Prosím o kontrolu.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-04-2026
Ran by 13918 (administrator) on MSI (Micro-Star International Co., Ltd. MS-7D46) (24-04-2026 06:09:37)
Running from C:\Users\13918\AppData\Local\Temp\scoped_dir7088_522007211\FRST64.exe
Loaded Profiles: 13918
Platform: Microsoft Windows 11 Home Version 25H2 26200.8246 (X64) Language: Čeština (Česko)
Default browser: Brave
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler64.exe
(C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\MSI Center\Engine\CC_Engine_x64.exe
(C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe
(C:\Users\13918\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\13918\AppData\Local\Programs\Opera\130.0.5847.41\opera_crashreporter.exe
(DriverStore\FileRepository\u0420529.inf_amd64_94ad5a6c4d1a04e2\B419765\atiesrxx.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0420529.inf_amd64_94ad5a6c4d1a04e2\B419765\atieclxx.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\13918\AppData\Local\Programs\Opera\opera.exe <24>
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\Epson Software\Download Navigator\EPSDNMON.EXE
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0420529.inf_amd64_94ad5a6c4d1a04e2\B419765\atiesrxx.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\DriverStore\FileRepository\amdfendr.inf_amd64_987f8cede005f427\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\NisSrv.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Case\MSI_Case_Service.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_31dd95d009763f70\RtkAudUService64.exe
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\epson\Epson Printer Driver Security Support Tool\EpSecuritySupport.exe
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.264.2.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe <2>
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.TerminalServer.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_31dd95d009763f70\RtkAudUService64.exe [3282984 2025-12-10] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [466760 2026-02-16] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2765952 2024-10-01] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [Samsung PanelMgr] => C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe [618496 2010-06-07] () [File not signed]
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIYWE.EXE [486808 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42086872 2026-04-12] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\Run: [EPSDNMON] => C:\Program Files (x86)\Epson Software\Download Navigator\EPSDNMON.EXE [419144 2026-03-09] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2589432 2026-03-26] (Wargaming Group Limited -> Wargaming.net)
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\Run: [MicrosoftEdgeAutoLaunch_B92492922E84AF6C06A72D733262D31A] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5026856 2026-04-16] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\SST3CPC: C:\Windows\System32\spool\prtprocs\x64\sst3cpc.dll [33792 2009-09-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Server 2003 DDK provider)
HKLM\...\Windows x64\Print Processors\us016PC: C:\Windows\System32\spool\prtprocs\x64\us016pc.dll [61736 2022-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\EPSON L3250 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBYWE.DLL [237568 2021-09-21] (Seiko Epson Corporation) [File not signed]
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\WINDOWS\system32\enppmon.dll [3182776 2025-02-20] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\SST3C Langmon: C:\WINDOWS\system32\sst3cl6.dll [27648 2009-09-11] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\us016 Langmon: C:\WINDOWS\system32\us016lm.dll [40744 2022-03-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\147.1.89.143\Installer\chrmstp.exe [6006352 2026-04-24] (Brave Software, Inc. -> Brave Software, Inc.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4DF556CF-C0D7-410C-BA35-90A8602F76DF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {BA3407C3-6B53-47EE-9C36-83318B7A0278} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore{0358413E-1F7F-4478-9608-77C19CAFF23E} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167504 2026-02-18] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {E47F3BD0-444F-4A52-BA1C-41B7D4EDBF3F} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA{304878B0-5238-4675-8F9C-03E2A0BD2B18} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167504 2026-02-18] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {83DE1DD5-136F-4D8A-B281-8DC3E766545F} - System32\Tasks\EPSON L3250 Series Update {8309C6D2-650D-406A-8A4F-95C7467EB3F7} => C:\Windows\System32\spool\drivers\x64\3\E_YTSYWE.EXE [680440 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {027C8F5B-7C13-405B-B79E-174574DC4C76} - System32\Tasks\EPSON L3250 Series Update {D54103F1-D3E7-4FD2-BC28-9BF7FB8E9841} => C:\Windows\System32\spool\drivers\x64\3\E_YTSYWE.EXE [680440 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {7DFFB18B-6471-4FC8-A7BC-633BEBB4DFE6} - System32\Tasks\EPSON L3250 Series Update {D67AFAC0-E17D-48B1-9407-11FAA59D5B3C} => C:\Windows\System32\spool\drivers\x64\3\E_YTSYWE.EXE [680440 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {5E796892-AF59-4040-B861-F7FB2323F3D6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F98FC699-B349-4F29-9238-379DDF24C2D0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B3EA37F2-6CA3-419C-9E3B-30B58CB4A001} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3B91ECB9-DD51-4C1A-9ABF-3C4595FB142E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe [1790616 2026-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4A6FCB80-7D69-4E75-8A21-6060F81AA439} - System32\Tasks\Opera scheduled assistant Autoupdate 1732362534 => C:\Users\13918\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [7365592 2026-04-15] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --installdir="C:\Users\13918\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {45EB40F8-3AB3-4483-BFBD-74011359E149} - System32\Tasks\Opera scheduled Autoupdate 1732362534 => C:\Users\13918\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [7365592 2026-04-15] (Opera Norway AS -> Opera Software)
Task: {D12A084C-630D-49B3-BCF2-19A315EA7C45} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe /bg /scheduledHC (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\EPSON L3250 Series Update {8309C6D2-650D-406A-8A4F-95C7467EB3F7}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSYWE.EXE:/EXE:{8309C6D2-650D-406A-8A4F-95C7467EB3F7} /F:UpdateWORKGROUP\MSI$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON L3250 Series Update {D54103F1-D3E7-4FD2-BC28-9BF7FB8E9841}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSYWE.EXE:/EXE:{D54103F1-D3E7-4FD2-BC28-9BF7FB8E9841} /F:UpdateWORKGROUP\MSI$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON L3250 Series Update {D67AFAC0-E17D-48B1-9407-11FAA59D5B3C}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSYWE.EXE:/EXE:{D67AFAC0-E17D-48B1-9407-11FAA59D5B3C} /F:UpdateWORKGROUP\MSI$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{18885cdd-4745-483f-8739-7c9b492d147a}: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-04-12] (Adobe Inc. -> Adobe Systems Inc.)
Edge:
=======
Edge Profile: C:\Users\13918\AppData\Local\Microsoft\Edge\User Data\Default [2026-04-23]
Edge Extension: (Dokumenty Google offline) - C:\Users\13918\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-04-20]
Edge Extension: (Edge relevant text changes) - C:\Users\13918\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-11-23]
Chrome:
=======
CHR HKU\S-1-5-21-3331464132-3830428412-573898847-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
Opera:
=======
OPR DefaultProfile: Default
StartMenuInternet: (HKU\S-1-5-21-3331464132-3830428412-573898847-1001) OperaStable - "C:\Users\13918\AppData\Local\Programs\Opera\opera.exe"
Brave:
=======
BRA Profile: C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2026-04-23]
BRA Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-04-18]
BRA Extension: (Brave Ad Block Updater (Brave First Party Adblock Filters (plaintext))) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2026-04-18]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2026-04-23]
BRA Extension: (Brave NTP background images) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2026-04-18]
BRA Extension: (Brave Ad Block Updater (Mobile app promo blocker (plaintext))) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2026-04-18]
BRA Extension: (Brave Ad Block Updater (Cookie notice blocker (plaintext))) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2026-04-23]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2025-01-27]
BRA Extension: (Brave NTP sponsored images) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\efkihffiamafhbhefjaljejgdpkelpal [2026-04-23]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2026-04-18]
BRA Extension: (Brave NTP Super Referrer mapping table) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\heplpbhjcbmiibdlchlanmdenffpiibo [2025-01-25]
BRA Extension: (Brave Ads Resources) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\iejekkikpddbbockoldagmfcdbffomfc [2026-02-25]
BRA Extension: (Brave Ad Block Updater (Brave Default Adblock Filters (plaintext))) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2026-04-23]
BRA Extension: (Brave Ad Block Updater (Brave Default Privacy Filters (plaintext))) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\kihnoaefogbkmblfimmibknnmkllbhlf [2026-04-23]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2026-04-10]
BRA Extension: (Brave User Agent) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\nlpaeekllejnmhoonlpcefpfnpbajbpe [2026-04-23]
BRA Extension: (Brave Ad Block Updater (EasyList Czech and Slovak (plaintext))) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\oegebjahecghlckbhkmojgnpcgdeajdi [2026-01-18]
BRA Extension: (P3A Configuration) - C:\Users\13918\AppData\Local\BraveSoftware\Brave-Browser\User Data\P3AConfig [2025-09-29]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167504 2026-02-18] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 BraveElevationService; C:\Program Files\BraveSoftware\Brave-Browser\Application\147.1.89.143\elevation_service.exe [4491344 2026-04-23] (Brave Software, Inc. -> Brave Software, Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167504 2026-02-18] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 EpSecuritySupport; C:\Program Files (x86)\Epson\Epson Printer Driver Security Support Tool\EpSecuritySupport.exe [280904 2025-06-19] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [222768 2024-12-02] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpDefenderCoreService.exe [2088128 2026-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 MicrosoftCopilotElevationService; C:\Program Files (x86)\Microsoft\Copilot\Application\147.0.3912.84\elevation_service.exe [3602240 2026-04-23] (Microsoft Corporation -> Microsoft Corporation)
R2 MSI_Case_Service; C:\Program Files (x86)\MSI\MSI Center\Case\MSI_Case_Service.exe [74768 2024-06-06] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MSI_Center_Service; C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe [172048 2024-07-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\NisSrv.exe [4480592 2026-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MsMpEng.exe [290744 2026-04-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ose; "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (No File)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\WINDOWS\System32\DriverStore\FileRepository\amdfendr.inf_amd64_987f8cede005f427\amdfendrmgr.sys [55688 2024-09-12] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amduw23g-420529-5f0fe368; C:\WINDOWS\System32\DriverStore\FileRepository\u0420529.inf_amd64_94ad5a6c4d1a04e2\B419765\amdkmdag.sys [101819840 2025-10-27] (Advanced Micro Devices -> Advanced Micro Devices, Inc.)
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2024-11-23] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_e64afe811c7e4662\e1d.sys [607400 2022-02-16] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_GPIO2_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_e11257f05c0c2f89\iaLPSS2_GPIO2_ADL.sys [139928 2021-07-29] (Intel Corporation -> Intel Corporation)
R3 IntelGNA; C:\WINDOWS\System32\DriverStore\FileRepository\gna.inf_amd64_6f93b7542fd3ead9\gna.sys [88656 2023-08-28] (Intel Corporation -> Intel Corporation)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82352 2026-01-28] (Microsoft Windows -> Microsoft Corporation)
R3 NTIOLib_CC_COMM; C:\Program Files (x86)\MSI\MSI Center\Lib\SYS\NTIOLib_X64.sys [32592 2024-09-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21888 2026-04-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [647560 2026-04-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2026-04-10] (Microsoft Windows -> Microsoft Corporation)
S3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2024-09-06] (Microsoft Windows -> Microsoft Corporation)
S3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys [61440 2025-09-10] (Microsoft Windows -> Microsoft Corporation)
S2 DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys (No File)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-04-24 06:09 - 2026-04-24 06:10 - 000000000 ____D C:\FRST
2026-04-24 06:08 - 2026-04-24 06:08 - 002447360 _____ (Farbar) C:\Users\13918\Downloads\FRST64.exe
2026-04-24 06:02 - 2026-04-24 06:02 - 000738852 _____ C:\WINDOWS\system32\perfh005.dat
2026-04-24 06:02 - 2026-04-24 06:02 - 000161342 _____ C:\WINDOWS\system32\perfc005.dat
2026-04-24 05:48 - 2026-04-24 05:53 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2026-04-24 05:44 - 2026-04-24 05:56 - 000000000 ____D C:\WINDOWS\pss
2026-04-23 18:26 - 2026-04-23 18:26 - 008412528 _____ (ESET) C:\Users\13918\Downloads\esetonlinescanner.exe
2026-04-20 12:42 - 2026-04-20 17:49 - 000000000 ____D C:\Users\13918\AppData\Roaming\Wargaming.net
2026-04-20 12:42 - 2026-04-20 12:42 - 000001892 _____ C:\Users\13918\Desktop\Game Center.lnk
2026-04-20 12:42 - 2026-04-20 12:42 - 000001657 _____ C:\Users\13918\Desktop\World of Tanks EU.lnk
2026-04-20 12:42 - 2026-04-20 12:42 - 000000000 ____D C:\Users\13918\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wargaming.net
2026-04-20 12:42 - 2026-04-20 12:42 - 000000000 ____D C:\Users\13918\AppData\Local\CEF
2026-04-20 12:41 - 2026-04-20 12:41 - 000000000 ____D C:\ProgramData\Wargaming.net
2026-04-18 10:00 - 2026-04-18 10:00 - 000078017 _____ C:\Users\13918\Downloads\altomi-3012501402-Predpis_2026-05-01-20260412-140255730.pdf
2026-04-16 08:29 - 2026-04-16 08:29 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-04-16 08:28 - 2026-04-16 08:28 - 000000000 ____D C:\Users\13918\AppData\Local\Backup
2026-04-16 08:11 - 2026-04-23 20:44 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-04-15 05:55 - 2026-04-15 05:55 - 000004575 _____ C:\WINDOWS\system32\ResPriUHMImageList
2026-04-15 05:55 - 2026-04-15 05:55 - 000004575 _____ C:\WINDOWS\system32\ResPriLMImageList
2026-04-15 05:55 - 2026-04-15 05:55 - 000004575 _____ C:\WINDOWS\system32\ResPriImageList
2026-04-15 05:55 - 2026-04-15 05:55 - 000004575 _____ C:\WINDOWS\system32\ResPriHMImageList
2026-04-15 05:52 - 2026-04-15 05:52 - 000036843 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-04-15 05:52 - 2026-04-15 05:52 - 000036843 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-04-06 20:21 - 2026-04-06 20:27 - 000000000 ____D C:\Users\13918\Desktop\Nová složka
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-04-24 06:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-04-24 06:02 - 2024-11-23 11:24 - 001745744 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-04-24 06:02 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-04-24 06:00 - 2024-11-23 14:58 - 000000000 ____D C:\Users\13918\AppData\Local\CrashDumps
2026-04-24 05:59 - 2026-02-18 10:01 - 000000000 ____D C:\ProgramData\Realtek
2026-04-24 05:59 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-04-24 05:59 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-04-24 05:58 - 2024-11-23 11:10 - 000034894 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-04-24 05:57 - 2024-11-24 13:30 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2026-04-24 05:57 - 2024-11-23 11:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-04-24 05:57 - 2024-11-21 14:58 - 000012288 ___SH C:\DumpStack.log.tmp
2026-04-24 05:56 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-04-24 05:47 - 2024-11-23 12:23 - 000000000 ____D C:\Users\13918
2026-04-24 05:26 - 2025-01-25 20:54 - 000002324 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2026-04-24 05:26 - 2025-01-25 20:54 - 000002283 _____ C:\Users\Public\Desktop\Brave.lnk
2026-04-24 05:26 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-04-23 18:26 - 2026-01-18 19:49 - 000001272 _____ C:\Users\13918\Desktop\ESET Online Scanner.lnk
2026-04-23 18:26 - 2026-01-18 19:48 - 000001378 _____ C:\Users\13918\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2026-04-23 09:01 - 2025-01-30 16:04 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3331464132-3830428412-573898847-1001
2026-04-23 09:01 - 2024-11-23 12:38 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3331464132-3830428412-573898847-1001
2026-04-23 09:01 - 2024-11-23 12:38 - 000003354 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3331464132-3830428412-573898847-1001
2026-04-23 09:01 - 2024-11-23 12:38 - 000002379 _____ C:\Users\13918\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-04-22 12:26 - 2024-11-23 13:54 - 000000000 ____D C:\Users\13918\AppData\Roaming\calibre
2026-04-22 12:25 - 2024-11-23 15:02 - 000000000 ____D C:\Users\13918\AppData\Roaming\Microsoft\Excel
2026-04-22 09:13 - 2024-11-23 12:28 - 000000000 ____D C:\Users\13918\AppData\Local\D3DSCache
2026-04-21 16:25 - 2024-11-23 15:03 - 000000000 ____D C:\Users\13918\AppData\Roaming\Microsoft\Šablony
2026-04-21 16:14 - 2024-11-23 13:54 - 000000000 ____D C:\Users\13918\AppData\Local\calibre-cache
2026-04-21 07:25 - 2024-11-23 13:48 - 000004442 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1732362534
2026-04-21 07:25 - 2024-11-23 13:48 - 000004160 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1732362534
2026-04-21 07:25 - 2024-11-23 13:48 - 000001386 _____ C:\Users\13918\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2026-04-20 19:05 - 2024-11-23 12:27 - 000000000 ____D C:\Users\13918\AppData\Local\AMD
2026-04-20 12:42 - 2025-12-15 13:48 - 000000000 ____D C:\Games
2026-04-18 13:39 - 2025-12-03 18:35 - 000000000 ____D C:\Users\13918\Downloads\Návody
2026-04-18 07:50 - 2024-11-23 11:10 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-04-17 07:51 - 2024-11-23 17:04 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-04-17 07:48 - 2024-11-23 17:03 - 218249592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-04-16 08:27 - 2024-11-23 12:27 - 000000000 ____D C:\Users\13918\AppData\Local\ConnectedDevicesPlatform
2026-04-16 08:14 - 2024-11-23 11:08 - 000477304 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-04-16 08:09 - 2025-07-13 13:29 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-04-16 08:09 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-04-16 08:09 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\SysWOW64\cs
2026-04-16 08:09 - 2024-04-01 18:28 - 000000000 ____D C:\WINDOWS\system32\cs
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-plocm
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-ploc
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\et-EE
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\am-ET
2026-04-16 08:09 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\DiagTrack
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-04-16 08:08 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-04-16 08:08 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-04-16 08:03 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2026-04-16 08:02 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2026-04-16 07:57 - 2026-03-01 18:47 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-04-16 07:57 - 2026-03-01 18:47 - 000002021 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2026-04-15 05:49 - 2026-01-14 13:55 - 003268096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-04-13 09:29 - 2024-11-23 13:54 - 000000000 ____D C:\Users\13918\Knihovna Calibre
2026-04-11 13:23 - 2024-11-23 11:10 - 000003714 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{0837D2A0-ECF5-4CBE-9D10-4DE5E7257372}
2026-04-11 13:23 - 2024-11-23 11:10 - 000003588 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{8C3F1172-25A0-45DA-98A8-4F099FCED7E3}
2026-04-10 05:38 - 2024-11-23 11:09 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-04-02 08:35 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2026-04-01 13:39 - 2026-03-15 08:57 - 000000000 ____D C:\Users\13918\Desktop\Moje fotky
2026-04-01 13:06 - 2024-11-21 14:07 - 000000000 ____D C:\Users\13918\Desktop\Foto dle roků
2026-03-27 18:16 - 2026-02-21 12:36 - 013308584 _____ C:\Users\13918\Desktop\Seznam knih.xlsx
2026-03-27 17:18 - 2024-11-23 11:08 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Addition
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-04-2026
Ran by 13918 (24-04-2026 06:15:19)
Running from C:\Users\13918\AppData\Local\Temp\scoped_dir7088_522007211
Microsoft Windows 11 Home Version 25H2 26200.8246 (X64) (2024-11-23 09:29:53)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
13918 (S-1-5-21-3331464132-3830428412-573898847-1001 - Administrators - Enabled) => C:\Users\13918
Administrator (S-1-5-21-3331464132-3830428412-573898847-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-3331464132-3830428412-573898847-503 - Limited - Disabled)
Guest (S-1-5-21-3331464132-3830428412-573898847-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3331464132-3830428412-573898847-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 26.001.21431 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 147.1.89.143 - Autoři prohlížeče Brave)
calibre 64bit (HKLM\...\{BFFEE51E-090E-4563-B344-1D0FAA3EC295}) (Version: 8.15.0 - Kovid Goyal)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 147.0.3912.84 - Microsoft Corporation)
CPUID CPU-Z MSI 2.09 (HKLM\...\CPUID CPU-Z MSI_is1) (Version: 2.09 - CPUID, Inc.)
Dropbox Redeem Launcher (HKLM-x32\...\{D606A7F3-60CF-47A8-97D8-46849E8BFFFE}}_is1) (Version: 1.0.0.04 - MSI)
Dynamic Application Loader Host Interface Service (HKLM\...\{FE08EA18-3549-49F1-8F5D-01F176DCE1CC}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.4.11 - Seiko Epson Corporation)
Epson Event Manager (HKLM-x32\...\{A3BFF401-11D7-4EAF-805C-118B4170604F}) (Version: 3.11.82 - Seiko Epson Corporation)
EPSON L3250 Series Printer Uninstall (HKLM\...\EPSON L3250 Series) (Version: - Seiko Epson Corporation)
Epson Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 2.0.4.0 - Seiko Epson Corporation)
Epson Photo+ (HKLM-x32\...\{6E9CEE8F-5CA9-44EC-8495-79418D1BD434}) (Version: 4.0.0.0 - Seiko Epson Corporation)
Epson Printer Connection Checker (HKLM-x32\...\{781FE583-2E59-4304-83F2-C229E5F61C2A}) (Version: 3.4.3.0 - Seiko Epson Corporation)
Epson Printer Driver Security Support Tool (HKLM-x32\...\{2395000B-DF3F-40E1-8D49-E73341296948}) (Version: 1.0.1.0 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version: - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{C37347BC-7549-47A6-8E7A-806A6751981E}) (Version: 3.00.06 - Seiko Epson Corporation)
EPSON Scan PDF Extensions (HKLM-x32\...\{E4C6B326-8218-4FC2-8B48-85A19DAB3AE4}) (Version: 1.03.02.01 - Seiko Epson Corporation)
Epson ScanSmart (HKLM-x32\...\{8D3E35BD-10F6-42A9-8F4D-F9BE5F51D477}) (Version: 3.7.17 - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\...\{946E5AD1-584A-4830-BA1B-BEA47E1D549F}) (Version: 5.0.2 - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{DB5EDF09-A7A7-47FA-B365-A7500A472878}) (Version: 3.3.1.0 - Seiko Epson Corporation)
Intel(R) Chipset Device Software (HKLM\...\{BAB97289-552B-49D5-B1E7-95DB4E4D2DEF}) (Version: 10.1.19627.8423 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{f48aa9ec-42b9-428a-8536-42b3a4b738c8}) (Version: 10.1.19627.8423 - Intel(R) Corporation)
Intel(R) LMS (HKLM\...\{6A2335AD-315C-4ADD-BFFC-0C7D0FC8A2B9}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{11107004-9658-44DB-8E95-2ECAFAE17B7B}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2201.16.0.2645 - Intel Corporation)
Intel(R) Management Engine Driver (HKLM\...\{7F7FEA98-7076-40EE-A318-07C48E67385F}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Serial IO (HKLM\...\{8EC4CB19-850D-4BD4-B914-F63DF7DAD67D}) (Version: 30.100.2131.26 - Intel Corporation) Hidden
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.2131.26 - Intel Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 147.0.3912.72 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 147.0.3912.72 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\OneDriveSetup.exe) (Version: 26.055.0323.0004 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34433 (HKLM-x32\...\{804e7d66-ccc2-4c12-84ba-476da31d103d}) (Version: 14.42.34433.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34433 (HKLM-x32\...\{e7802eac-3305-4da0-9378-e55d1ed05518}) (Version: 14.42.34433.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34433 (HKLM\...\{E1902FC6-C423-4719-AB8A-AC7B2694B367}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34433 (HKLM\...\{382F1166-A409-4C5B-9B1E-85ED538B8291}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34433 (HKLM-x32\...\{84E3E712-6343-484B-8B6C-9F145F019A70}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34433 (HKLM-x32\...\{C2BB95AA-90F3-4891-81C1-A7E565BB836C}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
MSI Center SDK (HKLM-x32\...\{15289038-41BE-48F8-B8B9-0B1021D3089E}}_is1) (Version: 3.2024.1114.01 - MSI)
Opera Stable 130.0.5847.41 (HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\Opera 130.0.5847.41) (Version: 130.0.5847.41 - Opera Software)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9757.1 - Realtek Semiconductor Corp.)
Údržba Samsung CLP-320 Series (HKLM-x32\...\Samsung CLP-320 Series) (Version: - Samsung Electronics Co., Ltd.)
Uninstall Samsung Printer Software (HKLM-x32\...\TotalUninstaller) (Version: 4.0.0.93 - Samsung Electronics CO., LTD.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
Wargaming.net Game Center (HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\Wargaming.net Game Center) (Version: 26.1.1.2050 - Wargaming.net)
WinRAR 6.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH)
Wolfenstein verze 1.0 (HKLM-x32\...\{A3E7F37D-2057-4768-A2B5-C8557169F9EF}_is1) (Version: 1.0 - )
World of Tanks EU (HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\2314027414) (Version: - Wargaming.net)
Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-11] ()
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets [2026-04-16] ()
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2024-11-24] (Microsoft Corp.)
MSI Center -> C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSICenter_2.0.68.0_x64__kzh8wxbdkxb8p [2026-04-01] (MICRO-STAR INTERNATIONAL CO., LTD) [Startup Task]
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.53.383.0_x64__dt26b99r8h8gj [2026-02-18] (Realtek Semiconductor Corp)
WinAppRuntime.Main.1.8 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.8_8000.806.2252.0_x64__8wekyb3d8bbwe [2026-04-01] (Microsoft Corp.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> "C:\Program Files\ESET\ESET Security\egui.exe" -ToastActivated => No File
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2210608 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-02-17] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [MidisrvTransferComplete] => 1
HKLM\...\Drivers32: [midi1] => C:\WINDOWS\system32\wdmaud2.drv [143360 2026-04-15] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Drivers32: [midi1] => C:\Windows\SysWOW64\wdmaud2.drv [94720 2026-04-15] (Microsoft Windows -> Microsoft Corporation)
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2024-11-23 14:43 - 2021-09-21 06:02 - 000237568 _____ (Seiko Epson Corporation) [File not signed] C:\WINDOWS\System32\E_YLMBYWE.DLL
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{75416E63-5912-4DFA-AE8F-3EFACCAFFB14} => ""="NvmeDisk"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{75416E63-5912-4DFA-AE8F-3EFACCAFFB14} => ""="NvmeDisk"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\samsungsetup.com -> hxxp://www.samsungsetup.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 ____N C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 10.0.0.138
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Intel(R) Ethernet Connection (17) I219-V -> e1d.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\Control Panel\Desktop\\Wallpaper ->
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "EPPCCMON"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "EEventManager"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKLM\...\StartupApproved\Run32: => "Samsung PanelMgr"
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\StartupApproved\Run: => "EPLTarget\P0000000000000000"
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_B92492922E84AF6C06A72D733262D31A"
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\StartupApproved\Run: => "Opera Stable"
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\...\StartupApproved\Run: => "Wargaming.net Game Center"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{F5224FE4-AD4E-460F-A5B6-782FE2D67A32}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [{0BC9C825-15A6-4283-A951-6E964739366C}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [{C2CA242C-F63C-4DCD-8B39-C57C3AEC826D}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [{81CED1E6-0D67-4545-AEC1-A7223E2E6E74}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [TCP Query User{598BCDF1-648C-4142-943E-86298FEE20FA}C:\users\13918\appdata\local\programs\opera\opera.exe] => (Block) C:\users\13918\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{C8BBB4DD-B318-4D51-BF6C-A6AB317D77AA}C:\users\13918\appdata\local\programs\opera\opera.exe] => (Block) C:\users\13918\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [TCP Query User{02FD9619-6AC2-44F3-9E4F-CD260D14FD34}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{15107285-23E4-4EA6-BF93-A2B39764A4B5}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [TCP Query User{33ED17AD-25B4-496B-B7FF-0C72E296EC4D}C:\users\13918\appdata\local\programs\opera\opera.exe] => (Block) C:\users\13918\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{EC088434-E9D2-4F0F-A705-F0E5D2E757A9}C:\users\13918\appdata\local\programs\opera\opera.exe] => (Block) C:\users\13918\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [TCP Query User{0F02941F-735A-4E12-AFB5-EF6C687F9660}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{DB4691C9-794C-49DD-AA16-EAB9428006A8}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [{CCE94D59-A770-4653-9E3B-F472E5E58E18}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
FirewallRules: [{9013847B-0BA6-47E8-89C9-9FE28E985D9A}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
FirewallRules: [TCP Query User{CBD6D345-0401-4616-A5E7-6F613AEDDE0E}C:\users\13918\desktop\hry\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\hry\age of empires 2 cz!!!!\empires2.exe (Microsoft Corporation) [File not signed]
FirewallRules: [UDP Query User{F66517A2-A9EC-4770-BBDB-30C8EEC01B3B}C:\users\13918\desktop\hry\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\hry\age of empires 2 cz!!!!\empires2.exe (Microsoft Corporation) [File not signed]
FirewallRules: [TCP Query User{3B7E6C2A-FD06-4B0E-B1EF-4879591B8DF5}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{569419BC-684B-42AD-8EC2-E84ADBCBEEF6}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [TCP Query User{B86EF33A-6F29-4E7D-AD7A-66985339C282}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [UDP Query User{7240FE28-7344-43B8-B643-C93F691BE00A}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
FirewallRules: [{8528F3AA-8AD1-48C6-ABFD-548F21E64CC1}] => (Allow) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
FirewallRules: [{44507F1B-E809-4CA1-BB55-9EC4B1521085}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D6174C38-C662-4E5D-8702-19E4A4AF0655}] => (Allow) LPort=32683
FirewallRules: [{490BA301-2546-4421-9E77-6095F826F598}] => (Allow) LPort=33683
FirewallRules: [{8E5FE52B-C26E-4A2F-81B6-A8554007321C}] => (Allow) LPort=26822
==================== Restore Points =========================
01-04-2026 07:01:11 Windows Update
06-04-2026 20:21:11 Windows Update
06-04-2026 20:21:11 Windows Update
09-04-2026 21:11:50 Windows Update
13-04-2026 05:56:11 Windows Update
13-04-2026 05:56:11 Windows Update
15-04-2026 05:40:25 Instalační služba modulů systému Windows
18-04-2026 07:46:31 Windows Update
22-04-2026 08:26:15 Windows Update
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (04/24/2026 05:59:51 AM) (Source: Application Error) (EventID: 1000) (User: MSI)
Description: Název chybující aplikace: StartMenuExperienceHost.exe, verze: 10.0.26100.8115, časové razítko: 0x36a2c273
Název chybujícího modulu: ntdll.dll, verze: 10.0.26100.8246, časové razítko: 0xf7576e9e
Kód výjimky: 0xc0000374
Posun chyby: 0x0000000000117555
ID chybujícího procesu: 0x1f38
Čas spuštění chybující aplikace: 0x1dcd39ec20201c4
Cesta k chybující aplikaci: C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID sestavy: 8eca31ac-3bd9-469f-967b-c4902aa4d859
Celý název chybujícího balíčku: Microsoft.Windows.StartMenuExperienceHost_10.0.26100.4768_neutral_neutral_cw5n1h2txyewy
ID chybující aplikace relativní vzhledem k balíčku: FullTrustApp
Error: (04/24/2026 05:47:05 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1512) (User: NT AUTHORITY)
Description: Systém Windows nemůže uvolnit soubor registru. Nebyla uvolněna paměť používaná registrem. Tento problém je často způsoben tím, že jsou služby spuštěny pomocí uživatelského účtu. Zkuste služby konfigurovat pro spuštění pomocí účtu místní nebo síťové služby.
PODROBNOSTI – Přístup byl odepřen.
Error: (04/24/2026 05:47:05 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1512) (User: NT AUTHORITY)
Description: Systém Windows nemůže uvolnit soubor registru. Nebyla uvolněna paměť používaná registrem. Tento problém je často způsoben tím, že jsou služby spuštěny pomocí uživatelského účtu. Zkuste služby konfigurovat pro spuštění pomocí účtu místní nebo síťové služby.
PODROBNOSTI – Přístup byl odepřen.
Error: (04/24/2026 05:33:26 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1512) (User: NT AUTHORITY)
Description: Systém Windows nemůže uvolnit soubor registru. Nebyla uvolněna paměť používaná registrem. Tento problém je často způsoben tím, že jsou služby spuštěny pomocí uživatelského účtu. Zkuste služby konfigurovat pro spuštění pomocí účtu místní nebo síťové služby.
PODROBNOSTI – Přístup byl odepřen.
Error: (04/24/2026 05:33:26 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1512) (User: NT AUTHORITY)
Description: Systém Windows nemůže uvolnit soubor registru. Nebyla uvolněna paměť používaná registrem. Tento problém je často způsoben tím, že jsou služby spuštěny pomocí uživatelského účtu. Zkuste služby konfigurovat pro spuštění pomocí účtu místní nebo síťové služby.
PODROBNOSTI – Přístup byl odepřen.
Error: (04/23/2026 04:28:31 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1512) (User: NT AUTHORITY)
Description: Systém Windows nemůže uvolnit soubor registru. Nebyla uvolněna paměť používaná registrem. Tento problém je často způsoben tím, že jsou služby spuštěny pomocí uživatelského účtu. Zkuste služby konfigurovat pro spuštění pomocí účtu místní nebo síťové služby.
PODROBNOSTI – Přístup byl odepřen.
Error: (04/23/2026 04:28:31 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1512) (User: NT AUTHORITY)
Description: Systém Windows nemůže uvolnit soubor registru. Nebyla uvolněna paměť používaná registrem. Tento problém je často způsoben tím, že jsou služby spuštěny pomocí uživatelského účtu. Zkuste služby konfigurovat pro spuštění pomocí účtu místní nebo síťové služby.
PODROBNOSTI – Přístup byl odepřen.
Error: (04/23/2026 08:55:04 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: Uživatelský podregistr načetl jiný proces (zámek registru). Název procesu: C:\Windows\System32\svchost.exe, identifikátor PID: 6632, identifikátor PID ProfSvc: 2188.
System errors:
=============
Error: (04/24/2026 06:02:51 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)
Description: Updated Secure Boot certificates are available on this device but have not yet been applied to the firmware. Review the published guidance to complete the update and maintain full protection. This device signature information is included here.
DeviceAttributes: BaseBoardManufacturer:Micro-Star International Co., Ltd.;FirmwareManufacturer:American Megatrends International, LLC.;FirmwareVersion:1.H0;OEMModelBaseBoard:PRO H610M-G DDR4 (MS-7D46);OEMManufacturerName:Micro-Star International Co., Ltd.;OSArchitecture:amd64;
BucketId: 95b044e23a63487aedc8df38002fa3c17868015b35add5bea76c92ab28e6817e
BucketConfidenceLevel: Under Observation - More Data Needed
UpdateType:
For more information, please see https://go.microsoft.com/fwlink/?linkid=2301018.
Error: (04/24/2026 06:00:03 AM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3502) (User: NT AUTHORITY)
Description: Zrušení přidružení zařízení (zrušení párování) se nezdařilo.
Error: (04/24/2026 05:57:48 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba DgiVecp neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.
Error: (04/24/2026 05:56:13 AM) (Source: DCOM) (EventID: 10005) (User: MSI)
Description: Služba DCOM zjistila chybu 1084 při pokusu o spuštění služby ShellHWDetection s argumenty Není k dispozici za účelem spuštění serveru:
{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (04/24/2026 05:55:57 AM) (Source: DCOM) (EventID: 10005) (User: MSI)
Description: Služba DCOM zjistila chybu 1084 při pokusu o spuštění služby ShellHWDetection s argumenty Není k dispozici za účelem spuštění serveru:
{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (04/24/2026 05:54:03 AM) (Source: DCOM) (EventID: 10005) (User: MSI)
Description: Služba DCOM zjistila chybu 1084 při pokusu o spuštění služby TokenBroker s argumenty Není k dispozici za účelem spuštění serveru:
Windows.Internal.Security.Authentication.Web.TokenBrokerInternal
Error: (04/24/2026 05:53:58 AM) (Source: DCOM) (EventID: 10005) (User: MSI)
Description: Služba DCOM zjistila chybu 1084 při pokusu o spuštění služby netprofm s argumenty Není k dispozici za účelem spuštění serveru:
{A47979D2-C419-11D9-A5B4-001185AD2B89}
Error: (04/24/2026 05:53:56 AM) (Source: DCOM) (EventID: 10005) (User: MSI)
Description: Služba DCOM zjistila chybu 1084 při pokusu o spuštění služby TokenBroker s argumenty Není k dispozici za účelem spuštění serveru:
Windows.Internal.Security.Authentication.Web.WamProviderRegistration
Error: (04/18/2026 03:24:38 PM) (Source: disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR4.
Error: (04/08/2026 06:29:51 PM) (Source: disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR17.
Error: (04/08/2026 06:29:49 PM) (Source: disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR17.
Error: (04/06/2026 08:31:33 PM) (Source: disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk2\DR14 má chybný blok.
Error: (04/06/2026 08:31:31 PM) (Source: disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk2\DR14 má chybný blok.
Error: (04/06/2026 08:31:28 PM) (Source: disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk2\DR14 má chybný blok.
Error: (04/06/2026 08:31:26 PM) (Source: disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk2\DR14 má chybný blok.
Error: (04/06/2026 08:31:23 PM) (Source: disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk2\DR14 má chybný blok.
Windows Defender:
================
Date: 2026-04-23 09:12:43
Description:
Antivirová ochrana v programu Microsoft Defender ŝςал ĥäѕ ъέзй šŧŏφφзδ ъ℮ƒǿŕě ĉόmрℓ℮ţįσń.%η %τŚçāл İĐ:%в{FB696C4C-1BB7-4C92-8FDD-9A88430C8F05}%ň %τŞĉąл Τўφέ:%ъAntimalwarový program%ή %ŧЅĉάп Рαґάмεťзřş:%вRychlé prohledávání%ņ %ťŲŝзґ:%ьNT AUTHORITY\SYSTEM%ň %тŜτόφ Ŗздšóñ:%ъЅċћêďùℓêð šςāņ ẃάš ѕķįррέð ъέĉąύšě ŧħє ŀäѕŧ śџć¢éŝѕƒũℓ şčãň ώăѕ ωîŧћίŋ ŧĥë ŀāşτ 7 ðåýŝ
Date: 2026-04-22 08:52:46
Description:
Antivirová ochrana v programu Microsoft Defender ŝςал ĥäѕ ъέзй šŧŏφφзδ ъ℮ƒǿŕě ĉόmрℓ℮ţįσń.%η %τŚçāл İĐ:%в{41CD5CE0-E9AB-403A-9205-D5DEC62C53CA}%ň %τŞĉąл Τўφέ:%ъAntimalwarový program%ή %ŧЅĉάп Рαґάмεťзřş:%вRychlé prohledávání%ņ %ťŲŝзґ:%ьNT AUTHORITY\SYSTEM%ň %тŜτόφ Ŗздšóñ:%ъЅċћêďùℓêð šςāņ ẃάš ѕķįррέð ъέĉąύšě ŧħє ŀäѕŧ śџć¢éŝѕƒũℓ şčãň ώăѕ ωîŧћίŋ ŧĥë ŀāşτ 7 ðåýŝ
Date: 2026-04-21 09:15:57
Description:
Antivirová ochrana v programu Microsoft Defender ŝςал ĥäѕ ъέзй šŧŏφφзδ ъ℮ƒǿŕě ĉόmрℓ℮ţįσń.%η %τŚçāл İĐ:%в{1CD88251-D656-4F49-8435-03878B139146}%ň %τŞĉąл Τўφέ:%ъAntimalwarový program%ή %ŧЅĉάп Рαґάмεťзřş:%вRychlé prohledávání%ņ %ťŲŝзґ:%ьNT AUTHORITY\SYSTEM%ň %тŜτόφ Ŗздšóñ:%ъЅċћêďùℓêð šςāņ ẃάš ѕķįррέð ъέĉąύšě ŧħє ŀäѕŧ śџć¢éŝѕƒũℓ şčãň ώăѕ ωîŧћίŋ ŧĥë ŀāşτ 7 ðåýŝ
Date: 2026-04-20 09:10:57
Description:
Antivirová ochrana v programu Microsoft Defender ŝςал ĥäѕ ъέзй šŧŏφφзδ ъ℮ƒǿŕě ĉόmрℓ℮ţįσń.%η %τŚçāл İĐ:%в{C20257F0-9C54-49C5-819B-8413B2295F1B}%ň %τŞĉąл Τўφέ:%ъAntimalwarový program%ή %ŧЅĉάп Рαґάмεťзřş:%вRychlé prohledávání%ņ %ťŲŝзґ:%ьNT AUTHORITY\SYSTEM%ň %тŜτόφ Ŗздšóñ:%ъЅċћêďùℓêð šςāņ ẃάš ѕķįррέð ъέĉąύšě ŧħє ŀäѕŧ śџć¢éŝѕƒũℓ şčãň ώăѕ ωîŧћίŋ ŧĥë ŀāşτ 7 ðåýŝ
Date: 2026-04-18 14:12:07
Description:
Antivirová ochrana v programu Microsoft Defender ŝςал ĥäѕ ъέзй šŧŏφφзδ ъ℮ƒǿŕě ĉόmрℓ℮ţįσń.%η %τŚçāл İĐ:%в{C17C6B59-37E8-4E01-A8E2-3B967CEE6E3D}%ň %τŞĉąл Τўφέ:%ъAntimalwarový program%ή %ŧЅĉάп Рαґάмεťзřş:%вRychlé prohledávání%ņ %ťŲŝзґ:%ьNT AUTHORITY\SYSTEM%ň %тŜτόφ Ŗздšóñ:%ъŖΡĆ ćøñⁿēčŧϊσл ѓúπďôши
Event[0]
Date: 2026-04-24 05:52:54
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2026-04-24 05:48:23
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2026-01-14 12:55:10
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Systém kontroly sítě
Kód chyby: 0x80004005
Popis chyby: Nespecifikovaná chyba
Důvod: V systému chybí aktualizace potřebné ke spuštění systému kontroly sítě. Nainstalujte potřebné aktualizace a restartujte zařízení.
Date: 2025-12-23 22:59:42
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Systém kontroly sítě
Kód chyby: 0x80004005
Popis chyby: Nespecifikovaná chyba
Důvod: V systému chybí aktualizace potřebné ke spuštění systému kontroly sítě. Nainstalujte potřebné aktualizace a restartujte zařízení.
Date: 2025-12-23 20:11:31
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.441.497.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.25100.9002
Kód chyby: 0x80240022
Popis chyby: V daném programu nelze zkontrolovat aktualizace definic.
CodeIntegrity:
===============
Date: 2025-12-23 20:10:11
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends International, LLC. 1.H0 03/26/2024
Motherboard: Micro-Star International Co., Ltd. PRO H610M-G DDR4 (MS-7D46)
Processor: 12th Gen Intel(R) Core(TM) i5-12400F
Percentage of memory in use: 19%
Total physical RAM: 32621.28 MB
Available physical RAM: 26314.29 MB
Total Virtual: 34669.28 MB
Available Virtual: 27746.65 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.65 GB) (Free:689.71 GB) (Model: ST1000DM003-1CH162) NTFS
\\?\Volume{d45cead4-be5f-49e5-abce-ffa08a6ee0c7}\ () (Fixed) (Total:0.75 GB) (Free:0.09 GB) NTFS
\\?\Volume{ecf3ce6e-656e-4e80-8e8a-612a9d020f99}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 73736572)
Partition: GPT.
==================== End of Addition.txt =======================

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
chodím i na nezabezpečený web
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin

- Příspěvky: 119867
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: chodím i na nezabezpečený web
Zdravím!
Otevřte poznámkový blok a zkopírujte do něj:
Otevřte poznámkový blok a zkopírujte do něj:
Uložte do C:\Users\13918\AppData\Local\Temp\scoped_dir7088_522007211 jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
Task: {D12A084C-630D-49B3-BCF2-19A315EA7C45} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe /bg /scheduledHC (No File)
S3 ose; "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (No File)
S2 DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
CustomCLSID: HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> "C:\Program Files\ESET\ESET Security\egui.exe" -ToastActivated => No File
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\Control Panel\Desktop\\Wallpaper ->
FirewallRules: [{F5224FE4-AD4E-460F-A5B6-782FE2D67A32}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [{0BC9C825-15A6-4283-A951-6E964739366C}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [TCP Query User{02FD9619-6AC2-44F3-9E4F-CD260D14FD34}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{15107285-23E4-4EA6-BF93-A2B39764A4B5}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [TCP Query User{0F02941F-735A-4E12-AFB5-EF6C687F9660}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{DB4691C9-794C-49DD-AA16-EAB9428006A8}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [{CCE94D59-A770-4653-9E3B-F472E5E58E18}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
FirewallRules: [{9013847B-0BA6-47E8-89C9-9FE28E985D9A}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
EmptyTemp:
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: chodím i na nezabezpečený web
Nemám soubor: scoped dir7088_522007211, mám jen: scoped_dir8360_1739101516
- Rudy
- Site Admin

- Příspěvky: 119867
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: chodím i na nezabezpečený web
To je váš problém, že jste si stažení nenasměroval někam jinam. Směrovat ho do dočasných souborů, je pitomost. Lze to nastavit v prohlížeči. Pokud FRST najdete, přesuňte ho na plochu. Potom na plochu přesuňte i soubor fixlist.txt a spusťte. Problém je totiž v tomn, že fixlkist musí být ve stejném adresáři, jako je FRST, jinak to nefunguje. Pokud FRST nenajdete, stáhněte ho znovu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: chodím i na nezabezpečený web
Omlouvám se a posílám log.
Fix result of Farbar Recovery Scan Tool (x64) Version: 24-04-2026
Ran by 13918 (24-04-2026 23:16:10) Run:1
Running from C:\Users\13918\Desktop\Frst
Loaded Profiles: 13918
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
Task: {D12A084C-630D-49B3-BCF2-19A315EA7C45} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe /bg /scheduledHC (No File)
S3 ose; "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (No File)
S2 DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
CustomCLSID: HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> "C:\Program Files\ESET\ESET Security\egui.exe" -ToastActivated => No File
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\Control Panel\Desktop\\Wallpaper ->
FirewallRules: [{F5224FE4-AD4E-460F-A5B6-782FE2D67A32}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [{0BC9C825-15A6-4283-A951-6E964739366C}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [TCP Query User{02FD9619-6AC2-44F3-9E4F-CD260D14FD34}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{15107285-23E4-4EA6-BF93-A2B39764A4B5}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [TCP Query User{0F02941F-735A-4E12-AFB5-EF6C687F9660}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{DB4691C9-794C-49DD-AA16-EAB9428006A8}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [{CCE94D59-A770-4653-9E3B-F472E5E58E18}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
FirewallRules: [{9013847B-0BA6-47E8-89C9-9FE28E985D9A}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D12A084C-630D-49B3-BCF2-19A315EA7C45}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D12A084C-630D-49B3-BCF2-19A315EA7C45}" => removed successfully
C:\WINDOWS\System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001" => removed successfully
HKLM\System\CurrentControlSet\Services\ose => removed successfully
ose => service removed successfully
HKLM\System\CurrentControlSet\Services\DgiVecp => removed successfully
DgiVecp => service removed successfully
Could not move "C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268} => removed successfully
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\Control Panel\Desktop\\Wallpaper -> => Error: No automatic fix found for this entry.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F5224FE4-AD4E-460F-A5B6-782FE2D67A32}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0BC9C825-15A6-4283-A951-6E964739366C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{02FD9619-6AC2-44F3-9E4F-CD260D14FD34}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{15107285-23E4-4EA6-BF93-A2B39764A4B5}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0F02941F-735A-4E12-AFB5-EF6C687F9660}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DB4691C9-794C-49DD-AA16-EAB9428006A8}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CCE94D59-A770-4653-9E3B-F472E5E58E18}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9013847B-0BA6-47E8-89C9-9FE28E985D9A}" => removed successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 1487497175 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 266207229 B
Edge => 308301161 B
Brave => 1438315034 B
Firefox => 0 B
Opera => 717635383 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 112115 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 112318 B
13918 => 143747265 B
RecycleBin => 4894720 B
EmptyTemp: => 4.1 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 24-04-2026 23:23:34)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
==== End of Fixlog 23:23:35 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 24-04-2026
Ran by 13918 (24-04-2026 23:16:10) Run:1
Running from C:\Users\13918\Desktop\Frst
Loaded Profiles: 13918
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
Task: {D12A084C-630D-49B3-BCF2-19A315EA7C45} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe /bg /scheduledHC (No File)
S3 ose; "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (No File)
S2 DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
CustomCLSID: HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> "C:\Program Files\ESET\ESET Security\egui.exe" -ToastActivated => No File
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\Control Panel\Desktop\\Wallpaper ->
FirewallRules: [{F5224FE4-AD4E-460F-A5B6-782FE2D67A32}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [{0BC9C825-15A6-4283-A951-6E964739366C}] => (Allow) C:\Users\13918\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\Data\ENEasyApp.exe => No File
FirewallRules: [TCP Query User{02FD9619-6AC2-44F3-9E4F-CD260D14FD34}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{15107285-23E4-4EA6-BF93-A2B39764A4B5}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Allow) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [TCP Query User{0F02941F-735A-4E12-AFB5-EF6C687F9660}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [UDP Query User{DB4691C9-794C-49DD-AA16-EAB9428006A8}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe] => (Block) C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe => No File
FirewallRules: [{CCE94D59-A770-4653-9E3B-F472E5E58E18}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
FirewallRules: [{9013847B-0BA6-47E8-89C9-9FE28E985D9A}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe => No File
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D12A084C-630D-49B3-BCF2-19A315EA7C45}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D12A084C-630D-49B3-BCF2-19A315EA7C45}" => removed successfully
C:\WINDOWS\System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-3331464132-3830428412-573898847-1001" => removed successfully
HKLM\System\CurrentControlSet\Services\ose => removed successfully
ose => service removed successfully
HKLM\System\CurrentControlSet\Services\DgiVecp => removed successfully
DgiVecp => service removed successfully
Could not move "C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
HKU\S-1-5-21-3331464132-3830428412-573898847-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268} => removed successfully
HKU\S-1-5-21-3331464132-3830428412-573898847-1001\Control Panel\Desktop\\Wallpaper -> => Error: No automatic fix found for this entry.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F5224FE4-AD4E-460F-A5B6-782FE2D67A32}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0BC9C825-15A6-4283-A951-6E964739366C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{02FD9619-6AC2-44F3-9E4F-CD260D14FD34}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{15107285-23E4-4EA6-BF93-A2B39764A4B5}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0F02941F-735A-4E12-AFB5-EF6C687F9660}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DB4691C9-794C-49DD-AA16-EAB9428006A8}C:\users\13918\desktop\age of empires 2 cz!!!!\empires2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CCE94D59-A770-4653-9E3B-F472E5E58E18}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9013847B-0BA6-47E8-89C9-9FE28E985D9A}" => removed successfully
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 1487497175 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 266207229 B
Edge => 308301161 B
Brave => 1438315034 B
Firefox => 0 B
Opera => 717635383 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 112115 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 112318 B
13918 => 143747265 B
RecycleBin => 4894720 B
EmptyTemp: => 4.1 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 24-04-2026 23:23:34)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
==== End of Fixlog 23:23:35 ====
- Rudy
- Site Admin

- Příspěvky: 119867
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: chodím i na nezabezpečený web
Smazáno, log je již OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?