Zpomalený PC
Napsal: 18 bře 2025 20:28
Dobrý den,
HDD často vytížen na 100%, celkově pomalý chod. Děkuji za pomoc.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-03-2025
Ran by Gor (administrator) on DESKTOP-72B6VSV (18-03-2025 19:51:42)
Running from C:\Users\jhonz\Desktop\FRST64.exe
Loaded Profiles: Gor
Platform: Microsoft Windows 10 Pro Version 22H2 19045.5608 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atiesrxx.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atieclxx.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <17>
(Oracle America, Inc. -> Oracle Corporation) E:\Program Files\OTE\runtime\bin\javaw.exe
(services.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atiesrxx.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\NisSrv.exe
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Schneider Electric -> Schneider Electric) [File not signed] C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe
(services.exe ->) (Schneider Electric -> Schneider Electric) [File not signed] C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
(Schneider Electric -> Schneider Electric) [File not signed] C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2501.1.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2509.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [11859680 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3147264 2021-08-20] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [BrStsInd00] => C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe [1885184 2012-12-18] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [480176 2019-06-07] (Schneider Electric -> Schneider Electric) [File not signed]
HKLM-x32\...\Run: [OtePkiClient] => E:\Program Files\OTE\OtePkiClient-2.6.exe [78336 2024-02-23] (OTE, a.s.) [File not signed]
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5007680 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [MicrosoftEdgeAutoLaunch_9433F0F67BB0CA384D427CACFB9DBC69] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4291128 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [CCleaner Smart Cleaning] => E:\Program Files\CCleaner\CCleaner64.exe [45452080 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [AvastBrowserAutoLaunch_9A25AE14D27C442B2D36462549D41684] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [GarminExpress] => E:\Program Files\Garmin\Garmin\Express\express.exe [28999440 2024-11-06] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5007680 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [AvastBrowserAutoLaunch_2393A21C72C23300E564BF07774A52C0] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [GarminExpress] => E:\Program Files\Garmin\Garmin\Express\express.exe [28999440 2024-11-06] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [CCleaner Smart Cleaning] => E:\Program Files\CCleaner\CCleaner64.exe [45452080 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-3033005680-393220151-2942893451-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4291128 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-500\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5007680 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\pdfcmon: C:\Windows\system32\pdfcmon.dll [181248 2022-10-31] (pdfforge GmbH) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\104.0.18003.81\Installer\chrmstp.exe [2022-08-18] (Avast Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2023-12-23]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric -> Schneider Electric) [File not signed]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {A6C14222-4FB9-4024-A172-B67A608435D2} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
Task: {4C7B03FF-6212-4149-9271-89B24841A6F5} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
Task: {6D583762-15FD-4BF0-B616-D6E0E330B926} - System32\Tasks\AvastBrowserProtectS-1-5-21-3033005680-393220151-2942893451-1007 => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1750664 2022-08-05] (Avast Software s.r.o. -> Avast Software)
Task: {B4B8C47F-C947-4377-A281-BA5E65CF62E2} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
Task: {6DD0DE38-2694-4CFC-93BE-D1DC87788898} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
Task: {9002D8D9-BF69-48C4-98BB-4FE7F1497A5D} - System32\Tasks\CCleaner Update => E:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B3DCFEBC-CFE0-40C7-B171-2025AABA4BA2} - System32\Tasks\CCleanerCrashReporting => E:\Program Files\CCleaner\CCleanerBugReport.exe [6139696 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "E:\Program Files\CCleaner\LOG" --programpath "E:\Program Files\CCleaner" --guid "e95f0aaf-9fd9-4834-aa74-2024c68e993a" --version "6.33.0.11465" --silent
Task: {BF1A1BDC-E4F7-4BD6-B5A2-4FA9AFA3F0BB} - System32\Tasks\CCleanerSkipUAC - Gor => E:\Program Files\CCleaner\CCleaner.exe [39224624 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {961D0C7C-548F-44AF-83BE-CC6AE43C824D} - System32\Tasks\GarminUpdaterTask => E:\Program Files\Garmin\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [30992 2024-11-06] (Garmin International, Inc. -> )
Task: {D79D6550-1B87-4218-9A41-AA9F43365328} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {171A1659-E2EC-480F-A948-CF22D4576D28} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {941134F8-FF04-4429-AABE-544CA0BD0A8F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DCD7C1C1-02C2-4977-B683-9882A37F775F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {11E35DB2-43A4-4F8E-B8EE-EBB0D358CBF8} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {D81236F3-4A66-4EE6-B32D-477F924A614A} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3033005680-393220151-2942893451-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {A6ADA0A8-ABDC-4298-9B1D-FF3E5B32268F} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3033005680-393220151-2942893451-1006 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {2CD3DB91-2619-4090-8BA8-F64096B4846A} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3033005680-393220151-2942893451-1007 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {6FC30F99-56A9-4967-B422-B808316F18E5} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34880 2025-03-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {A48DE569-ACF8-430D-91B9-BF78482C05A7} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {E78031C6-9C7C-4F28-A4BC-448130493FAE} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {357F00FD-E58A-4227-983E-B84E9A1AC2CA} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1006 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {E3A45598-1822-4945-BFF2-4708EECDFD7D} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1007 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {8E8AA1BE-4F24-463C-865D-9E35BB143ED0} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {D7658626-1DA9-4D94-8E4F-775EBE5816ED} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1001 => C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveLauncher.exe [669528 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {ADA41ABD-0B42-4A36-B76B-EC03D18B2ADD} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1007 => C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveLauncher.exe [669528 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {C00A249A-A6B1-4AD4-BB90-DCB399764E47} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-500 => C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveLauncher.exe [669528 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => E:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{dbe1fe2c-f503-4a02-9698-0682ff7c8581}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default [2025-03-17]
Edge DownloadDir: Default -> C:\Users\jhonz\Downloads
Edge StartupUrls: Default -> "hxxps://seznam.cz/"
Edge Extension: (Překladač - překlad a slovník) - C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cahegbfkmjbbjmglfcamfgojffcgnnoa [2024-12-08]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (Dokumenty Google offline) - C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-15]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
FireFox:
========
FF DefaultProfile: ufgfqr1x.default
FF ProfilePath: C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release [2025-03-18]
FF Homepage: Mozilla\Firefox\Profiles\sh5xz2qo.default-release -> hxxps://www.seznam.cz/
FF Extension: (AdBlocker Ultimate) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\adblockultimate@adblockultimate.net.xpi [2025-02-15]
FF Extension: (Zhasnout světla) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\stefanvandamme@stefanvd.net.xpi [2021-09-14]
FF Extension: (Google Translator for Firefox) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\translator@zoli.bod.xpi [2024-04-25]
FF Extension: (Str*Viewer for Strava) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\turangasoftware@gmail.com.xpi [2021-08-02]
FF Extension: (Sauce for Strava™) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{0f1b4c25-4ab0-411e-ba22-e56c27f3d151}.xpi [2025-03-04]
FF Extension: (FormApps Extension) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{69F080C9-A1D8-42F8-BD83-3D54D4BC81B3}.xpi [2021-10-18]
FF Extension: (strava-map-switcher) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{8bc8a884-a7db-45e3-84dd-963933a87d3c}.xpi [2023-07-28]
FF Extension: (Video DownloadHelper) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2025-01-31]
FF ProfilePath: C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\ufgfqr1x.default [2024-12-27]
FF Plugin: @videolan.org/vlc,version=3.0.20 -> E:\Program Files\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll [2022-03-10] (Avast Software s.r.o. -> AVAST Software)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll [2022-03-10] (Avast Software s.r.o. -> AVAST Software)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [14256 2019-06-07] (Schneider Electric -> Schneider Electric) [File not signed]
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [4261808 2019-06-07] (Schneider Electric -> Schneider Electric) [File not signed]
S3 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\104.0.18003.81\elevation_service.exe [2009480 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [321536 2021-08-20] (Brother Industries, Ltd.) [File not signed]
S3 CCleanerPerformanceOptimizerService; E:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1088816 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.031.0217.0003\FileSyncHelper.exe [3533648 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [13004248 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpDefenderCoreService.exe [1926976 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveUpdaterService.exe [3880256 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559328 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\NisSrv.exe [4352456 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MsMpEng.exe [270056 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 3xHybr64; C:\Windows\system32\DRIVERS\3xHybr64.sys [933760 2007-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Philips Semiconductors GmbH)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [278944 2025-03-06] (Microsoft Windows -> Microsoft Corporation)
R3 Ser2pl; C:\Windows\system32\DRIVERS\ser2pl64.sys [335008 2024-07-02] (Microsoft Windows Hardware Compatibility Publisher -> Prolific Technology Inc.)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ULCDRHlp; C:\Windows\SysWOW64\Drivers\ULCDRHlp.sys [27392 2004-12-23] (Ulead Systems, Inc.) [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [20016 2025-03-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [601520 2025-03-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [100768 2025-03-06] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-03-18 19:51 - 2025-03-18 19:54 - 000024004 _____ C:\Users\jhonz\Desktop\FRST.txt
2025-03-18 19:51 - 2025-03-18 19:54 - 000000000 ____D C:\FRST
2025-03-18 19:49 - 2025-03-18 19:49 - 002404352 _____ (Farbar) C:\Users\jhonz\Desktop\FRST64.exe
2025-03-18 19:34 - 2025-03-18 19:34 - 000001803 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-17.0.gz
2025-03-18 05:52 - 2025-03-18 05:52 - 000001669 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-17.0.gz
2025-03-17 18:54 - 2025-03-17 20:46 - 000000000 ____D C:\Users\jhonz\Documents\Reflect
2025-03-17 18:27 - 2025-03-17 18:27 - 000002023 _____ C:\Users\Public\Desktop\Macrium Reflect.lnk
2025-03-17 18:27 - 2025-03-17 18:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2025-03-17 18:27 - 2025-03-17 18:27 - 000000000 ____D C:\Program Files\Macrium
2025-03-17 18:18 - 2025-03-17 18:18 - 000000000 ____D C:\Users\jhonz\Downloads\Macrium
2025-03-17 18:17 - 2025-03-17 22:39 - 000000000 ____D C:\ProgramData\Macrium
2025-03-17 18:17 - 2025-03-17 18:17 - 005667264 _____ (Paramount Software UK Ltd) C:\Users\jhonz\Downloads\ReflectDLHF.exe
2025-03-17 18:03 - 2025-03-17 18:03 - 000001270 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-16.0.gz
2025-03-17 05:53 - 2025-03-17 05:53 - 000001290 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-16.0.gz
2025-03-16 21:22 - 2025-03-16 21:22 - 000152885 _____ C:\Users\jhonz\Downloads\priloha_1494831341_0_p721927976.pdf
2025-03-16 19:48 - 2025-03-16 19:48 - 000001274 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-15.0.gz
2025-03-16 05:53 - 2025-03-16 05:53 - 000001296 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-15.0.gz
2025-03-15 19:38 - 2025-03-15 19:38 - 000130285 _____ C:\Users\jhonz\Downloads\1102666138.pdf
2025-03-15 19:35 - 2025-03-15 19:35 - 000001277 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-14.0.gz
2025-03-15 06:01 - 2025-03-15 06:01 - 000001289 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-14.0.gz
2025-03-14 23:13 - 2025-03-14 23:13 - 000293984 _____ C:\Users\jhonz\Downloads\export(25).gpx
2025-03-14 21:12 - 2025-03-14 21:12 - 000241438 _____ C:\Users\jhonz\Downloads\export(24).gpx
2025-03-14 19:35 - 2025-03-14 19:35 - 000001277 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-13.0.gz
2025-03-14 05:55 - 2025-03-14 05:55 - 000001612 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-13.0.gz
2025-03-13 19:34 - 2025-03-13 19:34 - 000001279 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-12.0.gz
2025-03-13 05:55 - 2025-03-13 05:56 - 000001615 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-12.0.gz
2025-03-12 19:34 - 2025-03-12 19:34 - 000001278 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-11.0.gz
2025-03-12 15:52 - 2025-03-12 15:52 - 000000000 ___HD C:\$WinREAgent
2025-03-12 05:52 - 2025-03-12 22:56 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-03-12 05:51 - 2025-03-12 05:51 - 000001623 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-11.0.gz
2025-03-10 20:43 - 2025-03-10 20:43 - 000000839 _____ C:\Users\jhonz\Downloads\1st route - 2nd route(1).fit
2025-03-08 23:46 - 2025-03-08 23:46 - 001827521 _____ C:\Users\jhonz\Downloads\CDC-2021-0089-0024_attachment_1-1.pdf
2025-03-06 22:02 - 2025-03-06 22:02 - 000191807 _____ C:\Users\jhonz\Downloads\8.3. kratší.gpx
2025-03-06 21:57 - 2025-03-06 22:07 - 000212316 _____ C:\Users\jhonz\Downloads\8.3. delší.gpx
2025-03-01 23:55 - 2025-03-01 23:56 - 000000149 _____ C:\Users\jhonz\Desktop\Pegueot.url
2025-03-01 20:54 - 2025-03-01 20:54 - 000136094 _____ C:\Users\jhonz\Downloads\2.3.25.gpx
2025-02-27 21:39 - 2025-02-27 21:39 - 000000000 _____ C:\Users\jhonz\Desktop\VF34H5FWC9S151900.txt
2025-02-27 21:29 - 2025-02-27 21:29 - 000036206 _____ C:\Users\jhonz\Downloads\vozidlo-udaje.pdf
2025-02-27 19:40 - 2025-02-27 19:40 - 000135003 _____ C:\Users\jhonz\Downloads\Morning_Mountain_Bike_Ride.gpx
2025-02-25 21:44 - 2025-02-25 21:44 - 000076562 _____ C:\Users\jhonz\Downloads\Zelená karta k pojistné smlouvě číslo 5487092373.pdf
2025-02-23 20:14 - 2025-02-23 20:14 - 000178543 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-23 at 20.12.47.jpeg
2025-02-23 20:14 - 2025-02-23 20:14 - 000166963 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-23 at 20.12.46(1).jpeg
2025-02-23 20:14 - 2025-02-23 20:14 - 000145719 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-23 at 20.12.46.jpeg
2025-02-22 21:38 - 2025-02-22 21:38 - 000133479 _____ C:\Users\jhonz\Downloads\export(23).gpx
2025-02-21 21:56 - 2025-02-21 21:56 - 001916448 _____ C:\Users\jhonz\Downloads\fofr-cup-gps-data-gpx(2).gpx
2025-02-21 20:24 - 2025-02-21 20:24 - 000626777 _____ C:\Users\jhonz\Desktop\závody 25.xlsx
2025-02-16 19:37 - 2025-02-16 19:37 - 000264157 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-16 at 18.40.28.jpeg
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-03-18 19:57 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-03-18 19:35 - 2022-02-09 11:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-03-18 19:34 - 2021-08-01 09:17 - 000000000 ____D C:\Users\jhonz
2025-03-18 19:33 - 2021-12-18 01:19 - 000000000 ____D C:\Windows\SystemTemp
2025-03-18 18:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2025-03-18 14:20 - 2022-09-30 18:22 - 000003326 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2025-03-18 14:20 - 2022-09-30 18:22 - 000000670 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2025-03-18 05:52 - 2021-09-12 13:28 - 000000000 ____D C:\Users\Jirka 2
2025-03-17 23:16 - 2021-08-01 09:18 - 001702656 _____ C:\Windows\system32\PerfStringBackup.INI
2025-03-17 23:16 - 2019-12-07 15:43 - 000720264 _____ C:\Windows\system32\perfh005.dat
2025-03-17 23:16 - 2019-12-07 15:43 - 000146470 _____ C:\Windows\system32\perfc005.dat
2025-03-17 23:16 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2025-03-17 23:09 - 2021-08-01 09:07 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-03-17 23:09 - 2021-08-01 09:03 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-03-17 23:08 - 2021-08-01 09:03 - 000008192 ___SH C:\DumpStack.log.tmp
2025-03-17 18:12 - 2021-08-01 09:21 - 000000000 ____D C:\Users\jhonz\AppData\Local\Packages
2025-03-17 18:10 - 2021-12-23 20:09 - 000000000 ____D C:\Program Files\Common Files\Adobe
2025-03-16 20:30 - 2021-08-01 09:25 - 000000000 ____D C:\Users\jhonz\AppData\Local\D3DSCache
2025-03-16 19:48 - 2021-07-31 15:32 - 000000000 ____D C:\Users\jhonz\Documents\kolo
2025-03-16 19:32 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-03-16 06:00 - 2021-08-01 11:34 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-03-16 06:00 - 2021-08-01 11:34 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-03-15 06:06 - 2025-02-06 05:59 - 000003540 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-500
2025-03-15 06:06 - 2025-01-18 20:56 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-500
2025-03-15 06:06 - 2025-01-18 05:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1007
2025-03-15 06:06 - 2025-01-18 05:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1001
2025-03-15 06:06 - 2021-12-11 20:15 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1001
2025-03-15 06:06 - 2021-12-11 13:55 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1007
2025-03-15 06:06 - 2021-08-18 19:19 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-03-15 06:06 - 2021-08-01 20:52 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-03-15 06:06 - 2021-08-01 20:52 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-03-14 17:49 - 2021-09-12 13:28 - 000000000 ____D C:\Users\Jirka 2\AppData\Local\D3DSCache
2025-03-12 23:00 - 2023-12-25 13:43 - 000075587 _____ C:\Windows\SysWOW64\PCPELog.txt
2025-03-12 23:00 - 2021-08-01 09:23 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2025-03-12 23:00 - 2019-12-07 10:03 - 001572864 _____ C:\Windows\system32\config\BBI
2025-03-12 22:57 - 2021-08-01 09:03 - 000456120 _____ C:\Windows\system32\FNTCACHE.DAT
2025-03-12 22:56 - 2021-08-01 09:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-03-12 22:54 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-03-12 22:54 - 2019-12-07 15:44 - 000000000 ____D C:\Windows\system32\OpenSSH
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2025-03-12 22:54 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2025-03-12 16:38 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2025-03-12 16:27 - 2021-08-01 10:03 - 000419196 __RSH C:\bootmgr
2025-03-12 16:26 - 2021-08-01 09:09 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-03-12 13:56 - 2021-09-07 19:09 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2025-03-12 13:56 - 2021-08-01 09:54 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-03-11 22:48 - 2021-08-01 20:58 - 000000000 ____D C:\Users\jhonz\AppData\Roaming\Microsoft\Excel
2025-03-07 06:16 - 2021-08-01 11:34 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-03-07 06:16 - 2021-08-01 11:34 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-03-06 10:04 - 2021-08-01 09:07 - 000000000 ____D C:\Windows\system32\Drivers\wd
2025-02-28 20:41 - 2021-08-01 23:06 - 000074752 _____ C:\Users\jhonz\Desktop\porovnání spotřeby.xls
2025-02-28 19:41 - 2025-01-15 13:37 - 000000000 ____D C:\Windows\Minidump
2025-02-28 19:35 - 2022-08-17 16:50 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2025-02-18 19:36 - 2025-02-15 21:51 - 000000000 ____D C:\Users\Jirka 2\Documents\julča
==================== Files in the root of some directories ========
2025-01-08 00:17 - 2025-01-17 12:13 - 000007605 _____ () C:\Users\jhonz\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
HDD často vytížen na 100%, celkově pomalý chod. Děkuji za pomoc.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-03-2025
Ran by Gor (administrator) on DESKTOP-72B6VSV (18-03-2025 19:51:42)
Running from C:\Users\jhonz\Desktop\FRST64.exe
Loaded Profiles: Gor
Platform: Microsoft Windows 10 Pro Version 22H2 19045.5608 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atiesrxx.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atieclxx.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <17>
(Oracle America, Inc. -> Oracle Corporation) E:\Program Files\OTE\runtime\bin\javaw.exe
(services.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atiesrxx.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\NisSrv.exe
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Schneider Electric -> Schneider Electric) [File not signed] C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe
(services.exe ->) (Schneider Electric -> Schneider Electric) [File not signed] C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
(Schneider Electric -> Schneider Electric) [File not signed] C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2501.1.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2509.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [11859680 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3147264 2021-08-20] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [BrStsInd00] => C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe [1885184 2012-12-18] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [480176 2019-06-07] (Schneider Electric -> Schneider Electric) [File not signed]
HKLM-x32\...\Run: [OtePkiClient] => E:\Program Files\OTE\OtePkiClient-2.6.exe [78336 2024-02-23] (OTE, a.s.) [File not signed]
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5007680 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [MicrosoftEdgeAutoLaunch_9433F0F67BB0CA384D427CACFB9DBC69] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4291128 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [CCleaner Smart Cleaning] => E:\Program Files\CCleaner\CCleaner64.exe [45452080 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [AvastBrowserAutoLaunch_9A25AE14D27C442B2D36462549D41684] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-3033005680-393220151-2942893451-1001\...\Run: [GarminExpress] => E:\Program Files\Garmin\Garmin\Express\express.exe [28999440 2024-11-06] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5007680 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [AvastBrowserAutoLaunch_2393A21C72C23300E564BF07774A52C0] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [GarminExpress] => E:\Program Files\Garmin\Garmin\Express\express.exe [28999440 2024-11-06] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3033005680-393220151-2942893451-1007\...\Run: [CCleaner Smart Cleaning] => E:\Program Files\CCleaner\CCleaner64.exe [45452080 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-3033005680-393220151-2942893451-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4291128 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3033005680-393220151-2942893451-500\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5007680 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\pdfcmon: C:\Windows\system32\pdfcmon.dll [181248 2022-10-31] (pdfforge GmbH) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\104.0.18003.81\Installer\chrmstp.exe [2022-08-18] (Avast Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2023-12-23]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric -> Schneider Electric) [File not signed]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {A6C14222-4FB9-4024-A172-B67A608435D2} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
Task: {4C7B03FF-6212-4149-9271-89B24841A6F5} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2982144 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
Task: {6D583762-15FD-4BF0-B616-D6E0E330B926} - System32\Tasks\AvastBrowserProtectS-1-5-21-3033005680-393220151-2942893451-1007 => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowserProtect.exe [1750664 2022-08-05] (Avast Software s.r.o. -> Avast Software)
Task: {B4B8C47F-C947-4377-A281-BA5E65CF62E2} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
Task: {6DD0DE38-2694-4CFC-93BE-D1DC87788898} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
Task: {9002D8D9-BF69-48C4-98BB-4FE7F1497A5D} - System32\Tasks\CCleaner Update => E:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B3DCFEBC-CFE0-40C7-B171-2025AABA4BA2} - System32\Tasks\CCleanerCrashReporting => E:\Program Files\CCleaner\CCleanerBugReport.exe [6139696 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "E:\Program Files\CCleaner\LOG" --programpath "E:\Program Files\CCleaner" --guid "e95f0aaf-9fd9-4834-aa74-2024c68e993a" --version "6.33.0.11465" --silent
Task: {BF1A1BDC-E4F7-4BD6-B5A2-4FA9AFA3F0BB} - System32\Tasks\CCleanerSkipUAC - Gor => E:\Program Files\CCleaner\CCleaner.exe [39224624 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {961D0C7C-548F-44AF-83BE-CC6AE43C824D} - System32\Tasks\GarminUpdaterTask => E:\Program Files\Garmin\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [30992 2024-11-06] (Garmin International, Inc. -> )
Task: {D79D6550-1B87-4218-9A41-AA9F43365328} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {171A1659-E2EC-480F-A948-CF22D4576D28} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {941134F8-FF04-4429-AABE-544CA0BD0A8F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DCD7C1C1-02C2-4977-B683-9882A37F775F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {11E35DB2-43A4-4F8E-B8EE-EBB0D358CBF8} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {D81236F3-4A66-4EE6-B32D-477F924A614A} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3033005680-393220151-2942893451-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {A6ADA0A8-ABDC-4298-9B1D-FF3E5B32268F} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3033005680-393220151-2942893451-1006 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {2CD3DB91-2619-4090-8BA8-F64096B4846A} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3033005680-393220151-2942893451-1007 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {6FC30F99-56A9-4967-B422-B808316F18E5} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34880 2025-03-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {A48DE569-ACF8-430D-91B9-BF78482C05A7} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {E78031C6-9C7C-4F28-A4BC-448130493FAE} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {357F00FD-E58A-4227-983E-B84E9A1AC2CA} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1006 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {E3A45598-1822-4945-BFF2-4708EECDFD7D} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1007 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {8E8AA1BE-4F24-463C-865D-9E35BB143ED0} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222800 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {D7658626-1DA9-4D94-8E4F-775EBE5816ED} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1001 => C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveLauncher.exe [669528 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {ADA41ABD-0B42-4A36-B76B-EC03D18B2ADD} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1007 => C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveLauncher.exe [669528 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {C00A249A-A6B1-4AD4-BB90-DCB399764E47} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-500 => C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveLauncher.exe [669528 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => E:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{dbe1fe2c-f503-4a02-9698-0682ff7c8581}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default [2025-03-17]
Edge DownloadDir: Default -> C:\Users\jhonz\Downloads
Edge StartupUrls: Default -> "hxxps://seznam.cz/"
Edge Extension: (Překladač - překlad a slovník) - C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cahegbfkmjbbjmglfcamfgojffcgnnoa [2024-12-08]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (Dokumenty Google offline) - C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-15]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\jhonz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
FireFox:
========
FF DefaultProfile: ufgfqr1x.default
FF ProfilePath: C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release [2025-03-18]
FF Homepage: Mozilla\Firefox\Profiles\sh5xz2qo.default-release -> hxxps://www.seznam.cz/
FF Extension: (AdBlocker Ultimate) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\adblockultimate@adblockultimate.net.xpi [2025-02-15]
FF Extension: (Zhasnout světla) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\stefanvandamme@stefanvd.net.xpi [2021-09-14]
FF Extension: (Google Translator for Firefox) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\translator@zoli.bod.xpi [2024-04-25]
FF Extension: (Str*Viewer for Strava) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\turangasoftware@gmail.com.xpi [2021-08-02]
FF Extension: (Sauce for Strava™) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{0f1b4c25-4ab0-411e-ba22-e56c27f3d151}.xpi [2025-03-04]
FF Extension: (FormApps Extension) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{69F080C9-A1D8-42F8-BD83-3D54D4BC81B3}.xpi [2021-10-18]
FF Extension: (strava-map-switcher) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{8bc8a884-a7db-45e3-84dd-963933a87d3c}.xpi [2023-07-28]
FF Extension: (Video DownloadHelper) - C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\sh5xz2qo.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2025-01-31]
FF ProfilePath: C:\Users\jhonz\AppData\Roaming\Mozilla\Firefox\Profiles\ufgfqr1x.default [2024-12-27]
FF Plugin: @videolan.org/vlc,version=3.0.20 -> E:\Program Files\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll [2022-03-10] (Avast Software s.r.o. -> AVAST Software)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1206.2\npAvastBrowserUpdate3.dll [2022-03-10] (Avast Software s.r.o. -> AVAST Software)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [14256 2019-06-07] (Schneider Electric -> Schneider Electric) [File not signed]
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [4261808 2019-06-07] (Schneider Electric -> Schneider Electric) [File not signed]
S3 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [179936 2022-03-10] (Avast Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\104.0.18003.81\elevation_service.exe [2009480 2022-08-05] (Avast Software s.r.o. -> AVAST Software)
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [321536 2021-08-20] (Brother Industries, Ltd.) [File not signed]
S3 CCleanerPerformanceOptimizerService; E:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1088816 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.031.0217.0003\FileSyncHelper.exe [3533648 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [13004248 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpDefenderCoreService.exe [1926976 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.031.0217.0003\OneDriveUpdaterService.exe [3880256 2025-03-15] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559328 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\NisSrv.exe [4352456 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MsMpEng.exe [270056 2025-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 3xHybr64; C:\Windows\system32\DRIVERS\3xHybr64.sys [933760 2007-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Philips Semiconductors GmbH)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [278944 2025-03-06] (Microsoft Windows -> Microsoft Corporation)
R3 Ser2pl; C:\Windows\system32\DRIVERS\ser2pl64.sys [335008 2024-07-02] (Microsoft Windows Hardware Compatibility Publisher -> Prolific Technology Inc.)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ULCDRHlp; C:\Windows\SysWOW64\Drivers\ULCDRHlp.sys [27392 2004-12-23] (Ulead Systems, Inc.) [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [20016 2025-03-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [601520 2025-03-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [100768 2025-03-06] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-03-18 19:51 - 2025-03-18 19:54 - 000024004 _____ C:\Users\jhonz\Desktop\FRST.txt
2025-03-18 19:51 - 2025-03-18 19:54 - 000000000 ____D C:\FRST
2025-03-18 19:49 - 2025-03-18 19:49 - 002404352 _____ (Farbar) C:\Users\jhonz\Desktop\FRST64.exe
2025-03-18 19:34 - 2025-03-18 19:34 - 000001803 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-17.0.gz
2025-03-18 05:52 - 2025-03-18 05:52 - 000001669 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-17.0.gz
2025-03-17 18:54 - 2025-03-17 20:46 - 000000000 ____D C:\Users\jhonz\Documents\Reflect
2025-03-17 18:27 - 2025-03-17 18:27 - 000002023 _____ C:\Users\Public\Desktop\Macrium Reflect.lnk
2025-03-17 18:27 - 2025-03-17 18:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2025-03-17 18:27 - 2025-03-17 18:27 - 000000000 ____D C:\Program Files\Macrium
2025-03-17 18:18 - 2025-03-17 18:18 - 000000000 ____D C:\Users\jhonz\Downloads\Macrium
2025-03-17 18:17 - 2025-03-17 22:39 - 000000000 ____D C:\ProgramData\Macrium
2025-03-17 18:17 - 2025-03-17 18:17 - 005667264 _____ (Paramount Software UK Ltd) C:\Users\jhonz\Downloads\ReflectDLHF.exe
2025-03-17 18:03 - 2025-03-17 18:03 - 000001270 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-16.0.gz
2025-03-17 05:53 - 2025-03-17 05:53 - 000001290 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-16.0.gz
2025-03-16 21:22 - 2025-03-16 21:22 - 000152885 _____ C:\Users\jhonz\Downloads\priloha_1494831341_0_p721927976.pdf
2025-03-16 19:48 - 2025-03-16 19:48 - 000001274 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-15.0.gz
2025-03-16 05:53 - 2025-03-16 05:53 - 000001296 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-15.0.gz
2025-03-15 19:38 - 2025-03-15 19:38 - 000130285 _____ C:\Users\jhonz\Downloads\1102666138.pdf
2025-03-15 19:35 - 2025-03-15 19:35 - 000001277 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-14.0.gz
2025-03-15 06:01 - 2025-03-15 06:01 - 000001289 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-14.0.gz
2025-03-14 23:13 - 2025-03-14 23:13 - 000293984 _____ C:\Users\jhonz\Downloads\export(25).gpx
2025-03-14 21:12 - 2025-03-14 21:12 - 000241438 _____ C:\Users\jhonz\Downloads\export(24).gpx
2025-03-14 19:35 - 2025-03-14 19:35 - 000001277 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-13.0.gz
2025-03-14 05:55 - 2025-03-14 05:55 - 000001612 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-13.0.gz
2025-03-13 19:34 - 2025-03-13 19:34 - 000001279 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-12.0.gz
2025-03-13 05:55 - 2025-03-13 05:56 - 000001615 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-12.0.gz
2025-03-12 19:34 - 2025-03-12 19:34 - 000001278 _____ C:\Users\jhonz\ote-pki-client.log.2025-03-11.0.gz
2025-03-12 15:52 - 2025-03-12 15:52 - 000000000 ___HD C:\$WinREAgent
2025-03-12 05:52 - 2025-03-12 22:56 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-03-12 05:51 - 2025-03-12 05:51 - 000001623 _____ C:\Users\Jirka 2\ote-pki-client.log.2025-03-11.0.gz
2025-03-10 20:43 - 2025-03-10 20:43 - 000000839 _____ C:\Users\jhonz\Downloads\1st route - 2nd route(1).fit
2025-03-08 23:46 - 2025-03-08 23:46 - 001827521 _____ C:\Users\jhonz\Downloads\CDC-2021-0089-0024_attachment_1-1.pdf
2025-03-06 22:02 - 2025-03-06 22:02 - 000191807 _____ C:\Users\jhonz\Downloads\8.3. kratší.gpx
2025-03-06 21:57 - 2025-03-06 22:07 - 000212316 _____ C:\Users\jhonz\Downloads\8.3. delší.gpx
2025-03-01 23:55 - 2025-03-01 23:56 - 000000149 _____ C:\Users\jhonz\Desktop\Pegueot.url
2025-03-01 20:54 - 2025-03-01 20:54 - 000136094 _____ C:\Users\jhonz\Downloads\2.3.25.gpx
2025-02-27 21:39 - 2025-02-27 21:39 - 000000000 _____ C:\Users\jhonz\Desktop\VF34H5FWC9S151900.txt
2025-02-27 21:29 - 2025-02-27 21:29 - 000036206 _____ C:\Users\jhonz\Downloads\vozidlo-udaje.pdf
2025-02-27 19:40 - 2025-02-27 19:40 - 000135003 _____ C:\Users\jhonz\Downloads\Morning_Mountain_Bike_Ride.gpx
2025-02-25 21:44 - 2025-02-25 21:44 - 000076562 _____ C:\Users\jhonz\Downloads\Zelená karta k pojistné smlouvě číslo 5487092373.pdf
2025-02-23 20:14 - 2025-02-23 20:14 - 000178543 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-23 at 20.12.47.jpeg
2025-02-23 20:14 - 2025-02-23 20:14 - 000166963 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-23 at 20.12.46(1).jpeg
2025-02-23 20:14 - 2025-02-23 20:14 - 000145719 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-23 at 20.12.46.jpeg
2025-02-22 21:38 - 2025-02-22 21:38 - 000133479 _____ C:\Users\jhonz\Downloads\export(23).gpx
2025-02-21 21:56 - 2025-02-21 21:56 - 001916448 _____ C:\Users\jhonz\Downloads\fofr-cup-gps-data-gpx(2).gpx
2025-02-21 20:24 - 2025-02-21 20:24 - 000626777 _____ C:\Users\jhonz\Desktop\závody 25.xlsx
2025-02-16 19:37 - 2025-02-16 19:37 - 000264157 _____ C:\Users\jhonz\Downloads\WhatsApp Image 2025-02-16 at 18.40.28.jpeg
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-03-18 19:57 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-03-18 19:35 - 2022-02-09 11:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-03-18 19:34 - 2021-08-01 09:17 - 000000000 ____D C:\Users\jhonz
2025-03-18 19:33 - 2021-12-18 01:19 - 000000000 ____D C:\Windows\SystemTemp
2025-03-18 18:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2025-03-18 14:20 - 2022-09-30 18:22 - 000003326 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2025-03-18 14:20 - 2022-09-30 18:22 - 000000670 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2025-03-18 05:52 - 2021-09-12 13:28 - 000000000 ____D C:\Users\Jirka 2
2025-03-17 23:16 - 2021-08-01 09:18 - 001702656 _____ C:\Windows\system32\PerfStringBackup.INI
2025-03-17 23:16 - 2019-12-07 15:43 - 000720264 _____ C:\Windows\system32\perfh005.dat
2025-03-17 23:16 - 2019-12-07 15:43 - 000146470 _____ C:\Windows\system32\perfc005.dat
2025-03-17 23:16 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2025-03-17 23:09 - 2021-08-01 09:07 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-03-17 23:09 - 2021-08-01 09:03 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-03-17 23:08 - 2021-08-01 09:03 - 000008192 ___SH C:\DumpStack.log.tmp
2025-03-17 18:12 - 2021-08-01 09:21 - 000000000 ____D C:\Users\jhonz\AppData\Local\Packages
2025-03-17 18:10 - 2021-12-23 20:09 - 000000000 ____D C:\Program Files\Common Files\Adobe
2025-03-16 20:30 - 2021-08-01 09:25 - 000000000 ____D C:\Users\jhonz\AppData\Local\D3DSCache
2025-03-16 19:48 - 2021-07-31 15:32 - 000000000 ____D C:\Users\jhonz\Documents\kolo
2025-03-16 19:32 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-03-16 06:00 - 2021-08-01 11:34 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-03-16 06:00 - 2021-08-01 11:34 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-03-15 06:06 - 2025-02-06 05:59 - 000003540 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-500
2025-03-15 06:06 - 2025-01-18 20:56 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-500
2025-03-15 06:06 - 2025-01-18 05:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1007
2025-03-15 06:06 - 2025-01-18 05:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3033005680-393220151-2942893451-1001
2025-03-15 06:06 - 2021-12-11 20:15 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1001
2025-03-15 06:06 - 2021-12-11 13:55 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3033005680-393220151-2942893451-1007
2025-03-15 06:06 - 2021-08-18 19:19 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-03-15 06:06 - 2021-08-01 20:52 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-03-15 06:06 - 2021-08-01 20:52 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-03-14 17:49 - 2021-09-12 13:28 - 000000000 ____D C:\Users\Jirka 2\AppData\Local\D3DSCache
2025-03-12 23:00 - 2023-12-25 13:43 - 000075587 _____ C:\Windows\SysWOW64\PCPELog.txt
2025-03-12 23:00 - 2021-08-01 09:23 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2025-03-12 23:00 - 2019-12-07 10:03 - 001572864 _____ C:\Windows\system32\config\BBI
2025-03-12 22:57 - 2021-08-01 09:03 - 000456120 _____ C:\Windows\system32\FNTCACHE.DAT
2025-03-12 22:56 - 2021-08-01 09:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-03-12 22:54 - 2019-12-07 15:47 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-03-12 22:54 - 2019-12-07 15:44 - 000000000 ____D C:\Windows\system32\OpenSSH
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-03-12 22:54 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2025-03-12 22:54 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2025-03-12 16:38 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2025-03-12 16:27 - 2021-08-01 10:03 - 000419196 __RSH C:\bootmgr
2025-03-12 16:26 - 2021-08-01 09:09 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-03-12 13:56 - 2021-09-07 19:09 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2025-03-12 13:56 - 2021-08-01 09:54 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-03-11 22:48 - 2021-08-01 20:58 - 000000000 ____D C:\Users\jhonz\AppData\Roaming\Microsoft\Excel
2025-03-07 06:16 - 2021-08-01 11:34 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-03-07 06:16 - 2021-08-01 11:34 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-03-06 10:04 - 2021-08-01 09:07 - 000000000 ____D C:\Windows\system32\Drivers\wd
2025-02-28 20:41 - 2021-08-01 23:06 - 000074752 _____ C:\Users\jhonz\Desktop\porovnání spotřeby.xls
2025-02-28 19:41 - 2025-01-15 13:37 - 000000000 ____D C:\Windows\Minidump
2025-02-28 19:35 - 2022-08-17 16:50 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2025-02-18 19:36 - 2025-02-15 21:51 - 000000000 ____D C:\Users\Jirka 2\Documents\julča
==================== Files in the root of some directories ========
2025-01-08 00:17 - 2025-01-17 12:13 - 000007605 _____ () C:\Users\jhonz\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================