Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2026
Ran by maroš (administrator) on MAROć (Micro-Star International Co., Ltd. MS-7B23) (27-05-2026 17:04:58)
Running from C:\Users\maroš\Desktop\FRST64.exe
Loaded Profiles: maroš
Platform: Microsoft Windows 11 Pro Version 25H2 26200.8457 (X64) Language: Slovenčina (Slovensko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Epic Online Services\EpicOnlineServices.exe <2>
(C:\Program Files (x86)\Epic Games\Launcher\Portal\Extras\EOSBootStrapper\EOSBootStrapper.exe.old.ver ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Epic Online Services\EpicOnlineServicesUserHelper.exe <3>
(C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe <7>
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eServiceHost.exe <2>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA App\ShadowPlay\nvsphelper64.exe
(C:\Users\maroš\AppData\Roaming\utorrent\uTorrent.exe ->) (BitTorrent Inc -> BitTorrent Inc.) C:\Users\maroš\AppData\Roaming\utorrent\helper\helper.exe
(C:\Users\maroš\AppData\Roaming\utorrent\uTorrent.exe ->) (Rainberry Inc -> BitTorrent Inc.) C:\Users\maroš\AppData\Roaming\utorrent\updates\3.6.0_47254\utorrentie.exe <2>
(cmd.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\BrowserPrivacyAndSecurity.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Epic Online Services\EpicOnlineServicesInstallHelper.exe <2>
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Extras\EOSBootStrapper\EOSBootStrapper.exe.old.ver
(explorer.exe ->) (Rainberry Inc -> BitTorrent Limited) C:\Users\maroš\AppData\Roaming\utorrent\uTorrent.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <19>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoNotificationUx.exe
(services.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_01095d3b50bff033\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.264.3.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\printfilterpipelinesvc.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Moo0) [File not signed] C:\Users\maroš\Downloads\Moo0_SystemMonitor_v1.76_Portable\Moo0 SystemMonitor v1.76 Portable\SystemMonitor64.exe
(Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [boinctray] => C:\Program Files\BOINC\boinctray.exe [367456 2023-08-12] (University of California, Berkeley -> Space Sciences Laboratory)
HKLM\...\Run: [boincmgr] => C:\Program Files\BOINC\boincmgr.exe [10191200 2023-08-12] (University of California, Berkeley -> Space Sciences Laboratory)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285616 2026-04-10] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [466760 2026-02-12] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Run: [DataCollectionAgentController] => C:\Program Files\EPSON\Epson Data Collection Agent\DataCollectionAgentController.exe [398096 2025-07-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [eID_Client] => C:\Program Files (x86)\eID_klient\eID_Client.exe [22703944 2024-12-10] (Ministerstvo vnútra Slovenskej republiky -> )
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2770680 2025-09-19] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [751240 2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4749160 2026-05-25] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [5771928 2026-05-08] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [SendAnywhere] => C:\Program Files\Send Anywhere\Send Anywhere.exe [104268648 2026-01-23] (Rakuten Symphony Korea, Inc. -> Rakuten Symphony Inc.)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [Disig Web Signer] => C:\Program Files (x86)\Disig\Web Signer\WebSignerTray.exe [274296 2025-06-23] (Disig a.s. -> Disig a.s.)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [41671128 2026-01-31] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3391648 2026-04-02] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIZJE.EXE [486808 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [ut] => C:\Users\maroš\AppData\Roaming\utorrent\uTorrent.exe [3678312 2026-05-21] (Rainberry Inc -> BitTorrent Limited)
HKU\S-1-5-21-836710197-3910017001-3467480500-1001\...\Run: [MicrosoftEdgeAutoLaunch_EC3E573F4EF9979A5E61DD9643D907BB] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5168488 2026-05-21] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\EPSON L3270 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBZJE.DLL [247976 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\WINDOWS\system32\enppmon.dll [3182776 2025-02-20] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3995288 2026-05-21] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\148.0.7778.179\Installer\chrmstp.exe [7621272 2026-05-25] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> 
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {89D97E5A-98B3-4A1C-A6F8-29148BA3B458} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {165F979B-ED4E-43B1-A5C4-B0BF3D7B6282} - System32\Tasks\CCleaner 7 - Skip UAC - S-1-5-21-836710197-3910017001-3467480500-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5598328 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {17A0971E-D0DD-499C-80DF-83898E40998A} - System32\Tasks\CCleanerCrashReporting => C:\Users\maroš\Downloads\ccPortable\App\CCleaner\x64\CCleanerBugReport.exe  -> --product 90 --send dumps|report --path "C:\Users\maroš\Downloads\ccPortable\App\CCleaner\LOG" --programpath "C:\Users\maroš\Downloads\ccPortable\App\CCleaner" --guid "" --version "6.39.0.11548" --silent
Task: {B9B24DD5-5C20-471B-B6FD-AB631238EBAB} - System32\Tasks\CCleanerSkipUAC - maroš => "C:\Users\maroš\Downloads\ccPortable\App\CCleaner\CCleaner.exe"  $(Arg0) (No File)
Task: {404B3D7C-425E-45B8-B12A-0B75E81BC1BA} - System32\Tasks\DUpdaterTask => C:\Program Files (x86)\Ditec\DUpdater\DUpdater.exe [5515344 2024-06-18] (DITEC, a.s. -> DITEC, a.s.)
Task: {5E02E7F9-3610-4C62-BE53-6B359335F528} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\maroš\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [21737944 2023-09-09] (ESET, spol. s r.o. -> ESET)
Task: {94B31A1C-1717-47E7-8279-5EF1FAAF36D7} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\maroš\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [21737944 2023-09-09] (ESET, spol. s r.o. -> ESET)
Task: {BD55BE99-D79E-433A-AC8B-4FB7DB2CB755} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{DA88556A-CB9A-43E2-841B-AB561AD17FE6} => C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe [6638232 2026-05-19] (Google LLC -> Google LLC)
Task: {F88005BB-52BD-47DA-8CA5-D3A23A9E7927} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3995288 2026-05-21] (Google LLC -> Google LLC)
Task: {3F38905C-4B35-4A7E-ADEA-29E0A3C008DD} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_CheckEligible => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3995288 2026-05-21] (Google LLC -> Google LLC)
Task: {838DA93F-A4F0-4072-A5E7-F9231BFFB336} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Metrics => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3995288 2026-05-21] (Google LLC -> Google LLC)
Task: {27ECC8CD-5E96-4574-BFCA-ED74E1B2552B} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28644032 2024-11-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {5515E0A7-3B20-422F-B04E-A0B2559E7665} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28644032 2024-11-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {EE32D1B6-05AC-4772-B303-D271F950D59C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312408 2024-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {ACD82C21-B580-449B-B07E-8D574AC67687} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312408 2024-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AC766A5A-6E9A-4746-A576-D6EE26440E2B} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [187600 2024-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe  (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
Task: {7A003965-A297-4DC6-B15B-852D798391E0} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe  Reboot (No File)
Task: {E28465B1-9792-4B39-859F-9EFC14B29405} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC RebootDialog (No File)
Task: {CFA58C9E-50F1-4DDF-BD8F-A2154F906CF0} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery RebootDialog (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
Task: {EA3F661E-B31C-44A9-B40C-E3D5D56149D4} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display => C:\windows\system32\MusNotification.exe  Display (No File)
Task: {848DCC36-520C-4946-BF68-C7EFFEFA2F84} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot => C:\windows\system32\MusNotification.exe  ReadyToReboot (No File)
Task: {987C5C8F-BA39-4B1A-BFD2-006D40D236E9} - System32\Tasks\Moo0 System Monitor 1.76 => C:\Users\maroš\Downloads\Moo0_SystemMonitor_v1.76_Portable\Moo0 SystemMonitor v1.76 Portable\SystemMonitor64.exe [3507712 2013-10-20] (Moo0) [File not signed]
Task: {90949CD8-B41B-4703-B337-3138E0A34CC6} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3346544 2026-04-24] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5D61151F-54B5-401C-8623-5AA969174F2E} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {99D0F3B0-31FD-448E-BC27-3AA11EAE3D6E} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-836710197-3910017001-3467480500-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {2B6627EB-2003-42F6-90A7-F379FD5A83CC} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-836710197-3910017001-3467480500-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {FA7FC6BB-3794-47BC-8C92-EAD13A2AE2D8} - System32\Tasks\OneDrive Startup Task-S-1-5-21-836710197-3910017001-3467480500-1001 => C:\Program Files\Microsoft OneDrive\26.084.0504.0004_1\OneDriveLauncher.exe [758632 2026-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {7DFB30A7-7126-42EA-BDA8-1835C1B5DF9F} - System32\Tasks\OneDrive Startup Task-S-1-5-21-836710197-3910017001-3467480500-1002 => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveLauncher.exe  /startInstances (No File)
Task: {B3D4E7D5-AED2-41DD-8533-1F9E10B856DE} - System32\Tasks\Opera scheduled assistant Autoupdate 1737984008 => C:\Users\maroš\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe  -> --scheduledtask --productiscomponent --bypasslauncher --installdir="C:\Users\maroš\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {001C2B6B-FB55-48E7-963F-E35F20F9B055} - System32\Tasks\Opera scheduled Autoupdate 1737984004 => C:\Users\maroš\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe  --scheduledtask --bypasslauncher $(Arg0) (No File)
Task: {2F2DE3B6-3F11-4F1D-8061-B88BC95D8E1F} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-836710197-3910017001-3467480500-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5598328 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {E4C7B7DC-9E7B-41C6-991A-35E77F7BCC5C} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-836710197-3910017001-3467480500-1002 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5598328 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {F56AC061-ACD7-4CAA-AEAA-FAFF4E9791DA} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-836710197-3910017001-3467480500-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5598328 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {93D6041D-F356-4A0C-A9FC-6EAA0D6DC848} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6635128 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {B9A92D6D-1813-45A6-8AE8-51125034F4EE} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9274080 2026-01-19] (Gen Digital Inc. -> Gen Digital Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Users\maroš\Downloads\ccPortable\App\CCleaner\x64\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b6a8764b-a5aa-45d3-bffe-07bd8ac255d7}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b6a8764b-a5aa-45d3-bffe-07bd8ac255d7}: [DhcpDomain] home
Tcpip\..\Interfaces\{bb3171d5-9832-464a-81f6-50ddee4798bb}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{bb3171d5-9832-464a-81f6-50ddee4798bb}: [DhcpDomain] home

FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: MnIlUyLy.Profil 1 -> 308046B0AF4A39CB
FF DefaultProfile: ccw9abux.default-release -> 641D10338ABA448D
FF ProfilePath: C:\Users\maroš\AppData\Roaming\Mozilla\Firefox\Profiles\y0tpwlfv.default [2024-01-07]
FF ProfilePath: C:\Users\maroš\AppData\Roaming\Mozilla\Firefox\Profiles\MnIlUyLy.Profil 1 [2026-04-15]
FF Extension: (No Name) - C:\Users\maroš\AppData\Roaming\Mozilla\Firefox\Profiles\MnIlUyLy.Profil 1\Extensions\newtab@mozilla.org.xpi [0] [not signed]
FF Extension: (No Name) - C:\Users\maroš\AppData\Roaming\Mozilla\Firefox\Profiles\MnIlUyLy.Profil 1\Extensions\{cd6791f7-4b6d-47b4-8877-1d4c82c6699d}.xpi [0] [not signed]
FF Plugin: @java.com/DTPlugin,version=11.491.2 -> C:\Program Files\Java\jre1.8.0_491\bin\dtplugin\npDeployJava1.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.491.2 -> C:\Program Files\Java\jre1.8.0_491\bin\plugin2\npjp2.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-01-31] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: ditec.sk/DAsicFac -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~1.DLL [2022-08-15] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/DitecNMc -> C:\PROGRA~2\Ditec\DLAUNC~2\NPDITE~1.DLL [2022-05-06] (DITEC, a.s. -> DITEC, a.s.)
FF Plugin-x32: ditec.sk/DitecZepDViewerFb -> C:\PROGRA~2\Ditec\DViewer\NPDITE~1.DLL [2024-07-19] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigMessageContainer -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~2.DLL [2023-09-19] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesExtender -> C:\PROGRA~2\Ditec\DSIGNE~2.NET\NPDITE~3.DLL [2023-09-19] (DITEC, a.s. -> Ditec, a.s.)
FF Plugin-x32: ditec.sk/DSigXadesFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~1.DLL [2024-07-19] (DITEC, a.s. -> Ditec,a.s.)
FF Plugin-x32: ditec.sk/XmlDataContainerFb -> C:\PROGRA~2\Ditec\DSIGNE~1.NET\NPDITE~2.DLL [2024-07-19] (DITEC, a.s. -> Ditec,a.s.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2026-04-15]

Edge: 
=======
Edge DefaultProfile: Profile 2
Edge Profile: C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Guest Profile [2026-04-14]
Error reading preferences. Please make sure ESET "Secure Browser" option is disabled. <==== ATTENTION
Edge Profile: C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2 [2026-05-27]
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-05-20] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-30] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2026-05-27] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\hmclfiddnlhfnemdelgodbcmhpobomha [2026-04-14] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\jbkfoedolllekgbhcbcoahefnbanhhlh [2026-05-15] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-04-14] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\kgocmibpdgfgpbmckolcpjoegieclgdj [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2026-04-14] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2026-05-12] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\panammoooggmlehahpcjckcncfeffcoi [2026-05-20] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2026-05-14] [UpdateUrl:0] <==== ATTENTION
Edge Profile: C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3 [2026-04-17]
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge Extension: (No Name) - C:\Users\maroš\AppData\Local\Microsoft\Edge\User Data\Profile 3\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2026-04-17] [UpdateUrl:0] <==== ATTENTION
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]

Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default [2026-05-22]
Error reading preferences. Please make sure ESET "Secure Browser" option is disabled. <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-14] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-20] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2026-05-20] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-06-16] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\maroš\AppData\Local\Google\Chrome\User Data\Default\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2025-12-13] [UpdateUrl:0] <==== ATTENTION
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-836710197-3910017001-3467480500-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [oombnmpbbhbakfpfgdflaajkhicgfaam]

Brave: 
=======
BRA Profile: C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2026-02-26]
Error reading preferences. Please make sure ESET "Secure Browser" option is disabled. <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-02-26] [UpdateUrl:0] <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2026-02-26] [UpdateUrl:0] <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\kpiecbcckbofpmkkkdibbllpinceiihk [2026-02-26] [UpdateUrl:0] <==== ATTENTION
BRA Extension: (No Name) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2026-02-26] [UpdateUrl:0] <==== ATTENTION
BRA Extension: (Brave Ad Block Updater (Brave First Party Adblock Filters (plaintext))) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2026-02-26]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2026-02-26]
BRA Extension: (Brave NTP background images) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2026-02-26]
BRA Extension: (Brave Ad Block Updater (Mobile app promo blocker (plaintext))) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2026-02-26]
BRA Extension: (Brave Ad Block Updater (Cookie notice blocker (plaintext))) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2026-02-26]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2026-02-26]
BRA Extension: (Brave Ad Block Updater (Brave Default Adblock Filters (plaintext))) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2026-02-26]
BRA Extension: (Brave Ad Block Updater (Brave Default Privacy Filters (plaintext))) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\kihnoaefogbkmblfimmibknnmkllbhlf [2026-02-26]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2026-02-26]
BRA Extension: (Brave NTP sponsored images) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\mjgplcflbkgklplplbakkopkafojhbmk [2026-02-26]
BRA Extension: (Brave User Agent) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\nlpaeekllejnmhoonlpcefpfnpbajbpe [2026-02-26]
BRA Extension: (Brave Ads Resources) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\obponfmfefkaeehakbehbnnlcbebebhd [2026-02-26]
BRA Extension: (Brave Ad Block Updater (EasyList Czech and Slovak (plaintext))) - C:\Users\maroš\AppData\Local\BraveSoftware\Brave-Browser\User Data\oegebjahecghlckbhkmojgnpcgdeajdi [2026-02-26]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [30293112 2026-05-01] (Gen Digital Inc. -> Gen Digital Inc.)
S4 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13652176 2024-11-09] (Microsoft Corporation -> Microsoft Corporation)
S4 DCAgent; C:\Program Files\EPSON\Epson Data Collection Agent\DCAgent.exe [19728 2025-07-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S4 dLauncherLoopback; C:\Program Files (x86)\Ditec\DLauncher\dLauncherLoopback.exe [154960 2019-08-02] (DITEC, a.s. -> )
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [20539552 2026-04-02] (Electronic Arts, Inc. -> Electronic Arts)
S4 EDUSBAgent; C:\Program Files\EPSON\Epson Device USB Agent\EDUSBAgent.exe [20696 2025-11-26] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5639088 2026-04-10] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [5107712 2026-04-10] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [5107712 2026-04-10] (ESET, spol. s r.o. -> ESET)
S3 EpicGamesUpdater; C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3407800 2026-05-27] (Epic Games Inc. -> Epic Games, Inc.)
R2 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2023-08-02] (Epic Games Inc. -> Epic Games, Inc.)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [222768 2025-03-31] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S4 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.084.0504.0004_1\FileSyncHelper.exe [3611024 2026-05-25] (Microsoft Corporation -> Microsoft Corporation)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpDefenderCoreService.exe [2063376 2025-12-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_01095d3b50bff033\Display.NvContainer\NVDisplay.Container.exe [1702632 2026-05-21] (NVIDIA Corporation -> NVIDIA Corporation)
S4 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.084.0504.0004_1\OneDriveUpdaterService.exe [4018024 2026-05-25] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [811360 2026-02-25] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\NisSrv.exe [4426832 2025-12-30] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe [290704 2025-12-30] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [12257120 2024-02-20] (KRAFTON, Inc. -> KRAFTON, Inc)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACE-BASE; C:\WINDOWS\system32\drivers\ACE-BASE.sys [2198632 2024-07-22] (Microsoft Windows Hardware Compatibility Publisher -> ANTICHEATEXPERT.COM)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2025-01-30] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2025-01-30] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2024-11-22] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_9aec23fc8b7cff7c\e1d.sys [615552 2026-03-02] (Intel Corporation -> Intel Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [235528 2026-04-10] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [140464 2026-04-10] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
R1 edevmonm; C:\WINDOWS\System32\DRIVERS\edevmonm.sys [127072 2026-04-10] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [17840 2025-11-27] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [353856 2026-04-10] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [57928 2026-04-10] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [87328 2026-04-10] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [127584 2026-04-10] (ESET, spol. s r.o. -> ESET)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [226768 2026-05-01] (Microsoft Windows -> Microsoft Corporation)
S3 HoYoProtect; C:\WINDOWS\system32\HoYoKProtect.sys [3901080 2025-06-13] (Microsoft Windows Hardware Compatibility Publisher -> miHoYo)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333192 2025-12-30] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [144856 2026-05-01] (Microsoft Windows -> Microsoft Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [249376 2026-04-18] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [259216 2026-04-18] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxSup; C:\WINDOWS\system32\DRIVERS\VBoxSup.sys [1059760 2026-04-18] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxUSBMon; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [197232 2026-04-18] (Oracle America, Inc. -> Oracle and/or its affiliates)
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2025-05-30] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [21928 2025-12-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [635272 2025-12-30] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102792 2025-12-30] (Microsoft Windows -> Microsoft Corporation)
R3 WinRing0_1_2_0; C:\Users\maroš\Downloads\Moo0_SystemMonitor_v1.76_Portable\Moo0 SystemMonitor v1.76 Portable\WinRing0x64.sys [14544 2008-07-26] (Noriyuki MIYAZAKI -> OpenLibSys.org)
R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2024-11-22] (Microsoft Windows -> Microsoft Corporation)
R3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys [61440 2025-08-30] (Microsoft Windows -> Microsoft Corporation)
S1 netfilter2; system32\drivers\netfilter2.sys (No File)
S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (No File)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-05-27 17:04 - 2026-05-27 17:05 - 000039752 _____ C:\Users\maroš\Desktop\FRST.txt
2026-05-27 16:38 - 2026-05-27 17:05 - 000000000 ____D C:\FRST
2026-05-27 16:36 - 2026-05-27 16:37 - 002449408 _____ (Farbar) C:\Users\maroš\Desktop\FRST64.exe
2026-05-27 16:16 - 2026-05-27 16:16 - 000000000 ____D C:\WINDOWS\LastGood
2026-05-27 16:13 - 2026-05-21 07:41 - 003082800 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2026-05-27 16:13 - 2026-05-21 07:41 - 003082800 _____ C:\WINDOWS\system32\vulkaninfo.exe
2026-05-27 16:13 - 2026-05-21 07:41 - 002626608 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2026-05-27 16:13 - 2026-05-21 07:41 - 002626608 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2026-05-27 16:13 - 2026-05-21 07:41 - 001730096 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2026-05-27 16:13 - 2026-05-21 07:41 - 001730096 _____ C:\WINDOWS\system32\vulkan-1.dll
2026-05-27 16:13 - 2026-05-21 07:41 - 001542192 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2026-05-27 16:13 - 2026-05-21 07:41 - 001542192 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2026-05-27 16:13 - 2026-05-21 07:41 - 000540904 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2026-05-27 16:13 - 2026-05-21 07:41 - 000418024 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2026-05-27 16:13 - 2026-05-21 07:36 - 001408232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2026-05-27 16:13 - 2026-05-21 07:36 - 000676584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2026-05-27 16:13 - 2026-05-21 07:36 - 000510696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2026-05-27 16:13 - 2026-05-21 07:35 - 028094184 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2026-05-27 16:13 - 2026-05-21 07:35 - 002337512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2026-05-27 16:13 - 2026-05-21 07:35 - 001731304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2026-05-27 16:13 - 2026-05-21 07:35 - 001682152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2026-05-27 16:13 - 2026-05-21 07:35 - 001592040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2026-05-27 16:13 - 2026-05-21 07:35 - 001238760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2026-05-27 16:13 - 2026-05-21 07:35 - 001068264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2026-05-27 16:13 - 2026-05-21 07:35 - 000824040 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2026-05-27 16:13 - 2026-05-21 07:34 - 032166632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2026-05-27 16:13 - 2026-05-21 07:34 - 000469736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2026-05-27 16:13 - 2026-05-21 07:33 - 020993768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2026-05-27 16:13 - 2026-05-21 07:33 - 008488168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2026-05-27 16:13 - 2026-05-21 07:33 - 005925608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2026-05-27 16:13 - 2026-05-21 07:33 - 005796072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2026-05-27 16:13 - 2026-05-21 07:33 - 004714728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2026-05-27 16:13 - 2026-05-21 07:32 - 000853736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2026-05-27 16:13 - 2026-05-21 07:31 - 000572368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2026-05-27 16:13 - 2026-05-21 07:31 - 000441368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2026-05-27 16:13 - 2026-05-20 03:53 - 000167381 _____ C:\WINDOWS\system32\nvinfo.pb
2026-05-27 14:06 - 2026-05-27 15:34 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-05-27 14:04 - 2026-05-27 14:06 - 000000000 ___HD C:\$WinREAgent
2026-05-25 18:51 - 2026-05-25 18:51 - 000929040 _____ C:\Users\maroš\Downloads\Cch-sin-Liou_2_Temny-les.epub
2026-05-25 15:43 - 2026-05-25 15:43 - 000076120 _____ C:\WINDOWS\system32\perfh01B.dat
2026-05-25 15:43 - 2026-05-25 15:43 - 000020592 _____ C:\WINDOWS\system32\perfc01B.dat
2026-05-23 14:05 - 2026-05-23 14:05 - 000075460 _____ C:\Users\maroš\Downloads\654 (1).pdf
2026-05-23 14:04 - 2026-05-23 14:04 - 000075460 _____ C:\Users\maroš\Downloads\654.pdf
2026-05-21 19:49 - 2026-05-21 19:49 - 000089442 _____ C:\Users\maroš\Downloads\proofPayment_o-2026138-01.pdf
2026-05-21 16:24 - 2026-05-21 16:29 - 3168891298 _____ C:\Users\maroš\Downloads\Spasitel (2026) UHDRDV cz en.mkv
2026-05-21 16:23 - 2026-05-21 16:23 - 000142999 _____ C:\Users\maroš\Downloads\[SkT]Spasitel___Project_Hail_Mary_(2026)(CZ_EN)[2160p][HDR10_DV][HEVC]_=_CSFD_85%.torrent
2026-05-21 14:50 - 2026-05-21 14:56 - 2149581650 _____ C:\Users\maroš\Downloads\První člověk (2018) UHDR cz en.mkv
2026-05-21 14:48 - 2026-05-21 14:48 - 000123564 _____ C:\Users\maroš\Downloads\[SkT]První_člověk___First_Man_(2018)(CZ_EN)[2160p][HDR10_DV][HEVC]_=_CSFD_76%.torrent
2026-05-21 14:37 - 2026-05-21 14:37 - 000003990 _____ C:\Users\maroš\Downloads\[SkT]Anthony_Riches_-_serie_Rimane_(2011-2016)(CZ).torrent
2026-05-21 14:35 - 2026-05-27 17:06 - 000000000 ____D C:\Users\maroš\AppData\Roaming\utorrent
2026-05-21 14:35 - 2026-05-21 14:35 - 000000896 _____ C:\Users\maroš\Desktop\µTorrent.lnk
2026-05-21 14:35 - 2026-05-21 14:35 - 000000876 _____ C:\Users\maroš\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2026-05-21 14:35 - 2026-05-21 14:35 - 000000000 ____D C:\Users\maroš\AppData\LocalLow\uTorrent.WebView2
2026-05-17 18:35 - 2026-05-17 18:35 - 000002287 _____ C:\Users\maroš\Downloads\Cristiano_Ronaldo_text.pdf
2026-05-17 18:00 - 2026-05-17 18:00 - 000001923 _____ C:\Users\maroš\Downloads\ronaldo_nadpisy.pdf
2026-05-15 18:31 - 2026-05-15 18:31 - 000599131 _____ C:\Users\maroš\Downloads\Prognoza_360256754__13893601.zip
2026-05-15 18:31 - 2026-05-15 18:31 - 000599131 _____ C:\Users\maroš\Downloads\Prognoza_360256754__13893601 (1).zip
2026-05-15 08:54 - 2026-05-15 08:54 - 002401360 _____ C:\Users\maroš\Downloads\ZMYSLY KRUH.pdf
2026-05-15 08:53 - 2026-05-15 08:53 - 005542767 _____ C:\Users\maroš\Downloads\2. PREDIKTABILNÁ KNIHA.pdf
2026-05-14 09:53 - 2026-05-14 09:53 - 000294339 _____ C:\Users\maroš\Downloads\vyplatny_listok_202604.pdf
2026-05-13 18:04 - 2026-05-13 18:04 - 000000432 __RSH C:\ProgramData\ntuser.pol
2026-05-13 13:58 - 2026-05-13 13:58 - 000000000 ____D C:\WINDOWS\SecureBoot
2026-05-13 11:19 - 2026-05-13 11:19 - 000000000 ____D C:\Users\maroš\Downloads\Rufus
2026-05-13 11:09 - 2026-05-13 11:10 - 000000098 _____ C:\Users\maroš\Downloads\rufus.ini
2026-05-13 11:09 - 2026-05-13 11:09 - 002002280 _____ (Akeo Consulting) C:\Users\maroš\Downloads\rufus-4.14p.exe
2026-05-13 11:06 - 2026-05-13 11:07 - 2040528896 _____ C:\Users\maroš\Downloads\tails-amd64-7.7.3 (1).img
2026-05-13 10:36 - 2026-05-13 10:38 - 2040528896 _____ C:\Users\maroš\Downloads\tails-amd64-7.7.3.img
2026-05-09 13:48 - 2026-05-09 13:48 - 000000000 ____D C:\Users\maroš\VirtualBox VMs
2026-05-09 13:44 - 2026-05-09 13:46 - 2224007168 _____ C:\Users\maroš\Downloads\ubuntu-26.04-desktop-amd64.iso
2026-05-09 13:43 - 2026-05-13 14:20 - 000000000 ____D C:\Users\maroš\.VirtualBox
2026-05-09 13:42 - 2026-05-09 13:42 - 000000000 ____D C:\Program Files\Oracle
2026-05-09 13:41 - 2026-05-09 13:41 - 177853032 _____ (Oracle and/or its affiliates) C:\Users\maroš\Downloads\VirtualBox-7.2.8-173730-Win.exe
2026-05-09 13:40 - 2026-05-09 13:40 - 020069022 _____ C:\Users\maroš\Downloads\Oracle_VirtualBox_Extension_Pack-7.2.8.vbox-extpack
2026-05-09 13:17 - 2026-05-09 13:17 - 000000000 ____D C:\Users\maroš\AppData\Local\wsl
2026-05-09 13:04 - 2026-05-13 13:58 - 000000000 ____D C:\Program Files\Hyper-V
2026-05-09 13:04 - 2026-05-09 13:04 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2026-05-08 18:38 - 2026-05-08 18:38 - 000000000 ____D C:\Users\maroš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubuntu
2026-05-08 18:29 - 2026-05-15 11:18 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2026-05-08 18:27 - 2026-05-08 18:27 - 000000000 ____D C:\Program Files\WSL
2026-05-08 10:15 - 2026-05-08 10:15 - 000074411 _____ C:\Users\maroš\Downloads\Cristiano_Ronaldo_A4_Projekt.pdf
2026-05-08 10:15 - 2026-05-08 10:15 - 000004468 _____ C:\Users\maroš\Downloads\Cristiano_Ronaldo_Projekt_Obrazky.pdf
2026-05-07 16:22 - 2026-05-07 16:22 - 000027540 _____ C:\Users\maroš\Downloads\3625338777.pdf
2026-05-07 12:45 - 2025-02-28 15:58 - 001934669 _____ C:\Users\maroš\Downloads\IMG_0303.HEIC
2026-05-07 12:40 - 2025-02-28 15:58 - 002001658 _____ C:\Users\maroš\Downloads\IMG_0302.HEIC
2026-05-02 11:25 - 2026-05-02 11:25 - 018824928 _____ (Piriform Software Ltd) C:\Users\maroš\Downloads\spsetup133.exe
2026-05-02 11:25 - 2026-05-02 11:25 - 000000797 _____ C:\Users\Public\Desktop\Speccy.lnk
2026-05-02 11:25 - 2026-05-02 11:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2026-05-02 11:25 - 2026-05-02 11:25 - 000000000 ____D C:\Program Files\Speccy
2026-05-02 11:21 - 2026-05-02 12:28 - 000000000 ____D C:\Program Files\CPUID
2026-05-02 11:20 - 2026-05-02 11:20 - 004799168 _____ (CPUID, Inc. ) C:\Users\maroš\Downloads\cpu-z_2.19-en.exe
2026-05-01 10:30 - 2026-05-01 10:30 - 003213985 _____ C:\Users\maroš\Downloads\KID SK_20260417_clean-3.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 001869411 _____ C:\Users\maroš\Downloads\3.3. Predzmluvne informacie o nakladoch apoplatkoch_USD_20260314_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 001762118 _____ C:\Users\maroš\Downloads\3.2. Predzmluvne informacie o nakladoch apoplatkoch_EUR_20260314_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 001406944 _____ C:\Users\maroš\Downloads\01. Zakladne informacie o XTB_20260314_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000655328 _____ C:\Users\maroš\Downloads\01. Obchodne podmienky_20260314_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000269343 _____ C:\Users\maroš\Downloads\04. Deklaracia investicneho rizika_20260314_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000224324 _____ C:\Users\maroš\Downloads\10. Doplnujuce informacie_20230720.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000208717 _____ C:\Users\maroš\Downloads\03. Strategia vykonavania pokynov_ 20260105_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000189905 _____ C:\Users\maroš\Downloads\9. Pravidla vseobecnych investicnychodporucani_20251030_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000184871 _____ C:\Users\maroš\Downloads\agreement.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000130383 _____ C:\Users\maroš\Downloads\2022-01-25 Zdanovanie derivatov na uzemi Slovenskejrepubliky.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000126641 _____ C:\Users\maroš\Downloads\07. Investicny dotaznik_200251203_OMI_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000110454 _____ C:\Users\maroš\Downloads\12. AML dotaznik_20240229_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000107479 _____ C:\Users\maroš\Downloads\SK_Systematicky internalizator_20260105_clean.pdf
2026-05-01 10:30 - 2026-05-01 10:30 - 000100406 _____ C:\Users\maroš\Downloads\4. Informacie tykajuce sa konfliktuzaujmov_20260105_clean.pdf
2026-05-01 08:34 - 2026-05-01 08:34 - 000003872 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2026-05-01 08:33 - 2026-05-01 08:33 - 000085913 _____ C:\WINDOWS\SysWOW64\ctac.json
2026-05-01 08:33 - 2026-05-01 08:33 - 000085913 _____ C:\WINDOWS\system32\ctac.json
2026-04-27 16:39 - 2026-04-27 16:39 - 000000000 ___HD C:\OneDriveTemp

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-05-27 16:54 - 2022-11-29 19:38 - 000000000 ____D C:\Program Files (x86)\Steam
2026-05-27 16:43 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-05-27 16:43 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-05-27 16:37 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-05-27 16:37 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-05-27 16:16 - 2026-04-17 12:15 - 000000000 ____D C:\ProgramData\NVIDIA
2026-05-27 16:16 - 2026-04-14 09:41 - 000000000 ____D C:\Users\maroš\AppData\Local\NVIDIA
2026-05-27 16:16 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-05-27 16:12 - 2026-04-17 13:40 - 000003010 _____ C:\WINDOWS\system32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2026-05-27 16:12 - 2026-04-14 09:49 - 000000000 ____D C:\Users\maroš\AppData\Local\NVIDIA Corporation
2026-05-27 16:11 - 2022-11-30 09:02 - 000000000 ____D C:\Users\maroš\AppData\Local\BitTorrentHelper
2026-05-26 14:57 - 2022-12-07 13:45 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2026-05-26 10:30 - 2025-12-14 11:19 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH
2026-05-25 18:55 - 2023-01-08 17:25 - 000000000 ____D C:\Users\maroš\AppData\Roaming\Send Anywhere
2026-05-25 18:48 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ServiceState
2026-05-25 18:34 - 2026-04-13 11:26 - 000002776 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-05-25 18:34 - 2025-02-06 18:08 - 000003124 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-836710197-3910017001-3467480500-1001
2026-05-25 18:34 - 2024-11-22 21:36 - 000003126 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-836710197-3910017001-3467480500-1001
2026-05-25 18:33 - 2026-03-18 16:53 - 000000394 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2026-05-25 18:12 - 2026-04-13 11:25 - 000001983 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-05-25 18:12 - 2026-04-13 11:25 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-05-25 18:08 - 2022-11-29 19:48 - 000000000 ____D C:\ProgramData\Package Cache
2026-05-25 18:07 - 2024-10-23 11:51 - 000002219 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-05-25 18:07 - 2024-10-23 11:51 - 000002178 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-05-25 15:43 - 2024-11-22 21:38 - 000916836 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-05-25 10:26 - 2026-04-17 13:42 - 000000000 ____D C:\Users\maroš\AppData\Local\D3DSCache
2026-05-24 18:28 - 2024-11-22 21:36 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-05-24 18:28 - 2024-11-22 21:34 - 000019710 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-05-24 18:28 - 2022-11-29 18:23 - 000012288 ___SH C:\DumpStack.log.tmp
2026-05-24 17:11 - 2024-04-01 09:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-05-24 09:21 - 2024-11-22 21:36 - 000003542 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2026-05-23 15:26 - 2024-11-22 21:34 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-05-23 12:15 - 2023-01-21 18:52 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-05-23 12:15 - 2020-11-19 01:47 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-05-20 14:19 - 2024-11-22 19:05 - 000000000 ____D C:\Users\maroš
2026-05-13 15:11 - 2022-12-23 07:38 - 000000000 ____D C:\Users\maroš\AppData\Local\CrashDumps
2026-05-13 15:06 - 2025-02-23 15:47 - 000000000 ____D C:\Program Files\dotnet
2026-05-13 14:33 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\lxss
2026-05-13 13:59 - 2024-11-22 21:34 - 000325272 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-05-13 13:58 - 2024-04-01 18:35 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-plocm
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-ploc
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\et-EE
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\am-ET
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-05-13 13:58 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-05-13 12:32 - 2022-11-29 17:19 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-05-13 12:30 - 2022-11-29 17:19 - 220340424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-05-13 10:43 - 2022-11-29 17:07 - 000000000 ___RD C:\Users\maroš\OneDrive
2026-05-13 10:17 - 2024-11-22 21:36 - 003268096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-05-13 09:59 - 2026-04-17 13:40 - 000001390 _____ C:\Users\Public\Desktop\NVIDIA App.lnk
2026-05-13 09:59 - 2022-11-29 18:24 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2026-05-09 14:14 - 2022-11-29 17:05 - 000000000 ____D C:\Users\maroš\AppData\Local\Packages
2026-05-09 13:04 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\schemas
2026-05-09 12:37 - 2022-11-29 21:27 - 000000000 ____D C:\Users\maroš\AppData\Local\PlaceholderTileLogoFolder
2026-05-09 12:37 - 2020-11-19 01:49 - 000000000 ____D C:\ProgramData\Packages
2026-05-08 18:25 - 2024-11-22 19:05 - 000000000 ____D C:\Users\maroš\AppData\Roaming\Microsoft\Windows
2026-05-01 19:13 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2026-05-01 19:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-05-01 19:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-05-01 19:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-05-01 19:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-05-01 19:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-05-01 19:13 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-05-01 19:12 - 2025-06-28 20:45 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-05-01 19:12 - 2024-04-01 18:36 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-05-01 19:12 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-05-01 19:12 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-05-01 18:11 - 2024-11-22 21:36 - 000003630 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-05-01 18:11 - 2024-11-22 21:36 - 000003504 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore

==================== Files in the root of some directories ========

2022-12-05 10:37 - 2022-12-13 19:50 - 000012288 _____ () C:\Users\maroš\AppData\Roaming\emp.bin
2023-06-17 17:03 - 2024-01-05 16:16 - 000007597 _____ () C:\Users\maroš\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================