Prosím o kontrolu logů - výskyt Trojan:Win32/Wacatac
Napsal: 13 dub 2025 09:23
Dobrý den vážení, prosím o kontrolu logů a pomoc s odstraněním havěti.
Děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-04-2025
Ran by Pepík (administrator) on GAME_PC (Gigabyte Technology Co., Ltd. B550M DS3H AC) (13-04-2025 10:11:55)
Running from C:\Users\Pepík\Desktop\FRST64.exe
Loaded Profiles: Pepík & SQLTELEMETRY$WINCC
Platform: Microsoft Windows 11 Home Version 24H2 26100.3775 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe ->) (Siemens AG -> Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\pniomgr.exe
(C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oPNDiscoveryx64.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\um.Ris.exe
(C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\um.sso.exe
(Discord Inc. -> Discord Inc.) C:\Users\Pepík\AppData\Local\Discord\app-1.0.9188\Discord.exe <6>
(explorer.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(explorer.exe ->) (GAIJIN NETWORK LTD -> Gaijin) C:\Users\Pepík\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <34>
(explorer.exe ->) (Rainmeter Team -> Rainmeter) [File not signed] C:\Program Files\Rainmeter\Rainmeter.exe
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe
(explorer.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\UMTrayIcon.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\135.0.3179.73\Installer\setup.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_25060.205.3499.6849_x64__8wekyb3d8bbwe\ms-teams.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\EasyTuneEngineService.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\System32\GigabyteUpdateService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlceip.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Siemens\Automation\TIAADMIN\server\node.exe <2>
(services.exe ->) (OpenVPN Inc. -> ) C:\Program Files\OpenVPN Connect\agent_ovpnconnect.exe
(services.exe ->) (OpenVPN Inc. -> ) C:\Program Files\OpenVPN Connect\ovpnhelper_service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9f05190a2befb920\RtkAudUService64.exe <2>
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\CCAgent.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\CCEServer_x64.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\SCSDistServiceX.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\SCSMX.exe
(services.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files (x86)\Common Files\Siemens\bin\CCRemoteService.exe
(services.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files (x86)\Common Files\Siemens\commonarchiving\CCDBUtils.exe
(services.exe ->) (Siemens AG -> Siemens AG) C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCProjectMgr.exe
(services.exe ->) (Siemens AG -> Siemens AG) C:\Program Files (x86)\Siemens\Automation\WinCC RT Advanced\SmartServer.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oPNDiscoveryx64.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe
(services.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files\Common Files\Siemens\ETWEventCollector\bin\Siemens.Automation.Tracing.ETW.EventCollector.ServiceHost.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe
(services.exe ->) (Siemens AG -> SoftwareOption GmbH) C:\Program Files\Common Files\Siemens\SimNetCom\TraceConceptX.exe
(services.exe ->) (Siemens AG) [File not signed] C:\Program Files\Common Files\Siemens\TelemetryConnector\bin\Siemens.Simatic.TelemetryConnector.WindowsService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(Siemens AG -> Siemens AG) C:\Program Files\Siemens\Automation\TIAADMIN\server\modules\soft\native\TiaAdminNotifier.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2503.1001.9.0_x64__8wekyb3d8bbwe\XboxPcTray.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25022.57.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(sihost.exe ->) (Musecy SM Ltd. -> Muse) C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2514.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2503.1001.9.0_x64__8wekyb3d8bbwe\XboxPcApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2503.1001.9.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.296.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.5100.40.0_x64__cw5n1h2txyewy\WidgetBoard.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(svchost.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files\Common Files\Siemens\AlmPanelPlugin\ALMPanelPlugin.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [4143376 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9f05190a2befb920\RtkAudUService64.exe [2150760 2024-05-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [CCUCSurrogate.exe] => C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCUCSurrogate.exe [342536 2023-11-02] (Siemens AG -> )
HKLM-x32\...\Run: [TIAAdminNotifier] => C:\Program Files\Siemens\Automation\TIAADMIN\server\modules\soft\native\TIAAdminNotifier.exe [45064 2022-10-21] (Siemens AG -> Siemens AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1001\...\Run: [MicrosoftEdgeAutoLaunch_3EB89BCE30DDECA22A17FD5E3B8732EE] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4418112 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4694624 2025-04-02] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37357584 2025-04-11] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Gaijin.Net Updater] => C:\Users\Pepík\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [3067056 2024-02-14] (GAIJIN NETWORK LTD -> Gaijin)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Opera GX Stable] => C:\Users\Pepík\AppData\Local\Programs\Opera GX\opera.exe [1534856 2025-04-04] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Discord] => C:\Users\Pepík\AppData\Local\Discord\Update.exe [1505792 2024-11-25] (Discord Inc.) [File not signed]
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Opera GX Browser Assistant] => C:\Users\Pepík\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37357584 2025-04-11] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Discord] => C:\Users\Kubík\AppData\Local\Discord\Update.exe [1525024 2024-02-20] (Discord Inc. -> GitHub)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe [74683360 2025-04-01] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1892608 2025-03-31] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Gaijin.Net Updater] => C:\Users\Kubík\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [3067056 2024-02-14] (GAIJIN NETWORK LTD -> Gaijin)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [launcher] => C:\Program Files\Epic Games\WutheringWavesj3oFh\launcher.exe [15345976 2025-02-23] (KURO TECHNOLOGY (HONG KONG) CO., LIMITED -> Guangzhou Kuro Technology)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Medal] => C:\Users\Kubík\AppData\Local\Medal\update.exe [1962856 2025-04-04] (Ferox Games B.V. -> )
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Opera GX Stable] => C:\Users\Kubík\AppData\Local\Programs\Opera GX\opera.exe [1534856 2025-04-04] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Opera GX Browser Assistant] => C:\Users\Kubík\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Microsoft.Lists] => C:\Users\Kubík\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\Microsoft.SharePoint.exe [1030440 2025-04-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3786848 2025-04-03] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-598124734-1471702195-2874904135-1004\...\Run: [Battle.net] => C:\Program Files (x86)\Battle.net\Battle.net.exe [981632 2025-04-12] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-598124734-1471702195-2874904135-1004\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [45980192 2024-11-08] (NGWIN Software co. -> NGWIN)
HKLM\Software\...\AppCompatFlags\Custom\Siemens.Automation.Portal.exe: [{479eafda-32b8-47e0-9c89-d68f3b8a098f}.sdb] -> Siemens.Automation.Portal.exe
HKLM\Software\...\AppCompatFlags\InstalledSDB\{479eafda-32b8-47e0-9c89-d68f3b8a098f}: [DatabasePath] -> C:\Windows\AppPatch\CustomSDB\{479eafda-32b8-47e0-9c89-d68f3b8a098f}.sdb [2021-04-21]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.85\Installer\chrmstp.exe [2025-04-11] (Google LLC -> Google LLC)
Startup: C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2025-02-20]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Rainmeter Team -> Rainmeter) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\INZONE Hub.lnk [2024-12-25]
ShortcutTarget: INZONE Hub.lnk -> C:\Program Files\Sony\INZONE Hub\INZONEHub.exe (Sony Corporation -> Sony Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UMTrayicon.exe [2021-07-08] (SIEMENS AG) [symlink -> C:\Program Files\Siemens\Automation\UserManagement\BIN\UMTrayicon.exe]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {67627C21-4C89-415A-B47F-9303E3F579A1} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [672064 2023-11-16] (Advanced Micro Devices Inc. -> )
Task: {3BC2FA3B-6524-4385-94FA-C008ABA5B2F2} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Pepík\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15204208 2025-01-06] (ESET, spol. s r.o. -> ESET)
Task: {07B90453-047D-46AC-9A0A-FD88F6FA7676} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Pepík\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15204208 2025-01-06] (ESET, spol. s r.o. -> ESET)
Task: {6364DF76-1BFC-4160-AD52-18383C986B81} - System32\Tasks\GCC => C:\Program Files\GIGABYTE\Control Center\GCC.exe [35403888 2024-06-27] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) -> C:\Program Files\GIGABYTE\Control Center\\-b
Task: {6225C0B4-11AE-400F-BE56-D3139C196654} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem137.0.7115.0{16C3833B-C624-4F5A-AB38-2E341650135D} => C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe [7360096 2025-04-08] (Google LLC -> Google LLC)
Task: {DB48C1A4-1083-4438-800E-95DAC69A4D48} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [255040 2024-10-26] (Microsoft Corporation -> Microsoft)
Task: {67CCD214-A373-4E2B-A450-7FE097A15919} - System32\Tasks\Microsoft\Windows\AccountHealth\RecoverabilityToastTask => {B7F5B442-EBF8-46CD-9F0B-D8E45ED43492} C:\WINDOWS\system32\AccountHealth.dll [258048 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {27CE9D59-9D48-4D29-99BC-64657AEBA494} - System32\Tasks\Microsoft\Windows\Security\Pwdless\IntelligentPwdlessTask => {8702A841-D5CA-47C3-812D-9CEDC304C200}
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {E5150FC2-3919-43F2-9812-C82351280297} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {69A96C23-CEBE-4E2A-8989-EF20D84355BD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {145D2929-DCA1-4DEF-97D9-B8BEC97CF2AA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7A5FAADF-1C4C-4930-B409-80EA0DCFBCCC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0C402A8C-63FF-4126-9D88-FB0F07C6AE79} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3275808 2025-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4584BFDD-A1B9-4898-922C-34E73312EF33} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A5BD3E26-0FAF-47A5-B3FE-57034F65E5A8} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6D4BC268-BB9D-4511-8E85-D2A410A10B54} - System32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1002 => C:\Users\Pepík\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\OneDriveLauncher.exe [674624 2025-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {9C8CD0AA-CF2B-4D16-8F49-0BCFE5709336} - System32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1003 => C:\Users\Kubík\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\OneDriveLauncher.exe [674624 2025-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {A6CE320E-E2F7-4283-AFD1-8C666867B6C3} - System32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1004 => C:\Users\Honza\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\OneDriveLauncher.exe [674624 2025-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {93532F16-8937-4FAC-8E98-0A85B2F20AF8} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1731093148 => C:\Users\Kubík\AppData\Local\Programs\Opera GX\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Kubík\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {B4F64236-D95C-4264-9C1A-ADCD7D61E06A} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1738499635 => C:\Users\Pepík\AppData\Local\Programs\Opera GX\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Pepík\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {206FA742-111B-44F6-8621-2595CDB3A815} - System32\Tasks\Opera GX scheduled Autoupdate 1727636541 => C:\Users\Kubík\AppData\Local\Programs\Opera GX\autoupdate\opera_autoupdate.exe [5661064 2025-04-03] (Opera Norway AS -> Opera Software)
Task: {197E35CA-ECB1-4002-AD03-6EA8959A9BE1} - System32\Tasks\Opera GX scheduled Autoupdate 1732297780 => C:\Users\Pepík\AppData\Local\Programs\Opera GX\autoupdate\opera_autoupdate.exe [5661064 2025-04-03] (Opera Norway AS -> Opera Software)
Task: {11D8B74E-D8CE-44EE-9D06-3717973E6648} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2397440 2025-03-31] (Overwolf Ltd -> Overwolf LTD) -> C:\Program Files (x86)\Overwolf\/RunningFrom Schedule
Task: {229B8258-EF0C-490A-8E3D-3C82DA0E9EEA} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [728504 2023-08-04] (Advanced Micro Devices Inc. -> AMD)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2a46bb4f-55a0-4cac-ad90-fb16b9cde3f3}: [DhcpNameServer] 192.168.56.27
Tcpip\..\Interfaces\{9af5bb01-570b-4408-82b8-65b3620035bb}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{a48c8554-45b6-4342-beae-53bb0042d61b}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Profile: C:\Users\Pepík\AppData\Local\Microsoft\Edge\User Data\Default [2025-02-21]
Edge Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-13]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\Pepík\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-06]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.421.2 -> C:\Program Files\Java\jre1.8.0_421\bin\dtplugin\npDeployJava1.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.421.2 -> C:\Program Files\Java\jre1.8.0_421\bin\plugin2\npjp2.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
Chrome:
=======
CHR DefaultProfile: Guest Profile
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default [2025-04-13]
CHR Extension: (change-language) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\cofdbpoegempjloogbagkncekinflcnj [2025-03-17]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-24]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (All Black - Full Dark Theme/Black Theme) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkplpffahhkjfocfbfapcemhhkgmljpn [2024-03-06]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Shazam: Find song names from your browser) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmioliijnhnoblpgimnlajmefafdfilb [2025-02-13]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-06]hxxps://clients2.google.com/service/update2/crx
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Guest Profile [2025-04-13]
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 1 [2025-04-10]
CHR HomePage: Profile 1 -> hxxp://www.google.com/
CHR StartupUrls: Profile 1 -> "hxxps://mail.google.com/mail/u/0/?tab=rm&ogbl#inbox","hxxps://www.zskomtu.cz/"
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-27]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-06]hxxps://clients2.google.com/service/update2/crx
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 2 [2025-03-18]
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-18]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-03-18]hxxps://clients2.google.com/service/update2/crx
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\System Profile [2025-04-13]
Opera:
=======
StartMenuInternet: (HKU\S-1-5-21-598124734-1471702195-2874904135-1002) Opera GXStable - "C:\Users\Pepík\AppData\Local\Programs\Opera GX\opera.exe"
StartMenuInternet: (HKU\S-1-5-21-598124734-1471702195-2874904135-1003) Opera GXStable - "C:\Users\Kubík\AppData\Local\Programs\Opera GX\opera.exe"
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 agent_ovpnconnect; C:\Program Files\OpenVPN Connect\agent_ovpnconnect.exe [4688488 2024-07-17] (OpenVPN Inc. -> )
R2 almservice; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [2232328 2022-10-07] (Siemens AG -> SIEMENS AG)
R2 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe [527800 2023-08-04] (Advanced Micro Devices Inc. -> AMD)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3319424 2025-04-12] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [20285608 2025-04-04] (BattlEye Innovations e.K. -> )
R2 CCAgent; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\CCAgent.EXE [678224 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 CCAlgIAlarmDataCollector; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCAlgIAlarmDataCollector.exe [226792 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCAlgRtServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CcAlgRtServer.exe [148968 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCArchiveManagerService; C:\Program Files (x86)\Common Files\Siemens\CommonArchiving\CCArchiveManager.EXE [1062888 2021-04-16] (SIEMENS AG -> Siemens AG)
R2 CCDBUtils; C:\Program Files (x86)\Common Files\Siemens\CommonArchiving\CCDBUtils.EXE [158696 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCDeltaLoader; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCDeltaLoader.exe [890856 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCEClient; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\CCEClient_x64.exe [470088 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 CCEServer; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\CCEServer_x64.exe [410160 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 CCLicenseService; C:\Program Files (x86)\Common Files\Siemens\bin\CCLicenseService.exe [699400 2023-11-02] (Siemens AG -> Siemens AG)
S3 CCNSInfo2Provider; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCNSInfo2Provider.exe [772072 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCOpcUaImporter; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\OPC\UAClient\UaConfigServer\CCOpcUaImporter.exe [2603536 2023-10-31] (Siemens AG -> SIEMENS AG)
S3 CCPackageMgr; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCPackageMgr.exe [556008 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCPerfMon; C:\Program Files (x86)\Common Files\Siemens\bin\CCPerfMon.exe [595344 2016-07-11] (Siemens AG -> Siemens AG)
S3 CCProfileServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCProfileServer.exe [113128 2021-04-16] (SIEMENS AG -> Siemens AG)
R2 CCProjectMgr; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCProjectMgr.exe [8013328 2023-11-02] (Siemens AG -> Siemens AG)
S3 CCRedundancyAgent-Service; C:\Program Files (x86)\Common Files\Siemens\CommonArchiving\CCRedundancyAgent.exe [907752 2021-04-16] (SIEMENS AG -> Siemens AG)
R2 CCRemoteService; C:\Program Files (x86)\Common Files\Siemens\bin\CCRemoteService.exe [139752 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCRtsLoader; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCRtsLoader_x64.exe [154088 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCSystemDiagnosticsHost; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCSystemDiagnosticsHost.exe [102376 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCTextServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCTextServer.exe [663016 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCTlgServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCTlgServer.exe [147944 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCTMTimeSyncServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCTMTimeSyncServer.exe [382952 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CcUaDAS; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\OPC\UAClient\UaDAS\CcUaDAS.exe [5774344 2023-10-31] (Siemens AG -> SIEMENS AG)
S3 CCUsrAcv; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCUsrAcv.exe [1773584 2023-11-02] (Siemens AG -> Siemens AG)
U2 cortsmartserver; C:\Program Files (x86)\Siemens\Automation\WinCC RT Advanced\SmartServer.exe [906760 2023-11-16] (Siemens AG -> Siemens AG)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [18810976 2025-04-03] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1134624 2022-07-06] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [965872 2024-10-12] (EasyAntiCheat Oy -> Epic Games, Inc.)
R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [150640 2023-11-06] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 EpicGamesUpdater; C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3064848 2025-04-11] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [368088 2025-01-31] (Epic Games Inc. -> Epic Games, Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe [2009608 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MSSQL$WINCC; C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlservr.exe [485048 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
S3 MuseHub Updater Service; C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe [7815248 2025-01-31] (Musecy SM Ltd. -> Muse.Updater)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\Display.NvContainer\NVDisplay.Container.exe [1275024 2024-11-19] (NVIDIA Corporation -> NVIDIA Corporation)
S2 OCButtonService; C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\OcButtonService.exe [131184 2023-12-06] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2397440 2025-03-31] (Overwolf Ltd -> Overwolf LTD)
R2 ovpnhelper_service; C:\Program Files\OpenVPN Connect\ovpnhelper_service.exe [5218920 2024-07-17] (OpenVPN Inc. -> )
S3 RedundancyControl; C:\Program Files (x86)\Common Files\Siemens\ace\bin\RedundancyControl.exe [777392 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 RedundancyState; C:\Program Files (x86)\Common Files\Siemens\ace\bin\RedundancyState.exe [292928 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 s7oiehsx64; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [185968 2022-12-08] (Siemens AG -> SIEMENS AG)
R2 S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe [380792 2022-12-08] (Siemens AG -> SIEMENS AG)
R2 SCS Distribution Service; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\SCSDistServiceX.exe [367776 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 SCSFsX; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\SCSFsX.exe [234568 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 SCSMonitor; C:\Program Files (x86)\Common Files\Siemens\ace\bin\SCSMX.exe [308904 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 Siemens Diagnostics Data Collector Service; C:\Program Files\Common Files\Siemens\ETWEventCollector\bin\Siemens.Automation.Tracing.ETW.EventCollector.ServiceHost.exe [31304 2021-04-21] (SIEMENS AG -> Siemens AG)
R2 Siemens Telemetry Connector Service; C:\Program Files\Common Files\Siemens\TelemetryConnector\bin\Siemens.Simatic.TelemetryConnector.WindowsService.exe [8704 2022-08-29] (Siemens AG) [File not signed]
R2 SiemensTiaAdmin; C:\Program Files\Siemens\Automation\TIAADMIN\server\node.exe [57937528 2022-10-21] (OpenJS Foundation -> Node.js)
R2 SIMATIC PnDiscovery Service; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oPNDiscoveryx64.exe [890456 2022-12-08] (Siemens AG -> SIEMENS AG)
S4 SQLAgent$WINCC; C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\SQLAGENT.EXE [578744 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
R2 SQLTELEMETRY$WINCC; C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlceip.exe [246968 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
R2 TraceConceptX; C:\Program Files\Common Files\Siemens\SimNetCom\TraceConceptX.exe [114736 2022-06-20] (Siemens AG -> SoftwareOption GmbH)
S4 UMC Service; C:\Program Files\Siemens\Automation\UserManagement\BIN\UMCService.exe [350968 2021-07-08] (Siemens AG -> SIEMENS AG)
R2 umscsvc; C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe [489208 2021-07-08] (Siemens AG -> SIEMENS AG)
S4 UP Service; C:\Program Files\Siemens\Automation\UserManagement\BIN\UPService.exe [195320 2021-07-08] (Siemens AG -> SIEMENS AG)
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [763024 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [40071784 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
S3 VSInstallerElevationService; C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe [42544 2024-10-26] (Microsoft Corporation -> Microsoft)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [144000 2024-09-17] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe [4538400 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe [278320 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 GigabyteUpdateService; C:\WINDOWS\system32\GigabyteUpdateService.exe [861328 2025-04-13] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ACE-BASE; C:\Windows\system32\drivers\ACE-BASE.sys [2182128 2024-09-14] (Microsoft Windows Hardware Compatibility Publisher -> ANTICHEATEXPERT.COM)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [27920 2024-03-26] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 AudioMirror; C:\WINDOWS\System32\drivers\AudioMirror.sys [61800 2023-10-26] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 cortkbdrtmwdf; C:\Windows\system32\drivers\cortkbdrtmwdf.sys [25576 2021-01-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R1 CTIIO; C:\Windows\system32\drivers\CtiIo64.sys [34920 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
R3 dpmconv; C:\WINDOWS\System32\drivers\dpmconv.sys [268160 2020-08-19] (Microsoft Windows Hardware Compatibility Publisher -> Siemens AG)
R3 gdrv3; C:\Windows\System32\drivers\gdrv3.sys [52432 2024-08-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 HoYoProtect; C:\Windows\system32\HoYoKProtect.sys [3875992 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> miHoYo)
S3 INZONEHS; C:\WINDOWS\System32\DriverStore\FileRepository\inzoneheadset.inf_amd64_596822367d9ba756\INZONEHeadset.sys [187840 2024-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Sony Corporation)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 ovpn-dco; C:\WINDOWS\System32\drivers\ovpn-dco.sys [92664 2024-05-22] (WDKTestCert lev,133391533294737317 -> OpenVPN, Inc)
S4 RsFx0500; C:\WINDOWS\System32\DRIVERS\RsFx0500.sys [261848 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_0ca603ee5d51e3b2\rt68cx21x64.sys [810328 2024-03-19] (Realtek Semiconductor Corp. -> Realtek)
R3 s7odpx2x64; C:\WINDOWS\System32\drivers\s7odpx2x64.sys [101568 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7oppilx64; C:\WINDOWS\System32\Drivers\s7oppilx64.sys [47808 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7oppinx64; C:\WINDOWS\System32\drivers\s7oppinx64.sys [124608 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7oserix64; C:\WINDOWS\System32\Drivers\s7oserix64.sys [148160 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7osmcax64; C:\WINDOWS\System32\drivers\s7osmcax64.sys [236736 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7osobux64; C:\WINDOWS\System32\drivers\s7osobux64.sys [121536 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7otmcd64x; C:\WINDOWS\System32\Drivers\s7otmcd64x.sys [211136 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7otranx64; C:\WINDOWS\System32\drivers\s7otranx64.sys [281792 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7otsadx64; C:\WINDOWS\System32\drivers\s7otsadx64.sys [230592 2020-02-10] (Siemens AG -> SIEMENS AG)
R2 s7ousbu64x; C:\WINDOWS\System32\drivers\s7ousbu64x.sys [157888 2020-02-10] (Siemens AG -> SIEMENS AG)
R2 s7PnDiscoveryDriver; C:\WINDOWS\system32\DRIVERS\s7PnDiscoveryDriver.sys [46272 2020-02-10] (Siemens AG -> SIEMENS AG)
R2 Snpnio; C:\WINDOWS\system32\DRIVERS\snpnio.sys [100216 2021-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Siemens AG)
R2 SNTIE; C:\WINDOWS\system32\DRIVERS\sntie.sys [227288 2022-09-14] (Siemens AG -> Siemens AG)
R3 tap_ovpnconnect; C:\WINDOWS\System32\drivers\tap_ovpnconnect.sys [41112 2024-07-17] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-04-09] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
R3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [246200 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [256520 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxSup; C:\WINDOWS\system32\DRIVERS\VBoxSup.sys [1051944 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxUSBMon; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [195560 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [27067392 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
R3 vsnl2ada; C:\WINDOWS\System32\drivers\vsnl2ada.sys [137088 2020-08-19] (Microsoft Windows Hardware Compatibility Publisher -> SIEMENS AG)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20016 2025-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [605576 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 WinCCRtKbdFilter; C:\Windows\system32\drivers\WinCCRtKbdFilter.sys [24800 2021-04-16] (Siemens AG -> Windows (R) Win 7 DDK provider)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_bdb09ebda2834009\wini3ctarget.sys [75168 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-13 10:12 - 2025-04-13 10:12 - 000826668 _____ C:\WINDOWS\system32\perfh005.dat
2025-04-13 10:12 - 2025-04-13 10:12 - 000199566 _____ C:\WINDOWS\system32\perfc005.dat
2025-04-13 10:11 - 2025-04-13 10:12 - 000044071 _____ C:\Users\Pepík\Desktop\FRST.txt
2025-04-13 10:11 - 2025-04-13 10:12 - 000000000 ____D C:\FRST
2025-04-13 10:10 - 2025-04-13 10:10 - 002404864 _____ (Farbar) C:\Users\Pepík\Desktop\FRST64.exe
2025-04-12 18:20 - 2025-04-12 18:20 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-04-10 20:37 - 2025-04-10 20:37 - 000001391 _____ C:\Users\Pepík\Desktop\Roblox Player.lnk
2025-04-10 20:36 - 2025-04-10 20:36 - 000001219 _____ C:\Users\Pepík\Desktop\Roblox Studio.lnk
2025-04-10 20:31 - 2025-04-10 20:31 - 000000000 ____D C:\WINDOWS\system32\AccountHealthAssets
2025-04-10 20:31 - 2025-04-10 20:31 - 000000000 ____D C:\inetpub
2025-04-10 14:11 - 2025-04-12 20:20 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-09 16:11 - 2025-04-09 16:11 - 000029042 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-09 16:11 - 2025-04-09 16:11 - 000029042 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-06 13:42 - 2025-04-06 13:42 - 000881336 _____ C:\Users\Kubík\Downloads\AutoClicker-3.1.exe
2025-04-06 13:42 - 2025-04-06 13:42 - 000000000 ____D C:\Users\Kubík\Downloads\ACLib
2025-04-03 20:39 - 2025-04-03 20:40 - 000000000 ____D C:\Users\Pepík\Downloads\Wormhole bLWkLO
2025-04-03 20:38 - 2025-04-03 20:39 - 063448577 _____ C:\Users\Pepík\Downloads\Wormhole bLWkLO.zip
2025-04-03 20:12 - 2025-04-03 20:12 - 000005942 _____ C:\Users\Pepík\Downloads\traincraft 1.7.10.zip
2025-04-02 14:24 - 2025-04-02 14:25 - 000000000 ____D C:\Users\Pepík\AppData\Local\User Data
2025-04-02 14:24 - 2025-04-02 14:24 - 000000000 ____D C:\Users\Pepík\AppData\Local\nwjs
2025-04-01 15:44 - 2025-04-01 15:45 - 000000000 ___RD C:\Users\Pepík\Downloads\MicrosoftWindows.Client.CBS_cw5n1h2txyewy!InputApp
2025-03-31 11:06 - 2025-03-31 11:06 - 000000000 ____D C:\Users\Kubík\AppData\Local\EACrashReporter
2025-03-29 13:25 - 2025-03-29 13:25 - 000000000 ____D C:\ProgramData\CD Projekt Red
2025-03-28 20:10 - 2025-03-28 20:10 - 000000000 ____D C:\Users\Pepík\AppData\LocalLow\KishMish
2025-03-28 19:09 - 2025-03-28 19:09 - 000000223 _____ C:\Users\Pepík\Desktop\Bus World.url
2025-03-23 13:56 - 2025-03-29 18:26 - 000000000 ____D C:\Users\Pepík\AppData\LocalLow\Unity
2025-03-20 16:16 - 2025-03-29 12:13 - 000000000 ____D C:\Users\Kubík\AppData\Local\REDEngine
2025-03-20 16:16 - 2025-03-20 16:16 - 000000000 ____D C:\Users\Kubík\AppData\Local\CD Projekt Red
2025-03-20 10:11 - 2025-03-20 10:11 - 000000223 _____ C:\Users\Kubík\Desktop\Cyberpunk 2077.url
2025-03-20 10:11 - 2025-03-20 10:11 - 000000223 _____ C:\Users\Kubík\Desktop\Cyberpunk 2077 Bonus Content.url
2025-03-16 22:07 - 2025-03-16 22:07 - 000000000 ____D C:\Users\Pepík\AppData\LocalLow\EM Games
2025-03-14 14:55 - 2025-03-14 14:55 - 002253567 _____ C:\Users\Pepík\Downloads\create s lidma 1.20.1.zip
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-13 10:12 - 2025-02-21 21:41 - 002021898 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-13 10:12 - 2024-10-27 12:19 - 000000000 ____D C:\Users\Pepík\AppData\Local\Muse Hub
2025-04-13 10:12 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-13 10:08 - 2024-03-07 20:01 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2025-04-13 10:07 - 2024-03-07 15:46 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\discord
2025-04-13 10:06 - 2024-05-01 20:16 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Rainmeter
2025-04-13 10:06 - 2024-03-10 20:02 - 000000000 ____D C:\Users\Honza\AppData\Local\Battle.net
2025-04-13 10:06 - 2024-03-06 21:43 - 000000000 ____D C:\ProgramData\NVIDIA
2025-04-13 10:05 - 2025-02-21 21:41 - 000003432 _____ C:\WINDOWS\system32\Tasks\GCC
2025-04-13 10:05 - 2025-02-21 21:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-13 10:05 - 2025-02-21 21:39 - 000011826 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-13 10:05 - 2024-11-27 15:08 - 000000000 ____D C:\Users\Pepík\AppData\Local\Discord
2025-04-13 10:05 - 2024-10-27 12:19 - 000000000 ____D C:\Users\Pepík\AppData\Local\MuseSampler
2025-04-13 10:05 - 2024-10-27 12:19 - 000000000 ____D C:\ProgramData\boost_interprocess
2025-04-13 10:05 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-13 10:05 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-13 10:05 - 2024-03-06 22:07 - 000000000 ____D C:\Program Files (x86)\Steam
2025-04-13 10:05 - 2024-03-06 22:01 - 000000000 ___RD C:\Users\Pepík\OneDrive
2025-04-13 10:05 - 2024-03-06 21:49 - 000089232 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\system32\GigabyteDownloadAssistant.exe
2025-04-13 10:05 - 2024-03-06 21:35 - 000875536 _____ C:\WINDOWS\system32\wpbbin.exe
2025-04-13 10:05 - 2024-03-06 21:35 - 000861328 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\system32\GigabyteUpdateService.exe
2025-04-13 10:05 - 2024-03-06 21:35 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-13 10:04 - 2024-04-01 09:21 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2025-04-13 10:03 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-13 10:02 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-04-13 09:53 - 2024-03-10 20:02 - 000000000 ____D C:\Program Files (x86)\Battle.net
2025-04-12 21:15 - 2024-03-06 22:20 - 000000000 ____D C:\Users\Pepík\AppData\Local\Roblox
2025-04-12 17:30 - 2025-01-06 16:51 - 000001272 _____ C:\Users\Pepík\Desktop\ESET Online Scanner.lnk
2025-04-12 17:30 - 2024-03-07 17:38 - 000001378 _____ C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2025-04-12 11:47 - 2024-03-09 20:38 - 000000000 ____D C:\Users\Honza\AppData\Local\D3DSCache
2025-04-12 11:44 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-12 11:13 - 2024-03-09 20:36 - 000000000 ____D C:\Users\Honza\AppData\Local\Packages
2025-04-12 11:11 - 2024-03-06 21:36 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-12 11:10 - 2025-02-21 21:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-598124734-1471702195-2874904135-1004
2025-04-12 11:10 - 2025-02-21 21:41 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1004
2025-04-12 11:10 - 2025-02-21 21:41 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-598124734-1471702195-2874904135-1004
2025-04-12 11:10 - 2024-03-09 20:37 - 000002377 _____ C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-12 11:09 - 2024-03-09 20:36 - 000000000 ____D C:\Users\Honza\AppData\Local\NVIDIA Corporation
2025-04-11 19:18 - 2024-03-06 22:01 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-11 19:18 - 2024-03-06 22:01 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-04-10 20:43 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-10 20:37 - 2025-02-26 19:07 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-04-10 20:37 - 2025-02-26 19:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-04-10 20:37 - 2024-03-08 19:26 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-04-10 20:37 - 2024-03-06 22:20 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2025-04-10 20:37 - 2024-03-06 22:17 - 000000000 ____D C:\Users\Pepík\AppData\Local\NVIDIA Corporation
2025-04-10 20:35 - 2024-11-08 19:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox
2025-04-10 20:35 - 2024-03-08 19:37 - 000000000 ____D C:\Users\Pepík\AppData\Local\CrashDumps
2025-04-10 20:32 - 2025-02-21 21:37 - 000371552 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-10 20:31 - 2025-02-21 20:30 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-10 20:31 - 2025-02-21 20:23 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2025-04-10 20:31 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-04-10 20:31 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-04-10 20:31 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-10 20:31 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-04-10 20:31 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-04-10 20:30 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Medal
2025-04-10 20:30 - 2024-03-07 18:16 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\discord
2025-04-10 17:52 - 2024-03-06 22:02 - 000000000 ____D C:\Users\Pepík\AppData\Local\D3DSCache
2025-04-10 17:46 - 2024-03-06 23:21 - 000000000 ____D C:\Users\Kubík\AppData\Local\D3DSCache
2025-04-10 16:55 - 2024-03-07 18:16 - 000000000 ____D C:\Users\Kubík\AppData\Local\Discord
2025-04-10 15:50 - 2024-09-14 10:27 - 134222904 _____ C:\WINDOWS\392667600.dat
2025-04-10 15:46 - 2024-08-04 11:58 - 000001493 _____ C:\Users\Public\Desktop\Riot Client.lnk
2025-04-10 15:46 - 2024-03-07 19:28 - 000000000 ____D C:\ProgramData\Riot Games
2025-04-10 14:28 - 2024-03-07 19:30 - 000001426 _____ C:\Users\Kubík\Desktop\Roblox Player.lnk
2025-04-10 14:28 - 2024-03-07 19:30 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2025-04-10 14:28 - 2024-03-07 19:30 - 000000000 ____D C:\Users\Kubík\AppData\Local\Roblox
2025-04-10 14:27 - 2024-03-08 21:29 - 000000000 ____D C:\Users\Kubík\AppData\Local\CrashDumps
2025-04-10 14:27 - 2024-03-07 19:30 - 000001229 _____ C:\Users\Kubík\Desktop\Roblox Studio.lnk
2025-04-10 13:55 - 2024-10-25 21:12 - 000002317 _____ C:\Users\Kubík\Desktop\Mobius.lnk
2025-04-10 13:55 - 2024-09-29 21:20 - 000002317 _____ C:\Users\Kubík\Desktop\CurseForge.lnk
2025-04-10 13:55 - 2024-08-11 11:19 - 000001271 _____ C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Medal.lnk
2025-04-10 13:55 - 2024-08-11 11:19 - 000001263 _____ C:\Users\Kubík\Desktop\Medal.lnk
2025-04-10 13:55 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\Documents\Medal
2025-04-10 13:55 - 2024-08-11 11:19 - 000000000 ____D C:\Medal
2025-04-10 13:55 - 2024-08-04 12:01 - 000002317 _____ C:\Users\Kubík\Desktop\Control.lnk
2025-04-10 13:55 - 2024-06-29 12:54 - 000002317 _____ C:\Users\Kubík\Desktop\Valorant Tracker.lnk
2025-04-10 13:55 - 2024-04-27 20:30 - 000000000 ____D C:\Users\Kubík\AppData\Local\Overwolf
2025-04-10 13:55 - 2024-03-06 23:20 - 000000000 ___RD C:\Users\Kubík\OneDrive
2025-04-09 18:31 - 2025-02-21 21:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-598124734-1471702195-2874904135-1003
2025-04-09 18:31 - 2025-02-21 21:41 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1003
2025-04-09 18:31 - 2025-02-21 21:41 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-598124734-1471702195-2874904135-1003
2025-04-09 18:31 - 2024-03-06 23:20 - 000002377 _____ C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-09 17:40 - 2025-02-21 21:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-598124734-1471702195-2874904135-1002
2025-04-09 17:40 - 2025-02-21 21:41 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1002
2025-04-09 17:40 - 2025-02-21 21:41 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-598124734-1471702195-2874904135-1002
2025-04-09 17:40 - 2024-03-06 22:01 - 000002377 _____ C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-09 16:11 - 2025-02-21 21:40 - 003352064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-04-09 15:38 - 2024-03-08 20:49 - 000000000 ____D C:\Users\Pepík\AppData\Local\WarThunder
2025-04-08 20:28 - 2024-12-25 21:44 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\WeMod
2025-04-08 19:43 - 2024-03-06 23:24 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\EasyAntiCheat
2025-04-08 17:40 - 2024-12-25 21:44 - 000002201 _____ C:\Users\Pepík\Desktop\WeMod.lnk
2025-04-08 17:40 - 2024-12-25 21:44 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeMod
2025-04-08 17:40 - 2024-12-25 21:44 - 000000000 ____D C:\Users\Pepík\AppData\Local\WeMod
2025-04-08 17:40 - 2024-03-07 15:46 - 000000000 ____D C:\Users\Pepík\AppData\Local\SquirrelTemp
2025-04-08 17:18 - 2024-03-07 20:09 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\riot-client-ux
2025-04-08 15:02 - 2024-08-25 10:39 - 000000000 ____D C:\Program Files\DubbingAI
2025-04-07 18:14 - 2025-02-26 19:07 - 003114016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-04-07 18:14 - 2025-02-26 19:07 - 002403360 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-04-07 18:14 - 2024-03-08 19:26 - 000271392 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-04-07 18:14 - 2024-03-08 19:26 - 000245792 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-04-07 17:52 - 2024-03-08 19:26 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-04-07 17:52 - 2024-03-08 19:26 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-04-07 17:51 - 2024-03-08 19:26 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2025-04-06 10:05 - 2025-02-21 21:41 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-04-06 10:05 - 2025-02-21 21:41 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-04-06 09:56 - 2024-03-06 22:12 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-04 09:41 - 2025-02-21 21:41 - 000004234 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1727636541
2025-04-04 09:41 - 2024-09-29 21:02 - 000001473 _____ C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera GX.lnk
2025-04-04 09:41 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Medal B.V
2025-04-04 09:41 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\Medal
2025-04-04 09:40 - 2025-02-21 21:41 - 000004230 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1732297780
2025-04-04 09:40 - 2024-11-22 19:49 - 000001473 _____ C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera GX.lnk
2025-04-03 20:37 - 2024-09-29 15:43 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\.minecraft
2025-04-03 19:21 - 2024-03-20 15:41 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\MMC
2025-04-03 18:56 - 2024-09-28 17:57 - 000002243 _____ C:\Users\Pepík\Desktop\Discord.lnk
2025-04-03 17:20 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\log
2025-04-03 15:32 - 2024-12-08 00:05 - 000000000 ____D C:\ProgramData\EA Desktop
2025-04-02 17:20 - 2024-03-07 18:16 - 000002243 _____ C:\Users\Kubík\Desktop\Discord.lnk
2025-04-01 12:23 - 2024-03-06 21:35 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-04-01 12:06 - 2024-04-27 20:31 - 000000000 ____D C:\Program Files (x86)\Overwolf
2025-03-31 11:48 - 2024-09-29 21:02 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\.minecraft
2025-03-31 11:41 - 2024-09-29 21:02 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\.tlauncher
2025-03-30 17:50 - 2025-02-21 21:41 - 000003842 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2025-03-30 17:50 - 2025-02-21 21:41 - 000003400 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2025-03-30 12:57 - 2024-03-06 23:02 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\EasyAntiCheat
2025-03-30 10:39 - 2025-01-19 18:03 - 000000000 ____D C:\Users\Pepík\VirtualBox VMs
2025-03-30 10:39 - 2024-12-10 15:52 - 000000000 ____D C:\Users\Pepík\.VirtualBox
2025-03-29 19:42 - 2024-03-06 22:00 - 000000000 ____D C:\Users\Pepík\AppData\Local\Packages
2025-03-29 17:40 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\Ferox_Games_B.V
2025-03-29 17:38 - 2024-03-07 19:43 - 000000000 ____D C:\Program Files\Riot Vanguard
2025-03-28 17:02 - 2024-05-01 21:40 - 000000000 ____D C:\Users\Kubík\AppData\Local\ModernWarships
2025-03-27 18:15 - 2024-08-25 18:32 - 000000000 ____D C:\Users\Kubík\AppData\Local\Crossout
2025-03-27 16:17 - 2024-03-06 23:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\Packages
2025-03-23 14:08 - 2024-10-31 16:40 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\r2modman
2025-03-20 16:15 - 2024-12-08 00:05 - 000000000 ____D C:\Users\Kubík\AppData\Local\cache
2025-03-20 10:11 - 2024-12-07 23:43 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-03-18 21:45 - 2024-11-23 19:51 - 000000000 ____D C:\Users\Kubík\AppData\Local\Steam
2025-03-18 16:53 - 2025-01-05 16:58 - 000000000 ____D C:\Users\Pepík\Documents\Euro Truck Simulator 2
2025-03-18 16:16 - 2024-03-06 22:07 - 000000000 ____D C:\Users\Pepík\AppData\Local\Steam
2025-03-18 15:55 - 2024-08-25 10:39 - 000000877 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dubbing AI.lnk
2025-03-18 15:55 - 2024-08-25 10:39 - 000000865 _____ C:\Users\Public\Desktop\Dubbing AI.lnk
2025-03-15 14:22 - 2024-03-06 23:20 - 000000000 ____D C:\Users\Kubík\AppData\Local\PlaceholderTileLogoFolder
2025-03-15 12:15 - 2024-09-29 15:34 - 002897472 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2025-03-15 12:15 - 2024-09-29 15:34 - 000153152 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2025-03-15 12:15 - 2024-09-29 15:34 - 000124480 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2025-03-15 12:15 - 2024-09-29 15:34 - 000075304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2025-03-15 12:14 - 2024-09-29 15:34 - 000788008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2025-03-15 12:14 - 2024-09-29 15:34 - 000267816 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2025-03-15 12:14 - 2024-09-29 15:34 - 000243264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
==================== Files in the root of some directories ========
2024-04-01 19:45 - 2024-04-04 21:21 - 000000098 _____ () C:\Users\Pepík\AppData\Roaming\LauncherSettings_live.cfg
2024-04-04 21:01 - 2024-04-04 21:01 - 000002636 _____ () C:\Users\Pepík\AppData\Roaming\TheHunterSettings_live.bin
2024-04-04 21:12 - 2024-04-04 21:19 - 000000048 _____ () C:\Users\Pepík\AppData\Roaming\TheHunterSettings_steam_live.cfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-04-2025
Ran by Pepík (administrator) on GAME_PC (Gigabyte Technology Co., Ltd. B550M DS3H AC) (13-04-2025 10:11:55)
Running from C:\Users\Pepík\Desktop\FRST64.exe
Loaded Profiles: Pepík & SQLTELEMETRY$WINCC
Platform: Microsoft Windows 11 Home Version 24H2 26100.3775 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe ->) (Siemens AG -> Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\pniomgr.exe
(C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oPNDiscoveryx64.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\um.Ris.exe
(C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\um.sso.exe
(Discord Inc. -> Discord Inc.) C:\Users\Pepík\AppData\Local\Discord\app-1.0.9188\Discord.exe <6>
(explorer.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(explorer.exe ->) (GAIJIN NETWORK LTD -> Gaijin) C:\Users\Pepík\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <34>
(explorer.exe ->) (Rainmeter Team -> Rainmeter) [File not signed] C:\Program Files\Rainmeter\Rainmeter.exe
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe
(explorer.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\UMTrayIcon.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\135.0.3179.73\Installer\setup.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_25060.205.3499.6849_x64__8wekyb3d8bbwe\ms-teams.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\EasyTuneEngineService.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\System32\GigabyteUpdateService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlceip.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Siemens\Automation\TIAADMIN\server\node.exe <2>
(services.exe ->) (OpenVPN Inc. -> ) C:\Program Files\OpenVPN Connect\agent_ovpnconnect.exe
(services.exe ->) (OpenVPN Inc. -> ) C:\Program Files\OpenVPN Connect\ovpnhelper_service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9f05190a2befb920\RtkAudUService64.exe <2>
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\CCAgent.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\CCEServer_x64.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\SCSDistServiceX.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files (x86)\Common Files\Siemens\ace\bin\SCSMX.exe
(services.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files (x86)\Common Files\Siemens\bin\CCRemoteService.exe
(services.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files (x86)\Common Files\Siemens\commonarchiving\CCDBUtils.exe
(services.exe ->) (Siemens AG -> Siemens AG) C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCProjectMgr.exe
(services.exe ->) (Siemens AG -> Siemens AG) C:\Program Files (x86)\Siemens\Automation\WinCC RT Advanced\SmartServer.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oPNDiscoveryx64.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe
(services.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files\Common Files\Siemens\ETWEventCollector\bin\Siemens.Automation.Tracing.ETW.EventCollector.ServiceHost.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe
(services.exe ->) (Siemens AG -> SIEMENS AG) C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe
(services.exe ->) (Siemens AG -> SoftwareOption GmbH) C:\Program Files\Common Files\Siemens\SimNetCom\TraceConceptX.exe
(services.exe ->) (Siemens AG) [File not signed] C:\Program Files\Common Files\Siemens\TelemetryConnector\bin\Siemens.Simatic.TelemetryConnector.WindowsService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(Siemens AG -> Siemens AG) C:\Program Files\Siemens\Automation\TIAADMIN\server\modules\soft\native\TiaAdminNotifier.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2503.1001.9.0_x64__8wekyb3d8bbwe\XboxPcTray.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25022.57.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(sihost.exe ->) (Musecy SM Ltd. -> Muse) C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2514.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2503.1001.9.0_x64__8wekyb3d8bbwe\XboxPcApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2503.1001.9.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.296.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.5100.40.0_x64__cw5n1h2txyewy\WidgetBoard.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(svchost.exe ->) (SIEMENS AG -> Siemens AG) C:\Program Files\Common Files\Siemens\AlmPanelPlugin\ALMPanelPlugin.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [4143376 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9f05190a2befb920\RtkAudUService64.exe [2150760 2024-05-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [CCUCSurrogate.exe] => C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCUCSurrogate.exe [342536 2023-11-02] (Siemens AG -> )
HKLM-x32\...\Run: [TIAAdminNotifier] => C:\Program Files\Siemens\Automation\TIAADMIN\server\modules\soft\native\TIAAdminNotifier.exe [45064 2022-10-21] (Siemens AG -> Siemens AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1001\...\Run: [MicrosoftEdgeAutoLaunch_3EB89BCE30DDECA22A17FD5E3B8732EE] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4418112 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4694624 2025-04-02] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37357584 2025-04-11] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Gaijin.Net Updater] => C:\Users\Pepík\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [3067056 2024-02-14] (GAIJIN NETWORK LTD -> Gaijin)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Opera GX Stable] => C:\Users\Pepík\AppData\Local\Programs\Opera GX\opera.exe [1534856 2025-04-04] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Discord] => C:\Users\Pepík\AppData\Local\Discord\Update.exe [1505792 2024-11-25] (Discord Inc.) [File not signed]
HKU\S-1-5-21-598124734-1471702195-2874904135-1002\...\Run: [Opera GX Browser Assistant] => C:\Users\Pepík\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37357584 2025-04-11] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Discord] => C:\Users\Kubík\AppData\Local\Discord\Update.exe [1525024 2024-02-20] (Discord Inc. -> GitHub)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe [74683360 2025-04-01] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1892608 2025-03-31] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Gaijin.Net Updater] => C:\Users\Kubík\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [3067056 2024-02-14] (GAIJIN NETWORK LTD -> Gaijin)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [launcher] => C:\Program Files\Epic Games\WutheringWavesj3oFh\launcher.exe [15345976 2025-02-23] (KURO TECHNOLOGY (HONG KONG) CO., LIMITED -> Guangzhou Kuro Technology)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Medal] => C:\Users\Kubík\AppData\Local\Medal\update.exe [1962856 2025-04-04] (Ferox Games B.V. -> )
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Opera GX Stable] => C:\Users\Kubík\AppData\Local\Programs\Opera GX\opera.exe [1534856 2025-04-04] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Opera GX Browser Assistant] => C:\Users\Kubík\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [Microsoft.Lists] => C:\Users\Kubík\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\Microsoft.SharePoint.exe [1030440 2025-04-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-598124734-1471702195-2874904135-1003\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3786848 2025-04-03] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-598124734-1471702195-2874904135-1004\...\Run: [Battle.net] => C:\Program Files (x86)\Battle.net\Battle.net.exe [981632 2025-04-12] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-598124734-1471702195-2874904135-1004\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [45980192 2024-11-08] (NGWIN Software co. -> NGWIN)
HKLM\Software\...\AppCompatFlags\Custom\Siemens.Automation.Portal.exe: [{479eafda-32b8-47e0-9c89-d68f3b8a098f}.sdb] -> Siemens.Automation.Portal.exe
HKLM\Software\...\AppCompatFlags\InstalledSDB\{479eafda-32b8-47e0-9c89-d68f3b8a098f}: [DatabasePath] -> C:\Windows\AppPatch\CustomSDB\{479eafda-32b8-47e0-9c89-d68f3b8a098f}.sdb [2021-04-21]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.85\Installer\chrmstp.exe [2025-04-11] (Google LLC -> Google LLC)
Startup: C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2025-02-20]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Rainmeter Team -> Rainmeter) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\INZONE Hub.lnk [2024-12-25]
ShortcutTarget: INZONE Hub.lnk -> C:\Program Files\Sony\INZONE Hub\INZONEHub.exe (Sony Corporation -> Sony Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UMTrayicon.exe [2021-07-08] (SIEMENS AG) [symlink -> C:\Program Files\Siemens\Automation\UserManagement\BIN\UMTrayicon.exe]
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {67627C21-4C89-415A-B47F-9303E3F579A1} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [672064 2023-11-16] (Advanced Micro Devices Inc. -> )
Task: {3BC2FA3B-6524-4385-94FA-C008ABA5B2F2} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Pepík\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15204208 2025-01-06] (ESET, spol. s r.o. -> ESET)
Task: {07B90453-047D-46AC-9A0A-FD88F6FA7676} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Pepík\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15204208 2025-01-06] (ESET, spol. s r.o. -> ESET)
Task: {6364DF76-1BFC-4160-AD52-18383C986B81} - System32\Tasks\GCC => C:\Program Files\GIGABYTE\Control Center\GCC.exe [35403888 2024-06-27] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) -> C:\Program Files\GIGABYTE\Control Center\\-b
Task: {6225C0B4-11AE-400F-BE56-D3139C196654} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem137.0.7115.0{16C3833B-C624-4F5A-AB38-2E341650135D} => C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe [7360096 2025-04-08] (Google LLC -> Google LLC)
Task: {DB48C1A4-1083-4438-800E-95DAC69A4D48} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [255040 2024-10-26] (Microsoft Corporation -> Microsoft)
Task: {67CCD214-A373-4E2B-A450-7FE097A15919} - System32\Tasks\Microsoft\Windows\AccountHealth\RecoverabilityToastTask => {B7F5B442-EBF8-46CD-9F0B-D8E45ED43492} C:\WINDOWS\system32\AccountHealth.dll [258048 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {27CE9D59-9D48-4D29-99BC-64657AEBA494} - System32\Tasks\Microsoft\Windows\Security\Pwdless\IntelligentPwdlessTask => {8702A841-D5CA-47C3-812D-9CEDC304C200}
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {E5150FC2-3919-43F2-9812-C82351280297} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {69A96C23-CEBE-4E2A-8989-EF20D84355BD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {145D2929-DCA1-4DEF-97D9-B8BEC97CF2AA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7A5FAADF-1C4C-4930-B409-80EA0DCFBCCC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0C402A8C-63FF-4126-9D88-FB0F07C6AE79} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3275808 2025-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4584BFDD-A1B9-4898-922C-34E73312EF33} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A5BD3E26-0FAF-47A5-B3FE-57034F65E5A8} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6D4BC268-BB9D-4511-8E85-D2A410A10B54} - System32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1002 => C:\Users\Pepík\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\OneDriveLauncher.exe [674624 2025-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {9C8CD0AA-CF2B-4D16-8F49-0BCFE5709336} - System32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1003 => C:\Users\Kubík\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\OneDriveLauncher.exe [674624 2025-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {A6CE320E-E2F7-4283-AFD1-8C666867B6C3} - System32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1004 => C:\Users\Honza\AppData\Local\Microsoft\OneDrive\25.051.0317.0003\OneDriveLauncher.exe [674624 2025-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {93532F16-8937-4FAC-8E98-0A85B2F20AF8} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1731093148 => C:\Users\Kubík\AppData\Local\Programs\Opera GX\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Kubík\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {B4F64236-D95C-4264-9C1A-ADCD7D61E06A} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1738499635 => C:\Users\Pepík\AppData\Local\Programs\Opera GX\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Pepík\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {206FA742-111B-44F6-8621-2595CDB3A815} - System32\Tasks\Opera GX scheduled Autoupdate 1727636541 => C:\Users\Kubík\AppData\Local\Programs\Opera GX\autoupdate\opera_autoupdate.exe [5661064 2025-04-03] (Opera Norway AS -> Opera Software)
Task: {197E35CA-ECB1-4002-AD03-6EA8959A9BE1} - System32\Tasks\Opera GX scheduled Autoupdate 1732297780 => C:\Users\Pepík\AppData\Local\Programs\Opera GX\autoupdate\opera_autoupdate.exe [5661064 2025-04-03] (Opera Norway AS -> Opera Software)
Task: {11D8B74E-D8CE-44EE-9D06-3717973E6648} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2397440 2025-03-31] (Overwolf Ltd -> Overwolf LTD) -> C:\Program Files (x86)\Overwolf\/RunningFrom Schedule
Task: {229B8258-EF0C-490A-8E3D-3C82DA0E9EEA} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [728504 2023-08-04] (Advanced Micro Devices Inc. -> AMD)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2a46bb4f-55a0-4cac-ad90-fb16b9cde3f3}: [DhcpNameServer] 192.168.56.27
Tcpip\..\Interfaces\{9af5bb01-570b-4408-82b8-65b3620035bb}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{a48c8554-45b6-4342-beae-53bb0042d61b}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Profile: C:\Users\Pepík\AppData\Local\Microsoft\Edge\User Data\Default [2025-02-21]
Edge Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-13]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\Pepík\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-06]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.421.2 -> C:\Program Files\Java\jre1.8.0_421\bin\dtplugin\npDeployJava1.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.421.2 -> C:\Program Files\Java\jre1.8.0_421\bin\plugin2\npjp2.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
Chrome:
=======
CHR DefaultProfile: Guest Profile
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default [2025-04-13]
CHR Extension: (change-language) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\cofdbpoegempjloogbagkncekinflcnj [2025-03-17]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-24]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (All Black - Full Dark Theme/Black Theme) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkplpffahhkjfocfbfapcemhhkgmljpn [2024-03-06]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Shazam: Find song names from your browser) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmioliijnhnoblpgimnlajmefafdfilb [2025-02-13]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-06]hxxps://clients2.google.com/service/update2/crx
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Guest Profile [2025-04-13]
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 1 [2025-04-10]
CHR HomePage: Profile 1 -> hxxp://www.google.com/
CHR StartupUrls: Profile 1 -> "hxxps://mail.google.com/mail/u/0/?tab=rm&ogbl#inbox","hxxps://www.zskomtu.cz/"
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-27]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-06]hxxps://clients2.google.com/service/update2/crx
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 2 [2025-03-18]
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-18]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-03-18]hxxps://clients2.google.com/service/update2/crx
CHR Profile: C:\Users\Pepík\AppData\Local\Google\Chrome\User Data\System Profile [2025-04-13]
Opera:
=======
StartMenuInternet: (HKU\S-1-5-21-598124734-1471702195-2874904135-1002) Opera GXStable - "C:\Users\Pepík\AppData\Local\Programs\Opera GX\opera.exe"
StartMenuInternet: (HKU\S-1-5-21-598124734-1471702195-2874904135-1003) Opera GXStable - "C:\Users\Kubík\AppData\Local\Programs\Opera GX\opera.exe"
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 agent_ovpnconnect; C:\Program Files\OpenVPN Connect\agent_ovpnconnect.exe [4688488 2024-07-17] (OpenVPN Inc. -> )
R2 almservice; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [2232328 2022-10-07] (Siemens AG -> SIEMENS AG)
R2 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe [527800 2023-08-04] (Advanced Micro Devices Inc. -> AMD)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3319424 2025-04-12] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [20285608 2025-04-04] (BattlEye Innovations e.K. -> )
R2 CCAgent; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\CCAgent.EXE [678224 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 CCAlgIAlarmDataCollector; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCAlgIAlarmDataCollector.exe [226792 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCAlgRtServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CcAlgRtServer.exe [148968 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCArchiveManagerService; C:\Program Files (x86)\Common Files\Siemens\CommonArchiving\CCArchiveManager.EXE [1062888 2021-04-16] (SIEMENS AG -> Siemens AG)
R2 CCDBUtils; C:\Program Files (x86)\Common Files\Siemens\CommonArchiving\CCDBUtils.EXE [158696 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCDeltaLoader; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCDeltaLoader.exe [890856 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCEClient; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\CCEClient_x64.exe [470088 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 CCEServer; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\CCEServer_x64.exe [410160 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 CCLicenseService; C:\Program Files (x86)\Common Files\Siemens\bin\CCLicenseService.exe [699400 2023-11-02] (Siemens AG -> Siemens AG)
S3 CCNSInfo2Provider; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCNSInfo2Provider.exe [772072 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCOpcUaImporter; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\OPC\UAClient\UaConfigServer\CCOpcUaImporter.exe [2603536 2023-10-31] (Siemens AG -> SIEMENS AG)
S3 CCPackageMgr; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCPackageMgr.exe [556008 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCPerfMon; C:\Program Files (x86)\Common Files\Siemens\bin\CCPerfMon.exe [595344 2016-07-11] (Siemens AG -> Siemens AG)
S3 CCProfileServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCProfileServer.exe [113128 2021-04-16] (SIEMENS AG -> Siemens AG)
R2 CCProjectMgr; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCProjectMgr.exe [8013328 2023-11-02] (Siemens AG -> Siemens AG)
S3 CCRedundancyAgent-Service; C:\Program Files (x86)\Common Files\Siemens\CommonArchiving\CCRedundancyAgent.exe [907752 2021-04-16] (SIEMENS AG -> Siemens AG)
R2 CCRemoteService; C:\Program Files (x86)\Common Files\Siemens\bin\CCRemoteService.exe [139752 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCRtsLoader; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCRtsLoader_x64.exe [154088 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCSystemDiagnosticsHost; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCSystemDiagnosticsHost.exe [102376 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCTextServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCTextServer.exe [663016 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCTlgServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCTlgServer.exe [147944 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CCTMTimeSyncServer; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCTMTimeSyncServer.exe [382952 2021-04-16] (SIEMENS AG -> Siemens AG)
S3 CcUaDAS; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\OPC\UAClient\UaDAS\CcUaDAS.exe [5774344 2023-10-31] (Siemens AG -> SIEMENS AG)
S3 CCUsrAcv; C:\Program Files (x86)\Siemens\Automation\SCADA-RT_V11\WinCC\bin\CCUsrAcv.exe [1773584 2023-11-02] (Siemens AG -> Siemens AG)
U2 cortsmartserver; C:\Program Files (x86)\Siemens\Automation\WinCC RT Advanced\SmartServer.exe [906760 2023-11-16] (Siemens AG -> Siemens AG)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [18810976 2025-04-03] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1134624 2022-07-06] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [965872 2024-10-12] (EasyAntiCheat Oy -> Epic Games, Inc.)
R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [150640 2023-11-06] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 EpicGamesUpdater; C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3064848 2025-04-11] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [368088 2025-01-31] (Epic Games Inc. -> Epic Games, Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe [2009608 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MSSQL$WINCC; C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlservr.exe [485048 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
S3 MuseHub Updater Service; C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe [7815248 2025-01-31] (Musecy SM Ltd. -> Muse.Updater)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\Display.NvContainer\NVDisplay.Container.exe [1275024 2024-11-19] (NVIDIA Corporation -> NVIDIA Corporation)
S2 OCButtonService; C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\OcButtonService.exe [131184 2023-12-06] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2397440 2025-03-31] (Overwolf Ltd -> Overwolf LTD)
R2 ovpnhelper_service; C:\Program Files\OpenVPN Connect\ovpnhelper_service.exe [5218920 2024-07-17] (OpenVPN Inc. -> )
S3 RedundancyControl; C:\Program Files (x86)\Common Files\Siemens\ace\bin\RedundancyControl.exe [777392 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 RedundancyState; C:\Program Files (x86)\Common Files\Siemens\ace\bin\RedundancyState.exe [292928 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 s7oiehsx64; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [185968 2022-12-08] (Siemens AG -> SIEMENS AG)
R2 S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe [380792 2022-12-08] (Siemens AG -> SIEMENS AG)
R2 SCS Distribution Service; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\SCSDistServiceX.exe [367776 2023-10-30] (Siemens AG -> SIEMENS AG)
S3 SCSFsX; C:\Program Files (x86)\Common Files\Siemens\ACE\bin\SCSFsX.exe [234568 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 SCSMonitor; C:\Program Files (x86)\Common Files\Siemens\ace\bin\SCSMX.exe [308904 2023-10-30] (Siemens AG -> SIEMENS AG)
R2 Siemens Diagnostics Data Collector Service; C:\Program Files\Common Files\Siemens\ETWEventCollector\bin\Siemens.Automation.Tracing.ETW.EventCollector.ServiceHost.exe [31304 2021-04-21] (SIEMENS AG -> Siemens AG)
R2 Siemens Telemetry Connector Service; C:\Program Files\Common Files\Siemens\TelemetryConnector\bin\Siemens.Simatic.TelemetryConnector.WindowsService.exe [8704 2022-08-29] (Siemens AG) [File not signed]
R2 SiemensTiaAdmin; C:\Program Files\Siemens\Automation\TIAADMIN\server\node.exe [57937528 2022-10-21] (OpenJS Foundation -> Node.js)
R2 SIMATIC PnDiscovery Service; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oPNDiscoveryx64.exe [890456 2022-12-08] (Siemens AG -> SIEMENS AG)
S4 SQLAgent$WINCC; C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\SQLAGENT.EXE [578744 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
R2 SQLTELEMETRY$WINCC; C:\Program Files\Microsoft SQL Server\MSSQL14.WINCC\MSSQL\Binn\sqlceip.exe [246968 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
R2 TraceConceptX; C:\Program Files\Common Files\Siemens\SimNetCom\TraceConceptX.exe [114736 2022-06-20] (Siemens AG -> SoftwareOption GmbH)
S4 UMC Service; C:\Program Files\Siemens\Automation\UserManagement\BIN\UMCService.exe [350968 2021-07-08] (Siemens AG -> SIEMENS AG)
R2 umscsvc; C:\Program Files\Siemens\Automation\UserManagement\BIN\IPCSecCom.exe [489208 2021-07-08] (Siemens AG -> SIEMENS AG)
S4 UP Service; C:\Program Files\Siemens\Automation\UserManagement\BIN\UPService.exe [195320 2021-07-08] (Siemens AG -> SIEMENS AG)
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [763024 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [40071784 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
S3 VSInstallerElevationService; C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe [42544 2024-10-26] (Microsoft Corporation -> Microsoft)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [144000 2024-09-17] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe [4538400 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe [278320 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 GigabyteUpdateService; C:\WINDOWS\system32\GigabyteUpdateService.exe [861328 2025-04-13] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ACE-BASE; C:\Windows\system32\drivers\ACE-BASE.sys [2182128 2024-09-14] (Microsoft Windows Hardware Compatibility Publisher -> ANTICHEATEXPERT.COM)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [27920 2024-03-26] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 AudioMirror; C:\WINDOWS\System32\drivers\AudioMirror.sys [61800 2023-10-26] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 cortkbdrtmwdf; C:\Windows\system32\drivers\cortkbdrtmwdf.sys [25576 2021-01-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R1 CTIIO; C:\Windows\system32\drivers\CtiIo64.sys [34920 2024-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
R3 dpmconv; C:\WINDOWS\System32\drivers\dpmconv.sys [268160 2020-08-19] (Microsoft Windows Hardware Compatibility Publisher -> Siemens AG)
R3 gdrv3; C:\Windows\System32\drivers\gdrv3.sys [52432 2024-08-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 HoYoProtect; C:\Windows\system32\HoYoKProtect.sys [3875992 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> miHoYo)
S3 INZONEHS; C:\WINDOWS\System32\DriverStore\FileRepository\inzoneheadset.inf_amd64_596822367d9ba756\INZONEHeadset.sys [187840 2024-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Sony Corporation)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 ovpn-dco; C:\WINDOWS\System32\drivers\ovpn-dco.sys [92664 2024-05-22] (WDKTestCert lev,133391533294737317 -> OpenVPN, Inc)
S4 RsFx0500; C:\WINDOWS\System32\DRIVERS\RsFx0500.sys [261848 2017-08-22] (Microsoft Corporation -> Microsoft Corporation)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_0ca603ee5d51e3b2\rt68cx21x64.sys [810328 2024-03-19] (Realtek Semiconductor Corp. -> Realtek)
R3 s7odpx2x64; C:\WINDOWS\System32\drivers\s7odpx2x64.sys [101568 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7oppilx64; C:\WINDOWS\System32\Drivers\s7oppilx64.sys [47808 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7oppinx64; C:\WINDOWS\System32\drivers\s7oppinx64.sys [124608 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7oserix64; C:\WINDOWS\System32\Drivers\s7oserix64.sys [148160 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7osmcax64; C:\WINDOWS\System32\drivers\s7osmcax64.sys [236736 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7osobux64; C:\WINDOWS\System32\drivers\s7osobux64.sys [121536 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7otmcd64x; C:\WINDOWS\System32\Drivers\s7otmcd64x.sys [211136 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7otranx64; C:\WINDOWS\System32\drivers\s7otranx64.sys [281792 2020-02-10] (Siemens AG -> SIEMENS AG)
R3 s7otsadx64; C:\WINDOWS\System32\drivers\s7otsadx64.sys [230592 2020-02-10] (Siemens AG -> SIEMENS AG)
R2 s7ousbu64x; C:\WINDOWS\System32\drivers\s7ousbu64x.sys [157888 2020-02-10] (Siemens AG -> SIEMENS AG)
R2 s7PnDiscoveryDriver; C:\WINDOWS\system32\DRIVERS\s7PnDiscoveryDriver.sys [46272 2020-02-10] (Siemens AG -> SIEMENS AG)
R2 Snpnio; C:\WINDOWS\system32\DRIVERS\snpnio.sys [100216 2021-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Siemens AG)
R2 SNTIE; C:\WINDOWS\system32\DRIVERS\sntie.sys [227288 2022-09-14] (Siemens AG -> Siemens AG)
R3 tap_ovpnconnect; C:\WINDOWS\System32\drivers\tap_ovpnconnect.sys [41112 2024-07-17] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-04-09] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
R3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [246200 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [256520 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxSup; C:\WINDOWS\system32\DRIVERS\VBoxSup.sys [1051944 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 VBoxUSBMon; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [195560 2024-10-10] (Oracle America, Inc. -> Oracle and/or its affiliates)
R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [27067392 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
R3 vsnl2ada; C:\WINDOWS\System32\drivers\vsnl2ada.sys [137088 2020-08-19] (Microsoft Windows Hardware Compatibility Publisher -> SIEMENS AG)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20016 2025-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [605576 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 WinCCRtKbdFilter; C:\Windows\system32\drivers\WinCCRtKbdFilter.sys [24800 2021-04-16] (Siemens AG -> Windows (R) Win 7 DDK provider)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_bdb09ebda2834009\wini3ctarget.sys [75168 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-13 10:12 - 2025-04-13 10:12 - 000826668 _____ C:\WINDOWS\system32\perfh005.dat
2025-04-13 10:12 - 2025-04-13 10:12 - 000199566 _____ C:\WINDOWS\system32\perfc005.dat
2025-04-13 10:11 - 2025-04-13 10:12 - 000044071 _____ C:\Users\Pepík\Desktop\FRST.txt
2025-04-13 10:11 - 2025-04-13 10:12 - 000000000 ____D C:\FRST
2025-04-13 10:10 - 2025-04-13 10:10 - 002404864 _____ (Farbar) C:\Users\Pepík\Desktop\FRST64.exe
2025-04-12 18:20 - 2025-04-12 18:20 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-04-10 20:37 - 2025-04-10 20:37 - 000001391 _____ C:\Users\Pepík\Desktop\Roblox Player.lnk
2025-04-10 20:36 - 2025-04-10 20:36 - 000001219 _____ C:\Users\Pepík\Desktop\Roblox Studio.lnk
2025-04-10 20:31 - 2025-04-10 20:31 - 000000000 ____D C:\WINDOWS\system32\AccountHealthAssets
2025-04-10 20:31 - 2025-04-10 20:31 - 000000000 ____D C:\inetpub
2025-04-10 14:11 - 2025-04-12 20:20 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-09 16:11 - 2025-04-09 16:11 - 000029042 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-09 16:11 - 2025-04-09 16:11 - 000029042 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-06 13:42 - 2025-04-06 13:42 - 000881336 _____ C:\Users\Kubík\Downloads\AutoClicker-3.1.exe
2025-04-06 13:42 - 2025-04-06 13:42 - 000000000 ____D C:\Users\Kubík\Downloads\ACLib
2025-04-03 20:39 - 2025-04-03 20:40 - 000000000 ____D C:\Users\Pepík\Downloads\Wormhole bLWkLO
2025-04-03 20:38 - 2025-04-03 20:39 - 063448577 _____ C:\Users\Pepík\Downloads\Wormhole bLWkLO.zip
2025-04-03 20:12 - 2025-04-03 20:12 - 000005942 _____ C:\Users\Pepík\Downloads\traincraft 1.7.10.zip
2025-04-02 14:24 - 2025-04-02 14:25 - 000000000 ____D C:\Users\Pepík\AppData\Local\User Data
2025-04-02 14:24 - 2025-04-02 14:24 - 000000000 ____D C:\Users\Pepík\AppData\Local\nwjs
2025-04-01 15:44 - 2025-04-01 15:45 - 000000000 ___RD C:\Users\Pepík\Downloads\MicrosoftWindows.Client.CBS_cw5n1h2txyewy!InputApp
2025-03-31 11:06 - 2025-03-31 11:06 - 000000000 ____D C:\Users\Kubík\AppData\Local\EACrashReporter
2025-03-29 13:25 - 2025-03-29 13:25 - 000000000 ____D C:\ProgramData\CD Projekt Red
2025-03-28 20:10 - 2025-03-28 20:10 - 000000000 ____D C:\Users\Pepík\AppData\LocalLow\KishMish
2025-03-28 19:09 - 2025-03-28 19:09 - 000000223 _____ C:\Users\Pepík\Desktop\Bus World.url
2025-03-23 13:56 - 2025-03-29 18:26 - 000000000 ____D C:\Users\Pepík\AppData\LocalLow\Unity
2025-03-20 16:16 - 2025-03-29 12:13 - 000000000 ____D C:\Users\Kubík\AppData\Local\REDEngine
2025-03-20 16:16 - 2025-03-20 16:16 - 000000000 ____D C:\Users\Kubík\AppData\Local\CD Projekt Red
2025-03-20 10:11 - 2025-03-20 10:11 - 000000223 _____ C:\Users\Kubík\Desktop\Cyberpunk 2077.url
2025-03-20 10:11 - 2025-03-20 10:11 - 000000223 _____ C:\Users\Kubík\Desktop\Cyberpunk 2077 Bonus Content.url
2025-03-16 22:07 - 2025-03-16 22:07 - 000000000 ____D C:\Users\Pepík\AppData\LocalLow\EM Games
2025-03-14 14:55 - 2025-03-14 14:55 - 002253567 _____ C:\Users\Pepík\Downloads\create s lidma 1.20.1.zip
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-04-13 10:12 - 2025-02-21 21:41 - 002021898 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-13 10:12 - 2024-10-27 12:19 - 000000000 ____D C:\Users\Pepík\AppData\Local\Muse Hub
2025-04-13 10:12 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-13 10:08 - 2024-03-07 20:01 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2025-04-13 10:07 - 2024-03-07 15:46 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\discord
2025-04-13 10:06 - 2024-05-01 20:16 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Rainmeter
2025-04-13 10:06 - 2024-03-10 20:02 - 000000000 ____D C:\Users\Honza\AppData\Local\Battle.net
2025-04-13 10:06 - 2024-03-06 21:43 - 000000000 ____D C:\ProgramData\NVIDIA
2025-04-13 10:05 - 2025-02-21 21:41 - 000003432 _____ C:\WINDOWS\system32\Tasks\GCC
2025-04-13 10:05 - 2025-02-21 21:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-13 10:05 - 2025-02-21 21:39 - 000011826 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-13 10:05 - 2024-11-27 15:08 - 000000000 ____D C:\Users\Pepík\AppData\Local\Discord
2025-04-13 10:05 - 2024-10-27 12:19 - 000000000 ____D C:\Users\Pepík\AppData\Local\MuseSampler
2025-04-13 10:05 - 2024-10-27 12:19 - 000000000 ____D C:\ProgramData\boost_interprocess
2025-04-13 10:05 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-13 10:05 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-13 10:05 - 2024-03-06 22:07 - 000000000 ____D C:\Program Files (x86)\Steam
2025-04-13 10:05 - 2024-03-06 22:01 - 000000000 ___RD C:\Users\Pepík\OneDrive
2025-04-13 10:05 - 2024-03-06 21:49 - 000089232 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\system32\GigabyteDownloadAssistant.exe
2025-04-13 10:05 - 2024-03-06 21:35 - 000875536 _____ C:\WINDOWS\system32\wpbbin.exe
2025-04-13 10:05 - 2024-03-06 21:35 - 000861328 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\system32\GigabyteUpdateService.exe
2025-04-13 10:05 - 2024-03-06 21:35 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-13 10:04 - 2024-04-01 09:21 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2025-04-13 10:03 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-13 10:02 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-04-13 09:53 - 2024-03-10 20:02 - 000000000 ____D C:\Program Files (x86)\Battle.net
2025-04-12 21:15 - 2024-03-06 22:20 - 000000000 ____D C:\Users\Pepík\AppData\Local\Roblox
2025-04-12 17:30 - 2025-01-06 16:51 - 000001272 _____ C:\Users\Pepík\Desktop\ESET Online Scanner.lnk
2025-04-12 17:30 - 2024-03-07 17:38 - 000001378 _____ C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2025-04-12 11:47 - 2024-03-09 20:38 - 000000000 ____D C:\Users\Honza\AppData\Local\D3DSCache
2025-04-12 11:44 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-12 11:13 - 2024-03-09 20:36 - 000000000 ____D C:\Users\Honza\AppData\Local\Packages
2025-04-12 11:11 - 2024-03-06 21:36 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-12 11:10 - 2025-02-21 21:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-598124734-1471702195-2874904135-1004
2025-04-12 11:10 - 2025-02-21 21:41 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1004
2025-04-12 11:10 - 2025-02-21 21:41 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-598124734-1471702195-2874904135-1004
2025-04-12 11:10 - 2024-03-09 20:37 - 000002377 _____ C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-12 11:09 - 2024-03-09 20:36 - 000000000 ____D C:\Users\Honza\AppData\Local\NVIDIA Corporation
2025-04-11 19:18 - 2024-03-06 22:01 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-11 19:18 - 2024-03-06 22:01 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-04-10 20:43 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-10 20:37 - 2025-02-26 19:07 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-04-10 20:37 - 2025-02-26 19:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-04-10 20:37 - 2024-03-08 19:26 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-04-10 20:37 - 2024-03-06 22:20 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2025-04-10 20:37 - 2024-03-06 22:17 - 000000000 ____D C:\Users\Pepík\AppData\Local\NVIDIA Corporation
2025-04-10 20:35 - 2024-11-08 19:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox
2025-04-10 20:35 - 2024-03-08 19:37 - 000000000 ____D C:\Users\Pepík\AppData\Local\CrashDumps
2025-04-10 20:32 - 2025-02-21 21:37 - 000371552 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-10 20:31 - 2025-02-21 20:30 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-10 20:31 - 2025-02-21 20:23 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2025-04-10 20:31 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-04-10 20:31 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-04-10 20:31 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-10 20:31 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-10 20:31 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-04-10 20:31 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-04-10 20:30 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Medal
2025-04-10 20:30 - 2024-03-07 18:16 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\discord
2025-04-10 17:52 - 2024-03-06 22:02 - 000000000 ____D C:\Users\Pepík\AppData\Local\D3DSCache
2025-04-10 17:46 - 2024-03-06 23:21 - 000000000 ____D C:\Users\Kubík\AppData\Local\D3DSCache
2025-04-10 16:55 - 2024-03-07 18:16 - 000000000 ____D C:\Users\Kubík\AppData\Local\Discord
2025-04-10 15:50 - 2024-09-14 10:27 - 134222904 _____ C:\WINDOWS\392667600.dat
2025-04-10 15:46 - 2024-08-04 11:58 - 000001493 _____ C:\Users\Public\Desktop\Riot Client.lnk
2025-04-10 15:46 - 2024-03-07 19:28 - 000000000 ____D C:\ProgramData\Riot Games
2025-04-10 14:28 - 2024-03-07 19:30 - 000001426 _____ C:\Users\Kubík\Desktop\Roblox Player.lnk
2025-04-10 14:28 - 2024-03-07 19:30 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2025-04-10 14:28 - 2024-03-07 19:30 - 000000000 ____D C:\Users\Kubík\AppData\Local\Roblox
2025-04-10 14:27 - 2024-03-08 21:29 - 000000000 ____D C:\Users\Kubík\AppData\Local\CrashDumps
2025-04-10 14:27 - 2024-03-07 19:30 - 000001229 _____ C:\Users\Kubík\Desktop\Roblox Studio.lnk
2025-04-10 13:55 - 2024-10-25 21:12 - 000002317 _____ C:\Users\Kubík\Desktop\Mobius.lnk
2025-04-10 13:55 - 2024-09-29 21:20 - 000002317 _____ C:\Users\Kubík\Desktop\CurseForge.lnk
2025-04-10 13:55 - 2024-08-11 11:19 - 000001271 _____ C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Medal.lnk
2025-04-10 13:55 - 2024-08-11 11:19 - 000001263 _____ C:\Users\Kubík\Desktop\Medal.lnk
2025-04-10 13:55 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\Documents\Medal
2025-04-10 13:55 - 2024-08-11 11:19 - 000000000 ____D C:\Medal
2025-04-10 13:55 - 2024-08-04 12:01 - 000002317 _____ C:\Users\Kubík\Desktop\Control.lnk
2025-04-10 13:55 - 2024-06-29 12:54 - 000002317 _____ C:\Users\Kubík\Desktop\Valorant Tracker.lnk
2025-04-10 13:55 - 2024-04-27 20:30 - 000000000 ____D C:\Users\Kubík\AppData\Local\Overwolf
2025-04-10 13:55 - 2024-03-06 23:20 - 000000000 ___RD C:\Users\Kubík\OneDrive
2025-04-09 18:31 - 2025-02-21 21:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-598124734-1471702195-2874904135-1003
2025-04-09 18:31 - 2025-02-21 21:41 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1003
2025-04-09 18:31 - 2025-02-21 21:41 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-598124734-1471702195-2874904135-1003
2025-04-09 18:31 - 2024-03-06 23:20 - 000002377 _____ C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-09 17:40 - 2025-02-21 21:41 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-598124734-1471702195-2874904135-1002
2025-04-09 17:40 - 2025-02-21 21:41 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-598124734-1471702195-2874904135-1002
2025-04-09 17:40 - 2025-02-21 21:41 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-598124734-1471702195-2874904135-1002
2025-04-09 17:40 - 2024-03-06 22:01 - 000002377 _____ C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-09 16:11 - 2025-02-21 21:40 - 003352064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-04-09 15:38 - 2024-03-08 20:49 - 000000000 ____D C:\Users\Pepík\AppData\Local\WarThunder
2025-04-08 20:28 - 2024-12-25 21:44 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\WeMod
2025-04-08 19:43 - 2024-03-06 23:24 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\EasyAntiCheat
2025-04-08 17:40 - 2024-12-25 21:44 - 000002201 _____ C:\Users\Pepík\Desktop\WeMod.lnk
2025-04-08 17:40 - 2024-12-25 21:44 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeMod
2025-04-08 17:40 - 2024-12-25 21:44 - 000000000 ____D C:\Users\Pepík\AppData\Local\WeMod
2025-04-08 17:40 - 2024-03-07 15:46 - 000000000 ____D C:\Users\Pepík\AppData\Local\SquirrelTemp
2025-04-08 17:18 - 2024-03-07 20:09 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\riot-client-ux
2025-04-08 15:02 - 2024-08-25 10:39 - 000000000 ____D C:\Program Files\DubbingAI
2025-04-07 18:14 - 2025-02-26 19:07 - 003114016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-04-07 18:14 - 2025-02-26 19:07 - 002403360 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-04-07 18:14 - 2024-03-08 19:26 - 000271392 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-04-07 18:14 - 2024-03-08 19:26 - 000245792 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-04-07 17:52 - 2024-03-08 19:26 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-04-07 17:52 - 2024-03-08 19:26 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-04-07 17:51 - 2024-03-08 19:26 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2025-04-06 10:05 - 2025-02-21 21:41 - 000003640 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-04-06 10:05 - 2025-02-21 21:41 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-04-06 09:56 - 2024-03-06 22:12 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-04 09:41 - 2025-02-21 21:41 - 000004234 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1727636541
2025-04-04 09:41 - 2024-09-29 21:02 - 000001473 _____ C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera GX.lnk
2025-04-04 09:41 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Medal B.V
2025-04-04 09:41 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\Medal
2025-04-04 09:40 - 2025-02-21 21:41 - 000004230 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1732297780
2025-04-04 09:40 - 2024-11-22 19:49 - 000001473 _____ C:\Users\Pepík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera GX.lnk
2025-04-03 20:37 - 2024-09-29 15:43 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\.minecraft
2025-04-03 19:21 - 2024-03-20 15:41 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\Microsoft\MMC
2025-04-03 18:56 - 2024-09-28 17:57 - 000002243 _____ C:\Users\Pepík\Desktop\Discord.lnk
2025-04-03 17:20 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\log
2025-04-03 15:32 - 2024-12-08 00:05 - 000000000 ____D C:\ProgramData\EA Desktop
2025-04-02 17:20 - 2024-03-07 18:16 - 000002243 _____ C:\Users\Kubík\Desktop\Discord.lnk
2025-04-01 12:23 - 2024-03-06 21:35 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-04-01 12:06 - 2024-04-27 20:31 - 000000000 ____D C:\Program Files (x86)\Overwolf
2025-03-31 11:48 - 2024-09-29 21:02 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\.minecraft
2025-03-31 11:41 - 2024-09-29 21:02 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\.tlauncher
2025-03-30 17:50 - 2025-02-21 21:41 - 000003842 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2025-03-30 17:50 - 2025-02-21 21:41 - 000003400 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2025-03-30 12:57 - 2024-03-06 23:02 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\EasyAntiCheat
2025-03-30 10:39 - 2025-01-19 18:03 - 000000000 ____D C:\Users\Pepík\VirtualBox VMs
2025-03-30 10:39 - 2024-12-10 15:52 - 000000000 ____D C:\Users\Pepík\.VirtualBox
2025-03-29 19:42 - 2024-03-06 22:00 - 000000000 ____D C:\Users\Pepík\AppData\Local\Packages
2025-03-29 17:40 - 2024-08-11 11:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\Ferox_Games_B.V
2025-03-29 17:38 - 2024-03-07 19:43 - 000000000 ____D C:\Program Files\Riot Vanguard
2025-03-28 17:02 - 2024-05-01 21:40 - 000000000 ____D C:\Users\Kubík\AppData\Local\ModernWarships
2025-03-27 18:15 - 2024-08-25 18:32 - 000000000 ____D C:\Users\Kubík\AppData\Local\Crossout
2025-03-27 16:17 - 2024-03-06 23:19 - 000000000 ____D C:\Users\Kubík\AppData\Local\Packages
2025-03-23 14:08 - 2024-10-31 16:40 - 000000000 ____D C:\Users\Pepík\AppData\Roaming\r2modman
2025-03-20 16:15 - 2024-12-08 00:05 - 000000000 ____D C:\Users\Kubík\AppData\Local\cache
2025-03-20 10:11 - 2024-12-07 23:43 - 000000000 ____D C:\Users\Kubík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-03-18 21:45 - 2024-11-23 19:51 - 000000000 ____D C:\Users\Kubík\AppData\Local\Steam
2025-03-18 16:53 - 2025-01-05 16:58 - 000000000 ____D C:\Users\Pepík\Documents\Euro Truck Simulator 2
2025-03-18 16:16 - 2024-03-06 22:07 - 000000000 ____D C:\Users\Pepík\AppData\Local\Steam
2025-03-18 15:55 - 2024-08-25 10:39 - 000000877 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dubbing AI.lnk
2025-03-18 15:55 - 2024-08-25 10:39 - 000000865 _____ C:\Users\Public\Desktop\Dubbing AI.lnk
2025-03-15 14:22 - 2024-03-06 23:20 - 000000000 ____D C:\Users\Kubík\AppData\Local\PlaceholderTileLogoFolder
2025-03-15 12:15 - 2024-09-29 15:34 - 002897472 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2025-03-15 12:15 - 2024-09-29 15:34 - 000153152 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2025-03-15 12:15 - 2024-09-29 15:34 - 000124480 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2025-03-15 12:15 - 2024-09-29 15:34 - 000075304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2025-03-15 12:14 - 2024-09-29 15:34 - 000788008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2025-03-15 12:14 - 2024-09-29 15:34 - 000267816 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2025-03-15 12:14 - 2024-09-29 15:34 - 000243264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
==================== Files in the root of some directories ========
2024-04-01 19:45 - 2024-04-04 21:21 - 000000098 _____ () C:\Users\Pepík\AppData\Roaming\LauncherSettings_live.cfg
2024-04-04 21:01 - 2024-04-04 21:01 - 000002636 _____ () C:\Users\Pepík\AppData\Roaming\TheHunterSettings_live.bin
2024-04-04 21:12 - 2024-04-04 21:19 - 000000048 _____ () C:\Users\Pepík\AppData\Roaming\TheHunterSettings_steam_live.cfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================