
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Microsoft Edge a filtrované webové stránky v Eset
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Microsoft Edge a filtrované webové stránky v Eset
Zdravím, mám Windows 11 Home a antivir Eset Internet security. Když otevřu např. Historii prohlížených stránek či klepnu na tlačítko Další oblíbené položky v prohl. Edge, tak v antiviru v Protokolech filtrované webové stránky se objevuje viz. obr.
Dělal jsem kontrolu antivirem, MBAM a nic nenašly. Ve Firefoxu to nedělá.
Jak se toho zbavit ?
Děkuji za rady.
Dělal jsem kontrolu antivirem, MBAM a nic nenašly. Ve Firefoxu to nedělá.
Jak se toho zbavit ?
Děkuji za rady.
- Přílohy
-
- Snímek obrazovky 2026-04-22 204913.png (240.34 KiB) Zobrazeno 177 x
Re: Microsoft Edge a filtrované webové stránky v Eset
Ještě přikládám logy z FRST :
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-04-2026
Ran by david (administrator) on DESKTOP-IJSLQ8R (Micro-Star International Co., Ltd MS-7B86) (22-04-2026 20:31:56)
Running from C:\Users\david\Desktop\FRST64.exe
Loaded Profiles: david
Platform: Microsoft Windows 11 Home Version 25H2 26200.8246 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eServiceHost.exe <2>
(C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe ->) (SteelSeries France SASU -> A-Volute) C:\Users\david\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\dlls\wgc_renderer_host.exe <5>
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming.net Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wargamingerrormonitor.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wgc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncHelper.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0b6ff136fecebab7\RtkAudUService64.exe <2>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicService.exe
(svchost.exe ->) (21E1B422-257A-44A2-9C8F-379165856473 -> ) C:\Program Files\WindowsApps\A-Volute.Nahimic_1.10.9.0_x64__w2gh52qy24etm\Nahimic3.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.248.3.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
(svchost.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicSvc64.exe
(svchost.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\SysWOW64\NahimicSvc32.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0b6ff136fecebab7\RtkAudUService64.exe [1650016 2023-03-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285616 2026-04-07] (ESET, spol. s r.o. -> ESET)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4746600 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2589432 2026-03-26] (Wargaming Group Limited -> Wargaming.net)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [Proton VPN] => C:\Program Files\Proton\VPN\ProtonVPN.Launcher.exe [18781032 2025-11-28] (Proton AG -> ProtonVPN)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [MicrosoftCopilotAutoLaunch_175BE63C8904AE189174B074A7B4DA61] => C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe [4582440 2026-04-16] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1002\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4746600 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\Canon TS3300 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDG3.DLL [506368 2023-06-05] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS3300 series: C:\Windows\system32\CNMLMG3.DLL [1334784 2023-06-05] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {45C4F61A-1C24-4A35-A626-A5CD8767EEAD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {20CC335E-A06F-4DDD-BB58-EDF4BBA788C9} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [11419480 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {491BDBB5-5DCD-4416-A3B4-B71FE776493F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {872A580E-273F-476E-BFBC-C15AE694BABC} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\opushutil.exe [61280 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {A48ED4ED-CA7A-4991-9515-C1530E9D56EB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {94E92F3A-59C3-4B3E-AC29-89CE4609F31C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {71FBAE62-6500-42E4-B4EB-8451C8A68866} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B1AADECF-5E91-4F9C-BB81-D3D5972710CF} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2920095854-1669752291-3635278505-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705664 2026-04-21] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {CA13F34A-2E69-4611-873D-BCAFB4B801BF} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2920095854-1669752291-3635278505-1002 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705664 2026-04-21] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {67B73CDE-D8EC-43A1-BA0E-2E4BCCB6FEE7} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-04-21] (Mozilla Corporation -> Mozilla Foundation)
Task: {653DA56B-3946-43B8-8423-1C6A61DC2AEF} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [1118128 2025-01-14] (SteelSeries France SASU -> Nahimic)
Task: {D59DBDC6-EC3D-4181-BC12-4C81E0D0A90C} - System32\Tasks\NahimicSvc64Run => C:\Windows\system32\NahimicSvc64.exe [1438128 2025-01-14] (SteelSeries France SASU -> Nahimic)
Task: {F33D2010-466A-4540-885E-72B1B45DD93F} - System32\Tasks\NahimicTask32 => C:\Windows\System32\..\SysWOW64\NahimicSvc32.exe [1118128 0] (SteelSeries France SASU -> Nahimic)
Task: {7372F1AE-EAB8-4BF9-BBE6-9353BE9CAF71} - System32\Tasks\NahimicTask64 => C:\Windows\System32\.\NahimicSvc64.exe [1438128 0] (SteelSeries France SASU -> Nahimic)
Task: {CF859144-76F1-4A6C-A6F6-4D26F82D8382} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {0C642580-5160-4C97-8B9B-F25FCAE3A971} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {786121F6-529F-43B5-9307-AFCE5036EF9B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {2ACBAE90-3CBA-46D8-8AA6-DC21E9653A5E} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1001 => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveLauncher.exe [756584 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {96BD36BE-0E0A-4C02-8ECE-B629D29F6993} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1002 => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveLauncher.exe [756584 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{597a1605-d190-4301-8c5e-d20e46aa83ab}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: e4rv2yyu.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\loa9ywao.default [2025-06-10]
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release [2026-04-22]
FF Homepage: Mozilla\Firefox\Profiles\e4rv2yyu.default-release -> www.seznam.cz
FF Extension: (ESET Browser Privacy & Security) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\browserextension@eset.com.xpi [2025-11-17]
FF Extension: (New Tab) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\newtab@mozilla.org.xpi [2026-04-01]
FF Extension: (Google Translator for Firefox) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\translator@zoli.bod.xpi [2025-05-29]
FF Extension: (Lion Power) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\{7044fa00-e6bb-40d6-88a2-e087ac3f53e6}.xpi [2025-05-29]
FF Extension: (Firefox B) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\{ac40163c-8804-4dad-90fc-e25ebd6e9a57}.xpi [2025-05-29]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2026-04-12] (Adobe Inc. -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2026-04-22]
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default [2026-04-22]
Edge HomePage: Default -> hxxp://www.seznam.cz/
Edge StartupUrls: Default -> "hxxps://www.seznam.cz/"
Edge Extension: (Dokumenty Google offline) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-21]
Edge Extension: (Edge relevant text changes) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-03-29]
Edge Extension: (ESET Browser Privacy & Security) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2026-03-29]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]
Chrome:
=======
CHR HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13288288 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5639088 2026-04-07] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [5107712 2026-04-07] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [5107712 2026-04-07] (ESET, spol. s r.o. -> ESET)
R3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncHelper.exe [3601256 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460488 2024-04-03] (Canon Inc. -> )
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11481048 2026-04-22] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-04-22] (Malwarebytes Inc. -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe [2088128 2026-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 MicrosoftCopilotElevationService; C:\Program Files (x86)\Microsoft\Copilot\Application\147.0.3912.72\elevation_service.exe [3602512 2026-04-16] (Microsoft Corporation -> Microsoft Corporation)
R2 NahimicService; C:\Windows\System32\NahimicService.exe [1910704 2025-01-14] (SteelSeries France SASU -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\Display.NvContainer\NVDisplay.Container.exe [1702632 2026-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveUpdaterService.exe [4002704 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
S3 ProtonVPN Service; C:\Program Files\Proton\VPN\v4.3.9\ProtonVPNService.exe [477424 2025-11-28] (Proton AG -> ProtonVPN)
S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.WireGuardService.exe [476912 2025-11-28] (Proton AG -> ProtonVPN)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2024-10-18] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [933432 2024-10-18] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe [4451664 2026-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe [290704 2026-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [33592 2024-09-12] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [602112 2025-09-10] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [204800 2025-09-10] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [175824 2024-10-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [235528 2026-04-07] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [140464 2026-04-07] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [17840 2025-11-28] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [353856 2026-04-07] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [57928 2026-04-07] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [87328 2026-04-07] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [127584 2026-04-07] (ESET, spol. s r.o. -> ESET)
S3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82352 2026-02-14] (Microsoft Windows -> Microsoft Corporation)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-04-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [245864 2026-04-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 Nahimic_Mirroring; C:\Windows\System32\drivers\Nahimic_Mirroring.sys [94784 2022-06-02] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v4.3.9\Resources\ProtonVPN.CalloutDriver.sys [41416 2025-11-20] (Proton AG -> Proton AG)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174264 2024-10-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [21888 2026-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [641416 2026-03-27] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [103816 2026-03-27] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\Windows\System32\drivers\wintun.sys [29592 2025-08-30] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2025-08-28] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-04-22 20:31 - 2026-04-22 20:32 - 000022025 _____ C:\Users\david\Desktop\FRST.txt
2026-04-22 20:30 - 2026-04-22 20:32 - 000000000 ____D C:\FRST
2026-04-22 20:28 - 2026-04-22 20:28 - 002447360 _____ (Farbar) C:\Users\david\Desktop\FRST64.exe
2026-04-22 20:14 - 2026-04-22 20:14 - 000001241 _____ C:\Users\david\Downloads\Malwarebytes Threat Scan Report 2026-04-22 200142.txt
2026-04-22 19:54 - 2026-04-22 20:14 - 000000000 ____D C:\Users\david\AppData\Local\Malwarebytes
2026-04-22 19:54 - 2026-04-22 19:54 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-04-22 19:54 - 2026-04-22 19:54 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-04-22 19:54 - 2026-04-22 19:54 - 000000000 ____D C:\Users\david\AppData\Local\Sentry
2026-04-22 19:53 - 2026-04-22 19:53 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-04-22 19:53 - 2026-04-22 19:53 - 000000000 ____D C:\Program Files\Malwarebytes
2026-04-22 19:47 - 2026-04-22 19:47 - 002849080 _____ (Malwarebytes) C:\Users\david\Downloads\MBSetup.exe
2026-04-22 18:22 - 2026-04-22 18:22 - 000677108 _____ C:\Windows\system32\perfh005.dat
2026-04-22 18:22 - 2026-04-22 18:22 - 000144960 _____ C:\Windows\system32\perfc005.dat
2026-04-21 21:39 - 2026-04-22 14:48 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-04-21 14:21 - 2026-04-21 14:21 - 000037020 _____ C:\Users\david\Downloads\Cenové srovnání.pdf
2026-04-21 09:35 - 2026-04-21 09:35 - 002969948 _____ C:\Users\david\Downloads\El. sekačka.pdf
2026-04-18 15:47 - 2026-04-22 20:15 - 000000000 ____D C:\Windows\CbsTemp
2026-04-14 19:15 - 2026-04-14 19:15 - 000036843 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-04-14 19:15 - 2026-04-14 19:15 - 000036843 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriUHMImageList
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriLMImageList
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriImageList
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriHMImageList
2026-04-13 15:52 - 2026-04-13 16:37 - 000000000 ____D C:\ESD
2026-04-13 15:50 - 2026-04-13 15:50 - 000000000 ___HD C:\$Windows.~WS
2026-04-13 15:50 - 2026-04-13 15:50 - 000000000 ____D C:\$WINDOWS.~BT
2026-03-29 21:33 - 2026-03-29 21:33 - 000000000 ____D C:\Program Files\AMD
2026-03-29 20:18 - 2026-03-29 22:25 - 000000000 ____D C:\Users\david\AppData\Roaming\AMD
2026-03-27 18:45 - 2026-04-12 17:02 - 000000000 ____D C:\Windows\system32\Tasks\SoftLanding
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-04-22 20:31 - 2025-05-29 15:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-04-22 20:14 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-04-22 20:05 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SystemTemp
2026-04-22 19:54 - 2024-04-01 09:26 - 000000000 ___HD C:\Windows\ELAMBKUP
2026-04-22 19:54 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-04-22 19:54 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\AppReadiness
2026-04-22 19:54 - 2024-04-01 09:24 - 000000000 ____D C:\Windows\INF
2026-04-22 18:22 - 2025-05-29 13:41 - 001603790 _____ C:\Windows\system32\PerfStringBackup.INI
2026-04-22 18:16 - 2025-05-29 13:50 - 000000000 ___RD C:\Users\david\OneDrive
2026-04-22 18:15 - 2025-06-24 20:01 - 000003108 _____ C:\Windows\system32\Tasks\NahimicTask32
2026-04-22 18:15 - 2025-06-24 20:01 - 000003088 _____ C:\Windows\system32\Tasks\NahimicTask64
2026-04-22 18:15 - 2025-05-29 14:01 - 000000000 ____D C:\ProgramData\NVIDIA
2026-04-22 18:15 - 2025-05-29 13:32 - 000084096 _____ C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-04-22 18:15 - 2025-05-29 13:32 - 000012288 ___SH C:\DumpStack.log.tmp
2026-04-22 18:15 - 2025-05-29 13:32 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-04-22 18:15 - 2024-04-01 09:21 - 000524288 _____ C:\Windows\system32\config\BBI
2026-04-22 14:48 - 2025-05-29 15:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-04-22 14:31 - 2025-05-29 13:32 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-04-22 10:08 - 2025-06-13 13:55 - 000004212 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{29C9C97D-9D0C-4060-AB82-367C056F9AC0}
2026-04-22 09:34 - 2025-05-29 15:56 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-04-21 21:39 - 2025-12-10 09:34 - 000392320 _____ (Mozilla Foundation) C:\Users\david\Desktop\Firefox.exe
2026-04-21 14:17 - 2025-05-31 18:02 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-04-21 09:35 - 2025-07-26 08:40 - 000003552 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1002
2026-04-21 09:35 - 2025-07-21 21:42 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1002
2026-04-21 09:35 - 2025-05-31 18:02 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1001
2026-04-21 09:35 - 2025-05-31 18:02 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-04-21 09:35 - 2025-05-31 18:02 - 000002023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-04-21 09:35 - 2025-05-29 13:51 - 000003552 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1001
2026-04-19 19:18 - 2025-10-19 20:12 - 000000000 ____D C:\Program Files\CrystalDiskInfo
2026-04-19 14:46 - 2025-05-29 13:47 - 000000000 ____D C:\Users\david\AppData\Local\D3DSCache
2026-04-18 19:34 - 2025-05-29 13:32 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-04-18 19:34 - 2025-05-29 13:32 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-04-17 20:23 - 2025-05-29 14:11 - 000000000 ____D C:\Program Files (x86)\AMD
2026-04-17 19:53 - 2025-10-15 18:35 - 000001607 _____ C:\Windows\system32\config\VSMIDK
2026-04-17 19:51 - 2025-05-29 18:40 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2026-04-15 17:22 - 2025-11-25 15:43 - 000000000 ____D C:\Users\david\AppData\Local\DWriteCore
2026-04-15 17:12 - 2025-11-19 23:29 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2026-04-15 17:12 - 2025-11-19 23:29 - 000002124 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2026-04-14 19:42 - 2025-05-29 13:46 - 000000000 ____D C:\Users\david\AppData\Local\Packages
2026-04-14 19:39 - 2025-05-29 13:32 - 000344016 _____ C:\Windows\system32\FNTCACHE.DAT
2026-04-14 19:38 - 2025-07-08 22:15 - 000000000 ____D C:\Windows\system32\ruxim
2026-04-14 19:38 - 2024-04-01 18:30 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2026-04-14 19:38 - 2024-04-01 18:28 - 000000000 ____D C:\Windows\SysWOW64\cs
2026-04-14 19:38 - 2024-04-01 18:28 - 000000000 ____D C:\Windows\system32\cs
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ___SD C:\Windows\SysWOW64\F12
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ___SD C:\Windows\system32\F12
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\vi-VN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ur-PK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ug-CN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\tt-RU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\te-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ta-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\sq-AL
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\quz-PE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\qps-plocm
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\qps-ploc
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\pa-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\or-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\oobe
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\nn-NO
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ne-NP
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mt-MT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mr-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ml-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mk-MK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mi-NZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lo-LA
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lb-LU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\kok-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\kn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\km-KH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\kk-KZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ka-GE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\is-IS
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\InstallShield
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\id-ID
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\hy-AM
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\hi-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\gu-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\gl-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\gd-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ga-IE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\fil-PH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\fa-IR
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\eu-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\Dism
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\cy-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ca-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\bn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\be-BY
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\as-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\am-ET
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\af-ZA
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SystemResources
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinMetadata
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\vi-VN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ur-PK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ug-CN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\tt-RU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\te-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ta-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\sq-AL
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ShellExperiences
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\setup
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\quz-PE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\qps-plocm
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\qps-ploc
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\pa-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\or-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\oobe
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\nn-NO
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ne-NP
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mt-MT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mr-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ml-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mk-MK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mi-NZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\migwiz
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lv-LV
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lt-LT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lo-LA
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lb-LU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\kok-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\kn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\km-KH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\kk-KZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ka-GE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\is-IS
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\id-ID
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\hy-AM
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\hi-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\gu-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\gl-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\gd-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ga-IE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\fil-PH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\fa-IR
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\eu-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\et-EE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\es-MX
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\Dism
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\cy-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ca-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\bn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\be-BY
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\as-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\appraiser
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\am-ET
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\af-ZA
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellExperiences
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellComponents
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\Provisioning
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\DiagTrack
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\BrowserCore
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\bcastdvr
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-04-14 19:37 - 2024-04-01 09:21 - 000000000 ____D C:\Windows\servicing
2026-04-14 19:26 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2026-04-14 19:26 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2026-04-14 19:14 - 2025-05-29 13:34 - 003268096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2026-04-14 19:06 - 2025-05-29 14:32 - 000000000 ____D C:\Windows\system32\MRT
2026-04-14 19:05 - 2025-05-29 14:32 - 218249592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-04-13 16:37 - 2025-05-29 14:31 - 000000000 ____D C:\Windows\Panther
2026-04-12 19:14 - 2025-06-01 10:42 - 000000000 ____D C:\Users\david\AppData\Local\CrashDumps
2026-04-12 19:05 - 2025-05-29 14:02 - 000000000 ____D C:\MSI
2026-04-12 19:05 - 2025-05-29 14:01 - 000000000 ____D C:\Program Files (x86)\MSI
2026-04-12 18:58 - 2025-05-29 14:02 - 000000000 ____D C:\Users\david\AppData\Local\Downloaded Installations
2026-04-12 18:56 - 2025-05-29 13:45 - 000000000 ____D C:\Users\david\AppData\Local\PlaceholderTileLogoFolder
2026-04-12 17:03 - 2025-07-21 21:40 - 000000000 ____D C:\Users\David Šplíchal\AppData\Local\Packages
2026-04-10 12:00 - 2025-05-29 20:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingston SSD Manager x64
2026-04-10 12:00 - 2025-05-29 20:55 - 000000000 ____D C:\Program Files\Kingston_SSD_Manager
2026-04-10 09:48 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\SecurityHealth
2026-04-09 20:27 - 2025-05-29 13:32 - 000003714 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{01B088DA-A62B-4A48-BD8A-07CB154CA3F6}
2026-04-09 20:27 - 2025-05-29 13:32 - 000003588 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{6CF29DA0-3906-413B-B017-6557F6DCB4DD}
2026-04-07 18:45 - 2025-04-28 13:48 - 000353856 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000235528 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000140464 _____ (ESET) C:\Windows\system32\Drivers\edevmon.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000127584 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000087328 _____ (ESET) C:\Windows\system32\Drivers\epfw.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000057928 _____ (ESET) C:\Windows\system32\Drivers\ekbdflt.sys
2026-04-05 18:23 - 2025-05-29 14:05 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2026-04-05 18:23 - 2025-05-29 14:01 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2026-04-02 12:00 - 2025-05-31 17:20 - 000000000 ____D C:\Users\david\AppData\Roaming\Microsoft\Excel
2026-04-01 20:52 - 2025-06-07 15:10 - 000000000 ____D C:\Users\david\AppData\Local\NVIDIA
2026-04-01 20:41 - 2025-05-31 21:43 - 000000000 ____D C:\ProgramData\CanonIJPLM
2026-03-29 22:26 - 2025-05-29 13:40 - 000000000 ____D C:\Users\david
2026-03-29 22:25 - 2025-07-21 21:40 - 000000000 ____D C:\Users\David Šplíchal
2026-03-29 22:12 - 2025-06-24 19:57 - 000000000 ____D C:\ProgramData\A-Volute
2026-03-29 22:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\registration
2026-03-29 21:32 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps.tmp
2026-03-29 20:18 - 2025-05-29 14:11 - 000000000 ____D C:\AMD
2026-03-27 20:14 - 2025-05-29 13:32 - 000000000 ____D C:\Windows\system32\Drivers\wd
2026-03-26 15:36 - 2025-05-29 13:34 - 000000000 ____D C:\ProgramData\Packages
==================== Files in the root of some directories ========
2025-05-31 09:35 - 2025-10-04 18:13 - 000007653 _____ () C:\Users\david\AppData\Local\Resmon.ResmonCfg
2025-06-01 10:42 - 2025-06-01 10:42 - 000000036 _____ () C:\Users\david\AppData\Local\_LOCAL_GUID
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-04-2026
Ran by david (22-04-2026 20:33:16)
Running from C:\Users\david\Desktop
Microsoft Windows 11 Home Version 25H2 26200.8246 (X64) (2025-05-29 11:34:17)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2920095854-1669752291-3635278505-500 - Administrators - Disabled)
david (S-1-5-21-2920095854-1669752291-3635278505-1001 - Administrators - Enabled) => C:\Users\david
David Šplíchal (S-1-5-21-2920095854-1669752291-3635278505-1002 - Limited - Enabled) => C:\Users\David Šplíchal
DefaultAccount (S-1-5-21-2920095854-1669752291-3635278505-503 - Limited - Disabled)
Guest (S-1-5-21-2920095854-1669752291-3635278505-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2920095854-1669752291-3635278505-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Malwarebytes (Disabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 26.00 (x64) (HKLM\...\7-Zip) (Version: 26.00 - Igor Pavlov)
Adobe Acrobat Reader - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 26.001.21431 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.78.1094 - AB Team, d.o.o.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.90.3.36 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.5.5.3 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.6.0 - Canon Inc.)
Canon TS3300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS3300_series) (Version: 1.04 - Canon Inc.)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 147.0.3912.72 - Microsoft Corporation)
CrystalDiskInfo 9.7.2 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.7.2 - Crystal Dew World)
ESET Security (HKLM\...\{0F3CB7F7-E580-4E9D-BC90-58BF9A860742}) (Version: 19.1.12.0 - ESET, spol. s r.o.)
IrfanView 4.70 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.70 - Irfan Skiljan)
Kingston SSD Manager x64 1.5.6.5 (HKLM-x32\...\{53F657CD-C4FC-4DCD-826E-6862917532AC}_is1) (Version: 1.5.6.5 - @2021 Kingston Digital, Inc.)
Malwarebytes version 5.5.4.252 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.5.4.252 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 147.0.3912.72 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 147.0.3912.72 - Microsoft Corporation) Hidden
Microsoft Office 2019 pro studenty a domácnosti - cs-cz (HKLM\...\HomeStudent2019Retail - cs-cz) (Version: 16.0.19127.20302 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.055.0323.0004 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.50.35719 (HKLM\...\{AECD4ED0-8A3B-41E9-92D1-6BEE0374CCAF}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.50.35719 (HKLM\...\{61B44572-8722-4DAF-8ACF-8E742D30BCC5}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (HKLM-x32\...\{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (HKLM-x32\...\{73F77E4E-5A17-46E5-A5FC-8A061047725F}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 (HKLM-x32\...\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}) (Version: 14.50.35719.0 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox) (Version: 150.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 139.0 - Mozilla)
NVIDIA Ovladač HD audia 1.4.5.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.7 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 595.79 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 595.79 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
NVIDIA USBC Driver 1.52.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.52.831.832 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20302 - Microsoft Corporation) Hidden
Proton VPN (HKLM\...\Proton VPN_is1) (Version: 4.3.9 - Proton AG)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9492.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.74.1128.2024 - Realtek)
Registrace tiskárny (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.2 - Canon Inc.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.9.0.0 - Samsung Electronics Co., Ltd.)
Smart Switch Service (HKLM\...\{7B46CD5E-C3FF-4CB4-A569-425C545A9992}) (Version: 5.0.40.0 - Samsung Electronics Co., Ltd.)
Wargaming.net Game Center (HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Wargaming.net Game Center) (Version: 26.1.1.2050 - Wargaming.net)
World of Tanks EU (HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\2314027414) (Version: - Wargaming.net)
Packages:
=========
Adobe Acrobat Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Assets [2026-04-15] ()
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2026-04-15] (Sparse Package)
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2026-04-22] ()
Nahimic -> C:\Program Files\WindowsApps\A-Volute.Nahimic_1.10.9.0_x64__w2gh52qy24etm [2026-03-29] (A-Volute)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2026-03-29] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2026-03-29] (Realtek Semiconductor Corp)
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0 [2026-04-17] (Spotify AB) [Startup Task]
WinAppRuntime.Main.1.8 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.8_8000.806.2252.0_x64__8wekyb3d8bbwe [2026-04-14] (Microsoft Corp.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{04271989-C4D2-1C86-3D53-F2AC04DA8ED5} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{50726f74-6f6e-2e56-504e-000000000000}\localserver32 -> C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.Client.exe (Proton AG -> ProtonVPN)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> C:\Program Files\ESET\ESET Security\egui.exe (ESET, spol. s r.o. -> ESET)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{80172dde-4e20-4df0-81a2-0a48553e80bb}\localserver32 -> C:\Users\david\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe (SteelSeries France SASU -> A-Volute)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Acrobat Elements\ContextMenuShim64.dll [2026-02-17] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-04-07] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-04-07] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-04-22] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\nvshext.dll [2026-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-04-07] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-04-22] (Malwarebytes Inc -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [MidisrvTransferComplete] => 1
HKLM\...\Drivers32: [midi1] => C:\Windows\system32\wdmaud2.drv [143360 2026-04-14] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Drivers32: [midi1] => C:\Windows\SysWOW64\wdmaud2.drv [94720 2026-04-14] (Microsoft Windows -> Microsoft Corporation)
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2026-02-17 21:28 - 2026-02-12 12:00 - 000101888 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2025-05-31 17:11 - 2025-05-31 17:11 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll
2025-05-31 17:11 - 2025-05-31 17:11 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{75416E63-5912-4DFA-AE8F-3EFACCAFFB14} => ""="NvmeDisk"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSVC => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{75416E63-5912-4DFA-AE8F-3EFACCAFFB14} => ""="NvmeDisk"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2920095854-1669752291-3635278505-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_3.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "Proton VPN"
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "MicrosoftCopilotAutoLaunch_175BE63C8904AE189174B074A7B4DA61"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C01BF982-ED25-431B-A17D-4F081C2CF53F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F3217FB1-4FE7-4BE6-A23C-46874AB49F1B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{3FBD7C0E-E02F-4F8D-9948-BF2CD309DEA2}] => (Allow) LPort=33683
FirewallRules: [{9BF204D4-EE01-4A59-B32A-BB21FBDF042A}] => (Allow) LPort=26822
FirewallRules: [{B57999FB-3805-4B5B-9701-F09319F78EE2}] => (Allow) LPort=32683
FirewallRules: [{FD04402E-EE1B-4BED-B9ED-533502FE4328}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{91181B29-7AAC-401E-A451-61E40CD985E1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{7D2BCDF4-B21B-4B70-BE3F-DC67C850F479}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1FA5623F-2B8D-4580-90C9-07E17B053AAF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{32D31573-79F2-491A-A5E6-28B36737B41B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{08832137-620A-49B1-866A-494E11DCB89C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6FA1AF59-CC56-4973-8F00-8D72A2D8BC25}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{9C10F45A-FAF8-4F91-B5EB-1189FC787A3C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{4A44EEF3-79FF-4369-A851-303024340D25}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1CFAAFA9-30D3-404A-84E0-40534D14347B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{5E4E4465-DCE3-4CD4-95FF-16D6D57EAE21}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2AD4D90A-2349-475E-8505-C554BF3FFC9E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{74CA33A0-9C1B-40BB-B20D-F329432065EC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{33449615-0783-4098-A9D8-FCA21DE1E78F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
==================== Restore Points =========================
21-04-2026 16:16:06 Windows Update
21-04-2026 16:16:13 Windows Update
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (04/22/2026 07:08:39 PM) (Source: Microsoft Security Client) (EventID: 3002) (User: )
Description: Event-ID 3002
Error: (04/22/2026 07:08:39 PM) (Source: Microsoft Security Client) (EventID: 2002) (User: )
Description: Event-ID 2002
Error: (04/22/2026 07:08:39 PM) (Source: Microsoft Security Client) (EventID: 2003) (User: )
Description: Event-ID 2003
Error: (04/22/2026 06:15:54 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-IJSLQ8R$ přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 22 Apr 2026 16:15:53 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 0995427e-e449-4170-83cd-f76dcccca1d8
Metoda: GET(672ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (04/22/2026 06:15:53 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro Místní systém přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 22 Apr 2026 16:15:52 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 5c48a3f3-158a-44fe-ac56-7056528820f0
Metoda: GET(515ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (04/22/2026 02:48:39 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem Nezdařila se fáze obnovení..
Kontext: aplikace , katalog SystemIndex
Podrobnosti:
0x%08x (0x80040d23 - Vypínání indexovacího modulu (HRESULT : 0x80040d23))
Error: (04/22/2026 02:48:39 PM) (Source: Windows Search Service) (EventID: 3602) (User: )
Description: Ve fázi obnovování služby Windows Search došlo k chybě s ID 1. Restartujte službu. Pokud tato chyba potrvá, vytvořte index znovu.
Kontext: aplikace , katalog SystemIndex
Podrobnosti:
0x%08x (0x80040d23 - Vypínání indexovacího modulu (HRESULT : 0x80040d23))
Error: (04/22/2026 02:48:18 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-IJSLQ8R$ přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 22 Apr 2026 12:48:18 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: edf1aa7e-6e98-41b8-928a-dc84087d4f79
Metoda: GET(453ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
System errors:
=============
Error: (04/22/2026 06:17:42 PM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3502) (User: NT AUTHORITY)
Description: Zrušení přidružení zařízení (zrušení párování) se nezdařilo.
Error: (04/22/2026 06:17:12 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1023) (User: NT AUTHORITY)
Description: Tabulka zásad překladu IP adres byla poškozena. Překlad názvů DNS bude dále selhávat, dokud nebude tabulka opravena. Další informace: Čtení tabulky zásad pro pravidlo {3544EC45-B1D8-4C51-81BB-F0F27E9ECE06} se nepodařilo s chybou 87.
Error: (04/22/2026 06:15:34 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 124) (User: NT AUTHORITY)
Description: 03225747456
Error: (04/22/2026 06:15:34 PM) (Source: Microsoft-Windows-Hyper-V-Hypervisor) (EventID: 42) (User: NT AUTHORITY)
Description: Spuštění hypervisoru se nepovedlo. SVM není k dispozici nebo není povolené v systému BIOS.
Error: (04/22/2026 06:15:13 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (04/22/2026 06:15:13 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (04/22/2026 05:10:19 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1023) (User: NT AUTHORITY)
Description: Tabulka zásad překladu IP adres byla poškozena. Překlad názvů DNS bude dále selhávat, dokud nebude tabulka opravena. Další informace: Čtení tabulky zásad pro pravidlo {3C08B176-1D75-4994-94BB-F66514ACACF1} se nepodařilo s chybou 87.
Error: (04/22/2026 02:50:14 PM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3502) (User: NT AUTHORITY)
Description: Zrušení přidružení zařízení (zrušení párování) se nezdařilo.
Windows Defender:
================
Date: 2026-03-27 19:24:48
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{957E782B-0118-4C94-9DED-115799419C34}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŚċħеďŭľĕđ şçдη щαś śκīφρēđ ьéčаüŝě τħé ľãšт śúсçэѕśƒüℓ ŝċдņ ώãѕ ẅїтђίʼn ŧĥè ℓαѕт 7 ðãуś
Date: 2026-02-14 12:26:25
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{6F1BFD8A-47F1-475F-98F7-9F272DF62BBE}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŞĉђěδυŀзď şсåл ẃãŝ śкϊрρеđ ъè¢àϋšє тнè ŀаѕť ŝų¢сзŝšƒυĺ ѕçâń ωàş ώіτђĭʼn τђэ ľăŝŧ 7 đаўś
Date: 2026-01-04 12:11:29
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{AE9E3AFF-F184-4327-999F-F28AB9272554}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŞĉĥеδũĺέđ şĉāⁿ ŵāѕ ŝĸïφрёď вëčάùśε ŧĥе ℓдśт ŝůĉčęśśƒűł ѕčåñ щāś ώϊţђĭи ŧĥě ℓàŝт 7 ďàŷѕ
Date: 2026-01-04 11:33:11
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{FEA37172-9D1D-4668-8816-09B18C49BB21}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вÚplné prohledávání%л %ŧŨśęѓ:%ъDESKTOP-IJSLQ8R\david%ń %τŠτõρ Ŗėаѕǿп:%ьŲŋκйòщп
Date: 2026-01-04 11:32:35
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{04F1B824-E32A-4886-BE57-754AF36BA760}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŜ¢ĥзδůŀėď ѕčаň ẃªś ѕκϊφρзđ ъε¢άύśé тнė ļǻşт šџ¢čзššƒцľ śĉåή ώãŝ щīŧнĩň τћė ľάŝŧ 7 đªγś
Event[0]
Date: 2025-06-18 12:02:35
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-06-18 08:52:07
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-06-07 20:05:52
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-05-29 18:40:46
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
CodeIntegrity:
===============
Date: 2026-04-22 20:14:43
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.
Date: 2026-04-22 20:10:09
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends International, LLC. H.O0 09/01/2025
Motherboard: Micro-Star International Co., Ltd B450 GAMING PLUS MAX (MS-7B86)
Processor: AMD Ryzen 5 2600 Six-Core Processor
Percentage of memory in use: 32%
Total physical RAM: 16309.56 MB
Available physical RAM: 10971.45 MB
Total Virtual: 17333.56 MB
Available Virtual: 11192.9 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:299.17 GB) (Free:100.28 GB) (Model: KINGSTON SNV3S1000G) NTFS
Drive d: () (Fixed) (Total:631.51 GB) (Free:472.51 GB) (Model: KINGSTON SNV3S1000G) NTFS
\\?\Volume{626ee596-90b9-417c-9e79-037e89c2fd39}\ () (Fixed) (Total:0.71 GB) (Free:0.05 GB) NTFS
\\?\Volume{ebe85961-9060-4b84-ab32-783278932ad8}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-04-2026
Ran by david (administrator) on DESKTOP-IJSLQ8R (Micro-Star International Co., Ltd MS-7B86) (22-04-2026 20:31:56)
Running from C:\Users\david\Desktop\FRST64.exe
Loaded Profiles: david
Platform: Microsoft Windows 11 Home Version 25H2 26200.8246 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eServiceHost.exe <2>
(C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe ->) (SteelSeries France SASU -> A-Volute) C:\Users\david\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\dlls\wgc_renderer_host.exe <5>
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming.net Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wargamingerrormonitor.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wgc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncHelper.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0b6ff136fecebab7\RtkAudUService64.exe <2>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicService.exe
(svchost.exe ->) (21E1B422-257A-44A2-9C8F-379165856473 -> ) C:\Program Files\WindowsApps\A-Volute.Nahimic_1.10.9.0_x64__w2gh52qy24etm\Nahimic3.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.248.3.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
(svchost.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicSvc64.exe
(svchost.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\SysWOW64\NahimicSvc32.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0b6ff136fecebab7\RtkAudUService64.exe [1650016 2023-03-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285616 2026-04-07] (ESET, spol. s r.o. -> ESET)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4746600 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2589432 2026-03-26] (Wargaming Group Limited -> Wargaming.net)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [Proton VPN] => C:\Program Files\Proton\VPN\ProtonVPN.Launcher.exe [18781032 2025-11-28] (Proton AG -> ProtonVPN)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [MicrosoftCopilotAutoLaunch_175BE63C8904AE189174B074A7B4DA61] => C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe [4582440 2026-04-16] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1002\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4746600 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\Canon TS3300 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDG3.DLL [506368 2023-06-05] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS3300 series: C:\Windows\system32\CNMLMG3.DLL [1334784 2023-06-05] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {45C4F61A-1C24-4A35-A626-A5CD8767EEAD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {20CC335E-A06F-4DDD-BB58-EDF4BBA788C9} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [11419480 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {491BDBB5-5DCD-4416-A3B4-B71FE776493F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {872A580E-273F-476E-BFBC-C15AE694BABC} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\opushutil.exe [61280 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {A48ED4ED-CA7A-4991-9515-C1530E9D56EB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {94E92F3A-59C3-4B3E-AC29-89CE4609F31C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {71FBAE62-6500-42E4-B4EB-8451C8A68866} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B1AADECF-5E91-4F9C-BB81-D3D5972710CF} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2920095854-1669752291-3635278505-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705664 2026-04-21] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {CA13F34A-2E69-4611-873D-BCAFB4B801BF} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2920095854-1669752291-3635278505-1002 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705664 2026-04-21] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {67B73CDE-D8EC-43A1-BA0E-2E4BCCB6FEE7} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-04-21] (Mozilla Corporation -> Mozilla Foundation)
Task: {653DA56B-3946-43B8-8423-1C6A61DC2AEF} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [1118128 2025-01-14] (SteelSeries France SASU -> Nahimic)
Task: {D59DBDC6-EC3D-4181-BC12-4C81E0D0A90C} - System32\Tasks\NahimicSvc64Run => C:\Windows\system32\NahimicSvc64.exe [1438128 2025-01-14] (SteelSeries France SASU -> Nahimic)
Task: {F33D2010-466A-4540-885E-72B1B45DD93F} - System32\Tasks\NahimicTask32 => C:\Windows\System32\..\SysWOW64\NahimicSvc32.exe [1118128 0] (SteelSeries France SASU -> Nahimic)
Task: {7372F1AE-EAB8-4BF9-BBE6-9353BE9CAF71} - System32\Tasks\NahimicTask64 => C:\Windows\System32\.\NahimicSvc64.exe [1438128 0] (SteelSeries France SASU -> Nahimic)
Task: {CF859144-76F1-4A6C-A6F6-4D26F82D8382} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {0C642580-5160-4C97-8B9B-F25FCAE3A971} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {786121F6-529F-43B5-9307-AFCE5036EF9B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428136 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {2ACBAE90-3CBA-46D8-8AA6-DC21E9653A5E} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1001 => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveLauncher.exe [756584 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {96BD36BE-0E0A-4C02-8ECE-B629D29F6993} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1002 => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveLauncher.exe [756584 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{597a1605-d190-4301-8c5e-d20e46aa83ab}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: e4rv2yyu.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\loa9ywao.default [2025-06-10]
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release [2026-04-22]
FF Homepage: Mozilla\Firefox\Profiles\e4rv2yyu.default-release -> www.seznam.cz
FF Extension: (ESET Browser Privacy & Security) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\browserextension@eset.com.xpi [2025-11-17]
FF Extension: (New Tab) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\newtab@mozilla.org.xpi [2026-04-01]
FF Extension: (Google Translator for Firefox) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\translator@zoli.bod.xpi [2025-05-29]
FF Extension: (Lion Power) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\{7044fa00-e6bb-40d6-88a2-e087ac3f53e6}.xpi [2025-05-29]
FF Extension: (Firefox B) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\{ac40163c-8804-4dad-90fc-e25ebd6e9a57}.xpi [2025-05-29]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2026-04-12] (Adobe Inc. -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2026-04-22]
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default [2026-04-22]
Edge HomePage: Default -> hxxp://www.seznam.cz/
Edge StartupUrls: Default -> "hxxps://www.seznam.cz/"
Edge Extension: (Dokumenty Google offline) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-21]
Edge Extension: (Edge relevant text changes) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-03-29]
Edge Extension: (ESET Browser Privacy & Security) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2026-03-29]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]
Chrome:
=======
CHR HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13288288 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5639088 2026-04-07] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [5107712 2026-04-07] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [5107712 2026-04-07] (ESET, spol. s r.o. -> ESET)
R3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncHelper.exe [3601256 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460488 2024-04-03] (Canon Inc. -> )
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11481048 2026-04-22] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-04-22] (Malwarebytes Inc. -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe [2088128 2026-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 MicrosoftCopilotElevationService; C:\Program Files (x86)\Microsoft\Copilot\Application\147.0.3912.72\elevation_service.exe [3602512 2026-04-16] (Microsoft Corporation -> Microsoft Corporation)
R2 NahimicService; C:\Windows\System32\NahimicService.exe [1910704 2025-01-14] (SteelSeries France SASU -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\Display.NvContainer\NVDisplay.Container.exe [1702632 2026-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.055.0323.0004\OneDriveUpdaterService.exe [4002704 2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
S3 ProtonVPN Service; C:\Program Files\Proton\VPN\v4.3.9\ProtonVPNService.exe [477424 2025-11-28] (Proton AG -> ProtonVPN)
S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.WireGuardService.exe [476912 2025-11-28] (Proton AG -> ProtonVPN)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2024-10-18] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [933432 2024-10-18] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe [4451664 2026-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe [290704 2026-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [33592 2024-09-12] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [602112 2025-09-10] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [204800 2025-09-10] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [175824 2024-10-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [235528 2026-04-07] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [140464 2026-04-07] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [17840 2025-11-28] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [353856 2026-04-07] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [57928 2026-04-07] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [87328 2026-04-07] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [127584 2026-04-07] (ESET, spol. s r.o. -> ESET)
S3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82352 2026-02-14] (Microsoft Windows -> Microsoft Corporation)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-04-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [245864 2026-04-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 Nahimic_Mirroring; C:\Windows\System32\drivers\Nahimic_Mirroring.sys [94784 2022-06-02] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v4.3.9\Resources\ProtonVPN.CalloutDriver.sys [41416 2025-11-20] (Proton AG -> Proton AG)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174264 2024-10-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [21888 2026-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [641416 2026-03-27] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [103816 2026-03-27] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\Windows\System32\drivers\wintun.sys [29592 2025-08-30] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2025-08-28] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-04-22 20:31 - 2026-04-22 20:32 - 000022025 _____ C:\Users\david\Desktop\FRST.txt
2026-04-22 20:30 - 2026-04-22 20:32 - 000000000 ____D C:\FRST
2026-04-22 20:28 - 2026-04-22 20:28 - 002447360 _____ (Farbar) C:\Users\david\Desktop\FRST64.exe
2026-04-22 20:14 - 2026-04-22 20:14 - 000001241 _____ C:\Users\david\Downloads\Malwarebytes Threat Scan Report 2026-04-22 200142.txt
2026-04-22 19:54 - 2026-04-22 20:14 - 000000000 ____D C:\Users\david\AppData\Local\Malwarebytes
2026-04-22 19:54 - 2026-04-22 19:54 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-04-22 19:54 - 2026-04-22 19:54 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-04-22 19:54 - 2026-04-22 19:54 - 000000000 ____D C:\Users\david\AppData\Local\Sentry
2026-04-22 19:53 - 2026-04-22 19:53 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-04-22 19:53 - 2026-04-22 19:53 - 000000000 ____D C:\Program Files\Malwarebytes
2026-04-22 19:47 - 2026-04-22 19:47 - 002849080 _____ (Malwarebytes) C:\Users\david\Downloads\MBSetup.exe
2026-04-22 18:22 - 2026-04-22 18:22 - 000677108 _____ C:\Windows\system32\perfh005.dat
2026-04-22 18:22 - 2026-04-22 18:22 - 000144960 _____ C:\Windows\system32\perfc005.dat
2026-04-21 21:39 - 2026-04-22 14:48 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-04-21 14:21 - 2026-04-21 14:21 - 000037020 _____ C:\Users\david\Downloads\Cenové srovnání.pdf
2026-04-21 09:35 - 2026-04-21 09:35 - 002969948 _____ C:\Users\david\Downloads\El. sekačka.pdf
2026-04-18 15:47 - 2026-04-22 20:15 - 000000000 ____D C:\Windows\CbsTemp
2026-04-14 19:15 - 2026-04-14 19:15 - 000036843 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-04-14 19:15 - 2026-04-14 19:15 - 000036843 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriUHMImageList
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriLMImageList
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriImageList
2026-04-14 19:15 - 2026-04-14 19:15 - 000004575 _____ C:\Windows\system32\ResPriHMImageList
2026-04-13 15:52 - 2026-04-13 16:37 - 000000000 ____D C:\ESD
2026-04-13 15:50 - 2026-04-13 15:50 - 000000000 ___HD C:\$Windows.~WS
2026-04-13 15:50 - 2026-04-13 15:50 - 000000000 ____D C:\$WINDOWS.~BT
2026-03-29 21:33 - 2026-03-29 21:33 - 000000000 ____D C:\Program Files\AMD
2026-03-29 20:18 - 2026-03-29 22:25 - 000000000 ____D C:\Users\david\AppData\Roaming\AMD
2026-03-27 18:45 - 2026-04-12 17:02 - 000000000 ____D C:\Windows\system32\Tasks\SoftLanding
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-04-22 20:31 - 2025-05-29 15:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-04-22 20:14 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-04-22 20:05 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SystemTemp
2026-04-22 19:54 - 2024-04-01 09:26 - 000000000 ___HD C:\Windows\ELAMBKUP
2026-04-22 19:54 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-04-22 19:54 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\AppReadiness
2026-04-22 19:54 - 2024-04-01 09:24 - 000000000 ____D C:\Windows\INF
2026-04-22 18:22 - 2025-05-29 13:41 - 001603790 _____ C:\Windows\system32\PerfStringBackup.INI
2026-04-22 18:16 - 2025-05-29 13:50 - 000000000 ___RD C:\Users\david\OneDrive
2026-04-22 18:15 - 2025-06-24 20:01 - 000003108 _____ C:\Windows\system32\Tasks\NahimicTask32
2026-04-22 18:15 - 2025-06-24 20:01 - 000003088 _____ C:\Windows\system32\Tasks\NahimicTask64
2026-04-22 18:15 - 2025-05-29 14:01 - 000000000 ____D C:\ProgramData\NVIDIA
2026-04-22 18:15 - 2025-05-29 13:32 - 000084096 _____ C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-04-22 18:15 - 2025-05-29 13:32 - 000012288 ___SH C:\DumpStack.log.tmp
2026-04-22 18:15 - 2025-05-29 13:32 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-04-22 18:15 - 2024-04-01 09:21 - 000524288 _____ C:\Windows\system32\config\BBI
2026-04-22 14:48 - 2025-05-29 15:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-04-22 14:31 - 2025-05-29 13:32 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-04-22 10:08 - 2025-06-13 13:55 - 000004212 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{29C9C97D-9D0C-4060-AB82-367C056F9AC0}
2026-04-22 09:34 - 2025-05-29 15:56 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-04-21 21:39 - 2025-12-10 09:34 - 000392320 _____ (Mozilla Foundation) C:\Users\david\Desktop\Firefox.exe
2026-04-21 14:17 - 2025-05-31 18:02 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-04-21 09:35 - 2025-07-26 08:40 - 000003552 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1002
2026-04-21 09:35 - 2025-07-21 21:42 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1002
2026-04-21 09:35 - 2025-05-31 18:02 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1001
2026-04-21 09:35 - 2025-05-31 18:02 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-04-21 09:35 - 2025-05-31 18:02 - 000002023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-04-21 09:35 - 2025-05-29 13:51 - 000003552 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1001
2026-04-19 19:18 - 2025-10-19 20:12 - 000000000 ____D C:\Program Files\CrystalDiskInfo
2026-04-19 14:46 - 2025-05-29 13:47 - 000000000 ____D C:\Users\david\AppData\Local\D3DSCache
2026-04-18 19:34 - 2025-05-29 13:32 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-04-18 19:34 - 2025-05-29 13:32 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-04-17 20:23 - 2025-05-29 14:11 - 000000000 ____D C:\Program Files (x86)\AMD
2026-04-17 19:53 - 2025-10-15 18:35 - 000001607 _____ C:\Windows\system32\config\VSMIDK
2026-04-17 19:51 - 2025-05-29 18:40 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2026-04-15 17:22 - 2025-11-25 15:43 - 000000000 ____D C:\Users\david\AppData\Local\DWriteCore
2026-04-15 17:12 - 2025-11-19 23:29 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2026-04-15 17:12 - 2025-11-19 23:29 - 000002124 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2026-04-14 19:42 - 2025-05-29 13:46 - 000000000 ____D C:\Users\david\AppData\Local\Packages
2026-04-14 19:39 - 2025-05-29 13:32 - 000344016 _____ C:\Windows\system32\FNTCACHE.DAT
2026-04-14 19:38 - 2025-07-08 22:15 - 000000000 ____D C:\Windows\system32\ruxim
2026-04-14 19:38 - 2024-04-01 18:30 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2026-04-14 19:38 - 2024-04-01 18:28 - 000000000 ____D C:\Windows\SysWOW64\cs
2026-04-14 19:38 - 2024-04-01 18:28 - 000000000 ____D C:\Windows\system32\cs
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ___SD C:\Windows\SysWOW64\F12
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ___SD C:\Windows\system32\F12
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\vi-VN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ur-PK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ug-CN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\tt-RU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\te-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ta-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\sq-AL
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\quz-PE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\qps-plocm
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\qps-ploc
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\pa-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\or-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\oobe
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\nn-NO
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ne-NP
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mt-MT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mr-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ml-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mk-MK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\mi-NZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lo-LA
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\lb-LU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\kok-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\kn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\km-KH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\kk-KZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ka-GE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\is-IS
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\InstallShield
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\id-ID
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\hy-AM
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\hi-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\gu-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\gl-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\gd-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ga-IE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\fil-PH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\fa-IR
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\eu-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\Dism
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\cy-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\ca-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\bn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\be-BY
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\as-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\am-ET
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\af-ZA
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SystemResources
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinMetadata
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\vi-VN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ur-PK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ug-CN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\tt-RU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\te-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ta-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\sq-AL
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ShellExperiences
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\setup
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\quz-PE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\qps-plocm
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\qps-ploc
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\pa-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\or-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\oobe
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\nn-NO
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ne-NP
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mt-MT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mr-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ml-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mk-MK
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\mi-NZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\migwiz
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lv-LV
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lt-LT
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lo-LA
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\lb-LU
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\kok-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\kn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\km-KH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\kk-KZ
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ka-GE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\is-IS
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\id-ID
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\hy-AM
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\hi-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\gu-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\gl-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\gd-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ga-IE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\fil-PH
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\fa-IR
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\eu-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\et-EE
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\es-MX
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\Dism
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\cy-GB
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ca-ES
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\bn-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\be-BY
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\as-IN
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\appraiser
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\am-ET
2026-04-14 19:38 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\af-ZA
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellExperiences
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellComponents
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\Provisioning
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\DiagTrack
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\BrowserCore
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\bcastdvr
2026-04-14 19:37 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-04-14 19:37 - 2024-04-01 09:21 - 000000000 ____D C:\Windows\servicing
2026-04-14 19:26 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2026-04-14 19:26 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2026-04-14 19:14 - 2025-05-29 13:34 - 003268096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2026-04-14 19:06 - 2025-05-29 14:32 - 000000000 ____D C:\Windows\system32\MRT
2026-04-14 19:05 - 2025-05-29 14:32 - 218249592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-04-13 16:37 - 2025-05-29 14:31 - 000000000 ____D C:\Windows\Panther
2026-04-12 19:14 - 2025-06-01 10:42 - 000000000 ____D C:\Users\david\AppData\Local\CrashDumps
2026-04-12 19:05 - 2025-05-29 14:02 - 000000000 ____D C:\MSI
2026-04-12 19:05 - 2025-05-29 14:01 - 000000000 ____D C:\Program Files (x86)\MSI
2026-04-12 18:58 - 2025-05-29 14:02 - 000000000 ____D C:\Users\david\AppData\Local\Downloaded Installations
2026-04-12 18:56 - 2025-05-29 13:45 - 000000000 ____D C:\Users\david\AppData\Local\PlaceholderTileLogoFolder
2026-04-12 17:03 - 2025-07-21 21:40 - 000000000 ____D C:\Users\David Šplíchal\AppData\Local\Packages
2026-04-10 12:00 - 2025-05-29 20:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingston SSD Manager x64
2026-04-10 12:00 - 2025-05-29 20:55 - 000000000 ____D C:\Program Files\Kingston_SSD_Manager
2026-04-10 09:48 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\SecurityHealth
2026-04-09 20:27 - 2025-05-29 13:32 - 000003714 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{01B088DA-A62B-4A48-BD8A-07CB154CA3F6}
2026-04-09 20:27 - 2025-05-29 13:32 - 000003588 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{6CF29DA0-3906-413B-B017-6557F6DCB4DD}
2026-04-07 18:45 - 2025-04-28 13:48 - 000353856 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000235528 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000140464 _____ (ESET) C:\Windows\system32\Drivers\edevmon.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000127584 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000087328 _____ (ESET) C:\Windows\system32\Drivers\epfw.sys
2026-04-07 18:45 - 2025-04-28 13:48 - 000057928 _____ (ESET) C:\Windows\system32\Drivers\ekbdflt.sys
2026-04-05 18:23 - 2025-05-29 14:05 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2026-04-05 18:23 - 2025-05-29 14:01 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2026-04-02 12:00 - 2025-05-31 17:20 - 000000000 ____D C:\Users\david\AppData\Roaming\Microsoft\Excel
2026-04-01 20:52 - 2025-06-07 15:10 - 000000000 ____D C:\Users\david\AppData\Local\NVIDIA
2026-04-01 20:41 - 2025-05-31 21:43 - 000000000 ____D C:\ProgramData\CanonIJPLM
2026-03-29 22:26 - 2025-05-29 13:40 - 000000000 ____D C:\Users\david
2026-03-29 22:25 - 2025-07-21 21:40 - 000000000 ____D C:\Users\David Šplíchal
2026-03-29 22:12 - 2025-06-24 19:57 - 000000000 ____D C:\ProgramData\A-Volute
2026-03-29 22:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\registration
2026-03-29 21:32 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps.tmp
2026-03-29 20:18 - 2025-05-29 14:11 - 000000000 ____D C:\AMD
2026-03-27 20:14 - 2025-05-29 13:32 - 000000000 ____D C:\Windows\system32\Drivers\wd
2026-03-26 15:36 - 2025-05-29 13:34 - 000000000 ____D C:\ProgramData\Packages
==================== Files in the root of some directories ========
2025-05-31 09:35 - 2025-10-04 18:13 - 000007653 _____ () C:\Users\david\AppData\Local\Resmon.ResmonCfg
2025-06-01 10:42 - 2025-06-01 10:42 - 000000036 _____ () C:\Users\david\AppData\Local\_LOCAL_GUID
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-04-2026
Ran by david (22-04-2026 20:33:16)
Running from C:\Users\david\Desktop
Microsoft Windows 11 Home Version 25H2 26200.8246 (X64) (2025-05-29 11:34:17)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2920095854-1669752291-3635278505-500 - Administrators - Disabled)
david (S-1-5-21-2920095854-1669752291-3635278505-1001 - Administrators - Enabled) => C:\Users\david
David Šplíchal (S-1-5-21-2920095854-1669752291-3635278505-1002 - Limited - Enabled) => C:\Users\David Šplíchal
DefaultAccount (S-1-5-21-2920095854-1669752291-3635278505-503 - Limited - Disabled)
Guest (S-1-5-21-2920095854-1669752291-3635278505-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2920095854-1669752291-3635278505-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Malwarebytes (Disabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 26.00 (x64) (HKLM\...\7-Zip) (Version: 26.00 - Igor Pavlov)
Adobe Acrobat Reader - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 26.001.21431 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.78.1094 - AB Team, d.o.o.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.90.3.36 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.5.5.3 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.6.0 - Canon Inc.)
Canon TS3300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS3300_series) (Version: 1.04 - Canon Inc.)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 147.0.3912.72 - Microsoft Corporation)
CrystalDiskInfo 9.7.2 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.7.2 - Crystal Dew World)
ESET Security (HKLM\...\{0F3CB7F7-E580-4E9D-BC90-58BF9A860742}) (Version: 19.1.12.0 - ESET, spol. s r.o.)
IrfanView 4.70 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.70 - Irfan Skiljan)
Kingston SSD Manager x64 1.5.6.5 (HKLM-x32\...\{53F657CD-C4FC-4DCD-826E-6862917532AC}_is1) (Version: 1.5.6.5 - @2021 Kingston Digital, Inc.)
Malwarebytes version 5.5.4.252 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.5.4.252 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 147.0.3912.72 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 147.0.3912.72 - Microsoft Corporation) Hidden
Microsoft Office 2019 pro studenty a domácnosti - cs-cz (HKLM\...\HomeStudent2019Retail - cs-cz) (Version: 16.0.19127.20302 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.055.0323.0004 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.50.35719 (HKLM\...\{AECD4ED0-8A3B-41E9-92D1-6BEE0374CCAF}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.50.35719 (HKLM\...\{61B44572-8722-4DAF-8ACF-8E742D30BCC5}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (HKLM-x32\...\{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (HKLM-x32\...\{73F77E4E-5A17-46E5-A5FC-8A061047725F}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 (HKLM-x32\...\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}) (Version: 14.50.35719.0 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox) (Version: 150.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 139.0 - Mozilla)
NVIDIA Ovladač HD audia 1.4.5.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.7 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 595.79 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 595.79 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
NVIDIA USBC Driver 1.52.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.52.831.832 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20302 - Microsoft Corporation) Hidden
Proton VPN (HKLM\...\Proton VPN_is1) (Version: 4.3.9 - Proton AG)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9492.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.74.1128.2024 - Realtek)
Registrace tiskárny (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.2 - Canon Inc.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.9.0.0 - Samsung Electronics Co., Ltd.)
Smart Switch Service (HKLM\...\{7B46CD5E-C3FF-4CB4-A569-425C545A9992}) (Version: 5.0.40.0 - Samsung Electronics Co., Ltd.)
Wargaming.net Game Center (HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Wargaming.net Game Center) (Version: 26.1.1.2050 - Wargaming.net)
World of Tanks EU (HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\2314027414) (Version: - Wargaming.net)
Packages:
=========
Adobe Acrobat Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Assets [2026-04-15] ()
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2026-04-15] (Sparse Package)
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2026-04-22] ()
Nahimic -> C:\Program Files\WindowsApps\A-Volute.Nahimic_1.10.9.0_x64__w2gh52qy24etm [2026-03-29] (A-Volute)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2026-03-29] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2026-03-29] (Realtek Semiconductor Corp)
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0 [2026-04-17] (Spotify AB) [Startup Task]
WinAppRuntime.Main.1.8 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.8_8000.806.2252.0_x64__8wekyb3d8bbwe [2026-04-14] (Microsoft Corp.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{04271989-C4D2-1C86-3D53-F2AC04DA8ED5} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{50726f74-6f6e-2e56-504e-000000000000}\localserver32 -> C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.Client.exe (Proton AG -> ProtonVPN)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> C:\Program Files\ESET\ESET Security\egui.exe (ESET, spol. s r.o. -> ESET)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{80172dde-4e20-4df0-81a2-0a48553e80bb}\localserver32 -> C:\Users\david\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe (SteelSeries France SASU -> A-Volute)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Acrobat Elements\ContextMenuShim64.dll [2026-02-17] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-04-07] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-04-07] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-04-22] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.055.0323.0004\FileSyncShell64.dll [2026-04-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\nvshext.dll [2026-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-04-07] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-04-22] (Malwarebytes Inc -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [MidisrvTransferComplete] => 1
HKLM\...\Drivers32: [midi1] => C:\Windows\system32\wdmaud2.drv [143360 2026-04-14] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Drivers32: [midi1] => C:\Windows\SysWOW64\wdmaud2.drv [94720 2026-04-14] (Microsoft Windows -> Microsoft Corporation)
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2026-02-17 21:28 - 2026-02-12 12:00 - 000101888 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2025-05-31 17:11 - 2025-05-31 17:11 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll
2025-05-31 17:11 - 2025-05-31 17:11 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{75416E63-5912-4DFA-AE8F-3EFACCAFFB14} => ""="NvmeDisk"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSVC => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{75416E63-5912-4DFA-AE8F-3EFACCAFFB14} => ""="NvmeDisk"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.0.1
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2920095854-1669752291-3635278505-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_3.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "Proton VPN"
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "MicrosoftCopilotAutoLaunch_175BE63C8904AE189174B074A7B4DA61"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C01BF982-ED25-431B-A17D-4F081C2CF53F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F3217FB1-4FE7-4BE6-A23C-46874AB49F1B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{3FBD7C0E-E02F-4F8D-9948-BF2CD309DEA2}] => (Allow) LPort=33683
FirewallRules: [{9BF204D4-EE01-4A59-B32A-BB21FBDF042A}] => (Allow) LPort=26822
FirewallRules: [{B57999FB-3805-4B5B-9701-F09319F78EE2}] => (Allow) LPort=32683
FirewallRules: [{FD04402E-EE1B-4BED-B9ED-533502FE4328}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{91181B29-7AAC-401E-A451-61E40CD985E1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{7D2BCDF4-B21B-4B70-BE3F-DC67C850F479}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1FA5623F-2B8D-4580-90C9-07E17B053AAF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{32D31573-79F2-491A-A5E6-28B36737B41B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{08832137-620A-49B1-866A-494E11DCB89C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6FA1AF59-CC56-4973-8F00-8D72A2D8BC25}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{9C10F45A-FAF8-4F91-B5EB-1189FC787A3C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{4A44EEF3-79FF-4369-A851-303024340D25}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1CFAAFA9-30D3-404A-84E0-40534D14347B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{5E4E4465-DCE3-4CD4-95FF-16D6D57EAE21}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2AD4D90A-2349-475E-8505-C554BF3FFC9E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{74CA33A0-9C1B-40BB-B20D-F329432065EC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{33449615-0783-4098-A9D8-FCA21DE1E78F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.287.415.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
==================== Restore Points =========================
21-04-2026 16:16:06 Windows Update
21-04-2026 16:16:13 Windows Update
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (04/22/2026 07:08:39 PM) (Source: Microsoft Security Client) (EventID: 3002) (User: )
Description: Event-ID 3002
Error: (04/22/2026 07:08:39 PM) (Source: Microsoft Security Client) (EventID: 2002) (User: )
Description: Event-ID 2002
Error: (04/22/2026 07:08:39 PM) (Source: Microsoft Security Client) (EventID: 2003) (User: )
Description: Event-ID 2003
Error: (04/22/2026 06:15:54 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-IJSLQ8R$ přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 22 Apr 2026 16:15:53 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 0995427e-e449-4170-83cd-f76dcccca1d8
Metoda: GET(672ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (04/22/2026 06:15:53 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro Místní systém přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 22 Apr 2026 16:15:52 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 5c48a3f3-158a-44fe-ac56-7056528820f0
Metoda: GET(515ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (04/22/2026 02:48:39 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem Nezdařila se fáze obnovení..
Kontext: aplikace , katalog SystemIndex
Podrobnosti:
0x%08x (0x80040d23 - Vypínání indexovacího modulu (HRESULT : 0x80040d23))
Error: (04/22/2026 02:48:39 PM) (Source: Windows Search Service) (EventID: 3602) (User: )
Description: Ve fázi obnovování služby Windows Search došlo k chybě s ID 1. Restartujte službu. Pokud tato chyba potrvá, vytvořte index znovu.
Kontext: aplikace , katalog SystemIndex
Podrobnosti:
0x%08x (0x80040d23 - Vypínání indexovacího modulu (HRESULT : 0x80040d23))
Error: (04/22/2026 02:48:18 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-IJSLQ8R$ přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 22 Apr 2026 12:48:18 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: edf1aa7e-6e98-41b8-928a-dc84087d4f79
Metoda: GET(453ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
System errors:
=============
Error: (04/22/2026 06:17:42 PM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3502) (User: NT AUTHORITY)
Description: Zrušení přidružení zařízení (zrušení párování) se nezdařilo.
Error: (04/22/2026 06:17:12 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1023) (User: NT AUTHORITY)
Description: Tabulka zásad překladu IP adres byla poškozena. Překlad názvů DNS bude dále selhávat, dokud nebude tabulka opravena. Další informace: Čtení tabulky zásad pro pravidlo {3544EC45-B1D8-4C51-81BB-F0F27E9ECE06} se nepodařilo s chybou 87.
Error: (04/22/2026 06:15:34 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 124) (User: NT AUTHORITY)
Description: 03225747456
Error: (04/22/2026 06:15:34 PM) (Source: Microsoft-Windows-Hyper-V-Hypervisor) (EventID: 42) (User: NT AUTHORITY)
Description: Spuštění hypervisoru se nepovedlo. SVM není k dispozici nebo není povolené v systému BIOS.
Error: (04/22/2026 06:15:13 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (04/22/2026 06:15:13 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.
Error: (04/22/2026 05:10:19 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1023) (User: NT AUTHORITY)
Description: Tabulka zásad překladu IP adres byla poškozena. Překlad názvů DNS bude dále selhávat, dokud nebude tabulka opravena. Další informace: Čtení tabulky zásad pro pravidlo {3C08B176-1D75-4994-94BB-F66514ACACF1} se nepodařilo s chybou 87.
Error: (04/22/2026 02:50:14 PM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3502) (User: NT AUTHORITY)
Description: Zrušení přidružení zařízení (zrušení párování) se nezdařilo.
Windows Defender:
================
Date: 2026-03-27 19:24:48
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{957E782B-0118-4C94-9DED-115799419C34}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŚċħеďŭľĕđ şçдη щαś śκīφρēđ ьéčаüŝě τħé ľãšт śúсçэѕśƒüℓ ŝċдņ ώãѕ ẅїтђίʼn ŧĥè ℓαѕт 7 ðãуś
Date: 2026-02-14 12:26:25
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{6F1BFD8A-47F1-475F-98F7-9F272DF62BBE}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŞĉђěδυŀзď şсåл ẃãŝ śкϊрρеđ ъè¢àϋšє тнè ŀаѕť ŝų¢сзŝšƒυĺ ѕçâń ωàş ώіτђĭʼn τђэ ľăŝŧ 7 đаўś
Date: 2026-01-04 12:11:29
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{AE9E3AFF-F184-4327-999F-F28AB9272554}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŞĉĥеδũĺέđ şĉāⁿ ŵāѕ ŝĸïφрёď вëčάùśε ŧĥе ℓдśт ŝůĉčęśśƒűł ѕčåñ щāś ώϊţђĭи ŧĥě ℓàŝт 7 ďàŷѕ
Date: 2026-01-04 11:33:11
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{FEA37172-9D1D-4668-8816-09B18C49BB21}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вÚplné prohledávání%л %ŧŨśęѓ:%ъDESKTOP-IJSLQ8R\david%ń %τŠτõρ Ŗėаѕǿп:%ьŲŋκйòщп
Date: 2026-01-04 11:32:35
Description:
Antivirová ochrana v programu Microsoft Defender ŝċдή ћªś ьёéñ ѕţòρφéď вęƒõгè ćöмрŀέτіόⁿ.%ⁿ %ťŚςάŋ ĨĐ:%ъ{04F1B824-E32A-4886-BE57-754AF36BA760}%л %ŧЅćдń Ţγρэ:%ъAntimalwarový program%π %тЅςàή Ρäгámêт℮гŝ:%вRychlé prohledávání%л %ŧŨśęѓ:%ъNT AUTHORITY\SYSTEM%ń %τŠτõρ Ŗėаѕǿп:%ьŜ¢ĥзδůŀėď ѕčаň ẃªś ѕκϊφρзđ ъε¢άύśé тнė ļǻşт šџ¢čзššƒцľ śĉåή ώãŝ щīŧнĩň τћė ľάŝŧ 7 đªγś
Event[0]
Date: 2025-06-18 12:02:35
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-06-18 08:52:07
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-06-07 20:05:52
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-05-29 18:40:46
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
CodeIntegrity:
===============
Date: 2026-04-22 20:14:43
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.
Date: 2026-04-22 20:10:09
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends International, LLC. H.O0 09/01/2025
Motherboard: Micro-Star International Co., Ltd B450 GAMING PLUS MAX (MS-7B86)
Processor: AMD Ryzen 5 2600 Six-Core Processor
Percentage of memory in use: 32%
Total physical RAM: 16309.56 MB
Available physical RAM: 10971.45 MB
Total Virtual: 17333.56 MB
Available Virtual: 11192.9 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:299.17 GB) (Free:100.28 GB) (Model: KINGSTON SNV3S1000G) NTFS
Drive d: () (Fixed) (Total:631.51 GB) (Free:472.51 GB) (Model: KINGSTON SNV3S1000G) NTFS
\\?\Volume{626ee596-90b9-417c-9e79-037e89c2fd39}\ () (Fixed) (Total:0.71 GB) (Free:0.05 GB) NTFS
\\?\Volume{ebe85961-9060-4b84-ab32-783278932ad8}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
- Rudy
- Site Admin

- Příspěvky: 119865
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Microsoft Edge a filtrované webové stránky v Eset
Zdravím!
Zkusíme vyčistit FRST, ale obávám se, že je to záležitost nastavení ESETu.
Otevřte poznámkový blok a zkopírujte do něj:
Zkusíme vyčistit FRST, ale obávám se, že je to záležitost nastavení ESETu.
Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
C:\Program Files\WindowsApps.tmp
EmptyTemp:
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Microsoft Edge a filtrované webové stránky v Eset
Fix result of Farbar Recovery Scan Tool (x64) Version: 20-04-2026
Ran by david (23-04-2026 20:01:30) Run:1
Running from C:\Users\david\Desktop
Loaded Profiles: david & David Šplíchal
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
C:\Program Files\WindowsApps.tmp
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
Could not move "C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
"C:\Program Files\WindowsApps.tmp" Folder move:
C:\Program Files\WindowsApps.tmp => moved successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 662416728 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 163247619 B
Edge => 200625004 B
Firefox => 1377279994 B
Opera => 0 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 91866010 B
systemprofile32 => 30581460 B
LocalService => 2378768 B
NetworkService => 61268 B
david => 33941886 B
David Šplíchal => 887553 B
RecycleBin => 0 B
EmptyTemp: => 2.4 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 23-04-2026 20:10:53)
C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 20:10:53 ====
Ran by david (23-04-2026 20:01:30) Run:1
Running from C:\Users\david\Desktop
Loaded Profiles: david & David Šplíchal
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
C:\Program Files\WindowsApps.tmp
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
Could not move "C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
"C:\Program Files\WindowsApps.tmp" Folder move:
C:\Program Files\WindowsApps.tmp => moved successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 662416728 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 163247619 B
Edge => 200625004 B
Firefox => 1377279994 B
Opera => 0 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 91866010 B
systemprofile32 => 30581460 B
LocalService => 2378768 B
NetworkService => 61268 B
david => 33941886 B
David Šplíchal => 887553 B
RecycleBin => 0 B
EmptyTemp: => 2.4 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 23-04-2026 20:10:53)
C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 20:10:53 ====
- Rudy
- Site Admin

- Příspěvky: 119865
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Microsoft Edge a filtrované webové stránky v Eset
Smazáno. Změnilo se něco k lepšímu?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Microsoft Edge a filtrované webové stránky v Eset
Dělá to pořád
.
- Rudy
- Site Admin

- Příspěvky: 119865
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Microsoft Edge a filtrované webové stránky v Eset
Budete se muset kouknout do nastvení Esetu: Protože nevím, jakou verzi provozujtete, vyberte z e : https://www.google.com/search?client=fi ... C3%AD+eset. Eset by měl mít možnost nastavení vyjímek.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Microsoft Edge a filtrované webové stránky v Eset
Dobře, podívám se do nastavení. Používám Eset Internet Security 19.1.12.0
Děkuji za pomoc.
Děkuji za pomoc.
- Rudy
- Site Admin

- Příspěvky: 119865
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Microsoft Edge a filtrované webové stránky v Eset
Rádo se stalo! 
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?