
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola logu , proces system.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Kontrola logu , proces system.
Dobrý den proces systém ve windows 11 žere cca 10% CPU nikdy tolik CPU nežral v nouzovém režimu žere 0-0,1CPU. Prosím o kontrolu logu. Děkuji.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-02-2025
Ran by Jirka (05-02-2025 07:16:58)
Running from C:\Users\Jirka\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.2894 (X64) (2025-01-10 11:41:56)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2544418961-404871699-1754985800-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2544418961-404871699-1754985800-503 - Limited - Disabled)
Guest (S-1-5-21-2544418961-404871699-1754985800-501 - Limited - Disabled)
Jirka (S-1-5-21-2544418961-404871699-1754985800-1001 - Administrator - Enabled) => C:\Users\Jirka
WDAGUtilityAccount (S-1-5-21-2544418961-404871699-1754985800-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Aplikace NVIDIA 11.0.1.189 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.1.189 - NVIDIA Corporation)
Blender (HKLM\...\{DE735DFE-88BD-4470-A889-605A6D86B037}) (Version: 4.3.2 - Blender Foundation)
Canon Laser Printer/Scanner/Fax Extended Survey Program (HKLM\...\{8A16FF47-A5FC-49A8-96B5-31180D317059}) (Version: 3.0.4 - CANON INC.) Hidden
Canon Laser Printer/Scanner/Fax Extended Survey Program (HKLM\...\Canon Laser Printer/Scanner/Fax Extended Survey Program) (Version: 3.0.4.40070 - CANON INC.)
Canon MF4700 Series (HKLM\...\{47A8DB42-4E21-4d55-9931-D4F44CC3F03B}) (Version: 4.1.0.1 - CANON INC.)
Kontrola stavu osobního počítače s Windows (HKLM\...\{7DED818B-F556-4115-9CC0-ACE3F614CE63}) (Version: 4.0.2410.23001 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 132.0.2957.140 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 132.0.2957.140 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\OneDriveSetup.exe) (Version: 24.244.1204.0003 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.31301 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.22.27821 (HKLM\...\{6E2C7A8E-B17A-4637-9CE9-F0B1157CF378}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.22.27821 (HKLM\...\{0093C20C-273D-4397-B623-515CB8616CB9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.22.27821 (HKLM-x32\...\{3BDE80F7-7EC9-448E-8160-4ADA0CDA8879}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.22.27821 (HKLM-x32\...\{1E6FC929-567E-4D22-9206-C5B83F0A21B9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 128.6.0 - Mozilla)
Mozilla Thunderbird (x64 cs) (HKLM\...\Mozilla Thunderbird 128.6.0 (x64 cs)) (Version: 128.6.0 - Mozilla)
NVIDIA FrameView SDK 1.4.10624.35034762 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.4.10624.35034762 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.4.2.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.2.6 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 566.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 566.36 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
NVIDIA USBC Driver 1.52.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.52.831.832 - NVIDIA Corporation)
Opera Stable 116.0.5366.71 (HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Opera 116.0.5366.71) (Version: 116.0.5366.71 - Opera Software)
PDF-XChange PRO V6 (HKLM\...\{E9A303EA-87D9-4F28-83DA-73D79D05687B}) (Version: 6.0.322.7 - Tracker Software Products (Canada) Ltd.) Hidden
PDF-XChange PRO V6 (HKLM-x32\...\{19930704-143e-4dd8-99b0-98196c7006c7}) (Version: 6.0.322.7 - Tracker Software Products (Canada) Ltd.)
PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: - Jan Fiala)
Revo Uninstaller Pro 5.3.5 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.3.5 - VS Revo Group, Ltd.)
Room Arranger (32-bit) (HKLM-x32\...\Room Arranger) (Version: 9.6.0 - Jan Adamec)
Room Arranger (64-bit) (HKLM-x32\...\Room Arranger x64) (Version: 10.0.1 - Jan Adamec)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 11.50 - Ghisler Software GmbH)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_CZ_is1) (Version: 19.1707.2.30 - ZONER software)
Packages:
=========
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-02-05] (INTEL CORP) [Startup Task]
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2025-02-05] (Microsoft Corp.)
Microsoft.StartExperiencesApp -> C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.235.0_x64__8wekyb3d8bbwe [2025-02-05] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2025-02-05] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.51.353.0_x64__dt26b99r8h8gj [2025-02-05] (Realtek Semiconductor Corp)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2544418961-404871699-1754985800-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.24.31301\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2544418961-404871699-1754985800-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender 4.3\BlendThumb.dll (Stichting Blender Foundation -> )
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2210608 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [PDFXChange Editor Context menu] -> {2ACD35AB-F74A-4C20-AA9B-2DE80081626D} => C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
ContextMenuHandlers1-x32: [PSPad] -> {8903F6C9-25E3-40AC-A98F-E6D35CD0469C} => C:\Program Files (x86)\PSPad editor\PSPadShell.dll [2006-05-14] () [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\nvshext.dll [2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2022-04-04] (VS Revo Group Ltd. -> VS Revo Group)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNCENPM6.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO-x32: PDF-XChange V6 IE Plugin -> {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} -> C:\Program Files\Tracker Software\PDF-XChange 6\PXCIEAddin6.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM-x32 - PDF-XChange V6 IE Plugin - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 6\PXCIEAddin6.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2022-05-07 06:24 - 2025-01-22 08:37 - 000000851 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 account.zoner.com
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jirka\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\2644427204408557525\133832083544593637.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
Network Binding:
=============
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Ethernet: Realtek PCIe GbE Family Controller -> rtcx21x64.sys
Wi-Fi: Intel(R) Wi-Fi 6 AX201 160MHz -> Netwtw10.sys
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_9351DC8C75826C8A9C791E0FFD3CBFF5"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "Opera Stable"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{0E051944-08A1-49A1-8019-AA6668DABDEF}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AF896278-19B7-4C8C-9194-459D239CD42A}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C242D955-AF1A-40CD-82A6-F41407A8E668}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9F661240-55DD-4983-B060-583676A6EE66}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{E34A0FFD-5F55-473F-855F-444869709013}C:\users\jirka\appdata\local\programs\opera\opera.exe] => (Block) C:\users\jirka\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{28D0F73F-CADE-4A06-A887-881C3C973D68}C:\users\jirka\appdata\local\programs\opera\opera.exe] => (Block) C:\users\jirka\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{5DFFD2DC-9E4F-4FF3-9F69-3F0B0ACE2604}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\132.0.2957.140\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CDB9394B-F031-4E04-83EE-D7EDB5379753}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25007.607.3371.8436_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C71DB1FB-851C-48D6-B30D-0F4619A6DE29}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25007.607.3371.8436_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
22-01-2025 08:39:28 Revo Uninstaller Pro's restore point - zps9_cz
24-01-2025 13:50:58 Instalační služba modulů systému Windows
24-01-2025 13:52:24 Instalační služba modulů systému Windows
27-01-2025 15:52:20 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 15:52:49 Odebráno: CorelDRAW Graphics Suite 12
27-01-2025 15:58:13 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 16:01:36 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 16:02:02 Odebráno: CorelDRAW Graphics Suite 12
03-02-2025 09:02:26 Windows Update
03-02-2025 09:02:26 Windows Update
03-02-2025 09:02:27 Windows Update
==================== Faulty Device Manager Devices ============
Name: Canon MF4700 Series
Description: Canon MF4700 Series
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Canon
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: ========================
Application errors:
==================
Error: (02/05/2025 07:01:24 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(47ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (02/05/2025 06:50:48 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(32ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (02/05/2025 06:50:41 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4544,R,98,0) SRUJet: Při otevírání souboru protokolu C:\WINDOWS\system32\SRU\SRU00930.log došlo k chybě -1811 (0xfffff8ed).
Error: (02/04/2025 06:02:56 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(62ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (01/30/2025 07:01:51 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-99A8H9S)
Description: Název chybující aplikace: ZPS.EXE, verze: 19.1707.2.30, časové razítko: 0x596c9879
Název chybujícího modulu: Zxl.dll, verze: 19.1707.2.30, časové razítko: 0x596c973f
Kód výjimky: 0xc000041d
Posun chyby: 0x00000000004302f4
ID chybujícího procesu: 0x4b98
Čas spuštění chybující aplikace: 0x1db72db8943ca17
Cesta k chybující aplikaci: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\ZPS.EXE
Cesta k chybujícímu modulu: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\Zxl.dll
ID sestavy: ceab9cae-617e-4b18-a83a-1e58b7f9a652
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (01/30/2025 07:01:48 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-99A8H9S)
Description: Název chybující aplikace: ZPS.EXE, verze: 19.1707.2.30, časové razítko: 0x596c9879
Název chybujícího modulu: Zxl.dll, verze: 19.1707.2.30, časové razítko: 0x596c973f
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000004302f4
ID chybujícího procesu: 0x4b98
Čas spuštění chybující aplikace: 0x1db72db8943ca17
Cesta k chybující aplikaci: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\ZPS.EXE
Cesta k chybujícímu modulu: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\Zxl.dll
ID sestavy: 1a422d43-c829-4408-85ad-0f8b518b370d
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (01/27/2025 04:01:35 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen..To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.
Operace:
Shromažďování dat modulu pro zápis
Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {2594e2ff-058f-44c3-a65a-04db19292ec8}
Error: (01/27/2025 04:01:10 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(15ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
System errors:
=============
Error: (02/05/2025 07:14:57 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DESKTOP-99A8H9S)
Description: 0x8000002a32\??\C:\FRST\t8Ro3Dh1Ss3\SOFTWARE
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HECI Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Display Container LS byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Realtek Audio Universal Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Nahimic service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 3000 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HDCP Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Windows Defender:
================
Date: 2025-02-03 13:05:22
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {31E27872-BFEF-49DB-A81E-A715512966AC}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2025-02-03 09:06:38
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {FE85833E-D3F1-4C54-8BB2-4A1DAE67E989}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2025-01-29 17:50:12
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6C7707CE-1FE7-45C4-8BE5-CECC29ECDC8C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2025-01-28 19:11:18
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {2018DDAE-E77C-4941-8A03-5CD26B0B1445}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Vlastní prohledávání
Uživatel: DESKTOP-99A8H9S\Jirka
Date: 2025-01-28 18:59:12
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6F56AF5C-62D3-4C47-BD0B-48499EE294E3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Event[0]
Date: 2025-02-05 07:00:11
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-02-05 06:54:50
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-02-05 06:50:48
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací a pokusí se o obnovení na předchozí verzi.
Bezpečnostní informace, které se měly načíst: Aktuální
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu.
Verze bezpečnostních informací: 0.0.0.0;0.0.0.0
Verze modulu: 0.0.0.0
Date: 2025-01-11 07:19:34
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.421.1304.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24090.11
Kód chyby: 0x80080005
Popis chyby: Provádění serveru selhalo
CodeIntegrity:
===============
Date: 2025-02-05 07:14:10
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3e62be9c39fb0007\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. E17E7IMS.10C 11/17/2020
Motherboard: Micro-Star International Co., Ltd. MS-17E7
Processor: Intel(R) Core(TM) i7-10750H CPU @ 2.60GHz
Percentage of memory in use: 12%
Total physical RAM: 65356.14 MB
Available physical RAM: 57407.98 MB
Total Virtual: 75084.14 MB
Available Virtual: 67008.89 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.7 GB) (Free:823.01 GB) (Model: ADATA LEGEND 800) NTFS
Drive d: (Nový svazek) (Fixed) (Total:894.24 GB) (Free:573.75 GB) (Model: KINGSTON SA400S37960G) NTFS
\\?\Volume{1d84a99c-f4b3-490f-ba93-42859908be14}\ () (Fixed) (Total:0.69 GB) (Free:0.15 GB) NTFS
\\?\Volume{2f47f9ec-2cc4-472b-848f-659395f523c4}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 894.3 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-02-2025
Ran by Jirka (05-02-2025 07:16:58)
Running from C:\Users\Jirka\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.2894 (X64) (2025-01-10 11:41:56)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2544418961-404871699-1754985800-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2544418961-404871699-1754985800-503 - Limited - Disabled)
Guest (S-1-5-21-2544418961-404871699-1754985800-501 - Limited - Disabled)
Jirka (S-1-5-21-2544418961-404871699-1754985800-1001 - Administrator - Enabled) => C:\Users\Jirka
WDAGUtilityAccount (S-1-5-21-2544418961-404871699-1754985800-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Aplikace NVIDIA 11.0.1.189 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.1.189 - NVIDIA Corporation)
Blender (HKLM\...\{DE735DFE-88BD-4470-A889-605A6D86B037}) (Version: 4.3.2 - Blender Foundation)
Canon Laser Printer/Scanner/Fax Extended Survey Program (HKLM\...\{8A16FF47-A5FC-49A8-96B5-31180D317059}) (Version: 3.0.4 - CANON INC.) Hidden
Canon Laser Printer/Scanner/Fax Extended Survey Program (HKLM\...\Canon Laser Printer/Scanner/Fax Extended Survey Program) (Version: 3.0.4.40070 - CANON INC.)
Canon MF4700 Series (HKLM\...\{47A8DB42-4E21-4d55-9931-D4F44CC3F03B}) (Version: 4.1.0.1 - CANON INC.)
Kontrola stavu osobního počítače s Windows (HKLM\...\{7DED818B-F556-4115-9CC0-ACE3F614CE63}) (Version: 4.0.2410.23001 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 132.0.2957.140 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 132.0.2957.140 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\OneDriveSetup.exe) (Version: 24.244.1204.0003 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.31301 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.22.27821 (HKLM\...\{6E2C7A8E-B17A-4637-9CE9-F0B1157CF378}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.22.27821 (HKLM\...\{0093C20C-273D-4397-B623-515CB8616CB9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.22.27821 (HKLM-x32\...\{3BDE80F7-7EC9-448E-8160-4ADA0CDA8879}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.22.27821 (HKLM-x32\...\{1E6FC929-567E-4D22-9206-C5B83F0A21B9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 128.6.0 - Mozilla)
Mozilla Thunderbird (x64 cs) (HKLM\...\Mozilla Thunderbird 128.6.0 (x64 cs)) (Version: 128.6.0 - Mozilla)
NVIDIA FrameView SDK 1.4.10624.35034762 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.4.10624.35034762 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.4.2.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.2.6 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 566.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 566.36 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
NVIDIA USBC Driver 1.52.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.52.831.832 - NVIDIA Corporation)
Opera Stable 116.0.5366.71 (HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Opera 116.0.5366.71) (Version: 116.0.5366.71 - Opera Software)
PDF-XChange PRO V6 (HKLM\...\{E9A303EA-87D9-4F28-83DA-73D79D05687B}) (Version: 6.0.322.7 - Tracker Software Products (Canada) Ltd.) Hidden
PDF-XChange PRO V6 (HKLM-x32\...\{19930704-143e-4dd8-99b0-98196c7006c7}) (Version: 6.0.322.7 - Tracker Software Products (Canada) Ltd.)
PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: - Jan Fiala)
Revo Uninstaller Pro 5.3.5 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.3.5 - VS Revo Group, Ltd.)
Room Arranger (32-bit) (HKLM-x32\...\Room Arranger) (Version: 9.6.0 - Jan Adamec)
Room Arranger (64-bit) (HKLM-x32\...\Room Arranger x64) (Version: 10.0.1 - Jan Adamec)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 11.50 - Ghisler Software GmbH)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_CZ_is1) (Version: 19.1707.2.30 - ZONER software)
Packages:
=========
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-02-05] (INTEL CORP) [Startup Task]
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2025-02-05] (Microsoft Corp.)
Microsoft.StartExperiencesApp -> C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.235.0_x64__8wekyb3d8bbwe [2025-02-05] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2025-02-05] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.51.353.0_x64__dt26b99r8h8gj [2025-02-05] (Realtek Semiconductor Corp)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2544418961-404871699-1754985800-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.24.31301\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2544418961-404871699-1754985800-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender 4.3\BlendThumb.dll (Stichting Blender Foundation -> )
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2210608 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [PDFXChange Editor Context menu] -> {2ACD35AB-F74A-4C20-AA9B-2DE80081626D} => C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
ContextMenuHandlers1-x32: [PSPad] -> {8903F6C9-25E3-40AC-A98F-E6D35CD0469C} => C:\Program Files (x86)\PSPad editor\PSPadShell.dll [2006-05-14] () [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\nvshext.dll [2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2022-04-04] (VS Revo Group Ltd. -> VS Revo Group)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNCENPM6.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO-x32: PDF-XChange V6 IE Plugin -> {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} -> C:\Program Files\Tracker Software\PDF-XChange 6\PXCIEAddin6.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM-x32 - PDF-XChange V6 IE Plugin - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 6\PXCIEAddin6.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2022-05-07 06:24 - 2025-01-22 08:37 - 000000851 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 account.zoner.com
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jirka\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\2644427204408557525\133832083544593637.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
Network Binding:
=============
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Ethernet: Realtek PCIe GbE Family Controller -> rtcx21x64.sys
Wi-Fi: Intel(R) Wi-Fi 6 AX201 160MHz -> Netwtw10.sys
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_9351DC8C75826C8A9C791E0FFD3CBFF5"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "Opera Stable"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{0E051944-08A1-49A1-8019-AA6668DABDEF}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AF896278-19B7-4C8C-9194-459D239CD42A}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C242D955-AF1A-40CD-82A6-F41407A8E668}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9F661240-55DD-4983-B060-583676A6EE66}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{E34A0FFD-5F55-473F-855F-444869709013}C:\users\jirka\appdata\local\programs\opera\opera.exe] => (Block) C:\users\jirka\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{28D0F73F-CADE-4A06-A887-881C3C973D68}C:\users\jirka\appdata\local\programs\opera\opera.exe] => (Block) C:\users\jirka\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{5DFFD2DC-9E4F-4FF3-9F69-3F0B0ACE2604}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\132.0.2957.140\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CDB9394B-F031-4E04-83EE-D7EDB5379753}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25007.607.3371.8436_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C71DB1FB-851C-48D6-B30D-0F4619A6DE29}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25007.607.3371.8436_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
22-01-2025 08:39:28 Revo Uninstaller Pro's restore point - zps9_cz
24-01-2025 13:50:58 Instalační služba modulů systému Windows
24-01-2025 13:52:24 Instalační služba modulů systému Windows
27-01-2025 15:52:20 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 15:52:49 Odebráno: CorelDRAW Graphics Suite 12
27-01-2025 15:58:13 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 16:01:36 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 16:02:02 Odebráno: CorelDRAW Graphics Suite 12
03-02-2025 09:02:26 Windows Update
03-02-2025 09:02:26 Windows Update
03-02-2025 09:02:27 Windows Update
==================== Faulty Device Manager Devices ============
Name: Canon MF4700 Series
Description: Canon MF4700 Series
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Canon
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: ========================
Application errors:
==================
Error: (02/05/2025 07:01:24 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(47ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (02/05/2025 06:50:48 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(32ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (02/05/2025 06:50:41 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4544,R,98,0) SRUJet: Při otevírání souboru protokolu C:\WINDOWS\system32\SRU\SRU00930.log došlo k chybě -1811 (0xfffff8ed).
Error: (02/04/2025 06:02:56 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(62ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (01/30/2025 07:01:51 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-99A8H9S)
Description: Název chybující aplikace: ZPS.EXE, verze: 19.1707.2.30, časové razítko: 0x596c9879
Název chybujícího modulu: Zxl.dll, verze: 19.1707.2.30, časové razítko: 0x596c973f
Kód výjimky: 0xc000041d
Posun chyby: 0x00000000004302f4
ID chybujícího procesu: 0x4b98
Čas spuštění chybující aplikace: 0x1db72db8943ca17
Cesta k chybující aplikaci: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\ZPS.EXE
Cesta k chybujícímu modulu: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\Zxl.dll
ID sestavy: ceab9cae-617e-4b18-a83a-1e58b7f9a652
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (01/30/2025 07:01:48 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-99A8H9S)
Description: Název chybující aplikace: ZPS.EXE, verze: 19.1707.2.30, časové razítko: 0x596c9879
Název chybujícího modulu: Zxl.dll, verze: 19.1707.2.30, časové razítko: 0x596c973f
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000004302f4
ID chybujícího procesu: 0x4b98
Čas spuštění chybující aplikace: 0x1db72db8943ca17
Cesta k chybující aplikaci: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\ZPS.EXE
Cesta k chybujícímu modulu: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\Zxl.dll
ID sestavy: 1a422d43-c829-4408-85ad-0f8b518b370d
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (01/27/2025 04:01:35 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen..To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.
Operace:
Shromažďování dat modulu pro zápis
Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {2594e2ff-058f-44c3-a65a-04db19292ec8}
Error: (01/27/2025 04:01:10 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:
GetCACaps
Metoda: GET(15ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
System errors:
=============
Error: (02/05/2025 07:14:57 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DESKTOP-99A8H9S)
Description: 0x8000002a32\??\C:\FRST\t8Ro3Dh1Ss3\SOFTWARE
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HECI Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Display Container LS byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Realtek Audio Universal Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Nahimic service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 3000 milisekund: Restartovat službu.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HDCP Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Windows Defender:
================
Date: 2025-02-03 13:05:22
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {31E27872-BFEF-49DB-A81E-A715512966AC}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2025-02-03 09:06:38
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {FE85833E-D3F1-4C54-8BB2-4A1DAE67E989}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2025-01-29 17:50:12
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6C7707CE-1FE7-45C4-8BE5-CECC29ECDC8C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Date: 2025-01-28 19:11:18
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {2018DDAE-E77C-4941-8A03-5CD26B0B1445}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Vlastní prohledávání
Uživatel: DESKTOP-99A8H9S\Jirka
Date: 2025-01-28 18:59:12
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6F56AF5C-62D3-4C47-BD0B-48499EE294E3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Event[0]
Date: 2025-02-05 07:00:11
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-02-05 06:54:50
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.
Date: 2025-02-05 06:50:48
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací a pokusí se o obnovení na předchozí verzi.
Bezpečnostní informace, které se měly načíst: Aktuální
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu.
Verze bezpečnostních informací: 0.0.0.0;0.0.0.0
Verze modulu: 0.0.0.0
Date: 2025-01-11 07:19:34
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.421.1304.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24090.11
Kód chyby: 0x80080005
Popis chyby: Provádění serveru selhalo
CodeIntegrity:
===============
Date: 2025-02-05 07:14:10
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3e62be9c39fb0007\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. E17E7IMS.10C 11/17/2020
Motherboard: Micro-Star International Co., Ltd. MS-17E7
Processor: Intel(R) Core(TM) i7-10750H CPU @ 2.60GHz
Percentage of memory in use: 12%
Total physical RAM: 65356.14 MB
Available physical RAM: 57407.98 MB
Total Virtual: 75084.14 MB
Available Virtual: 67008.89 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.7 GB) (Free:823.01 GB) (Model: ADATA LEGEND 800) NTFS
Drive d: (Nový svazek) (Fixed) (Total:894.24 GB) (Free:573.75 GB) (Model: KINGSTON SA400S37960G) NTFS
\\?\Volume{1d84a99c-f4b3-490f-ba93-42859908be14}\ () (Fixed) (Total:0.69 GB) (Free:0.15 GB) NTFS
\\?\Volume{2f47f9ec-2cc4-472b-848f-659395f523c4}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 894.3 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
- Rudy
- Site Admin
- Příspěvky: 119309
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu , proces system.
Zdravím!
Potřebuji vidět ještě log FRST (toto je Addition). Najdete ho v C:\Users\Jirka\Downloads frst.txt. Děkuji.
Potřebuji vidět ještě log FRST (toto je Addition). Najdete ho v C:\Users\Jirka\Downloads frst.txt. Děkuji.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu , proces system.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-02-2025
Ran by Jirka (administrator) on DESKTOP-99A8H9S (Micro-Star International Co., Ltd. GL75 Leopard 10SDR) (10-02-2025 15:50:08)
Running from C:\Users\Jirka\Downloads\FRST64.exe
Loaded Profiles: Jirka
Platform: Microsoft Windows 11 Pro Version 24H2 26100.2894 (X64) Language: Čeština (Česko)
Default browser: "C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(A-Volute SAS -> A-Volute) C:\Windows\System32\NhNotifSys.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Jirka\AppData\Local\Programs\Opera\116.0.5366.71\opera_crashreporter.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe <96>
(explorer.exe ->) (Prog-Soft s.r.o.) [File not signed] C:\Program Files (x86)\PSPad editor\PSPad.exe
(explorer.exe ->) (ZONER software, a.s. -> ZONER software) C:\Program Files\Zoner\Photo Studio 19\Program64\Zps.exe
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2410.21.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe <3>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <2>
(services.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_629847df3bb3f110\RtkAudUService64.exe <2>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22301.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22301.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_629847df3bb3f110\RtkAudUService64.exe [2375128 2024-12-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [486552 2012-09-27] (CANON INC. -> CANON INC.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation) [File not signed]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [MicrosoftEdgeAutoLaunch_9351DC8C75826C8A9C791E0FFD3CBFF5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3923496 2025-01-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [Opera Stable] => C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe [1622424 2025-02-03] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [Opera Browser Assistant] => C:\Users\Jirka\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4459928 2025-01-08] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation) [File not signed]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" [84027432 2025-02-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Uninstall 24.244.1204.0003\i386] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\24.244.1204.0003\i386" [0 2025-02-10] () <==== ATTENTION [zero byte File/Folder]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Uninstall 24.244.1204.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\24.244.1204.0003" [131072 2025-02-10] () [File not signed]
HKLM\...\Print\Monitors\Canon MFNP Port: C:\WINDOWS\system32\CNCENPM6.dll [152064 2012-09-26] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon WSD Language Monitor: C:\WINDOWS\system32\cnnx0_flm.dll [1420800 2013-02-25] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\CPCA Language Monitor3b: C:\WINDOWS\system32\CNAS0MOK.DLL [1006080 2012-08-09] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\PDF-XChange6: C:\WINDOWS\system32\pxc60pm.dll [59072 2017-01-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
Startup: C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RuntimeBroker.lnk [2025-01-21]
ShortcutTarget: RuntimeBroker.lnk -> C:\Users\Jirka\AppData\Roaming\Corel User Preferences\Backup files\CorelDRAW Graphics Suite 2021.exe (Corel Corporation) [File not signed]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {FD6D0C94-7015-4FC2-83EE-38497361643B} - System32\Tasks\Canon\OIPPESP\Canon OIP Product Extended Survey Program => C:\Program Files\Canon\OIPPESP\Cnpspcnt.exe [1826264 2020-07-29] (CANON INC. -> CANON INC.) -> /Config:"C:\Program Files\Canon\OIPPESP\CnpspCfg.xml"
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {C812530A-F87D-41DA-9070-C99599522F67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2AE149A9-97AC-4BF4-97F5-C4ECA91DAC6C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {38309FF9-F793-4797-98BD-44D26870505C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BE18E8D2-9E8D-45C8-973F-710300A7E985} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FFFCF6BA-0475-4438-AC46-2A9E50641AA7} - System32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA app.exe [3287080 2025-01-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {61295927-FC13-46A6-A4B2-93DC805E5E29} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2544418961-404871699-1754985800-1001 => C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\25.005.0112.0003\OneDriveLauncher.exe [447032 2025-02-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {736214A3-83E2-4312-92DD-D4FAF391CDD8} - System32\Tasks\Opera scheduled assistant Autoupdate 1736584659 => C:\Users\Jirka\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5656472 2025-01-28] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --bypasslauncher --installdir="C:\Users\Jirka\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {01B7D443-7B2B-4354-84AC-624F8F3E489D} - System32\Tasks\Opera scheduled Autoupdate 1736584655 => C:\Users\Jirka\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5656472 2025-01-28] (Opera Norway AS -> Opera Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 0.0.0.0 account.zoner.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{10624d03-044f-4dff-84d3-d5a7d1626de5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{10624d03-044f-4dff-84d3-d5a7d1626de5}\24C65746F667963656E65647: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3746ef48-1b44-4fe5-b84a-0abba4de1340}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{3746ef48-1b44-4fe5-b84a-0abba4de1340}: [DhcpDomain] axad.cz
Edge:
=======
Edge Profile: C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default [2025-02-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-01-11]
Edge Extension: (Edge relevant text changes) - C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-11]
FireFox:
========
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2544418961-404871699-1754985800-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1888424 2021-10-08] (A-Volute SAS -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\Display.NvContainer\NVDisplay.Container.exe [1275568 2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559304 2025-01-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 MpKslbef2cdcb; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4B2576B4-0DFC-4698-A319-1F809B7E6132}\MpKslDrv.sys [267552 2025-02-10] (Microsoft Windows -> Microsoft Corporation)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [94784 2022-06-03] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22104 2025-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [606624 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105888 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-02-10 14:56 - 2025-02-10 14:56 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-05 15:24 - 2025-02-05 15:24 - 000001875 _____ C:\Users\Jirka\Downloads\Klicenka.svg
2025-02-05 15:13 - 2025-02-05 15:51 - 000000000 ____D C:\Users\Jirka\Desktop\Zetfa_web
2025-02-05 08:30 - 2025-02-05 15:56 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2025-02-05 08:20 - 2025-02-05 08:20 - 000000782 _____ C:\Users\Jirka\Desktop\Plocha 2025 – zástupce.lnk
2025-02-05 07:16 - 2025-02-05 07:17 - 000030033 _____ C:\Users\Jirka\Downloads\Addition.txt
2025-02-05 07:14 - 2025-02-10 15:50 - 000017118 _____ C:\Users\Jirka\Downloads\FRST.txt
2025-02-05 07:14 - 2025-02-10 15:50 - 000000000 ____D C:\FRST
2025-02-05 07:08 - 2025-02-05 07:08 - 008790880 _____ (Malwarebytes) C:\Users\Jirka\Downloads\adwcleaner (1).exe
2025-02-05 07:08 - 2025-02-05 07:08 - 000678362 _____ C:\WINDOWS\system32\perfh005.dat
2025-02-05 07:08 - 2025-02-05 07:08 - 000145178 _____ C:\WINDOWS\system32\perfc005.dat
2025-02-05 07:08 - 2025-02-05 07:08 - 000000000 ____D C:\AdwCleaner
2025-02-05 07:05 - 2025-02-05 07:05 - 008790880 _____ (Malwarebytes) C:\Users\Jirka\Downloads\AdwCleaner.exe
2025-02-05 07:05 - 2025-02-05 07:05 - 002403328 _____ (Farbar) C:\Users\Jirka\Downloads\FRST64.exe
2025-02-05 06:54 - 2025-02-05 07:00 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-02-05 06:54 - 2025-02-05 06:54 - 000000000 ____D C:\WINDOWS\pss
2025-02-05 06:25 - 2025-02-05 06:25 - 000000000 ____D C:\Users\Jirka\AppData\Local\OneDrive
2025-01-30 11:46 - 2025-01-30 11:46 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\HTML Help
2025-01-30 10:35 - 2025-01-30 10:35 - 000000110 ____H C:\Users\Jirka\Downloads\as.46554565.jpg.uid-zps
2025-01-30 10:21 - 2025-01-30 10:21 - 000025638 _____ C:\Users\Jirka\Downloads\01 (1).webp
2025-01-30 10:20 - 2025-01-30 10:20 - 000025638 _____ C:\Users\Jirka\Downloads\01.webp
2025-01-30 10:10 - 2025-01-30 10:10 - 000000110 ____H C:\Users\Jirka\Downloads\istockphoto-1458223077-1024x1024.jpg.uid-zps
2025-01-30 10:08 - 2025-01-30 10:08 - 000000110 ____H C:\Users\Jirka\Downloads\istockphoto-515906629-1024x1024.jpg.uid-zps
2025-01-30 09:18 - 2025-01-30 09:18 - 000011052 _____ C:\Users\Jirka\Documents\Byt Karel Demel.xlsx
2025-01-29 19:21 - 2022-09-30 05:24 - 000174112 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2025-01-29 19:21 - 2022-09-30 05:24 - 000050720 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ss_conn_usb_driver2.sys
2025-01-29 19:20 - 2022-09-30 05:23 - 000167440 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus2.sys
2025-01-29 19:05 - 2025-01-29 19:05 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2025-01-29 17:40 - 2025-01-29 17:40 - 000011007 _____ C:\Users\Jirka\Documents\Oprava kanalizace _Gis - stavinvex a,s.xlsx
2025-01-29 16:45 - 2025-01-29 16:44 - 000010581 _____ C:\Users\Jirka\Documents\Kraftova_odpady.xlsx
2025-01-29 07:14 - 2025-01-29 07:15 - 1042927416 _____ (NVIDIA Corporation) C:\Users\Jirka\Downloads\Canvas1.4.311.exe
2025-01-28 07:21 - 2025-01-28 07:21 - 000000000 ____D C:\Users\Jirka\AppData\LocalLow\NVIDIA
2025-01-28 07:21 - 2025-01-28 07:21 - 000000000 ____D C:\Users\Jirka\ansel
2025-01-28 07:20 - 2025-02-05 08:18 - 000000000 ____D C:\Users\Jirka\AppData\Local\NVIDIA Corporation
2025-01-28 07:19 - 2025-02-05 08:18 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-01-28 07:19 - 2025-02-05 08:18 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-01-28 07:19 - 2025-02-05 06:49 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2025-01-28 07:19 - 2025-01-28 07:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-25 13:25 - 003108904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 002398760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 000271912 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 000245800 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-01-28 07:19 - 2025-01-25 13:05 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-01-28 07:19 - 2025-01-25 13:05 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 002060664 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 002060664 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001600376 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001600376 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001452432 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001452432 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001301880 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001301880 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 000478384 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 000374432 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 001114792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 000670352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 000505504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 025450120 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-01-28 07:16 - 2024-12-04 19:01 - 001554608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 001208992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 000863888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-01-28 07:16 - 2024-12-04 19:00 - 016811696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 002185360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 001634464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 001042072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 000801432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 000462480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-01-28 07:16 - 2024-12-04 18:59 - 017736840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 006953104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 005909664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 005435544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 003807888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 000853680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-01-28 07:16 - 2024-12-04 18:58 - 007158560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-01-28 07:16 - 2024-12-04 18:58 - 006236264 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-01-28 07:16 - 2024-12-04 02:11 - 000132703 _____ C:\WINDOWS\system32\nvinfo.pb
2025-01-28 07:16 - 2024-12-04 02:11 - 000125048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2025-01-28 07:16 - 2024-11-26 08:17 - 000059928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2025-01-28 07:03 - 2025-01-28 07:04 - 732914600 _____ (NVIDIA Corporation) C:\Users\Jirka\Downloads\566.36-notebook-win10-win11-64bit-international-dch-whql.exe
2025-01-28 05:33 - 2025-01-28 05:33 - 000000000 ____D C:\Users\Jirka\Downloads\CorelDRAW Graphics Suite 2023 v24 x64 Multilingual (Pre-Activated)
2025-01-27 16:19 - 2025-01-29 16:44 - 000010581 _____ C:\Users\Jirka\Documents\Žilina podlahy.xlsx
2025-01-27 16:10 - 2025-01-27 17:53 - 1867303969 _____ C:\Users\Jirka\Downloads\CorelDRAW Graphics Suite 2023 v24 x64 Multilingual (Pre-Activated).zip
2025-01-27 15:51 - 2025-01-30 07:01 - 000000000 ____D C:\Users\Jirka\AppData\Local\CrashDumps
2025-01-27 15:42 - 2025-01-27 15:42 - 000000539 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prace.lnk
2025-01-26 09:56 - 2025-01-26 09:56 - 000010153 _____ C:\Users\Jirka\Documents\Ventilátor Ostrava.xlsx
2025-01-24 13:53 - 2025-01-24 13:53 - 000000000 ____D C:\Users\Jirka\AppData\LocalLow\Temp
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ___HD C:\WINDOWS\system32\CanonMF Uninstaller Information
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\ProgramData\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\Program Files\Canon
2025-01-24 09:56 - 2025-01-24 09:56 - 000000000 ____D C:\Users\Jirka\Downloads\MF4700MFDriverV4101WPEN
2025-01-24 09:56 - 2012-09-26 14:02 - 000195584 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPR6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNCENPM6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPM6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000105984 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPU6.dll
2025-01-24 09:56 - 2009-06-11 22:47 - 000017861 _____ C:\WINDOWS\system32\CNCENPMK.chm
2025-01-24 07:50 - 2025-01-24 07:50 - 000862582 _____ C:\Users\Jirka\Documents\priloha_1451506360_0_2024-23874.pdf
2025-01-22 15:11 - 2025-01-22 15:12 - 000000000 ____D C:\Users\Jirka\Downloads\ipnetinfo_czech
2025-01-22 15:11 - 2025-01-22 15:11 - 000063443 _____ C:\Users\Jirka\Downloads\ipnetinfo.zip
2025-01-22 15:10 - 2025-01-22 15:10 - 000001932 _____ C:\Users\Jirka\Downloads\ipnetinfo_czech.zip
2025-01-22 14:55 - 2025-01-22 14:56 - 000000000 ____D C:\Users\Jirka\Downloads\cports_czech
2025-01-22 14:55 - 2025-01-22 14:55 - 000131911 _____ C:\Users\Jirka\Downloads\cports-x64.zip
2025-01-22 14:54 - 2025-01-22 14:54 - 000002863 _____ C:\Users\Jirka\Downloads\cports_czech.zip
2025-01-22 14:04 - 2025-01-22 14:25 - 000000000 ____D C:\dev
2025-01-22 10:01 - 2025-01-22 10:01 - 000057600 _____ C:\Users\Jirka\Downloads\FreeSample-Vectorizer-io-velke-removebg .svg
2025-01-22 09:37 - 2025-01-22 09:37 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\NVIDIA
2025-01-22 08:43 - 2025-01-22 08:43 - 000002031 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Zoner Photo Studio X.lnk
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Zoner
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\Zoner
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\CEF
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Program Files\Zoner
2025-01-22 08:42 - 2025-01-22 08:42 - 000000000 ____D C:\Users\Jirka\AppData\Local\Backup
2025-01-22 08:26 - 2025-01-22 08:26 - 000000000 ____D C:\Users\Jirka\Downloads\Zoner Photo Studio X v19.1707.2.30 (CZ) funkční Crack a návod jak to upravit _-)
2025-01-22 08:16 - 2025-01-22 08:32 - 321529316 _____ C:\Users\Jirka\Downloads\Zoner Photo Studio X.zip
2025-01-22 08:04 - 2025-01-22 08:04 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Corel
2025-01-22 08:02 - 2025-01-22 08:41 - 000767994 _____ C:\Users\Jirka\Downloads\Eco House Realty Logo _ BrandCrowd Logo Maker _ BrandCrowd.pdf
2025-01-21 16:27 - 2025-02-05 06:49 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\GHISLER
2025-01-21 16:27 - 2025-01-21 16:46 - 000000000 ____D C:\Users\Jirka\AppData\Local\GHISLER
2025-01-21 16:27 - 2025-01-21 16:27 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2025-01-21 16:27 - 2025-01-21 16:27 - 000000000 ____D C:\Program Files\totalcmd
2025-01-21 16:26 - 2025-01-21 16:26 - 007016880 _____ (Ghisler Software GmbH) C:\Users\Jirka\Downloads\tcmd1150x64.exe
2025-01-21 12:55 - 2025-01-21 12:55 - 000001278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Program Updates.lnk
2025-01-21 12:42 - 2025-01-27 17:13 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Corel User Preferences
2025-01-20 11:52 - 2025-01-20 11:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Clip Organizer
2025-01-19 07:42 - 2025-01-19 07:42 - 011473496 _____ C:\Users\Jirka\Downloads\Poliigon_MetalSteelBrushed_7174.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 009472341 _____ C:\Users\Jirka\Downloads\fabric_pattern_07_1k.blend.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 005273768 _____ C:\Users\Jirka\Downloads\fabric_leather_02_1k.blend.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 005171753 _____ C:\Users\Jirka\Downloads\fabric_leather_01_1k.blend.zip
2025-01-19 07:33 - 2025-01-19 07:33 - 004977270 _____ C:\Users\Jirka\Downloads\patterned_brick_floor_03_1k.blend.zip
2025-01-19 07:33 - 2025-01-19 07:33 - 004386622 _____ C:\Users\Jirka\Downloads\diagonal_parquet_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:33 - 005679365 _____ C:\Users\Jirka\Downloads\stone_tiles_02_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 005647662 _____ C:\Users\Jirka\Downloads\brick_pavement_02_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 005151850 _____ C:\Users\Jirka\Downloads\square_tiles_03_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 004751833 _____ C:\Users\Jirka\Downloads\granite_tile_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 004574026 _____ C:\Users\Jirka\Downloads\painted_concrete_02_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 005104392 _____ C:\Users\Jirka\Downloads\wood_floor_deck_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 004711431 _____ C:\Users\Jirka\Downloads\concrete_floor_worn_001_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 004170783 _____ C:\Users\Jirka\Downloads\wood_floor_worn_1k.blend.zip
2025-01-19 07:29 - 2025-01-19 07:29 - 080517810 _____ C:\Users\Jirka\Downloads\metal_grate_rusty_4k.blend.zip
2025-01-19 07:29 - 2025-01-19 07:29 - 006524568 _____ C:\Users\Jirka\Downloads\metal_grate_rusty_1k.blend.zip
2025-01-17 15:20 - 2025-01-28 07:19 - 000000000 ____D C:\Users\Jirka\AppData\Local\NVIDIA
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blender
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Blender Foundation
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Local\Blender Foundation
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\.thumbnails
2025-01-17 15:19 - 2025-01-17 15:19 - 000000000 ____D C:\Program Files\Blender Foundation
2025-01-17 15:08 - 2025-01-17 15:08 - 009280994 _____ C:\Users\Jirka\Downloads\3D_outdoorlamp_1.blend
2025-01-17 15:05 - 2025-01-17 15:05 - 005545596 _____ C:\Users\Jirka\Downloads\3D_bench_24.blend
2025-01-17 15:02 - 2025-01-17 15:02 - 002594005 _____ C:\Users\Jirka\Downloads\leopard_skin-1K.zip
2025-01-17 15:02 - 2025-01-17 15:02 - 000000000 ____D C:\Users\Jirka\Downloads\leopard_skin-1K
2025-01-17 15:01 - 2025-01-17 15:01 - 002106339 _____ C:\Users\Jirka\Downloads\wall_stone_1-1K.zip
2025-01-17 15:01 - 2025-01-17 15:01 - 000000000 ____D C:\Users\Jirka\Downloads\wall_stone_1-1K
2025-01-17 14:59 - 2025-01-17 14:59 - 003740902 _____ C:\Users\Jirka\Downloads\stone_wall_8-1K.zip
2025-01-17 14:59 - 2025-01-17 14:59 - 000000000 ____D C:\Users\Jirka\Downloads\stone_wall_8-1K
2025-01-17 14:58 - 2025-01-17 14:58 - 000000000 ____D C:\Users\Jirka\Downloads\colorfull_brick_wall-1K
2025-01-17 14:57 - 2025-01-17 14:57 - 000000000 ____D C:\Users\Jirka\Downloads\brick_wall_11-1K
2025-01-17 14:56 - 2025-01-17 14:56 - 000000000 ____D C:\Users\Jirka\Downloads\red_brick_wall_7-1K
2025-01-17 14:55 - 2025-01-17 14:55 - 003152520 _____ C:\Users\Jirka\Downloads\brick_wall_11-1K.zip
2025-01-17 14:53 - 2025-01-17 14:53 - 003298091 _____ C:\Users\Jirka\Downloads\red_brick_wall_7-1K.zip
2025-01-17 14:52 - 2025-01-17 14:52 - 002060302 _____ C:\Users\Jirka\Downloads\colorfull_brick_wall-1K.zip
2025-01-17 14:47 - 2025-01-17 14:47 - 000000000 ____D C:\Users\Jirka\Downloads\paving_stone-1K
2025-01-17 14:46 - 2025-01-17 14:46 - 003009055 _____ C:\Users\Jirka\Downloads\paving_stone-1K.zip
2025-01-17 14:41 - 2025-01-17 14:41 - 017104379 _____ C:\Users\Jirka\Downloads\woodparquet_122-1K.zip
2025-01-17 14:41 - 2025-01-17 14:41 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_122-1K
2025-01-17 14:26 - 2025-01-17 14:26 - 010500235 _____ C:\Users\Jirka\Downloads\woodparquet_83-1K (1).zip
2025-01-17 14:26 - 2025-01-17 14:26 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_83-1K (1)
2025-01-17 14:23 - 2025-01-17 14:23 - 010500235 _____ C:\Users\Jirka\Downloads\woodparquet_83-1K.zip
2025-01-17 14:23 - 2025-01-17 14:23 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_83-1K
2025-01-17 14:21 - 2025-01-17 14:21 - 001509573 _____ C:\Users\Jirka\Downloads\wooden_ceramic_2-1K.zip
2025-01-17 14:21 - 2025-01-17 14:21 - 000000000 ____D C:\Users\Jirka\Downloads\wooden_ceramic_2-1K
2025-01-17 14:19 - 2025-01-17 14:19 - 000000000 ____D C:\Users\Jirka\Downloads\ground_13-1K
2025-01-17 14:18 - 2025-01-17 14:18 - 007693179 _____ C:\Users\Jirka\Downloads\ground_13-1K.zip
2025-01-17 14:16 - 2025-01-17 14:16 - 010326888 _____ C:\Users\Jirka\Downloads\ground_17-1K.zip
2025-01-17 14:16 - 2025-01-17 14:16 - 000000000 ____D C:\Users\Jirka\Downloads\ground_17-1K
2025-01-17 14:14 - 2025-01-17 14:14 - 003002837 _____ C:\Users\Jirka\Downloads\amethyst_texture_1-1K.zip
2025-01-17 14:14 - 2025-01-17 14:14 - 000000000 ____D C:\Users\Jirka\Downloads\amethyst_texture_1-1K
2025-01-17 14:13 - 2025-01-17 14:13 - 001987391 _____ C:\Users\Jirka\Downloads\fabric_91-1K.zip
2025-01-17 14:13 - 2025-01-17 14:13 - 000000000 ____D C:\Users\Jirka\Downloads\fabric_91-1K
2025-01-16 08:20 - 2025-01-16 08:20 - 000170574 _____ C:\Users\Jirka\Downloads\cabinet-door-open-100526.wav
2025-01-16 08:19 - 2025-01-16 08:19 - 000248910 _____ C:\Users\Jirka\Downloads\open-doors-114615.wav
2025-01-16 08:12 - 2025-01-16 08:12 - 000108366 _____ C:\Users\Jirka\Downloads\paper-clips-80906.wav
2025-01-16 08:05 - 2025-01-16 08:05 - 000001404 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\4K Video to MP3.lnk
2025-01-16 07:13 - 2025-01-16 07:13 - 017937304 _____ (VS Revo Group ) C:\Users\Jirka\Downloads\RevoUninProSetup (1).exe
2025-01-16 07:04 - 2025-01-16 07:04 - 000002977 _____ C:\Users\Jirka\Downloads\uz-463100049108-20240709-071225.xml
2025-01-16 06:45 - 2025-01-16 06:45 - 000886832 _____ (Open Media LLC) C:\Users\Jirka\Downloads\4kvideotomp3_3.0.1_x64_online.exe
2025-01-15 14:06 - 2025-01-15 14:06 - 000000000 ____D C:\Users\Jirka\AppData\Local\PeerDistRepub
2025-01-15 11:53 - 2025-01-15 11:53 - 000028078 _____ C:\Users\Jirka\Downloads\14377_30366-dos-maderas-p-x-10yo-ron-anejo-superior-doble-crianza-40-0-2l (1).webp
2025-01-15 11:28 - 2025-01-15 11:28 - 000028078 _____ C:\Users\Jirka\Downloads\14377_30366-dos-maderas-p-x-10yo-ron-anejo-superior-doble-crianza-40-0-2l.webp
2025-01-15 11:18 - 2025-01-15 11:18 - 000001156 _____ C:\Users\Jirka\Downloads\Kiom UpDown round si.rao
2025-01-15 11:18 - 2025-01-15 11:18 - 000001156 _____ C:\Users\Jirka\Downloads\Kiom UpDown round si (1).rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000267970 _____ C:\Users\Jirka\Downloads\Samsung dbl door fridge.rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000255180 _____ C:\Users\Jirka\Downloads\beer tap - MGD.rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000249466 _____ C:\Users\Jirka\Downloads\amana double door fridge.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000317993 _____ C:\Users\Jirka\Downloads\liqour bottle - Naranja.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000305619 _____ C:\Users\Jirka\Downloads\liqour bottle - Gran Marnier.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000167862 _____ C:\Users\Jirka\Downloads\liqour bottle - whiskey.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000164611 _____ C:\Users\Jirka\Downloads\liqour bottle - gold rum.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000157887 _____ C:\Users\Jirka\Downloads\liqour bottle - vodka.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000110293 _____ C:\Users\Jirka\Downloads\liqour bottle - DM root beer.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000055325 _____ C:\Users\Jirka\Downloads\liqour bottle - Demain cognac.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000022738 _____ C:\Users\Jirka\Downloads\bottle - jaqk wine.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000005628 _____ C:\Users\Jirka\Downloads\Picture by TS.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000042765 _____ C:\Users\Jirka\Downloads\Wall Clocks, Sunflowers 7.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000007263 _____ C:\Users\Jirka\Downloads\Light 2.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000006343 _____ C:\Users\Jirka\Downloads\Lamp 1.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000004070 _____ C:\Users\Jirka\Downloads\Light 1.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000003235 _____ C:\Users\Jirka\Downloads\Light 4.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000001459 _____ C:\Users\Jirka\Downloads\Light 3.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000001458 _____ C:\Users\Jirka\Downloads\Lamp 2.rao
2025-01-15 11:14 - 2025-01-15 11:14 - 000148548 _____ C:\Users\Jirka\Downloads\Gorenje K 28P by BJ.rap
2025-01-15 08:42 - 2025-02-10 15:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-01-15 08:42 - 2025-01-15 08:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\mde
2025-01-15 08:42 - 2025-01-15 08:42 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-01-15 08:32 - 2025-01-15 08:33 - 000000000 ____D C:\WINDOWS\CSC
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ___SD C:\WINDOWS\system32\AppV
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ____D C:\WINDOWS\RemotePackages
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ____D C:\WINDOWS\Containers
2025-01-15 08:08 - 2025-01-15 08:10 - 000373324 _____ C:\Users\Jirka\Downloads\Děkujeme za objednávku - SERVIS-REPAS.CZ.pdf
2025-01-15 06:55 - 2025-01-15 06:55 - 000001345 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2025-01-15 06:55 - 2025-01-15 06:55 - 000000000 ____D C:\Users\Jirka\AppData\Local\PCHealthCheck
2025-01-14 05:58 - 2025-01-14 05:58 - 001413059 _____ C:\Users\Jirka\Downloads\julka-spalna.rap
2025-01-12 07:08 - 2025-01-12 07:08 - 000000848 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RoomAranger.lnk
2025-01-12 06:50 - 2025-01-12 06:50 - 000000000 ____D C:\Users\Jirka\AppData\Local\cache
2025-01-12 06:49 - 2025-01-12 06:49 - 000000000 ____D C:\Program Files\Room Arranger
2025-01-12 06:48 - 2025-01-12 06:48 - 023870896 _____ C:\Users\Jirka\Downloads\rooarr1001_64bit.exe
2025-01-12 06:44 - 2025-01-12 06:44 - 000299993 _____ C:\Users\Jirka\Downloads\Informace-zadost-106_Pr-001_2019-08-02_Info-106-99-MF-18721-2019-48.xlsx
2025-01-12 06:41 - 2025-01-12 06:41 - 000034914 _____ C:\Users\Jirka\Downloads\vzor-2022-zaverecne-vyuctovani-dotace-kopie-210422.xlsx
2025-01-11 16:25 - 2025-01-11 16:25 - 000043853 _____ C:\Users\Jirka\Downloads\externalTemplateLoader-0.4.4.xpi
2025-01-11 14:32 - 2025-01-22 08:41 - 000000000 ____D C:\Users\Jirka\AppData\Local\Room Arranger
2025-01-11 14:32 - 2025-01-11 14:33 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Room Arranger
2025-01-11 14:31 - 2025-01-12 06:49 - 000000888 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Room Arranger.lnk
2025-01-11 14:31 - 2025-01-11 16:58 - 000000000 ____D C:\Users\Jirka\Documents\Room Arranger
2025-01-11 14:31 - 2025-01-11 14:31 - 000000000 ____D C:\ProgramData\Room Arranger
2025-01-11 14:24 - 2025-01-16 13:13 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\UProof
2025-01-11 14:24 - 2025-01-11 14:24 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Proof
2025-01-11 14:23 - 2025-02-05 15:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Word
2025-01-11 14:23 - 2025-02-05 15:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Šablony
2025-01-11 14:23 - 2025-01-11 14:23 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Document Building Blocks
2025-01-11 14:20 - 2025-01-11 14:20 - 000000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2025-01-11 14:17 - 2025-01-11 14:17 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Outlook
2025-01-11 14:16 - 2025-01-30 09:18 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Excel
2025-01-11 14:16 - 2025-01-22 08:08 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Office
2025-01-11 14:16 - 2025-01-11 14:16 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Doplňky
2025-01-11 14:01 - 2025-01-27 16:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\WINDOWS\PCHEALTH
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Works
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2025-01-11 13:59 - 2025-01-11 13:59 - 000000000 ____D C:\Program Files\Microsoft Office
2025-01-11 13:58 - 2025-01-11 14:00 - 000000000 ____D C:\WINDOWS\SHELLNEW
2025-01-11 13:58 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2025-01-11 13:58 - 2025-01-11 13:58 - 000000000 __RHD C:\MSOCache
2025-01-11 13:58 - 2025-01-11 13:58 - 000000000 ____D C:\Users\Jirka\AppData\Local\Microsoft Help
2025-01-11 11:51 - 2025-02-05 15:11 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\PSpad
2025-01-11 11:51 - 2025-01-11 11:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSPad editor
2025-01-11 11:51 - 2025-01-11 11:51 - 000000000 ____D C:\Program Files (x86)\PSPad editor
2025-01-11 10:52 - 2025-01-11 10:52 - 000000696 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jirka.lnk
2025-01-11 10:52 - 2025-01-11 10:52 - 000000279 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tento počítač.lnk
2025-01-11 10:52 - 2025-01-11 10:52 - 000000279 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koš.lnk
2025-01-11 10:44 - 2025-01-15 08:53 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Tracker Software
2025-01-11 10:44 - 2025-01-11 10:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software
2025-01-11 10:44 - 2025-01-11 10:44 - 000000000 ____D C:\ProgramData\FileOpen
2025-01-11 10:44 - 2017-01-11 10:54 - 000059072 _____ (Tracker Software Products (Canada) Ltd.) C:\WINDOWS\system32\pxc60pm.dll
2025-01-11 10:43 - 2025-01-11 10:43 - 000000000 ____D C:\Program Files\Tracker Software
2025-01-11 10:40 - 2025-01-28 07:19 - 000000000 ____D C:\ProgramData\Package Cache
2025-01-11 10:28 - 2025-01-11 10:28 - 000000504 _____ C:\Users\Jirka\Documents\aktivace revouninstaler.rupaf
2025-01-11 10:26 - 2025-01-16 07:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\Users\Jirka\AppData\Local\VS Revo Group
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\ProgramData\VS Revo Group
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\Program Files\VS Revo Group
2025-01-11 10:25 - 2025-01-11 10:25 - 017948560 _____ (VS Revo Group ) C:\Users\Jirka\Downloads\RevoUninProSetup.exe
2025-01-11 09:43 - 2025-02-05 15:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-01-11 09:43 - 2025-02-05 15:56 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2025-01-11 09:43 - 2025-02-05 15:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-01-11 09:43 - 2025-01-11 09:43 - 066672584 _____ (Mozilla) C:\Users\Jirka\Downloads\Thunderbird Setup 128.6.0esr.exe
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Thunderbird
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Mozilla
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\Thunderbird
2025-01-11 09:37 - 2025-02-03 08:57 - 000004266 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1736584655
2025-01-11 09:37 - 2025-02-03 08:57 - 000001386 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2025-01-11 09:37 - 2025-01-15 08:09 - 000004548 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1736584659
2025-01-11 09:37 - 2025-01-11 09:37 - 000000000 ____D C:\Users\Jirka\AppData\Local\Opera Software
2025-01-11 09:36 - 2025-01-11 09:36 - 002254144 _____ () C:\Users\Jirka\Downloads\OperaSetup.exe
2025-01-11 09:36 - 2025-01-11 09:36 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Opera Software
2025-01-11 09:29 - 2025-01-11 09:29 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\WinRAR
2025-01-11 09:26 - 2025-01-11 09:26 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-01-11 09:26 - 2025-01-11 09:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-01-11 09:25 - 2025-01-11 09:26 - 000000000 ____D C:\Program Files\WinRAR
2025-01-11 05:47 - 2025-01-11 05:47 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-02-10 15:09 - 2025-01-10 12:39 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-02-10 15:08 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-02-10 15:08 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-02-10 15:03 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-02-10 15:03 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-02-10 15:03 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF
2025-02-10 14:56 - 2025-01-10 12:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-10 14:56 - 2025-01-10 12:41 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-10 14:56 - 2025-01-10 07:32 - 000002377 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-02-05 07:09 - 2025-01-10 11:56 - 000000000 ____D C:\ProgramData\NVIDIA
2025-02-05 07:08 - 2025-01-10 12:43 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-02-05 07:01 - 2025-01-10 12:41 - 000001752 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-02-05 07:01 - 2025-01-10 12:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-02-05 07:01 - 2025-01-10 11:55 - 000000000 __SHD C:\Users\Jirka\IntelGraphicsProfiles
2025-02-05 07:01 - 2025-01-10 07:26 - 000012288 ___SH C:\DumpStack.log.tmp
2025-02-05 07:00 - 2024-04-01 08:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-02-05 06:51 - 2025-01-10 07:26 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-02-05 06:50 - 2025-01-10 12:39 - 000478600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-02-05 06:50 - 2025-01-10 12:39 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-02-05 06:50 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka
2025-02-05 06:48 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\registration
2025-02-04 18:15 - 2025-01-10 07:31 - 000000000 ____D C:\Users\Jirka\AppData\Local\D3DSCache
2025-01-28 07:21 - 2025-01-10 08:55 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-10 08:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-10 08:55 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-01-27 16:00 - 2025-01-10 08:55 - 000023019 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2025-01-27 16:00 - 2025-01-10 08:55 - 000020122 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2025-01-27 16:00 - 2025-01-10 08:55 - 000014135 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2025-01-24 09:57 - 2024-04-01 08:26 - 000000000 __RSD C:\WINDOWS\Media
2025-01-24 09:56 - 2025-01-10 07:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\MMC
2025-01-24 09:39 - 2025-01-10 08:55 - 000001205 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2025-01-22 08:42 - 2025-01-10 07:30 - 000000000 ____D C:\Users\Jirka\AppData\Local\ConnectedDevicesPlatform
2025-01-21 17:24 - 2025-01-10 07:32 - 000000000 ____D C:\Users\Jirka\AppData\Local\VirtualStore
2025-01-21 13:04 - 2025-01-10 12:00 - 000000000 ___DC C:\WINDOWS\Panther
2025-01-21 12:55 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2025-01-17 15:29 - 2025-01-10 07:30 - 000000000 ____D C:\Users\Jirka\AppData\Local\Packages
2025-01-17 13:31 - 2025-01-10 07:30 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-01-15 11:31 - 2025-01-10 07:38 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-01-15 09:33 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows
2025-01-15 08:32 - 2025-01-10 12:27 - 000000000 ____D C:\WINDOWS\InboxApps
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\security
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-01-15 08:29 - 2025-01-10 07:28 - 000000000 ____D C:\ProgramData\Packages
2025-01-15 07:15 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-01-15 06:28 - 2025-01-10 07:38 - 206927936 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-01-14 16:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-01-11 14:20 - 2022-05-07 06:24 - 000000167 _____ C:\WINDOWS\win.ini
2025-01-11 13:59 - 2024-04-01 08:26 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-01-11 09:20 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Spelling
2025-01-11 05:54 - 2025-01-10 08:01 - 000000000 ____D C:\Users\Jirka\AppData\Local\PlaceholderTileLogoFolder
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by Jirka (administrator) on DESKTOP-99A8H9S (Micro-Star International Co., Ltd. GL75 Leopard 10SDR) (10-02-2025 15:50:08)
Running from C:\Users\Jirka\Downloads\FRST64.exe
Loaded Profiles: Jirka
Platform: Microsoft Windows 11 Pro Version 24H2 26100.2894 (X64) Language: Čeština (Česko)
Default browser: "C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(A-Volute SAS -> A-Volute) C:\Windows\System32\NhNotifSys.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Jirka\AppData\Local\Programs\Opera\116.0.5366.71\opera_crashreporter.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe <96>
(explorer.exe ->) (Prog-Soft s.r.o.) [File not signed] C:\Program Files (x86)\PSPad editor\PSPad.exe
(explorer.exe ->) (ZONER software, a.s. -> ZONER software) C:\Program Files\Zoner\Photo Studio 19\Program64\Zps.exe
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2410.21.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe <3>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <2>
(services.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_629847df3bb3f110\RtkAudUService64.exe <2>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22301.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22301.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_629847df3bb3f110\RtkAudUService64.exe [2375128 2024-12-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [486552 2012-09-27] (CANON INC. -> CANON INC.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation) [File not signed]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [MicrosoftEdgeAutoLaunch_9351DC8C75826C8A9C791E0FFD3CBFF5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3923496 2025-01-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [Opera Stable] => C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe [1622424 2025-02-03] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [Opera Browser Assistant] => C:\Users\Jirka\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4459928 2025-01-08] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation) [File not signed]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" [84027432 2025-02-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Uninstall 24.244.1204.0003\i386] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\24.244.1204.0003\i386" [0 2025-02-10] () <==== ATTENTION [zero byte File/Folder]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Uninstall 24.244.1204.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\24.244.1204.0003" [131072 2025-02-10] () [File not signed]
HKLM\...\Print\Monitors\Canon MFNP Port: C:\WINDOWS\system32\CNCENPM6.dll [152064 2012-09-26] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon WSD Language Monitor: C:\WINDOWS\system32\cnnx0_flm.dll [1420800 2013-02-25] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\CPCA Language Monitor3b: C:\WINDOWS\system32\CNAS0MOK.DLL [1006080 2012-08-09] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\PDF-XChange6: C:\WINDOWS\system32\pxc60pm.dll [59072 2017-01-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
Startup: C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RuntimeBroker.lnk [2025-01-21]
ShortcutTarget: RuntimeBroker.lnk -> C:\Users\Jirka\AppData\Roaming\Corel User Preferences\Backup files\CorelDRAW Graphics Suite 2021.exe (Corel Corporation) [File not signed]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {FD6D0C94-7015-4FC2-83EE-38497361643B} - System32\Tasks\Canon\OIPPESP\Canon OIP Product Extended Survey Program => C:\Program Files\Canon\OIPPESP\Cnpspcnt.exe [1826264 2020-07-29] (CANON INC. -> CANON INC.) -> /Config:"C:\Program Files\Canon\OIPPESP\CnpspCfg.xml"
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {C812530A-F87D-41DA-9070-C99599522F67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2AE149A9-97AC-4BF4-97F5-C4ECA91DAC6C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {38309FF9-F793-4797-98BD-44D26870505C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BE18E8D2-9E8D-45C8-973F-710300A7E985} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FFFCF6BA-0475-4438-AC46-2A9E50641AA7} - System32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA app.exe [3287080 2025-01-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {61295927-FC13-46A6-A4B2-93DC805E5E29} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2544418961-404871699-1754985800-1001 => C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\25.005.0112.0003\OneDriveLauncher.exe [447032 2025-02-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {736214A3-83E2-4312-92DD-D4FAF391CDD8} - System32\Tasks\Opera scheduled assistant Autoupdate 1736584659 => C:\Users\Jirka\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5656472 2025-01-28] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --bypasslauncher --installdir="C:\Users\Jirka\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {01B7D443-7B2B-4354-84AC-624F8F3E489D} - System32\Tasks\Opera scheduled Autoupdate 1736584655 => C:\Users\Jirka\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5656472 2025-01-28] (Opera Norway AS -> Opera Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 0.0.0.0 account.zoner.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{10624d03-044f-4dff-84d3-d5a7d1626de5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{10624d03-044f-4dff-84d3-d5a7d1626de5}\24C65746F667963656E65647: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3746ef48-1b44-4fe5-b84a-0abba4de1340}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{3746ef48-1b44-4fe5-b84a-0abba4de1340}: [DhcpDomain] axad.cz
Edge:
=======
Edge Profile: C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default [2025-02-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-01-11]
Edge Extension: (Edge relevant text changes) - C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-11]
FireFox:
========
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2544418961-404871699-1754985800-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
Opera:
=======
OPR DefaultProfile: Default
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1888424 2021-10-08] (A-Volute SAS -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\Display.NvContainer\NVDisplay.Container.exe [1275568 2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559304 2025-01-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 MpKslbef2cdcb; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4B2576B4-0DFC-4698-A319-1F809B7E6132}\MpKslDrv.sys [267552 2025-02-10] (Microsoft Windows -> Microsoft Corporation)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [94784 2022-06-03] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22104 2025-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [606624 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105888 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-02-10 14:56 - 2025-02-10 14:56 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-05 15:24 - 2025-02-05 15:24 - 000001875 _____ C:\Users\Jirka\Downloads\Klicenka.svg
2025-02-05 15:13 - 2025-02-05 15:51 - 000000000 ____D C:\Users\Jirka\Desktop\Zetfa_web
2025-02-05 08:30 - 2025-02-05 15:56 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2025-02-05 08:20 - 2025-02-05 08:20 - 000000782 _____ C:\Users\Jirka\Desktop\Plocha 2025 – zástupce.lnk
2025-02-05 07:16 - 2025-02-05 07:17 - 000030033 _____ C:\Users\Jirka\Downloads\Addition.txt
2025-02-05 07:14 - 2025-02-10 15:50 - 000017118 _____ C:\Users\Jirka\Downloads\FRST.txt
2025-02-05 07:14 - 2025-02-10 15:50 - 000000000 ____D C:\FRST
2025-02-05 07:08 - 2025-02-05 07:08 - 008790880 _____ (Malwarebytes) C:\Users\Jirka\Downloads\adwcleaner (1).exe
2025-02-05 07:08 - 2025-02-05 07:08 - 000678362 _____ C:\WINDOWS\system32\perfh005.dat
2025-02-05 07:08 - 2025-02-05 07:08 - 000145178 _____ C:\WINDOWS\system32\perfc005.dat
2025-02-05 07:08 - 2025-02-05 07:08 - 000000000 ____D C:\AdwCleaner
2025-02-05 07:05 - 2025-02-05 07:05 - 008790880 _____ (Malwarebytes) C:\Users\Jirka\Downloads\AdwCleaner.exe
2025-02-05 07:05 - 2025-02-05 07:05 - 002403328 _____ (Farbar) C:\Users\Jirka\Downloads\FRST64.exe
2025-02-05 06:54 - 2025-02-05 07:00 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-02-05 06:54 - 2025-02-05 06:54 - 000000000 ____D C:\WINDOWS\pss
2025-02-05 06:25 - 2025-02-05 06:25 - 000000000 ____D C:\Users\Jirka\AppData\Local\OneDrive
2025-01-30 11:46 - 2025-01-30 11:46 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\HTML Help
2025-01-30 10:35 - 2025-01-30 10:35 - 000000110 ____H C:\Users\Jirka\Downloads\as.46554565.jpg.uid-zps
2025-01-30 10:21 - 2025-01-30 10:21 - 000025638 _____ C:\Users\Jirka\Downloads\01 (1).webp
2025-01-30 10:20 - 2025-01-30 10:20 - 000025638 _____ C:\Users\Jirka\Downloads\01.webp
2025-01-30 10:10 - 2025-01-30 10:10 - 000000110 ____H C:\Users\Jirka\Downloads\istockphoto-1458223077-1024x1024.jpg.uid-zps
2025-01-30 10:08 - 2025-01-30 10:08 - 000000110 ____H C:\Users\Jirka\Downloads\istockphoto-515906629-1024x1024.jpg.uid-zps
2025-01-30 09:18 - 2025-01-30 09:18 - 000011052 _____ C:\Users\Jirka\Documents\Byt Karel Demel.xlsx
2025-01-29 19:21 - 2022-09-30 05:24 - 000174112 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2025-01-29 19:21 - 2022-09-30 05:24 - 000050720 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ss_conn_usb_driver2.sys
2025-01-29 19:20 - 2022-09-30 05:23 - 000167440 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus2.sys
2025-01-29 19:05 - 2025-01-29 19:05 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2025-01-29 17:40 - 2025-01-29 17:40 - 000011007 _____ C:\Users\Jirka\Documents\Oprava kanalizace _Gis - stavinvex a,s.xlsx
2025-01-29 16:45 - 2025-01-29 16:44 - 000010581 _____ C:\Users\Jirka\Documents\Kraftova_odpady.xlsx
2025-01-29 07:14 - 2025-01-29 07:15 - 1042927416 _____ (NVIDIA Corporation) C:\Users\Jirka\Downloads\Canvas1.4.311.exe
2025-01-28 07:21 - 2025-01-28 07:21 - 000000000 ____D C:\Users\Jirka\AppData\LocalLow\NVIDIA
2025-01-28 07:21 - 2025-01-28 07:21 - 000000000 ____D C:\Users\Jirka\ansel
2025-01-28 07:20 - 2025-02-05 08:18 - 000000000 ____D C:\Users\Jirka\AppData\Local\NVIDIA Corporation
2025-01-28 07:19 - 2025-02-05 08:18 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-01-28 07:19 - 2025-02-05 08:18 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-01-28 07:19 - 2025-02-05 06:49 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2025-01-28 07:19 - 2025-01-28 07:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-25 13:25 - 003108904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 002398760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 000271912 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 000245800 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-01-28 07:19 - 2025-01-25 13:05 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-01-28 07:19 - 2025-01-25 13:05 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 002060664 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 002060664 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001600376 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001600376 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001452432 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001452432 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001301880 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001301880 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 000478384 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 000374432 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 001114792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 000670352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 000505504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 025450120 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-01-28 07:16 - 2024-12-04 19:01 - 001554608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 001208992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 000863888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-01-28 07:16 - 2024-12-04 19:00 - 016811696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 002185360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 001634464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 001042072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 000801432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 000462480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-01-28 07:16 - 2024-12-04 18:59 - 017736840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 006953104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 005909664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 005435544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 003807888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 000853680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-01-28 07:16 - 2024-12-04 18:58 - 007158560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-01-28 07:16 - 2024-12-04 18:58 - 006236264 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-01-28 07:16 - 2024-12-04 02:11 - 000132703 _____ C:\WINDOWS\system32\nvinfo.pb
2025-01-28 07:16 - 2024-12-04 02:11 - 000125048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2025-01-28 07:16 - 2024-11-26 08:17 - 000059928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2025-01-28 07:03 - 2025-01-28 07:04 - 732914600 _____ (NVIDIA Corporation) C:\Users\Jirka\Downloads\566.36-notebook-win10-win11-64bit-international-dch-whql.exe
2025-01-28 05:33 - 2025-01-28 05:33 - 000000000 ____D C:\Users\Jirka\Downloads\CorelDRAW Graphics Suite 2023 v24 x64 Multilingual (Pre-Activated)
2025-01-27 16:19 - 2025-01-29 16:44 - 000010581 _____ C:\Users\Jirka\Documents\Žilina podlahy.xlsx
2025-01-27 16:10 - 2025-01-27 17:53 - 1867303969 _____ C:\Users\Jirka\Downloads\CorelDRAW Graphics Suite 2023 v24 x64 Multilingual (Pre-Activated).zip
2025-01-27 15:51 - 2025-01-30 07:01 - 000000000 ____D C:\Users\Jirka\AppData\Local\CrashDumps
2025-01-27 15:42 - 2025-01-27 15:42 - 000000539 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prace.lnk
2025-01-26 09:56 - 2025-01-26 09:56 - 000010153 _____ C:\Users\Jirka\Documents\Ventilátor Ostrava.xlsx
2025-01-24 13:53 - 2025-01-24 13:53 - 000000000 ____D C:\Users\Jirka\AppData\LocalLow\Temp
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ___HD C:\WINDOWS\system32\CanonMF Uninstaller Information
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\ProgramData\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\Program Files\Canon
2025-01-24 09:56 - 2025-01-24 09:56 - 000000000 ____D C:\Users\Jirka\Downloads\MF4700MFDriverV4101WPEN
2025-01-24 09:56 - 2012-09-26 14:02 - 000195584 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPR6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNCENPM6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPM6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000105984 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPU6.dll
2025-01-24 09:56 - 2009-06-11 22:47 - 000017861 _____ C:\WINDOWS\system32\CNCENPMK.chm
2025-01-24 07:50 - 2025-01-24 07:50 - 000862582 _____ C:\Users\Jirka\Documents\priloha_1451506360_0_2024-23874.pdf
2025-01-22 15:11 - 2025-01-22 15:12 - 000000000 ____D C:\Users\Jirka\Downloads\ipnetinfo_czech
2025-01-22 15:11 - 2025-01-22 15:11 - 000063443 _____ C:\Users\Jirka\Downloads\ipnetinfo.zip
2025-01-22 15:10 - 2025-01-22 15:10 - 000001932 _____ C:\Users\Jirka\Downloads\ipnetinfo_czech.zip
2025-01-22 14:55 - 2025-01-22 14:56 - 000000000 ____D C:\Users\Jirka\Downloads\cports_czech
2025-01-22 14:55 - 2025-01-22 14:55 - 000131911 _____ C:\Users\Jirka\Downloads\cports-x64.zip
2025-01-22 14:54 - 2025-01-22 14:54 - 000002863 _____ C:\Users\Jirka\Downloads\cports_czech.zip
2025-01-22 14:04 - 2025-01-22 14:25 - 000000000 ____D C:\dev
2025-01-22 10:01 - 2025-01-22 10:01 - 000057600 _____ C:\Users\Jirka\Downloads\FreeSample-Vectorizer-io-velke-removebg .svg
2025-01-22 09:37 - 2025-01-22 09:37 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\NVIDIA
2025-01-22 08:43 - 2025-01-22 08:43 - 000002031 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Zoner Photo Studio X.lnk
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Zoner
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\Zoner
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\CEF
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Program Files\Zoner
2025-01-22 08:42 - 2025-01-22 08:42 - 000000000 ____D C:\Users\Jirka\AppData\Local\Backup
2025-01-22 08:26 - 2025-01-22 08:26 - 000000000 ____D C:\Users\Jirka\Downloads\Zoner Photo Studio X v19.1707.2.30 (CZ) funkční Crack a návod jak to upravit _-)
2025-01-22 08:16 - 2025-01-22 08:32 - 321529316 _____ C:\Users\Jirka\Downloads\Zoner Photo Studio X.zip
2025-01-22 08:04 - 2025-01-22 08:04 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Corel
2025-01-22 08:02 - 2025-01-22 08:41 - 000767994 _____ C:\Users\Jirka\Downloads\Eco House Realty Logo _ BrandCrowd Logo Maker _ BrandCrowd.pdf
2025-01-21 16:27 - 2025-02-05 06:49 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\GHISLER
2025-01-21 16:27 - 2025-01-21 16:46 - 000000000 ____D C:\Users\Jirka\AppData\Local\GHISLER
2025-01-21 16:27 - 2025-01-21 16:27 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2025-01-21 16:27 - 2025-01-21 16:27 - 000000000 ____D C:\Program Files\totalcmd
2025-01-21 16:26 - 2025-01-21 16:26 - 007016880 _____ (Ghisler Software GmbH) C:\Users\Jirka\Downloads\tcmd1150x64.exe
2025-01-21 12:55 - 2025-01-21 12:55 - 000001278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Program Updates.lnk
2025-01-21 12:42 - 2025-01-27 17:13 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Corel User Preferences
2025-01-20 11:52 - 2025-01-20 11:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Clip Organizer
2025-01-19 07:42 - 2025-01-19 07:42 - 011473496 _____ C:\Users\Jirka\Downloads\Poliigon_MetalSteelBrushed_7174.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 009472341 _____ C:\Users\Jirka\Downloads\fabric_pattern_07_1k.blend.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 005273768 _____ C:\Users\Jirka\Downloads\fabric_leather_02_1k.blend.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 005171753 _____ C:\Users\Jirka\Downloads\fabric_leather_01_1k.blend.zip
2025-01-19 07:33 - 2025-01-19 07:33 - 004977270 _____ C:\Users\Jirka\Downloads\patterned_brick_floor_03_1k.blend.zip
2025-01-19 07:33 - 2025-01-19 07:33 - 004386622 _____ C:\Users\Jirka\Downloads\diagonal_parquet_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:33 - 005679365 _____ C:\Users\Jirka\Downloads\stone_tiles_02_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 005647662 _____ C:\Users\Jirka\Downloads\brick_pavement_02_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 005151850 _____ C:\Users\Jirka\Downloads\square_tiles_03_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 004751833 _____ C:\Users\Jirka\Downloads\granite_tile_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 004574026 _____ C:\Users\Jirka\Downloads\painted_concrete_02_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 005104392 _____ C:\Users\Jirka\Downloads\wood_floor_deck_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 004711431 _____ C:\Users\Jirka\Downloads\concrete_floor_worn_001_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 004170783 _____ C:\Users\Jirka\Downloads\wood_floor_worn_1k.blend.zip
2025-01-19 07:29 - 2025-01-19 07:29 - 080517810 _____ C:\Users\Jirka\Downloads\metal_grate_rusty_4k.blend.zip
2025-01-19 07:29 - 2025-01-19 07:29 - 006524568 _____ C:\Users\Jirka\Downloads\metal_grate_rusty_1k.blend.zip
2025-01-17 15:20 - 2025-01-28 07:19 - 000000000 ____D C:\Users\Jirka\AppData\Local\NVIDIA
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blender
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Blender Foundation
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Local\Blender Foundation
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\.thumbnails
2025-01-17 15:19 - 2025-01-17 15:19 - 000000000 ____D C:\Program Files\Blender Foundation
2025-01-17 15:08 - 2025-01-17 15:08 - 009280994 _____ C:\Users\Jirka\Downloads\3D_outdoorlamp_1.blend
2025-01-17 15:05 - 2025-01-17 15:05 - 005545596 _____ C:\Users\Jirka\Downloads\3D_bench_24.blend
2025-01-17 15:02 - 2025-01-17 15:02 - 002594005 _____ C:\Users\Jirka\Downloads\leopard_skin-1K.zip
2025-01-17 15:02 - 2025-01-17 15:02 - 000000000 ____D C:\Users\Jirka\Downloads\leopard_skin-1K
2025-01-17 15:01 - 2025-01-17 15:01 - 002106339 _____ C:\Users\Jirka\Downloads\wall_stone_1-1K.zip
2025-01-17 15:01 - 2025-01-17 15:01 - 000000000 ____D C:\Users\Jirka\Downloads\wall_stone_1-1K
2025-01-17 14:59 - 2025-01-17 14:59 - 003740902 _____ C:\Users\Jirka\Downloads\stone_wall_8-1K.zip
2025-01-17 14:59 - 2025-01-17 14:59 - 000000000 ____D C:\Users\Jirka\Downloads\stone_wall_8-1K
2025-01-17 14:58 - 2025-01-17 14:58 - 000000000 ____D C:\Users\Jirka\Downloads\colorfull_brick_wall-1K
2025-01-17 14:57 - 2025-01-17 14:57 - 000000000 ____D C:\Users\Jirka\Downloads\brick_wall_11-1K
2025-01-17 14:56 - 2025-01-17 14:56 - 000000000 ____D C:\Users\Jirka\Downloads\red_brick_wall_7-1K
2025-01-17 14:55 - 2025-01-17 14:55 - 003152520 _____ C:\Users\Jirka\Downloads\brick_wall_11-1K.zip
2025-01-17 14:53 - 2025-01-17 14:53 - 003298091 _____ C:\Users\Jirka\Downloads\red_brick_wall_7-1K.zip
2025-01-17 14:52 - 2025-01-17 14:52 - 002060302 _____ C:\Users\Jirka\Downloads\colorfull_brick_wall-1K.zip
2025-01-17 14:47 - 2025-01-17 14:47 - 000000000 ____D C:\Users\Jirka\Downloads\paving_stone-1K
2025-01-17 14:46 - 2025-01-17 14:46 - 003009055 _____ C:\Users\Jirka\Downloads\paving_stone-1K.zip
2025-01-17 14:41 - 2025-01-17 14:41 - 017104379 _____ C:\Users\Jirka\Downloads\woodparquet_122-1K.zip
2025-01-17 14:41 - 2025-01-17 14:41 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_122-1K
2025-01-17 14:26 - 2025-01-17 14:26 - 010500235 _____ C:\Users\Jirka\Downloads\woodparquet_83-1K (1).zip
2025-01-17 14:26 - 2025-01-17 14:26 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_83-1K (1)
2025-01-17 14:23 - 2025-01-17 14:23 - 010500235 _____ C:\Users\Jirka\Downloads\woodparquet_83-1K.zip
2025-01-17 14:23 - 2025-01-17 14:23 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_83-1K
2025-01-17 14:21 - 2025-01-17 14:21 - 001509573 _____ C:\Users\Jirka\Downloads\wooden_ceramic_2-1K.zip
2025-01-17 14:21 - 2025-01-17 14:21 - 000000000 ____D C:\Users\Jirka\Downloads\wooden_ceramic_2-1K
2025-01-17 14:19 - 2025-01-17 14:19 - 000000000 ____D C:\Users\Jirka\Downloads\ground_13-1K
2025-01-17 14:18 - 2025-01-17 14:18 - 007693179 _____ C:\Users\Jirka\Downloads\ground_13-1K.zip
2025-01-17 14:16 - 2025-01-17 14:16 - 010326888 _____ C:\Users\Jirka\Downloads\ground_17-1K.zip
2025-01-17 14:16 - 2025-01-17 14:16 - 000000000 ____D C:\Users\Jirka\Downloads\ground_17-1K
2025-01-17 14:14 - 2025-01-17 14:14 - 003002837 _____ C:\Users\Jirka\Downloads\amethyst_texture_1-1K.zip
2025-01-17 14:14 - 2025-01-17 14:14 - 000000000 ____D C:\Users\Jirka\Downloads\amethyst_texture_1-1K
2025-01-17 14:13 - 2025-01-17 14:13 - 001987391 _____ C:\Users\Jirka\Downloads\fabric_91-1K.zip
2025-01-17 14:13 - 2025-01-17 14:13 - 000000000 ____D C:\Users\Jirka\Downloads\fabric_91-1K
2025-01-16 08:20 - 2025-01-16 08:20 - 000170574 _____ C:\Users\Jirka\Downloads\cabinet-door-open-100526.wav
2025-01-16 08:19 - 2025-01-16 08:19 - 000248910 _____ C:\Users\Jirka\Downloads\open-doors-114615.wav
2025-01-16 08:12 - 2025-01-16 08:12 - 000108366 _____ C:\Users\Jirka\Downloads\paper-clips-80906.wav
2025-01-16 08:05 - 2025-01-16 08:05 - 000001404 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\4K Video to MP3.lnk
2025-01-16 07:13 - 2025-01-16 07:13 - 017937304 _____ (VS Revo Group ) C:\Users\Jirka\Downloads\RevoUninProSetup (1).exe
2025-01-16 07:04 - 2025-01-16 07:04 - 000002977 _____ C:\Users\Jirka\Downloads\uz-463100049108-20240709-071225.xml
2025-01-16 06:45 - 2025-01-16 06:45 - 000886832 _____ (Open Media LLC) C:\Users\Jirka\Downloads\4kvideotomp3_3.0.1_x64_online.exe
2025-01-15 14:06 - 2025-01-15 14:06 - 000000000 ____D C:\Users\Jirka\AppData\Local\PeerDistRepub
2025-01-15 11:53 - 2025-01-15 11:53 - 000028078 _____ C:\Users\Jirka\Downloads\14377_30366-dos-maderas-p-x-10yo-ron-anejo-superior-doble-crianza-40-0-2l (1).webp
2025-01-15 11:28 - 2025-01-15 11:28 - 000028078 _____ C:\Users\Jirka\Downloads\14377_30366-dos-maderas-p-x-10yo-ron-anejo-superior-doble-crianza-40-0-2l.webp
2025-01-15 11:18 - 2025-01-15 11:18 - 000001156 _____ C:\Users\Jirka\Downloads\Kiom UpDown round si.rao
2025-01-15 11:18 - 2025-01-15 11:18 - 000001156 _____ C:\Users\Jirka\Downloads\Kiom UpDown round si (1).rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000267970 _____ C:\Users\Jirka\Downloads\Samsung dbl door fridge.rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000255180 _____ C:\Users\Jirka\Downloads\beer tap - MGD.rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000249466 _____ C:\Users\Jirka\Downloads\amana double door fridge.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000317993 _____ C:\Users\Jirka\Downloads\liqour bottle - Naranja.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000305619 _____ C:\Users\Jirka\Downloads\liqour bottle - Gran Marnier.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000167862 _____ C:\Users\Jirka\Downloads\liqour bottle - whiskey.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000164611 _____ C:\Users\Jirka\Downloads\liqour bottle - gold rum.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000157887 _____ C:\Users\Jirka\Downloads\liqour bottle - vodka.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000110293 _____ C:\Users\Jirka\Downloads\liqour bottle - DM root beer.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000055325 _____ C:\Users\Jirka\Downloads\liqour bottle - Demain cognac.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000022738 _____ C:\Users\Jirka\Downloads\bottle - jaqk wine.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000005628 _____ C:\Users\Jirka\Downloads\Picture by TS.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000042765 _____ C:\Users\Jirka\Downloads\Wall Clocks, Sunflowers 7.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000007263 _____ C:\Users\Jirka\Downloads\Light 2.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000006343 _____ C:\Users\Jirka\Downloads\Lamp 1.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000004070 _____ C:\Users\Jirka\Downloads\Light 1.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000003235 _____ C:\Users\Jirka\Downloads\Light 4.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000001459 _____ C:\Users\Jirka\Downloads\Light 3.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000001458 _____ C:\Users\Jirka\Downloads\Lamp 2.rao
2025-01-15 11:14 - 2025-01-15 11:14 - 000148548 _____ C:\Users\Jirka\Downloads\Gorenje K 28P by BJ.rap
2025-01-15 08:42 - 2025-02-10 15:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-01-15 08:42 - 2025-01-15 08:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\mde
2025-01-15 08:42 - 2025-01-15 08:42 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-01-15 08:32 - 2025-01-15 08:33 - 000000000 ____D C:\WINDOWS\CSC
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ___SD C:\WINDOWS\system32\AppV
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ____D C:\WINDOWS\RemotePackages
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ____D C:\WINDOWS\Containers
2025-01-15 08:08 - 2025-01-15 08:10 - 000373324 _____ C:\Users\Jirka\Downloads\Děkujeme za objednávku - SERVIS-REPAS.CZ.pdf
2025-01-15 06:55 - 2025-01-15 06:55 - 000001345 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2025-01-15 06:55 - 2025-01-15 06:55 - 000000000 ____D C:\Users\Jirka\AppData\Local\PCHealthCheck
2025-01-14 05:58 - 2025-01-14 05:58 - 001413059 _____ C:\Users\Jirka\Downloads\julka-spalna.rap
2025-01-12 07:08 - 2025-01-12 07:08 - 000000848 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RoomAranger.lnk
2025-01-12 06:50 - 2025-01-12 06:50 - 000000000 ____D C:\Users\Jirka\AppData\Local\cache
2025-01-12 06:49 - 2025-01-12 06:49 - 000000000 ____D C:\Program Files\Room Arranger
2025-01-12 06:48 - 2025-01-12 06:48 - 023870896 _____ C:\Users\Jirka\Downloads\rooarr1001_64bit.exe
2025-01-12 06:44 - 2025-01-12 06:44 - 000299993 _____ C:\Users\Jirka\Downloads\Informace-zadost-106_Pr-001_2019-08-02_Info-106-99-MF-18721-2019-48.xlsx
2025-01-12 06:41 - 2025-01-12 06:41 - 000034914 _____ C:\Users\Jirka\Downloads\vzor-2022-zaverecne-vyuctovani-dotace-kopie-210422.xlsx
2025-01-11 16:25 - 2025-01-11 16:25 - 000043853 _____ C:\Users\Jirka\Downloads\externalTemplateLoader-0.4.4.xpi
2025-01-11 14:32 - 2025-01-22 08:41 - 000000000 ____D C:\Users\Jirka\AppData\Local\Room Arranger
2025-01-11 14:32 - 2025-01-11 14:33 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Room Arranger
2025-01-11 14:31 - 2025-01-12 06:49 - 000000888 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Room Arranger.lnk
2025-01-11 14:31 - 2025-01-11 16:58 - 000000000 ____D C:\Users\Jirka\Documents\Room Arranger
2025-01-11 14:31 - 2025-01-11 14:31 - 000000000 ____D C:\ProgramData\Room Arranger
2025-01-11 14:24 - 2025-01-16 13:13 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\UProof
2025-01-11 14:24 - 2025-01-11 14:24 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Proof
2025-01-11 14:23 - 2025-02-05 15:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Word
2025-01-11 14:23 - 2025-02-05 15:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Šablony
2025-01-11 14:23 - 2025-01-11 14:23 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Document Building Blocks
2025-01-11 14:20 - 2025-01-11 14:20 - 000000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2025-01-11 14:17 - 2025-01-11 14:17 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Outlook
2025-01-11 14:16 - 2025-01-30 09:18 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Excel
2025-01-11 14:16 - 2025-01-22 08:08 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Office
2025-01-11 14:16 - 2025-01-11 14:16 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Doplňky
2025-01-11 14:01 - 2025-01-27 16:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\WINDOWS\PCHEALTH
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Works
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2025-01-11 13:59 - 2025-01-11 13:59 - 000000000 ____D C:\Program Files\Microsoft Office
2025-01-11 13:58 - 2025-01-11 14:00 - 000000000 ____D C:\WINDOWS\SHELLNEW
2025-01-11 13:58 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2025-01-11 13:58 - 2025-01-11 13:58 - 000000000 __RHD C:\MSOCache
2025-01-11 13:58 - 2025-01-11 13:58 - 000000000 ____D C:\Users\Jirka\AppData\Local\Microsoft Help
2025-01-11 11:51 - 2025-02-05 15:11 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\PSpad
2025-01-11 11:51 - 2025-01-11 11:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSPad editor
2025-01-11 11:51 - 2025-01-11 11:51 - 000000000 ____D C:\Program Files (x86)\PSPad editor
2025-01-11 10:52 - 2025-01-11 10:52 - 000000696 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jirka.lnk
2025-01-11 10:52 - 2025-01-11 10:52 - 000000279 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tento počítač.lnk
2025-01-11 10:52 - 2025-01-11 10:52 - 000000279 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koš.lnk
2025-01-11 10:44 - 2025-01-15 08:53 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Tracker Software
2025-01-11 10:44 - 2025-01-11 10:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software
2025-01-11 10:44 - 2025-01-11 10:44 - 000000000 ____D C:\ProgramData\FileOpen
2025-01-11 10:44 - 2017-01-11 10:54 - 000059072 _____ (Tracker Software Products (Canada) Ltd.) C:\WINDOWS\system32\pxc60pm.dll
2025-01-11 10:43 - 2025-01-11 10:43 - 000000000 ____D C:\Program Files\Tracker Software
2025-01-11 10:40 - 2025-01-28 07:19 - 000000000 ____D C:\ProgramData\Package Cache
2025-01-11 10:28 - 2025-01-11 10:28 - 000000504 _____ C:\Users\Jirka\Documents\aktivace revouninstaler.rupaf
2025-01-11 10:26 - 2025-01-16 07:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\Users\Jirka\AppData\Local\VS Revo Group
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\ProgramData\VS Revo Group
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\Program Files\VS Revo Group
2025-01-11 10:25 - 2025-01-11 10:25 - 017948560 _____ (VS Revo Group ) C:\Users\Jirka\Downloads\RevoUninProSetup.exe
2025-01-11 09:43 - 2025-02-05 15:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-01-11 09:43 - 2025-02-05 15:56 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2025-01-11 09:43 - 2025-02-05 15:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-01-11 09:43 - 2025-01-11 09:43 - 066672584 _____ (Mozilla) C:\Users\Jirka\Downloads\Thunderbird Setup 128.6.0esr.exe
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Thunderbird
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Mozilla
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\Thunderbird
2025-01-11 09:37 - 2025-02-03 08:57 - 000004266 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1736584655
2025-01-11 09:37 - 2025-02-03 08:57 - 000001386 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2025-01-11 09:37 - 2025-01-15 08:09 - 000004548 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1736584659
2025-01-11 09:37 - 2025-01-11 09:37 - 000000000 ____D C:\Users\Jirka\AppData\Local\Opera Software
2025-01-11 09:36 - 2025-01-11 09:36 - 002254144 _____ () C:\Users\Jirka\Downloads\OperaSetup.exe
2025-01-11 09:36 - 2025-01-11 09:36 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Opera Software
2025-01-11 09:29 - 2025-01-11 09:29 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\WinRAR
2025-01-11 09:26 - 2025-01-11 09:26 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-01-11 09:26 - 2025-01-11 09:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-01-11 09:25 - 2025-01-11 09:26 - 000000000 ____D C:\Program Files\WinRAR
2025-01-11 05:47 - 2025-01-11 05:47 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-02-10 15:09 - 2025-01-10 12:39 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-02-10 15:08 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-02-10 15:08 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-02-10 15:03 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-02-10 15:03 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-02-10 15:03 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF
2025-02-10 14:56 - 2025-01-10 12:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-10 14:56 - 2025-01-10 12:41 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-10 14:56 - 2025-01-10 07:32 - 000002377 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-02-05 07:09 - 2025-01-10 11:56 - 000000000 ____D C:\ProgramData\NVIDIA
2025-02-05 07:08 - 2025-01-10 12:43 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-02-05 07:01 - 2025-01-10 12:41 - 000001752 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-02-05 07:01 - 2025-01-10 12:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-02-05 07:01 - 2025-01-10 11:55 - 000000000 __SHD C:\Users\Jirka\IntelGraphicsProfiles
2025-02-05 07:01 - 2025-01-10 07:26 - 000012288 ___SH C:\DumpStack.log.tmp
2025-02-05 07:00 - 2024-04-01 08:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-02-05 06:51 - 2025-01-10 07:26 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-02-05 06:50 - 2025-01-10 12:39 - 000478600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-02-05 06:50 - 2025-01-10 12:39 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-02-05 06:50 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka
2025-02-05 06:48 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\registration
2025-02-04 18:15 - 2025-01-10 07:31 - 000000000 ____D C:\Users\Jirka\AppData\Local\D3DSCache
2025-01-28 07:21 - 2025-01-10 08:55 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-10 08:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-10 08:55 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-01-27 16:00 - 2025-01-10 08:55 - 000023019 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2025-01-27 16:00 - 2025-01-10 08:55 - 000020122 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2025-01-27 16:00 - 2025-01-10 08:55 - 000014135 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2025-01-24 09:57 - 2024-04-01 08:26 - 000000000 __RSD C:\WINDOWS\Media
2025-01-24 09:56 - 2025-01-10 07:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\MMC
2025-01-24 09:39 - 2025-01-10 08:55 - 000001205 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2025-01-22 08:42 - 2025-01-10 07:30 - 000000000 ____D C:\Users\Jirka\AppData\Local\ConnectedDevicesPlatform
2025-01-21 17:24 - 2025-01-10 07:32 - 000000000 ____D C:\Users\Jirka\AppData\Local\VirtualStore
2025-01-21 13:04 - 2025-01-10 12:00 - 000000000 ___DC C:\WINDOWS\Panther
2025-01-21 12:55 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2025-01-17 15:29 - 2025-01-10 07:30 - 000000000 ____D C:\Users\Jirka\AppData\Local\Packages
2025-01-17 13:31 - 2025-01-10 07:30 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-01-15 11:31 - 2025-01-10 07:38 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-01-15 09:33 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows
2025-01-15 08:32 - 2025-01-10 12:27 - 000000000 ____D C:\WINDOWS\InboxApps
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\security
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-01-15 08:29 - 2025-01-10 07:28 - 000000000 ____D C:\ProgramData\Packages
2025-01-15 07:15 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-01-15 06:28 - 2025-01-10 07:38 - 206927936 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-01-14 16:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-01-11 14:20 - 2022-05-07 06:24 - 000000167 _____ C:\WINDOWS\win.ini
2025-01-11 13:59 - 2024-04-01 08:26 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-01-11 09:20 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Spelling
2025-01-11 05:54 - 2025-01-10 08:01 - 000000000 ____D C:\Users\Jirka\AppData\Local\PlaceholderTileLogoFolder
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
- Rudy
- Site Admin
- Příspěvky: 119309
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu , proces system.
Otevřte poznámkový blok a zkopírujte do něj:
Uložte do C:\Users\Jirka\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
CloseProcesses:
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
EmptyTemp:
Hosts:
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu , proces system.
Fix result of Farbar Recovery Scan Tool (x64) Version: 11-02-2025
Ran by Jirka (12-02-2025 05:03:28) Run:1
Running from C:\Users\Jirka\Downloads\virty
Loaded Profiles: Jirka
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
EmptyTemp:
Hosts:
End
*****************
Processes closed successfully.
"HKU\S-1-5-21-2544418961-404871699-1754985800-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
Could not move "C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 158288365 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 368065 B
Edge => 0 B
Firefox => 0 B
Opera => 19008255 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 26864 B
Jirka => 193841292 B
RecycleBin => 1684475 B
EmptyTemp: => 357.2 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 12-02-2025 05:04:50)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 05:04:50 ====
Ran by Jirka (12-02-2025 05:03:28) Run:1
Running from C:\Users\Jirka\Downloads\virty
Loaded Profiles: Jirka
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp
EmptyTemp:
Hosts:
End
*****************
Processes closed successfully.
"HKU\S-1-5-21-2544418961-404871699-1754985800-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
Could not move "C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 158288365 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 368065 B
Edge => 0 B
Firefox => 0 B
Opera => 19008255 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 26864 B
Jirka => 193841292 B
RecycleBin => 1684475 B
EmptyTemp: => 357.2 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 12-02-2025 05:04:50)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
C:\DumpStack.log.tmp => Could not move
==== End of Fixlog 05:04:50 ====
- Rudy
- Site Admin
- Příspěvky: 119309
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu , proces system.
Smazáno. Snížila se spotřeba systé,ových prostředků? Mmch 10% není zase tak mnoho a v nouz. režimu neběží všechny procesy.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu , proces system.
Dobrý den
Ne pořad ntoskrnl.exe žere mezi 8 - 15 % dnes jsem si všiml, že jsem notes dal uspat a jak jsem ho zapnul tak byl klid a ticho i když jsem pracoval s úpravami fotek. Hned jsem to šel vyzkoušet vypl jsem notes a proces se rozběhl a tak jsem ho dal uspat s nadějí že bude zase klid a nic.
Ne pořad ntoskrnl.exe žere mezi 8 - 15 % dnes jsem si všiml, že jsem notes dal uspat a jak jsem ho zapnul tak byl klid a ticho i když jsem pracoval s úpravami fotek. Hned jsem to šel vyzkoušet vypl jsem notes a proces se rozběhl a tak jsem ho dal uspat s nadějí že bude zase klid a nic.
- Rudy
- Site Admin
- Příspěvky: 119309
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu , proces system.
Koukněte sem: https://www.zive.cz/poradna/vysoke-vyuz ... tanswers=1# . Je to systémová záležitost, s viry to nemá nic společného.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu , proces system.
Děkuji za kontrolu logu článek jsem četl dřív než jste na něj upozornil je už staršího data.
Ještě jednou děkuji.
Ještě jednou děkuji.
- Rudy
- Site Admin
- Příspěvky: 119309
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu , proces system.
Rádo se stalo! 

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.