Pomalé PC, mnoho spojení ven do internetu
Napsal: 25 čer 2025 12:11
Dobrý den.
Prosím o kontrolu logů. PC je občas pomalé a jednou denně po přihlášení uživatele vytvoří i 1000 spojení do internetu. Po cca 10 - 15 minutách se většina spojení zruší a pak bývá klid...
Log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-06-2025
Ran by polakovad (administrator) on CERVENA-PC (ATComputers TRILINE PROFI) (25-06-2025 13:07:15)
Running from \\zskola2\user-prac\cervenad\Plocha\FRST64.exe
Loaded Profiles: polakovad & MSSQLFDLauncher$FENIX2019 & SQLTELEMETRY$FENIX2019 & MSSQLLaunchpad$FENIX2019
Platform: Microsoft Windows 10 Pro Version 22H2 19045.5965 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe <2>
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Asseco Solutions a.s. -> Asseco Solutions, a.s.) C:\Program Files (x86)\PVT\Fenix\Asseco.Fenix.SpolecnySpoustec.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(C:\AlfaSoftware\Avensio\Avensio.exe ->) (Alfa Software, s.r.o. -> RSM Payroll Centre CZ s.r.o.) C:\AlfaSoftware\Avensio\Avensiovypocet.exe
(C:\AlfaSoftware\Avensio\Avensio.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files (x86)\Icecream Screen Recorder 7\recorder.exe ->) (ICECREAM APPS LTD -> ) C:\Program Files (x86)\Icecream Screen Recorder 7\uservice.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdlauncher.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdhost.exe
(DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atieclxx.exe
(explorer.exe ->) (Alfa Software, s.r.o. -> RSM Payroll Centre CZ s.r.o.) C:\AlfaSoftware\Avensio\Avensio.exe
(explorer.exe ->) (Cisco WebEx LLC -> Cisco Webex LLC) C:\Users\cervenad\AppData\Local\WebEx\WebexHost.exe
(explorer.exe ->) (ICECREAM APPS LTD -> Icecream) C:\Program Files (x86)\Icecream Screen Recorder 7\recorder.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Seyfor, a. s. -> Seyfor, a.s.) C:\Program Files (x86)\Solitea\Money S3\MS3Auto.exe
(KOMERCNI BANKA A.S. -> Komerční banka, a.s.) C:\Program Files (x86)\Profibanka\KB_PCB.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.095.0518.0002\Microsoft.SharePoint.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_25122.1415.3698.6812_x64__8wekyb3d8bbwe\ms-teams.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atiesrxx.exe
(services.exe ->) (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BrYNSvc.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
(services.exe ->) (Firebird Project) [File not signed] C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe
(services.exe ->) (Firebird Project) [File not signed] C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Profibanka\System\Binn\MSSQL12.PROFIBANKA\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdlauncher.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\Launchpad.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlceip.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9971779a1c712866\RtkAudUService64.exe <2>
(services.exe ->) (Seyfor.BankAgregator.Api) [File not signed] C:\Program Files (x86)\Seyfor\BankApi\Seyfor.BankAgregator.Api.exe
(services.exe ->) (Software602 a.s. -> Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.095.0518.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mobsync.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.5911_none_7dd4fd687cb889e8\TiWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9971779a1c712866\RtkAudUService64.exe [1201968 2020-10-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [195760 2025-04-05] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.) [File not signed]
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\137.0.3296.93\Installer\setup.exe [7395880 2025-06-21] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [GpNetworkStartTimeoutPolicyValue] 60
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [S3AutomaticSTART] => C:\Program Files (x86)\Solitea\Money S3\MS3Auto.exe [23842968 2025-05-23] (Seyfor, a. s. -> Seyfor, a.s.)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [CiscoMeetingDaemon] => C:\Users\cervenad\AppData\Local\WebEx\WebexHost.exe [8077920 2023-12-12] (Cisco WebEx LLC -> Cisco Webex LLC)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [Icecream_Screen_Recorder_New_Auto_Start] => C:\Program Files (x86)\Icecream Screen Recorder 7\recorder.exe [6987344 2025-05-05] (ICECREAM APPS LTD -> Icecream)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [MicrosoftEdgeAutoLaunch_A82912258D1D457A596D706B4507A3C9] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4141624 2025-06-19] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-667896778-3875923744-3874593446-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-667896778-3875923744-3874593446-1001\...\Run: [MicrosoftEdgeAutoLaunch_97C59669F16695898DE380691D1CE2A8] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4141624 2025-06-19] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-80-114141689-1879193004-1034857213-2089710861-3707162680\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-80-1505278109-670671082-1469591077-705002473-3960138673\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-80-909382125-310599901-4005563289-2766013183-973844813\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [S3Automatic] => C:\Program Files (x86)\Solitea\Money S3\MS3Auto.exe [23842968 2025-05-23] (Seyfor, a. s. -> Seyfor, a.s.)
HKLM\...\Windows x64\Print Processors\hpcpp160: C:\Windows\System32\spool\prtprocs\x64\hpcpp160.dll [602912 2013-12-03] (Hewlett-Packard Company -> Hewlett-Packard Corporation)
HKLM\...\Windows x64\Print Processors\hpzpplhn: C:\Windows\System32\spool\prtprocs\x64\hpzpplhn.dll [99840 2008-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\Windows\system32\HPMPW081.DLL [74016 2013-12-03] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM\...\Print\Monitors\HPMLM135: C:\Windows\system32\hpmlm135.dll [237344 2013-12-03] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\...\Print\Monitors\rica7Qlm: C:\Windows\system32\rica7Qlm.dll [28160 2013-12-26] (Microsoft Windows Hardware Compatibility Publisher -> RICOH CO.,Ltd.)
HKLM\...\Print\Monitors\Software602 XPS port monitor: C:\Windows\system32\602localmon.dll [47896 2021-09-23] (Software602 a.s. -> Windows (R) Win 7 DDK provider)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\137.0.7151.120\Installer\chrmstp.exe [2025-06-21] (Google LLC -> Google LLC)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {B5FA014C-2A18-4A1F-9314-EF77E6361579} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {39578F20-1E6D-4226-B440-72E4CBC82957} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {AB048B39-C0CC-4928-A45C-D509166F47D9} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {B97DE14B-6A35-4756-90BB-CDA4C9AE59A7} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [355840 2021-10-05] (Advanced Micro Devices, Inc.) [File not signed]
Task: {F1FAFF53-F422-4CDE-B296-B6D1EDBF87C6} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [5974424 2025-06-11] (Microsoft Windows -> Microsoft Corporation)
Task: {3398DB82-809C-4C2F-9AEA-B741AB2BA3D2} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{979D3406-0080-4581-8A4D-7965092B0AAF} => C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe [7080032 2025-05-22] (Google LLC -> Google LLC)
Task: {9007C027-1B03-4346-9DA1-C1A1E6F92DB6} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-02] (HP Inc. -> HP Inc.)
Task: {EF8E5F92-86FA-4697-9393-008E3E51FF08} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-02] (HP Inc. -> HP Inc.)
Task: {CC0E9B46-F5A7-48D3-9950-45C5276121C2} - System32\Tasks\Komercni banka\Profibanka\Profibanka AutoBackup => C:\Program Files (x86)\Profibanka\CreateTaskW10.exe [22552 2015-10-02] (KOMERCNI BANKA A.S. -> ) -> C:\Program#Files#(x86)\profibanka\Backup\backup.bak
Task: {5C99E5D2-0D0E-4CB9-8DDB-ECC5AF64D688} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23572056 2025-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {C93598F6-E3C1-453C-AB6D-02CD44E35389} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23572056 2025-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {08D1A9BD-780A-4D3E-88AC-0A617895D165} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209936 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {A30394E1-D3E6-4022-A534-64034E6272CC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209936 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {AC1AB55C-1911-4D37-B033-4FE498409E26} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514960 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {897D3190-D07C-4655-968F-1C47517AB1BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514960 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F628214-3628-4144-88BB-F39FBA7293D2} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\Windows\system32\gpupdate.exe [30720 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
Task: {F3401EAD-F305-4D11-8C4A-8FBCCDF9314D} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\Windows\system32\gpupdate.exe [30720 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
Task: {5B3C2F83-E51B-4093-88E1-6924E6AEC52F} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {387E62F4-0FFB-4C3B-9197-12438B08CC0A} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {1577F35C-9331-4CE4-9FC0-A806E2CA47B2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-1159 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F877B03-CC1A-432D-8E81-AB7241FF9E5C} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {79553ADB-0C2D-43F7-A995-E7597AF52937} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4104191108-630384649-3272312177-1194 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {0FF5F2CF-844D-4ED5-8F6E-AF0522AE326A} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4104191108-630384649-3272312177-2762 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {35E6625F-8F78-4505-A488-6988ED69FAFE} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4104191108-630384649-3272312177-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BD15D0AD-7FCF-4DB7-88B3-D278C46C3C6D} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-667896778-3875923744-3874593446-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5E08AB79-4B8C-46A1-9824-F87FD90DF58F} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-1159 => C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveLauncher.exe [684344 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AD8C2150-57B5-4102-821F-2C3DCB7BA2AD} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-500 => C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveLauncher.exe [684344 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {33250B85-50C8-4AA4-90F8-7690D8DE05FC} - System32\Tasks\OneDrive Startup Task-S-1-5-21-667896778-3875923744-3874593446-1001 => C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveLauncher.exe [684344 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {79E81F0F-BC1F-4122-873E-48F44B4383A5} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [55288 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {CEBCCD32-32EB-44E8-83AB-D4E0B8EC08CC} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [260600 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {8BE217C1-014E-41A0-83EB-9236DD5036D8} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2496437920-1329170045-526373181-1159 => C:\Users\cervenad\AppData\Roaming\Zoom\bin\Zoom.exe [441144 2025-05-27] (Zoom Video Communications, Inc. -> Zoom Communications, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{963096d6-22e6-4dfb-976a-5fb00ad683f8}: [NameServer] 10.42.31.4,8.8.8.8
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\cervenad\AppData\Local\Microsoft\Edge\User Data\Default [2025-06-25]
Edge Extension: (Dokumenty Google offline) - C:\Users\cervenad\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-08]
Edge Extension: (Edge relevant text changes) - C:\Users\cervenad\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-06-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2018-01-08] (Software602 a.s. -> Software602 a.s.)
Chrome:
=======
CHR Profile: C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default [2025-06-25]
CHR Notifications: Default -> hxxps://cz.avon-brochure.com; hxxps://petona.cz; hxxps://upcr.cz; hxxps://www.dobre-knihy.cz
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-06-19]
CHR Extension: (Dokumenty Google offline) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-05-29]
CHR Extension: (FormApps Extension) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2024-04-15]
CHR Extension: (Cryptoplus KB - podepisovací modul) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldildmkoeoicfkknedfdpjmgjmpkpooc [2023-07-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-07-19]
CHR HKU\S-1-5-21-2496437920-1329170045-526373181-1159\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s. -> Software602 a.s.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
R2 AzureAttestService; C:\Program Files\Microsoft\AzureAttestService\AzureAttestService.dll [151288 2019-07-24] (Microsoft Windows -> Microsoft Corporation)
R2 BankAPI Seyfor; C:\Program Files (x86)\Seyfor\BankApi\Seyfor.BankAgregator.Api.exe [139264 2025-04-02] (Seyfor.BankAgregator.Api) [File not signed]
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9499264 2025-05-25] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5566320 2025-04-05] (ESET, spol. s r.o. -> ESET)
S3 EHttpSrv; C:\Program Files\ESET\ESET Security\ehttpsrv.exe [58224 2025-04-05] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4529832 2025-04-05] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4529832 2025-04-05] (ESET, spol. s r.o. -> ESET)
R2 EraAgentSvc; C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe [1529112 2023-08-14] (ESET, spol. s r.o. -> ESET)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.095.0518.0002\FileSyncHelper.exe [3621688 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
R2 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe [156672 2019-06-20] (Firebird Project) [File not signed]
R3 FirebirdServerDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe [5825024 2019-06-20] (Firebird Project) [File not signed]
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-05-02] (HP Inc. -> HP Inc.)
S3 MonS3Service; C:\Program Files (x86)\Common Files\Solitea\MonS3Service.exe [1765536 2025-05-23] (Seyfor, a. s. -> Seyfor, a.s.)
S3 MsMpiLaunchSvc; C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe [161040 2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
R2 MSSQL$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlservr.exe [626280 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 MSSQL$PROFIBANKA; C:\Program Files (x86)\Profibanka\System\Binn\MSSQL12.PROFIBANKA\MSSQL\Binn\sqlservr.exe [199760 2018-09-07] (Microsoft Corporation -> Microsoft Corporation)
R3 MSSQLFDLauncher$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdlauncher.exe [85600 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 MSSQLLaunchpad$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\launchpad.exe [1228608 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-11-14] (Hewlett-Packard) [File not signed]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveUpdaterService.exe [3873064 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2013-11-14] (Hewlett-Packard) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [917440 2025-06-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 SQLAgent$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\SQLAGENT.EXE [695912 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
S4 SQLAgent$PROFIBANKA; C:\Program Files (x86)\Profibanka\System\Binn\MSSQL12.PROFIBANKA\MSSQL\Binn\SQLAGENT.EXE [454736 2018-09-07] (Microsoft Corporation -> Microsoft Corporation)
R2 SQLTELEMETRY$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlceip.exe [290648 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [20994352 2025-05-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [54720 2022-08-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\Windows\System32\DriverStore\FileRepository\amdsafd.inf_amd64_50fee1227e96ec14\amdsafd.sys [100792 2021-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\amdkmdag.sys [94358424 2022-08-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\Windows\System32\drivers\amdxe.sys [65168 2021-08-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [284672 2021-04-09] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [225144 2025-02-09] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [16336 2022-09-05] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [269056 2025-02-09] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [86200 2025-02-09] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [128528 2025-02-09] (ESET, spol. s r.o. -> ESET)
R3 GemCCID; C:\Windows\System32\DriverStore\FileRepository\gemccid.inf_amd64_526ec61d10ad09ec\GemCCID.sys [162992 2025-05-15] (Thales DIS CPL USA, Inc. -> Gemalto)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
S4 RsFx0600; C:\Windows\System32\DRIVERS\RsFx0600.sys [286976 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
S3 usbscan; C:\Windows\System32\drivers\usbscan.sys [49664 2022-07-13] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-25 13:07 - 2025-06-25 13:07 - 000000000 ____D C:\FRST
2025-06-24 14:55 - 2025-06-24 14:59 - 000007655 _____ C:\Users\cervenad\AppData\Local\Resmon.ResmonCfg
2025-06-24 12:07 - 2025-06-24 12:07 - 000207516 _____ C:\Users\cervenad\Downloads\priloha_1536203059_0_Usneseni_o_zastaveni_rizeni_Polak_Michal.pdf
2025-06-23 08:32 - 2025-06-23 08:32 - 000041455 _____ C:\Users\cervenad\Downloads\1237181070287_6_1132_20250620.pdf
2025-06-18 18:33 - 2025-06-18 18:33 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-06-17 14:21 - 2025-06-17 14:21 - 000030154 _____ C:\Users\cervenad\Downloads\Potvrzeni o prijmu (1).pdf
2025-06-16 12:30 - 2025-06-16 12:30 - 000060064 _____ C:\Users\cervenad\Downloads\3300461684.pdf
2025-06-13 13:50 - 2025-06-13 13:50 - 000847276 _____ C:\Users\cervenad\Downloads\cza13917_2025-01-10-09_33_08 (2).zip
2025-06-13 12:16 - 2025-06-13 12:16 - 000579513 _____ C:\Users\cervenad\Downloads\2984704686 (1).pdf
2025-06-12 09:48 - 2025-06-12 09:48 - 000117784 _____ C:\Users\cervenad\Downloads\faktura_erich.pdf
2025-06-12 09:48 - 2025-06-12 09:48 - 000117784 _____ C:\Users\cervenad\Downloads\faktura_erich (1).pdf
2025-06-12 07:56 - 2025-06-12 07:56 - 000549677 _____ C:\Users\cervenad\Downloads\Reindex CZ (1) (1).pdf
2025-06-12 07:54 - 2025-06-12 07:54 - 000549677 _____ C:\Users\cervenad\Downloads\Reindex CZ (1).pdf
2025-06-11 15:17 - 2025-06-11 15:17 - 000000000 ___HD C:\$WinREAgent
2025-06-11 14:56 - 2025-06-11 14:56 - 000579842 _____ C:\Users\cervenad\Downloads\2984704686.pdf
2025-06-10 12:01 - 2025-06-10 12:01 - 000000000 ____D C:\Program Files (x86)\dotnet
2025-06-05 08:35 - 2025-06-05 08:35 - 000088054 _____ C:\Users\cervenad\Downloads\Zpětvzetí žádost o prominutí penále ČSSZ.pdf
2025-06-05 07:38 - 2025-06-05 07:38 - 000194670 _____ C:\Users\cervenad\Downloads\TU_červen 2025.pdf
2025-06-05 07:08 - 2025-06-05 07:08 - 000604115 _____ C:\Users\cervenad\Downloads\2983933586.pdf
2025-06-05 07:07 - 2025-06-05 07:07 - 000609335 _____ C:\Users\cervenad\Downloads\2983933591.pdf
2025-06-04 20:58 - 2025-06-04 20:58 - 000000000 ____D C:\Program Files\HP
2025-06-04 09:33 - 2025-06-04 09:33 - 001868243 _____ C:\Users\cervenad\Downloads\Dalsi_financni_prostredky_pro_skoly_na_rok_2025.xlsx
2025-06-04 09:33 - 2025-06-04 09:33 - 000095106 _____ C:\Users\cervenad\Downloads\Priloha.xlsx
2025-06-02 11:37 - 2025-06-02 11:37 - 002770850 _____ C:\Users\cervenad\Downloads\priloha_1532097212_0_Kantyna_SPS_Trebic.pdf
2025-06-02 11:37 - 2025-06-02 11:37 - 000213966 _____ C:\Users\cervenad\Downloads\priloha_1531693351_0_Polak_Michal.pdf
2025-06-02 09:46 - 2025-06-02 09:46 - 000484182 _____ C:\Users\cervenad\Downloads\2979131233 (2).pdf
2025-06-02 09:46 - 2025-06-02 09:46 - 000483635 _____ C:\Users\cervenad\Downloads\2981220150 (1).pdf
2025-06-02 08:47 - 2025-06-02 08:47 - 000499269 _____ C:\Users\cervenad\Downloads\bankovní identita.pdf
2025-05-30 09:13 - 2025-05-30 09:13 - 000040293 _____ C:\Users\cervenad\Downloads\1237181070287_5_1132_20250522.pdf
2025-05-30 07:24 - 2025-06-25 13:03 - 000003086 _____ C:\Windows\system32\Tasks\AMDLinkUpdate
2025-05-29 14:03 - 2025-05-29 14:03 - 000113977 _____ C:\Users\cervenad\Downloads\Žádost o prominutí penále ČSSZ.pdf
2025-05-27 14:11 - 2025-05-27 14:11 - 000012467 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036 (1).pdf
2025-05-27 14:11 - 2025-05-27 14:11 - 000006073 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036-1634566842-potvrzeni.p7s
2025-05-27 14:11 - 2025-05-27 14:11 - 000003652 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036-1634566842-potvrzeni.pdf
2025-05-27 14:10 - 2025-05-27 14:10 - 000012467 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036.pdf
2025-05-27 08:47 - 2025-05-27 08:47 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2025-05-26 12:58 - 2025-05-26 12:58 - 001579688 _____ C:\Users\cervenad\Downloads\voucher-KARTDAA49BC9DE0002.pdf
2025-05-26 12:58 - 2025-05-26 12:58 - 001579688 _____ C:\Users\cervenad\Downloads\voucher-KART90E5085E5D7003.pdf
2025-05-26 12:57 - 2025-05-26 12:57 - 001579678 _____ C:\Users\cervenad\Downloads\voucher-KARTEE185384845001.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-25 13:03 - 2025-02-27 08:17 - 000003118 _____ C:\Windows\system32\Tasks\AMDInstallLauncher
2025-06-25 12:55 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-06-25 12:52 - 2021-11-24 10:21 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-06-25 11:39 - 2021-12-28 10:58 - 000000144 _____ C:\Windows\system32\config\netlogon.ftl
2025-06-25 10:26 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-06-25 10:26 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2025-06-25 04:33 - 2021-12-27 19:06 - 000000000 ____D C:\Windows\SystemTemp
2025-06-24 13:04 - 2023-07-19 19:19 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Word
2025-06-24 10:46 - 2023-07-19 19:20 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Excel
2025-06-24 08:07 - 2023-08-28 18:22 - 000000000 ____D C:\Users\cervenad\AppData\LocalLow\Temp
2025-06-24 08:07 - 2023-07-19 19:03 - 000000000 ____D C:\Users\cervenad\AppData\LocalLow\Adobe
2025-06-24 07:45 - 2021-12-28 11:30 - 000000000 ____D C:\KBprikazy
2025-06-22 00:32 - 2021-12-27 18:41 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-06-21 08:33 - 2023-07-19 18:51 - 000000000 ____D C:\Users\cervenad\AppData\Local\Packages
2025-06-21 08:33 - 2021-11-24 10:21 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-06-19 19:10 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2025-06-19 10:39 - 2023-07-19 18:51 - 000000000 ____D C:\Users\cervenad\AppData\Local\D3DSCache
2025-06-19 07:25 - 2023-05-09 10:12 - 000000000 ____D C:\ProgramData\firebird
2025-06-18 18:33 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-06-18 18:32 - 2021-12-28 11:09 - 000000000 ____D C:\Program Files\Microsoft Office
2025-06-18 15:25 - 2021-11-24 10:26 - 002319808 _____ C:\Windows\system32\PerfStringBackup.INI
2025-06-18 15:25 - 2021-04-30 08:05 - 000934756 _____ C:\Windows\system32\perfh005.dat
2025-06-18 15:25 - 2021-04-30 08:05 - 000234006 _____ C:\Windows\system32\perfc005.dat
2025-06-18 15:25 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2025-06-18 15:21 - 2021-12-28 12:22 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2025-06-18 15:21 - 2021-12-28 11:00 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-06-18 15:21 - 2021-11-24 10:21 - 000008192 ___SH C:\DumpStack.log.tmp
2025-06-18 15:21 - 2021-11-24 10:21 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-06-18 15:21 - 2019-12-07 11:03 - 001310720 _____ C:\Windows\system32\config\BBI
2025-06-18 08:01 - 2021-12-28 11:30 - 000000000 ____D C:\KBvypisy
2025-06-16 07:53 - 2023-08-07 06:25 - 000000000 ____D C:\Users\cervenad\AppData\Local\AMD_Common
2025-06-14 13:02 - 2025-02-06 11:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-667896778-3875923744-3874593446-1001
2025-06-14 13:02 - 2025-02-06 11:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-1159
2025-06-14 13:02 - 2025-02-06 11:57 - 000003540 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-500
2025-06-14 13:02 - 2023-07-19 16:29 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-500
2025-06-14 13:02 - 2023-07-19 16:19 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-1159
2025-06-14 13:02 - 2021-12-27 19:08 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-667896778-3875923744-3874593446-1001
2025-06-14 13:02 - 2021-11-24 10:27 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-06-14 13:02 - 2021-11-24 10:27 - 000002137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-06-13 07:32 - 2024-04-19 08:39 - 000002080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-06-13 07:32 - 2023-03-07 09:20 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2025-06-11 17:37 - 2021-11-24 10:21 - 000447968 _____ C:\Windows\system32\FNTCACHE.DAT
2025-06-11 17:36 - 2024-07-10 08:18 - 000000000 ____D C:\Windows\system32\compatrel
2025-06-11 17:36 - 2019-12-07 11:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\PrintDialog
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellComponents
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-06-11 15:25 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2025-06-11 15:22 - 2021-11-24 10:24 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-06-11 15:17 - 2021-12-27 18:46 - 000000000 ____D C:\Windows\system32\MRT
2025-06-11 15:15 - 2021-12-27 18:46 - 216824056 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2025-06-11 14:56 - 2023-07-19 19:18 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Outlook
2025-06-11 08:21 - 2023-07-19 19:18 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Office
2025-06-10 12:01 - 2021-11-24 10:23 - 000000000 ____D C:\ProgramData\Package Cache
2025-06-10 11:59 - 2021-12-28 12:13 - 000000000 ____D C:\Záloha Fenix
2025-06-10 11:59 - 2021-11-24 09:59 - 000000000 ____D C:\install
2025-06-09 18:11 - 2023-07-19 19:02 - 000000000 ____D C:\Users\cervenad\AVENSIO
2025-06-09 12:56 - 2024-03-19 10:41 - 000000000 ____D C:\Users\cervenad\AppData\Local\CrashDumps
2025-06-05 13:57 - 2023-07-19 16:28 - 000000000 ____D C:\Users\administrator.ZSPRIBYSLAV
2025-06-05 13:57 - 2022-08-25 08:46 - 000000000 ____D C:\Users\knihovna
2025-06-05 13:57 - 2021-12-28 10:59 - 000000000 ____D C:\Users\administrator
2025-06-05 13:57 - 2021-12-27 18:38 - 000000000 ____D C:\Users\dpadmin
2025-06-05 07:05 - 2023-07-19 18:51 - 000000000 ____D C:\Users\cervenad
2025-05-27 14:37 - 2023-10-24 08:40 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Zoom
2025-05-27 08:47 - 2024-12-12 10:00 - 000004256 _____ C:\Windows\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2496437920-1329170045-526373181-1159
2025-05-26 07:21 - 2021-12-28 11:45 - 000000000 ____D C:\Program Files (x86)\Profibanka
==================== Files in the root of some directories ========
2025-06-24 14:55 - 2025-06-24 14:59 - 000007655 _____ () C:\Users\cervenad\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Prosím o kontrolu logů. PC je občas pomalé a jednou denně po přihlášení uživatele vytvoří i 1000 spojení do internetu. Po cca 10 - 15 minutách se většina spojení zruší a pak bývá klid...
Log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-06-2025
Ran by polakovad (administrator) on CERVENA-PC (ATComputers TRILINE PROFI) (25-06-2025 13:07:15)
Running from \\zskola2\user-prac\cervenad\Plocha\FRST64.exe
Loaded Profiles: polakovad & MSSQLFDLauncher$FENIX2019 & SQLTELEMETRY$FENIX2019 & MSSQLLaunchpad$FENIX2019
Platform: Microsoft Windows 10 Pro Version 22H2 19045.5965 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe <2>
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Asseco Solutions a.s. -> Asseco Solutions, a.s.) C:\Program Files (x86)\PVT\Fenix\Asseco.Fenix.SpolecnySpoustec.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(C:\AlfaSoftware\Avensio\Avensio.exe ->) (Alfa Software, s.r.o. -> RSM Payroll Centre CZ s.r.o.) C:\AlfaSoftware\Avensio\Avensiovypocet.exe
(C:\AlfaSoftware\Avensio\Avensio.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files (x86)\Icecream Screen Recorder 7\recorder.exe ->) (ICECREAM APPS LTD -> ) C:\Program Files (x86)\Icecream Screen Recorder 7\uservice.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdlauncher.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdhost.exe
(DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atieclxx.exe
(explorer.exe ->) (Alfa Software, s.r.o. -> RSM Payroll Centre CZ s.r.o.) C:\AlfaSoftware\Avensio\Avensio.exe
(explorer.exe ->) (Cisco WebEx LLC -> Cisco Webex LLC) C:\Users\cervenad\AppData\Local\WebEx\WebexHost.exe
(explorer.exe ->) (ICECREAM APPS LTD -> Icecream) C:\Program Files (x86)\Icecream Screen Recorder 7\recorder.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Seyfor, a. s. -> Seyfor, a.s.) C:\Program Files (x86)\Solitea\Money S3\MS3Auto.exe
(KOMERCNI BANKA A.S. -> Komerční banka, a.s.) C:\Program Files (x86)\Profibanka\KB_PCB.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.095.0518.0002\Microsoft.SharePoint.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_25122.1415.3698.6812_x64__8wekyb3d8bbwe\ms-teams.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atiesrxx.exe
(services.exe ->) (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BrYNSvc.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
(services.exe ->) (Firebird Project) [File not signed] C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe
(services.exe ->) (Firebird Project) [File not signed] C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Profibanka\System\Binn\MSSQL12.PROFIBANKA\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdlauncher.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\Launchpad.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlceip.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9971779a1c712866\RtkAudUService64.exe <2>
(services.exe ->) (Seyfor.BankAgregator.Api) [File not signed] C:\Program Files (x86)\Seyfor\BankApi\Seyfor.BankAgregator.Api.exe
(services.exe ->) (Software602 a.s. -> Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.095.0518.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mobsync.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.5911_none_7dd4fd687cb889e8\TiWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_9971779a1c712866\RtkAudUService64.exe [1201968 2020-10-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [195760 2025-04-05] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.) [File not signed]
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\137.0.3296.93\Installer\setup.exe [7395880 2025-06-21] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [GpNetworkStartTimeoutPolicyValue] 60
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [S3AutomaticSTART] => C:\Program Files (x86)\Solitea\Money S3\MS3Auto.exe [23842968 2025-05-23] (Seyfor, a. s. -> Seyfor, a.s.)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [CiscoMeetingDaemon] => C:\Users\cervenad\AppData\Local\WebEx\WebexHost.exe [8077920 2023-12-12] (Cisco WebEx LLC -> Cisco Webex LLC)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [Icecream_Screen_Recorder_New_Auto_Start] => C:\Program Files (x86)\Icecream Screen Recorder 7\recorder.exe [6987344 2025-05-05] (ICECREAM APPS LTD -> Icecream)
HKU\S-1-5-21-2496437920-1329170045-526373181-1159\...\Run: [MicrosoftEdgeAutoLaunch_A82912258D1D457A596D706B4507A3C9] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4141624 2025-06-19] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-667896778-3875923744-3874593446-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-667896778-3875923744-3874593446-1001\...\Run: [MicrosoftEdgeAutoLaunch_97C59669F16695898DE380691D1CE2A8] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4141624 2025-06-19] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-80-114141689-1879193004-1034857213-2089710861-3707162680\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-80-1505278109-670671082-1469591077-705002473-3960138673\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-80-909382125-310599901-4005563289-2766013183-973844813\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966728 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [S3Automatic] => C:\Program Files (x86)\Solitea\Money S3\MS3Auto.exe [23842968 2025-05-23] (Seyfor, a. s. -> Seyfor, a.s.)
HKLM\...\Windows x64\Print Processors\hpcpp160: C:\Windows\System32\spool\prtprocs\x64\hpcpp160.dll [602912 2013-12-03] (Hewlett-Packard Company -> Hewlett-Packard Corporation)
HKLM\...\Windows x64\Print Processors\hpzpplhn: C:\Windows\System32\spool\prtprocs\x64\hpzpplhn.dll [99840 2008-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\Windows\system32\HPMPW081.DLL [74016 2013-12-03] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM\...\Print\Monitors\HPMLM135: C:\Windows\system32\hpmlm135.dll [237344 2013-12-03] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\...\Print\Monitors\rica7Qlm: C:\Windows\system32\rica7Qlm.dll [28160 2013-12-26] (Microsoft Windows Hardware Compatibility Publisher -> RICOH CO.,Ltd.)
HKLM\...\Print\Monitors\Software602 XPS port monitor: C:\Windows\system32\602localmon.dll [47896 2021-09-23] (Software602 a.s. -> Windows (R) Win 7 DDK provider)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\137.0.7151.120\Installer\chrmstp.exe [2025-06-21] (Google LLC -> Google LLC)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {B5FA014C-2A18-4A1F-9314-EF77E6361579} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {39578F20-1E6D-4226-B440-72E4CBC82957} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {AB048B39-C0CC-4928-A45C-D509166F47D9} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {B97DE14B-6A35-4756-90BB-CDA4C9AE59A7} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [355840 2021-10-05] (Advanced Micro Devices, Inc.) [File not signed]
Task: {F1FAFF53-F422-4CDE-B296-B6D1EDBF87C6} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [5974424 2025-06-11] (Microsoft Windows -> Microsoft Corporation)
Task: {3398DB82-809C-4C2F-9AEA-B741AB2BA3D2} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{979D3406-0080-4581-8A4D-7965092B0AAF} => C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe [7080032 2025-05-22] (Google LLC -> Google LLC)
Task: {9007C027-1B03-4346-9DA1-C1A1E6F92DB6} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-02] (HP Inc. -> HP Inc.)
Task: {EF8E5F92-86FA-4697-9393-008E3E51FF08} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-02] (HP Inc. -> HP Inc.)
Task: {CC0E9B46-F5A7-48D3-9950-45C5276121C2} - System32\Tasks\Komercni banka\Profibanka\Profibanka AutoBackup => C:\Program Files (x86)\Profibanka\CreateTaskW10.exe [22552 2015-10-02] (KOMERCNI BANKA A.S. -> ) -> C:\Program#Files#(x86)\profibanka\Backup\backup.bak
Task: {5C99E5D2-0D0E-4CB9-8DDB-ECC5AF64D688} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23572056 2025-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {C93598F6-E3C1-453C-AB6D-02CD44E35389} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23572056 2025-05-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {08D1A9BD-780A-4D3E-88AC-0A617895D165} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209936 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {A30394E1-D3E6-4022-A534-64034E6272CC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209936 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {AC1AB55C-1911-4D37-B033-4FE498409E26} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514960 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {897D3190-D07C-4655-968F-1C47517AB1BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514960 2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F628214-3628-4144-88BB-F39FBA7293D2} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\Windows\system32\gpupdate.exe [30720 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
Task: {F3401EAD-F305-4D11-8C4A-8FBCCDF9314D} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\Windows\system32\gpupdate.exe [30720 2025-04-09] (Microsoft Windows -> Microsoft Corporation)
Task: {5B3C2F83-E51B-4093-88E1-6924E6AEC52F} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {387E62F4-0FFB-4C3B-9197-12438B08CC0A} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {1577F35C-9331-4CE4-9FC0-A806E2CA47B2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-1159 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F877B03-CC1A-432D-8E81-AB7241FF9E5C} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {79553ADB-0C2D-43F7-A995-E7597AF52937} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4104191108-630384649-3272312177-1194 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {0FF5F2CF-844D-4ED5-8F6E-AF0522AE326A} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4104191108-630384649-3272312177-2762 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {35E6625F-8F78-4505-A488-6988ED69FAFE} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4104191108-630384649-3272312177-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BD15D0AD-7FCF-4DB7-88B3-D278C46C3C6D} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-667896778-3875923744-3874593446-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223792 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5E08AB79-4B8C-46A1-9824-F87FD90DF58F} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-1159 => C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveLauncher.exe [684344 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AD8C2150-57B5-4102-821F-2C3DCB7BA2AD} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-500 => C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveLauncher.exe [684344 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {33250B85-50C8-4AA4-90F8-7690D8DE05FC} - System32\Tasks\OneDrive Startup Task-S-1-5-21-667896778-3875923744-3874593446-1001 => C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveLauncher.exe [684344 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {79E81F0F-BC1F-4122-873E-48F44B4383A5} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [55288 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {CEBCCD32-32EB-44E8-83AB-D4E0B8EC08CC} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [260600 2021-10-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {8BE217C1-014E-41A0-83EB-9236DD5036D8} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2496437920-1329170045-526373181-1159 => C:\Users\cervenad\AppData\Roaming\Zoom\bin\Zoom.exe [441144 2025-05-27] (Zoom Video Communications, Inc. -> Zoom Communications, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{963096d6-22e6-4dfb-976a-5fb00ad683f8}: [NameServer] 10.42.31.4,8.8.8.8
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\cervenad\AppData\Local\Microsoft\Edge\User Data\Default [2025-06-25]
Edge Extension: (Dokumenty Google offline) - C:\Users\cervenad\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-08]
Edge Extension: (Edge relevant text changes) - C:\Users\cervenad\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-06-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-06-18] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2018-01-08] (Software602 a.s. -> Software602 a.s.)
Chrome:
=======
CHR Profile: C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default [2025-06-25]
CHR Notifications: Default -> hxxps://cz.avon-brochure.com; hxxps://petona.cz; hxxps://upcr.cz; hxxps://www.dobre-knihy.cz
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-06-19]
CHR Extension: (Dokumenty Google offline) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-05-29]
CHR Extension: (FormApps Extension) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2024-04-15]
CHR Extension: (Cryptoplus KB - podepisovací modul) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldildmkoeoicfkknedfdpjmgjmpkpooc [2023-07-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\cervenad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-07-19]
CHR HKU\S-1-5-21-2496437920-1329170045-526373181-1159\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s. -> Software602 a.s.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
R2 AzureAttestService; C:\Program Files\Microsoft\AzureAttestService\AzureAttestService.dll [151288 2019-07-24] (Microsoft Windows -> Microsoft Corporation)
R2 BankAPI Seyfor; C:\Program Files (x86)\Seyfor\BankApi\Seyfor.BankAgregator.Api.exe [139264 2025-04-02] (Seyfor.BankAgregator.Api) [File not signed]
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9499264 2025-05-25] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5566320 2025-04-05] (ESET, spol. s r.o. -> ESET)
S3 EHttpSrv; C:\Program Files\ESET\ESET Security\ehttpsrv.exe [58224 2025-04-05] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4529832 2025-04-05] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4529832 2025-04-05] (ESET, spol. s r.o. -> ESET)
R2 EraAgentSvc; C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe [1529112 2023-08-14] (ESET, spol. s r.o. -> ESET)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.095.0518.0002\FileSyncHelper.exe [3621688 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
R2 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe [156672 2019-06-20] (Firebird Project) [File not signed]
R3 FirebirdServerDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe [5825024 2019-06-20] (Firebird Project) [File not signed]
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-05-02] (HP Inc. -> HP Inc.)
S3 MonS3Service; C:\Program Files (x86)\Common Files\Solitea\MonS3Service.exe [1765536 2025-05-23] (Seyfor, a. s. -> Seyfor, a.s.)
S3 MsMpiLaunchSvc; C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe [161040 2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
R2 MSSQL$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlservr.exe [626280 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 MSSQL$PROFIBANKA; C:\Program Files (x86)\Profibanka\System\Binn\MSSQL12.PROFIBANKA\MSSQL\Binn\sqlservr.exe [199760 2018-09-07] (Microsoft Corporation -> Microsoft Corporation)
R3 MSSQLFDLauncher$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\fdlauncher.exe [85600 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 MSSQLLaunchpad$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\launchpad.exe [1228608 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-11-14] (Hewlett-Packard) [File not signed]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.095.0518.0002\OneDriveUpdaterService.exe [3873064 2025-06-14] (Microsoft Corporation -> Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2013-11-14] (Hewlett-Packard) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [917440 2025-06-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 SQLAgent$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\SQLAGENT.EXE [695912 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
S4 SQLAgent$PROFIBANKA; C:\Program Files (x86)\Profibanka\System\Binn\MSSQL12.PROFIBANKA\MSSQL\Binn\SQLAGENT.EXE [454736 2018-09-07] (Microsoft Corporation -> Microsoft Corporation)
R2 SQLTELEMETRY$FENIX2019; C:\Program Files\Microsoft SQL Server\MSSQL15.FENIX2019\MSSQL\Binn\sqlceip.exe [290648 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [20994352 2025-05-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [54720 2022-08-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\Windows\System32\DriverStore\FileRepository\amdsafd.inf_amd64_50fee1227e96ec14\amdsafd.sys [100792 2021-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\amdkmdag.sys [94358424 2022-08-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\Windows\System32\drivers\amdxe.sys [65168 2021-08-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [284672 2021-04-09] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [225144 2025-02-09] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [16336 2022-09-05] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [269056 2025-02-09] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [86200 2025-02-09] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [128528 2025-02-09] (ESET, spol. s r.o. -> ESET)
R3 GemCCID; C:\Windows\System32\DriverStore\FileRepository\gemccid.inf_amd64_526ec61d10ad09ec\GemCCID.sys [162992 2025-05-15] (Thales DIS CPL USA, Inc. -> Gemalto)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
S4 RsFx0600; C:\Windows\System32\DRIVERS\RsFx0600.sys [286976 2019-09-24] (Microsoft Corporation -> Microsoft Corporation)
S3 usbscan; C:\Windows\System32\drivers\usbscan.sys [49664 2022-07-13] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-25 13:07 - 2025-06-25 13:07 - 000000000 ____D C:\FRST
2025-06-24 14:55 - 2025-06-24 14:59 - 000007655 _____ C:\Users\cervenad\AppData\Local\Resmon.ResmonCfg
2025-06-24 12:07 - 2025-06-24 12:07 - 000207516 _____ C:\Users\cervenad\Downloads\priloha_1536203059_0_Usneseni_o_zastaveni_rizeni_Polak_Michal.pdf
2025-06-23 08:32 - 2025-06-23 08:32 - 000041455 _____ C:\Users\cervenad\Downloads\1237181070287_6_1132_20250620.pdf
2025-06-18 18:33 - 2025-06-18 18:33 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-06-17 14:21 - 2025-06-17 14:21 - 000030154 _____ C:\Users\cervenad\Downloads\Potvrzeni o prijmu (1).pdf
2025-06-16 12:30 - 2025-06-16 12:30 - 000060064 _____ C:\Users\cervenad\Downloads\3300461684.pdf
2025-06-13 13:50 - 2025-06-13 13:50 - 000847276 _____ C:\Users\cervenad\Downloads\cza13917_2025-01-10-09_33_08 (2).zip
2025-06-13 12:16 - 2025-06-13 12:16 - 000579513 _____ C:\Users\cervenad\Downloads\2984704686 (1).pdf
2025-06-12 09:48 - 2025-06-12 09:48 - 000117784 _____ C:\Users\cervenad\Downloads\faktura_erich.pdf
2025-06-12 09:48 - 2025-06-12 09:48 - 000117784 _____ C:\Users\cervenad\Downloads\faktura_erich (1).pdf
2025-06-12 07:56 - 2025-06-12 07:56 - 000549677 _____ C:\Users\cervenad\Downloads\Reindex CZ (1) (1).pdf
2025-06-12 07:54 - 2025-06-12 07:54 - 000549677 _____ C:\Users\cervenad\Downloads\Reindex CZ (1).pdf
2025-06-11 15:17 - 2025-06-11 15:17 - 000000000 ___HD C:\$WinREAgent
2025-06-11 14:56 - 2025-06-11 14:56 - 000579842 _____ C:\Users\cervenad\Downloads\2984704686.pdf
2025-06-10 12:01 - 2025-06-10 12:01 - 000000000 ____D C:\Program Files (x86)\dotnet
2025-06-05 08:35 - 2025-06-05 08:35 - 000088054 _____ C:\Users\cervenad\Downloads\Zpětvzetí žádost o prominutí penále ČSSZ.pdf
2025-06-05 07:38 - 2025-06-05 07:38 - 000194670 _____ C:\Users\cervenad\Downloads\TU_červen 2025.pdf
2025-06-05 07:08 - 2025-06-05 07:08 - 000604115 _____ C:\Users\cervenad\Downloads\2983933586.pdf
2025-06-05 07:07 - 2025-06-05 07:07 - 000609335 _____ C:\Users\cervenad\Downloads\2983933591.pdf
2025-06-04 20:58 - 2025-06-04 20:58 - 000000000 ____D C:\Program Files\HP
2025-06-04 09:33 - 2025-06-04 09:33 - 001868243 _____ C:\Users\cervenad\Downloads\Dalsi_financni_prostredky_pro_skoly_na_rok_2025.xlsx
2025-06-04 09:33 - 2025-06-04 09:33 - 000095106 _____ C:\Users\cervenad\Downloads\Priloha.xlsx
2025-06-02 11:37 - 2025-06-02 11:37 - 002770850 _____ C:\Users\cervenad\Downloads\priloha_1532097212_0_Kantyna_SPS_Trebic.pdf
2025-06-02 11:37 - 2025-06-02 11:37 - 000213966 _____ C:\Users\cervenad\Downloads\priloha_1531693351_0_Polak_Michal.pdf
2025-06-02 09:46 - 2025-06-02 09:46 - 000484182 _____ C:\Users\cervenad\Downloads\2979131233 (2).pdf
2025-06-02 09:46 - 2025-06-02 09:46 - 000483635 _____ C:\Users\cervenad\Downloads\2981220150 (1).pdf
2025-06-02 08:47 - 2025-06-02 08:47 - 000499269 _____ C:\Users\cervenad\Downloads\bankovní identita.pdf
2025-05-30 09:13 - 2025-05-30 09:13 - 000040293 _____ C:\Users\cervenad\Downloads\1237181070287_5_1132_20250522.pdf
2025-05-30 07:24 - 2025-06-25 13:03 - 000003086 _____ C:\Windows\system32\Tasks\AMDLinkUpdate
2025-05-29 14:03 - 2025-05-29 14:03 - 000113977 _____ C:\Users\cervenad\Downloads\Žádost o prominutí penále ČSSZ.pdf
2025-05-27 14:11 - 2025-05-27 14:11 - 000012467 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036 (1).pdf
2025-05-27 14:11 - 2025-05-27 14:11 - 000006073 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036-1634566842-potvrzeni.p7s
2025-05-27 14:11 - 2025-05-27 14:11 - 000003652 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036-1634566842-potvrzeni.pdf
2025-05-27 14:10 - 2025-05-27 14:10 - 000012467 _____ C:\Users\cervenad\Downloads\DADPIS-0070944938-20250527-141036.pdf
2025-05-27 08:47 - 2025-05-27 08:47 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2025-05-26 12:58 - 2025-05-26 12:58 - 001579688 _____ C:\Users\cervenad\Downloads\voucher-KARTDAA49BC9DE0002.pdf
2025-05-26 12:58 - 2025-05-26 12:58 - 001579688 _____ C:\Users\cervenad\Downloads\voucher-KART90E5085E5D7003.pdf
2025-05-26 12:57 - 2025-05-26 12:57 - 001579678 _____ C:\Users\cervenad\Downloads\voucher-KARTEE185384845001.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-25 13:03 - 2025-02-27 08:17 - 000003118 _____ C:\Windows\system32\Tasks\AMDInstallLauncher
2025-06-25 12:55 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-06-25 12:52 - 2021-11-24 10:21 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-06-25 11:39 - 2021-12-28 10:58 - 000000144 _____ C:\Windows\system32\config\netlogon.ftl
2025-06-25 10:26 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-06-25 10:26 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2025-06-25 04:33 - 2021-12-27 19:06 - 000000000 ____D C:\Windows\SystemTemp
2025-06-24 13:04 - 2023-07-19 19:19 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Word
2025-06-24 10:46 - 2023-07-19 19:20 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Excel
2025-06-24 08:07 - 2023-08-28 18:22 - 000000000 ____D C:\Users\cervenad\AppData\LocalLow\Temp
2025-06-24 08:07 - 2023-07-19 19:03 - 000000000 ____D C:\Users\cervenad\AppData\LocalLow\Adobe
2025-06-24 07:45 - 2021-12-28 11:30 - 000000000 ____D C:\KBprikazy
2025-06-22 00:32 - 2021-12-27 18:41 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-06-21 08:33 - 2023-07-19 18:51 - 000000000 ____D C:\Users\cervenad\AppData\Local\Packages
2025-06-21 08:33 - 2021-11-24 10:21 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-06-19 19:10 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2025-06-19 10:39 - 2023-07-19 18:51 - 000000000 ____D C:\Users\cervenad\AppData\Local\D3DSCache
2025-06-19 07:25 - 2023-05-09 10:12 - 000000000 ____D C:\ProgramData\firebird
2025-06-18 18:33 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-06-18 18:32 - 2021-12-28 11:09 - 000000000 ____D C:\Program Files\Microsoft Office
2025-06-18 15:25 - 2021-11-24 10:26 - 002319808 _____ C:\Windows\system32\PerfStringBackup.INI
2025-06-18 15:25 - 2021-04-30 08:05 - 000934756 _____ C:\Windows\system32\perfh005.dat
2025-06-18 15:25 - 2021-04-30 08:05 - 000234006 _____ C:\Windows\system32\perfc005.dat
2025-06-18 15:25 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2025-06-18 15:21 - 2021-12-28 12:22 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2025-06-18 15:21 - 2021-12-28 11:00 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-06-18 15:21 - 2021-11-24 10:21 - 000008192 ___SH C:\DumpStack.log.tmp
2025-06-18 15:21 - 2021-11-24 10:21 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-06-18 15:21 - 2019-12-07 11:03 - 001310720 _____ C:\Windows\system32\config\BBI
2025-06-18 08:01 - 2021-12-28 11:30 - 000000000 ____D C:\KBvypisy
2025-06-16 07:53 - 2023-08-07 06:25 - 000000000 ____D C:\Users\cervenad\AppData\Local\AMD_Common
2025-06-14 13:02 - 2025-02-06 11:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-667896778-3875923744-3874593446-1001
2025-06-14 13:02 - 2025-02-06 11:57 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-1159
2025-06-14 13:02 - 2025-02-06 11:57 - 000003540 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2496437920-1329170045-526373181-500
2025-06-14 13:02 - 2023-07-19 16:29 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-500
2025-06-14 13:02 - 2023-07-19 16:19 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2496437920-1329170045-526373181-1159
2025-06-14 13:02 - 2021-12-27 19:08 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-667896778-3875923744-3874593446-1001
2025-06-14 13:02 - 2021-11-24 10:27 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-06-14 13:02 - 2021-11-24 10:27 - 000002137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-06-13 07:32 - 2024-04-19 08:39 - 000002080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-06-13 07:32 - 2023-03-07 09:20 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2025-06-11 17:37 - 2021-11-24 10:21 - 000447968 _____ C:\Windows\system32\FNTCACHE.DAT
2025-06-11 17:36 - 2024-07-10 08:18 - 000000000 ____D C:\Windows\system32\compatrel
2025-06-11 17:36 - 2019-12-07 11:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\PrintDialog
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellComponents
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2025-06-11 17:36 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-06-11 15:25 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2025-06-11 15:22 - 2021-11-24 10:24 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-06-11 15:17 - 2021-12-27 18:46 - 000000000 ____D C:\Windows\system32\MRT
2025-06-11 15:15 - 2021-12-27 18:46 - 216824056 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2025-06-11 14:56 - 2023-07-19 19:18 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Outlook
2025-06-11 08:21 - 2023-07-19 19:18 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Microsoft\Office
2025-06-10 12:01 - 2021-11-24 10:23 - 000000000 ____D C:\ProgramData\Package Cache
2025-06-10 11:59 - 2021-12-28 12:13 - 000000000 ____D C:\Záloha Fenix
2025-06-10 11:59 - 2021-11-24 09:59 - 000000000 ____D C:\install
2025-06-09 18:11 - 2023-07-19 19:02 - 000000000 ____D C:\Users\cervenad\AVENSIO
2025-06-09 12:56 - 2024-03-19 10:41 - 000000000 ____D C:\Users\cervenad\AppData\Local\CrashDumps
2025-06-05 13:57 - 2023-07-19 16:28 - 000000000 ____D C:\Users\administrator.ZSPRIBYSLAV
2025-06-05 13:57 - 2022-08-25 08:46 - 000000000 ____D C:\Users\knihovna
2025-06-05 13:57 - 2021-12-28 10:59 - 000000000 ____D C:\Users\administrator
2025-06-05 13:57 - 2021-12-27 18:38 - 000000000 ____D C:\Users\dpadmin
2025-06-05 07:05 - 2023-07-19 18:51 - 000000000 ____D C:\Users\cervenad
2025-05-27 14:37 - 2023-10-24 08:40 - 000000000 ____D C:\Users\cervenad\AppData\Roaming\Zoom
2025-05-27 08:47 - 2024-12-12 10:00 - 000004256 _____ C:\Windows\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2496437920-1329170045-526373181-1159
2025-05-26 07:21 - 2021-12-28 11:45 - 000000000 ____D C:\Program Files (x86)\Profibanka
==================== Files in the root of some directories ========
2025-06-24 14:55 - 2025-06-24 14:59 - 000007655 _____ () C:\Users\cervenad\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================