Stránka 1 z 1

Kontrola logu , proces system.

Napsal: 05 úno 2025 07:29
od ketez67
Dobrý den proces systém ve windows 11 žere cca 10% CPU nikdy tolik CPU nežral v nouzovém režimu žere 0-0,1CPU. Prosím o kontrolu logu. Děkuji.



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-02-2025
Ran by Jirka (05-02-2025 07:16:58)
Running from C:\Users\Jirka\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.2894 (X64) (2025-01-10 11:41:56)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-2544418961-404871699-1754985800-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2544418961-404871699-1754985800-503 - Limited - Disabled)
Guest (S-1-5-21-2544418961-404871699-1754985800-501 - Limited - Disabled)
Jirka (S-1-5-21-2544418961-404871699-1754985800-1001 - Administrator - Enabled) => C:\Users\Jirka
WDAGUtilityAccount (S-1-5-21-2544418961-404871699-1754985800-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Aplikace NVIDIA 11.0.1.189 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.1.189 - NVIDIA Corporation)
Blender (HKLM\...\{DE735DFE-88BD-4470-A889-605A6D86B037}) (Version: 4.3.2 - Blender Foundation)
Canon Laser Printer/Scanner/Fax Extended Survey Program (HKLM\...\{8A16FF47-A5FC-49A8-96B5-31180D317059}) (Version: 3.0.4 - CANON INC.) Hidden
Canon Laser Printer/Scanner/Fax Extended Survey Program (HKLM\...\Canon Laser Printer/Scanner/Fax Extended Survey Program) (Version: 3.0.4.40070 - CANON INC.)
Canon MF4700 Series (HKLM\...\{47A8DB42-4E21-4d55-9931-D4F44CC3F03B}) (Version: 4.1.0.1 - CANON INC.)
Kontrola stavu osobního počítače s Windows (HKLM\...\{7DED818B-F556-4115-9CC0-ACE3F614CE63}) (Version: 4.0.2410.23001 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 132.0.2957.140 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 132.0.2957.140 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Czech) 2007 (HKLM-x32\...\{90120000-0015-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Excel MUI (Czech) 2007 (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2007 (HKLM-x32\...\{90120000-00BA-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2007 (HKLM-x32\...\{90120000-0044-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2007 (HKLM-x32\...\{90120000-00A1-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2007 (HKLM-x32\...\{90120000-001A-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2007 (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2007 (HKLM-x32\...\{90120000-001F-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2007 (HKLM-x32\...\{90120000-001F-041B-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2007 (HKLM-x32\...\{90120000-002C-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2007 (HKLM-x32\...\{90120000-0019-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2007 (HKLM\...\{90120000-002A-0405-1000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2007 (HKLM-x32\...\{90120000-006E-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2007 (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}) (Version: 12.0.4518.1025 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\OneDriveSetup.exe) (Version: 24.244.1204.0003 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.31301 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.22.27821 (HKLM\...\{6E2C7A8E-B17A-4637-9CE9-F0B1157CF378}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.22.27821 (HKLM\...\{0093C20C-273D-4397-B623-515CB8616CB9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.22.27821 (HKLM-x32\...\{3BDE80F7-7EC9-448E-8160-4ADA0CDA8879}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.22.27821 (HKLM-x32\...\{1E6FC929-567E-4D22-9206-C5B83F0A21B9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 128.6.0 - Mozilla)
Mozilla Thunderbird (x64 cs) (HKLM\...\Mozilla Thunderbird 128.6.0 (x64 cs)) (Version: 128.6.0 - Mozilla)
NVIDIA FrameView SDK 1.4.10624.35034762 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.4.10624.35034762 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.4.2.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.2.6 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 566.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 566.36 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
NVIDIA USBC Driver 1.52.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.52.831.832 - NVIDIA Corporation)
Opera Stable 116.0.5366.71 (HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Opera 116.0.5366.71) (Version: 116.0.5366.71 - Opera Software)
PDF-XChange PRO V6 (HKLM\...\{E9A303EA-87D9-4F28-83DA-73D79D05687B}) (Version: 6.0.322.7 - Tracker Software Products (Canada) Ltd.) Hidden
PDF-XChange PRO V6 (HKLM-x32\...\{19930704-143e-4dd8-99b0-98196c7006c7}) (Version: 6.0.322.7 - Tracker Software Products (Canada) Ltd.)
PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: - Jan Fiala)
Revo Uninstaller Pro 5.3.5 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.3.5 - VS Revo Group, Ltd.)
Room Arranger (32-bit) (HKLM-x32\...\Room Arranger) (Version: 9.6.0 - Jan Adamec)
Room Arranger (64-bit) (HKLM-x32\...\Room Arranger x64) (Version: 10.0.1 - Jan Adamec)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 11.50 - Ghisler Software GmbH)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_CZ_is1) (Version: 19.1707.2.30 - ZONER software)

Packages:
=========
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-02-05] (INTEL CORP) [Startup Task]
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2025-02-05] (Microsoft Corp.)
Microsoft.StartExperiencesApp -> C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.235.0_x64__8wekyb3d8bbwe [2025-02-05] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2025-02-05] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.51.353.0_x64__dt26b99r8h8gj [2025-02-05] (Realtek Semiconductor Corp)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2544418961-404871699-1754985800-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.24.31301\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2544418961-404871699-1754985800-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender 4.3\BlendThumb.dll (Stichting Blender Foundation -> )
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2210608 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [PDFXChange Editor Context menu] -> {2ACD35AB-F74A-4C20-AA9B-2DE80081626D} => C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
ContextMenuHandlers1-x32: [PSPad] -> {8903F6C9-25E3-40AC-A98F-E6D35CD0469C} => C:\Program Files (x86)\PSPad editor\PSPadShell.dll [2006-05-14] () [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\nvshext.dll [2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2022-04-04] (VS Revo Group Ltd. -> VS Revo Group)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNCENPM6.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO-x32: PDF-XChange V6 IE Plugin -> {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} -> C:\Program Files\Tracker Software\PDF-XChange 6\PXCIEAddin6.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM-x32 - PDF-XChange V6 IE Plugin - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 6\PXCIEAddin6.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2022-05-07 06:24 - 2025-01-22 08:37 - 000000851 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 account.zoner.com

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2544418961-404871699-1754985800-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jirka\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\2644427204408557525\133832083544593637.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

Network Binding:
=============
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Ethernet: Realtek PCIe GbE Family Controller -> rtcx21x64.sys
Wi-Fi: Intel(R) Wi-Fi 6 AX201 160MHz -> Netwtw10.sys

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_9351DC8C75826C8A9C791E0FFD3CBFF5"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\StartupApproved\Run: => "Opera Stable"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{0E051944-08A1-49A1-8019-AA6668DABDEF}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AF896278-19B7-4C8C-9194-459D239CD42A}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C242D955-AF1A-40CD-82A6-F41407A8E668}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9F661240-55DD-4983-B060-583676A6EE66}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24334.1103.3302.5694_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{E34A0FFD-5F55-473F-855F-444869709013}C:\users\jirka\appdata\local\programs\opera\opera.exe] => (Block) C:\users\jirka\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{28D0F73F-CADE-4A06-A887-881C3C973D68}C:\users\jirka\appdata\local\programs\opera\opera.exe] => (Block) C:\users\jirka\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{5DFFD2DC-9E4F-4FF3-9F69-3F0B0ACE2604}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\132.0.2957.140\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CDB9394B-F031-4E04-83EE-D7EDB5379753}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25007.607.3371.8436_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C71DB1FB-851C-48D6-B30D-0F4619A6DE29}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25007.607.3371.8436_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

22-01-2025 08:39:28 Revo Uninstaller Pro's restore point - zps9_cz
24-01-2025 13:50:58 Instalační služba modulů systému Windows
24-01-2025 13:52:24 Instalační služba modulů systému Windows
27-01-2025 15:52:20 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 15:52:49 Odebráno: CorelDRAW Graphics Suite 12
27-01-2025 15:58:13 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 16:01:36 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite 12
27-01-2025 16:02:02 Odebráno: CorelDRAW Graphics Suite 12
03-02-2025 09:02:26 Windows Update
03-02-2025 09:02:26 Windows Update
03-02-2025 09:02:27 Windows Update

==================== Faulty Device Manager Devices ============
Name: Canon MF4700 Series
Description: Canon MF4700 Series
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Canon
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (02/05/2025 07:01:24 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:

GetCACaps

Metoda: GET(47ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)

Error: (02/05/2025 06:50:48 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:

GetCACaps

Metoda: GET(32ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)

Error: (02/05/2025 06:50:41 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4544,R,98,0) SRUJet: Při otevírání souboru protokolu C:\WINDOWS\system32\SRU\SRU00930.log došlo k chybě -1811 (0xfffff8ed).

Error: (02/04/2025 06:02:56 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:

GetCACaps

Metoda: GET(62ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)

Error: (01/30/2025 07:01:51 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-99A8H9S)
Description: Název chybující aplikace: ZPS.EXE, verze: 19.1707.2.30, časové razítko: 0x596c9879
Název chybujícího modulu: Zxl.dll, verze: 19.1707.2.30, časové razítko: 0x596c973f
Kód výjimky: 0xc000041d
Posun chyby: 0x00000000004302f4
ID chybujícího procesu: 0x4b98
Čas spuštění chybující aplikace: 0x1db72db8943ca17
Cesta k chybující aplikaci: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\ZPS.EXE
Cesta k chybujícímu modulu: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\Zxl.dll
ID sestavy: ceab9cae-617e-4b18-a83a-1e58b7f9a652
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (01/30/2025 07:01:48 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-99A8H9S)
Description: Název chybující aplikace: ZPS.EXE, verze: 19.1707.2.30, časové razítko: 0x596c9879
Název chybujícího modulu: Zxl.dll, verze: 19.1707.2.30, časové razítko: 0x596c973f
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000004302f4
ID chybujícího procesu: 0x4b98
Čas spuštění chybující aplikace: 0x1db72db8943ca17
Cesta k chybující aplikaci: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\ZPS.EXE
Cesta k chybujícímu modulu: C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\PROGRAM64\Zxl.dll
ID sestavy: 1a422d43-c829-4408-85ad-0f8b518b370d
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:

Error: (01/27/2025 04:01:35 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen..To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {2594e2ff-058f-44c3-a65a-04db19292ec8}

Error: (01/27/2025 04:01:10 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-99A8H9S$ přes https://INTC-KeyId-9aaf591ee263caae10f5 ... s/Aik/scep se nepovedla:

GetCACaps

Metoda: GET(15ms)
Fáze: GetCACaps
Nelze rozpoznat název nebo adresu serveru. 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)


System errors:
=============
Error: (02/05/2025 07:14:57 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DESKTOP-99A8H9S)
Description: 0x8000002a32\??\C:\FRST\t8Ro3Dh1Ss3\SOFTWARE

Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HECI Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Display Container LS byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Realtek Audio Universal Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.

Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Nahimic service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 3000 milisekund: Restartovat službu.

Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HDCP Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (02/05/2025 07:09:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.


Windows Defender:
================
Date: 2025-02-03 13:05:22
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {31E27872-BFEF-49DB-A81E-A715512966AC}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2025-02-03 09:06:38
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {FE85833E-D3F1-4C54-8BB2-4A1DAE67E989}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2025-01-29 17:50:12
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6C7707CE-1FE7-45C4-8BE5-CECC29ECDC8C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2025-01-28 19:11:18
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {2018DDAE-E77C-4941-8A03-5CD26B0B1445}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Vlastní prohledávání
Uživatel: DESKTOP-99A8H9S\Jirka

Date: 2025-01-28 18:59:12
Description:
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {6F56AF5C-62D3-4C47-BD0B-48499EE294E3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
Event[0]

Date: 2025-02-05 07:00:11
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-02-05 06:54:50
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-02-05 06:50:48
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací a pokusí se o obnovení na předchozí verzi.
Bezpečnostní informace, které se měly načíst: Aktuální
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu.
Verze bezpečnostních informací: 0.0.0.0;0.0.0.0
Verze modulu: 0.0.0.0

Date: 2025-01-11 07:19:34
Description:
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.421.1304.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.24090.11
Kód chyby: 0x80080005
Popis chyby: Provádění serveru selhalo

CodeIntegrity:
===============
Date: 2025-02-05 07:14:10
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3e62be9c39fb0007\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends Inc. E17E7IMS.10C 11/17/2020
Motherboard: Micro-Star International Co., Ltd. MS-17E7
Processor: Intel(R) Core(TM) i7-10750H CPU @ 2.60GHz
Percentage of memory in use: 12%
Total physical RAM: 65356.14 MB
Available physical RAM: 57407.98 MB
Total Virtual: 75084.14 MB
Available Virtual: 67008.89 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:930.7 GB) (Free:823.01 GB) (Model: ADATA LEGEND 800) NTFS
Drive d: (Nový svazek) (Fixed) (Total:894.24 GB) (Free:573.75 GB) (Model: KINGSTON SA400S37960G) NTFS

\\?\Volume{1d84a99c-f4b3-490f-ba93-42859908be14}\ () (Fixed) (Total:0.69 GB) (Free:0.15 GB) NTFS
\\?\Volume{2f47f9ec-2cc4-472b-848f-659395f523c4}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 894.3 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Re: Kontrola logu , proces system.

Napsal: 06 úno 2025 14:50
od Rudy
Zdravím!
Potřebuji vidět ještě log FRST (toto je Addition). Najdete ho v C:\Users\Jirka\Downloads frst.txt. Děkuji.

Re: Kontrola logu , proces system.

Napsal: 10 úno 2025 15:57
od ketez67
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-02-2025
Ran by Jirka (administrator) on DESKTOP-99A8H9S (Micro-Star International Co., Ltd. GL75 Leopard 10SDR) (10-02-2025 15:50:08)
Running from C:\Users\Jirka\Downloads\FRST64.exe
Loaded Profiles: Jirka
Platform: Microsoft Windows 11 Pro Version 24H2 26100.2894 (X64) Language: Čeština (Česko)
Default browser: "C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(A-Volute SAS -> A-Volute) C:\Windows\System32\NhNotifSys.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Jirka\AppData\Local\Programs\Opera\116.0.5366.71\opera_crashreporter.exe
(explorer.exe ->) (Opera Norway AS -> Opera Software) C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe <96>
(explorer.exe ->) (Prog-Soft s.r.o.) [File not signed] C:\Program Files (x86)\PSPad editor\PSPad.exe
(explorer.exe ->) (ZONER software, a.s. -> ZONER software) C:\Program Files\Zoner\Photo Studio 19\Program64\Zps.exe
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2410.21.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe <3>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <2>
(services.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_629847df3bb3f110\RtkAudUService64.exe <2>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22301.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22301.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_629847df3bb3f110\RtkAudUService64.exe [2375128 2024-12-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [486552 2012-09-27] (CANON INC. -> CANON INC.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation) [File not signed]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [MicrosoftEdgeAutoLaunch_9351DC8C75826C8A9C791E0FFD3CBFF5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3923496 2025-01-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [Opera Stable] => C:\Users\Jirka\AppData\Local\Programs\Opera\opera.exe [1622424 2025-02-03] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [Opera Browser Assistant] => C:\Users\Jirka\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4459928 2025-01-08] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation) [File not signed]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" [84027432 2025-02-10] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Uninstall 24.244.1204.0003\i386] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\24.244.1204.0003\i386" [0 2025-02-10] () <==== ATTENTION [zero byte File/Folder]
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Uninstall 24.244.1204.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\24.244.1204.0003" [131072 2025-02-10] () [File not signed]
HKLM\...\Print\Monitors\Canon MFNP Port: C:\WINDOWS\system32\CNCENPM6.dll [152064 2012-09-26] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon WSD Language Monitor: C:\WINDOWS\system32\cnnx0_flm.dll [1420800 2013-02-25] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\CPCA Language Monitor3b: C:\WINDOWS\system32\CNAS0MOK.DLL [1006080 2012-08-09] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\PDF-XChange6: C:\WINDOWS\system32\pxc60pm.dll [59072 2017-01-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
Startup: C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RuntimeBroker.lnk [2025-01-21]
ShortcutTarget: RuntimeBroker.lnk -> C:\Users\Jirka\AppData\Roaming\Corel User Preferences\Backup files\CorelDRAW Graphics Suite 2021.exe (Corel Corporation) [File not signed]

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {FD6D0C94-7015-4FC2-83EE-38497361643B} - System32\Tasks\Canon\OIPPESP\Canon OIP Product Extended Survey Program => C:\Program Files\Canon\OIPPESP\Cnpspcnt.exe [1826264 2020-07-29] (CANON INC. -> CANON INC.) -> /Config:"C:\Program Files\Canon\OIPPESP\CnpspCfg.xml"
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {C812530A-F87D-41DA-9070-C99599522F67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2AE149A9-97AC-4BF4-97F5-C4ECA91DAC6C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {38309FF9-F793-4797-98BD-44D26870505C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BE18E8D2-9E8D-45C8-973F-710300A7E985} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FFFCF6BA-0475-4438-AC46-2A9E50641AA7} - System32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA app.exe [3287080 2025-01-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {61295927-FC13-46A6-A4B2-93DC805E5E29} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2544418961-404871699-1754985800-1001 => C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\25.005.0112.0003\OneDriveLauncher.exe [447032 2025-02-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {736214A3-83E2-4312-92DD-D4FAF391CDD8} - System32\Tasks\Opera scheduled assistant Autoupdate 1736584659 => C:\Users\Jirka\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5656472 2025-01-28] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --bypasslauncher --installdir="C:\Users\Jirka\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {01B7D443-7B2B-4354-84AC-624F8F3E489D} - System32\Tasks\Opera scheduled Autoupdate 1736584655 => C:\Users\Jirka\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5656472 2025-01-28] (Opera Norway AS -> Opera Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 0.0.0.0 account.zoner.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{10624d03-044f-4dff-84d3-d5a7d1626de5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{10624d03-044f-4dff-84d3-d5a7d1626de5}\24C65746F667963656E65647: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3746ef48-1b44-4fe5-b84a-0abba4de1340}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{3746ef48-1b44-4fe5-b84a-0abba4de1340}: [DhcpDomain] axad.cz

Edge:
=======
Edge Profile: C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default [2025-02-05]
Edge Extension: (Dokumenty Google offline) - C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-01-11]
Edge Extension: (Edge relevant text changes) - C:\Users\Jirka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-11]

FireFox:
========
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2544418961-404871699-1754985800-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2017-08-11] (Tracker Software Products (Canada) Ltd -> Tracker Software Products (Canada) Ltd.)

Opera:
=======
OPR DefaultProfile: Default

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1888424 2021-10-08] (A-Volute SAS -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_085de2d4b49d7707\Display.NvContainer\NVDisplay.Container.exe [1275568 2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559304 2025-01-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2025-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 MpKslbef2cdcb; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4B2576B4-0DFC-4698-A319-1F809B7E6132}\MpKslDrv.sys [267552 2025-02-10] (Microsoft Windows -> Microsoft Corporation)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [94784 2022-06-03] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22104 2025-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [606624 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105888 2025-01-10] (Microsoft Windows -> Microsoft Corporation)
R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-01-10] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-02-10 14:56 - 2025-02-10 14:56 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-05 15:24 - 2025-02-05 15:24 - 000001875 _____ C:\Users\Jirka\Downloads\Klicenka.svg
2025-02-05 15:13 - 2025-02-05 15:51 - 000000000 ____D C:\Users\Jirka\Desktop\Zetfa_web
2025-02-05 08:30 - 2025-02-05 15:56 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2025-02-05 08:20 - 2025-02-05 08:20 - 000000782 _____ C:\Users\Jirka\Desktop\Plocha 2025 – zástupce.lnk
2025-02-05 07:16 - 2025-02-05 07:17 - 000030033 _____ C:\Users\Jirka\Downloads\Addition.txt
2025-02-05 07:14 - 2025-02-10 15:50 - 000017118 _____ C:\Users\Jirka\Downloads\FRST.txt
2025-02-05 07:14 - 2025-02-10 15:50 - 000000000 ____D C:\FRST
2025-02-05 07:08 - 2025-02-05 07:08 - 008790880 _____ (Malwarebytes) C:\Users\Jirka\Downloads\adwcleaner (1).exe
2025-02-05 07:08 - 2025-02-05 07:08 - 000678362 _____ C:\WINDOWS\system32\perfh005.dat
2025-02-05 07:08 - 2025-02-05 07:08 - 000145178 _____ C:\WINDOWS\system32\perfc005.dat
2025-02-05 07:08 - 2025-02-05 07:08 - 000000000 ____D C:\AdwCleaner
2025-02-05 07:05 - 2025-02-05 07:05 - 008790880 _____ (Malwarebytes) C:\Users\Jirka\Downloads\AdwCleaner.exe
2025-02-05 07:05 - 2025-02-05 07:05 - 002403328 _____ (Farbar) C:\Users\Jirka\Downloads\FRST64.exe
2025-02-05 06:54 - 2025-02-05 07:00 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-02-05 06:54 - 2025-02-05 06:54 - 000000000 ____D C:\WINDOWS\pss
2025-02-05 06:25 - 2025-02-05 06:25 - 000000000 ____D C:\Users\Jirka\AppData\Local\OneDrive
2025-01-30 11:46 - 2025-01-30 11:46 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\HTML Help
2025-01-30 10:35 - 2025-01-30 10:35 - 000000110 ____H C:\Users\Jirka\Downloads\as.46554565.jpg.uid-zps
2025-01-30 10:21 - 2025-01-30 10:21 - 000025638 _____ C:\Users\Jirka\Downloads\01 (1).webp
2025-01-30 10:20 - 2025-01-30 10:20 - 000025638 _____ C:\Users\Jirka\Downloads\01.webp
2025-01-30 10:10 - 2025-01-30 10:10 - 000000110 ____H C:\Users\Jirka\Downloads\istockphoto-1458223077-1024x1024.jpg.uid-zps
2025-01-30 10:08 - 2025-01-30 10:08 - 000000110 ____H C:\Users\Jirka\Downloads\istockphoto-515906629-1024x1024.jpg.uid-zps
2025-01-30 09:18 - 2025-01-30 09:18 - 000011052 _____ C:\Users\Jirka\Documents\Byt Karel Demel.xlsx
2025-01-29 19:21 - 2022-09-30 05:24 - 000174112 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2025-01-29 19:21 - 2022-09-30 05:24 - 000050720 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ss_conn_usb_driver2.sys
2025-01-29 19:20 - 2022-09-30 05:23 - 000167440 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus2.sys
2025-01-29 19:05 - 2025-01-29 19:05 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2025-01-29 17:40 - 2025-01-29 17:40 - 000011007 _____ C:\Users\Jirka\Documents\Oprava kanalizace _Gis - stavinvex a,s.xlsx
2025-01-29 16:45 - 2025-01-29 16:44 - 000010581 _____ C:\Users\Jirka\Documents\Kraftova_odpady.xlsx
2025-01-29 07:14 - 2025-01-29 07:15 - 1042927416 _____ (NVIDIA Corporation) C:\Users\Jirka\Downloads\Canvas1.4.311.exe
2025-01-28 07:21 - 2025-01-28 07:21 - 000000000 ____D C:\Users\Jirka\AppData\LocalLow\NVIDIA
2025-01-28 07:21 - 2025-01-28 07:21 - 000000000 ____D C:\Users\Jirka\ansel
2025-01-28 07:20 - 2025-02-05 08:18 - 000000000 ____D C:\Users\Jirka\AppData\Local\NVIDIA Corporation
2025-01-28 07:19 - 2025-02-05 08:18 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-01-28 07:19 - 2025-02-05 08:18 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-01-28 07:19 - 2025-02-05 06:49 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2025-01-28 07:19 - 2025-01-28 07:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-25 13:25 - 003108904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 002398760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 000271912 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-01-28 07:19 - 2025-01-25 13:25 - 000245800 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-01-28 07:19 - 2025-01-25 13:05 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-01-28 07:19 - 2025-01-25 13:05 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 002060664 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 002060664 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001600376 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001600376 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-01-28 07:16 - 2024-12-04 19:05 - 001452432 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001452432 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001301880 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 001301880 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 000478384 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-01-28 07:16 - 2024-12-04 19:05 - 000374432 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 001114792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 000670352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-01-28 07:16 - 2024-12-04 19:02 - 000505504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 025450120 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-01-28 07:16 - 2024-12-04 19:01 - 001554608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 001208992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-01-28 07:16 - 2024-12-04 19:01 - 000863888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-01-28 07:16 - 2024-12-04 19:00 - 016811696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 002185360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 001634464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 001042072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 000801432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-01-28 07:16 - 2024-12-04 19:00 - 000462480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-01-28 07:16 - 2024-12-04 18:59 - 017736840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 006953104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 005909664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 005435544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 003807888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-01-28 07:16 - 2024-12-04 18:59 - 000853680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-01-28 07:16 - 2024-12-04 18:58 - 007158560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-01-28 07:16 - 2024-12-04 18:58 - 006236264 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-01-28 07:16 - 2024-12-04 02:11 - 000132703 _____ C:\WINDOWS\system32\nvinfo.pb
2025-01-28 07:16 - 2024-12-04 02:11 - 000125048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2025-01-28 07:16 - 2024-11-26 08:17 - 000059928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2025-01-28 07:03 - 2025-01-28 07:04 - 732914600 _____ (NVIDIA Corporation) C:\Users\Jirka\Downloads\566.36-notebook-win10-win11-64bit-international-dch-whql.exe
2025-01-28 05:33 - 2025-01-28 05:33 - 000000000 ____D C:\Users\Jirka\Downloads\CorelDRAW Graphics Suite 2023 v24 x64 Multilingual (Pre-Activated)
2025-01-27 16:19 - 2025-01-29 16:44 - 000010581 _____ C:\Users\Jirka\Documents\Žilina podlahy.xlsx
2025-01-27 16:10 - 2025-01-27 17:53 - 1867303969 _____ C:\Users\Jirka\Downloads\CorelDRAW Graphics Suite 2023 v24 x64 Multilingual (Pre-Activated).zip
2025-01-27 15:51 - 2025-01-30 07:01 - 000000000 ____D C:\Users\Jirka\AppData\Local\CrashDumps
2025-01-27 15:42 - 2025-01-27 15:42 - 000000539 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prace.lnk
2025-01-26 09:56 - 2025-01-26 09:56 - 000010153 _____ C:\Users\Jirka\Documents\Ventilátor Ostrava.xlsx
2025-01-24 13:53 - 2025-01-24 13:53 - 000000000 ____D C:\Users\Jirka\AppData\LocalLow\Temp
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ___HD C:\WINDOWS\system32\CanonMF Uninstaller Information
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\ProgramData\Canon
2025-01-24 09:57 - 2025-01-24 09:57 - 000000000 ____D C:\Program Files\Canon
2025-01-24 09:56 - 2025-01-24 09:56 - 000000000 ____D C:\Users\Jirka\Downloads\MF4700MFDriverV4101WPEN
2025-01-24 09:56 - 2012-09-26 14:02 - 000195584 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPR6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNCENPM6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000152064 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPM6.dll
2025-01-24 09:56 - 2012-09-26 14:02 - 000105984 _____ (CANON INC.) C:\WINDOWS\system32\CNCENPU6.dll
2025-01-24 09:56 - 2009-06-11 22:47 - 000017861 _____ C:\WINDOWS\system32\CNCENPMK.chm
2025-01-24 07:50 - 2025-01-24 07:50 - 000862582 _____ C:\Users\Jirka\Documents\priloha_1451506360_0_2024-23874.pdf
2025-01-22 15:11 - 2025-01-22 15:12 - 000000000 ____D C:\Users\Jirka\Downloads\ipnetinfo_czech
2025-01-22 15:11 - 2025-01-22 15:11 - 000063443 _____ C:\Users\Jirka\Downloads\ipnetinfo.zip
2025-01-22 15:10 - 2025-01-22 15:10 - 000001932 _____ C:\Users\Jirka\Downloads\ipnetinfo_czech.zip
2025-01-22 14:55 - 2025-01-22 14:56 - 000000000 ____D C:\Users\Jirka\Downloads\cports_czech
2025-01-22 14:55 - 2025-01-22 14:55 - 000131911 _____ C:\Users\Jirka\Downloads\cports-x64.zip
2025-01-22 14:54 - 2025-01-22 14:54 - 000002863 _____ C:\Users\Jirka\Downloads\cports_czech.zip
2025-01-22 14:04 - 2025-01-22 14:25 - 000000000 ____D C:\dev
2025-01-22 10:01 - 2025-01-22 10:01 - 000057600 _____ C:\Users\Jirka\Downloads\FreeSample-Vectorizer-io-velke-removebg .svg
2025-01-22 09:37 - 2025-01-22 09:37 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\NVIDIA
2025-01-22 08:43 - 2025-01-22 08:43 - 000002031 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Zoner Photo Studio X.lnk
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Zoner
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\Zoner
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\CEF
2025-01-22 08:43 - 2025-01-22 08:43 - 000000000 ____D C:\Program Files\Zoner
2025-01-22 08:42 - 2025-01-22 08:42 - 000000000 ____D C:\Users\Jirka\AppData\Local\Backup
2025-01-22 08:26 - 2025-01-22 08:26 - 000000000 ____D C:\Users\Jirka\Downloads\Zoner Photo Studio X v19.1707.2.30 (CZ) funkční Crack a návod jak to upravit _-)
2025-01-22 08:16 - 2025-01-22 08:32 - 321529316 _____ C:\Users\Jirka\Downloads\Zoner Photo Studio X.zip
2025-01-22 08:04 - 2025-01-22 08:04 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Corel
2025-01-22 08:02 - 2025-01-22 08:41 - 000767994 _____ C:\Users\Jirka\Downloads\Eco House Realty Logo _ BrandCrowd Logo Maker _ BrandCrowd.pdf
2025-01-21 16:27 - 2025-02-05 06:49 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\GHISLER
2025-01-21 16:27 - 2025-01-21 16:46 - 000000000 ____D C:\Users\Jirka\AppData\Local\GHISLER
2025-01-21 16:27 - 2025-01-21 16:27 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2025-01-21 16:27 - 2025-01-21 16:27 - 000000000 ____D C:\Program Files\totalcmd
2025-01-21 16:26 - 2025-01-21 16:26 - 007016880 _____ (Ghisler Software GmbH) C:\Users\Jirka\Downloads\tcmd1150x64.exe
2025-01-21 12:55 - 2025-01-21 12:55 - 000001278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Program Updates.lnk
2025-01-21 12:42 - 2025-01-27 17:13 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Corel User Preferences
2025-01-20 11:52 - 2025-01-20 11:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Clip Organizer
2025-01-19 07:42 - 2025-01-19 07:42 - 011473496 _____ C:\Users\Jirka\Downloads\Poliigon_MetalSteelBrushed_7174.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 009472341 _____ C:\Users\Jirka\Downloads\fabric_pattern_07_1k.blend.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 005273768 _____ C:\Users\Jirka\Downloads\fabric_leather_02_1k.blend.zip
2025-01-19 07:37 - 2025-01-19 07:37 - 005171753 _____ C:\Users\Jirka\Downloads\fabric_leather_01_1k.blend.zip
2025-01-19 07:33 - 2025-01-19 07:33 - 004977270 _____ C:\Users\Jirka\Downloads\patterned_brick_floor_03_1k.blend.zip
2025-01-19 07:33 - 2025-01-19 07:33 - 004386622 _____ C:\Users\Jirka\Downloads\diagonal_parquet_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:33 - 005679365 _____ C:\Users\Jirka\Downloads\stone_tiles_02_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 005647662 _____ C:\Users\Jirka\Downloads\brick_pavement_02_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 005151850 _____ C:\Users\Jirka\Downloads\square_tiles_03_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 004751833 _____ C:\Users\Jirka\Downloads\granite_tile_1k.blend.zip
2025-01-19 07:32 - 2025-01-19 07:32 - 004574026 _____ C:\Users\Jirka\Downloads\painted_concrete_02_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 005104392 _____ C:\Users\Jirka\Downloads\wood_floor_deck_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 004711431 _____ C:\Users\Jirka\Downloads\concrete_floor_worn_001_1k.blend.zip
2025-01-19 07:31 - 2025-01-19 07:31 - 004170783 _____ C:\Users\Jirka\Downloads\wood_floor_worn_1k.blend.zip
2025-01-19 07:29 - 2025-01-19 07:29 - 080517810 _____ C:\Users\Jirka\Downloads\metal_grate_rusty_4k.blend.zip
2025-01-19 07:29 - 2025-01-19 07:29 - 006524568 _____ C:\Users\Jirka\Downloads\metal_grate_rusty_1k.blend.zip
2025-01-17 15:20 - 2025-01-28 07:19 - 000000000 ____D C:\Users\Jirka\AppData\Local\NVIDIA
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blender
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Blender Foundation
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\AppData\Local\Blender Foundation
2025-01-17 15:20 - 2025-01-17 15:20 - 000000000 ____D C:\Users\Jirka\.thumbnails
2025-01-17 15:19 - 2025-01-17 15:19 - 000000000 ____D C:\Program Files\Blender Foundation
2025-01-17 15:08 - 2025-01-17 15:08 - 009280994 _____ C:\Users\Jirka\Downloads\3D_outdoorlamp_1.blend
2025-01-17 15:05 - 2025-01-17 15:05 - 005545596 _____ C:\Users\Jirka\Downloads\3D_bench_24.blend
2025-01-17 15:02 - 2025-01-17 15:02 - 002594005 _____ C:\Users\Jirka\Downloads\leopard_skin-1K.zip
2025-01-17 15:02 - 2025-01-17 15:02 - 000000000 ____D C:\Users\Jirka\Downloads\leopard_skin-1K
2025-01-17 15:01 - 2025-01-17 15:01 - 002106339 _____ C:\Users\Jirka\Downloads\wall_stone_1-1K.zip
2025-01-17 15:01 - 2025-01-17 15:01 - 000000000 ____D C:\Users\Jirka\Downloads\wall_stone_1-1K
2025-01-17 14:59 - 2025-01-17 14:59 - 003740902 _____ C:\Users\Jirka\Downloads\stone_wall_8-1K.zip
2025-01-17 14:59 - 2025-01-17 14:59 - 000000000 ____D C:\Users\Jirka\Downloads\stone_wall_8-1K
2025-01-17 14:58 - 2025-01-17 14:58 - 000000000 ____D C:\Users\Jirka\Downloads\colorfull_brick_wall-1K
2025-01-17 14:57 - 2025-01-17 14:57 - 000000000 ____D C:\Users\Jirka\Downloads\brick_wall_11-1K
2025-01-17 14:56 - 2025-01-17 14:56 - 000000000 ____D C:\Users\Jirka\Downloads\red_brick_wall_7-1K
2025-01-17 14:55 - 2025-01-17 14:55 - 003152520 _____ C:\Users\Jirka\Downloads\brick_wall_11-1K.zip
2025-01-17 14:53 - 2025-01-17 14:53 - 003298091 _____ C:\Users\Jirka\Downloads\red_brick_wall_7-1K.zip
2025-01-17 14:52 - 2025-01-17 14:52 - 002060302 _____ C:\Users\Jirka\Downloads\colorfull_brick_wall-1K.zip
2025-01-17 14:47 - 2025-01-17 14:47 - 000000000 ____D C:\Users\Jirka\Downloads\paving_stone-1K
2025-01-17 14:46 - 2025-01-17 14:46 - 003009055 _____ C:\Users\Jirka\Downloads\paving_stone-1K.zip
2025-01-17 14:41 - 2025-01-17 14:41 - 017104379 _____ C:\Users\Jirka\Downloads\woodparquet_122-1K.zip
2025-01-17 14:41 - 2025-01-17 14:41 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_122-1K
2025-01-17 14:26 - 2025-01-17 14:26 - 010500235 _____ C:\Users\Jirka\Downloads\woodparquet_83-1K (1).zip
2025-01-17 14:26 - 2025-01-17 14:26 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_83-1K (1)
2025-01-17 14:23 - 2025-01-17 14:23 - 010500235 _____ C:\Users\Jirka\Downloads\woodparquet_83-1K.zip
2025-01-17 14:23 - 2025-01-17 14:23 - 000000000 ____D C:\Users\Jirka\Downloads\woodparquet_83-1K
2025-01-17 14:21 - 2025-01-17 14:21 - 001509573 _____ C:\Users\Jirka\Downloads\wooden_ceramic_2-1K.zip
2025-01-17 14:21 - 2025-01-17 14:21 - 000000000 ____D C:\Users\Jirka\Downloads\wooden_ceramic_2-1K
2025-01-17 14:19 - 2025-01-17 14:19 - 000000000 ____D C:\Users\Jirka\Downloads\ground_13-1K
2025-01-17 14:18 - 2025-01-17 14:18 - 007693179 _____ C:\Users\Jirka\Downloads\ground_13-1K.zip
2025-01-17 14:16 - 2025-01-17 14:16 - 010326888 _____ C:\Users\Jirka\Downloads\ground_17-1K.zip
2025-01-17 14:16 - 2025-01-17 14:16 - 000000000 ____D C:\Users\Jirka\Downloads\ground_17-1K
2025-01-17 14:14 - 2025-01-17 14:14 - 003002837 _____ C:\Users\Jirka\Downloads\amethyst_texture_1-1K.zip
2025-01-17 14:14 - 2025-01-17 14:14 - 000000000 ____D C:\Users\Jirka\Downloads\amethyst_texture_1-1K
2025-01-17 14:13 - 2025-01-17 14:13 - 001987391 _____ C:\Users\Jirka\Downloads\fabric_91-1K.zip
2025-01-17 14:13 - 2025-01-17 14:13 - 000000000 ____D C:\Users\Jirka\Downloads\fabric_91-1K
2025-01-16 08:20 - 2025-01-16 08:20 - 000170574 _____ C:\Users\Jirka\Downloads\cabinet-door-open-100526.wav
2025-01-16 08:19 - 2025-01-16 08:19 - 000248910 _____ C:\Users\Jirka\Downloads\open-doors-114615.wav
2025-01-16 08:12 - 2025-01-16 08:12 - 000108366 _____ C:\Users\Jirka\Downloads\paper-clips-80906.wav
2025-01-16 08:05 - 2025-01-16 08:05 - 000001404 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\4K Video to MP3.lnk
2025-01-16 07:13 - 2025-01-16 07:13 - 017937304 _____ (VS Revo Group ) C:\Users\Jirka\Downloads\RevoUninProSetup (1).exe
2025-01-16 07:04 - 2025-01-16 07:04 - 000002977 _____ C:\Users\Jirka\Downloads\uz-463100049108-20240709-071225.xml
2025-01-16 06:45 - 2025-01-16 06:45 - 000886832 _____ (Open Media LLC) C:\Users\Jirka\Downloads\4kvideotomp3_3.0.1_x64_online.exe
2025-01-15 14:06 - 2025-01-15 14:06 - 000000000 ____D C:\Users\Jirka\AppData\Local\PeerDistRepub
2025-01-15 11:53 - 2025-01-15 11:53 - 000028078 _____ C:\Users\Jirka\Downloads\14377_30366-dos-maderas-p-x-10yo-ron-anejo-superior-doble-crianza-40-0-2l (1).webp
2025-01-15 11:28 - 2025-01-15 11:28 - 000028078 _____ C:\Users\Jirka\Downloads\14377_30366-dos-maderas-p-x-10yo-ron-anejo-superior-doble-crianza-40-0-2l.webp
2025-01-15 11:18 - 2025-01-15 11:18 - 000001156 _____ C:\Users\Jirka\Downloads\Kiom UpDown round si.rao
2025-01-15 11:18 - 2025-01-15 11:18 - 000001156 _____ C:\Users\Jirka\Downloads\Kiom UpDown round si (1).rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000267970 _____ C:\Users\Jirka\Downloads\Samsung dbl door fridge.rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000255180 _____ C:\Users\Jirka\Downloads\beer tap - MGD.rao
2025-01-15 11:17 - 2025-01-15 11:17 - 000249466 _____ C:\Users\Jirka\Downloads\amana double door fridge.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000317993 _____ C:\Users\Jirka\Downloads\liqour bottle - Naranja.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000305619 _____ C:\Users\Jirka\Downloads\liqour bottle - Gran Marnier.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000167862 _____ C:\Users\Jirka\Downloads\liqour bottle - whiskey.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000164611 _____ C:\Users\Jirka\Downloads\liqour bottle - gold rum.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000157887 _____ C:\Users\Jirka\Downloads\liqour bottle - vodka.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000110293 _____ C:\Users\Jirka\Downloads\liqour bottle - DM root beer.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000055325 _____ C:\Users\Jirka\Downloads\liqour bottle - Demain cognac.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000022738 _____ C:\Users\Jirka\Downloads\bottle - jaqk wine.rao
2025-01-15 11:16 - 2025-01-15 11:16 - 000005628 _____ C:\Users\Jirka\Downloads\Picture by TS.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000042765 _____ C:\Users\Jirka\Downloads\Wall Clocks, Sunflowers 7.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000007263 _____ C:\Users\Jirka\Downloads\Light 2.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000006343 _____ C:\Users\Jirka\Downloads\Lamp 1.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000004070 _____ C:\Users\Jirka\Downloads\Light 1.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000003235 _____ C:\Users\Jirka\Downloads\Light 4.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000001459 _____ C:\Users\Jirka\Downloads\Light 3.rao
2025-01-15 11:15 - 2025-01-15 11:15 - 000001458 _____ C:\Users\Jirka\Downloads\Lamp 2.rao
2025-01-15 11:14 - 2025-01-15 11:14 - 000148548 _____ C:\Users\Jirka\Downloads\Gorenje K 28P by BJ.rap
2025-01-15 08:42 - 2025-02-10 15:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-01-15 08:42 - 2025-01-15 08:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\mde
2025-01-15 08:42 - 2025-01-15 08:42 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-01-15 08:32 - 2025-01-15 08:33 - 000000000 ____D C:\WINDOWS\CSC
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ___SD C:\WINDOWS\system32\AppV
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ____D C:\WINDOWS\RemotePackages
2025-01-15 08:32 - 2025-01-15 08:32 - 000000000 ____D C:\WINDOWS\Containers
2025-01-15 08:08 - 2025-01-15 08:10 - 000373324 _____ C:\Users\Jirka\Downloads\Děkujeme za objednávku - SERVIS-REPAS.CZ.pdf
2025-01-15 06:55 - 2025-01-15 06:55 - 000001345 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2025-01-15 06:55 - 2025-01-15 06:55 - 000000000 ____D C:\Users\Jirka\AppData\Local\PCHealthCheck
2025-01-14 05:58 - 2025-01-14 05:58 - 001413059 _____ C:\Users\Jirka\Downloads\julka-spalna.rap
2025-01-12 07:08 - 2025-01-12 07:08 - 000000848 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RoomAranger.lnk
2025-01-12 06:50 - 2025-01-12 06:50 - 000000000 ____D C:\Users\Jirka\AppData\Local\cache
2025-01-12 06:49 - 2025-01-12 06:49 - 000000000 ____D C:\Program Files\Room Arranger
2025-01-12 06:48 - 2025-01-12 06:48 - 023870896 _____ C:\Users\Jirka\Downloads\rooarr1001_64bit.exe
2025-01-12 06:44 - 2025-01-12 06:44 - 000299993 _____ C:\Users\Jirka\Downloads\Informace-zadost-106_Pr-001_2019-08-02_Info-106-99-MF-18721-2019-48.xlsx
2025-01-12 06:41 - 2025-01-12 06:41 - 000034914 _____ C:\Users\Jirka\Downloads\vzor-2022-zaverecne-vyuctovani-dotace-kopie-210422.xlsx
2025-01-11 16:25 - 2025-01-11 16:25 - 000043853 _____ C:\Users\Jirka\Downloads\externalTemplateLoader-0.4.4.xpi
2025-01-11 14:32 - 2025-01-22 08:41 - 000000000 ____D C:\Users\Jirka\AppData\Local\Room Arranger
2025-01-11 14:32 - 2025-01-11 14:33 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Room Arranger
2025-01-11 14:31 - 2025-01-12 06:49 - 000000888 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Room Arranger.lnk
2025-01-11 14:31 - 2025-01-11 16:58 - 000000000 ____D C:\Users\Jirka\Documents\Room Arranger
2025-01-11 14:31 - 2025-01-11 14:31 - 000000000 ____D C:\ProgramData\Room Arranger
2025-01-11 14:24 - 2025-01-16 13:13 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\UProof
2025-01-11 14:24 - 2025-01-11 14:24 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Proof
2025-01-11 14:23 - 2025-02-05 15:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Word
2025-01-11 14:23 - 2025-02-05 15:52 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Šablony
2025-01-11 14:23 - 2025-01-11 14:23 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Document Building Blocks
2025-01-11 14:20 - 2025-01-11 14:20 - 000000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2025-01-11 14:17 - 2025-01-11 14:17 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Outlook
2025-01-11 14:16 - 2025-01-30 09:18 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Excel
2025-01-11 14:16 - 2025-01-22 08:08 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Office
2025-01-11 14:16 - 2025-01-11 14:16 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Doplňky
2025-01-11 14:01 - 2025-01-27 16:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\WINDOWS\PCHEALTH
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Works
2025-01-11 14:00 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2025-01-11 13:59 - 2025-01-11 13:59 - 000000000 ____D C:\Program Files\Microsoft Office
2025-01-11 13:58 - 2025-01-11 14:00 - 000000000 ____D C:\WINDOWS\SHELLNEW
2025-01-11 13:58 - 2025-01-11 14:00 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2025-01-11 13:58 - 2025-01-11 13:58 - 000000000 __RHD C:\MSOCache
2025-01-11 13:58 - 2025-01-11 13:58 - 000000000 ____D C:\Users\Jirka\AppData\Local\Microsoft Help
2025-01-11 11:51 - 2025-02-05 15:11 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\PSpad
2025-01-11 11:51 - 2025-01-11 11:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSPad editor
2025-01-11 11:51 - 2025-01-11 11:51 - 000000000 ____D C:\Program Files (x86)\PSPad editor
2025-01-11 10:52 - 2025-01-11 10:52 - 000000696 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jirka.lnk
2025-01-11 10:52 - 2025-01-11 10:52 - 000000279 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tento počítač.lnk
2025-01-11 10:52 - 2025-01-11 10:52 - 000000279 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koš.lnk
2025-01-11 10:44 - 2025-01-15 08:53 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Tracker Software
2025-01-11 10:44 - 2025-01-11 10:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software
2025-01-11 10:44 - 2025-01-11 10:44 - 000000000 ____D C:\ProgramData\FileOpen
2025-01-11 10:44 - 2017-01-11 10:54 - 000059072 _____ (Tracker Software Products (Canada) Ltd.) C:\WINDOWS\system32\pxc60pm.dll
2025-01-11 10:43 - 2025-01-11 10:43 - 000000000 ____D C:\Program Files\Tracker Software
2025-01-11 10:40 - 2025-01-28 07:19 - 000000000 ____D C:\ProgramData\Package Cache
2025-01-11 10:28 - 2025-01-11 10:28 - 000000504 _____ C:\Users\Jirka\Documents\aktivace revouninstaler.rupaf
2025-01-11 10:26 - 2025-01-16 07:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\Users\Jirka\AppData\Local\VS Revo Group
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\ProgramData\VS Revo Group
2025-01-11 10:26 - 2025-01-11 10:26 - 000000000 ____D C:\Program Files\VS Revo Group
2025-01-11 10:25 - 2025-01-11 10:25 - 017948560 _____ (VS Revo Group ) C:\Users\Jirka\Downloads\RevoUninProSetup.exe
2025-01-11 09:43 - 2025-02-05 15:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-01-11 09:43 - 2025-02-05 15:56 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2025-01-11 09:43 - 2025-02-05 15:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-01-11 09:43 - 2025-01-11 09:43 - 066672584 _____ (Mozilla) C:\Users\Jirka\Downloads\Thunderbird Setup 128.6.0esr.exe
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Thunderbird
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Mozilla
2025-01-11 09:43 - 2025-01-11 09:43 - 000000000 ____D C:\Users\Jirka\AppData\Local\Thunderbird
2025-01-11 09:37 - 2025-02-03 08:57 - 000004266 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1736584655
2025-01-11 09:37 - 2025-02-03 08:57 - 000001386 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2025-01-11 09:37 - 2025-01-15 08:09 - 000004548 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1736584659
2025-01-11 09:37 - 2025-01-11 09:37 - 000000000 ____D C:\Users\Jirka\AppData\Local\Opera Software
2025-01-11 09:36 - 2025-01-11 09:36 - 002254144 _____ () C:\Users\Jirka\Downloads\OperaSetup.exe
2025-01-11 09:36 - 2025-01-11 09:36 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Opera Software
2025-01-11 09:29 - 2025-01-11 09:29 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\WinRAR
2025-01-11 09:26 - 2025-01-11 09:26 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-01-11 09:26 - 2025-01-11 09:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-01-11 09:25 - 2025-01-11 09:26 - 000000000 ____D C:\Program Files\WinRAR
2025-01-11 05:47 - 2025-01-11 05:47 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-02-10 15:09 - 2025-01-10 12:39 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-02-10 15:08 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-02-10 15:08 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-02-10 15:03 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-02-10 15:03 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-02-10 15:03 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF
2025-02-10 14:56 - 2025-01-10 12:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-10 14:56 - 2025-01-10 12:41 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2544418961-404871699-1754985800-1001
2025-02-10 14:56 - 2025-01-10 07:32 - 000002377 _____ C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-02-05 07:09 - 2025-01-10 11:56 - 000000000 ____D C:\ProgramData\NVIDIA
2025-02-05 07:08 - 2025-01-10 12:43 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-02-05 07:01 - 2025-01-10 12:41 - 000001752 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-02-05 07:01 - 2025-01-10 12:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-02-05 07:01 - 2025-01-10 11:55 - 000000000 __SHD C:\Users\Jirka\IntelGraphicsProfiles
2025-02-05 07:01 - 2025-01-10 07:26 - 000012288 ___SH C:\DumpStack.log.tmp
2025-02-05 07:00 - 2024-04-01 08:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-02-05 06:51 - 2025-01-10 07:26 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-02-05 06:50 - 2025-01-10 12:39 - 000478600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-02-05 06:50 - 2025-01-10 12:39 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-02-05 06:50 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka
2025-02-05 06:48 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\registration
2025-02-04 18:15 - 2025-01-10 07:31 - 000000000 ____D C:\Users\Jirka\AppData\Local\D3DSCache
2025-01-28 07:21 - 2025-01-10 08:55 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-10 08:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-01-28 07:19 - 2025-01-10 08:55 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-01-27 16:00 - 2025-01-10 08:55 - 000023019 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2025-01-27 16:00 - 2025-01-10 08:55 - 000020122 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2025-01-27 16:00 - 2025-01-10 08:55 - 000014135 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2025-01-24 09:57 - 2024-04-01 08:26 - 000000000 __RSD C:\WINDOWS\Media
2025-01-24 09:56 - 2025-01-10 07:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\MMC
2025-01-24 09:39 - 2025-01-10 08:55 - 000001205 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2025-01-22 08:42 - 2025-01-10 07:30 - 000000000 ____D C:\Users\Jirka\AppData\Local\ConnectedDevicesPlatform
2025-01-21 17:24 - 2025-01-10 07:32 - 000000000 ____D C:\Users\Jirka\AppData\Local\VirtualStore
2025-01-21 13:04 - 2025-01-10 12:00 - 000000000 ___DC C:\WINDOWS\Panther
2025-01-21 12:55 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2025-01-17 15:29 - 2025-01-10 07:30 - 000000000 ____D C:\Users\Jirka\AppData\Local\Packages
2025-01-17 13:31 - 2025-01-10 07:30 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-01-15 11:31 - 2025-01-10 07:38 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-01-15 09:33 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Windows
2025-01-15 08:32 - 2025-01-10 12:27 - 000000000 ____D C:\WINDOWS\InboxApps
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\security
2025-01-15 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-01-15 08:29 - 2025-01-10 07:28 - 000000000 ____D C:\ProgramData\Packages
2025-01-15 07:15 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-01-15 06:58 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-01-15 06:28 - 2025-01-10 07:38 - 206927936 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-01-14 16:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-01-11 14:20 - 2022-05-07 06:24 - 000000167 _____ C:\WINDOWS\win.ini
2025-01-11 13:59 - 2024-04-01 08:26 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-01-11 09:20 - 2025-01-10 12:32 - 000000000 ____D C:\Users\Jirka\AppData\Roaming\Microsoft\Spelling
2025-01-11 05:54 - 2025-01-10 08:01 - 000000000 ____D C:\Users\Jirka\AppData\Local\PlaceholderTileLogoFolder

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Re: Kontrola logu , proces system.

Napsal: 10 úno 2025 16:54
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp

EmptyTemp:
Hosts:
End
Uložte do C:\Users\Jirka\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Kontrola logu , proces system.

Napsal: 12 úno 2025 05:06
od ketez67
Fix result of Farbar Recovery Scan Tool (x64) Version: 11-02-2025
Ran by Jirka (12-02-2025 05:03:28) Run:1
Running from C:\Users\Jirka\Downloads\virty
Loaded Profiles: Jirka
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKU\S-1-5-21-2544418961-404871699-1754985800-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Jirka\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
C:\DumpStack.log.tmp

EmptyTemp:
Hosts:
End

*****************

Processes closed successfully.
"HKU\S-1-5-21-2544418961-404871699-1754985800-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
Could not move "C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2" => Scheduled to move on reboot.
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 158288365 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 368065 B
Edge => 0 B
Firefox => 0 B
Opera => 19008255 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 26864 B
Jirka => 193841292 B

RecycleBin => 1684475 B
EmptyTemp: => 357.2 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 12-02-2025 05:04:50)

C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 => Could not move
C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 05:04:50 ====

Re: Kontrola logu , proces system.

Napsal: 12 úno 2025 09:20
od Rudy
Smazáno. Snížila se spotřeba systé,ových prostředků? Mmch 10% není zase tak mnoho a v nouz. režimu neběží všechny procesy.

Re: Kontrola logu , proces system.

Napsal: 12 úno 2025 16:10
od ketez67
Dobrý den
Ne pořad ntoskrnl.exe žere mezi 8 - 15 % dnes jsem si všiml, že jsem notes dal uspat a jak jsem ho zapnul tak byl klid a ticho i když jsem pracoval s úpravami fotek. Hned jsem to šel vyzkoušet vypl jsem notes a proces se rozběhl a tak jsem ho dal uspat s nadějí že bude zase klid a nic.

Re: Kontrola logu , proces system.

Napsal: 12 úno 2025 16:56
od Rudy
Koukněte sem: https://www.zive.cz/poradna/vysoke-vyuz ... tanswers=1# . Je to systémová záležitost, s viry to nemá nic společného.

Re: Kontrola logu , proces system.

Napsal: 13 úno 2025 17:06
od ketez67
Děkuji za kontrolu logu článek jsem četl dřív než jste na něj upozornil je už staršího data.
Ještě jednou děkuji.

Re: Kontrola logu , proces system.

Napsal: 13 úno 2025 17:56
od Rudy
Rádo se stalo! :-)