launcher.lnk"
Error Reading file: "C:\ProgramData\Desktop\League of Legends PBE.lnk"
Error Reading file: "C:\ProgramData\Desktop\GOG Galaxy.lnk"
Error Reading file: "C:\ProgramData\Desktop\Epic Games Launcher.lnk"
Error Reading file: "C:\ProgramData\Desktop\EA.lnk"
Error Reading file: "C:\ProgramData\Desktop\desktop.ini"
Error Reading file: "C:\ProgramData\Desktop\CPUID HWMonitor.lnk"
Error Reading file: "C:\ProgramData\Desktop\Bloody7.lnk"
Error Reading file: "C:\ProgramData\Desktop\Battlestate Games Launcher.lnk"
Error Reading file: "C:\ProgramData\Desktop\Battle.net.lnk"
Error Reading file: "C:\ProgramData\Desktop\Avast Free Antivirus.lnk"
Error Reading file: "C:\ProgramData\Desktop\Ascension Launcher.lnk"
2026-05-17 21:26 - 2026-05-17 21:26 - 000033038 _____ C:\Users\David Hynek\Desktop\FRST.txt
2026-05-17 21:25 - 2026-05-17 21:24 - 002448896 _____ (Farbar) C:\Users\David Hynek\Desktop\FRST64.exe
2026-05-17 21:21 - 2026-05-17 21:21 - 000032600 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\gdrv2.sys
2026-05-16 00:50 - 2026-05-16 00:50 - 000000000 ____D C:\WINDOWS\SecureBoot
2026-05-14 00:01 - 2026-05-14 00:01 - 000000000 ____D C:\Program Files\Microsoft GameInput
2026-05-14 00:00 - 2026-05-14 00:00 - 000477640 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_e.dll.0
2026-05-14 00:00 - 2026-05-14 00:00 - 000000028 ____H C:\.GamingRoot
2026-05-14 00:00 - 2026-05-14 00:00 - 000000000 ____D C:\XboxGames
2026-05-14 00:00 - 2026-05-14 00:00 - 000000000 ____D C:\Users\Public\XboxGamingApp
2026-05-12 20:10 - 2026-05-12 20:10 - 000000202 _____ C:\Users\David Hynek\Desktop\PUBG BATTLEGROUNDS.url
2026-05-04 18:58 - 2026-05-04 18:58 - 000000203 _____ C:\Users\David Hynek\Desktop\Apex Legends.url
2026-05-01 11:19 - 2026-05-01 11:19 - 000324264 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2026-04-30 12:56 - 2026-04-30 12:56 - 000174204 _____ C:\Users\David Hynek\Desktop\4ipi10rox6yg1.jpeg
2026-04-24 15:28 - 2026-04-24 15:28 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\Sun
2026-04-24 15:28 - 2026-04-24 15:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2026-04-24 15:28 - 2026-04-24 15:28 - 000000000 ____D C:\Program Files (x86)\Java
2026-04-24 15:28 - 2026-03-30 08:18 - 000182456 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2026-04-24 15:24 - 2026-04-24 15:27 - 000000931 _____ C:\Users\David Hynek\Desktop\易火-ETor.lnk
2026-04-24 15:24 - 2026-04-24 15:24 - 000000931 _____ C:\Users\David Hynek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\易火-ETor.lnk
2026-04-24 15:24 - 2026-04-24 15:24 - 000000000 ____D C:\Users\David Hynek\AppData\Local\etor-updater
2026-04-23 20:10 - 2026-04-23 20:10 - 000000659 _____ C:\Users\David Hynek\Desktop\TITrack.lnk
2026-04-18 17:25 - 2026-04-18 17:25 - 000145149 _____ C:\Users\David Hynek\Desktop\m3cpdpjfjxvg1.jpeg

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-05-17 21:26 - 2021-12-17 12:47 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-05-17 21:26 - 2020-01-15 02:16 - 000000000 ____D C:\FRST
2026-05-17 21:24 - 2020-04-15 21:20 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2026-05-17 21:23 - 2019-04-28 19:26 - 000000000 ____D C:\Users\David Hynek\AppData\Local\Spotify
2026-05-17 21:22 - 2025-08-31 16:24 - 000001870 _____ C:\Users\David Hynek\Desktop\PoE Overlay II.lnk
2026-05-17 21:22 - 2025-04-02 13:54 - 000001870 _____ C:\Users\David Hynek\Desktop\Mobalytics.lnk
2026-05-17 21:22 - 2022-11-19 14:05 - 000000000 ____D C:\Users\David Hynek\AppData\Local\Overwolf
2026-05-17 21:22 - 2019-04-28 13:49 - 000000000 ____D C:\Users\David Hynek\AppData\Local\CrashDumps
2026-05-17 21:21 - 2021-02-08 12:07 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-05-17 21:21 - 2021-02-08 12:03 - 000008192 ___SH C:\DumpStack.log.tmp
2026-05-17 21:21 - 2020-08-21 19:58 - 000000000 ____D C:\ProgramData\NVIDIA
2026-05-17 21:21 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2026-05-17 21:21 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-05-17 21:21 - 2019-04-28 19:15 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\Spotify
2026-05-17 21:21 - 2019-04-28 10:33 - 000000000 ____D C:\ProgramData\AVAST Software
2026-05-17 21:21 - 2019-04-28 09:51 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\Discord
2026-05-17 21:21 - 2019-04-28 09:51 - 000000000 ____D C:\Users\David Hynek\AppData\Local\Discord
2026-05-17 21:14 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-05-17 21:04 - 2025-04-02 13:54 - 000003230 _____ C:\WINDOWS\system32\Tasks\Overwolf Updater Task
2026-05-17 21:04 - 2025-02-08 15:07 - 000003128 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-994775172-3552113607-2548991599-1001
2026-05-17 21:04 - 2024-12-05 21:27 - 000003010 _____ C:\WINDOWS\system32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2026-05-17 21:04 - 2022-08-09 20:13 - 000002970 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132
2026-05-17 21:04 - 2022-08-09 20:13 - 000002604 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon
2026-05-17 21:04 - 2022-07-09 16:10 - 000003752 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-994775172-3552113607-2548991599-1001UA
2026-05-17 21:04 - 2022-07-09 16:10 - 000003668 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-994775172-3552113607-2548991599-1001Core
2026-05-17 21:04 - 2022-06-21 23:40 - 000002606 _____ C:\WINDOWS\system32\Tasks\GraphicsCardEngine
2026-05-17 21:04 - 2022-06-21 23:35 - 000002552 _____ C:\WINDOWS\system32\Tasks\GBTECService
2026-05-17 21:04 - 2021-12-11 21:40 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-994775172-3552113607-2548991599-1001
2026-05-17 21:04 - 2021-02-08 12:07 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-05-17 21:04 - 2021-02-08 12:07 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2026-05-17 21:04 - 2021-02-08 12:07 - 000003340 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-05-17 21:04 - 2021-02-08 12:07 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-994775172-3552113607-2548991599-1001
2026-05-17 21:04 - 2021-02-08 12:07 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2026-05-17 20:28 - 2021-02-08 12:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-05-17 18:39 - 2026-04-03 17:06 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\EasyAntiCheat
2026-05-17 14:56 - 2019-04-28 13:34 - 000000000 ____D C:\Users\David Hynek\AppData\Local\D3DSCache
2026-05-16 21:11 - 2020-06-10 15:09 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-05-16 21:11 - 2020-06-10 15:09 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-05-16 20:10 - 2021-02-08 12:08 - 001693414 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-05-16 20:10 - 2019-12-07 16:41 - 000716770 _____ C:\WINDOWS\system32\perfh005.dat
2026-05-16 20:10 - 2019-12-07 16:41 - 000144948 _____ C:\WINDOWS\system32\perfc005.dat
2026-05-16 20:10 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2026-05-16 11:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-05-16 00:51 - 2021-02-08 12:03 - 000445936 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-05-16 00:50 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-05-16 00:50 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2026-05-16 00:50 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-05-16 00:50 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-05-16 00:50 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-05-16 00:50 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-05-15 15:15 - 2019-04-28 10:37 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-05-15 15:12 - 2019-04-28 20:47 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-05-15 15:12 - 2019-04-28 10:37 - 220340424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-05-15 07:24 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-05-15 07:22 - 2019-04-28 09:58 - 000429958 __RSH C:\bootmgr
2026-05-15 07:21 - 2021-02-08 12:05 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-05-15 07:16 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-05-15 07:15 - 2019-04-28 09:16 - 000000000 ____D C:\Users\David Hynek\AppData\Local\Packages
2026-05-14 20:00 - 2024-09-20 13:48 - 000000000 ____D C:\ProgramData\Packer
2026-05-14 18:02 - 2024-02-24 01:02 - 000002452 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner
2026-05-14 00:32 - 2021-02-07 23:37 - 000000000 ____D C:\Users\David Hynek
2026-05-14 00:00 - 2019-04-28 09:51 - 000000000 ____D C:\Users\David Hynek\AppData\Local\PlaceholderTileLogoFolder
2026-05-14 00:00 - 2019-04-28 09:32 - 000000000 ____D C:\ProgramData\Packages
2026-05-13 23:59 - 2022-07-11 19:31 - 000000000 ____D C:\Program Files\Common Files\PUBG
2026-05-13 16:37 - 2021-02-07 23:37 - 000002397 _____ C:\Users\David Hynek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-05-12 22:29 - 2026-01-23 22:30 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\etor
2026-05-11 17:57 - 2019-05-07 16:56 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\Microsoft\Word
2026-05-10 16:35 - 2019-08-17 18:04 - 000000000 ____D C:\ProgramData\Riot Games
2026-05-10 16:34 - 2026-02-18 22:50 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\Riot Client
2026-05-10 16:34 - 2024-04-27 11:31 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\riot-client-ux
2026-05-10 11:14 - 2025-11-23 15:51 - 000000612 _____ C:\Users\Public\Desktop\Battlestate Games Launcher.lnk
2026-05-10 11:14 - 2025-11-23 15:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlestate Games
2026-05-10 11:08 - 2024-05-21 10:26 - 000000000 ____D C:\Program Files\Riot Vanguard
2026-05-09 15:47 - 2024-09-20 23:46 - 134222904 _____ C:\WINDOWS\392667600.dat
2026-05-09 01:37 - 2020-11-14 12:52 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\obs-studio
2026-05-06 07:51 - 2019-04-28 10:36 - 001292896 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSP.sys
2026-05-04 23:02 - 2020-03-13 19:54 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\vlc
2026-05-04 22:10 - 2026-04-03 17:06 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat_EOS
2026-05-02 16:42 - 2019-05-17 20:46 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\Microsoft\Excel
2026-05-01 13:02 - 2022-10-13 11:29 - 000002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-05-01 11:20 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-05-01 11:19 - 2020-10-13 19:22 - 000289376 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2026-05-01 11:19 - 2020-04-14 17:46 - 000633440 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswNetHub.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000911456 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswSnx.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000466016 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswVmm.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000451168 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000315488 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000259168 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswArPot.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000096864 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000087136 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000071776 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000032864 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswKbd.sys
2026-05-01 11:19 - 2019-04-28 10:36 - 000021088 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2026-04-30 21:27 - 2019-04-28 17:28 - 000000000 ____D C:\Users\David Hynek\AppData\Local\Battle.net
2026-04-27 23:35 - 2019-07-16 23:27 - 000000000 ____D C:\Users\David Hynek\AppData\Roaming\uTorrent
2026-04-27 21:49 - 2019-04-28 20:24 - 000000000 ____D C:\Users\David Hynek\AppData\Local\BitTorrentHelper
2026-04-23 19:15 - 2022-08-18 12:16 - 000000000 ____D C:\Program Files\dotnet
2026-04-23 19:15 - 2019-04-28 09:59 - 000000000 ____D C:\ProgramData\Package Cache
2026-04-23 18:38 - 2019-04-28 10:08 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2026-04-18 02:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-04-18 02:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-04-18 02:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup

==================== Files in the root of some directories ========

2023-05-26 15:59 - 2023-05-26 15:59 - 000000016 _____ () C:\Users\David Hynek\AppData\Roaming\obs-virtualcam.txt
2024-06-21 16:48 - 2024-06-21 16:48 - 000001008 _____ () C:\Users\David Hynek\AppData\Roaming\taris_launcher.reg
2023-04-09 01:09 - 2023-07-29 15:18 - 000046397 _____ () C:\Users\David Hynek\AppData\Roaming\VoiceMeeterBananaDefault.xml
2023-04-07 18:14 - 2023-04-07 18:36 - 000008113 _____ () C:\Users\David Hynek\AppData\Roaming\VoiceMeeterDefault.xml
2025-11-27 21:20 - 2025-11-27 21:20 - 000000048 ____R () C:\Users\David Hynek\AppData\Local\0119AC2FC90D95AC063B177717B7B3B6
2024-12-12 14:46 - 2024-12-12 14:46 - 000000048 ____R () C:\Users\David Hynek\AppData\Local\AF0831FAAC772AE528D2AD80F69081C7
2019-04-28 13:28 - 2023-04-26 20:29 - 000007596 _____ () C:\Users\David Hynek\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================